Where the AI Act Bites: A Practical Guide to High-Risk Uses and the GDPR

2026-07-28 • Source: KR & Associates

AI tools that recruit, evaluate, allocate and monitor staff are among the high-risk uses the EU AI Act names, and most obligations now fall due from 2 December 2027. What counts as high risk, how the GDPR stacks on top, and where to start. The third article in a four-part series with KR & Associates.

*This article is part of a four-part series on European digital sovereignty, published in partnership with [KR & Associates](https://kevinryan.io).* Bring in an AI tool to sift job applications, draft appraisals, share out work or keep an eye on productivity, and you are reaching for an obvious efficiency. Several of those uses also count as high risk under the EU AI Act. The Act is a horizontal regulation, so it governs the technology across sectors rather than industry by industry. It sorts AI systems into four bands: prohibited practices, high-risk uses with detailed obligations, limited-risk uses with transparency duties, and minimal-risk uses with almost none. ![Figure 1. The EU AI Act's risk tiers, the high-risk uses named in Annex III, and the GDPR duties that attach.](/images/articles/article-3-ai-act-risk-tiers.svg) ## The timing matters as much as the rules The Act came into force on 1 August 2024 and applies in stages, and after the 2026 simplification most of the obligations for the high-risk uses in Annex III fall due from 2 December 2027. That simplification followed heavy pressure from large technology companies and from the United States. The Commission called the change one of timing and said it stayed "fully behind the AI Act and its objectives", so the direction holds even where the dates have shifted. ## What makes a system high risk? Its use has to pose a significant risk to health, safety or fundamental rights, and it has to fall within the categories the Act lists. Once it does, both the provider and the deployer carry obligations: risk management, data quality, documentation, transparency, human oversight, accuracy and security. These run through the life of the system, so monitoring and record-keeping carry on after launch. They are far cheaper to build in at the design stage than to bolt on once a tool is in daily use. ## Where the Act meets the GDPR Three everyday uses show how the duties stack up. Profiling, biometric identification and credit scoring are each high risk under the Act, and each also engages the GDPR. Biometric data is a special category under Article 9. Profiling and solely automated credit decisions engage Article 22, which limits decisions taken without a human in the loop. Since one system can trigger both the Act and the GDPR, it pays to run the two assessments together, and a single record can then set out the lawful basis, the risk controls and the human check. In practice that means meaningful human oversight, a data protection impact assessment, and a clear lawful basis written down before the system goes live. ## Annex III casts a wide net It covers recruitment, law enforcement and access to essential services, and it also covers AI used to recruit, to evaluate performance, to allocate tasks and to monitor staff. That means a manager can end up as the deployer of a high-risk system in the very effort to help a team work better. The way to find out is to map the AI uses you have, or plan to have, against Annex III, and to give the provider and deployer obligations a named owner. The classification turns on the details of each system. Where it is unclear, a tailored review from European Tech Map, working with a consultancy such as [KR & Associates](https://kevinryan.io), can pin down what falls within scope. ## Where to start The two concerns meet in the same place. The tools that lift a team's output, those that recruit, evaluate, allocate and monitor, are among the high-risk uses the Act names, so the push to adopt AI and the duty to comply land in one set of systems. A short readiness step keeps both in view: list the AI uses across the organisation, mark which touch an Annex III category, give the obligations an owner, and work to the staged dates so the effort lands against the right deadline. *By Peter Houghton, Kevin Ryan & Andy Wijman, KR & Associates* *Source: Barbara Moens, Financial Times, 7 November 2025.*

Tags: policy, security