Romanian lawyer reviewing employee and independent contractor arrangements with business clients

Employee vs Contractor in Romania: Legal Risks

Employee or independent contractor in Romania?

Foreign companies must match the contract to the way the work will actually be organised. Romanian employment and tax rules look beyond labels, invoices and foreign templates when control, integration and commercial independence point in another direction.

Individual Employment Labour Code Article 10 Subordination & Authority Mandatory Protections Payroll & Social Security B2B Services Agreement Fiscal Code Article 7 4-of-7 Independence Test Commercial Autonomy Own Risk & Deliverables VS Romanian Substance-Over-Form Legal Review

A company cannot turn an employee into an independent contractor simply by changing the contract title. Romanian authorities and courts may examine how the relationship works in practice: who controls the schedule, location and method of work, whether the individual may serve other clients, who bears commercial risk and whose resources are used. Before engaging a Romanian contractor, foreign companies should test both the written terms and the operating model, document genuine independence and correct any inconsistent practices.

Hiring an individual in Romania requires an early classification decision. The company must determine whether it needs an employee working under its authority or an independent provider responsible for delivering agreed services through their own business activity.

This distinction affects much more than the contract label. It can determine employment protections, payroll and social-contribution treatment, working-time controls, termination requirements and the allocation of commercial risk. A foreign template describing someone as a “consultant” or “independent contractor” will not resolve those questions if the day-to-day relationship operates like employment.

Can the parties simply choose employee or contractor status?

No. The parties may choose a contractual structure, but that structure must match the legal and economic reality of the work. A services agreement cannot safely replace an employment contract where the individual is, in substance, working under the company’s authority and direction.

Romanian law approaches classification from more than one direction. The Romanian Labour Code defines an individual employment contract through work performed for and under the authority of an employer in return for remuneration. Separately, the Romanian Fiscal Code defines independent activity through a statutory set of criteria and allows the tax authorities to reclassify a transaction or activity so that its tax treatment reflects its economic substance.

The practical assessment therefore has two connected parts:

  1. Contractual structure: what rights, duties, control mechanisms and risks the documents create.
  2. Operational reality: how managers and the individual actually organise and perform the work.

Risk: A carefully drafted contractor agreement can still be undermined by daily instructions, fixed attendance, manager approval of absences, exclusivity, company-controlled tools or treatment identical to employees.

What is the practical difference between an employee and an independent contractor?

Decision factorEmployeeIndependent contractor
Legal relationshipPerforms work under an individual employment contract.Provides defined services under a civil or commercial agreement.
Direction and controlWorks for and under the authority of the employer.Controls the method and organisation of the service, subject to agreed deliverables.
Schedule and locationNormally follows contractual and employer-established working arrangements.Should have meaningful freedom to choose when, where and how the service is performed.
Commercial riskThe employer bears the business risk and owes the agreed salary.The provider assumes genuine risks linked to cost, performance and organisation.
Other clientsMay have other employment, subject to working-time, conflict and incompatibility rules.Should be free in substance to offer services to several clients.
Tools and resourcesWork is commonly performed with employer-provided systems and resources.The provider ordinarily uses or organises their own professional resources.
Statutory protectionsReceives the mandatory protections attached to employment status.Relies primarily on the services agreement and the law governing that agreement.
Ending the relationshipTermination must follow the applicable employment route and mandatory safeguards.Termination follows the contract and applicable civil or commercial rules.
Legal Matrix

The Workforce Classification Spectrum in Romania

Full Subordination • Mandatory daily working hours • Supervised work execution • Integrated into staff hierarchy ➔ Individual Employment (CIM) Gray / Misclassified Zone • Invoiced through PFA / SRL • But 100% exclusive dedication • Fixed salary-like retainers ⚠ High Reclassification Risk Commercial Autonomy • Freedom of place & schedule • Result/deliverable-based • Multi-client portfolio & risk ✓ Lawful B2B Contractor EMPLOYEE (CIM) SUBSTANCE OVER FORM INDEPENDENT (B2B)
Figure 1: The operational spectrum used by Romanian Labour & Tax authorities to assess workforce relationships.

