In this Global Insight episode of the On Aon podcast, Aon experts examine how the European Union's AI Act is reshaping leadership priorities for organizations — including workforce decisions. As AI is used more and more in hiring, talent assessment and workforce management, leaders will need to understand how these tools are governed, monitored and deployed. The discussion explores why accountability cannot be delegated, how organizations can strengthen oversight of third-party solutions and the actions HR leaders can take to build confidence, unlock value and stay ahead as AI adoption accelerates.
Key Takeaways:
Experts in this episode:
Key Moments:
(03:10) Understanding the EU AI Act, why it was introduced and why its influence may extend beyond Europe.
(08:35) Breaking down the Act's risk-based framework and what "high-risk" classification means for AI tools used in employment decisions.
(12:05) Why organizations cannot outsource accountability, and the importance of AI vendor due diligence, explainability and governance.
Soundbites:
Charlotte Schaller:
“If there's one message to leave HR leaders with, it's this: The EU AI Act is not just a compliance issue. It's a trust issue, a governance issue and ultimately a business performance issue.”
John McLaughlin:
“You can outsource the technology, but you cannot outsource the responsibility for it, how it affects your people.”
Michael Fetzer:
“A lot of companies are wondering where do we start? I've always recommended the great first step you might want to start with is carry out a thorough audit of your current HR AI use.”
Charlotte Schaller
If there's one message to leave HR leaders with, it's this: The EU AI Act is not just a compliance issue. It's a trust issue, a governance issue, and ultimately a business performance issue.
Intro:
Hello and welcome to the latest episode of On Aon. There’s no doubt that AI is transforming HR — but are employers ready for the risks? This week, Aon experts Charlotte Schaller, Michael Fetzer and John McLaughlin unpack what the European Union’s AI Act means for hiring, workforce decisions and accountability. They also explain the steps businesses can take to use AI responsibly to build trust and stay compliant.
Charlotte Schaller
Hello, and welcome to the latest Global Insight episode of the On Aon podcast. My name is Charlotte Schaller. I'm the Head of Talent Assessment at Aon. And today we'll be discussing the impact and implications of the European Union's AI Act, which began its compliance obligations in February 2025.
The Act is the region's regulation covering artificial intelligence, and will have a significant impact on businesses using AI — both in the EU and beyond.
So today we'll be focusing on what the Act means for the use of AI in HR processes. And I'm really pleased to have two great Aon experts with me to help discuss the main lessons and what businesses should be thinking about when it comes to the Act.
So with me today are John McLaughlin, CCO and Head of Assessment Talent Solutions, for EMEA here at Aon, and Mike Fetzer, our Global Director of Science and Product Development. Welcome both.
Michael Fetzer
Thanks, Charlotte. It's great to be here and I'm really looking forward to the discussion today.
John McLaughlin
Thank you for having us, Charlotte. Nothing quite like a podcast about compliance. To be fair, to be fair though, the impact of AI is quite staggering and is one hundred percent an area that should not be left to its own devices.
Charlotte Schaller
Oh that's an interesting starter point, John. So do want to elaborate on that for us?
John McLaughlin
I would love to Charlotte. If anything, we underestimate the capabilities of AI models today. And it doesn't matter as much if we're talking about an open AI or an Anthropic or even a Meta.
We have seen models escape and hack other companies' systems with ease. We see these stories come up in the news every other day. What they can do already is quite impressive and in certain cases actually quite scary.
Does that require us to put some rules into place to ensure they operate in a safe way? I would say absolutely it does.
So today is of course about the HR function and its use of AI. And in some ways, I would say we have leapfrogged to deploying AI at scale in HR and, in particular, in areas like talent acquisition.
Michael Fetzer
I would just add that it's worth noting that in our assessment practice where we're helping our clients make high-stakes talent decisions, we've always had the core principles of the EU AI Act at heart and really have essentially been operating in compliance with it before it was even conceptualized.
But Charlotte, we've been kind of hinting around at the regulation, but I'm conscious that we haven't explained just what that is. Perhaps you can give an overview for our audience?
Charlotte Schaller
Yeah, happy to. So what is the EU AI Act all about? John's touched on this already. The main purpose is to address risks surrounding AI.
It's similar to the EU GDPR in that it applies to any company operating in any EU country and any company offering AI services to the EU market, regardless of where it's based. The EU AI Act is the first comprehensive legal framework for AI introduced by a major jurisdiction.
