A site manager reads a headline about the EU AI Act on his phone during a tea break, and a small worry lands somewhere behind his sternum. Does that regulation touch the app his cleaning crews tap in and out of every morning? Is a clock-in tool now, by some quirk of Brussels drafting, a “high-risk AI system”? The question sounds overcautious until you actually open the text, because the AI Act does single out software that manages people at work, and it puts a slice of it in the same risk tier as AI used in medical devices and power grids. The worry is reasonable. The answer, though, depends entirely on what the software actually does, not on whether it happens to run on a phone with a green icon.
What the AI Act actually flags
Regulation (EU) 2024/1689, the AI Act, lists categories of “high-risk” AI in its Annex III, and point 4 of that annex is dedicated to employment, workers’ management and access to self-employment. It covers AI built to recruit or select people, including systems that place targeted job adverts, filter applications or score candidates. It then goes further, into systems used to decide on promotion, termination or the allocation of tasks based on someone’s individual behaviour or personal traits, and into systems that monitor and evaluate the performance and conduct of people already in work. None of that is vague. It is a list of AI that makes or heavily shapes decisions about a human being’s job, and Brussels decided those decisions deserve scrutiny, human oversight and a paper trail, not a black box.
This is the branch of technology sometimes called algorithmic management: software that assigns shifts, ranks output, flags underperformers or nudges someone towards the door, with a manager rubber-stamping whatever the model concludes. It has crept into logistics, call centres and gig platforms over the last decade, usually sold as efficiency and arriving as something closer to a supervisor nobody elected. The AI Act does not ban it outright. What it does is force it into the open: providers and employers who deploy this kind of system face a fundamental rights impact assessment, a duty to keep logs, a requirement for competent human oversight, and an obligation to tell workers and their representatives, before the system goes live, that it is being used on them at all.
Wondering which side of the line your own tools sit on?
See what a transparent, geo-timestamped attendance record looks like in practice.
Open your trialWhere the line actually sits

Here is the distinction that gets lost every time this subject comes up in a trade press headline. There is a wide gap between an AI system that decides something about a worker and a record that simply states a fact about them. A tool that scores candidates, ranks performance or flags who should be let go is making a judgement, and the AI Act is right to treat judgement of that kind as high stakes. A tool that logs who clocked in at a job site, at what time, and for how many hours, is not judging anything. It is not weighing personal traits, it is not predicting who will underperform next quarter, and it is not deciding who gets the next shift. It states a fact that already happened, and it leaves every decision about what to do with that fact in human hands. Annex III catches the first kind of system. It has no reason to catch the second.
The practical test, for an owner running crews of cleaners, security guards or installers, is not whether software touches employment at all. It is whether that software makes an automated decision or produces an automated score about a person, and whether the worker can see, understand and challenge what it records about them. Transparency is the hinge the whole regulation turns on. An employer deploying a genuinely high-risk system under the AI Act has to inform workers’ representatives and the people affected before switching it on, has to keep records a human can audit, and has to make sure a competent person, not the algorithm, carries the final call. A tool that never makes that call in the first place has already cleared the hardest part of that obligation, simply by design. Recording is not deciding, and the regulation was never really written to catch the record.









