Skip to main content

Boardroom Answers · AI & Data · AI, Data & Analytics

Where does your platform sit under the EU AI Act — prohibited, high-risk, limited, minimal? And your talent modules touch employment, which is Annex III. Convince me.?

The question a Chief Artificial Intelligence Officer (CAIO) asks.

The short answer

Limited-risk decision support by design, with the four workforce modules explicitly flagged for counsel confirmation against Annex III — and a pre-built geo-gate that can switch them off for EU organisations with one flag.

The full executive answer

Our engineering classification, published as model cards inside the platform: nothing we do is in the prohibited category — no social scoring, no biometric inference, no manipulation. The core platform is limited-risk decision support: it produces advisory analysis that a named human remains accountable for, and it meets the transparency obligations by labelling AI output and showing provenance. Several purely analytical modules — benchmarking narratives, FinOps, vendor comparisons — we class as minimal risk.

Now the part you are right to push on. Annex III, paragraph 4 classes AI for employment and workforce management as high-risk. Four of our modules touch workforce topics — talent intelligence, skills intelligence, org design, and adoption-and-sentiment. Our engineering read is that they produce organisation-level advisory analysis — skills-gap patterns, aggregate sentiment — not decisions about individuals: no hiring, firing, evaluation or task allocation for a named person ever comes out of the platform. That distinction matters under Annex III. But here is the honest status: that read is an engineering assessment, explicitly flagged in our model cards as awaiting qualified counsel confirmation. It is not legal advice and I will not present it as settled.

Because it is not settled, we built the compensating control before launch: a geo-gate exists in the code that can block exactly those four workforce modules for EU-located organisations with a single configuration flag, pending the conformity assessment. Counsel decides the module list and when it flips. So the worst case is contained — if counsel says high-risk, EU customers lose four modules until conformity, not the platform. That is what taking the Act seriously looks like before a regulator makes you.

Grounded in: EU AI Act Annex III §4 (employment and workers management); EU AI Act Art. 50 transparency obligations (limited risk); ISO/IEC 42001 for the supporting management system.

Want this answered live, on your data?