EU AI Act by department: HR, finance, marketing, and operations
EU AI Act obligations per department depend on the risk class of the AI system. HR selection and credit scoring are high-risk (Annex III) and carry the full Art. 26 obligations; marketing AI and chatbots usually fall under the transparency obligation of Art. 50. A per-system Art. 6 analysis determines the exact obligation.
Updated: June 2026
Introduction: department-level AI compliance
The EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → is a horizontal regulation, it applies across all sectors and all departments. But the practical compliance requirements vary significantly depending on the type of AI application. An HR department using AI for CV screening faces high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → obligations including FRIAFRIAFundamental Rights Impact Assessment: required of public bodies and certain private deployers before using some high-risk AI systems under the EU AI Act.Open full entry → and human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry →. A marketing department using AI for advertising copy has, in most cases, only the transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → obligation of Art. 50.
This guide analyses the most common AI applications by department against their EU AI Act status and compliance requirements. It is a diagnostic instrument, not a substitute for the full classification analysis required by Art. 6 for each specific system.
HR & recruitment
CV screening and candidate assessment: High-risk AI (Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry →, point 4). This is the most regulated HR application under the EU AI Act. AI that selects, scores, or ranks candidates based on their CV, cover letter, or online questionnaire responses falls without exception into the high-risk category. All Art. 26 obligations apply: human oversight (Art. 26.2), input data quality controlscontrolThe concrete, testable measure that reduces a specific risk, and through that risk protects the principle behind it. Also called a risk management measure, risk response, or risk treatment. Always traceable to the risk it addresses: under EU AI Act Art. 9 every control must map back to a specific risk, and controls recorded separately from their risks is a recognized compliance failure. It works in one of three types: preventive, detective, or corrective. See risk, control types, evidence.Open full entry →, and informing the affected individual (Art. 26(11)). The "four-eyes" two-person rule is not a general requirement here; it is specifically Art. 14(5) for biometric identification.
Borderline: A tool that only checks CV formatting (completeness check) without any substantive assessment of the candidate probably falls outside Annex III. Once the system makes substantive judgments about suitability, it falls within point 4.
Performance evaluation systems: High-risk AI (Annex III, point 4). AI contributing to employee assessment for promotion, salary increase, or contract termination falls under point 4. Human oversight (Art. 26.2) requires genuine review, a manager who rubber-stamps AI assessments without substantive evaluation does not satisfy the obligation.
AI scheduling systems: Limited risk or minimal risk, depending on system autonomy. If the system generates a roster that a planner can freely modify, and does not affect employees' working hours or contract conditions, it is probably not high-risk. If the system effectively determines actual working conditions, further analysis is required.
Finance & risk
Credit scoring and credit allocation: High-risk AI (Annex III, point 5.b). Systems assessing the creditworthiness of natural personsnatural personA living human individual, as distinct from a legal person such as a company; the holder of data-protection and AI-Act rights.Open full entry → are high-risk under Annex III point 5(b); lending to a business is outside 5(b) unless the debtor is a natural person. This applies to banks, leasing companies, buy-now-pay-later providersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry →, and other financial institutions. Sector-specific regulations (Wft, EBA guidelines on AI in credit) apply alongside the EU AI Act.
Fraud detection: AI used to detect financial fraud is expressly carved out of Annex III point 5(b), so it is not high-risk on that basis. It may still be high-risk on a different ground, for example where it is the sole basis for a decision that itself falls under another Annex III category, but the fraud-detection function alone does not trigger 5(b).
Financial reporting AI and budget forecasting: Minimal risk in most cases. AI analyzing financial data and generating forecasts for internal use without direct decision consequences for external persons generally falls outside the high-risk category. Transparency with management users about forecast limitations is good practice.
Marketing & communications
Generative AIgenerative AIAI systems that produce new content (text, images, audio, code) rather than only classifying or predicting. Large language models are the prominent example.Open full entry → for content production (text, images): Limited risk (Art. 50). AI-generated content must be labeled as such when it could be mistaken for human-created content. A fully AI-generated blog presented as "written by our editorial team" violates Art. 50. Systems that support human writers with AI assistance (co-pilot), where the human makes substantive contributions, require less clear labeling of the end content.
Personalized advertising targeting: Minimal to limited risk in most cases. Targeting algorithmsalgorithmThe learning procedure (e.g. gradient descent, tree induction); running it on training data produces a model. Controls attach to models and systems, not algorithms in the abstract.Open full entry → that segment audiences based on clickstream behavior are not high-risk AI. Watch out: if targeting specifically exploits vulnerable groups (Art. 5.1.b) or uses subliminal techniques (Art. 5.1.a), it is a prohibited AI practice regardless of risk class.
AI chatbots for customer service: Limited risk (Art. 50). Chatbots must identify themselves as AI. The risk level increases if the chatbot makes or supports decisions with significant consequences for the customer (e.g. credit limit adjustments, contract modifications), in that case, a classification analysis is required.
Operations & IT
AI for quality control in manufacturing: Context-dependent. If the system makes safety-related decisions for products covered by Annex I (machinery, medical devices), it is high-risk AI. If the system flags quality deviations that are always reviewed by an operator, Art. 6.3 may apply.
Predictive maintenance: Minimal risk in most cases. AI that predicts machine failures and advises maintenance for internal use is generally not high-risk, unless the system directly intervenes in critical infrastructure (Annex III, point 2).
IT security AI (anomaly detection, SIEM): Minimal to limited risk depending on automated action. If the system only generates alerts for security analysts, it is not high-risk AI. If the system automatically blocks accounts or denies access to employees or customers based on AI assessment, a classification analysis is required.
Healthcare
AI diagnostic support (imaging analysis, symptom checker): High-risk AI in most cases (Annex I if a MDR-regulated product, or Annex III for standalone AI advisory systems). Medical AI faces the highest compliance burden: conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry → by a notified bodynotified bodyAn independent conformity-assessment organization designated to verify that a high-risk AI system meets the AI Act before it reaches the market.Open full entry → (for MDR products), technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry →, human oversight, and typically a FRIA.
Administrative AI in healthcare (scheduling, billing verification): Minimal risk in most cases, unless decisions directly affect the provision of care to individual patients.
Practical starting point: build your AI inventory
This overview is a starting point, not a definitive classification. For each AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → your organization deploys, conduct a formal classification analysis per Art. 6. Start with the highest-risk categories: HR selection, credit assessment, and medical AI. These are most urgent and carry the heaviest compliance obligations.
Compliance checklist
- Has your HR department inventoried all AI tools used in selection, assessment, or workforce management?
- Are your finance AI tools for credit or risk assessment classified as high-risk?
- Are your marketing chatbots configured to identify themselves as AI (Art. 50)?
- Have AI tools in safety-critical operational systems been assessed for their impact on human safety?
- Is there a central AI inventoryAI inventoryA register of all AI systems an organization builds, buys or embeds, with owners and risk tiers. It is the prerequisite for governing any of them.Open full entry → tracking all systems by department?
- Is there a procedure for notifying new AI procurement to the AI Officer?
- Are department heads informed about their responsibility for Art. 4 AI literacyAI literacySufficient understanding of AI's workings, capabilities and risks for one's role, an explicit expectation for provider and deployer staff under the EU AI Act.Open full entry → in their team?