No single row decides the classification. The correct conclusion depends on the relationship as a whole. For example, a contractor may need access to a client’s secure systems without becoming an employee. Conversely, issuing invoices through a registered business does not by itself prove independence if the individual remains subject to employee-like control.

What does Romanian employment law treat as employment?

The central employment indicator is subordination: the individual performs work for and under the authority of the employer in return for remuneration. The company’s control over the person, not merely its right to accept a deliverable, is particularly important.

Article 10 of the Labour Code defines the individual employment contract as the agreement under which an individual undertakes to perform work for and under the authority of an employer in exchange for remuneration. This is different from a genuine customer-provider relationship, where the customer specifies the expected result but does not manage the provider as part of its workforce.

Where the facts point to employment, our employment lawyers in Romania can review the proposed contract, workplace controls and onboarding documents before work begins.

For employment, the contract must be concluded in writing, in Romanian, no later than the day before the employee starts work. The employer must also complete the required employee-register formalities before work begins. The Romanian Labour Inspectorate confirms these requirements in its official employment-contract guidance.

Operational indicators that may point towards employment include:

  • a manager determines the individual’s daily or weekly schedule;
  • attendance at a company location or continuous online availability is mandatory;
  • the individual receives detailed instructions about how work must be performed;
  • absences require permission rather than coordination of deliverables;
  • performance is managed through the same hierarchy and procedures used for employees;
  • the individual is presented internally or externally as a member of staff;
  • the role is personal and the individual cannot use collaborators or substitutes;
  • the individual bears little or no genuine commercial risk.

These are indicators, not an automatic checklist. The nature of the work, regulatory requirements, information security and customer obligations may justify some controls. The question is whether those controls preserve an independent business relationship or place the individual under employer-like authority.

When does the Fiscal Code recognise an independent activity?

Under Article 7 of the Fiscal Code, an activity performed by an individual for income is independent when at least four of seven statutory criteria are met. The evidence should show that those criteria operate in practice, not only that they were copied into the contract.

Fiscal Code criterionPractical evidence to examine
1. Freedom over place, method and scheduleThe provider plans performance independently and is not assigned employee attendance hours.
2. Freedom to work for several clientsThe contract permits other clients and the operational model does not make that freedom artificial.
3. Assumption of inherent business riskThe provider bears relevant costs, rectification duties or other genuine performance risks.
4. Use of the individual’s own assetsThe provider uses or arranges professional equipment, software, workspace or other business resources where appropriate.
5. Use of intellectual or physical capacityThe service depends on the provider’s own professional expertise or performance.
6. Membership of a regulated professional bodyThe activity is carried out within a legally regulated profession, where applicable.
7. Freedom to perform directly, with staff or collaboratorsThe provider may lawfully organise delivery personally or through employees or collaborators, subject to justified qualification and confidentiality requirements.
Statutory Rule

Romanian Fiscal Code Article 7: The 4-of-7 Independence Test

1 Autonomy Place, method & schedule 2 Multiple Clients Substantive freedom to serve 3 Commercial Risk Inherent business risk borne 4 Own Assets / Tools Equipment, premises, licenses 5 Capacity & Skill Own professional expertise 6 Professional Body Regulated trade or guild 7 Criterion 7: Delegation & Substitutes Lawful freedom to perform directly or via staff/collaborators MINIMUM 4 REQUIRED to satisfy Fiscal Code Art. 7
Figure 2: The 7 statutory criteria under Romanian Fiscal Code Art. 7. At least 4 must be satisfied and backed by operational proof.

Practical tip: Build a short evidence file for each material contractor relationship. Keep the agreement, scope of work, invoices, deliverable records and evidence of independent organisation together. A clause is stronger when the working record supports it.

Are four fiscal criteria enough to eliminate employment risk?

Not necessarily. The four-of-seven test defines independent activity for Romanian tax purposes, but it should not be treated as permission to reproduce an employment relationship through a services contract.

