2026. April 28.
Szerző: Ügyvédi Iroda

If you are a business owner or HR manager and your team uses ChatGPT, Copilot or any other AI tool on a daily basis, the EU AI Act applies to you. The regulation imposes direct EU AI Act employer obligations (Hungarian: eu ai act munkáltató kötelezettségei) in three key areas: recruitment, performance evaluation and mandatory AI training for employees. In this article, we provide a practical guide on how to meet these requirements on time and effectively.

Why Does the AI Act Affect Almost Every Hungarian Employer?

Who qualifies as a “deployer” under the regulation?

Under Regulation (EU) 2024/1689 — commonly known as the AI Act — any organisation that uses an AI system under its own authority in a professional context qualifies as a deployer. In practice, this means that if an employer allows the use of any AI-based tool, the AI Act HR compliance (Hungarian: AI Act HR kötelezettségek) requirements apply. In our firm’s experience, many businesses are unaware that everyday generative AI tools also fall within this scope.

What are the key deadlines?

The regulation takes effect in stages. Since 2 February 2025, prohibited AI practices must be discontinued and AI literacy obligations are already in force. The penalty framework was activated on 2 August 2025, giving authorities the power to impose fines. Full compliance — including rules on high-risk systems — becomes mandatory on 2 August 2026, although the European Commission’s Digital Simplification Package may extend this deadline to the end of 2027.

The Risk Classification Logic — Which HR Activity Falls Where?

Unacceptable, high, limited and minimal risk

The AI Act takes a risk-based approach, classifying AI systems into four categories. Minimal-risk systems (such as spam filters or recommendation engines) are subject to virtually no requirements. Limited-risk systems (such as chatbots) must meet transparency obligations: users must be informed they are interacting with AI.

High-risk systems are subject to strict documentation, testing and oversight requirements. Unacceptable-risk systems are banned outright.

Why are recruitment and performance evaluation classified as “high risk”?

Annex III, point 4 of the AI Act explicitly lists AI systems used in employment and workforce management as high-risk. The reasoning is straightforward: these tools directly affect people’s livelihoods, careers and fundamental rights. Every employer should be aware that the entire spectrum — from recruitment screening tools to performance evaluation algorithms — may fall into this category.

AI Act Recruitment Rules — What Is Allowed and What Is Not?

Job advertising, screening and candidate assessment with AI

Under the regulation, any AI system used for targeted job advertising, analysing and filtering applications, or evaluating candidates qualifies as high-risk. This does not mean these tools are banned — but their use is subject to strict conditions. Employers must ensure high-quality training data, detailed documentation of the system’s operation and the implementation of risk management measures.

Human oversight and non-discrimination

One of the most important AI Act recruitment rules (Hungarian: AI Act toborzás szabályai) is the requirement for human oversight. AI cannot make final hiring decisions on its own — a human must always have the final say. In addition, AI systems must be free from discrimination, supported by an EU conformity declaration. In our legal practice, we often see companies overlook the fact that GDPR data protection rules also apply in full to AI-based recruitment.

AI Employee Performance Evaluation — New Rules for the Workplace

Promotion, dismissal and changes to employment conditions using AI

It is not only recruitment that falls under the regulation. Decisions made during the course of employment are equally affected. If an AI system is involved in promotions, dismissals or changes to working conditions, this also constitutes a high-risk application. This classification triggers the same documentation, transparency and oversight obligations as recruitment systems. It is therefore essential that employers consider the rules on AI employee performance evaluation beyond just the hiring process.

What is the difference between analysis and decision-making?

Not every use of AI automatically qualifies as high-risk. If a system merely analyses the outcomes of prior human decisions or identifies patterns without influencing future decisions, it may not fall into the stricter category. However, if AI actively contributes to shaping an employment-related decision — for example, by ranking employees based on performance — it clearly constitutes a high-risk application. Drawing this line requires case-by-case assessment for each system.

Workplace Emotion Recognition — What the AI Act Categorically Prohibits

Which systems fall under the ban?

