Nobody sat in a meeting and decided to deploy an emotion recognition system. The feature came with the platform. It was called sentiment analysis, or tone detection, or a frustration alert, and it was switched on because it was there and looked useful.
Since 2 August 2026 that feature has a legal classification.
Two rules, not one
The AI Act deals with emotion recognition in two separate places, and the difference between them is large.
Article 5(1)(f) prohibits AI systems that infer the emotions of people in the workplace or in education, with an exception for medical and safety purposes. That prohibition has applied since 2 February 2025. It lands on something many contact centres have running: dashboards that score an agent's tone, stress level or "energy" across a shift. Breaching the prohibitions can be fined up to EUR 35 million or seven per cent of global annual turnover.
Annex III, point 1(c) lists AI systems intended for emotion recognition as high-risk. The rules for Annex III systems started to apply on 2 August 2026 – the same day as the disclosure duty for voice agents. High-risk does not mean prohibited. It means a risk management system, data governance, technical documentation, logging, human oversight, conformity assessment and registration in the EU database. The ceiling here is EUR 15 million or three per cent.
One detail that is easy to misread: classifying a system as high-risk does not make it lawful. The Act is explicit that its use must still have a basis in other law – in practice the GDPR and national data protection rules.
Text is not biometrics
This is the distinction that decides the most in practice, and almost nobody puts the question to their vendor.
The Act defines an emotion recognition system as one that identifies or infers emotions or intentions on the basis of biometric data. Biometric data means personal data resulting from technical processing of physical, physiological or behavioural characteristics.
The voice is such a characteristic – something that already has security consequences. If the system measures pitch, tempo, stress or breathing pattern and concludes "angry", that is emotion recognition.
If the system reads the transcript and registers that the customer said "this is the third time I have called and I am considering switching supplier", that is not biometrics. It is content analysis, and it falls outside the emotion recognition rules. It does not fall outside the GDPR, and not outside the rules on profiling if the conclusion is used to treat customers differently.
The difference is not cosmetic. Two systems can raise the same alert to the same case handler, and only one of them triggers a high-risk regime.
The legislator does not trust the measurement
The reasoning in the Act is not privacy alone. It is technical: there is considerable scientific uncertainty around emotion recognition, expression varies across cultures and between individuals, and the results can be unreliable and discriminatory.
For a Nordic contact centre that is not an academic point. A model trained on English-language call audio holds an opinion about what anger sounds like. That opinion then meets a caller with a broad western Norwegian dialect, a Danish customer who speaks fast, and an older customer who speaks quietly because their hearing is poor. The system returns a number regardless. The number looks like a measurement, but it is a judgement – and it is used to prioritise queues, escalate cases and evaluate staff.
The carve-out for existing systems is narrower than it looks
Article 111 provides a transition: the Act applies to high-risk systems put into service before 2 August 2026 only if, from that date, those systems are subject to significant changes in their design. Public bodies have until 2 August 2030 regardless.
That is usually read as an exemption. It is closer to a freeze. If the vendor swaps the underlying model, retrains the feature or extends it to a new purpose, the change is significant – and the system falls under the regulation in full. In a category where vendors ship new models several times a year, this is an exemption with a short shelf life.
The clean-up is shorter than the fear:
Find out what is actually switched on. Not in the product sheet – in the configuration.
Ask the vendor one question: is the emotion inferred from audio or from text? If you do not get a clear answer, that is the answer. Choosing a vendor is a compliance question, not only a procurement one.
Turn off emotion scoring aimed at your own employees. That is not a project, it is a setting – and it has been unlawful for eighteen months.
Inform the people it applies to. If you keep emotion recognition pointed at customers, you are obliged to tell them the system is in use.
You do not need to measure feelings to resolve the call
It is worth asking what the feature actually gave you.
Almost everything a contact centre wants an anger alert for – prioritising a queue, escalating to a human, catching a customer on the way out the door – can be decided from what the customer says and does. How many times they have made contact about the same case. Words like "cancel", "complaint", "lawyer". That the case was not resolved last time. That the customer asked for a human and did not get one.
Those are stronger signals than tone of voice. They can be explained after the fact. And they are not biometric.
The point is not to measure less. It is to decide what the agent should listen for, and to be able to account for it afterwards – the same discipline that separates customer dialogue that scales from customer dialogue that merely produces data.
Threll.ai builds voice agents on Nordic infrastructure, where it is possible to answer what the system assesses and why. Since 2 August, that answer is no longer optional.