The tax and employment analyses overlap, particularly around control, business risk and operational autonomy, but they do not perform exactly the same function. The Labour Code focuses on work performed under employer authority. The Fiscal Code focuses on the conditions for independent activity and the correct tax treatment of economic substance.

Article 11 of the Fiscal Code allows the tax authorities to disregard a transaction without economic purpose or reclassify the form of a transaction or activity to reflect its economic content. The authority must explain the relevant facts and evidence supporting the reclassification. This makes consistent documentation important, but it also means that documentation must reflect reality.

European Union case law follows a similar substance-based approach for EU-law concepts of “worker”. In Yodel Delivery Network, Case C-692/19, the Court of Justice explained that an “independent contractor” label does not prevent worker classification where independence is merely notional. Relevant considerations included control over time, place and content of work, exposure to commercial risk, integration into the undertaking and freedom to use substitutes or serve third parties.

Which arrangements create the highest misclassification risk?

Fixed employee-style availability

The contractor must work the company’s standard hours, remain continuously available and obtain approval for any absence, regardless of deliverables.

Control over method, not only result

A company manager allocates daily tasks, prescribes the precise working method and continuously supervises the individual in the same way as employees.

Artificial freedom to serve other clients

The agreement permits other clients, but workload, exclusivity expectations or availability requirements make that freedom unrealistic.

No meaningful business risk

The individual receives a fixed recurring amount, bears no relevant costs or correction obligations and is paid regardless of the agreed output.

Full integration into the organisation

The contractor has an internal job title, reports through the employee hierarchy, appears in staff structures and is evaluated under employee procedures.

A recurring monthly fee, a long relationship, one important client or use of a customer system is not automatically decisive. Each fact must be assessed in context. Risk rises when several employee-like elements combine and genuine commercial independence becomes difficult to demonstrate.

What can happen after a misclassification finding?

A misclassification finding can open separate tax, employment, social-contribution and contractual questions. The precise exposure depends on who makes the finding, the period reviewed, the parties involved and the evidence.

Tax and social-contribution exposure

The tax authority may reassess the economic substance of the activity and determine the related tax and contribution consequences. Historic treatment, payment records, filings and the allocation of responsibility between the parties must be reviewed before quantifying any exposure.

Employment rights and claims

An individual may argue that the factual relationship was employment and seek rights associated with employee status. Questions may arise concerning remuneration, working time, leave, termination, employee records and other mandatory protections. The outcome depends on the legal route and the evidence, not on the contract title alone.

Inspection and document risk

Where work has in substance been performed as employment without the required employment formalities, the company may face labour-inspection consequences. Specific sanctions should be assessed against the law in force and the facts at the date of the review.

Commercial and transaction risk

Misclassification can affect due diligence, financing, investment or an acquisition. A buyer may ask for the contractor population, templates, tax treatment, intellectual-property arrangements and potential historic liabilities to be reviewed before closing.

Intellectual property and confidentiality

The company should not assume that an employment-style intellectual-property position automatically applies to an independent provider. Ownership, assignment, permitted use, confidentiality and return or deletion of information should be dealt with expressly and consistently with the actual relationship.

Does contracting through a PFA or an SRL remove the risk?

No business form provides an automatic safe harbour. It may change the contractual and tax analysis, but the parties should still examine who performs the service, how the relationship operates and whether the structure has genuine commercial substance.

A Romanian authorised individual enterprise, commonly referred to as a PFA, is closely connected to the individual providing the activity. An SRL is a separate legal entity, which may employ staff, assume business risks and organise delivery through its own resources. Those differences matter, but neither registration document should replace a factual review.

If the supplier structure is still being established, the practical differences should also be considered alongside our guidance on company formation in Romania for foreign founders.

For an SRL supplier, examine whether the supplier is genuinely providing a business service or whether one individual is effectively inserted into the customer’s organisation under continuous personal control. For a PFA, test the statutory independence criteria directly and retain evidence supporting them.

