Boardroom Answers · AI & Data · AI, Data & Analytics
Where does your platform sit under the EU AI Act — prohibited, high-risk, limited, minimal? And your talent modules touch employment, which is Annex III. Convince me.?
The question a Chief Artificial Intelligence Officer (CAIO) asks.
The short answer
Limited-risk decision support by design, with the four workforce modules explicitly flagged for counsel confirmation against Annex III — and a pre-built geo-gate that can switch them off for EU organisations with one flag.
The full executive answer
Our engineering classification, published as model cards inside the platform: nothing we do is in the prohibited category — no social scoring, no biometric inference, no manipulation. The core platform is limited-risk decision support: it produces advisory analysis that a named human remains accountable for, and it meets the transparency obligations by labelling AI output and showing provenance. Several purely analytical modules — benchmarking narratives, FinOps, vendor comparisons — we class as minimal risk.
Now the part you are right to push on. Annex III, paragraph 4 classes AI for employment and workforce management as high-risk. Four of our modules touch workforce topics — talent intelligence, skills intelligence, org design, and adoption-and-sentiment. Our engineering read is that they produce organisation-level advisory analysis — skills-gap patterns, aggregate sentiment — not decisions about individuals: no hiring, firing, evaluation or task allocation for a named person ever comes out of the platform. That distinction matters under Annex III. But here is the honest status: that read is an engineering assessment, explicitly flagged in our model cards as awaiting qualified counsel confirmation. It is not legal advice and I will not present it as settled.
Because it is not settled, we built the compensating control before launch: a geo-gate exists in the code that can block exactly those four workforce modules for EU-located organisations with a single configuration flag, pending the conformity assessment. Counsel decides the module list and when it flips. So the worst case is contained — if counsel says high-risk, EU customers lose four modules until conformity, not the platform. That is what taking the Act seriously looks like before a regulator makes you.
Grounded in: EU AI Act Annex III §4 (employment and workers management); EU AI Act Art. 50 transparency obligations (limited risk); ISO/IEC 42001 for the supporting management system.
The natural next questions
Related governed answers
- If a board acts on a hallucinated number from your platform and loses money, who is liable — and can you prove, after the fact, that the number was not invented?
- All defenses eventually miss. When the model IS wrong and a customer catches it, what is the correction loop — or does the mistake just sit there?
- Why should I trust this recommendation? Show me WHY the AI said that — can you actually explain a specific output, or is it a black box?
Want this answered live, on your data?