negocio · 4 min read
AI Time Tracking: When Your Clock-In System Is 'High-Risk'
A fingerprint reader alone isn't high-risk AI, but a system that flags fraud or predicts absences might be. What the EU AI Act and Spain's AEPD already require.
Most Spanish companies shopping for time-tracking software focus on one thing: does it satisfy RD-ley 8/2019, the law requiring a verifiable daily record of every employee’s clock-in and clock-out. Meanwhile, more vendors are bolting “AI” onto that same product — fraud detection on punch patterns, absenteeism prediction, face recognition instead of a badge — without anyone asking whether that changes which rulebook applies. At Evicron, an AI and custom software studio based in Barcelona, this is exactly the question that gets skipped when we review tools for clients: not “does it log hours correctly,” but “what kind of AI system is this, under EU law.”
A fingerprint reader alone isn’t “high-risk AI”
The EU AI Act classifies as high-risk the Annex III systems covering “employment, workers management and access to self-employment” — a category that explicitly includes systems used to monitor and evaluate the performance and behavior of employees. That’s where many “AI-powered” time-tracking products land without the vendor advertising it: a dashboard that scores punctuality, flags “suspicious” clock-in patterns, or predicts who’s likely to call in sick isn’t just a clock — it’s a system that influences decisions about people.
The line isn’t automatic, though. A fingerprint or face scanner that only logs a timestamp, without inferring or scoring anything, doesn’t turn the system into Annex III “high-risk AI” — there’s no automated decision about the person. But it does trigger a separate, independent set of rules: the ones governing biometric data.
Biometrics don’t wait for the AI Act — Spain’s AEPD already covers them
Spain’s data protection authority, the AEPD, published a dedicated guide on biometric attendance-control systems that’s already in force, independent of any AI Act deadline. Its position, in short: fingerprints and face recognition are special-category data, and using them just to clock hours rarely passes the necessity-and-proportionality test against less intrusive options — an NFC card, a PIN, an app. The AEPD has also been explicit that employee consent doesn’t count as a valid legal basis here, because the power imbalance in an employment relationship means it can’t be truly free. In practice, that means a documented impact assessment is required before installing any biometric clock-in system, a point also covered in PwC’s analysis of the AEPD’s criteria.
Three clocks running at once — don’t mix them up
- RD-ley 8/2019 (daily time record): in force since 2019, applies today, unrelated to AI.
- AI Act transparency (Article 50): enforceable since August 2, 2026, and already sanctionable by AESIA, Spain’s AI supervision agency. If your system uses AI to make or suggest decisions about staff, disclosing that is no longer optional.
- Annex III high-risk obligations (including performance monitoring): have a transition period until December 2, 2027 — but that only delays the full paperwork (conformity assessment, documented human oversight), not the need to start classifying the system now.
- Biometrics (AEPD): not tied to any AI Act deadline at all. If you’re already clocking people in by fingerprint or face, the obligation to justify necessity and proportionality applies today.
Four questions to audit your time-tracking system
- Does it capture a biometric scan (fingerprint, face) at every clock-in, or just a card, PIN, or app? If the former, you need the AEPD-required impact assessment before continuing to use it.
- Does any dashboard feature “score,” “flag anomalies,” or “predict” something about a specific person, beyond totaling hours? If so, you’re likely inside Annex III’s employment category.
- Can the vendor document which model it uses and how it reaches those conclusions? If they can’t explain it to you, you won’t be able to explain it to a labor inspector or to AESIA either.
- Is there a less intrusive alternative that would meet the same goal — reliable attendance control — without biometrics or scoring? If so, that’s the one the AEPD expects you to use.
If your company answers yes to the first or second question, it’s not a reason to panic — Annex III allows until 2027 — but it is the moment to start documenting, not to wait for an inspection to find out.
How we approach this at Evicron
We build and maintain QWorker, our own time-tracking software: clock-in from mobile, browser, or a shared NFC reader, with weekly digital signatures and full traceability — no biometrics, no behavioral scoring. That’s a deliberate choice: it satisfies RD-ley 8/2019 without adding a layer of regulatory risk most SMEs neither need nor want to manage.
If your company already uses — or is evaluating — biometric clock-in or an anomaly-detection dashboard, our AI consulting service starts by reviewing what kind of system you actually have under the AI Act and AEPD rules, before recommending whether to keep it, adjust it, or replace it. We cover the related regulatory landscape in more depth in our guides on what AESIA does and how it fines companies and on the full AI Act risk-level breakdown.
The takeaway
Not every “AI-powered” time-tracking system is high-risk, but none is neutral by default either: if it scores, flags patterns, or predicts an employee’s behavior, it falls under the AI Act’s Annex III employment category; if it uses a fingerprint or face scan, it falls under AEPD rules that already apply today. Assuming “it has AI” means “it’s compliant” is the kind of mistake that’s expensive to catch late.
Want us to check whether your current time-tracking setup — AI or not — sits on the right side of this line? Get in touch: the first consultation is free and we reply within 24 hours.