Foreign companies should also avoid importing assumptions from their home jurisdiction. A worker physically performing activity in Romania may trigger Romanian employment, tax, social-security, registration or permanent-establishment questions. Those cross-border issues require a separate review based on the company, worker, location and duration of the arrangement.

Related structures may require a different analysis. Our guide to dual employment in Romania explains the rules applicable when an individual holds more than one employment contract, while the guide to service contract requirements in Romania covers the clauses and compliance points relevant to genuine service relationships.

Three illustrative classification scenarios

Scenario 1: project-based software specialist

A specialist agrees to deliver defined software modules, chooses the working schedule and location, uses their own business equipment, serves several clients and may use qualified collaborators. The customer controls security standards, acceptance criteria and deadlines but not the specialist’s daily organisation.

Assessment: These facts support independence, subject to the complete contract, tax position and actual implementation.

Scenario 2: “consultant” managed as staff

An individual works from 09:00 to 18:00, reports daily to a department manager, needs approval for time off, uses only company equipment, appears on the internal organisation chart and cannot accept other clients.

Assessment: The contractor label is difficult to reconcile with the operational indicators of subordination and workforce integration.

Scenario 3: regulated client environment

An external professional must work through the customer’s secure system and attend specific meetings because of regulatory and information-security requirements. The professional otherwise decides how to perform the mandate, bears professional risk and maintains other clients.

Assessment: Use of customer systems and scheduled coordination do not decide the issue alone. The purpose and extent of control must be examined.

These scenarios are illustrative. Changing one fact, such as exclusivity, substitution rights, commercial risk or management control, may change the conclusion.

How should a foreign company structure a genuine contractor relationship?

  1. Define the result. Describe services, deliverables, acceptance criteria and deadlines instead of creating an employee job description.
  2. Preserve operational autonomy. Allow the provider meaningful control over place, schedule and method, subject to justified security and coordination requirements.
  3. Address other clients. Avoid broad exclusivity unless a narrow restriction is genuinely necessary and legally supportable.
  4. Allocate business risk. Specify responsibility for costs, tools, corrections, professional organisation and non-conforming deliverables.
  5. Review substitution and collaboration. Permit lawful use of qualified personnel or collaborators where compatible with the service, confidentiality and regulatory requirements.
  6. Separate contractors from HR procedures. Do not automatically apply employee leave approval, performance management, benefits or disciplinary systems.
  7. Protect data, confidentiality and IP. Draft clauses that fit an independent services relationship and the actual information or assets involved.
  8. Keep evidence. Retain statements of work, invoices, deliverables and communications showing independent organisation.
  9. Reassess material changes. Review the classification when the scope, reporting line, exclusivity, workload or duration changes.

How can a company audit its existing Romanian contractors?

Audit Roadmap

7-Step Romanian Contractor Classification Audit

1 Inventory All PFA/SRL 2 Fact Map Daily routine 3 Fiscal Test 4-of-7 check 4 Labour Test Authority check 5 Risk Scan IP & Tax PE 6 Classify Risk tiers 7 Remediate Lawful fix Remediation must be prospective; avoid backdating documents or creating artificial records.
Figure 3: Corporate audit roadmap for evaluating contractor populations in Romania.
  1. Inventory every arrangement. Identify individuals engaged directly, through a PFA, through a personal SRL or through an intermediary.
  2. Map the facts. Record schedule, location, reporting, tools, clients, payment model, risk, substitution and integration.
  3. Test the seven fiscal criteria. Identify which criteria are genuinely met and what evidence supports each conclusion.
  4. Test employment subordination. Compare management practices against the Labour Code concept of work under employer authority.
  5. Check connected risks. Review tax, social security, immigration, permanent establishment, IP, confidentiality and data protection where relevant.
  6. Classify by risk. Separate clearly independent providers, fact-sensitive cases and arrangements that operate like employment.
  7. Implement a lawful correction plan. Amend terms and practices where the relationship remains genuinely independent, or move to an appropriate employment structure where the facts require it.

