DEV Community

Multigrid
Multigrid

Posted on • Originally published at multigrid.ai

The Notice Duty for Emotion Recognition and Biometric Categorisation Systems

Coverage of emotion recognition under the AI Act tends to stop at Article 5, which bans two specific uses. That leaves a large remainder of lawful deployments, and Article 50(3) attaches a duty to those: tell the people exposed to the system that it is operating.

The duty in Article 50(3)

Article 50(3) of Regulation (EU) 2024/1689 requires deployers of an emotion recognition system or a biometric categorisation system to inform the natural persons exposed thereto of the operation of the system, and to process personal data in accordance with Regulation (EU) 2016/679, Regulation (EU) 2018/1725 and, where relevant, Directive (EU) 2016/680. The text is on EUR-Lex.

Three features distinguish it from the other Article 50 duties. It falls on the deployer. Its trigger is exposure rather than interaction, so it reaches people who never chose to engage — somebody walking past a camera is exposed. And it is not about output at all: nothing generated needs labelling, because the point is the existence of the analysis.

The exception mirrors the one in Article 50(1): it does not apply to AI systems used for biometric categorisation and emotion recognition that are permitted by law to detect, prevent or investigate criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties and in accordance with Union law.

Emotion inference and biometric categorisation almost always involve processing personal data, and frequently special-category data. This page describes one AI Act obligation only, it is not legal advice, and the data protection analysis is a separate exercise you should take advice on.

Banned, high-risk, or merely notifiable

The reason Article 50(3) exists is that Article 5 does not ban these system categories outright. It bans particular uses of them, and the gaps between the bans are where Article 50(3) lives.

  • Prohibited. Article 5(1)(f) prohibits placing on the market, putting into service or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where intended for medical or safety reasons. Article 5(1)(g) prohibits biometric categorisation systems that categorise natural persons individually on the basis of their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, with a carve-out for lawful labelling or filtering of lawfully acquired datasets. Detail on the emotion recognition ban and the biometric categorisation ban.
  • High-risk. Annex III point 1 lists emotion recognition systems and biometric categorisation systems among the biometrics category of high-risk systems, so a deployment that is not prohibited may still carry the full Chapter III regime — including deployer duties under Article 26.
  • Neither, but notifiable. Everything else: emotion inference in a retail environment, in a vehicle cabin, in market research, in a call centre analysing customer sentiment rather than employee performance. Article 50(3) applies here.

The workplace point deserves emphasis because it is where teams most often assume they are fine. The Article 5(1)(f) prohibition is about inferring emotions of natural persons in the workplace, and a call analytics product that scores customer emotion also processes employee speech. Whether a given deployment infers employee emotion is a factual question with a very different answer depending on how the system is built, and it is not one to resolve by assumption.

What the two definitions actually cover

Article 3(39) defines an emotion recognition system as an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data. Two things follow. “Intentions” is in the definition, which pulls in intent-prediction systems that would not describe themselves as emotion recognition. And the basis must be biometric data — Recital 18 indicates that the notion does not extend to detecting readily apparent expressions, gestures or movements unless used to infer emotions, and that physical states such as pain or fatigue are outside it, for instance systems detecting pilot or driver fatigue for safety.

Article 3(40) defines a biometric categorisation system as an AI system for assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons. That ancillary carve-out is narrower than it looks: it requires both ancillarity and strict technical necessity, so a filter that incidentally classifies faces to apply an effect may qualify while a demographic-inference feature bolted onto an unrelated service will not.

The data protection layer underneath

Article 50(3) expressly requires processing in accordance with the GDPR, and this is the part that usually decides whether a deployment is viable, not the notice duty itself. Biometric data processed for the purpose of uniquely identifying a natural person is special-category data under Article 9(1) GDPR and needs an Article 9(2) condition, which in a commercial setting usually means explicit consent — hard to obtain validly from people merely walking past a sensor. See the Article 9 biometrics page.

Whether emotion inference that does not uniquely identify anyone falls within Article 9 is contested. Supervisory authorities have taken firm positions on biometric processing in public spaces, and the EDPB has been consistently sceptical of emotion inference generally; but the AI Act notice duty and the GDPR lawfulness analysis are separate questions and satisfying one says nothing about the other. A transparency notice is not a legal basis.

Giving the notice

Article 50(5) governs the form: information must be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must conform with the applicable accessibility requirements. For an exposure-triggered duty, “at the latest at first exposure” means the notice has to be in place before the person is in range, which in a physical space means signage at the entrance rather than a notice at the till.

The content standard is the operation of the system, which is more than its existence. A sign saying “CCTV in operation” does not tell anybody that their expressions are being classified. A notice that does the work says what is being inferred and by what kind of system, in language the exposed person can act on.

Article 50 applies from 2 August 2026 under Article 113 — note that the Article 5 prohibitions applied earlier, from 2 February 2025, so the ban and the notice duty did not start on the same day. Non-compliance with Article 50 sits in the Article 99(4) tier of up to EUR 15 million or 3% of worldwide annual turnover; breach of an Article 5 prohibition sits in the higher Article 99(3) tier of up to EUR 35 million or 7%.

The two dates on this page both held. The digital omnibus on AI was enacted as Regulation (EU) 2026/1744 (Official Journal, 24 July 2026; in force 27 July 2026), and it postponed the high-risk regime — Annex III to 2 December 2027, Annex I products to 2 August 2028 — without moving the Article 5 prohibitions from 2 February 2025 or the Article 50 transparency duties from 2 August 2026. Note the consequence for this particular subject: an emotion recognition system that is also high-risk under Annex III point 1 now owes the Article 50(3) notice more than a year before the Chapter III obligations attach to it. Penalty tiers are from 2024/1689 as adopted; confirm all of this against the consolidated EUR-Lex text.

Related

Top comments (0)