ISHIGHRISK AI
Analysis

When is emotion recognition banned, and when is a notice enough?

Article 50(3) has applied since 2 August 2026 and binds the deployer. In the workplace and in education, Article 5(1)(f) prohibits the same system.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 50(3) has applied since 2 August 2026 and it binds the deployer, not the vendor: anyone running an emotion recognition or biometric categorisation system must tell the people exposed that it is operating. Two gates in Article 3(39) decide whether a product is caught, an inference of emotion or intention rather than the detection of an expression, and biometric data rather than text. Who is in front of the camera then decides the regime: the same tone model owes a notice at 15,000,000 euro or 3 percent when it reads a customer, and is prohibited under Article 5(1)(f) at 35,000,000 euro or 7 percent when it reads an employee or a student, or, on the Commission's reading of workplace, a job candidate.

What Article 50(3) requires, and who owes it

Article 50(3) is one sentence, and it lands on one party: "Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable."

Article 3(4) defines the deployer as a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the system is used in the course of a personal non-professional activity. The duty attaches to the retailer running the camera, the venue, the call centre and the games studio, not to the company that built the model. Article 50 changes hands halfway through: 50(1) and 50(2) bind providers, 50(3) and 50(4) bind deployers, as the provider and deployer page sets out.

What has to be said is narrow. The Commission's draft guidelines on Article 50 read the duty as informing people that a system of that kind is being operated and that they are exposed to it, and record that the AI Act does not require information about the reasons for its operation. It runs to everyone exposed, including children, in real time or ex post, so a recording analysed a week later is still an exposure. Art 50(3)

The data protection clause in the second half of the sentence is a cross-reference, not a licence. The draft guidance is explicit that the information obligation "does not, in itself, render the use of an emotion recognition and biometric categorisation system lawful. Nor does it legitimise intrusive or discriminatory uses that might be unlawful and prohibited under Article 5 AI Act or other Union law." Article 50(6) makes the same point structurally, preserving Chapter III and other Union or national transparency law alongside Article 50.

The duty applied from 2 August 2026, three days ago, along with the rest of what lands on that date. Breach sits in the Article 99(4)(g) tier, 15,000,000 euro or 3 percent of total worldwide annual turnover, whichever is higher.

On the guidance quoted here. Two Commission documents are cited below, at different stages. The guidelines on prohibited AI practices were published on 4 February 2025 and are adopted. The Article 50 transparency guidelines, drawn up under Article 96(1)(d), exist as the draft published on 8 May 2026 for a consultation that closed on 3 June 2026. Neither binds anyone: the Commission reserves authoritative interpretation to the Court of Justice.

Is it an emotion recognition system? Article 3(39) and the biometric-data gate

Almost nothing caught by Article 50(3) is sold as emotion recognition. It is sold as engagement analytics, agent assist, wellbeing monitoring or audience measurement. The label decides nothing, Article 3(39) does, and it sets two cumulative gates: an emotion recognition system is "an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data".

Gate one: identifying or inferring emotions or intentions. Intentions sit in the definition alongside emotions, which makes Article 3(39) wider than the Article 5(1)(f) prohibition, whose text covers emotions only. A system that infers what a person means to do next, from biometric data, is caught even though the word emotion never appears in the product brief.

Gate two: on the basis of biometric data. This gate decides most real audits. The Commission's guidelines on prohibited practices put it plainly: "An AI system inferring emotions from written text (content/sentiment analyses) to define the style or the tone of a certain article is not based on biometric data and therefore does not fall within the scope of the prohibition." By contrast, "An AI system inferring emotions from key stroke (way of typing), facial expressions, body postures or movements is based on biometric data". Article 3(34) sets the outer edge: biometric data is personal data from specific technical processing of the physical, physiological or behavioural characteristics of a natural person, so voice, gait, keystroke dynamics and eye movement can all qualify.

So the same "sentiment" feature is in or out depending on which pipe it reads. Scoring a chat transcript, an email thread or a support ticket is text analysis and sits outside Article 3(39) altogether, while tone scoring of the audio of that same conversation is inference from voice and sits inside it. Only the input changes the answer.

What falls outside the definition: recital 18 on expressions and physical states

Recital 18 draws the outside line, and it draws it three times. In scope are "emotions or intentions such as happiness, sadness, anger, surprise, disgust, embarrassment, excitement, shame, contempt, satisfaction and amusement". Out are physical states: "It does not include physical states, such as pain or fatigue, including, for example, systems used in detecting the state of fatigue of professional pilots or drivers for the purpose of preventing accidents." Also out is "the mere detection of readily apparent expressions, gestures or movements, unless they are used for identifying or inferring emotions", illustrated with a frown, a smile, hand or head movements, and a raised or whispering voice.