Risk: Do not “repair” the file by backdating documents or creating evidence that did not exist. Remediation should accurately record the current position and lawfully correct the arrangement going forward, while historic exposure is assessed separately.

The Bottom Line

The employee-versus-contractor decision must be made from the work model, not from the preferred invoice or contract label. Genuine contractors organise an independent activity, retain meaningful autonomy and assume real business responsibility. Employees perform work within the employer’s authority and receive the mandatory protections attached to that status.

For foreign companies, the safest starting point is a combined contract and operations review before the individual begins work. The same review should be repeated whenever the role becomes more integrated, exclusive or manager-controlled.

Frequently asked questions

Can a Romanian contractor work for only one client?

One client does not automatically create employment, but it weakens one of the express indicators of independent activity and may increase economic dependence. The full relationship must still be assessed, including control over schedule and method, commercial risk, tools, substitution rights and whether the contractor is integrated into the client’s organisation.

Is a monthly fixed fee evidence of employment?

Not by itself. A genuine provider may charge a monthly retainer or recurring service fee. Risk increases where the payment resembles a salary and is combined with fixed attendance, continuous personal availability, direct supervision, no deliverable risk and treatment identical to employees.

Can a foreign company hire a Romanian individual as a contractor?

Potentially, but the company should confirm that the activity is genuinely independent and that the contractor has an appropriate legal and tax setup. The arrangement may also raise Romanian tax, social-security, employment, registration or permanent-establishment questions depending on the company, work location and duration.

Does an SRL invoice eliminate misclassification risk?

No. An SRL is a separate legal entity and that distinction matters, but the customer should still examine whether it receives an independently organised business service or manages one individual as part of its workforce. Contracting structure, economic substance and daily practice must be assessed together.

Should the agreement use Romanian law?

The applicable law depends on the parties and cross-border structure. A foreign governing-law clause cannot necessarily remove mandatory rules relevant to work performed in Romania. The governing law, jurisdiction, tax position and mandatory employment protections should be reviewed together before using a foreign template.

When should an existing contractor arrangement be reviewed?

Review it when the contractor becomes exclusive, moves into a managerial reporting line, adopts employee working hours, receives company benefits, stops using independent resources or shifts from project delivery to an ongoing internal role. A periodic review is also appropriate for material or long-running engagements.

Disclaimer: This article provides general legal information and does not constitute legal or tax advice. Classification depends on the contract, the actual working relationship, the parties’ tax status and the applicable Romanian and EU rules.

AI Notice: AI-assisted content, reviewed by a qualified Romanian lawyer.

Two corporate professionals reviewing AI transparency controls, compliance dashboards, and synthetic content verification tools on screens in an office setting.

EU AI Act in Romania: 2026 Guide for Foreign Companies

EU AI Act compliance representation with glowing neural networks in a modern legal setting
Preparing for the EU AI Act: foreign companies operating in Romania must align their AI deployment with the new regulatory framework starting August 2026.

The compliance question is no longer whether a business “uses AI”. Most international groups do. The practical questions are which legal entity controls each use, whether the system affects people in Romania, and whether the company is a provider, deployer, importer or distributor for that system.

This guide is written for foreign companies, investors and employers with Romanian operations. It reflects legislation and official information available on 31 July 2026 and explains the rules applicable from 2 August 2026.

What Changes on 2 August 2026?

The immediate operational change is the application of Article 50 transparency duties, not the full high-risk regime for HR and other Annex III systems.

Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026. It moved the Annex III high-risk deadline to 2 December 2027 and the deadline for high-risk AI embedded in regulated products to 2 August 2028. The European Commission’s updated AI Act timeline confirms these dates.

