EU AI Act readiness
AI that allocates tasks to workers or monitors their work is the category Annex III of the EU AI Act addresses. This page states our position precisely: the category, the timeline, the mechanism-by-mechanism map — and exactly what we do not yet hold. It is written to be forwarded to your counsel.
The category, without the spin
First: AI intended to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate workers’ performance and behaviour, falls under Annex III point 4(b) of the EU AI Act. Whether a given NOW OS deployment is in scope turns on its intended purpose and configuration — a determination your counsel makes, not your vendor.
Second: we build to the high-risk oversight bar regardless of classification, and we will never use our named-humans-decide design to argue you out of the classification. A design that keeps people in charge is evidence for your oversight obligations — it is not an exemption from them.
Third: the high-risk obligations covering this category apply from 2 December 2027. No vendor can accurately claim compliance with high-risk obligations that have not yet begun to apply — so we don’t, and we would treat any vendor’s “EU AI Act certified” badge as a diligence finding, not a credential.
We are not compliant, certified, or approved against the Act’s high-risk requirements — no vendor is yet, because those obligations have not started applying. We are building to the bar, in the open, and this page tracks exactly where that stands.
The mechanism map
Two kinds of record matter under the Act, and they are not the same thing. We keep them distinct because your counsel will.
| What the EU AI Act and related EU law ask of high-risk workplace AI | What NOW OS does today |
|---|---|
| Human oversight by design (Article 14) — systems built so people can genuinely oversee, intervene, and decide | The product’s core mechanism, not a feature: NOW OS recommends one of four modes per action; your named people decide, with real authority to decide otherwise, and the design assumes they will use it. |
| Deployers assign competent, trained humans to oversee (Article 26) | Every allocation decision carries a named decider. The record makes visible whether oversight is actually staffed — who decided, how often, on what rationale. |
| Automatic event logging by the system, retained by deployers (Articles 12 and 26) | System-generated event logs are distinct from the human decision record, and both exist. The named-human record complements the technical logs; it does not replace them, and we will not blur the two. |
| Workers and their representatives informed before deployment (Article 26) | The per-action decision record is a concrete artifact an employer can put in front of a works council — what is mapped, what is recommended, who decides. See the workers’-representatives section. |
| Meaningful human review of consequential automated decisions (GDPR Article 22, following the CJEU’s SCHUFA judgment) | Named deciders with documented rationale and genuine authority — the record shows who decided and why. Whether review is meaningful in practice depends on how you staff it; the record makes that verifiable. |
| Fundamental-rights impact assessments for public bodies and certain other deployers (Article 27) | Per-action evidence — what is mapped, what is scored, what is recommended, who decides — in a form built to feed your assessment. |
Article references and regulatory dates summarized in plain language for orientation — your counsel’s reading governs. Maintained by Nexus of Work · Last reviewed 1 September 2026.
The runway
Held today: the oversight architecture above, shipping and in use in our U.S. beta — one major public university system, one governed process end-to-end, every decision on the tamper-evident record.
Not yet held — stated here so you don’t have to ask: no conformity assessment, no EU entity, no appointed EU representative, no EU data residency, no European customers, no SOC 2 or ISO 27001. The dated inventory lives on our Europe page and is updated quarterly.
The commitment: before any EU market placement of a high-risk system, the required representatives get appointed, the technical documentation and conformity work gets done, and this page records each step when it is real — not when it is planned.