So employers should expect the EU AI Act to be the starting point here.
It takes a risk-based approach to AI with different obligations for different levels of risk. So we'll dive into that a little later. And just like the GDPR, the penalties for not complying are high. So John, over to you. Could you outline a bit about the impact of the Act on Businesses HR function?
John McLaughlin
Maybe just to say your take on GDPR and its likeness to GDPR is quite interesting because that has just become part and parcel of how we operate today. Like it forms part of our general dealings with a whole range of organizations, pretty much every organization that we operate with or do business with.
So I can 100% see the parallels that you just alluded to, Charlotte. So I would fully agree with that.
Now that is not the question you asked me. Specifically on the EU AI Act, it touches on many aspects of AI, but it has very specific implications for HR, including where we use AI to support decisions around talent acquisition, performance management, and many more use cases across the employee life cycle. In short, if we deploy AI in any part of the talent life cycle, the EU AI Act.
I feel like we need an abbreviation for this... But yeah, if we deploy AI in any part of the talent life cycle, the EU AI Act will more than likely apply. Err on the side of caution would be my advice to our listeners. I think we all remember the Amazon example of building an AI algorithm that automatically scored applicants. I'm sure you remember, Mike.
Michael Fetzer
I sure do, and that's a great example, John.
John McLaughlin
Amazon built that algorithm to make hiring decisions at scale and at speed. It ended up prioritizing middle aged white men in application processes at scale and at speed.
It highlights the inherent risk in trusting algorithms, or AI models for that matter, the right decisions when left to their own devices or not being aligned to best practice design, validation and testing.
This, of course, is what the Act is all about, maturing our practices around the usage of AI and its responsible and ethical use.
More on that later, but it is worth noting that the Amazon risk without the right governance is likely just the tip of the iceberg.
The same goals for workforce management as a whole. In so many ways, AI offers us the opportunity to reshape how we make the most of our most important — and most expensive asset — our people.
Take this example. Nearly half of organizations in Aon's 2026 Human Capital Trends Study identify HR as a top area for AI deployment. In addition, acceleration of digital transformation of HR processes is ranked as the top people's strategic priority.
AI is not just on everyone's HR agenda, it's already embedded too, with roughly 59% of European enterprises having integrated AI into their HR processes. And all of that in the absence of specific and targeted regulation.
It will be interesting when we start to look properly under the hood of what and how we use AI across HR, and if we can truly stand over every single process we already have in place or that we are thinking about deploying over the next couple of months.
Of course, to be very fair to the companies out there already, a lot of organizations have stringent governance processes in place.
But maybe, Michael, now's a good time to go deeper into the obligations companies face under the Act. Over to you.
Michael Fetzer
Yep, thanks, John. The Act is it's really a framework with four levels of risk associated with AI. Starting at the highest level, they call that unacceptable risk. And then it goes down through high, limited and minimal risk. So really any AI system used to support employment assessment is explicitly classified as a high-risk application under the Act, covering the full employment lifecycle, not just specifically hiring.
So this means that HR teams are really required to review, document, and demonstrate that their tools can meet the strict demands of the Act.
As Charlotte mentioned, the consequences of inaction can be significant, not just with regards to substantial fines, but also reputational damages, loss of employee trust and even legal liability.
Charlotte Schaller
Thanks Mike and thanks John for that. What I took from that is that businesses and their HR functions can't afford to wait to act.
You can find a link to a guide on the Act in the show notes on this podcast, but in the time we have left, let's the three of us walk the listeners through what actions they should be thinking about when it comes to the AI Act.
Mike, would you like to kick things off?
Michael Fetzer
Sure. Thanks, Charlotte. And a lot of companies are wondering where do we start? I've always recommended the great first step you might want to start with is carry out a thorough audit of your current HR AI use.
So anywhere you're using AI within any sort of HR process, and really what you're trying to do here is define your exposure and potential obligations. So by this I mean you really need to kind of document every AI-driven system or tool that you use across the full talent lifecycle — again, not just for hiring — but from candidate sourcing and assessments to internal people analytics, productivity trackers, even reward decision making tools.
So, this should include informal and embedded AI use as well, not just officially procured HR platforms. Whether you've got recruiters, managers, vendors, they may already be using AI enabled tools in ways that your organization has not really fully mapped yet.
So as you're going through this process, be sure to record what each tool does, what kind of data it accesses, and especially what sort of decisions it informs or influences. The Act really requires this detailed level of awareness.
