Organizations using AI for recruitment, candidate screening, employee evaluation, or supporting HR decisions will be required to demonstrate compliance with the requirements of the AI Act. The absence of appropriate procedures and documentation may result in inspections, financial penalties, and liability for violations of the rights of employees and candidates.
This is particularly important for HR departments, recruitment teams, compliance functions, and company management boards.
Over the past few years, many organizations have focused primarily on the opportunities offered by artificial intelligence. Today, AI tools support recruitment processes, CV analysis, candidate assessment, job advertisement creation, talent management, and employee evaluations. At the same time, generative AI tools are increasingly being used to prepare job descriptions, reports, and HR analyses.
The challenge is that in many companies, implementations have taken place rapidly, often without central oversight and without consistent rules governing AI use.
This is where AI Governance comes into play.
AI Act from 2 August 2026
One of the most common mistakes organizations make is assuming that compliance with the AI Act can be left entirely to the IT department.
AI Governance is not a technology project.
It is a system for managing the use of artificial intelligence that encompasses processes, people, data, accountability, and oversight.
In practice, responsibility is distributed across multiple organizational functions:
Therefore, AI Governance should be treated as an element of corporate governance, rather than merely a technology initiative.
In the employment context, artificial intelligence can influence decisions concerning people. This is precisely why solutions used in recruitment and workforce management are at the center of regulatory attention.
This includes systems supporting:
The greater the influence of AI on employment-related decisions, the more important transparency, human oversight, risk management, and accountability become.
One of the most important elements of the AI Act is its risk-based approach.
The Regulation does not treat all AI applications equally. The greater the impact an AI system has on an individual's rights, opportunities, and life circumstances, the greater the obligations placed upon the organization.
This is why regulators pay particular attention to AI solutions used in employment and workforce management processes.
This means that even if an organization uses AI solely as a support tool for recruiters or managers, it should assess whether the solution is subject to additional requirements under the AI Act.
In practice, the key question is no longer only:
“Do we use AI?”
but also:
“Do we understand the regulatory risks associated with the way we use it?”
Public discussions surrounding the AI Act often focus on potentially high financial penalties. While sanctions are an important element of the regulation, for most organizations the greater challenge may be demonstrating that AI is used in a controlled and compliant manner.
Nevertheless, the AI Act provides for significant administrative fines for certain violations. Depending on the nature of the infringement, penalties may reach:
For most organizations, however, the key takeaway should not be the level of penalties alone.
A far more important question is:
Can we demonstrate during an audit, regulatory inspection, or client inquiry that we have an effective AI Governance framework in place?
Documentation, AI system inventories, risk assessments, oversight procedures, and employee training will form the organization's first line of defense.
Many organizations assume that if a tool works properly, the problem is solved. This is a dangerous assumption.
AI Governance assessments frequently reveal that companies use dozens of different AI tools implemented independently by various teams.
The technology works.
The governance framework does not exist.
And that may become the organization's greatest challenge during an inspection or audit.
Imagine a situation in which a candidate or employee raises concerns regarding a process supported by artificial intelligence.
In such circumstances, the organization may be asked to demonstrate how it manages its AI systems.
Common questions include:
Failure to answer these questions may indicate not only a regulatory issue but also significant business risks.
Financial penalties typically receive the most attention. However, sanctions are only one aspect of the risk.
A much greater challenge may be demonstrating that the organization has a genuine AI management framework and appropriate documentation.
In HR, reputation plays a crucial role. Information about non-transparent use of AI in recruitment processescan quickly affect how candidates, customers, and business partners perceive the employer.
Improper use of artificial intelligence may lead to:
Increasingly, customers and business partners are asking questions similar to those raised a few years ago regarding GDPR:
Answers to these questions are increasingly becoming part of procurement processes, supplier audits, and contractual risk assessments.
The first step should not be purchasing another AI tool.
The first step should be assessing the organization's current level of AI Governance maturity.
Every company should be able to answer the following questions:
If the answer to even one of these questions is “no” or “I don't know,” it should be treated as a signal to conduct a comprehensive assessment.
In 2026, the most important question is not:
“Are we using artificial intelligence?”
Most organizations already are.
The more important question is:
“Can we demonstrate that we manage artificial intelligence in compliance with the AI Act?”
The ability to document processes, responsibilities, oversight arrangements, and risk assessments will be one of the most important indicators of mature AI Governance.
Technology can be implemented in minutes. The trust of employees, candidates, customers, and regulators takes years to build. That is why the greatest risk is not the use of artificial intelligence itself. The greatest risk is not knowing where, how, and under what rules AI is being used throughout the organization.
From 2 August 2026, the use of artificial intelligence within organizations will become not only a matter of innovation but also of business and regulatory responsibility.
For many organizations, the greatest challenge will not be the technology itself, but proving that AI is used in a controlled, transparent, and compliant manner.
This is particularly important in HR and recruitment, where AI-assisted decisions can directly affect candidates and employees. Organizations should already be identifying their AI tools, building AI system inventories, implementing policies, and establishing oversight and risk management mechanisms.
AI Governance is no longer a technology project. It is becoming part of corporate governance, much like information security, compliance, and data protection. Organizations that establish a mature AI management framework early will not only mitigate regulatory risks but also gain competitive advantage and greater trust from customers, employees, and business partners.
The AI Act is being implemented in stages, which means organizations should closely monitor the timeline for the applicability of specific requirements.
Key upcoming dates
For many organizations, 2026 will be the first year in which regulators begin to expect a documented approach to AI Governance.
Yes. The AI Act applies both to providers of AI systems and to organizations that use artificial intelligence in their operations. However, the scope of obligations depends on the type of solution and the level of risk associated with its use.
Yes. Many organizations mistakenly assume that AI Governance applies only to large, specialized AI systems. In reality, the use of popular generative AI tools such as ChatGPT, Copilot, Gemini, or Claude should also be governed by appropriate policies, procedures, and oversight mechanisms.
There is no single universal model. Responsibility is typically shared among the management board, compliance, legal, HR, IT, cybersecurity, and the Data Protection Officer. However, it is essential to appoint a process owner and clearly define responsibilities.
Yes. An AI systems inventory is one of the fundamental tools for risk management. It enables organizations to identify which solutions are being used, by which departments, for what purposes, and with what associated risks.
Risk assessments should not be treated as one-off exercises. They should be reviewed whenever new tools are implemented, business processes change, AI systems gain new functionalities, or incidents and irregularities occur.
In practice, yes. Even the best procedures will be ineffective if employees do not know how to use AI safely. Training is particularly important for HR teams, managers, employees who use AI in their daily work, and senior leadership.
This is a simplification, but a partly accurate one. Just as GDPR standardized the management of personal data, AI Governance standardizes the management of artificial intelligence. In both cases, documentation, accountability, oversight, and risk management are critical.
The most common indicators include:
The benefits extend far beyond compliance. Organizations gain:
The best starting point is an assessment of the organization's current state. Only after identifying existing tools, processes, risks, and gaps can an organization effectively design policies, procedures, accountability structures, and training programs.
Crowe Poland