The EU AI Act has long been discussed as a piece of future regulation. By August 2026, however, the situation has changed. The EU AI Act has now been in force for two years, and a significant part of its obligations has already become applicable. The Act has also already been amended. Among other things, the AI Omnibus, which entered into force in July 2026, postponed the application dates of certain obligations concerning high-risk AI systems.
From a company perspective, the situation is twofold. Some obligations, such as the requirements concerning prohibited AI practices and transparency, already apply. By contrast, companies still have time to prepare for the most extensive obligations relating to high-risk AI systems. Nevertheless, companies should already map how they use AI, identify use cases that are specifically regulated, and ensure that their internal processes and contracts support compliance with the applicable requirements.
Which obligations under the AI Act already apply?
The first significant obligations under the AI Act became applicable in February 2025. These included, among other things, the provisions on prohibited AI practices. Obligations relating to AI literacy among personnel also began to apply. The AI literacy provision was eased in July 2026, but companies that provide or use AI systems are still required to take measures to support their personnel’s AI competence.
Since August 2025, providers of general-purpose AI models have been subject to specific obligations. This part of the regulation primarily concerns developers and providers of AI models. An ordinary company that, for example, purchases an AI tool available on the market or uses a ready-made third-party AI model as part of its own SaaS service will therefore generally not be directly subject to these obligations. The key is to identify the company’s own role in the AI value chain.
Another significant set of requirements became applicable at the beginning of August 2026: the AI Act’s transparency requirements. For example, in certain situations users must be informed that they are interacting with an AI system rather than a human. AI-generated or manipulated content is also subject to new requirements concerning its detectability and labelling.
When will the obligations concerning high-risk AI systems begin to apply?
One of the key areas covered by the AI Act concerns high-risk AI systems. These may include, for example, certain systems used in recruitment, employee evaluation, education, critical infrastructure or biometric identification.
However, the timetable for these systems has changed from the original schedule. The AI Omnibus, which entered into force in July 2026, postponed the application of the obligations concerning high-risk systems referred to in Annex III of the AI Act until 2 December 2027. For high-risk AI systems incorporated into regulated products, such as certain machinery and other physical products, the new deadline is 2 August 2028.
The additional time does not mean that companies should wait before starting preparations. Requirements imposed on providers of high-risk systems concern, among other things, risk management, documentation, data governance, logging, human oversight and conformity assessment. Deployers are also subject to obligations relating, for example, to following the instructions for use, ensuring human oversight, retaining logs in certain situations, monitoring the use of the system and reporting serious incidents. Companies should begin preparing these practical processes well in advance. Building processes afterwards is often significantly more difficult than taking the requirements into account already when developing a system or planning its deployment.
How should companies prepare for the AI Act in 2026?
A natural first step for every company is to determine where and how AI is being used within the organization. In many organizations, the use of AI has developed rapidly without any centralized overview. The marketing team may be using one tool, HR another, customer service may be testing an AI assistant, while at the same time a business unit is purchasing a new system with embedded AI functionality. From the perspective of the AI Act, these use cases may have very different implications.
In practice, one of the most common use cases encountered in companies relates to HR and recruitment. Particular care is needed here because AI used, for example, to assess or select job applicants or to evaluate employee performance may fall within the category of high-risk AI systems. A solution that appears to be an ordinary efficiency-enhancing HR tool may therefore create considerably broader obligations under the AI Act than the company initially expects. In addition to the requirements of the AI Act, other applicable legislation must naturally also be taken into account, including data protection and employment law requirements.
When mapping their use cases, companies should ensure that systems are used in accordance with their intended purpose. If a deployer makes a substantial modification to a system or changes its intended purpose so that the system becomes high-risk – for example, because it is unexpectedly repurposed for an HR use case – the deployer may be regarded as the provider of the system under the AI Act. An ordinary company using AI will generally not have the capabilities required to register the system, demonstrate conformity, maintain an extensive quality management system, or fulfill the other obligations of a high-risk system provider. These situations should therefore be identified and prevented in advance. Generally, for a high-risk use case, a company should procure a system that the provider has expressly intended for that purpose and appropriately registered as a high-risk AI system.
