Fiona Young

Consultant

Tessa Rosado-Standen

Associate

Whether you are a Gibraltar-based gaming operator, a financial services provider, or a public sector entity, the AI “compliance cliff” is no longer on the horizon; it is beneath your feet. 

When it comes to the use of AI in the workplace, for Gibraltar-based employers, the transition from theoretical risk to urgent operational implementation is here and it calls for a careful balancing of EU mandated obligations and local law.

In what follows, Ramparts Employment Practitioners, Fiona Young and Tessa Rosado-Standen, discuss  the impact the regulations are likely to have on local employers and their employment practices. 

Fiona: Tessa, you have undertaken some research into the new Regulations. What are the key points that employers in Gibraltar need to know? 

Tessa: The EU AI Act is set to come fully into force in August 2026. It provides a robust regulatory framework for the development and use of AI within the European Union. 

Fiona: Will Gibraltar be required to implement the Regulations, given our position since Brexit?

Tessa: Yes. It is a common, and dangerous, misconception that post-Brexit Gibraltar is out of the EU’s reach. The EU AI Act will apply where the output of an AI system occurs within the EU, and Gibraltar’s unique geosocial position increases the likelihood of such reach.

Despite Gibraltar’s operation outside of the EU following Brexit, Gibraltar employers must remain aware that the EU Act has an aggressive extraterritorial reach, sharpened by Gibraltar’s socioeconomic integration with the EU. With thousands of frontier workers residing in Spain and commuting to Gibraltar daily to work, any AI-driven decision, from a CV rejection during the application process, to a performance-based bonus calculation, will inevitably produce an output in the EU: in Spain, where the employee is resident and likely to receive that information. 

Moreover, many Gibraltar companies are subsidiaries or headquarters of groups with an EU presence. The shared use of enterprise resource planning (ERP) or human capital management (HCM) systems across borders will necessitate group-wide compliance with the strictest standard, which is invariably the EU AI Act.

Fiona: In that case, what should local employers be looking at in terms of the systems and processes they have introduced that already utilise AI?

Tessa: Gibraltar’s local laws already demand that employers tread carefully in their use of AI tools in order to navigate the risks of bias and discrimination in recruitment and beyond. Employers should act now to audit their software, implement robust AI management systems, and ensure that all automated decisions remain transparent and explicable, with properly trained human oversight. 

Fiona: Effectively, employers should already be very careful with the systems and processes they rely on when recruiting or managing workforce. Therefore, this legislation will expect them to reassess those mechanisms in line with existing regulatory and statutory expectations, and ensure that AI capability is meeting their existing standards.

Tessa:  To an extent, yes- but this Act sets the bar even higher. Employers should be mindful of the High Risk considerations of utilising AI Tools for Recruitment and Work Force Management.  

The EU AI Act classifies AI systems based on the risks they pose, and employment systems have been identified as high-risk, specifically any systems which involve:

a) Recruitment and Selection: systems which are used for placing targeted job advertisements, screening or filtering applications, and evaluating candidates during interviews or tests. 

b) Workforce management: systems which are used to make decisions on promotion and termination, to allocate tasks based on individual behaviour or traits, or to monitor and evaluate performance and behaviour. 

Employers should conduct a thorough inventory of all software used, and not simply tools labelled explicitly as “AI”. Many legacy Applicant Tracking Systems (ATS) have integrated machine learning features for ranking or matching candidates, and if these features influence the shortlisting process for a role, the entire system could fall within the high-risk scope.

This high-risk classification triggers a host of obligations that must be fully applied by employers by 2nd August 2026.

Fiona: It is interesting that the law is setting the standard for AI systems (and even automated systems) so high. Employers often focus on the famous 52 week requirement to bring tribunal proceedings but do forget that a disgruntled, rejected candidate for a role may have legal rights in relation to the selection process utilised, and the data they may have relied on to make a decision. There was always a concern that a human error of judgement could result in  a decision being challenged, now that concern extends to AI processes that could result in an employee believing they are being unfairly treated or discriminated against. What is the employer expected to do to prevent exposure to challenge?

