Reglog

← Guides & analysis

Is AI emotion recognition banned in the EU? What Article 5(1)(f) actually prohibits at work

· 17 min read

If your company runs sentiment scoring on sales calls, "engagement" analytics on video meetings, webcam-based attention tracking in training, or an AI that flags when an agent sounds frustrated, this is the provision to read first. Not because it is new — because it has applied since 2 February 2025, it sits at the AI Act's highest fine tier, and since 2 August 2026 the AI Act's market surveillance chapter has applied in full, giving national authorities its investigation and corrective-action powers.

It is also narrower than the headlines and wider than the vendor decks. Both errors are expensive.

This page covers point (f) only. For the full list of prohibited practices, including the two the Digital Omnibus adds from 2 December 2026, see EU AI Act prohibited practices (Article 5).

This is an information service to help you plan, not legal advice. To see the obligations that attach to your own AI use, answer three questions about it.

The short answer

Article 5(1)(f) of the AI Act prohibits:

"the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons"

The Commission's guidelines treat the conditions as cumulative. Restated for practical use, all four of these must be true, and the medical-or-safety exception must not apply:

# Condition Where the real arguments happen
1 Placing on the market, putting into service for this purpose, or use Catches providers and deployers alike
2 An AI system that infers emotions or intentions Not the same as detecting a smile, or pain, or fatigue
3 Inference drawn from biometric data The gate most cases turn on
4 In the areas of workplace or education institutions Read very broadly — including recruitment

Miss any one of the four and Article 5(1)(f) does not apply — but what follows depends on which one you miss. A system that still infers emotions or intentions from biometric data, and escapes only on the setting (pointed at customers rather than staff, say), is an emotion recognition system: as a rule, it lands in the high-risk tier instead, which is covered further down. A system that fails condition 2 or 3 — fatigue detection, say, or sentiment scoring of written text — is not an emotion recognition system under Article 3(39) at all, so neither Annex III point 1(c) nor the emotion-recognition duty in Article 50(3) reaches it. That is still not the same as unregulated: other Annex III listings, such as monitoring and evaluating workers' performance and behaviour under point 4(b), can apply, and data protection and employment law still do.

The question that decides most cases: is it biometric?

Article 3(39) defines an emotion recognition system as one that identifies or infers emotions or intentions on the basis of biometric data. The prohibition in Article 5(1)(f) is worded differently — it refers simply to "AI systems to infer emotions" — but the Commission reads the biometric limit across into the prohibition, "for consistency reasons", so that Article 5(1)(f) has a similar scope to the rules on emotion recognition systems in Annex III point 1(c) and Article 50(3).

Article 3(34) then defines biometric data broadly: personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a person. Note "behavioural" — this is wider than the everyday sense of "biometric", and wider than the GDPR definition, which additionally requires that the data allow or confirm unique identification.

The guidelines work the line through directly:

Signal the system reads Biometric? Inside the prohibition (at work / in education)?
Written text — email, chat transcript, survey free text No No — expressly outside scope
Facial expression, from a webcam or meeting video Yes Yes
Voice characteristics — tone, pitch, prosody Yes Yes
Body posture, gestures, movement Yes Yes
Keystroke patterns — the way a person types Yes Yes
Eye tracking used only for gaze position (e.g. exam proctoring) — No, unless also used to infer emotion

Two practical consequences fall straight out of this table.

Text-based sentiment analysis is not caught by this prohibition. Scoring the tone of a support ticket, a written performance review or an engagement survey does not rest on biometric data. The Commission's example is unambiguous: an AI system inferring emotions from written text "is not based on biometric data and therefore does not fall within the scope of the prohibition". Data protection and employment law still apply, and a works council may still have a view — but Article 5(1)(f) does not.

Voice-based sentiment analysis is caught. This is the one that surprises teams. A great deal of contact-centre tooling sold as "conversation intelligence" or "agent coaching" infers emotional state from vocal characteristics. Applied to your own agents, that is inside the prohibition.

The Commission's guidelines allow one narrow carve-out. It is not in the text of Article 5(1)(f), which names only medical or safety reasons, so treat it as the Commission's non-binding reading: a system deployed only for the employee's personal training is allowed if the results are not shared with HR and cannot affect the person's assessment, promotion or work relationship, provided the prohibition is not circumvented. Emotion scores that reach HR, or that feed a performance review, a QA scorecard or any other assessment of the agent, fall outside that carve-out. A system that fits it is still an emotion recognition system, so the high-risk and Article 50(3) rules below still apply.

