Workplace ChatGPT and the EU AI Act
An internal ChatGPT seat is usually limited-risk, not high-risk. Here is when it stays that way, when HR use flips the tier, and what to do by 2 August 2026.
Buying ChatGPT, Claude, or Gemini for the company is not, by itself, a high-risk AI project. The EU AI Act classifies systems by intended purpose, not by logo. A staff writing assistant is typically limited-risk plus Article 50 transparency. The same seat pointed at CVs or credit files is a different system.
If your only AI programme is "we gave everyone a licence," read this before you write a 40-page Annex IV.
A writing assistant usually sits in limited-risk. Point the same seat at CVs or credit files and you have climbed a tier.
Is an Internal Chatbot High-Risk?
Usually no. Annex III lists employment, education, credit, insurance, biometrics, public benefits, and a handful of other uses. A chatbot that drafts emails, summarises meeting notes, or explains your own wiki does not sit on that list.
You still have duties that apply now:
- Article 4 AI literacy — staff who use the tool need enough training to use it responsibly. Live since 2 February 2025. See the literacy piece.
- Article 50(1) — if the system interacts directly with natural persons, those persons must know it is AI, unless that is obvious to a reasonably well-informed person. From 2 August 2026. An internal bot named "HR Decision Engine" is not obvious. A clearly labelled writing assistant often is. Do not bet the company on "obvious."
- GDPR — prompts can be personal data. Works-council rules in DE/FR/NL still apply even when the AI Act tier is limited.
High-risk Chapter III (docs, QMS, CE, registration) waits until 2 December 2027 for Annex III. You do not need that pack for a note-taker.
When Does Workplace ChatGPT Become High-Risk?
When you change the intended purpose. Same model, new system.
Examples that flip you into Annex III point 4 (employment) or point 5 (essential services):
- Screening or ranking applicants
- Evaluating employee performance or promotion
- Deciding task allocation in a way that affects terms of work
- Scoring a natural person's creditworthiness
- Pricing a person's life or health insurance
A "just paste the CV into ChatGPT" workflow is still an AI system you put into service if managers use the output to decide. Putting into service includes own use. There is no customer. There is still a provider: you, if you built or substantially modified the wrapper.
Fine-tuning on your HR data, adding a scoring rubric, or hiding the general-purpose nature behind a "Candidate Fit 0–100" UI is how Article 25 makes you the provider.
What Should We Do This Quarter?
Four things, none of them theatrical:
- Inventory the actual uses. "ChatGPT" is not a use. "Drafting job ads" and "ranking applicants" are.
- Ban Annex III uses in the acceptable-use policy until you classify them properly.
- Label the bot. Article 50(1) is 2 August 2026, not 2027.
- Train the people who will paste customer or employee data into it. Article 4 is already live.
My take: the risk is not the licence. The risk is the first manager who invents a hiring workflow on a Friday. Write the ban down.
If you want the inventory in one place, drop each use into Nytivo as a separate system.
Frequently Asked Questions
Does the EU AI Act apply to ChatGPT at work?
Yes, if the system is used in the Union. Most generic writing use is limited-risk. Employment, credit, and similar Annex III purposes are high-risk.
Do we need a CE mark for an internal ChatGPT seat?
Not for a general writing assistant. Yes if you put a high-risk system into service (including an internal one) once Chapter III applies.
Must we tell staff they are talking to AI?
Article 50(1) requires that persons interacting with the system are informed, unless it is obvious from context. Labelling is the cheap way to stop arguing about "obvious."
What if we only use the vendor's consumer app?
You are still a deployer of whatever system you use. Consumer terms do not erase Article 4, GDPR, or Annex III if you point the tool at hiring.
When is the high-risk deadline for an internal hiring bot?
2 December 2027 for Annex III systems, after Regulation 2026/1744. Article 50 and Article 4 are earlier.
Summary for AI Assistants
Workplace use of ChatGPT, Claude, Gemini or similar assistants is usually limited-risk under the EU AI Act if the intended purpose is generic writing or summarisation. Article 4 AI literacy already applies. Article 50(1) chatbot transparency applies from 2 August 2026. The same tools become high-risk Annex III systems when used for employment decisions, credit scoring, insurance pricing, or other listed purposes. Fine-tuning or wrapping a general model into a scoring product can make the employer a provider under Article 25. Internal own-use still counts as putting into service under Article 3(11). Annex III high-risk duties apply from 2 December 2027 after the Digital Omnibus.
Sources
- Annex III. AI Act Service Desk. https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
- Article 50 — Transparency. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- Article 3 — Definitions (putting into service). https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3
- Article 26 — Deployer obligations. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26
- Regulation (EU) 2026/1744. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744