DateRulePractical consequence
2 February 2025Prohibited AI practices and AI literacyCompanies must stop prohibited uses and support AI literacy for personnel and other people operating AI on their behalf.
2 August 2025General-purpose AI model rules and parts of the enforcement frameworkMainly relevant to model providers; ordinary business users are usually deployers, subject to role-specific duties.
2 August 2026Article 50 transparency obligationsCertain AI interactions and AI-generated or manipulated outputs require disclosure, marking or labelling.
3 August 2026Supervision and enforcement of AI literacyThe Commission states that Article 4 supervision and enforcement rules apply from this date.
2 December 2026Limited legacy grace periodProviders of generative systems placed on the market before 2 August 2026 must meet the machine-readable marking duty from this date.
2 December 2027Annex III high-risk rulesCovers listed uses in employment, education, credit, biometrics, essential services and other areas.
2 August 2028Annex I product-related high-risk rulesCovers qualifying AI safety components or AI products under listed EU product legislation.

The original Artificial Intelligence Act remains Regulation (EU) 2024/1689, but it must now be read together with the enacted AI Omnibus.

Minimalist representation of AI transparency and regulation
Understanding the core boundaries: the AI Act imposes tiered obligations depending on the specific use case and risk level.

Does the AI Act Apply to a Foreign Company Operating in Romania?

Yes, potentially even when the provider or parent company is outside the EU. Location alone does not remove a business from scope.

The Act applies to providers that place AI systems or general-purpose AI models on the EU market, deployers established or located in the EU, importers and distributors, and certain product manufacturers. It can also apply to providers and deployers outside the EU where the system’s output is used in the Union. The Commission’s AI Act scope page sets out the territorial rules.

A foreign group should map the role of each entity rather than treat “the company” as a single actor.

Business positionTypical example in RomaniaCore question
ProviderA group develops a recruitment tool and releases it under its own name.Who controls development, intended purpose and market placement?
DeployerA Romanian subsidiary uses a third-party CV-screening or productivity tool under its authority.Who decides how the system is used and on whom?
ImporterAn EU entity first places a third-country AI system on the Union market.Who brings the system into the EU supply chain?
DistributorA reseller makes an AI system available in the EU without being the provider or importer.Does the reseller alter the system, branding or intended purpose?
Provider by reclassificationA business substantially modifies a system, changes its intended purpose or markets it under its own name.Has the business assumed provider obligations despite buying the original tool?

Contracting with a US or other non-EU vendor does not automatically transfer the Romanian deployer’s responsibilities. Conversely, white-labelling, materially modifying or repurposing a tool may move a company into the provider role.

Which AI Uses Should a Company Classify First?

Start with the intended use and its effect on people, then identify the company’s role. Product labels such as “AI-powered” or “assistant” are not a legal classification.

An operational inventory can use four screening groups, but the legal analysis should remain tied to the Act:

  • Prohibited practices: uses that must not be deployed, subject to narrow statutory exceptions.
  • High-risk systems: Annex III uses and certain AI safety components or regulated products, subject to the revised future dates.
  • Article 50 systems: interactive or generative uses and certain emotion-recognition, biometric or synthetic-content uses with transparency duties.
  • Other AI systems: systems outside those rules may still be subject to AI literacy, GDPR, consumer, employment, intellectual-property, confidentiality and sector-specific law.

This last point matters. “Minimal risk” does not mean “no compliance”. A low-impact writing assistant may still require staff guidance, data controls and human review.

Which Workplace AI Uses Are Already Prohibited?

An employer must not infer workers’ emotions through AI except where a narrow medical or safety exception applies. Other Article 5 prohibitions may also affect workplace or customer systems.

The Commission identifies prohibited practices including manipulative or exploitative AI, certain social scoring, certain biometric categorisation, untargeted facial-image scraping, individual predictive policing based solely on profiling, and emotion recognition in workplaces and education, subject to specific exceptions. The AI Omnibus also added a prohibition targeting AI that generates non-consensual sexually explicit or intimate content and child sexual abuse material. See the Commission’s prohibited-practices guidance.

For employers, the label used by a vendor is not decisive. A video-interview tool, wellness platform or workforce-monitoring service may claim to detect engagement, stress, attitude or sentiment without calling the function “emotion recognition”. Review the actual inputs, inferences and purpose.

A professional contract signing session in a modern office
Structuring vendor relationships: clear contracts and allocation of roles are essential for compliance when using third-party AI tools.