Tessa: The Act sets out clear obligations that the employer should familiarise themselves with:

  • Technical and Organisation Measures: Employers must implement measures to ensure that the systems they use are compliant with the instructions as provided by the vendor of the AI system. 
  • Human Oversight: Employers must assign natural persons with proper competence, training and authority to oversee the AI. These individuals need to be able to understand the AI system’s limitations and, crucially, have the power to override the AI decision.
  • Data Governance: Employers must ensure the information it inputs into the AI is relevant and representative. 
  • Monitoring and Logging: Employers must keep system logs for at least 6 months. These logs need to capture both the system’s output and the human operator’s interaction with it (e.g. did the human validate or reject the AI’s advice?).
  • Fundamental Rights Impact Assessment (FRIA): See below. 
  • Worker Notification: Employers must notify their employees/workers and any representatives that they will be subject to a system. 

Fundamental Rights Impact Assessment (FRIA)

FRIA is the beating heart of compliance under the EU AI Act, and mandatory for deployers of high-risk systems. Unlike the Data Protection Impact Assessment (DPIA) under the GDPR, which focuses on data privacy risks, the FRIA assesses broader risks to fundamental rights, including the right to non-discrimination, the right to good administration, and the right to an effective remedy.

Structuring the FRIA in the case of recruitment

  1. Description of the Employer’s Processes: Detail exactly where the AI fits into the hiring workflow. Is it a filter at the top of the funnel, or a scoring mechanism for the final shortlist?
  2. Period and Frequency: How long will the system be used? Is it for a specific period or indefinite use?
  3. Categories of Affected Persons: This section requires specific attention to Gibraltar’s worker demographics. It should explicitly list “frontier workers,” “local residents,” and potentially vulnerable groups such as “persons with disabilities” who may be disadvantaged by automated testing formats.
  4. Specific Risks of Harm: The assessment must quantify the risk of bias. For example, if the AI is trained on UK datasets, it may downgrade Spanish university qualifications held by frontier workers, leading to indirect discrimination based on nationality.
  5. Human Oversight Measures: Detail the specific protocols for human review. Who reviews the rejected candidates? What training have they received?

Crucially, the EU AI Act allows the FRIA to complement the existing DPIA. Employers should integrate these assessments into a single, comprehensive governance document to avoid duplication and ensure consistency between data protection and fundamental rights safeguards.

Fiona: While that might sound onerous to employers needing to implement these systems and ensure compliance and training, to me – as an employment lawyer –  it makes perfect sense. Being able to justify a decision reached is a fundamental aspect of determining fairness in employment tribunals, and being able to present clear evidence of the process utilised, and its proportionality to the process in question (and size of the organisation), should safeguard the employer appropriately while giving them the freedom to explore AI’s capability to improve their recruitment and workforce management approach. 

To my mind, therefore, the EU AI Act serves to ensure that the use of AI capability does not inadvertently detract from their existing obligations to potential employees and existing employees. Shall we recap some of these existing obligations?

Tessa: That’s right, regulation of automated decision making is not new to the jurisdiction.  Local employers already need to take significant precautions when utilising automated decision making systems:

  • Gibraltar General Data Protection Regulation (GDPR): 

Article 22 of the Gibraltar GDPR deals with automated individual decision making, including profiling. The Gibraltar Regulatory Authority (GRA) explicitly identifies e-recruitment processes involving automated filtering as ‘profiling’.  

In accordance with this Article, an employee or prospective employee has the right not to be subject to a decision made exclusively by AI, but rather to have ‘meaningful’ human intervention in any decision made about them. Any attempt by an employer to circumvent Article 22 by inserting a nominal human reviewer into the loop merely as a tick-box solution without proper training and oversight falls legally short. 

Fiona: That requirement of “meaningful human intervention” is an essential check and balance. In my line of work, I handle many complaints of discrimination and bias under the Equal Opportunities Act. I have read some fascinating insights into the inherent bias that AI is accidentally learning, owing to the way in which it has accessed historic data and the manner in which it is being programmed. This is, of course, another conversation for another time, but for the sake of this article, let’s explore what employers need to consider in line with their AI usage and Equal Opportunities protections.

Tessa:  Absolutely, bias is often built into the algorithms and models of AI, beginning from the manner in which data is collected, leaking into the way in which systems are designed, and finally showing up in how they are deployed in a real-world context. 

