Across Europe, AI used in hiring, promotion, workforce management and performance evaluation, is being formally classified as ‘high-risk’ under the recent EU AI Act. HR is now on the regulatory front line. This year, most of the core rules for those systems will begin to apply, with further obligations phasing in through 2027.
That label is supposed to be a safeguard, but inside many HR teams it often lands more like a warning: if something is ‘high-risk’, it is safer to keep your hands off it altogether. Faced with new regulation, loud debate and limited capacity, many business leaders are quietly concluding that the safest option is to delay, restrict or avoid AI in HR altogether.
In my view, that instinct, however understandable, is now one of the biggest risks HR faces. Over-caution does not freeze risk, it freezes progress. The real choice for HR leaders is no longer ‘AI or no AI’. It is what kind of AI they use, under what controls, and with whom in charge.
High risk doesn’t mean ‘don’t touch‘
The EU AI Act organises systems by risk. At the top are prohibited practices, such as emotion recognition in workplaces or social scoring, which are simply banned. Below that sit the ‘high-risk’ systems, including many HR and people management tools, where stricter rules apply. These include documentation, human oversight, transparency and robust data governance.
On paper, that is a familiar pattern. Medical devices, credit scoring and critical infrastructure controls are all treated as high-risk too. The message isn’t ‘never use them’, it’s ‘treat them as important, design them carefully, and put them under proper governance’.
In HR, though, ‘high-risk’ can sound scary. If something goes wrong in a recruitment algorithm or workforce-planning tool, it is not hard to imagine the headlines. That fear is pushing some organisations towards a defensive posture, to park AI projects, ban tools outright, and stay in the comfort zone of manual decisions.
The problem is that ‘going manual’ isn’t the same as ‘being safe’. It simply hides risk better. Spreadsheets do not come with model cards or audit logs, but they can still embed bias, errors and inconsistency.
In many ways, this moment mirrors the shift from paper records to spreadsheets. At the time, some organisations worried that digital tools would introduce new risks. In reality, spreadsheets improved accuracy, visibility and accountability. AI represents a similar shift today — the difference being that well-designed systems can now surface risks earlier rather than burying them inside manual processes.
According to HBHRʼs own research drawing on a survey of 2,000 UK employees, ongoing manual payroll errors are already having an immense impact on the workforce. Twenty percent of workers say a single payslip error has caused them to miss a bill, while 18% report having to borrow money because of payroll mistakes.
A well designed, well documented AI system with human oversight is not the opposite of compliance. Increasingly, it is exactly how compliance will be demonstrated.
The hidden cost of over-caution
When organisations freeze on AI, they push more strain onto already stretched HR teams juggling legacy systems and manual workarounds. Modern tools are simply an expectation, with HBHRʼs research demonstrating that 85% of employees expect their employers to use up-to-date technology to minimise mistakes, with 72% saying that the technology their employer uses directly correlates to the confidence they feel in their pay being accurate and on time. Outdated legacy tools not only contribute to a lack of trust among employees, but create extra work and pain for employers.
You see it most clearly in high-volume processes, where recruiters spend days sifting through CVs, whilst payroll teams are forced to manually reconcile inputs, hoping nothing has been mistyped along the way. At the same time, boardrooms are being told that AI is a once-in-a-generation opportunity, and that countries like the UK face a huge economic gap if they fail to develop the right skills and adopt the right tools. HR simply cannot sit that conversation out and still claim to be a strategic partner.
Over-caution creates its own risk: higher error rates in core people processes, slower responses to regulatory change, and HR teams so buried in admin that they have no capacity left for culture, capability or workforce planning. These errors and barriers are not without consequence – 61% of employees surveyed by HBHR would look for a new job after six months of repeated payroll errors and delays.
Moving beyond ‘AI vs humans‘
Public debate often frames AI as a direct threat to HR roles, as algorithms that replace recruiters and chatbots that replace HR advisers. This narrative is just not true. Most HR teams I meet are not short of work, rather theyʼre short of capacity. The opportunity is a symbiotic HR function, where each does what it is best at.
In practical terms, AI is very good at repetitive, pattern-recognition tasks at scale. It can scan thousands of CVs for clearly defined, job-relevant criteria and hand recruiters a shortlist that is actually manageable. It can monitor payroll and pension data for anomalies, payments that do not match any live employee, or contributions that look out of line with policy, and flag them long before they become front-page stories. It can power assistants, like our own HRGenie at HBHR, that answers routine questions about holiday, pay and policies on demand, instead of sending employees into ticket queues.
People, by contrast, are good at context, empathy and ethical judgement. They are the ones who should decide whether a flagged pattern is a genuine risk or a perfectly reasonable exception, whether a candidate is the right fit for a team, whether a performance signal points to misconduct, burnout or a problem with the role itself.
The most effective HR functions I see are not those that automate everything they can, nor those that reject automation outright. They are the ones that deliberately design people-led, AI-supported processes, with humans making the calls that actually affect jobs, pay and progression.
From admin to engine
Across organisations, three clear camps are emerging in the approach to AI: those that use it with clear intent by starting with real operational problems, those that experiment widely but lack a coherent strategy and those that reject it outright as too risky. The third, overly cautious group is already beginning to fall behind, not because they lack talent, but because they lack the tools to scale it.
Everyone talks about wanting ‘strategic HR’. But strategy requires headroom and trustworthy data. If HR leaders are still spending most of their week reconciling numbers between three systems, or chasing down the source of basic discrepancies, it is almost impossible to play that strategic role.
The combination of the EU AI Act and accelerating workplace change makes this an inflection point. HR can either retreat into manual, reactive processes in the name of caution, or step forward and shape a people-led, AI-enabled function that is more resilient, more compliant and more human than what came before.
That does not mean turning HR into a testing ground for experimental tools. It means getting the foundations right: unified HR and payroll systems rather than fragmented stacks of disconnected tools, clear governance for AI, and HR leaders who are confident asking hard questions about how technology works, not just what the sales slide promises.
Handled thoughtfully, AI will not replace the ‘people’ side of HR. If anything, it will finally give HR teams the time, visibility and capacity to focus on it properly.
In an era where regulations are tightening, skills are shifting and expectations are rising, an overly cautious approach to AI in HR is no longer the safest option. Standing still may ultimately prove far riskier than moving forward thoughtfully.
By Callum Pennington, CEO & Co-founder, HBHR
- Data & AI
- People & Culture