At this stage, companies should establish a sufficient overall understanding of the AI systems they currently use or plan to use, their intended purposes, and the company’s role in relation to each system. This mapping can be used to identify potentially prohibited use cases, transparency obligations and high-risk applications, as well as to ensure that contracts support regulatory compliance.
In contracts, particular attention should be paid to the availability of necessary documentation, permitted uses, the use of data, change management, and responsibility for regulatory changes and the related costs. Measures supporting personnel’s AI literacy, such as training and internal guidance, should also be proportionate to the identified use cases and their risk classifications.
The time for waiting is coming to an end
The AI Act continues to become applicable in stages, and companies do not need to resolve every issue at once. By August 2026, however, the regulation is no longer something waiting on the horizon: it is already part of today’s compliance requirements. The European Commission and national authorities have begun enforcing the applicable obligations, and the next major deadlines are already in sight.
Companies should therefore ensure now that their use of AI, internal processes and contractual arrangements provide a sufficiently solid foundation for both current and upcoming obligations.
We are happy to assist with questions relating to the application of the AI Act, the assessment and risk classification of AI system use cases, and contracts concerning AI.

Katri Aarnio
Counsel
+358 50 306 2031
To receive our articles directly in your inbox, subscribe to Folks’ newsletter here.
In business law, legal expertise is a basic requirement. But for the client, the quality of the collaboration becomes clear well before the final answer is delivered: does the lawyer take ownership of an issue that is still taking shape, ask the right questions, and make sure everyone knows what happens next after the discussion?
In our previous article, we looked at what companies expect from their legal partner in 2026. In this article, we focus on how our clients describe what it is actually like to work with Folks.
A total of 48 clients responded to Folks’ 2026 customer satisfaction survey. Of them, 43 said they were very satisfied with the collaboration and five said they were satisfied. In a separate recommendation question, our NPS score was 96. We are delighted with the numbers. But the open-ended responses tell us even more about what our clients believe makes for successful collaboration.
“It’s always easy to work with you. The help is fast, knowledgeable and easy to understand.”
The client shouldn’t have to manage the lawyer
Legal questions rarely arrive in a company as neatly defined assignments. A contract may already be under negotiation, an employment matter may require a quick decision, or the terms relating to the introduction of new technology may still be unclear.
The client should not need to formulate a fully developed legal question or know in advance what information is needed to resolve the matter. It is the lawyer’s job to take ownership of the situation: understand the objectives and facts, identify the relevant legal issues and help develop a solution that works in practice.
The client makes the business decisions. The lawyer’s role is to make the options, risks and consequences clear so that the client can make an informed decision.
The value of an approachable legal partner is that clients feel comfortable calling before a situation turns into a problem. A short conversation at the right time can save a significant amount of time, cost and unnecessary investigation later.
In addition to fast, clear answers and a strong understanding of the business, one respondent highlighted the fact that our pricing does not create a barrier to asking for advice. They also summed up the collaboration like this:
“And it’s always a pleasure to work with fun people.”
Different strengths, one shared goal
In the client feedback, Folks was not described simply as a single service. Respondents talked about individual lawyers, the way they work and what it feels like to work with them.
Working with Antti was described as professional, easy and warm, with particular praise for his quick responses and ability to avoid unnecessarily complicated legal jargon.
Feedback on Anna highlighted trust, efficiency, clear communication and a strong understanding of the client’s industry, even under tight deadlines.
Clients who had worked with Katri praised her thoroughness, responsiveness and friendly way of working, which they described as highly valuable to the client.
Kaisa’s particular strength was identifying the heart of the issue: her answers were clear and practical, and her work stayed focused on what mattered.
Those who had worked with Lila praised her knowledgeable and clear advice, as well as the ease with which she takes on questions and keeps matters moving forward.
The same theme came up repeatedly in our clients’ descriptions: the burden of managing the collaboration is not left to the client, and the client does not have to translate a legal answer into practical next steps themselves.
“You’re all absolutely brilliant. We can always reach you at short notice, and things move forward quickly.”
Good communication improves the quality of the work
A pleasant way of working together also improves the quality of the legal work. Difficult and unfinished matters are easier to deal with when there is trust in the relationship. Questions can be raised earlier, uncertainties do not need to be hidden, and the lawyer gains a better understanding of what genuinely matters to the client in the situation. When objectives, concerns and practical constraints are identified early enough, the lawyer can focus their work on what is truly relevant.