What Transparency Duties Apply from 2 August 2026?

Article 50 applies to specified uses regardless of whether the system is high-risk. The duty depends on whether the company is the provider or deployer and on the type of interaction or output.

The Commission published final Article 50 transparency guidance in July 2026.

SituationResponsible actorRequired control
AI system directly interacts with a personProviderDesign the system so the person is informed from the first interaction, unless the AI interaction is obvious under the restrictive exception.
Generative AI produces synthetic text, image, audio or videoProviderApply effective, interoperable, robust and reliable machine-readable marking, subject to statutory exceptions and technical feasibility.
Emotion recognition or biometric categorisation is used lawfullyDeployerInform exposed natural persons at first exposure and comply with applicable data-protection law.
AI generates or manipulates a deepfakeDeployerClearly disclose that the content is artificially generated or manipulated; a machine-readable mark alone is insufficient.
AI-generated text informs the public on a matter of public interestDeployerLabel the text unless it received substantive human review or editorial control and a person holds editorial responsibility.

Does a Customer-Facing Chatbot Need a Disclosure?

Usually, the system should inform a person at the start of the first interaction that they are interacting with AI, unless this is obvious to a reasonably well-informed, observant and circumspect person. The provider bears the design obligation. A business deploying a third-party chatbot should nevertheless verify that the notice is implemented in its actual interface and allocate responsibility in the contract.

Must AI-Assisted Business Content Be Labelled?

Not every AI-assisted text requires a public label. Article 50 focuses on text published to inform the public on matters of public interest. The Commission states that substantive human review or editorial control, together with editorial responsibility, can qualify for an exemption. Spell-checking, formatting or superficial approval is not enough.

For images, audio and video, a deployer must separately assess whether the output is a deepfake. Where disclosure is required, it must be clear to people at first exposure; embedded technical metadata alone does not satisfy the deployer’s obligation.

Is There a Grace Period?

The Commission confirms a narrow grace period only for providers’ machine-readable marking obligation for generative AI systems placed on the market before 2 August 2026. Those systems must comply from 2 December 2026. Content generated before 2 August 2026 need not be labelled retroactively. Other Article 50 duties do not receive a general grace period.

Legal compliance documents and checklists on a desk
Detailed documentation is key: companies must keep records of AI literacy programs and Article 50 transparency notices.

What Must Employers Know About Recruitment and Employee-Management AI?

Recruitment and worker-management AI remains a priority compliance area, but the principal Annex III high-risk duties now apply from 2 December 2027.

The AI Act’s Annex III lists systems intended to:

  • place targeted job advertisements;
  • analyse and filter applications;
  • evaluate candidates;
  • make decisions affecting work terms, promotion or termination;
  • allocate tasks based on behaviour, traits or characteristics; or
  • monitor and evaluate worker performance or behaviour.

Some listed systems may fall outside high-risk treatment if they do not create a significant risk and satisfy Article 6(3), for example because they perform a narrow procedural or preparatory task and do not materially influence a decision. Systems that profile natural persons remain high-risk. Providers relying on an exclusion must document the assessment. As of 31 July 2026, the Commission’s detailed high-risk classification guidelines were still in draft following consultation.

What Duties Arrive in December 2027?

Depending on role and use, the high-risk regime includes risk management, data governance, technical documentation, record-keeping, information for deployers, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment, registration, post-market monitoring and incident reporting.

Deployers must follow instructions, assign competent human oversight, monitor operation, retain logs under their control, and use relevant and sufficiently representative input data where they control those inputs. Employer deployers must inform workers’ representatives and affected workers before putting a high-risk workplace system into service or use, in accordance with applicable law.

The delay should be used to obtain the documentation and contractual rights that cannot be created at the end of procurement.

What Does AI Literacy Require After the AI Omnibus?

AI literacy remains a legal obligation. The AI Omnibus removed the idea that every person must reach a prescribed “sufficient” level, but providers and deployers must still take measures that support staff and other operators in using AI appropriately.

