Regulation

How EU AI Rules Change Employers' Duties in Hungary

Hungary applies the EU AI Act definitions via the 2025 LXXV.

One of 2025’s major consequences was the widespread adoption of artificial intelligence (AI) systems. Hungary adopts the legal framework of the European Union’s 2024/1689 regulation (the "AI Act" or "Regulation"): the 2025 Act LXXV states that domestic rules apply the AI Act terminology.

Definition and personal scope under the AI Act

According to Article 3(1) of the AI Act, an AI system is a machine‑based system designed to operate with varying levels of autonomy and to be adaptive after deployment, which infers from its inputs how to generate outputs—such as predictions, content, recommendations or decisions—that may affect physical or virtual environments.

The Regulation applies to providers, distributors and importers of AI systems and also imposes significant obligations on organisations that deploy such systems. An "user" (applicator) is any natural or legal person, public authority, agency or other body using an AI system under its control, except for personal non‑professional use. Therefore employers who deploy AI systems in a professional or organisational context fall within the Regulation’s scope and bear responsibilities for lawful and informed use, human oversight depending on risk classification, and in some instances risk management.

In practice, an employer is considered an applicator if it enables or requires employees to use chatbots, image‑processing systems (e.g. AI cameras), document‑analysis tools, predictive models, or AI decision‑support systems in fulfilment of work tasks under the employer’s supervision.

If an AI system is used outside a professional context (for example, an employee asks a publicly available AI system an unrelated question), the Regulation’s additional requirements do not apply to that employer.

Labour law perspective: AI as a work tool

From an employment law perspective an AI system is a work tool used by employees to perform their duties. The Hungarian Labour Code (2012 Act I, "Mt.") does not set detailed rules for AI tools, but Mt. 52 § (1) c) requires employees to perform their work personally, with generally expected professional skill and care, following applicable rules and instructions.

Under Mt. 11/A §, AI systems qualify as technological tools, so the obligations and restrictions in that provision govern their use.

Employers must therefore incorporate the Regulation’s requirements into their professional rules, instructions and internal policies so employees can use these specific work tools in compliance with the law.

Key dates and phased obligations

  • 1 August 2024: AI Act entered into force.\
  • 2 February 2025: certain obligations became mandatory, notably ensuring AI literacy and rules on prohibited AI uses (e.g. systems inferring emotions).\
  • 2 August 2026: the full compliance deadline by which employers must implement all obligations applicable to users, including special duties where employees use high‑risk systems.

The Regulation’s requirements depend heavily on a system’s risk classification. Many systems used in employment contexts may qualify as high‑risk, which triggers additional obligations. Examples of high‑risk systems include candidate‑screening and resume‑analysis systems, AI‑based performance evaluation and employee monitoring tools, and systems supporting hiring, promotion, task allocation or changes to employment conditions.

General obligations: AI literacy and internal rules

All employers who are users must ensure appropriate, organisation‑tailored AI literacy. Employees need to understand how the AI tools they use operate and their risks. Employers may satisfy this obligation via policies, written instructions, training sessions, e‑learning, or combinations thereof. It is important that AI literacy be demonstrably documented for legal compliance.

Clear internal rules reduce the risk of "Shadow AI"—unsanctioned use of AI tools by employees—which can lead to leaks of confidential information or intellectual property if uncontrolled tools are used.

Internal rules should address at least the following points:

  • Whether and under what conditions employees may use publicly available AI tools, and what types of data may be uploaded;\
  • What constitutes prohibited content (the Regulation prohibits data that could activate banned AI practices, such as biometric or emotion‑related data), with the employer free to extend the prohibited list (e.g. recordings of colleagues, technical process descriptions);\
  • Restrictions on processing employees’ personal data consistent with the Regulation and GDPR;\
  • Rules on personal vs. professional use of AI tools and how the two are separated, given employers’ limited entitlement to monitor employees’ private use;\
  • The requirement that AI‑generated outputs be checked, interpreted and validated by the employee before use to avoid over‑reliance;\
  • That most AI interactions, including inputs and outputs, are logged and that logged data may be reviewed by the employer within legal limits and respecting privacy principles.

Additional obligations for users of high‑risk systems

After 2 August 2026, employees who use high‑risk systems (notably HR, recruitment, payroll and performance‑management staff) and the employers who deploy those systems must comply with further obligations, including:

  • Informing employees and the works council that a high‑risk AI system is used, explaining its purpose, the data used and available safeguards and remedies for decisions from such systems;\
  • Ensuring employees comply with provider‑specified conditions of use, and that employees have verifiably reviewed those conditions before using the system;\
  • Establishing and documenting the technical and organisational safeguards, guarantees and internal (audit) procedures, including lawful data processing and cybersecurity arrangements (especially relevant for NIS2‑obliged organisations);\
  • Restricting access to high‑risk systems to appropriately competent and trained employees who can evaluate, pause or override system decisions where necessary;\
  • Requiring clear labelling when AI systems produce synthetic image/audio/video (deepfakes) used for marketing, employer branding or recruitment;\
  • Ensuring that data entered into high‑risk systems (e.g. employee performance data or CVs) are relevant, accurate and sufficiently representative;\
  • Continuously monitoring system operation, notifying the provider of deviations or risks, and suspending use until issues are resolved;\
  • Retaining automatically generated system logs under employer control for at least six months and informing users about this retention in advance.

Consequences and the complexity of implementation

Non‑compliance can lead to significant penalties. Under the AI Act, fines range from €7.5 million up to €35 million or 1–7% of the global annual turnover of the offending corporate group. The highest sanctions apply to prohibited AI practices (up to €35M or 7%); other infringements such as misuse of high‑risk systems or misleading information can also attract substantial fines.

Compliance is a complex, multi‑disciplinary task. Apart from labour law duties, employers must consider data protection, cybersecurity, trade secrets, personality rights, copyright, and in some cases consumer protection and competition law. Preparing and implementing AI systems in organisations typically requires months of preparatory work and close cooperation among IT, HR and legal teams.

Market surveillance authorities—and in the financial sector the Magyar Nemzeti Bank—may inspect compliance and impose sanctions.

In sum, AI systems used at work constitute a new, high‑risk class of work tools whose deployment and use are permitted only after multiple procedural and substantive safeguards are implemented and documented.