Regulation and compliance

Emotion analytics in customer calls: everyone watched the wrong date

The trade press spent the spring reporting that analysing a caller's tone of voice would be reclassified as high-risk on 2 August. That deadline moved to December 2027. The prohibition that actually applies reached the contact centre in February 2025 — and it is about your staff, not your customers.

IngridIngrid,
Seen from behind, a woman in a dark jumper sits at her desk in an open-plan office after hours, one hand resting on a desk phone she has just hung up, an unworn headset beside her and two colleagues talking out of focus further back in the room

The claim has been circulating in the trade press since the spring, and it runs roughly like this:

"From 2 August 2026, analysing a customer's emotions during a phone call becomes a high-risk use under the EU AI Act. With it come conformity assessments, human oversight, logging and fundamental rights impact assessments — and fines of up to €15 million or 3% of global turnover."

The date came and went four weeks ago. Nothing happened. The conclusion most people drew from that — that the danger has passed — is the one conclusion that is wrong.

Why the claim stuck

Because it was correct when it was written.

The AI Act's original calendar did set 2 August 2026 as the date the obligations for high-risk systems under Annex III began to apply. Emotion recognition is listed there. The trade press wrote it up all spring, countdown clocks and all, and reported the content accurately.

Then came the Digital Omnibus on AI — Regulation (EU) 2026/1744 — published in the Official Journal on 24 July and in force from 27 July 2026. Five days before the deadline. It moved the Chapter III obligations to 2 December 2027 for stand-alone Annex III systems, and to 2 August 2028 for systems embedded as a safety component in a product.

The change was mostly written up as a technicality, in the middle of the summer holidays. The spring articles were never updated. They are still there, with the wrong date and the right content, and they are what most people have read.

Three dates, and only one of them moved

They are worth keeping apart. They bind different parties, and right now they have entirely different status.

The high-risk obligations: deferred. Conformity assessment, risk management system, logging, human oversight, registration. Applying from 2 December 2027 for stand-alone systems. The deferral covers Chapter III and nothing else.

The transparency duty: not deferred. Article 50(3) requires anyone deploying an emotion recognition system to inform the people exposed to it. It has applied since 2 August 2026 and the Omnibus left it alone. It sits with the organisation using the system, not the vendor building it — unlike the marking duty for synthetic audio, which is the vendor's.

The prohibition: eighteen months old. Article 5(1)(f) prohibits emotion recognition in the workplace and in educational institutions. It has been enforceable since 2 February 2025. The exception for medical or safety purposes is narrow — it covers driver fatigue monitoring, for example, not general logging of how an employee sounds. The fine tier is the highest in the Act: up to €35 million or 7% of global turnover.

One caveat for readers outside the EU. In the EEA states — Norway, Iceland, Liechtenstein — the Act is marked EEA-relevant, and the date each individual requirement binds locally is not necessarily the EU date. The order of the three dates does not change either way.

The last one is the one that hits a contact centre

This is the point, and it is uncomfortable.

The Commission's classification guidelines use a contact centre as the textbook example of an emotion recognition system: a platform that analyses vocal tone, pitch and volume to flag that a caller is angry. And the prohibition in Article 5(1)(f) is expressly meant to cover contact centres — as workplaces.

Most speech analytics platforms sit in the middle of the call. They listen to both parties and produce output about both. Under the Act that is no longer one product. It is two legal objects.

The half facing the customer is high-risk. That deadline moved to 2027.

The half facing the employee is prohibited. That deadline passed in February 2025.

And it is the second half that is wired into quality assurance and coaching at a great many operations: a post-call summary with a score for how patient the agent sounded, an alert to the team leader about negative tone. That is precisely what Article 5(1)(f) forbids.

The line falls at inference, not at recording. Counting how many times a call was interrupted is measurement. Concluding from the voice that the agent was irritated is emotion recognition. The distinction is small in practice and decisive in law — and it is worth noting that the numbers that actually show whether the call was resolved require no inference about anyone's feelings at all.

Data protection law does not move with any of these dates

Article 50(3) has two limbs, and the second gets overlooked. Alongside the duty to inform, it requires that the associated personal data be processed in compliance with the GDPR.

Biometric data is a special category under Article 9. The AI Act creates no new legal basis. Anyone deploying such a system has to establish a valid Article 9(2) ground — in practice, explicit consent — before it goes live. That track runs independently of the entire AI Act calendar, and it has never been deferred.

What is worth doing now

The deferral bought time on the paperwork. It did not buy time on the prohibition.

The question worth asking this week does not go to your lawyer. It goes to whoever administers the speech analytics platform: does it analyse employees' voices, and what is the output used for? If there is a tone field in the quality report, that is not a task for December 2027. It is a question for the vendor about what can be switched off, and when.

And if you simply run an ordinary voice agent with no emotion analytics: none of this applies to you. The disclosure duty in Article 50(1) does, and it is both cheaper and simpler to satisfy.

Threll.ai builds voice agents in Norwegian, Swedish and Danish. We do not infer emotions from the voice, neither the customer's nor the employee's. That is not an ethical position. It is that a system which does not guess how people feel never ends up in this conversation.

Related Articles

Continue reading more articles