Article 4 has applied since 2 February 2025. The Commission’s updated AI literacy questions and answers recommend a risk-based approach that considers the organisation’s role, the systems used, staff knowledge and the people affected.

There is no mandatory certificate or prescribed course. A defensible programme may include:

  • an approved-AI-tools register;
  • role-based training for management, HR, procurement, IT, marketing and ordinary users;
  • rules on personal, confidential and privileged information;
  • verification requirements for AI output;
  • escalation for high-impact decisions;
  • specific human-oversight training for high-risk systems; and
  • internal records of training and guidance.

Reading a vendor’s instructions may be insufficient, particularly where human oversight or affected persons’ rights are at stake. The Commission states that supervision and enforcement of Article 4 begins on 3 August 2026.

How Does the AI Act Interact with GDPR and Employment Law?

AI Act compliance does not replace data-protection or employment compliance. The same project can trigger several legal regimes at once.

Where an AI system processes candidate, worker, customer or other personal data, the GDPR continues to apply. The company must identify a lawful basis, provide transparent information, observe purpose limitation and data minimisation, manage processors and international transfers, protect data, and assess automated decision-making. A data protection impact assessment may be required where processing is likely to create a high risk.

The European Data Protection Board’s Opinion 28/2024 addresses anonymity, legitimate interests and the consequences of unlawfully processed training data. For a Romania-specific overview, see our guide to GDPR compliance when using AI.

Employment projects also require review of discrimination, monitoring, employee information and consultation, collective arrangements and the validity of decisions under Romanian law. A human approval click does not automatically remove automated-decision or discrimination risk if the human reviewer cannot meaningfully change the outcome.

What Should a Foreign Investor Check in AI Due Diligence?

AI due diligence should test legal role, actual use and evidence—not only whether the target has an “AI policy”.

An investor or buyer of a Romanian business should request:

  1. the AI systems inventory and owners;
  2. provider, deployer, importer and distributor role assessments;
  3. the prohibited-practices review;
  4. Article 50 notices, labels and technical marking evidence;
  5. AI literacy materials and attendance records;
  6. vendor contracts, data-processing agreements, audit rights and change notices;
  7. GDPR records, data protection impact assessments and automated-decision analysis;
  8. the roadmap for Annex III and Annex I systems;
  9. complaints, incidents, regulator correspondence and known bias issues; and
  10. insurance coverage, warranties, indemnities and remediation budgets.

Representations should be tied to disclosed systems and evidence. A generic warranty that the target “complies with all AI laws” is unlikely to identify which party must remediate a specific tool or fund a delayed conformity project.

Who Supervises the AI Act in Romania?

Romania has proposed a multi-authority model, but the final national implementing framework should be checked before any filing or regulator engagement.

In March 2026, the Romanian Government approved a memorandum proposing the National Authority for Management and Regulation in Communications (ANCOM) as market-surveillance authority and single point of contact, with sectoral roles for other bodies including the National Bank of Romania, the Financial Supervisory Authority, the national data-protection authority and the Authority for the Digitalisation of Romania.

ANCOM’s own June 2026 notice describes ANCOM as proposed for that role. The national implementing law was therefore still a point to verify as of this guide’s preparation. GDPR matters remain within the competence of the Romanian data-protection authority, while financial and product-sector regulators may have parallel powers.

What Penalties Can Apply?

The AI Act sets high maximum ceilings, but the actual measure must be effective, proportionate and dissuasive and must reflect the circumstances of the infringement.

The Article 99 penalty framework includes:

  • up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, whichever is higher for undertakings;
  • up to EUR 15 million or 3% for specified operator obligations, including Article 50 transparency duties, whichever is higher for undertakings; and
  • up to EUR 7.5 million or 1% for incorrect, incomplete or misleading information supplied to competent authorities or notified bodies, whichever is higher for undertakings.

For SMEs, including start-ups, the applicable ceiling is the lower of the fixed amount and percentage. Authorities must consider factors such as gravity, duration, harm, company size, cooperation, responsibility, mitigation and intent. These are maximum ceilings, not automatic fines.