The Commission compresses the test into a pair of examples: observing that a person is smiling is not emotion recognition, while concluding from that smile that the person is happy is. Detection of the signal is not inference of the state. A dashboard that starts by counting smiles and ends by reporting a mood score has changed sides without changing a camera. The Commission treats these carve-outs as governing Article 5(1)(f) too, so it is one line in both regimes.

Feature What it reads In scope of Art 3(39) Why
Counting how often a presenter smiles to camera Facial expressions, counted No Recital 18: mere detection of a readily apparent expression
Reporting from that footage that the presenter is happy Facial expressions, inferred state Yes Art 3(39): an emotion inferred from biometric data
Fatigue detection that suggests a driver takes a break Eyelid and head movement No Recital 18 excludes physical states, and names driver fatigue
Sentiment scoring of a support ticket Written text No Art 3(39) requires biometric data, and text is not
Tone scoring of the audio of that conversation Voice Yes Voice is behavioural biometric data
Frustration inferred from typing rhythm Keystroke dynamics Yes Keystroke patterns are biometric data

Biometric categorisation reaches further than the high-risk rules

Article 50(3) covers a second family of systems, and its definition carries its own exception. Article 3(40): a biometric categorisation system is "an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons". The ancillary carve-out sits inside the definition, not inside Article 50, so a system that meets it is not a biometric categorisation system at all for any purpose in the Act.

Recital 16 lists the categories reached, "sex, age, hair colour, eye colour, tattoos, behavioural or personality traits, language, religion, membership of a national minority, sexual or political orientation", and gives two worked examples of the carve-out: marketplace filters that let a consumer preview a product on themselves, and social network filters that categorise facial or body features so users can modify pictures. The conditions are strict: the feature must be one that "cannot, for objective technical reasons, be used without the principal service" and must not be "a means to circumvent the applicability of the rules", so anything that could run as a standalone product is outside the carve-out.

Then the asymmetry that catches teams who worked the high-risk annex first. Annex III point 1(b) makes biometric categorisation high-risk only where it operates "according to sensitive or protected attributes or characteristics based on the inference of those attributes or characteristics". Article 50(3) has no such qualifier. The draft Article 50 guidelines read it the same way, as applying to any biometric categorisation system, age or gender classification included, "regardless of whether they fall or not in the scope of high-risk AI systems", unless the practice is prohibited by Article 5(1)(g).

So an age-estimation camera in a shop window is not high-risk and still owes the notice today. Above both sits Article 5(1)(g), which prohibits biometric categorisation that individually categorises natural persons on the basis of their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, with a narrow exception for labelling or filtering lawfully acquired datasets. One technology, three tiers, and the attribute inferred decides which one applies.

Prohibited in one room, notifiable in the next

Article 5(1)(f) prohibits "the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons". It has applied since 2 February 2025 under Article 113, third paragraph, point (a). Recital 44 gives the reason, "the imbalance of power in the context of work or education, combined with the intrusive nature of these systems", and reads the exception narrowly: the prohibition should not cover systems placed on the market strictly for medical or safety reasons, "such as systems intended for therapeutical use".

The Commission's guidelines extend the word workplace to the point before employment starts. The prohibition, they reason, should also be understood to apply to candidates during the selection and hiring process, because the power imbalance and the intrusive nature of emotion recognition may already apply at the recruitment stage. The worked examples are unequivocal: emotion recognition during recruitment and during the probationary period is prohibited, as is monitoring emotional tone in hybrid work teams from the voice and imagery of video calls. In education, inferring the interest and attention of students is prohibited. That is the Commission's reading rather than the text's, and it does not bind, but it is where a market surveillance authority starts.

The mirror image is the other half of the same call. The Commission states that emotion recognition used in a commercial context for addressing customers does not fall under Article 5(1)(f), and that a call centre tracking its customers' emotions, such as anger or impatience, from their voices is not prohibited by that point. It adds one residual check: Article 5(1)(a) and (b) on manipulation and exploitation may still catch such practices.

