When an employee puts a client’s or a colleague’s data into an artificial intelligence (AI) tool, the organisation is responsible. It is the controller, because it determines the purposes and means of the processing (Article 4(7) GDPR). So an AI tool needs the same as any other processing: a clear purpose, a legal basis, a contract with the vendor and, where the risk is high, a data protection impact assessment. The AI Act – Regulation (EU) 2024/1689 – does not replace the GDPR. It states itself that, apart from the exceptions in Articles 4a and 59, it does not affect the GDPR (Article 2(7) of the AI Act).
On 27 July 2026 an amendment entered into force – Regulation (EU) 2026/1744, which moved some of the dates. The dates here follow that text.
When an employee puts data into an AI chatbot
A common situation: an employee copies a client’s email, a contract or a colleague’s appraisal into a publicly available AI chatbot to get a reply or a summary.
Did the employee have your instructions? A person acting under the authority of the controller may process personal data only on the controller’s instructions (Article 29 GDPR). The controller must take steps to make sure of this (Article 32(4) GDPR). If the organisation has not set out which tools and which data may be used, it cannot show that it meets these duties.
What is the vendor’s role? A vendor that processes the data only on your behalf is a processor (Article 4(8) GDPR). You need a contract with it which, among other things, says that it processes the data only on your documented instructions (Article 28(3)(a) GDPR). When such a contract is required and what it must cover is explained in Data processing agreement: when it is required. And if, under its own terms, the vendor itself determines what to use the data for, for example to train its models, it is a separate controller for that processing (Article 4(7) GDPR). You have then not entrusted the data to a processor – you have disclosed it to another controller, and that needs its own legal basis. Where a processor, in breach of your instructions, itself determines the purposes and means of processing, it is considered a controller for that processing (Article 28(10) GDPR).
Where does the data go? If the vendor’s servers or other processors it uses are outside the EEA, the transfer rules apply (Article 44 GDPR). When a transfer needs standard contractual clauses is covered in our article on transferring personal data outside the EEA.
The data minimisation principle also applies: only the data needed for the purpose is processed (Article 5(1)(c) GDPR). If data was disclosed without authorisation, this may be a personal data breach (Article 4(12) GDPR). It must be notified to VDAI without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to people’s rights and freedoms (Article 33(1) GDPR).
The AI Act adds one duty here. Whoever uses an AI system in their work is its deployer (Article 3(4) of the AI Act). Providers and deployers take measures to support the development of AI literacy of their staff (Article 4(1) of the AI Act). This duty applies from 2 February 2025 (Article 113, point (a), of the AI Act). Until 27 July 2026 it required ensuring, to their best extent, a sufficient level of AI literacy; now no specific level has to be guaranteed.
AI note-takers in meetings and calls
A tool that records, transcribes and summarises a conversation processes the voice and words of every participant, including clients and people from other organisations. This needs a legal basis (Article 6(1) GDPR). People must be informed at the time the data is obtained (Article 13(1) GDPR), that is, before the recording starts, not after the meeting.
The VDAI list makes a DPIA mandatory for recording telephone conversations (point 7) and for processing employees’ audio data at the workplace for monitoring or control (point 10). Recording a video meeting is not literally named in point 7, so in that case the need for a DPIA must be assessed under Article 35(1) GDPR. When note-taker data is used to assess employees’ work, it is already monitoring. The employer must respect employees’ rights to privacy and to the protection of personal data (Article 27(1) of the Labour Code, DK). Where there is a works council, an employer with an average of twenty or more employees must inform and consult it when adopting rules on introducing new technological processes or on monitoring employees (Article 206(1)(4) and (5) DK). What monitoring is allowed at all is covered in Employee monitoring: cameras, GPS and call recording.
Since 2 February 2025 it is prohibited to use AI systems to infer the emotions of a natural person in the areas of workplace and education institutions, except for medical or safety reasons (Article 5(1)(f) and Article 113, point (a), of the AI Act). The ban targets systems that infer emotions from biometric data, such as voice or face (Article 3(39) and Recital 44 of the AI Act). So a tool that infers agents’ emotions or mood from their voice, with the results used to assess their work, is not a risk to be managed – it is a prohibited practice. Merely detecting a raised voice, without inferring emotions from it, is not covered (Recital 18), and analysis of the text of a conversation remains subject to the GDPR. The European Commission’s guidelines on prohibited AI practices (C(2025) 5052) say that the notion of workplace also covers candidates during recruitment, so inferring emotions, for example by analysing a video interview with a candidate, is also prohibited (paragraph 254).
