Humano — home

AI Agents in HR: What They Can Do Alone (and What the Law Doesn’t Allow)

A chatbot answers you. An AI agent, on top of that, can read your HR system, cross-reference data across your workforce, draft a notice and send it to 300 people without anyone reviewing it first. That difference —from «responding» to «acting»— is exactly what the law cares about. And it’s the one thing almost nobody checks before rolling out an agent.

At Humano (humano.io) we work every day with HR teams at companies with operational, distributed workforces: factories, warehouses, farms, retail floors. More and more of them ask us the same thing: «Can we put an AI agent in charge of scheduling, first-line payroll questions, or incident alerts?» The short answer is yes —on one condition: you design it knowing exactly which obligations it triggers.

Who is liable if something goes wrong

A common mistake: assuming that if the agent fails, the fault lies «with the AI» or with whoever built it. The company using the agent with its employees remains responsible for how it’s configured, what it’s used for, and which decisions it leaves in the agent’s hands; that responsibility isn’t transferred to the technology provider by contract, although the contract with them should spell out security and data-processing guarantees.

The law doesn’t look at the label, it looks at the function

Call it an «agent», an «assistant» or a «bot» —it makes no difference. Neither the GDPR nor the EU AI Act regulate based on what you name the system, but on three things: what it does (does it inform or execute?), what data it uses (personal? special category?), and what consequences it has (does it affect a right or a working condition?). The higher the reading on these three axes, the greater the legal risk.

Four levels of autonomy, four levels of scrutiny

  • Low: search, summarize or answer questions. It doesn’t decide or execute anything affecting a person.
  • Medium: prepare documents, update administrative records, or draft communications that a human reviews before sending.
  • High: recommend hires, evaluate employees, calculate incentives, or prioritize candidates. This is where GDPR Article 22 and, very likely, the AI Act’s «high-risk» category come into play.
  • Not authorized: disciplining, dismissing, or making any legally relevant decision without a human genuinely reviewing and deciding it.

What the law triggers, in short

An agent that touches employee data and decides on it can trigger, all at once: the right not to be subject to a fully automated decision (GDPR Article 22), the obligation to assess impact before deployment if there’s high risk, classification as a high-risk AI system if it’s involved in recruitment, evaluation or contract termination —with the obligation to inform workers and their representatives before it’s put into use—, and workers’ representatives’ right to know the parameters of any algorithm affecting working conditions (shifts, tasks, evaluation). The AI Act also generally prohibits recognizing employees’ emotions.

None of these obligations depend on calling your system an «agent»: they depend on what it does. Our complete guide breaks down each one, article by article, with more HR examples.

Making sure employees know they’re talking to an AI

If an employee writes to an agent believing they’re talking to a person in HR, that’s a transparency problem. European regulation requires informing people that they’re interacting with an AI system, unless it’s obvious from context, and explaining in plain language what it can do well (answer common questions) and what it can’t (make final decisions or replace a human manager in sensitive cases). It’s not just a legal requirement: it’s what stops someone from entrusting an important matter to a system that isn’t built to handle it.

The design principle we apply at Humano (humano.io)

The agent can search, explain, summarize, calculate and prepare drafts. It cannot autonomously adopt or execute decisions that produce relevant employment-related, financial or legal effects on a person. Those actions require review and explicit confirmation from an authorized user.

And here’s the point that actually matters: compliance isn’t solved with a disclaimer. Writing «AI can make mistakes» in fine print protects no one if, underneath, the system can write, send or decide without anyone stopping it in time. Responsibility isn’t delegated to a disclaimer: it’s built into the product, with:

  • Role-based permissions, so not everyone can grant the agent the same level of access.
  • Access to strictly necessary data for each task, not a person’s entire history.
  • Explicit confirmations before any action with a real effect on a person.
  • Reversible actions whenever possible.
  • Logs of what the agent saw, what it proposed, and who approved it.
  • Isolation between companies, so a failure in one account can’t affect another.
  • Effective human oversight: a person with the time, information and real authority —not an approve button clicked out of habit.

Examples applied to HR

  • An agent that summarizes time-tracking incidents for the shift manager to decide → low level.
  • An agent that drafts an internal notice that HR reviews and sends → medium level, perfectly manageable with real oversight.
  • An agent that prioritizes applications in a selection process based on CV data → high level: requires meaningful human oversight and advance notice to candidates.
  • An agent that decides and communicates to an employee that their contract won’t be renewed, without human review → not authorized.

The practical rule

Design the agent’s autonomy from the outside in: first define which decisions it must never make alone, then decide what can be automated without oversight. Not all AI applied to HR is «high-risk» by default —it depends on its purpose, its data and its real effects—, but when it is, the difference between a prepared company and an exposed one shows up in whether this principle can be verified, line by line, in the product they actually use.

Want to see how we apply this in shift scheduling, internal communication and HR processes? Talk to our team and we’ll walk you through real examples. And if you want the full regulatory detail —GDPR article by article, the AI Act, the Spanish Workers’ Statute—, read the complete guide.

This article is a practical, informational guide, not individualized legal advice. For your specific case, consult your legal advisor or compliance department.

¿Listo para dejar las hojas de cálculo?

Humano digitaliza fichajes, turnos, ausencias, documentos y comunicación para equipos sobre el terreno.

Solicita tu demo