Under Gibraltar’s Equal Opportunities Act 2006, these biases can lead to “indirect discrimination”, where an apparently “neutral” algorithm statistically disadvantages a protected group.

Fiona: Can you give some working examples of how AI may have developed a potentially challengeable bias?

Tessa: Yes, models often have an auditory bias towards male voices or Received Pronunciation, and Natural Language Processing (NLP) tools have a preference for standard dialects. AI is likely to favour key words associated with certain types of elite education (for example, a preference for terminology associated with English universities over Spanish universities, even if the skill being described is the same) or activity (exhibiting a preference for language associated with traditionally male dominated, or able-bodied, past-times). CVs exhibiting ‘gaps’ will often be immediately filtered out without consideration of the reasons for- and value of- that gap, often disproportionately affecting female applicants who still, disproportionately, take on caring responsibilities.

In a phenomenon dubbed the “high-tech echo chamber”, AI trained on historical hiring data might inadvertently replicate past prejudices and penalise, for example, women or Spanish residents (frontier workers), especially in Gibraltar’s dominant sectors like the gaming industry or financial services where historically there have been gender and race imbalances. 

Fiona: Managing Diversity and Inclusion amongst a human workforce is already a massive challenge for employers. What will they need to do to adequately ensure that their AI does not expose them to claims?

Tessa: To defend against claims of discrimination, employers must demonstrate “reasonable care” in auditing their systems. It is no longer a defense to claim ignorance of how the AI made its decision. Fortunately, there are a number of techniques that employers can introduce to reduce the risk of inadvertently discriminating against an employee or potential employee:

“SHAP”

The AI Act’s transparency requirements and the GDPR’s “Right to Explanation” necessitate the use of Explainable AI (XAI). Techniques such as SHAP (SHapley Additive exPlanations) values allow auditors to see exactly which features (e.g., “years of experience,” “university name”) contributed to a specific candidate’s score. If a SHAP analysis reveals that “Gender = Female” or a proxy variable had a negative impact on the score, the employer has 

The 4/5ths Rule (Impact Ratio)

The “4/5ths rule” (or 80% rule) is a widely accepted statistical metric for identifying adverse impact. It states that if the selection rate for a protected group is less than 80% of the rate for the group with the highest rate, there is evidence of adverse impact.30

The AI Management System (AIMS)

To operationalise these obligations, many leading organisations are adopting ISO/IEC 42001, the international standard for AI Management Systems (AIMS). The ISO 42001 helpfully provides a checklist to guide employers in their compliance, some of which overlaps with the FRIA: 

  • Policy: A specific and detailed “AI in Recruitment/Work Management” should be drafted and published to include acceptable use, prohibited practices and oversight hierarchies. 
  • Risk Assessment: Employers should conduct risk assessments for each AI tool, considering the impact on different candidate groups. 
  • Data Management: Audit training data for representativeness/verify if the vendor used local/relevant data sets.
  • System Lifecycle: No system can go live without a passed bias audit and FRIA.
  • Human Oversight: The job description for the ‘human overseer’ must be clearly defined.
  • Incident Management: Establish a clear protocol for “AI Incidents” (for example, when a candidate complains of bias)

Third-Party Risk Management

Most employers will procure AI tools rather than build them, and so employers should focus on procurement governance: 

  • Vendor Warranties: Contracts must demand proof of compliance with the EU AI Act (CE marking, Declaration of Conformity).
  • Transparency Requirements: Employers should refuse to deploy “black box” systems. If the vendor cannot explain the decision logic, the employer cannot fulfill their “Right to Explanation” duties under GDPR.
  • Indemnification: Contracts should include specific indemnities for regulatory fines arising from the vendor’s non-compliance (e.g., biased training data causing an Equal Opportunities Act claim).

Fiona: I would also add that this is as good a time as any for employers who are excited about using AI capability to improve their employment process and framework, to also refamiliarise themselves with the legal  standards and expectations of an Employer in this context. The buzzwords of assessing whether an Employer has behaved lawfully towards an employee or potential employee are “Fair, Reasonable and Justifiable” the standard is whether an Objective Observer would assess this, not that we ourselves believe a system to be thus. Another factor to take into account is Proportionality. Were the measures taken proportionate, taking into account the employer’s size, profitability and the number of employees they engage? The EU AI Act, as I am understanding from your explanation, Tessa, sets out very clear parameters that an Employer must comply with to ensure that the system is Fair, Reasonable and Justifiable.

