Nobody sat in a meeting and decided to deploy an emotion recognition system. The feature came with the platform. It was called sentiment analysis, or tone detection, or a frustration alert, and it was switched on because it was there and looked useful.
That feature now has a legal classification.
Two rules, not one
The AI Act deals with emotion recognition in two separate places, and the difference between them is large.
Article 5(1)(f) prohibits AI systems that infer the emotions of people in the workplace or in education, with an exception for medical and safety purposes. That prohibition has applied since 2 February 2025. It lands on something many contact centres have running: dashboards that score an agent's tone, stress level or "energy" across a shift. Breaching the prohibitions can be fined up to EUR 35 million or seven per cent of global annual turnover.
Annex III, point 1(c) lists AI systems intended for emotion recognition as high-risk. Under the original timetable the rules for Annex III systems were to apply from 2 August 2026, the same day as the disclosure duty for voice agents. The Digital Omnibus amending package, approved by the European Parliament on 16 June 2026, deferred them: 2 December 2027 for stand-alone high-risk systems, and 2 August 2028 for high-risk systems embedded in products. The disclosure duty was not deferred.
High-risk does not mean prohibited. It means a risk management system, data governance, technical documentation, logging, human oversight, conformity assessment and registration in the EU database. The ceiling here is EUR 15 million or three per cent.
The deferral is worth reading for what it is. It moves the deadline for documentation and conformity assessment. It does not change the classification, it does not touch the 2025 prohibition, and it does nothing to the data protection rules that apply in the meantime.
One detail that is easy to misread: classifying a system as high-risk does not make it lawful. The Act is explicit that its use must still have a basis in other law – in practice the GDPR and national data protection rules.
Text is not biometrics
This is the distinction that decides the most in practice, and almost nobody puts the question to their vendor.
The Act defines an emotion recognition system as one that identifies or infers emotions or intentions on the basis of biometric data. Biometric data means personal data resulting from technical processing of physical, physiological or behavioural characteristics.
The voice is such a characteristic – something that already has security consequences. If the system measures pitch, tempo, stress or breathing pattern and concludes "angry", that is emotion recognition.
If the system reads the transcript and registers that the customer said "this is the third time I have called and I am considering switching supplier", that is not biometrics. It is content analysis, and it falls outside the emotion recognition rules. It does not fall outside the GDPR, and not outside the rules on profiling if the conclusion is used to treat customers differently.
The difference is not cosmetic. Two systems can raise the same alert to the same case handler, and only one of them triggers a high-risk regime.





