Compliance

Article 5(1)(f) and education institutions

Education is one of only two contexts the EU singled out for an outright ban on emotion inference. If you run a VLE, an online course business or a training function, this rule is addressed to you directly.

8 min read
In short

Article 5(1)(f) prohibits AI systems that infer emotions from biometric data in education and training institutions, in force since 2 February 2025. It covers all types and levels of education including admissions, applies to vendors and institutions alike, and has no consent exception. Behavioural engagement analytics that do not infer emotions fall outside it.

Why education was singled out

The EU AI Act prohibits a short list of practices outright. Emotion inference is on that list for exactly two contexts: the workplace and education institutions.

The reasoning is about power asymmetry. In both settings, the person being analysed cannot meaningfully decline. A student cannot opt out of the VLE their degree is delivered through. An employee cannot decline the mandatory compliance module. Consent, which does most of the work elsewhere in EU data law, cannot function as a safeguard where refusal carries a real penalty.

Layer onto that the contested scientific footing of inferring discrete emotional states from facial expressions, and the documented pattern of these systems performing unevenly across demographic groups, and you get a legislature deciding the practice should not be available at all rather than available subject to paperwork.

Who counts as an education institution

Guidance reads the category broadly. It covers all types and levels of education and training, and extends to admissions — so the analysis reaches applicants as well as enrolled students.

In practice, treat the following as likely in scope:

The "related to" language matters. An external provider running a module for a university's students does not escape because it is not itself the institution.

What the prohibition covers

The prohibited practice requires four elements together:

  1. An AI system within the Article 3(1) definition
  2. That infers emotions of a natural person
  3. From biometric data — the Article 3(34) definition, broader than GDPR's
  4. In a workplace or education institution context

Remove any one and Article 5(1)(f) does not apply, though GDPR obligations continue regardless.

The exception is medical or safety use, construed narrowly. Medical points toward CE-marked devices used therapeutically. Safety means protecting life and health. "Supporting student wellbeing" is neither, however genuinely meant.

The consent misunderstanding

Institutions frequently assume that a clear opt-in, an ethics committee approval or a student agreement resolves this. It does not. Article 5 practices are prohibited rather than permitted-with-safeguards. There is no consent gateway, and an ethics approval is not a legal basis for a practice the law forbids.

Proctoring, a special case

Online proctoring is where this gets genuinely difficult, and where the guidance is least settled.

A proctoring system's primary purpose is usually integrity monitoring — detecting whether someone is looking away, whether another person is present, whether the environment has changed. That is not obviously emotion inference.

But many systems also produce "suspicion" or "anomaly" scores derived from facial and gaze behaviour, and some vendors have marketed stress or nervousness detection as a feature. The Commission guidelines explicitly leave open whether a system with emotion inference as a secondary functionality is caught by the prohibition. The worked example in the literature is precisely this: a system that monitors students during a test but also identifies emotions.

Until that is resolved, institutions should:

There is also a separate, non-legal dimension worth weighing. Student campaigns against proctoring software have been sustained and effective, with objections including that gaze-based flagging discriminates against neurodivergent students who look away from the screen. Reputational risk here is real and independent of the compliance position.

What remains lawful

The prohibition is narrow. A great deal of learning analytics is untouched by it.

Practice Status
Completion, progression and assessment data ✅ Not caught
Time-on-task and dwell analytics ✅ Not caught
Tab-switching and focus-loss telemetry ✅ Not caught
At-risk identification from engagement patterns ✅ Not caught
Content-level engagement heatmaps ✅ Not caught
Surveys and self-reported experience ✅ Not caught
Gaze and eye tracking ⚠️ Grey area
Facial emotion analysis in a VLE ❌ Prohibited

Everything in the green rows can be combined into a genuinely useful engagement picture. Research published in 2024 identified tab-switching as the single strongest predictor of disengagement in online courses — stronger than self-regulation or satisfaction measures. The most predictive signal available is in the lawful column.

Practical steps for institutions

  1. Inventory what you already run. VLE plugins, proctoring tools, engagement dashboards, lecture capture analytics. Vendors have added AI features to existing products without much fanfare.
  2. Ask each vendor the direct question in writing. Does the system infer emotions from biometric data at any stage? Intermediate values count.
  3. Disable emotion features explicitly. In configuration and in the contract.
  4. Update your DPIA. The AI Act analysis sits alongside, not instead of, the GDPR one.
  5. Standardise on behavioural signals for engagement measurement. Lawful, better evidenced, and it avoids the student-consultation problem entirely.
  6. Aggregate to content level. "Week 6 loses 40% of the cohort" is the actionable insight, requires no personal data, and takes the surveillance question off the table.

The point worth holding onto: the EU has not banned understanding whether your teaching is working. It has banned inferring how students feel from their faces. Those were never the same project, and the second one was never where the useful signal lived.

Frequently asked questions

Does this apply to private online course businesses?
The Act refers to education and training institutions, and guidance reads this broadly across types and levels. A commercial e-learning provider delivering training is likely within scope, particularly where the training is delivered to a client's employees, which brings the workplace limb into play as well. Take advice rather than assuming a private provider sits outside.
Can a university use emotion recognition for research?
Academic research is a different context from the operational running of an education institution, and the Act contains provisions relating to research activity. But research conducted on the institution's own students, in their capacity as students, sits uncomfortably close to the prohibited context. Ethics approval does not substitute for the legal analysis.
What about detecting whether students are struggling?
It depends entirely on the signal. Identifying at-risk students from engagement patterns, assessment performance and platform behaviour is ordinary learning analytics and is not caught. Identifying them by inferring emotional states from their faces is.
Does the ban apply to students under 18 specifically?
The prohibition is not age-limited — it applies to education institutions generally. Separate provisions on exploiting vulnerabilities related to age also exist under Article 5, and children's data attracts additional protection under GDPR, so deployments involving minors carry compounded risk.

Learning analytics without the prohibited step

Content-level engagement data from behavioural signals — no camera, no emotion inference, no Article 5 exposure.

See how Signals works
Get Started

See what completion rates can't tell you

Find out exactly where your content works, where it fails, and what disengagement looks like before people leave.

Request a Demo