Tessa: Exactly, in 2026, ignorance is not a defense. To defend against potential statutory liability and uncapped damages in the Employment Tribunal, employers should immediately take stock of their software stack and ensure:

  1. A full FRIA is conducted 
  2. The AIMS checklist is met
  3. Third Party Risk is managed
  4. Humans are properly trained to oversee and override AI decisions. 

In relation to that last one point, it goes without saying that the Human Oversight should be  experienced HR personnel with clear and up to date knowledge of the relevant  Statutory Provisions that protect employees and potential employees. 

Fiona: There’s a lot of food for thought there. What are the key takeaways that can help employers feel less daunted and more excited about the introduction of systems that can improve their employer experience through AI capability?

Tessa: Well the EU AI Act does set a high bar for AI used in recruitment and workforce management, classifying these systems as “High-Risk.” This is non-negotiable for Gibraltar employers due to the Act’s extraterritorial reach and the local presence of “frontier workers” and EU-parent companies. Please remember that the hard deadline for full compliance is 2nd August 2026.

To fully prepare for the implementation Employers should:

  1. Conduct a Full Fundamental Rights Impact Assessment (FRIA): This is mandatory for high-risk systems and focuses on assessing the risk of bias against vulnerable groups (like frontier workers and persons with disabilities).
  2. Implement an AI Management System (AIMS): Adopting the ISO/IEC 42001 standard provides a clear framework for managing AI risk, including drafting a policy and creating protocols for “AI Incidents” (like bias complaints).
  3. Manage Third-Party Risk: Since most tools are procured, your contracts must demand vendors prove their EU AI Act compliance and provide full transparency (avoid “black box” systems).
  4. Ensure Meaningful Human Oversight: You must assign experienced, trained HR personnel who can understand the AI’s limitations and, crucially, have the authority to override its decisions, fulfilling the “meaningful human intervention” required by Gibraltar GDPR (Article 22).

The Overriding Principle

The goal of all these requirements is to ensure that every employment decision remains Fair, Reasonable, and Justifiable to an Objective Observer, thereby safeguarding you against claims of indirect discrimination under the Equal Opportunities Act 2006.

21.04.26

News & Insights

Gibraltar’s Prediction Market Regulations: A New Regulatory Category for Emerging Markets

Gibraltar has introduced a dedicated regulatory framework for prediction markets, marking a significant step in the evolution of its gambling and financial services landscape. The Prediction Market Regulations 2026, made under the Gambling Act 2025, establish a standalone regime for a category of activity that has, until now, sat between traditional gambling and financial trading. Andrew Tait Head of Betting & Gaming Arnas Urbutis Trainee Associate A distinct regulatory categoryAt the core of the new framework is a clear policy…

The 2026 Employer’s Audit: Navigating AI Recruitment and Bias under Gibraltar Law & the EU AI Act

Fiona Young Consultant Tessa Rosado-Standen Associate Whether you are a Gibraltar-based gaming operator, a financial services provider, or a public sector entity, the AI "compliance cliff" is no longer on the horizon; it is beneath your feet. When it comes to the use of AI in the workplace, for Gibraltar-based employers, the transition from theoretical risk to urgent operational implementation is here and it calls for a careful balancing of EU mandated obligations and local law. In what follows, Ramparts…

The 90-Day Standard: Navigating the 2025 Contract Termination Regulations for UK and Gibraltar Providers

David Borge Practice Director Due to come into force on 28 April 2026, the Payment Services and Payment Accounts (Contract Termination) (Amendment) Regulations 2025 (the Regulations) are designed to strengthen consumer protections regarding the termination of payment service contracts. The scope of the Regulations is broad, covering credit institutions, payment institutions, and E-Money Institutions. Consequently, online payment providers and processors are explicitly included within the remit of these new rules. The landscape for payment service providers (PSPs) and Electronic Money…

Discover more from Ramparts

Subscribe now to keep reading and get access to the full archive.

Continue reading