Emotion-Inferring AI: Where the Line Falls

Under the EU AI Act, inferring emotions is banned in workplaces and schools but merely notifiable elsewhere. Where your use sits.

Author
AuthorAuthor

AI Engineer · 36+ years in IT · Japanese, based in Manila for 13+ years

Emotion-Inferring AI: Where the Line Falls

Software that reads a person's feelings from their face or voice is no longer unusual. It now ships inside business products in the form of call analysis, interview support and in-store reaction tracking. This module takes the EU AI Act's treatment of such systems as its subject and works through, in concrete steps, how a Japanese company operating in the Philippines should audit what it already has running.

According to the published provisions, the treatment differs sharply depending on where the system is used. In workplaces and educational institutions, using AI to infer people's emotions is prohibited in principle. That prohibition sits in Article 5, with exceptions stated for medical or safety reasons. Where emotion recognition systems or biometric categorisation systems are used in other settings, Article 50 sets out an obligation to inform the people exposed to the system that it is operating, and those transparency provisions apply from 2 August 2026. The prohibition came earlier: Article 5 has applied since 2 February 2025. In other words, the same "AI that reads emotions" calls for entirely different action depending on whether it is pointed at your employees or at your customers. In this module we work through that distinction in Parts 1 to 4, applying it to your own situation.


Part 1: Read, Then Consider the Implications for Your Company

The treatment differs sharply depending on where the system is used.

Where it is usedTreatmentBasis and date of application
Workplaces and educational institutionsEmotion inference is prohibited in principle (medical or safety reasons are the exception)Article 5, applying from 2 February 2025
Other settingsDuty to inform the people exposed that the system is operatingArticle 50, applying from 2 August 2026

Step 1: Pre-Reading (3 min)

Before you read, consider how this applies to your own company.

  • Where in your operations does AI analyse people's expressions, voices or speech patterns?
  • Is the subject of that analysis an employee or a customer?
  • Do the people being analysed know that it is happening?

Step 2: First Reading (10 min)

The following is a fictional internal memo, written for this module with a Japanese company in the Philippines as the subject, based on the content of the provisions.


Internal memo: How emotion-inferring AI is treated, and what we need to check

I have reviewed how emotion recognition is handled under the EU AI Act. Three points deserve attention.

First, emotion inference in the workplace is not something notification can resolve. Article 5 prohibits, in principle, the use of AI to infer emotions in workplaces and educational institutions. It is not structured so that obtaining consent makes it permissible. Exceptions are stated for medical or safety reasons, but it is a natural reading that performance evaluation and monitoring of work attitude fall outside them.

Second, notification is required when the system is pointed at customers. Article 50 requires those who use emotion recognition or biometric categorisation systems to inform the people exposed that the system is operating. That provision applies from 2 August 2026.

Third, facial recognition and emotion inference have to be treated as separate things. The facial matching we use for attendance confirms whether a person is who they claim to be; it does not read emotions. The call analysis being considered for the contact centre, on the other hand, includes a function that infers the degree of dissatisfaction from how someone speaks. Both are "AI looking at people", but their standing is different.

Whether we fall directly within scope depends on whether we operate the system inside the EU, or whether its output is used inside the EU. That question needs confirmation from legal counsel. In addition, within the Philippines the Data Privacy Act treats biometric information as sensitive personal information, so a separate check is required alongside the EU provisions.

Our three takeaways: (1) compile a list of the systems that analyse people, (2) sort each one into identity verification, emotion inference or attribute categorisation, and (3) for anything pointed at employees, establish the purpose and the legal basis first.


Source: Article 5: Prohibited AI Practices — EU Artificial Intelligence Act / Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems — EU Artificial Intelligence Act

Note: the business scenario above is a fictional internal memo written for learning purposes on the basis of publicly available information. Interpretations of scope and exceptions can change, so any determination of whether your company is covered must rest on primary sources and professional advice.

Step 3: Comprehension Check (5 min)

  • How is emotion inference in the workplace treated, and what is cited as an exception?
  • What is required of those who use emotion recognition systems outside the workplace?
  • Why do facial matching for identity verification and emotion inference need to be considered separately?

Step 4: Three-Minute Briefing (10 min)

Practise explaining this topic to your management team in three minutes. Presenting it in the order "what is happening (emotion-inferring AI is treated differently depending on where it is used) → why it matters (systems pointed at employees cannot be resolved by notification and are prohibited in principle) → what we should do (take stock of the systems that analyse people and sort them by type)" tends to land well.

Related: Lessons from Meta's "NameTag" Face-Recognition Controversy: Handling Biometric Data in the Philippines explains this in detail.

Part 2: Key Terms Explained (for Management)

Emotion recognition system: a system that infers a person's emotions or intentions from biometric signals such as facial expression, tone of voice or speaking pace. It covers more than judgements of mood; systems that gauge fatigue or levels of concentration may also fall within it.

Biometric categorisation system: a system that sorts people into categories on the basis of biometric information. Use aimed at inferring race, political opinions, trade union membership, beliefs, sex life or sexual orientation is stated to be prohibited under Article 5.

Identity verification (matching): a system that confirms whether someone is an already-registered individual — facial recognition for attendance, or unlocking a device. Its purpose differs from emotion inference, and so does its treatment under the provisions. Because it handles biometric information, however, a separate review from a data protection standpoint is still necessary.

