Workplace AI law · AI Act · GDPR · CSE · DUERP

AI at work: what obligations for the employer?

Deploying artificial intelligence in an organisation is not a matter of a single text. Depending on the use, the data processed and the effects of the system on employees, several frameworks can be combined: AI Act, GDPR, Labour Code, social dialogue and prevention of occupational risks.

Governing AI based on what it really changes. The starting point is not the name of the tool. The obligations depend on the transformed task, the people involved, the data used and the possible consequences of the system’s output.

Dated official sourcesFour separate frameworksNo automatic green light

Direct answer

In brief

In France, the deployment of artificial intelligence at work does not fall within a single framework. The employer must examine the use with regard to the European regulation on artificial intelligence (AI Act), the General Data Protection Regulation (GDPR), the Labour Code and its obligation to prevent occupational risks. Depending on the system and its effects, this may in particular involve information or consultation of the Social and Economic Committee (CSE), a data protection impact analysis (DPIA), an update of the Single Occupational Risk Assessment Document (DUERP), human supervision and documented monitoring. Compliance with one framework does not constitute compliance with others.

01 / AI ACT

Qualify the system and its level of risk.

Usage, role of the organisation, prohibitions, transparency, high risk, supervision and monitoring.

Use not classified as “high risk” may nevertheless raise other issues.

02 / GDPR

Govern personal data.

Purpose, legal basis, minimisation, rights, processors and possible DPIA.

The DPIA depends on the characteristics of the processing and the level of risk.

03 / LABOUR CODE

Examine what the project changes.

Employment, organisation, recruitment, working conditions, control and social dialogue.

Information or consultation of the CSE depends on the context and the effects.

04 / PREVENTION

Evaluate the effects on real work.

Workload, autonomy, monitoring, responsibilities, skills, teams and risks.

The DUERP is updated in the situations provided for by the applicable framework.

To remember. The obligations do not depend on the brand of the software, but on the function performed by the system, the data processed and its actual influence on the work or decisions.

01 / Determine the applicable rules

How to qualify an AI used at work?

01

What task is AI transforming?

Write, summarize, recommend, classify, recruit, assign a task, monitor or contribute to a decision.

02

Which people are concerned?

Candidates, employees, managers, professionals or users — directly or via a score, an alert or a recommendation.

03

What data is used?

Nature of the data, purpose, location, recipients, retention period, reuse and subcontractors.

04

What influence does AI have on the decision?

Simple reviewable draft, order of priority, score, control of activity or result likely to produce a significant effect.

05

How can a human regain control?

Skill, time and authority to control, challenge, correct, suspend use and return to a fallback.

02 / Examine the frameworks

What legal frameworks govern AI at work?

A single project may fall under several sets of rules. Examining them separately allows you to identify the obligations, those responsible and the relevant official sources.

An AI at work project can simultaneously fall under the AI Act, the GDPR, the Labour Code and the obligation to prevent occupational risks.

01
Applicable with deferred deadlines

AI Act: qualify the system, the role and the applicable date

Regulation (EU) 2024/1689, modified by the AI Omnibus, distinguishes in particular prohibited practices, transparency obligations and high-risk AI systems.

Starting questionsIs the organisation a provider or deployer, and does the use relate to the employment or management of workers?
  • the transparency obligations of Article 50 have applied since 2 August 2026 for the systems concerned;
  • the rules of Annex III relating to high-risk systems, in particular certain employment practices, apply from December 2, 2027;
  • for an employer deploying a high risk system, article 26 provides in particular for the prior information of the representatives of the workers and the workers concerned, according to the applicable framework.

A system which is not classified "high risk" may nevertheless fall under the GDPR, the Labour Code and the obligation of prevention.

Read the consolidated text ↗
02
In force

GDPR and CNIL: regulating personal data

The General Data Protection Regulation (GDPR) applies when the processing of personal data falls within its scope.

Starting questionsWhat data enters the system, for what purpose and with what effect on a person?
  • where is it sent and how long is it kept?
  • who accesses it and which processors are involved?
  • are they involved in a decision concerning an individual?

The need for a data protection impact assessment (DPIA) depends on the risks of the processing; using AI does not automatically require one.

DPIA method of the CNIL ↗
03
In force

Labour Code and CSE: examine the effects of the project

The Social and Economic Committee (CSE) must be able to understand the possible consequences of the project on employment, organisation, working conditions, recruitment or control of activity.