A trusted lawyer brings risks to the table and, when necessary, says clearly that a plan needs to change. What matters is that the client understands the reasoning behind the advice and knows what options are available.
Not every situation requires a lengthy legal memo. Sometimes the best legal service is a concise discussion that leaves the decision-makers knowing what to do next and which issues still require further clarification. One of our clients summed up their experience like this:
“The level of service and expertise is such that you never feel you’re paying for something unnecessary.”
The service should work regardless of which lawyer is handling the matter
Strong client feedback is not just a measure of success for us. It also creates an expectation that the service should work equally well regardless of which Folks lawyer is handling the matter.
That means sharing expertise, working smoothly together across the team and making sure that agreed actions, deadlines and client objectives are followed through. At the same time, every lawyer should be able to use their individual strengths and build a way of working with the client that feels natural and effective.
At its best, a lawyer is involved while decisions are still being prepared. Unfinished questions can be discussed early, and solutions can be found before the situation develops into a problem.
If your company is looking for an easily accessible legal partner to support day-to-day matters and decision-making, take a look at our outsourced legal department or our team. You can also get in touch even if you are not yet exactly sure what kind of legal support you need.
Updated: Aug 5
Imagine a situation in which AI screens hundreds of job applications in a matter of minutes and recommends the best candidates for interview, or optimises a complex shift schedule while taking into account the needs and preferences of thousands of employees. This is no longer distant wishful thinking, but a reality in many organisations. According to research, 52 per cent of Finnish organisations use AI solutions in HR tasks. Although adoption is still fragmented, the potential is enormous: AI can make recruitment, onboarding and offboarding processes more efficient, facilitate the allocation of shifts and tasks, support performance management and produce more advanced people analytics.
However, AI is only as capable as its users. Using intelligent tools effectively requires HR professionals and managers to be trained and to understand the applicable ground rules so that the benefits can be achieved responsibly and sustainably. At the same time, more is required from employers: the use of AI raises legal, ethical and practical questions that cannot be resolved merely by producing an AI strategy document. Legislation is imposing increasing obligations on the use of AI, most recently through the EU AI Act, which sets requirements for both providers and users of AI applications.
Introducing AI: needs, risks and employee participation
An employer must address several important issues before introducing an AI system into HR management. The first step is to identify the need for which AI is intended to be used and assess the associated risks. Employment and data protection legislation in particular require employers to assess in advance how new technology may affect employees. If, for example, an AI-based tool supporting recruitment is to be introduced, this concerns the very core of processing job applicants’ personal data. The employer must identify and justify why personal data is processed, how and to what extent it is used, and what changes the AI system may require in existing practices or in the information provided to applicants. Data protection legislation requires, among other things, an assessment of risks relating to personal data, including a data protection impact assessment where applicable, before new technology is introduced, regardless of whether the technology uses AI. In practice, the use of AI systems in HR almost automatically means that risks to employees’ privacy must be identified and the necessary safeguards determined in advance. Fully automated decision-making in recruitment, such as screening job applications without any human involvement in the final decision, is generally prohibited under data protection legislation. The recruiter must therefore always retain a meaningful role in the process.
Employers also have cooperation obligations when the organisation’s operations are developed by introducing new technology. Every organisation employing at least 20 people must engage in dialogue with its personnel to safeguard employees’ opportunities to influence matters affecting them. The introduction of AI-based solutions in HR is clearly such a matter and should be discussed with personnel well in advance. Employers with more than 50 employees are also subject to an express, simplified change negotiation obligation when introducing new technology. If AI is expected to reduce the need for labour or materially alter employees’ duties, more extensive change negotiations must be conducted with personnel before implementation. All these cooperation procedures must take place at the appropriate time, meaning before procurement decisions are made, in order to meet the requirements of the Act on Co-operation within Undertakings.
The Occupational Safety and Health Act also applies to the introduction of AI in the workplace. A central principle of the Act is that employers must identify work-related hazards and harmful factors and address them proactively. AI may introduce new dimensions to traditional occupational safety considerations: what kinds of risks and strain may arise from its introduction, and how should they be prevented? Learning to use new technology may, for example, place a psychological burden on employees, while concerns about their rights may cause stress when AI becomes involved in HR processes and managerial work. Employers must assess these risks as well and provide appropriate induction, support and measures to safeguard employee wellbeing during the change.
