Article 5(1)(f) prohibits AI systems that infer emotions from biometric data in education and training institutions, in force since 2 February 2025. It covers all types and levels of education including admissions, applies to vendors and institutions alike, and has no consent exception. Behavioural engagement analytics that do not infer emotions fall outside it.
Why education was singled out
The EU AI Act prohibits a short list of practices outright. Emotion inference is on that list for exactly two contexts: the workplace and education institutions.
The reasoning is about power asymmetry. In both settings, the person being analysed cannot meaningfully decline. A student cannot opt out of the VLE their degree is delivered through. An employee cannot decline the mandatory compliance module. Consent, which does most of the work elsewhere in EU data law, cannot function as a safeguard where refusal carries a real penalty.
Layer onto that the contested scientific footing of inferring discrete emotional states from facial expressions, and the documented pattern of these systems performing unevenly across demographic groups, and you get a legislature deciding the practice should not be available at all rather than available subject to paperwork.
Who counts as an education institution
Guidance reads the category broadly. It covers all types and levels of education and training, and extends to admissions — so the analysis reaches applicants as well as enrolled students.
In practice, treat the following as likely in scope:
- Schools, colleges, universities
- Vocational and professional training providers
- Online course platforms and MOOCs
- Corporate training functions — which are also caught by the workplace limb
- Third-party training providers delivering into either context
- Admissions and entrance assessment processes
The "related to" language matters. An external provider running a module for a university's students does not escape because it is not itself the institution.
What the prohibition covers
The prohibited practice requires four elements together:
- An AI system within the Article 3(1) definition
- That infers emotions of a natural person
- From biometric data — the Article 3(34) definition, broader than GDPR's
- In a workplace or education institution context
Remove any one and Article 5(1)(f) does not apply, though GDPR obligations continue regardless.
The exception is medical or safety use, construed narrowly. Medical points toward CE-marked devices used therapeutically. Safety means protecting life and health. "Supporting student wellbeing" is neither, however genuinely meant.
Institutions frequently assume that a clear opt-in, an ethics committee approval or a student agreement resolves this. It does not. Article 5 practices are prohibited rather than permitted-with-safeguards. There is no consent gateway, and an ethics approval is not a legal basis for a practice the law forbids.
Proctoring, a special case
Online proctoring is where this gets genuinely difficult, and where the guidance is least settled.
A proctoring system's primary purpose is usually integrity monitoring — detecting whether someone is looking away, whether another person is present, whether the environment has changed. That is not obviously emotion inference.
But many systems also produce "suspicion" or "anomaly" scores derived from facial and gaze behaviour, and some vendors have marketed stress or nervousness detection as a feature. The Commission guidelines explicitly leave open whether a system with emotion inference as a secondary functionality is caught by the prohibition. The worked example in the literature is precisely this: a system that monitors students during a test but also identifies emotions.
Until that is resolved, institutions should:
- Obtain a written statement from the proctoring vendor on whether any emotional or affective inference is produced at any pipeline stage, including intermediate values never surfaced in the UI
- Disable any emotion or stress detection feature explicitly and in writing
- Document the analysis in the DPIA
There is also a separate, non-legal dimension worth weighing. Student campaigns against proctoring software have been sustained and effective, with objections including that gaze-based flagging discriminates against neurodivergent students who look away from the screen. Reputational risk here is real and independent of the compliance position.
What remains lawful
The prohibition is narrow. A great deal of learning analytics is untouched by it.
| Practice | Status |
|---|---|
| Completion, progression and assessment data | ✅ Not caught |
| Time-on-task and dwell analytics | ✅ Not caught |
| Tab-switching and focus-loss telemetry | ✅ Not caught |
| At-risk identification from engagement patterns | ✅ Not caught |
| Content-level engagement heatmaps | ✅ Not caught |
| Surveys and self-reported experience | ✅ Not caught |
| Gaze and eye tracking | ⚠️ Grey area |
| Facial emotion analysis in a VLE | ❌ Prohibited |
Everything in the green rows can be combined into a genuinely useful engagement picture. Research published in 2024 identified tab-switching as the single strongest predictor of disengagement in online courses — stronger than self-regulation or satisfaction measures. The most predictive signal available is in the lawful column.
Practical steps for institutions
- Inventory what you already run. VLE plugins, proctoring tools, engagement dashboards, lecture capture analytics. Vendors have added AI features to existing products without much fanfare.
- Ask each vendor the direct question in writing. Does the system infer emotions from biometric data at any stage? Intermediate values count.
- Disable emotion features explicitly. In configuration and in the contract.
- Update your DPIA. The AI Act analysis sits alongside, not instead of, the GDPR one.
- Standardise on behavioural signals for engagement measurement. Lawful, better evidenced, and it avoids the student-consultation problem entirely.
- Aggregate to content level. "Week 6 loses 40% of the cohort" is the actionable insight, requires no personal data, and takes the surveillance question off the table.
The point worth holding onto: the EU has not banned understanding whether your teaching is working. It has banned inferring how students feel from their faces. Those were never the same project, and the second one was never where the useful signal lived.
Frequently asked questions
Does this apply to private online course businesses?
Can a university use emotion recognition for research?
What about detecting whether students are struggling?
Does the ban apply to students under 18 specifically?
Learning analytics without the prohibited step
Content-level engagement data from behavioural signals — no camera, no emotion inference, no Article 5 exposure.