"Emotion" is broad — but three things are outside it

Recital 18 lists emotions and intentions "such as happiness, sadness, anger, surprise, disgust, embarrassment, excitement, shame, contempt, satisfaction and amusement". The Commission says the concept "should be understood in a wide sense and not interpreted restrictively", and that the prohibition cannot be circumvented by relabelling emotions as attitudes.

Three categories sit outside:

  1. Physical states — pain and fatigue. Detecting a driver's or pilot's fatigue to prevent an accident is not emotion recognition at all. It fails condition 2 before any exception is needed.
  2. Mere detection of readily apparent expressions, gestures or movements — unless used to infer an emotion. The Commission's paired examples make the line concrete: observing that a person is smiling is not emotion recognition; concluding that a person is happy is. A broadcaster counting how often a news presenter smiles at the camera is not emotion recognition; a system inferring from a frown or the absence of a smile that an employee is unhappy or angry towards customers is.
  3. Identifying whether someone is sick. Also not emotion recognition.

"Workplace" is read very broadly — and it starts at recruitment

The Commission reads "workplace" as any physical or virtual space where people carry out tasks assigned by an employer or an organisation they are affiliated with. That spans offices, factories and warehouses; publicly accessible spaces such as shops, stadiums and museums; open-air sites, vehicles, and temporary or mobile sites. It is independent of employment status — employees, contractors, trainees, volunteers and the self-employed are all covered.

Critically, it reaches people who do not work for you yet:

  • Emotion recognition during the recruitment process is prohibited. The imbalance of power and the intrusiveness of the technique already apply at the hiring stage.
  • Emotion recognition during the probationary period is prohibited.
  • For education institutions, the prohibition likewise applies to candidates during the admissions process.

Worked examples from the guidelines, which map neatly onto real products:

Scenario Position
Call centre uses webcams and voice recognition to track its own agents' emotions, such as anger Prohibited, unless used only for the agent's own training, with results kept from HR and no effect on assessment or the work relationship
Call centre uses voice recognition to track customers' emotions, such as anger or impatience Not prohibited by Article 5(1)(f)
System monitors emotional tone in hybrid work teams from voice and video on calls, to manage team dynamics Prohibited
Supermarket uses cameras to track its employees' emotions, such as happiness Prohibited
Supermarket or bank uses cameras to detect a customer about to commit a robbery, with no employee tracking and sufficient safeguards Not prohibited by Article 5(1)(f)
Emotion recognition used in recruitment or during a probationary period Prohibited
Education institution infers students' interest and attention Prohibited (role-play training, for example of actors or teachers, whose results cannot affect evaluation or certification is allowed)
Emotion recognition app for online language learning, used outside an education institution Not prohibited — but prohibited if an institution requires students to use it

The employee/customer split is the single most useful distinction here for anyone selling or buying this software. A product can fall outside Article 5(1)(f) pointed one way and be prohibited pointed the other, with no change to the code. (Outside point (f) is not automatically in the clear: the guidelines note that customer-facing emotion recognition can still be caught by the manipulation and exploitation prohibitions in Article 5(1)(a) and (b) if all their conditions are met.) If you are the deployer, the direction of the camera or microphone is your compliance decision, not your vendor's.

The medical-or-safety exception is narrower than it sounds

Article 5(1)(f) carves out systems intended for medical or safety reasons. The Commission says this exception "should be narrowly interpreted", and then narrows it hard:

  • Therapeutic uses are to be understood as uses of CE-marked medical devices.
  • The exception does not cover general wellbeing. General monitoring of stress levels at the workplace is not permitted on health or safety grounds. A system intended to detect burnout or depression at work or in education is not covered and remains prohibited.
  • Assessing wellbeing, motivation levels, or job or learning satisfaction does not qualify as a medical reason.
  • "Safety" means life and health only — not protecting property against theft or fraud.
  • Any permitted use must stay strictly necessary and proportionate, limited in time, scale and the people it touches, with safeguards; the necessity is assessed objectively, not by reference to the employer's "needs", and requires asking whether a less intrusive means would achieve the same end.

The Commission's own illustration of the boundary: an employer may not deploy devices measuring employees' anxiety from stress levels, or their boredom — unless the elevated stress or lack of concentration poses a specific danger, such as operating dangerous machinery or handling dangerous chemicals. Even then the data may not be reused for other purposes such as performance assessment.

If your product is marketed on employee wellbeing, engagement or burnout prevention and it reads faces or voices, the exception does not save it.