Deployer: the party that uses AI in its own operations. What is required of the deployer differs from what is required of the provider that builds and supplies the system, and the notification obligation sits primarily with the party using it.

Sensitive personal information: a category under the Philippine Data Privacy Act, stated to include biometric information. It is a separate regime from the EU provisions, so both need to be checked.

Related: Where Do You Draw the Line on "High-Impact Actions Need Human Sign-Off"? Designing Approval When AI Handles Your Defences | A Case Study for Japanese Companies in the Philippines explains this in detail.

Part 3: Applying This to Your Company

Sort your own systems into these three categories.

CategoryWhat the system doesPriority for review
Identity verificationConfirms whether someone is the registered personLow (not emotion inference)
Emotion inferenceReads mood, engagement or degree of dissatisfactionHighest where aimed at employees
Biometric categorisationSorts people into groups from biometric dataHighest where aimed at employees

List the systems that analyse people

Start by listing every system running in your company that handles people's faces, voices or physical characteristics. You will find them in attendance facial recognition, access control, call recording and analysis, visitor logs and interview support tools. It is not unusual for these to have been introduced by different departments, with nobody holding the full picture.

Related: Lessons from a Government Order to Stop Using an AI Provider: Preparing for the Day Your AI Becomes Unavailable | A Case Study for Japanese Companies in the Philippines explains this in detail.

Sort them into three types

Once you have the list, sort each entry into one of three categories.

  1. Identity verification: confirming whether someone is an already-registered individual
  2. Emotion inference: reading feelings, motivation, degrees of dissatisfaction and the like
  3. Attribute categorisation: sorting people into categories on the basis of biometric information

Once the sorting is settled, the order of work settles with it. Anything in categories 2 and 3 that is pointed at employees is what needs checking first.

Re-read the product documentation

A function described at the time of purchase as no more than "voice analysis" may include emotion inference. Obtain the feature list for the products you have under contract, and confirm in writing with the vendor which items amount to inference of emotion or motivation. A verbal explanation leaves nothing you can trace later.

Prepare notification wording for anything customer-facing

Where sentiment analysis is used in customer service, the people concerned need to be informed. An announcement at the start of a call, a note in the terms of use, or in-store signage are all plausible formats. The wording can be brief, but it has to convey what is actually taking place.

Part 4: Common Failure Patterns (What Not to Do)

This is the most dangerous misunderstanding. Emotion inference in the workplace is not structured so that notification or consent renders it lawful. The reasoning behind this is doubt over whether consent can genuinely be voluntary within an employment relationship. There are exceptions for medical or safety reasons, but explaining performance evaluation or attitude monitoring as a safety measure will not hold up.

Failure 2: Treating facial recognition and emotion inference as the same issue

We are sometimes asked whether attendance facial recognition should be switched off. Identity matching and emotion inference are different systems, and judging them together risks shutting down something you actually need. Separate them first.

Failure 3: Reviewing only new purchases and ignoring what is already installed

Many companies audit what they are about to introduce and overlook what is already running. Emotion inference frequently arrives later, as an added feature in call management or attendance products. The longer a product has been in place, the more it is worth requesting a fresh feature list.

Failure 4: Not checking the Philippine regime

Looking only at the EU provisions leaves the check closest to home undone. Under the Philippine Data Privacy Act, biometric information is treated as sensitive personal information, and its collection and use require separate review. This applies even to companies with no EU-facing business.

Failure 5: Completing the review inside the administrative function without telling the front line

It is the front line that selects products and changes settings. If the review is finished inside the administrative function alone, another department will enable a similar feature the following month. Even sharing just two things — the three-way sorting, and the rule that anything pointed at employees must be raised in advance — makes a difference.

Three Tips for Getting Value from This

  1. Build the list first: judgements can come afterwards. Finish writing down every system that handles people's faces, voices or physical characteristics this week.
  2. Make the sorting part of your internal vocabulary: once identity verification, emotion inference and attribute categorisation are the terms everyone uses, later discussions move faster.
  3. Go to primary sources: the scope of the exceptions and the guidance will keep moving. Read the text of the provisions and the official commentary rather than summary articles.

Bonus: How to Make Use of PH AI Works

Working out which of your systems amount to emotion inference, and which part of the product documentation to check, takes time when done entirely in-house. In a free PH AI Works consultation we take questions from Japanese companies operating in the Philippines on taking stock of the systems that analyse people and sorting them into the three categories. Legal determinations themselves belong to qualified professionals; our part is helping you establish what is actually running and how to structure the internal process around it.

Sources

About the author

Author
Author

Founder / AI Engineer (36+ years in IT)

  • From Tokyo · based in Manila for 13+ years
  • 36+ years in IT (development, SEO, AI)
  • IBM Certified Generative AI Engineer
  • AI chatbots, RAG & AI agent development

A Japanese AI engineer with 36+ years in IT and 13+ years on the ground in the Philippines. I write from hands-on experience to help Japanese companies adopt AI that actually delivers results — chatbots, workflow automation, AI agents, and AI-driven marketing. Feel free to reach out in Japanese or English.

Your Competitors Are Already Using AI!

Is your business keeping up?