It is already widely recognised that the use of AI presents challenges for non-discrimination in working life. Under the Non-Discrimination Act, an employer may not treat employees or job applicants differently on discriminatory grounds such as age, gender or another personal characteristic. Because AI learns and draws conclusions from the data provided to it, it may absorb biases hidden in that data. A recruitment algorithm may, for instance, favour applicants on the basis of gender rather than merit. If most people recruited in the past have been of a particular gender, the AI system may interpret this as a “model of success”. Eliminating discriminatory bias from AI is difficult because algorithms are often opaque to users and their decision-making may be difficult to explain. On the basis of the current Government Programme, a research project has been launched in Finland’s public administration to identify and prevent discrimination risks associated with AI.
The EU AI Act will gradually tighten the requirements
The European Union has also entered the field of AI regulation. The EU AI Act entered into force in summer 2024 and introduces new requirements for the use of AI. Since February 2025, organisations have already been required to ensure that their personnel have an adequate level of AI literacy. AI literacy refers to employees’ ability to assess AI-generated outputs critically and to use AI responsibly and appropriately.
Further obligations will follow from August 2026, when the core risk-based requirements of the AI Act begin to apply. The Act distinguishes between four categories: prohibited AI practices, high-risk systems, limited-risk systems and minimal-risk systems. This will be a significant milestone for employers using AI, as many systems acquired to support HR processes are classified as high-risk AI systems under the Act. A high-risk classification also brings more extensive statutory obligations for the employer using the system. Compliance with the AI Act is reinforced by substantial administrative fines, which may amount to millions of euros depending on the size of the company.
Applications used to recognise employees’ emotions are prohibited where they analyse matters such as an employee’s intentions or job satisfaction. The use of biometric identifiers to categorise individuals on the basis of ethnic origin, political opinion, religion or sexual orientation is likewise prohibited. Social scoring based on personal characteristics is also prohibited where it results in detrimental treatment, such as restricting or preventing career progression. Subliminal manipulation and the exploitation of vulnerabilities are not permitted either.
In the terminology of the AI Act, an employer will typically be the deployer of a system where it acquires a ready-made AI solution for HR purposes. However, an organisation may modify a general-purpose AI system for its own purposes, in which case the employer may become a provider under the Act. The distinction between the roles of deployer and provider is important: providers are subject to significantly broader legal obligations, including continuous quality assurance, technical documentation, system certification and detailed regulatory reporting, compared with a deployer. Employers should therefore generally prefer ready-made applications designed for HR use and use them strictly in accordance with the provider’s instructions and intended purpose.
Higher risks and greater responsibilities
What types of AI use are considered high-risk in an HR context? Automated decision-making and profiling based on personal characteristics are always high-risk. Under the AI Act, high-risk systems include those that affect access to employment, employment terms, career progression or decisions concerning performance at work. Examples include AI systems used in recruitment, decisions concerning employment conditions and career development, or the termination of employment. The same category includes systems that allocate work tasks on the basis of a person’s behaviour, personality or other personal characteristics, as well as systems used to monitor and assess employee performance during employment. These are all situations in which AI directly affects individuals and their treatment in working life. They are precisely the kinds of sensitive situations in which risks must be identified.
The dividing line is not always entirely clear. Some of the uses described above may be considered low-risk if they do not cause significant harm or pose risks to employees’ health, safety or fundamental rights and do not materially influence decisions concerning them. For example, a system that screens job applications and recommends the most suitable candidates to a recruiter would clearly appear to be a high-risk application. By contrast, an AI tool that merely classifies and transfers applications between systems without influencing whether applicants progress in the recruitment process, or that identifies anomalies in decision-making without intervening in the decision itself, would fall into the minimal-risk category. Interactive AI tools, such as virtual assistants used in HR matters, fall into the limited-risk category. In such cases, the employer must inform users that they are interacting with AI.