If you are not prohibited, you are probably high-risk

For a genuine emotion recognition system — one that infers emotions or intentions from biometric data — falling outside Article 5(1)(f) moves you down the risk ladder, not off it. Emotion recognition systems that are not prohibited are, as a rule, high-risk under Annex III, point 1(c) (an Annex III system can escape that classification under the Article 6(3) derogation, but only if it meets that article's conditions — see when an Annex III system is not high-risk). That pulls in the Chapter III Section 2 requirements — risk management, data governance, technical documentation, logging, transparency and instructions for deployers, human oversight, and accuracy, robustness and cybersecurity. Following the Digital Omnibus, those obligations apply to Annex III systems from 2 December 2027. Because emotion recognition sits in Annex III point 1 (biometrics), it is also the one Annex III area where Article 43(1) can make a notified body mandatory — for instance where the provider has not applied harmonised standards or common specifications in full — see do you need a notified body?.

Separately and sooner, Article 50(3) requires deployers of an emotion recognition or biometric categorisation system to inform the people exposed to it, and to process the personal data in line with the GDPR. That duty has applied since 2 August 2026. See what Article 50 requires in full.

And if you are an employer deploying a high-risk AI system at the workplace, Article 26(7) obliges you — for Annex III systems, from 2 December 2027 — to inform workers' representatives and the affected workers before you put it into service or use it. For the rest of what a deploying employer owes, see EU AI Act deployer obligations. Two more things worth knowing:

  • Article 2(11) lets Member States keep or introduce rules more favourable to workers, and allows more protective collective agreements. The Commission notes that a Member State could, for instance, legislate that emotion recognition may not be used at work even for medical purposes. So a clean EU-level analysis is a floor, not a ceiling. Check national employment law and any collective agreement that applies to you. National AI Act implementing laws are a separate layer: Germany's KI-MIG, for example, names the Bundesnetzagentur as the default market surveillance authority and sets the fine rules.
  • Emotion recognition is not the only AI Act issue in HR tooling. Recruitment and workforce-management systems have their own Annex III exposure — see the EU AI Act for HR and recruitment software.

Dates and money

Date What it means for Article 5(1)(f) Source
2 Feb 2025 The prohibition applies. Chapters I and II applied from this date Article 113, third para, point (a)
2 Aug 2025 Penalty ceilings apply. Chapter XII applied from this date, except Article 101; each Member State lays down the penalty rules under which fines are imposed (Article 99(1)). Chapter VII (governance), including the duty to designate market surveillance authorities in Article 70, applied from the same date Article 113, third para, point (b)
2 Aug 2026 Chapter IX applies. The AI Act's market surveillance chapter applied on the general date, giving national authorities its powers to investigate, demand documents and order corrective action Article 113, second and third paras
2 Dec 2027 High-risk obligations bite for non-prohibited emotion recognition under Annex III Article 113, third para, point (c)(i), as amended

The sequence is worth internalising, and one part of it is not settled. The rule has bound you since 2 February 2025. The AI Act's governance and penalty chapters, including the duty on Member States to designate market surveillance authorities, have applied since 2 August 2025, and the Commission's guidelines treat that as the date from which those authorities could monitor compliance with the prohibitions; they add that, because the prohibitions have direct effect, affected people could go to national courts and seek interim injunctions even before 2 August 2025. The Act's own market surveillance chapter (Chapter IX), however, applied only from 2 August 2026, so how far an authority could act before then depended on the reading taken and on national law. What is not in doubt: the prohibition itself did not change on 2 August 2026, and the AI Act's enforcement chapters now all apply — with fines imposed under each Member State's own penalty rules. Do not assume conduct between August 2025 and July 2026 is beyond reach.

On amounts, Article 99(3) sets the top tier for Article 5 breaches: up to EUR 35 000 000 or, for an undertaking, 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. Two qualifications that are often stated wrongly:

  • Article 99(6) flips the test for SMEs and start-ups: whichever of the percentage or the amount is lower.
  • The Digital Omnibus inserted a new Article 99(6a) giving the same relief to small mid-cap enterprises (SMCs) — but only for the fines in paragraphs 4 and 5. Paragraph 3, the prohibitions tier, is not in that list. An SMC breaching a prohibition faces the same ceiling as a multinational. For the full fine structure, see how much the EU AI Act can cost you.

A citation worth getting right

Many write-ups cite the Commission's prohibited-practices guidelines as C(2025) 884 final of 4 February 2025. That document is real, but it is a Communication to the Commission approving the content of a draft.

The operative document — the Communication from the Commission, "Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act)" — is C(2025) 5052 final, dated 29 July 2025. That is the version to quote, and the one every passage above is drawn from.

The guidelines are not binding. Only the Court of Justice of the European Union can authoritatively interpret the AI Act. They are, however, the clearest signal available of how the Commission and national authorities will read Article 5 — and Article 99(1) requires Member States to take the Commission's Article 96 guidelines, which include these, into account in laying down and implementing their rules on penalties and other enforcement measures.