Use Whose emotions are inferred Regime Ceiling
Scoring a candidate's expressions in a video interview Job candidate Prohibited, Art 5(1)(f) as the Commission reads it 35,000,000 euro or 7%
Emotional tone monitoring across hybrid team calls Employees Prohibited, Art 5(1)(f) 35,000,000 euro or 7%
Inferring interest and attention in a classroom Students Prohibited, Art 5(1)(f) 35,000,000 euro or 7%
Tone analysis of the customer on a support call Customers Notice owed, Art 50(3) 15,000,000 euro or 3%
Tone analysis of the agent on that same call Employee Prohibited, Art 5(1)(f) 35,000,000 euro or 7%
A therapeutic device inferring a patient's state Patients Medical exception in Art 5(1)(f), notice still owed under Art 50(3) 15,000,000 euro or 3%

The notice is therefore the last question, not the first. A team that opens with "what should the disclosure say" on a workplace or education case has skipped the step that decides whether the practice is available at all, and the gap is 4 percentage points of global turnover. Run the case through the seven-stage triage first, then the detail on recruitment and HR and education.

How the notice has to land, and the law enforcement carve-out

Article 50(5) sets the manner for the whole of Article 50: the information "shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", and must conform to the applicable accessibility requirements.

The draft Article 50 guidelines add a negative test worth more than any definition of clarity: information is not clear and distinguishable where it can easily be overlooked or missed, and the draft names three ways that happens, a manual, layers of menu options, or terms of use that are often not read. The accessibility instruments named are Directives (EU) 2016/2102 and (EU) 2019/882. For placement it offers two examples worth copying: a centrally placed pop-up before a game launches, and a visible notice at each entrance to an exhibition room.

First exposure is not first interaction with a screen. Article 50(1) has an interface to attach a notice to. Article 50(3) often does not, because the person walks into a room or picks up a telephone. A notice shown when a customer later opens an app is too late if a camera categorised them at the door.

The exception is drafted differently from the rest of Article 50. Its second sentence disapplies the duty for systems "permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, and in accordance with Union law". Two things differ from the equivalent carve-outs in 50(1), 50(2) and 50(4): it says permitted by law rather than authorised by law, and it lists detect, prevent or investigate, omitting prosecute.

The draft guidance treats the first difference as deliberate: the other exceptions in Article 50 require an explicit law authorising the non-transparent use, whereas 50(3) is available where the legal rules governing the powers of law enforcement authorities permit the use without informing the persons concerned, subject to appropriate safeguards. The safeguards limb is not decorative, and the carve-out is written around the powers of law enforcement authorities: a private security operator is not inside it because footage might one day interest the police.

The second wave: Annex III point 1 and 2 December 2027

A deployer can owe the notice today and a full Chapter III obligation set sixteen months from now for the same system. Annex III point 1 is headed "Biometrics, in so far as their use is permitted under relevant Union or national law" and has three limbs: (a) remote biometric identification, excluding one-to-one verification; (b) biometric categorisation according to sensitive or protected attributes; and (c) "AI systems intended to be used for emotion recognition". Point 1(c) carries no qualifier, so any emotion recognition system that survives Article 5 is high-risk on the face of the annex.

Regulation (EU) 2026/1744 changed when that regime starts, not what is in it. Under the amended Article 113 the high-risk obligation set applies from 2 December 2027 to standalone Annex III systems classified under Article 6(2), and from 2 August 2028 to AI embedded in Annex I products under Article 6(1). From that first date the deployer picks up the Article 26 duties and, for the deployers Article 27 names, a fundamental rights impact assessment, while the provider picks up the Articles 9 to 15 requirements, conformity assessment under Article 43 and registration under Article 49. That stack is set out on the high-risk systems page and, in plainer terms, in what high-risk actually means.

The Article 6(3) derogation is the route out of the annex and it is not a self-certification. Two things have to hold at once: no significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of four listed conditions. Notwithstanding that, an Annex III system "shall always be considered to be high-risk where the AI system performs profiling of natural persons". Article 6(4) requires the assessment to be documented before placing on the market, with registration under Article 49(2). The Article 6(3) page works through the conditions.

2 Dec 2027 The high-risk obligations apply to standalone Annex III systems, including emotion recognition under point 1(c) and sensitive-attribute biometric categorisation under point 1(b).

Beyond that date, the Digital Omnibus, Regulation (EU) 2026/1744, left this area alone. Its Article 5 change was a ninth prohibition, on AI generating child sexual abuse material or non-consensual intimate imagery, applying from 2 December 2026 and saying nothing about point (f), and it left the Annex III use areas alone. So the definitions in Article 3(39) and 3(40), the prohibition in Article 5(1)(f), the duty in Article 50(3) and Annex III point 1 all stand as enacted, and the Article 99 tiers on the penalties page are unchanged.