It places the onus on employers as AI deployers to understand the level of risk associated with their AI systems and really that category of risk that I mentioned earlier into which it may fall. So after you've done that, you need to evaluate each of your tools against the Act’s risk categories and especially determine which, if any, of those tools qualify as a high-risk AI system.
And this classification exercise should definitely be undertaken with your legal department or compliance experts or counsel. You really need their expertise and have that depth of knowledge as to how things are connecting up with the Act.
But by giving your risk classification to each of these tools, you'll really be able to identify which requirements apply and where your action is most urgent, depending on the risk level.
Now, high-risk systems will require significant controls and really, in many cases, a conformity assessment.
I can't emphasize enough this stage is vital if you want to identify your next steps.
John, you wanna take it from here?
John McLaughlin
Sure, Mike. As part of this process, it's essential that businesses strengthen their due diligence for AI vendors and new HR tools. I mentioned governance earlier. That is really what we're talking about here.
Under the Act, you can't simply rely on assurances of your vendors that they're compliant and that they're doing what needs to be done. You're responsible for how any AI is used in your organization. Are you clear on how the model you're deploying has been developed and what data it was trained on?
The simple test is can you explain it in your own words in a transparent fashion?
We are after the glass box model here, not the black box.
And explainability in this scenario is everything. Your providers, apart from being able to explain what they do verbally, are also required under the Act to supply detailed technical documentation. Ensure you obtain, review, and understand this documentation.
It sounds straightforward, but in our busy day-to-day work life, sometimes even that can be challenging. Worth noting as well, due diligence does not end at deployment.
Treat vendor relationships as ongoing partnerships.
You need to monitor for emerging risks and revisit compliance as the tool and your use evolve. Models today don't stand still. Like if you're thinking about like the latest ChatGPT model, it looks very different to what we've been using at the start of last year, right? Like the evolution of these models is staggering. The pace at which they get better and better is impressive.
And I would say we're only seeing like the evolution speed of these models tick up.
One last thing, prevent scope creep by ensuring that your HR AI tools are used only for the intended approved purpose. And this one is hard. We see something work very well over here. Why can't it work very well over there? Maybe with saying it 100% can, but it needs to go through its own due diligence process. And while that may sound like red tape, the potential of getting it wrong is so significant. We should be 100% prepared.
A tool introduced to support productivity can quickly undermine trust if its purpose, limits, and oversight are not clearly defined.
The key point for employers is that using a third-party tool does not remove accountability.
You can outsource the technology, but you cannot outsource the responsibility for it, how it affects your people.
Charlotte Schaller
Just picking up on what both of you have been saying, by adding that, it's vital that you put in place a governance structure that helps ensure your ongoing use of AI in your HR processes remain ethical, effective, and legally compliant.
Interesting, especially important as Aon's 2026 Human Capital Trends study found that only 28 % of organizations currently have fully operational AI guidelines with oversight mechanisms in place.
So it explicitly requires businesses to ensure that those working with AI systems are adequately trained. And so it doesn't mean that all HR teams need to be experts, but HR leaders, recruiters and managers do need enough AI literacy to ask the right questions, challenge the outputs and understand its limitations. And know when a human decision maker needs to step in.
HR teams and managers who rely on AI outputs must understand how those systems work, their limitations, and how to interpret their results.
A practical starting point is simple. Know where AI is already being used. Know what decisions it influences. Know who can explain it and who is accountable if something goes wrong.
We've covered a lot here. If there's one message to leave HR leaders with, it's this: The EU AI Act is not just a compliance issue. It's a trust issue, a governance issue, and ultimately a business performance issue.
My thanks to John and Mike for their great insight when it comes to the EU AI Act.
You can find out more about the Act by clicking on the link in the show notes and head to Aon.com to learn more about how we as a firm can help businesses shape how work gets done, how people are empowered to do the work and how performance is measured through skills and learning, job design and job architecture, metrics and incentives and governance and trust. So that's our show for today.
Thanks again for listening.
On Aon, we'll be back in the coming weeks with more expert insights into the latest Risk Capital, Human Capital, Industry and Global topics. Until next time.
Outro:
Thanks for tuning into the latest episode of On Aon. If you have enjoyed this episode, don’t forget to like, share and subscribe wherever you get your podcasts and be sure to visit Aon.com to learn more about Aon.
We’ll be back next week with another episode — our Risk Capital Insight — when we’ll be talking about the latest trends in the insurance market.