What the EU AI Act Actually Bans, and Why Practitioners Keep Getting it Wrong

Picture of Dr Lisa Turner

Dr Lisa Turner

World renowned visionary, author, high-performance mindset trainer for coaches to elevate skills, empower clients to achieve their maximum potential

A client asks whether the app her employer has introduced is something she should worry about. A consultant wants to know which conversation-analysis tool you would recommend to an organisation trying to get ahead of a harassment problem. A colleague asks whether the thing advertising itself to her clients as manipulation detection is legitimate.

These questions arrive constantly now, and the honest answer for most practitioners is that they do not know. That is uncomfortable, because the people asking are often in situations where a wrong recommendation carries real consequences.

European law settled a good deal of this some time ago. Most of the practitioner world has either missed it or, more commonly, has half-heard it and drawn the wrong conclusion.

The rule everyone half-knows

Article 5(1)(f) of the EU AI Act prohibits the use of AI systems to infer the emotions of a person in workplaces and education institutions, with narrow exceptions for medical and safety purposes. It has been in force since February 2025. Breach carries penalties of up to 35 million euros or 7 percent of global annual turnover, whichever is higher, which is the highest tier in the entire Act. Employee consent does not make it lawful. The prohibition is categorical.

That much has circulated reasonably widely. What has not circulated is the definition, and the definition is where all the meaning sits.

The word that decides everything

Article 3(39) defines an emotion recognition system as an AI system for identifying or inferring emotions or intentions of natural persons on the basis of their biometric data.

Biometric data, under Article 3(34), means personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of a person. Facial images. Voice. Fingerprints. Body posture and movement. And, in an example the Commission gives directly, keystroke dynamics, meaning the manner in which somebody types.

So the way you type is regulated. The words you type are not.

The Commission put this beyond argument in its Guidelines on prohibited practices, stating that a system inferring emotions from written text through content or sentiment analysis is not based on biometric data and therefore falls outside the scope of the prohibition.

That single clarification does a great deal of work. A tool that watches an employee’s face during a video call and reports that she seems disengaged is prohibited in an EU workplace. A tool that reads the actual emails she was sent and reports what patterns appear in them is not covered by the prohibition at all. Same broad subject matter, entirely different legal position, because one operates on her body and the other operates on the record.

Why the line falls there

It would be easy to assume the ban is about privacy, and that documented text escaped through some drafting accident. Recital 44 says otherwise, and it is worth reading carefully because the reasoning is unusually candid for a piece of legislation.

The Recital grounds the prohibition in the lack of scientific basis for emotion recognition, together with limited reliability, lack of specificity and limited generalisability. It observes that expression of emotions varies considerably across cultures and situations, and even within a single individual.

That is a legislature stating, in the operative reasoning of a binding regulation, that inferring what a person feels from how their face or voice behaves does not work well enough to be relied upon where power is unequal. The second limb of the reasoning is the power imbalance itself: workers and students occupy structurally vulnerable positions, and an unreliable instrument aimed at them from above produces predictable harm.

Documented communication is not exempted because it is less sensitive. It is outside the prohibition because it raises a different problem. When a system reports on what was written, the underlying claim can be checked. The words exist. The person concerned can read them and argue about what they mean.

The exception that is narrower than people assume

Practitioners advising organisations should know one further detail, because vendors lean on it.

The medical and safety exception is drawn tightly. The Commission’s Guidelines indicate that therapeutic uses should apply only to CE-marked medical devices, and that safety justifications are limited to protecting life and health rather than property or fraud prevention. Most importantly, the Guidelines state that the exception does not extend to general wellbeing monitoring, including stress and burnout detection.

That matters, because wellbeing is precisely the wrapper these products arrive in. A platform offering to monitor employee stress levels from voice or video, positioned as a duty-of-care initiative, is not rescued by the framing. The Guidelines also record that attitude and emotion are treated as equivalent for the purposes of the prohibition, which closes the obvious route of renaming the output.

The test to apply

When somebody asks you about a tool, one question does most of the sorting.

What is the system reading? If it processes faces, voices, physiological signals, body movement or typing behaviour in order to determine how a person feels, it is an emotion recognition system, and in a workplace or educational setting it is prohibited. If it processes documented text, it is not an emotion recognition system under the Act at all.

Two further questions are worth asking whatever the answer to the first.

What claim is the output making? There is a real difference between a system asserting that a person is experiencing an emotion and a system reporting that a described pattern occurs in a body of correspondence. The first is an assessment of a person. The second is a description of a record.

Can the person concerned see the evidence? This is the question least often asked and the one that most reliably separates useful tools from confident ones. If a finding cannot be traced back to material the subject could read for themselves, the tool is asking for trust it has not earned.

A caution against overclaiming

One correction is due to a story circulating in this sector, and it is worth practitioners hearing it from someone with no product interest in the answer.

Being outside the emotion recognition prohibition does not mean a tool is unregulated. The AI Act has other tiers. A system used to monitor or evaluate the behaviour of workers may be classified as high-risk under Annex III regardless of whether it touches biometric data, which brings substantial obligations with it. Data protection law applies in full independently. Any vendor describing itself as AI Act compliant on the strength of not being an emotion recognition system is telling you about one provision and staying quiet about several others.

Ask which provisions they mean.

What this means for the work

For those of us supporting people inside coercive, toxic or manipulative dynamics, the distinction the law has drawn happens to describe the problem we already have.

The difficulty in this work has never been identifying what a client feels. Clients tell us. The difficulty is that what they feel is systematically disbelieved, by employers, by family members, by courts, and in time by the client herself. Somebody who has spent three years being told she is oversensitive does not need a machine to confirm that she is distressed. She needs the pattern that produced the distress made visible to people who currently cannot see it.

That requires evidence, meaning material that survives contact with a sceptic. A system reporting that a person appears anxious contributes nothing to that, because her anxiety was never the point in dispute. A system demonstrating that a documented pattern of reality-denial appears repeatedly across eleven months of correspondence, with each instance available to be read, is a different kind of object, and it is the kind that changes outcomes.

In more than twenty years of teaching and professional practice, the thing I have seen block resolution most consistently is not disbelief in a person’s suffering. It is the absence of anything that makes the cause of that suffering legible to somebody else.

Where Validate sits

Validate analyses documented written correspondence. It falls outside the definition of an emotion recognition system, because that definition requires biometric data and Validate does not use any.

It is also worth saying plainly that Validate does not attempt to infer emotional states at all. It identifies where documented patterns of coercive control appear across a body of correspondence, and shows the specific exchanges supporting each finding. The output is a description of what is in the record, with the record attached. Whoever the findings concern can read every piece of evidence behind every conclusion and disagree with the interpretation.

That design decision was made for reasons of rigour rather than compliance. It has turned out to sit on the right side of a distinction that European regulators have since written into law, and the reasoning they gave for drawing it where they did is the same reasoning that produced the tool.

Share:

Related Posts

Consent Management Platform by Real Cookie Banner