Vimeo Twitter Linkedin RSS
Foto

The AI Regulation establishes a stringent legal framework for the business use of artificial intelligence, with a particular impact in the employment sphere.

Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act) establishes a binding legal framework applicable to the entire AI value chain (providers, deployers, importers and distributors), going beyond the strictly technological sphere and affecting any organisation that uses such systems. Its application is phased: since February 2025, the absolute prohibitions under Article 5 have been in force (such as the use of AI to infer emotions in the workplace or the biometric categorisation of sensitive data); in August 2025, the obligations for general-purpose models come into effect; and in August 2026, the requirements for high-risk systems will become fully enforceable, a category that includes labour management tools (recruitment, evaluation, promotion, supervision or termination of employment). These obligations entail, among others, comprehensive risk management, data governance, traceability, conformity assessment, enhanced transparency and effective human oversight, requiring companies to immediately begin their compliance strategies, particularly by identifying and internally classifying the AI systems they use.

However, compliance with the AI Act does not exhaust legal requirements, as in the Spanish legal system there are additional obligations in the fields of labour law and data protection (Workers’ Statute, LOPDGDD, GDPR, equality and prevention regulations), which are cumulative and may give rise to liability even in systems not classified as high risk. Particular emphasis should be placed on the obligation of algorithmic transparency towards workers’ legal representatives (Article 64.4(d) of the Workers’ Statute), the limits on employer digital monitoring and the right to privacy (Articles 87 et seq. of the LOPDGDD), as well as the need to carry out impact assessments and avoid discriminatory bias. Case law has reinforced these requirements, declaring monitoring policies adopted without trade union involvement to be void. In this context, companies must take immediate measures: inventory AI systems, verify prohibitions and risks, inform workers’ representatives, ensure genuine human oversight, review contracts with suppliers, audit digital monitoring policies, train staff and adopt internal AI use policies. An integrated approach is essential to avoid legal risks and ensure effective compliance.

Access the full alert

Publicado en

Labour
Data Protection, Cybersecurity and Technology
Profesionales relacionados

También te puede interesar