Article 26(7) of the EU AI Act (Regulation (EU) 2024/1689) requires employer-deployers of high-risk AI systems to inform workers’ representatives and the affected workers that they will be subject to the system, before it’s put into service or used at the workplace. That information is provided, where applicable, in accordance with the rules, procedures and practice on informing workers and their representatives laid down in Union and national law. One short clause routes the AI Act straight into works council law — and the procedure, the timing, and the leverage workers actually have are all determined nationally from there, not by the Act itself.
What the duty actually is
Read literally, the Act’s own text requires informing, not consulting. But that duty is expressly channelled through whatever national information rules and practice already exist — and in several Member States, those rules go further and require actual consultation before a workplace change like this. This distinction decides your real timeline: if you’re only reading Article 26(7) itself, you might plan for a notice sent shortly before go-live; if your national regime channels this into an existing consultation obligation, you’re planning for a process with its own lead time, and possibly its own points where workers’ representatives can push back before you’re clear to proceed.
Who has to be told
Both workers’ representatives and the affected workers themselves — not one or the other. “Affected workers” is a broader category than “users of the system.” A worker who is monitored, evaluated, or has decisions made about them by a high-risk system is affected by it whether or not they ever personally interact with its interface. Scoping this notice to the people who log into the tool, rather than everyone the tool is actually applied to, undercounts who the Act means to protect.
When
Before the system is put into service or used. For a phased rollout, that points toward informing each new population as it’s actually brought into the system’s scope, rather than a single blanket notice issued at the start that tries to cover populations not yet affected. A pilot counts — running a smaller-scale version of the system is still putting it into service or using it, and doesn’t get treated as exempt just because it’s temporary or limited. A vendor upgrade that changes what the system actually does to workers — new monitoring capability, a different basis for evaluation — is a fresh trigger in its own right; the original notice covered the original system, not whatever it becomes afterward.
The Article 2(11) fragmentation problem
Article 2(11) states plainly that the Regulation doesn’t prevent the Union or Member States from maintaining or introducing legislative or administrative provisions more favourable to workers regarding the protection of their rights in relation to employers’ use of AI systems, or from encouraging or allowing more favourable collective agreements. The AI Act sets the floor; national law and collective bargaining set the ceiling, and the ceiling varies. A rollout across the EU doesn’t have one answer to “what do we owe workers here” — it potentially has as many answers as there are Member States involved, and collective agreements can raise the bar further still in any one of them. Rather than attempting to summarise 27 different national positions here, the honest move is to point at the national implementation trackers directly and check the specific markets a rollout actually touches.
What else the employer-deployer owes
Article 26(7) doesn’t sit alone. The same Article requires using the system in accordance with its instructions for use, and assigning human oversight specifically to natural persons who have the necessary competence, training and authority, and who receive the necessary support to exercise it — not oversight assigned on paper to someone without the standing or resources to actually do it. Where the deployer controls the input data, that data has to be relevant and sufficiently representative for the system’s intended purpose. And deployers monitor the system’s operation against its instructions for use, retaining the automatically generated logs, to the extent under their control, for a period appropriate to the system’s purpose and at least six months, unless other Union or national law requires longer.
Separate from all of this, Article 4 AI literacy applies regardless of risk tier — it isn’t limited to high-risk deployments — and it explicitly reaches staff and other persons operating or using AI systems on the deployer’s behalf, not employees alone. A contractor or an external service provider running your systems for you falls inside this duty too.
A practical sequence
Inventory what AI systems are actually deployed at the workplace and where. Classify which are high-risk. Identify the affected population properly, beyond just the direct users. Map the specific national information and consultation route for each country involved, since this isn’t one process repeated identically everywhere. Brief workers’ representatives through that route. Document the date this happened, since it’s the fact you’ll need to point to later. Only then go live.
Frequently asked questions
Is a works council agreement required before we can proceed?
Not under the AI Act’s own text, which only requires informing. Whether a formal agreement, or consultation with a real chance to object, is required depends entirely on whether your national information and consultation regime already demands that for a change like this — in jurisdictions with strong co-determination rights, it very well might be.
Does this apply to a tool we already use?
The duty attaches to putting the system into service or using it — a tool already in continuous use presumably triggered it at that original point. A material change to what the tool does, or who it’s applied to, is a fresh trigger in its own right, even for a system that’s been running for years.
What if the system isn’t high-risk?
Article 26(7) specifically is a high-risk deployer obligation, so it doesn’t apply on its own terms to a non-high-risk system. Article 4 AI literacy still applies regardless of risk tier, and separate national employment or data protection law may independently require informing workers about workplace monitoring tools whether or not the AI Act’s own high-risk trigger is met.
Can workers object once informed?
The Act’s own text gives an information right, not an explicit objection right. Whether workers or their representatives have real leverage to push back depends on the national regime Article 26(7) channels this through — some Member States’ consultation frameworks give workers’ representatives genuine influence over the outcome; others may limit the right to notice itself.
What’s the penalty for skipping it?
Article 26 obligations, including this one, sit in the same fine tier as the rest of the Act’s high-risk operator duties: up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, with the lower of the two figures applying to SMEs and start-ups instead.
