Emotion recognition
Inferring emotions or intentions from biometric data is prohibited in the workplace and in educational institutions, except for medical or safety purposes — the concept of "workplace" extends to the recruitment process and the probationary period. In other contexts an emotion-recognition system is not prohibited, but under Article 50(3) the deployer must inform the individuals concerned about how the system operates.
Two entirely different legal regimes apply to the same technology depending on the context of use. In the workplace and in education, Article 5(1)(f) — read together with Article 3(39) and Article 2(11) — prohibits use outright, except for medical or safety purposes; this is the most common real-world corporate exposure among the prohibited practices, typically arising as a switched-on emotion-analysis feature of a purchased video-interview tool. In every other context — e.g. customer-service voice analysis, marketing research — emotion recognition is not prohibited, but under Article 50(3) and (5)–(6) the deployer must inform the individuals exposed to the system about how it operates, and must process the data in line with the GDPR; this obligation has applied since 2 August 2026, regardless of risk category. The line between the two regimes — workplace/education versus everything else — is the first thing a company must clarify before deploying any emotion-analysis tool.
This is the most likely prohibited-practice risk in the life of a Hungarian SME — for every video-interview or HR tool procured, it is worth explicitly asking whether it has an emotion-analysis feature, and switching it off if it does.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Prohibited AI practiceArticle 5(1) prohibits eight AI practices outright: subliminal or deceptive manipulation, exploitation of vulnerabilities, social scoring, predicting criminal offending from profiling alone, untargeted scraping of facial images, emotion recognition in the workplace and education, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in public spaces. There is no compliance pathway for these.
- Transparency obligation (Article 50)Article 50 lays down four separate transparency obligations, regardless of risk category: the provider must disclose when a user is interacting with AI and must mark generated content in a machine-readable format; the deployer must inform individuals about emotion recognition and must disclose the artificial origin of deepfake content. All four have applied since 2 August 2026.
- Biometric categorisationA biometric categorisation system that individually categorises natural persons based on their biometric data in order to infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation is prohibited. The prohibition targets inference of protected characteristics.
Related questions in the knowledge base (Hungarian)
- Tilos-e az érzelemfelismerés a munkahelyen az EU AI Act szerint?Igen. Tilos a biometrikus adaton alapuló érzelem- vagy szándékkövetkeztetés a munkahelyen és az oktatási intézményekben, kizárólag orvosi vagy biztonsági célú használat kivételével. A „munkahely” fogalma kiterjed a kiválasztási és felvételi folyamatra, sőt a próbaidőre is, ezért az érzelemelemző videóinterjú tiltott. Ez a leggyakoribb valós vállalati kitettség.
- Mit kell közölni, ha érzelemfelismerő vagy biometrikus kategorizáló rendszert használunk?Az alkalmazónak tájékoztatnia kell a rendszernek kitett természetes személyeket annak működéséről, és az adatkezelést a GDPR-ral összhangban kell végeznie. A kötelezettség 2026. augusztus 2. óta él, a kockázati besorolástól függetlenül. Ha a rendszer a munkahelyen vagy oktatásban ismer fel érzelmet, az 5. cikk szerint tiltott, és az 50. cikk (3) fel sem merül.
- Hol merül fel valóban tiltott AI-gyakorlat kockázata egy szolgáltató cégnél?A reális kitettség szinte teljes egészében a munkahelyi érzelemfelismerés köré csoportosul, alkalmazói minőségben. Másodsorban a munkavállalói vagy jelölti pontozás releváns, ha nem kapcsolódó kontextusból származó adatot aggregál. Az arcképlekaparás tanácsadói környezetben jellemzően nem AI Act-, hanem GDPR-kockázat. A tilalmak 2025. február 2. óta élnek, a felső szankciósáv 35 millió euró vagy 7%.