06 AOÛ 2026
GOUVERNANCE

Seyfarth and HR Executive spell it out in early August: GDPR and the AI Act overlap on workplace monitoring — at AppH, our new Messenger features (presence, read receipts) stay on the right side of the line

Two professional publications, in early August 2026, map the same grey area: Seyfarth Shaw details the HR tools the AI Act classifies as "high-risk" (recruitment, workforce planning, employee monitoring, performance management); HR Executive puts a number on the fine (up to €35M or 7% of worldwide turnover) and lists the uses already in scope. The distinction that matters for an SMB: scoring or ranking an employee is not the same thing as showing whether they are online.

On 3 August, Seyfarth Shaw (through partners Yana Komsitsky, Paul Whinder and Georgia Hill Smith) published a note that starts from a simple observation: the legal risk around AI at work now goes beyond GDPR alone. Recruitment, workforce planning, employee monitoring and performance management are the four areas they identify as likely to tip a tool into the AI Act's "high-risk" category — with a technical point many employers underestimate: buying "compliant" software is not enough, the company deploying the tool keeps its own liability regardless of the vendor's guarantees. The same day, HR Executive goes further on the numbers: the AI Act classifies "virtually all AI systems used in recruitment, performance management and workforce planning" as high-risk, with enforcement starting on 2 August 2026 (the full set of obligations waits until December 2027, as we covered in an earlier digest). The concrete examples they cite: CV screening, video-interview analysis, employee monitoring coupled with promotion recommendations, restructuring decisions, headcount forecasting, payroll compliance detection. In the United States, the same logic arrives piecemeal — New York's Local Law 144 already requires an annual bias audit and candidate notification, the Colorado AI Act takes effect this year — while China regulates the same ground through its personal data protection law.

What makes this article relevant for AppH this very week is that we have just shipped a series of Messenger features that, on paper, look like "employee monitoring": online presence dots, read receipts, @someone mentions, pinned messages, a missed-call log. The honest question to ask — and one an SMB owner should ask of any tool they buy — is not "does this touch an employee's activity?" (the answer is almost always yes), but "does this score, rank, or trigger an automated decision about an employee?". A presence dot says an account is connected, not whether the person is working well. A read receipt says a message was opened, not whether the reply was relevant. Nothing in these features computes a responsiveness score, ranks employees against each other, or recommends a promotion, a reprimand or a restructuring — the exact uses Seyfarth and HR Executive place on the "high-risk" side. This is not marketing rephrasing after the fact: it is the grid we used before shipping them, and it is the same grid we republish here so a customer can apply it to their own tools, not just ours.

For AppH

  • Seyfarth and HR Executive draw the same dividing line AppH already applies internally — scoring/ranking/deciding about an employee versus displaying a status — which gives an SMB owner a concrete grid to audit any tool, not just Messenger.
  • The Messenger features shipped this week (presence, read receipts, mentions, pins, missed calls) pass that grid without ambiguity: deterministic status, zero inference about the person — verified before shipping, not after the fact for this article.

Against / what does not hold indefinitely

  • HR Executive's list of "high-risk" uses — promotion recommendations, restructuring, headcount forecasting — is exactly the direction a product like AppManager could drift towards over time; "not high-risk today" is a check to redo with every new feature, not a permanent guarantee.
  • Neither Seyfarth nor HR Executive names a dedicated French regulator for workplace monitoring — unlike Germany, which appointed BaFin for finance (see our previous article). The legal obligation already exists; the authority that will concretely enforce it for French SMBs does not yet.

We could have opened this article by saying "good news, our new Messenger features are compliant" — true, but not the useful point. The useful point is the line itself: a presence dot, a read receipt, an @someone mention, a logged missed call — these are facts, not judgements. Nothing in these features evaluates, ranks or recommends a decision about an employee. The day AppH built a responsiveness score, a performance ranking based on this data, or an automatic promotion recommendation — that day we would be on the "high-risk" side Seyfarth and HR Executive describe, and we would say so clearly before building it, not after the fact in an article like this one. Supporting an SMB owner means giving them this reading grid now, not waiting for a customer to ask whether Messenger monitors their team. And the rule we repeat in every article of this series applies here without exception: no action with real consequences for an employee — an evaluation, an HR decision, a flag — ever leaves AppManager without a human validating it first.

Reviewed by a human at AppH
← Previous article (older)Next article (newer) →

← Back to news

Want us to walk you through how this applies to a real case?

Talk to AppH

Get new posts by email

One email when we publish new analysis — never spam, unsubscribe in one click.