Skip to main content

Regulation

Emotion Recognition at Work and the Article 5 Prohibitions

Article 5(1)(f) bans inferring emotions in the workplace and in education, and it binds the employer that uses the system as directly as the vendor that supplies it. This guide explains what the prohibition covers, how narrow the medical and safety exception is, where the boundaries are genuinely uncertain, and what to inventory and document first.

Emotion Recognition at Work and the Article 5 Prohibitions

A renewal lands on your desk. The contact centre's quality-assurance platform has a new module: voice analytics scoring each agent's calls for frustration, stress and "empathy". Operations says it will cut coaching time. Nobody has asked whether it is lawful, because the product has sold for years.

This is the shape the Article 5 emotion recognition prohibition almost always takes. It rarely arrives labelled as an emotion recognition system. It arrives as engagement analytics, wellbeing monitoring, sentiment scoring or interview assessment, bolted onto a tool you already own. Unlike most of the Act, it does not wait for a conformity assessment or a harmonised standard: it applies now, it binds the employer as much as the vendor, and it carries the regulation's highest penalty exposure.

What Article 5(1)(f) actually prohibits

The provision bans the placing on the market, the putting into service for that specific purpose, and the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions. The only carve-out is where the system is intended for medical or safety reasons.

Three features of that drafting matter operationally. It prohibits use, not just supply, so buying the tool does not move the risk to the vendor. It is framed by area rather than sector, so a workplace deployment is caught whatever your industry. And the exception turns on the system's intended purpose, not on good intentions recorded in a policy.

The Chapter II prohibitions have applied since 2 February 2025 and the penalty provisions since 2 August 2025. Breach of Article 5 sits in the top band: up to 7% of global annual turnover. Most other AI Act obligations top out at up to 3%, a parallel UK or EU GDPR failure at up to 4%. Designation of national market surveillance authorities has been uneven, which affects how quickly you hear from a regulator, not whether the prohibition binds you.

Who the duty falls on

This is where advisers most often get the Act wrong, so state it plainly to your board: Article 5 binds the deployer directly. Across most of the Act the heavy obligations — technical documentation, risk management, conformity assessment — sit with the provider, and the deployer carries lighter duties under Article 26. Article 5 breaks that pattern. The word "use" catches the employer who switches the module on, even where the vendor built, markets and maintains it.

The provider limb bites separately. If you supply such a system, put your own name or trade mark on a third party's, substantially modify it, or change its intended purpose, you become its provider. That last trigger is the realistic one: an employer that takes a general video-analytics or transcription product and configures it to score staff emotional state has changed the intended purpose and can be treated as the provider, not merely the user. For the prohibition itself the distinction changes nothing — both routes are unlawful — but it decides who owes the surrounding duties on any related deployment that is high-risk rather than prohibited.

Note the asymmetry. A vendor selling a general sentiment tool not marketed for workplace use may not breach the "placing on the market" limb at all, while the customer who points it at employees breaches the "use" limb. Vendor comfort language is weak evidence for you.

What counts as inferring emotion, and what does not

The Act defines an emotion recognition system as one identifying or inferring emotions or intentions of natural persons on the basis of their biometric data. The recitals treat emotions as states such as happiness, anger, surprise, shame or contempt, and put physical states such as pain or fatigue outside the concept, along with detection of an expression or gesture from which no emotional inference is drawn. The Act's definition of biometric data is broader than the familiar GDPR framing: it does not require unique identification, and behavioural characteristics can qualify.

One honest caveat: Article 5(1)(f) speaks of systems that infer emotions without repeating the word biometric, though the definition and recitals use it. A regulator could take the wider reading. Treat a purely textual system as lower risk, not safe.

DeploymentLikely positionReason
Camera scoring meeting participants for engagementProhibitedBiometric inference of emotion at work; a wellbeing rationale is not a medical or safety reason
Voice analytics scoring the agent's stress on callsProhibitedThe agent is in the workplace and the inference is drawn from voice
Voice analytics scoring only the customer's sentimentNot caught hereThe customer is not in a workplace; expect high-risk classification and a duty to inform those exposed
Drowsiness detection for drivers or machine operatorsOutside the conceptPhysical state, not emotion; a safety purpose applies in any event
Sentiment analysis of free-text survey answersUncertain, lower riskNo biometric input on the usual reading, but the wider reading is arguable
Keystroke or mouse-dynamics "stress" scoringUncertain, treat as in scopeBehavioural characteristics can be biometric data under the Act

The medical and safety exception is narrower than it sounds

The exception attaches to the system's intended purpose, and the recitals frame it restrictively. Therapeutic use, or a system genuinely put in place to protect a person from physical harm, is the target. A burnout dashboard or a duty-of-care narrative attached to a productivity tool is unlikely to qualify: neither is medical treatment, and neither protects against a safety hazard in the sense the provision contemplates. If you rely on the exception, document the case before deployment and make sure it survives the question "what physical harm does this prevent, and how?"

The layer underneath: data protection and employment law

Even where the AI Act does not bite — a purely textual tool, or a customer-facing deployment — the same project usually fails elsewhere. Emotion inference from images or voice engages special category analysis under UK and EU GDPR, and in an employment relationship consent is rarely a viable lawful basis because of the imbalance of power. The ICO has publicly cautioned that emotion analysis technologies are immature and may not work as claimed, which undermines any necessity and proportionality argument in a DPIA. Scores feeding performance management also create indirect discrimination exposure, given documented variation in expression across cultures and among disabled and neurodivergent staff. In several Member States works council consultation is a precondition, not a courtesy.

Limits of this guidance

This is a general explanation of a prohibition whose boundaries are still being worked out. The Commission has issued guidelines on prohibited practices; they do not bind courts, several interpretive questions above are genuinely open, and enforcement practice has barely formed. Nothing here is a determination about a particular product or deployment.

Take specialist legal advice before deploying or continuing any system that infers emotional state at work or in education; before relying on the medical or safety exception; where a deployment spans Member States with differing consultation regimes; and where you may have crossed from deployer to provider. Where a deployment may already be unlawful, the decision to continue belongs to senior management with legal input, not a configuration review.

  • AI Act
  • Article 5
  • Prohibited Practices
  • Emotion Recognition
  • Workplace Monitoring
  • Deployer Obligations

More guides

Start Free AI Compliance Review