AI is now woven into almost every stage of the employment lifecycle. It screens resumes, ranks candidates, analyses video interviews, flags retention risk, generates performance ratings, and forecasts headcount. A 2025 SHRM survey found that 43% of HR professionals now use AI tools to support HR functions, nearly double the 26% reported in 2024.
The law is catching up, but not evenly. The EU, the US, and China have each taken a different path, and for HR teams managing international workforces, or for Employer of Record (EOR) providers who legally employ workers in dozens of countries, those differences carry real financial and reputational stakes.
This guide compares the three most significant regulatory frameworks shaping AI in HR today, and sets out what each one means in practice, especially for EOR providers, who sit in an unusually exposed position: they are simultaneously the legal employer of workers across markets, and the deployer of the AI systems used to manage them.
The three use cases this guide covers
- Hiring and recruitment AI: tools that screen, score, or rank candidates
- Performance management AI: systems that assess, monitor, or rate employee performance
- Workforce planning AI: tools that forecast headcount, identify skills gaps, or support redundancy decisions
The European Union: a comprehensive, risk-based framework
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive horizontal law governing artificial intelligence. It entered into force on 1 August 2024, and the most significant obligations for HR-related AI systems, the high-risk rules, became fully enforceable on 2 August 2026.
The Act sorts AI systems into four risk tiers: unacceptable risk (prohibited outright), high risk (strictly regulated), limited risk (transparency obligations only), and minimal risk (no specific obligations). For HR, the critical tier is high-risk: all AI systems used in employment and workforce management are expressly listed in Annex III as high-risk, including CV screening, targeted job advertising, video interview analysis, performance monitoring, promotion and pay decisions, termination and restructuring, and task allocation and scheduling.
What deployers (employers) must do from August 2026
- Risk management: implement and document a risk management system proportionate to the system’s risks
- Human oversight: assign competent individuals with the authority to intervene and override AI outputs
- Worker notification: inform workers and their representatives before deploying any high-risk AI system
- Logging: retain logs generated by high-risk AI systems for a minimum of six months