One technology, three dates: 2 February 2025 for the prohibition, 2 August 2026 for the notice, 2 December 2027 for Annex III point 1(c).

So inventory by input rather than by product name, listing every feature that reads a face, a voice, a posture, a gaze or a typing pattern. For each, record whether it infers a state or merely detects a signal, and whether the input is biometric data or text, with the reasoning written down at the time. Then sort what survives by who is in front of the sensor. The remaining limbs of the transparency article are mapped on the Article 50 page.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Is emotion recognition AI banned in the EU?

Only in two settings. Article 5(1)(f) prohibits the placing on the market, the putting into service for that specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the system is intended to be put in place or into the market for medical or safety reasons. That prohibition has applied since 2 February 2025 under Article 113, third paragraph, point (a). Everywhere else emotion recognition is not prohibited, it is notifiable: Article 50(3) requires the deployer to inform the people exposed that the system is operating, and the high-risk obligations that follow from Annex III point 1(c) apply from 2 December 2027. The setting, not the technology, decides which regime applies.

Can we use emotion analysis in video job interviews?

No. The Commission's guidelines on prohibited practices, published on 4 February 2025, read the word workplace in Article 5(1)(f) as reaching candidates during the selection and hiring process, on the basis that the power imbalance and the intrusive nature of the technology already apply at the recruitment stage. They treat emotion recognition during recruitment as prohibited, and say the same of the probationary period. That places the practice in the top penalty tier under Article 99(3), up to 35,000,000 euro or 7 percent of total worldwide annual turnover, whichever is higher. No notice cures it, and the draft Article 50 guidance is explicit that the information duty does not, in itself, make a use lawful. The guidelines are non-binding, so this reading is the Commission's rather than the text's.

Is sentiment analysis covered by the EU AI Act?

It depends on what the model reads. Article 3(39) defines an emotion recognition system as one that identifies or infers emotions or intentions of natural persons on the basis of their biometric data, so the input decides. The Commission's guidelines on prohibited practices state that a system inferring emotions from written text, meaning content or sentiment analysis, is not based on biometric data and so falls outside the prohibition, and the same gate sits in the definition itself. Scoring the sentiment of a chat transcript, an email or a support ticket is therefore not emotion recognition under the Act. Running the same inference on the audio of a call is, because voice is behavioural biometric data, as are keystroke patterns, gait and eye movement. One feature, two answers, decided by the medium.

What do you have to tell people under Article 50(3)?

That an emotion recognition or biometric categorisation system is being operated and that they are exposed to it. The Commission's draft Article 50 guidelines, published on 8 May 2026, read the duty as not requiring information about the reasons for the system's operation, although data protection law may. Article 50(5) sets the manner: clear and distinguishable, at the latest at the time of the first interaction or exposure, and conforming to the applicable accessibility requirements, which that draft identifies as Directives (EU) 2016/2102 and (EU) 2019/882. Information that can easily be overlooked, buried in a manual, hidden under menu layers or folded into terms of use, does not meet that bar. The duty runs to everyone exposed, including children, whether the analysis is live or run on a recording afterwards.

Is driver drowsiness detection emotion recognition under the AI Act?

No. Recital 18 excludes physical states from the definition and names this example directly: emotion recognition does not include physical states such as pain or fatigue, including systems used in detecting the state of fatigue of professional pilots or drivers for the purpose of preventing accidents. The Commission repeats the point in its guidelines on prohibited practices, treating a system that detects fatigue and suggests a break as outside emotion recognition. On that ground the system sits outside Article 5(1)(f), outside Article 50(3) and outside Annex III point 1(c). The exclusion is about physical state, so a system that goes on to infer frustration or anger from the same camera feed is back inside Article 3(39).

Is age or gender estimation from a camera high-risk under the AI Act?

Not on that basis. Annex III point 1(b) catches biometric categorisation only where it works according to sensitive or protected attributes or characteristics based on the inference of those attributes, so estimating an age bracket or a gender from biometric data is not high-risk under that limb. Article 50(3) still applies, because it carries no equivalent qualifier, and the Commission's draft Article 50 guidelines read it as covering any biometric categorisation system, unless the practice is prohibited under Article 5(1)(g), regardless of whether it falls within the scope of high-risk systems. A shop-window screen estimating the age of passers-by therefore owes the notice now, without owing the Chapter III obligation set. Emotion recognition is different, because Annex III point 1(c) carries no qualifier at all.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.