One company wanted to use an AI tool to analyse call recordings and evaluate agents’ work. Our lawyer answered: define the purpose, choose a legal basis for each stage of the AI use, limit the data, assess the risk, carry out an impact assessment where needed, plan how people’s rights will be ensured, and involve the data protection officer.
AI in recruitment and decisions about employees
A candidate or employee has the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects them (Article 22(1) GDPR). Recital 71 GDPR gives e-recruiting practices without any human intervention as an example. Such a decision is allowed only in three cases: where it is necessary for entering into or performing a contract, where the law authorises it, or where the person has given explicit consent (Article 22(2) GDPR). In the first and third case the person must have at least the right to obtain human intervention, to express their point of view and to contest the decision (Article 22(3) GDPR). Where systematic and extensive automated evaluation of people is the basis for such decisions, an impact assessment is mandatory (Article 35(3)(a) GDPR).
When a company asks what the AI Act means for it, one of our first questions is: are you building the system yourself or using one built by someone else? Whoever develops a system and places it on the market or puts it into service under its own name is its provider (Article 3(3) of the AI Act); whoever uses one built by someone else is the deployer. AI systems intended for recruiting or selecting candidates, filtering applications and evaluating candidates, and for decisions on promotion, termination, task allocation based on individual behaviour or personal traits, or monitoring and evaluating employees’ performance are high-risk (Annex III, point 4, of the AI Act). One of the deployer’s duties: before putting such a system into use at the workplace, the employer informs workers’ representatives and the affected workers (Article 26(7) of the AI Act).
In the original text, the obligations for Annex III systems were to apply from 2 August 2026. After the amendment, they apply from 2 December 2027 (Article 113, point (c), of the AI Act). For systems placed on the market or put into service before that date, these obligations apply only if their design is significantly changed afterwards (Article 111(2) of the AI Act).
What can go wrong
The first risk is processing without a basis and breaching the principles. Breaching Articles 5 and 6 GDPR, the rights in Article 22 or the transfer rules can lead to a fine of up to twenty million euros or, for an undertaking, up to 4 % of its total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a)–(c) GDPR). Having no processor contract or no impact assessment – up to ten million euros or up to 2 % (Article 83(4)(a) GDPR).
The second risk is a prohibited AI practice. Non-compliance with the prohibitions in Article 5 of the AI Act carries fines of up to thirty-five million euros or, for an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year, whichever is higher; for SMEs, whichever is lower (Article 99(3) and (6) of the AI Act). The rules on penalties and how they are enforced are laid down by the Member States (Article 99(1) of the AI Act).
The third risk is inheriting the vendor’s infringement. The European Data Protection Board says in Opinion 28/2024 that where personal data are retained in the model, supervisory authorities should take into account whether the controller deploying the model conducted an appropriate assessment to ascertain that the model was not developed by unlawfully processing personal data (paragraph 129).
When to call a lawyer
- when staff already use AI tools and there are no rules on what data may be uploaded;
- when you are choosing an AI vendor and need to assess the contract, its role and transfers outside the EEA;
- when AI is used to select candidates or to assess employees’ performance;
- when client or employee data has already been uploaded to a public AI tool and you need to decide whether this is a breach.
Frequently asked questions
Does the AI Act apply to us if we only use a tool built by someone else?
Yes. Whoever uses an AI system in their work is its deployer (Article 3(4) of the AI Act). The AI literacy duty (Article 4 of the AI Act) and the prohibited practices (Article 5 of the AI Act; two new prohibitions from 2 December 2026) already apply to deployers, and since 2 August 2026 so do the transparency duties, for example informing people that an emotion recognition system is used (Article 50(3) of the AI Act).
Can an AI tool reject candidates automatically?
Only in the exceptional cases listed in Article 22(2) GDPR, and with the right to obtain human intervention and to contest the decision (Article 22(3) GDPR). If such decision-making is used, candidates must be told about it and given meaningful information about the logic involved (Article 13(2)(f) GDPR).
Did the AI Act amendment postpone all obligations?
No. Regulation (EU) 2026/1744 postponed the high-risk obligations to 2 December 2027 (for Annex III systems), changed the wording of the AI literacy duty and added two new prohibitions (on generating intimate images of identifiable people without their consent, and on generating child sexual abuse material), which apply from 2 December 2026. The other prohibited practices, including inferring emotions at work, apply from 2 February 2025 (Article 113, point (a), of the AI Act).
How to start
List the AI tools your staff already use, what data they upload to them and whether there is a contract with the vendor. Mark where AI records conversations, assesses people or helps make decisions about them. Send us this list – we will tell you where an impact assessment is needed, where a contract is needed and where the tool is better dropped.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: Data protection impact assessment.