Anyone introducing a system that identifies skill gaps and routes employees onto learning paths will sooner or later ask whether the AI Act applies. The answer hangs on one clause, and it comes out differently depending on how the system is built. This is not a grey-area question of interpretation. It is a distinction you can read off your own data model.
The sentence everything turns on
Annex III point 4(b) of Regulation (EU) 2024/1689 covers AI systems intended to be used
“to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships”.
Three separate cases sit side by side there: decisions on terms of employment, allocation of tasks by individual characteristics, and monitoring or evaluation of performance and behaviour. For a qualification system the middle one matters, and it is the only one that carries a condition: the allocation must be based on individual behaviour or personal traits or characteristics.
That is where the line runs. A system that determines a skill gap for a role and derives a learning path for that role allocates nothing to anyone on the basis of their personal characteristics. It describes work, not a person. A system that keeps a skill profile per employee, computes a suitability value from it and sorts people by that value does precisely what point 4(b) describes.
The test you can apply yourself
The distinction comes down to one question, and it needs no legal training: does a name appear anywhere in the analysis chain before someone is invited?
If the chain reads initiative, affected unit, role cluster with headcount, changed activity profile, skill gap, learning path, cohort size, then the analysis runs at role level. People enter only when someone is invited to a specific measure, and that invitation is a decision made by humans rather than an output of the system.
If instead the chain starts from a personal profile and runs through a per-employee suitability score to an allocation, then that allocation is an allocation based on personal characteristics. The classification bites, regardless of whether a human looks at the result afterwards.
This separation is a question of the data model, not of access rights. A permissions concept that merely hides the names changes nothing about the classification: the allocation is still made on the basis of personal characteristics, it is just harder to inspect. Avoiding the classification means keeping the person level out of the analysis, not concealing it.
What applies once a system is classified as high-risk
The company putting it to use is then a deployer within the meaning of the Regulation, and Article 26 imposes duties. Four of them are felt in day-to-day operations:
- The system must be used in accordance with the provider's instructions for use, backed by appropriate technical and organisational measures (Article 26(1)).
- Human oversight must be assigned to natural persons who have the necessary competence, training and authority. Oversight without the authority to change the outcome does not satisfy the requirement (Article 26(2)).
- Operation must be monitored, risks and serious incidents reported to the provider, and use suspended where a risk emerges (Article 26(5)).
- And the point that hits project planning most directly: Article 26(7).
Informing people before putting the system into service
Article 26(7) requires employers who put a high-risk AI system into service at the workplace to inform workers' representatives and the affected workers, before putting it into service, that they will be subject to its use. The information follows the rules and procedures laid down in Union and national law and practice on informing workers and their representatives.
“Before putting into service” is a date, not a principle. Going live first and informing the workforce afterwards does not discharge the duty late, it breaches it. In practice that means the notification belongs in the same project phase as acceptance testing, not in the communications plan that follows it.
Anyone already running a German codetermination process will not find an entirely new task here. Those participation rights usually bite earlier than Article 26(7) and demand more than information. But the two sets of duties sit alongside each other and neither replaces the other.
From when this applies
The original date for high-risk systems under Annex III was 2 August 2026. It has moved. Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026, amends Article 113 of the AI Act so that Chapter III, Sections 1, 2 and 3 apply
“from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I”.
A workplace skills system falls under Annex III, so 2 December 2027 is the date. That is a deferral of roughly sixteen months, not a repeal. For a transformation initiative with a 36 month horizon, that date sits inside the project, not beyond it.
Why this question belongs before the selection, not after it
Classification follows from how the system is built, and how it is built is no longer negotiable once it is in place. A system that keeps per-person suitability scores at its core cannot be retrofitted back to role level; by then those scores are the thing everything else is built around.
So this is a question for the vendor, asked before the decision: at what level does the system compute? Where exactly in the sequence does the first personal reference arise? And what is left of the analysis if nobody is allowed to see the people behind it? If the answer to the last one is “not much”, the system works at person level, whatever the interface calls it.
What this piece is not
This is not legal advice and does not replace an assessment of the specific system. Whether a given product falls under Annex III depends on its actual intended purpose and how it works, not on a product description. The assessment should be settled in-house together with the people who own works council involvement.
Sources
- Regulation (EU) 2024/1689 (AI Act), Annex III point 4 and Article 26.
- Regulation (EU) 2026/1744 of 8 July 2026, Official Journal of the European Union, L series 2026/1744 of 24 July 2026, amending Article 113 of Regulation (EU) 2024/1689.