The AI Act classifies workplace emotion recognition AI systems as unacceptable risk. This includes tools that infer emotional states, satisfaction levels or mental health from employees’ biometric data — facial expressions, voice tone, posture or gestures. This ban has been in force since 2 February 2025 and already applies to every Hungarian employer. Our firm considers it particularly important to highlight this, as some performance evaluation software may contain hidden emotion recognition features.

Fines: up to EUR 35 million

The regulation imposes the most severe penalties for using unacceptable-risk AI practices: up to EUR 35 million, or 7% of the company’s annual global turnover — whichever is higher. The Hungarian implementing decree (Government Decree 344/2025) sets the upper limit in forints at HUF 13.3 billion (approximately EUR 34 million). The AI market surveillance authority — the Ministry of National Economy — has been authorised to apply these sanctions since August 2025.

Mandatory AI Training Employer Obligations — AI Literacy in Practice

What exactly does Article 4 of the AI Act require?

Article 4 of the AI Act requires organisations that deploy AI systems to take measures to ensure their employees have an adequate level of AI literacy. This obligation has been applicable since 2 February 2025 — in other words, it is not a future task but a current requirement. The regulation does not prescribe a specific format: training may be delivered through e-learning, classroom sessions, internal policies or a combination of these. The key point is that employees must understand how the AI systems they use work, their capabilities and their risks.

How can employers make training mandatory?

Under the Hungarian Labour Code (Mt.), employers have the right to issue instructions, which means they can unilaterally require employees to complete AI training if it is relevant to their role. In this case, training time counts as working hours, wages are payable and the employer bears the full cost. A study contract may also be used as an alternative, offering an incentive-based solution for both parties. From the mandatory AI training employer (Hungarian: MI képzés kötelező munkáltató) perspective, the legal tools are in place — the question is whether companies act in time.

Documentation and verifiability

In the event of a regulatory inspection, the employer must be able to demonstrate that it has taken all necessary steps to ensure employee AI literacy. This is why proper documentation is the key to complying with AI use workplace regulations: training plans, attendance records, test results and proof of internal policy distribution. A policy document alone is not enough — AI literacy must become part of everyday work practice. In our experience, the most successful organisations treat AI training not as a one-off obligation but as an ongoing development programme.

AI Use Workplace Regulations — Applying the GDPR and the AI Act Together

Why is it not enough to comply with the AI Act alone?

When using AI in relation to employees, the GDPR and the data protection provisions of the Hungarian Labour Code must also be fully observed alongside the AI Act. Employers may only request personal data from employees that is relevant to the establishment, performance or termination of the employment relationship. EU AI Act employer obligations therefore do not operate in isolation — the legal framework is complex, and compliance can only be assessed as a whole.

Shadow AI — the invisible risk

One of the greatest practical challenges is the phenomenon of shadow AI, where employees use AI tools without the employer’s knowledge or approval. In such cases, not only may AI Act compliance obligations be breached, but trade secrets and personal data may also escape the organisation’s control. The most effective preventive measure is to establish an internal AI policy that clearly defines which tools may be used and under what conditions.

How Should Employers Prepare to Meet EU AI Act Employer Obligations by 2026?

Practical steps to take now

EU AI Act employer obligations cannot wait until August 2026 — preparation must begin now. The first step is to conduct an AI inventory: identify which AI systems are used within the organisation and which risk category they fall into. This should be followed by developing an internal policy, preparing a training plan and building a documentation system. Those who start preparing now will not only ensure regulatory compliance but also gain a competitive advantage in the market.

Why is it worth seeking legal advice?

The combined application of the AI Act, the GDPR, the Hungarian Labour Code and Act LXXV of 2025 (Hungarian AI Act Implementation Law) requires complex legal analysis. The risk classification of individual AI systems, the required content of documentation and the precise scope of training obligations are all questions where template solutions are not sufficient. The severity of regulatory fines alone — potentially reaching billions of forints — justifies making the preparation a structured, professionally guided process rather than a last-minute exercise.

We can help you prepare for AI Act compliance.

Madarassy Law Firm, with over 20 years of experience, stands ready to support clients in the fields of AI regulation, data protection and employment law. Whether you need an AI inventory, an internal policy or help meeting your EU AI Act employer obligations — get in touch with us at www.madarassy-legal.com.