When an employer introduces a high-risk AI system, the AI Act requires it to fulfil several obligations. First, it must ensure that the system is used appropriately and in accordance with its instructions and intended purpose. Second, the organisation must appoint a responsible person or team to oversee the system’s operation. Those responsible for oversight must have sufficient competence, training, authority and resources to perform the task. The employer must also pay particular attention to data governance and ensure that the data entered by the organisation is relevant to the intended purpose and sufficiently representative so that the system does not produce misleading results. In addition, the user organisation must respond to risks arising during use and report any errors or biased decision-making to the system provider and the competent authority where required, and cooperate with supervisory authorities where necessary.
Transparency is another key element of the Act: employees must be informed when an AI system is introduced, and where they are subject to AI-based decisions, they have the right to receive an explanation of a decision affecting them. Last but not least, the employer must retain the AI system’s automatically generated logs for at least six months where those logs are under its control. The logs may contain information on how the system reached particular outputs or decisions. Retaining and tracing this information is essential when investigating possible disputes at a later stage.
As noted above, existing legislation already requires employers to follow similar principles in many respects. Employees may, for example, be informed appropriately through cooperation procedures, while data protection legislation already requires personal data to be processed appropriately. The EU AI Act nevertheless adds new and concrete AI-specific obligations: when using high-risk AI systems, organisations must, among other things, retain logs and ensure continuous and adequate human oversight throughout the system’s lifecycle.
Users and data at the heart of an AI strategy
Although legislation provides the framework for responsible AI use, its ultimate success depends on people. A company may create an ambitious AI strategy, but if employees lack the ability, willingness or confidence to use the system, the expected benefits may not be realised. User trust is crucial, and in decisions affecting personnel it is critical. Research indicates that concerns about employees’ rights or the purpose for which a system is used directly affect whether employees accept AI as part of their everyday work. Trust is similarly weakened by concerns that employees’ ability to influence matters may be reduced and by doubts regarding the system’s actual capabilities.
Employers should therefore invest in introducing AI as openly and transparently as possible and in providing comprehensive information to personnel. Integrating AI into HR functions is always a process of change that requires traditional change management and learning. New technology may initially place a burden on both its users and those affected by its decisions, depending on the individual’s role and readiness. Management should therefore listen to employees, provide the necessary support and, above all, communicate clearly about the change. Subsequent disagreements and potential legal proceedings are also best prevented by investing in competence and AI literacy.
Usability is central to a successful AI investment. A phenomenon known as “shadow AI” has emerged: where employer-provided tools are perceived as difficult or inefficient, employees may begin to use external AI solutions instead of the organisation’s approved tools. This may cause the benefits of the investment to be lost while creating concrete data protection and cybersecurity risks as data is processed through uncontrolled channels. In addition to ensuring adequate AI literacy, organisations must therefore provide proper user training so that everyone knows how to use the new systems. Clear internal guidance is also needed on how external AI tools, such as general-purpose chatbots and other services, may be used at work. This helps protect personal data, trade secrets and other confidential information.
A central principle of the AI era is that an AI system is only as reliable as the data it uses. In addition to considering big data, organisations must pay close attention to their own HR data. If the data is incomplete or inaccurate, the AI system will inevitably draw incorrect or imprecise conclusions. At worst, an employer may unintentionally discriminate against an employee or job applicant where historical data contains structural bias. The EU AI Act therefore expressly requires the quality and reliability of data to be ensured in high-risk HR systems. In practice, this means that HR data must be collected, updated and cleaned continuously so that AI-based decisions are based on information that is as representative, accurate and relevant as possible. This is not an entirely new principle, as Finnish employers have for more than twenty years been required under the Act on the Protection of Privacy in Working Life to process only employee data that is necessary for the employment relationship.
Conclusion
The enormous potential of AI will undoubtedly be used more extensively to support HR functions in the coming years. Although its use is not free from legal or ethical challenges, AI can at its best make work more meaningful and HR and managerial processes more equal, personalised and efficient. However, AI must be introduced and used systematically so that organisations can realise its full potential while safeguarding employees’ rights. Ultimately, people remain at the heart of all of this: the users who turn strategy into reality in their daily work. Organisations that genuinely invest in their personnel’s technical and ethical competence, as well as in user-friendly tools, will be well positioned in the age of AI.

Kaisa Salo
Counsel
+35840 168 1418
To receive our articles directly by email, subscribe to the Folks newsletter here.
