AIURIS

Analysis No. 1 / 2026  ·  July 2026  ·  AI Act  ·  labour law  ·  algorithmic audit

Algorithmic management ahead of the deadline. What changes on 2 August 2026

Within a few weeks, artificial intelligence systems used in employment will no longer be assessed solely through the lens of data protection. The entry into application of the AI Act's provisions on high-risk systems means that an employer using algorithmic tools for recruitment, evaluation or supervision becomes subject to a self-standing catalogue of obligations, compliance with which it must be able to demonstrate.

From practice to legal classification

Algorithmic management is not a future phenomenon in Polish workplaces. Systems that filter candidate applications, software that scores productivity, tools for automated shift scheduling, and platforms monitoring employee activity have been in use for years, and their legal assessment has so far taken place chiefly under the GDPR and the Labour Code's provisions on monitoring (Articles 22² and 22³ of the Polish Labour Code). This is about to change fundamentally. Under Article 113 of Regulation (EU) 2024/1689 (the AI Act), from 2 August 2026 the provisions on high-risk systems classified under Article 6(2) in conjunction with Annex III become applicable.

Point 4 of Annex III covers two groups of systems related to employment. The first comprises systems intended for the recruitment or selection of natural persons, in particular for placing targeted job advertisements, analysing and filtering applications, and evaluating candidates. The second comprises systems used to make decisions affecting the terms of employment relationships, promotion or termination of contractual employment relationships, systems allocating tasks based on individual behaviour, personal traits or characteristics, and systems monitoring and evaluating the performance and behaviour of persons in such relationships. The practical significance of this list lies in the fact that it covers a substantial share of the tools currently offered on the HR market, regardless of whether their vendors use the term "artificial intelligence" in their marketing materials.

For systems already in use, the transitional rule under Article 111 of the AI Act remains important: high-risk systems placed on the market or put into service before the cut-off date are subject to the Regulation once they undergo a substantial modification in their design after that date. This rule is sometimes read as grounds for complacency, but that comfort is illusory. Model updates, changes in functionality and migrations to new versions — typical of software delivered as a service — may themselves constitute such a substantial modification, and the burden of demonstrating continuity will in practice rest on whoever uses the system.

The employer as deployer

The structure of the AI Act divides obligations between the provider of a system and its deployer, which in the context discussed here is, as a rule, the employer. The catalogue set out in Article 26 includes, in particular, the obligation to use the system in accordance with its instructions for use, to entrust oversight to persons with appropriate competence, training and authority, to ensure the relevance and representativeness of input data to the extent the employer exercises control over them, to monitor the system's operation, and to retain the automatically generated logs. From the perspective of collective labour law, Article 26(7) is of particular importance: it requires the employer to inform worker representatives and the workers concerned that they will be subject to a high-risk system, and to do so before the system is put into service or used in the workplace. This obligation introduces a minimum information standard into Polish law that will need to be coordinated with existing information and consultation procedures.

This architecture is complemented by Article 86, which grants persons subject to a decision based on the output of a high-risk system the right to obtain clear and meaningful explanations of the role of the system in the decision-making procedure. Read together with Article 22 of the GDPR and the obligation to carry out a data protection impact assessment (Article 35 GDPR), a multi-layered regime emerges in which the same HR decision may simultaneously be assessed from the standpoint of data protection, AI Act requirements, and labour-law safeguards — foremost among them the principle of equal treatment. A breach of a deployer's obligations is subject to an administrative fine of up to EUR 15 million or up to 3% of annual worldwide turnover (Article 99(4) AI Act).

The picture is completed by Directive (EU) 2024/2831 on improving working conditions in platform work, whose transposition deadline falls on 2 December 2026. Its chapter on algorithmic management — covering, among other things, transparency of automated monitoring and decision-making systems, human oversight, and the right to a human review of decisions — sets a direction in which standards developed for platform work will shape the wider debate on algorithms in employment generally.

The audit as a translation of statute into practice

Between the text of the Regulation and the daily reality of an HR department lies what might be called a control gap: the law assumes that an employer knows which systems it uses, how they work, and which decisions they support, whereas in practice this knowledge tends to be scattered between the vendor, the IT department and business users. Research experience suggests that the most effective tool for closing this gap is an algorithmic management audit — a structured procedure comprising an inventory of the systems in use, an assessment of their legal classification, a review of documentation received from vendors, verification of genuine — rather than merely declared — human oversight, and an analysis of compliance with information obligations toward the workforce.

The output of such an audit should be a Minimum Audit Information Package: a set of documents and data that the employer can present at any time to a supervisory authority, worker representatives, or a court. The value of this package extends beyond compliance alone. The same material that protects the employer against a charge of negligence gives the workforce genuine — not illusory — knowledge of the systems that co-determine its situation, restoring the equality of informational arms without which worker participation in an algorithmic environment remains a declaration only.

Three questions for today

Does the organisation hold a complete inventory of the software tools that support decisions about candidates and employees? Has each of them been assessed, against the criteria of Annex III, as to whether it is a high-risk system? Have worker representatives been informed of the systems that concern them before those systems began operating? If the answer to any of these questions is no, 2 August 2026 marks a natural horizon for putting matters in order.

The coming months will show whether the application of the AI Act in employment follows the path of formal statement-collecting or that of genuine control over technology. Experience from GDPR implementation to date teaches that the difference between the two is decided not on the day the provisions enter into force, but during their first year of application, when practices, document templates and regulatory expectations take shape. It is to that period that the forthcoming analyses published here will be devoted.

About the author. Dr hab. Paweł Nowik, Professor at KUL, Head of the Department of Labour Law and Social Insurance at KUL. Author of works on algorithmic management, worker participation and the auditing of artificial intelligence systems, published in journals including Computer Law & Security Review and the European Labour Law Journal. The analysis reflects the author's own views and does not constitute legal advice in any individual case.