Starting questionDoes the project fall into a case of information or consultation provided for by the applicable framework?

The answer depends in particular on the workforce, the nature of the system, the importance of the project and its effects. The information must be transmitted early enough so that the dialogue can still influence the project.

Article L. 2312-8 ↗
04
In force

DUERP and prevention: assessing occupational risks

The Single Occupational Risk Assessment Document (DUERP) records the results of the employer’s risk assessment.

Starting questionDoes the project modify the workload, intensity, autonomy, supervision, responsibilities, skills or collectives?

The analysis must focus on the work actually organized, including cognitive load, value conflicts, social relationships and psychological safety. The DUERP is updated in the situations provided for by the applicable framework.

Evaluate the effects of an AI project on work and psychosocial risks.

Article L. 4121-3 ↗
Central principle

Compliance with the GDPR does not constitute compliance with the AI Act; the application of the AI Act does not exempt either from social dialogue or from the obligation to prevent occupational risks.

03 / Read by use case

Do the obligations change according to the use of AI?

Yes. A writing assistant, a recruiting tool, and a performance monitoring system do not raise the same questions.

The obligations do not depend on the brand of the software but on the function performed by the system. The matrix guides the analysis without replacing the qualification of the project.

Intended use Questions to consider first Effects on the work to be documented First deliverable
01Research, synthesis and rewriting
General support
Confidentiality, data submitted, source reliability and transparency. Check time, plausible errors, productivity expectations and fallback solution. Usage note, input rules and human verification protocol.
02Recruitment, pre-selection and mobility
Employment · sensitive use
AI Act, bias, non-discrimination, data, the actual human role and informing candidates. Invisible criteria, review workload, ability to challenge and liability. AI Act qualification, data mapping, impact analysis and social-dialogue dossier.
03Task planning and allocation
Work management
Influence on access to tasks, schedules, evaluation and decisions. Autonomy, intensification, fairness, workarounds and decision margins. Before/after mapping, challenge procedures and pilot protocol.
04Activity and performance monitoring
Surveillance
Purpose, necessity, proportionality, prior information, access and consequences. Feeling of surveillance, unrealistic goals, behaviours and psychosocial risks. Proportionality test, DPIA if necessary, social dialogue and prevention.
05Health, medical fitness or medical data
Specialized analysis
Health data, professional secrecy, security, separation of roles and sectoral framework. Clinical liability, trust, errors, time pressure and continuity. Legal, clinical, technical and organisational analysis before any pilot.

Limit. Certain uses related to employment and worker management are among the sensitive areas of the AI Act, but the qualification depends on the precise function of the system and the applicable rules and exceptions.

04 / Distribute responsibilities

Who should participate in the governance of an AI project?

Management, HR, the CSE, the DPO, prevention teams, professional groups, purchasing and security each contribute different evidence to the same decision file.

This pathway indicates a starting point. Stakeholders then compare their analyses before a decision is made.

01Employer or project management

Start from the need for work, not from an already chosen tool.

Describe the problem, the alternatives, the expected result and the person who will make the decision to launch, modify or stop the pilot.

  • Name the project manager
  • Define the stopping criteria
  • Require a shared file to the professions
02Human resources / HRD

Describe what is changing for each population.

Identify the displaced tasks, the criteria likely to influence an HR decision and the skills necessary to verify or challenge.

  • Map the work before/after
  • Document HR criteria
  • Prepare information and training
03CSE or staff representative

Ask for the elements that still allow you to influence.

Examine the need, the alternatives, the people concerned, the power of the system, the data, the objectives and the follow-up of the pilot.

  • Clarify the exact use
  • Ask for the effects on work
  • Set a return date
04Lawyer / DPO

Link each data to a purpose and a decision.

Map the data, qualify the role of the organisation, check rights and determine what impact analyses are necessary.

  • Trace flows and subcontractors
  • Qualify AI Act and GDPR
  • Write guarantees and remedies
05SPSTI / prevention / health at work

Observe the transformation of real work.

Examine load, autonomy, conflicts of values, surveillance, skills and collectives, then propose prevention measures.

  • Analyse concrete situations
  • Identify exposed groups
  • Propose monitoring indicators
06Purchasing / information systems security

Obtain the information before signing.

Check the intended uses, limits, data, subcontracting, incident management and the real possibility of leaving the solution.

  • Require documentation
  • Frame data and incidents
  • Plan for reversibility

05 / Decide

How to decide if an AI can be deployed?