What to do now

  1. Inventory anything that reads a face, a voice, a body or a keyboard and produces a judgement about a person's state — including features buried inside meeting tools, contact-centre platforms, proctoring software and HR suites.
  2. For each one, ask these questions in order. Does it infer an emotion or intention, rather than a physical state or a bare expression? Is the inference drawn from biometric data? Is the subject a worker, candidate, trainee or student? Is it genuinely medical or safety, on the narrow reading? If you are relying on the Commission's personal-training carve-out, can you show the results never reach HR or any assessment of the person? Write the answers down — the evidence matters more than the conclusion.
  3. Check the direction of the sensor. Same product, different subject, different legal position. Employee-facing is the risk; customer-facing falls outside point (f) but, as a rule, into the high-risk tier and Article 50(3), and can still be caught by Article 5(1)(a) or (b) if all the conditions of those manipulation and exploitation prohibitions are met.
  4. Re-read your vendor's claims against the biometric gate. "Sentiment analysis" is not one thing. Ask the vendor, in writing, which signals the model consumes.
  5. Check the national layer. Article 2(11) means a Member State or a collective agreement may go further than the AI Act.
  6. Read Article 5 in the amended text, not on a page still showing the 2024 version. The Digital Omnibus added two further prohibitions to Article 5 in July 2026, which apply from 2 December 2026; they do not change point (f), but they do change the list.

Two of these can be settled in an afternoon. The one that takes longest is the inventory — which is often the step that turns up the system nobody remembered buying.

To see which AI Act obligations attach to what you actually run, answer three questions about your AI use and we will show the matching obligations with the article each comes from, sorted by date. If you want to be told when any of them change, join the waitlist. And if you are not yet sure which side of the risk classification your systems fall on, start with is your AI system high-risk? or the broader which obligations apply to your company.

The official text is Regulation (EU) 2024/1689 — Article 5(1)(f), Article 3(34) and (39), Article 50(3), Article 99(3) and (6), Article 113 and Annex III point 1(c), read with Recitals 18 and 44 — as amended by Regulation (EU) 2026/1744, together with the Commission's Guidelines on prohibited artificial intelligence practices (C(2025) 5052 final, 29 July 2025). This article is an information service to help you orient — it is not legal advice.

Frequently asked questions

Is emotion recognition AI banned in the EU?

Not everywhere — but it is banned in two settings. Article 5(1)(f) of the EU AI Act prohibits placing on the market, putting into service for that purpose, or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions, unless the system is intended for medical or safety reasons. The Commission's guidelines also treat a few narrow training-only uses as allowed, where the results cannot affect the person's assessment. Outside those two settings, Article 5(1)(f) does not prohibit it; a biometric emotion recognition system is instead, as a rule, classified as high-risk under Annex III, point 1(c), and carries a transparency duty under Article 50(3). The prohibition has applied since 2 February 2025.

Does the ban cover text sentiment analysis of employee emails or survey answers?

No, on the current Commission reading. The prohibition is limited to inferences drawn from biometric data — data resulting from specific technical processing of a person's physical, physiological or behavioural characteristics. The Commission's guidelines give the direct example that an AI system inferring emotions from written text does not fall within the scope of the prohibition. Inferring emotions from a face, a voice, body posture or even keystroke patterns does fall within it. Other law, including data protection and employment law, still applies either way.

Can we use emotion recognition on customers rather than employees?

Article 5(1)(f) does not prohibit it. The Commission's guidelines state directly that a call centre using voice recognition to track customers' emotions, such as anger or impatience, is not prohibited by Article 5(1)(f) — while tracking the call centre's own employees' emotions is prohibited (outside a narrow personal-training carve-out in the guidelines). But a customer-facing emotion recognition system is, as a rule, high-risk under Annex III, point 1(c), Article 50(3) requires you to inform the people exposed to it, and the guidelines note it can still be caught by the manipulation and exploitation prohibitions in Article 5(1)(a) and (b) if all their conditions are met. Not prohibited by point (f) is not the same as unregulated.

Is AI that monitors employee stress, burnout or fatigue banned?

It depends on what it infers and why. According to the Commission's guidelines, detecting a physical state such as fatigue — for example to prevent a driver's or pilot's accident — is not emotion recognition at all. But the medical-or-safety exception in Article 5(1)(f) is read narrowly: general monitoring of stress levels at the workplace is not permitted on health or safety grounds, and a system intended to detect burnout or depression at work remains prohibited if it reads faces or voices. The guidelines accept a specific danger, such as operating dangerous machinery, as a possible safety reason, and even then the data may not be reused for purposes such as performance assessment.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.