Useful governance designates responsibilities, disagreements, avenues of appeal and the authority capable of suspending use.

Project managementDescribes the need, the scope and takes responsibility for the decision.
Lawyer & DPOQualify the frameworks, processing operations and rights.
CSEExamine the consequences on employment and work.
SPSTI & preventionClarify the effects on activity and health.
Professionals & managementTest actual use, errors and workarounds.
Purchasing & securityDocument the supplier, access and reversibility.

06 / Social dialogue

When and how to organize dialogue with the CSE?

The timing and content of the dialogue depend on the applicable framework. A supplier demonstration is not enough to describe future work.

When the project enters a case of information or consultation, the CSE must receive sufficiently precise elements and early enough to understand the effects and formulate a useful opinion.

Before the decision

Give input on the project.

  • needs, uses and alternatives
  • populations and tasks concerned
  • data and supplier documentation
  • expected transformation of the organisation
During the pilot

Document trade-offs.

  • human intervention rules
  • verification burden and objectives
  • incidents, errors and workarounds
  • conditions for immediate suspension
After the pilot

Come back with facts.

  • gaps between planned and actual work
  • effects on health, autonomy and skills
  • corrections implemented
  • reasoned decision to continue or stop

07 / Prepare a pilot

What documents should you prepare before a pilot?

These eight documents make the project open to discussion, traceable and reversible. Checking them does not constitute certification or evidence of compliance.

08 / Quick Answers

Frequently asked questions about AI at work

What rules govern artificial intelligence at work in France?

An artificial intelligence project at work may simultaneously fall under the European regulation on artificial intelligence, the GDPR, the Labour Code and the obligation to prevent occupational risks. The applicable rules depend on the actual use, the data processed, the people concerned and the effects of the system.

Should a company consult the CSE before deploying AI?

This depends in particular on the workforce, the nature of the project and its consequences on employment, organisation, working conditions or control of the activity. When the applicable framework provides for information or consultation of the CSE, this must take place early enough so that the opinion can still influence the project.

When is an AI used at work considered “high risk”?

Certain uses linked to employment and management of workers appear in Annex III of the AI Act. Qualification depends on the precise function of the system as well as the conditions and exceptions of the regulation. After the AI Omnibus, the corresponding rules apply from December 2, 2027; this does not suspend other obligations already applicable, in particular in terms of data, social dialogue and prevention.

Does the GDPR apply to AI used by the employer?

The GDPR applies when the processing of personal data falls within its scope. The use of AI does not deviate from any of the usual obligations relating to the purpose, legal basis, minimisation, security, information and rights of individuals.

Should an AI project be included in the DUERP?

Risk assessment must take into account work transformations likely to affect health or security. The DUERP must be updated in the situations provided for by the applicable framework; the mere presence of an AI therefore does not automatically trigger an update.

Can AI be used to recruit or assess employees?

These uses are particularly sensitive and may simultaneously fall under the AI Act, the GDPR, labour law, non-discrimination, social dialogue and prevention. They require precise qualification, effective human supervision and avenues for challenge.

Who is responsible when a decision is assisted by AI?

Using a system does not automatically transfer responsibility to the provider or model. The organisation must define the roles, human validation, avenues for contestation, termination conditions and the person who makes the final decision.

09 / Sources and updates

Official texts linked to the claims they support.

AI law is evolving. The links below allow you to compare each qualification with the text in force and the precise context of the organisation.

01
EUR-LexConsolidated version of the regulation after the AI Omnibus.
Read the text ↗
02
European CommissionRegulatory framework and official timetable for the AI Act.
Consult ↗
03
European CommissionAI Omnibus: entry into force and new deadlines.
Consult ↗
04
European CommissionTransparency obligations under Article 50.
Consult ↗
05
CNILDetermine whether a data protection impact assessment is necessary.
Consult ↗
06
Labour CodeArticle L. 2312-8 on the responsibilities of the CSE.
Légifrance ↗
07
Labour CodeArticle L. 2312-38 on recruitment, automated management and control.
Légifrance ↗
08
Labour CodeArticle L. 4121-3 on the assessment of occupational risks.
Légifrance ↗

Written by Dr Charles Broutin — occupational physician, AI lead of the French Society of Occupational Health (SFST).

For an example of a limited and evaluated use, see artificial intelligence in Inter-company Prevention and Occupational Health Services.

To place the law in a broader pathway, return to the AI & Occupational Health pathway.