The EU prohibits AI systems that infer emotions from biometric data in workplace and education contexts under AI Act Article 5(1)(f), in force since February 2025. The UK has no equivalent statutory ban, but UK GDPR requires a lawful basis, a DPIA and a proportionality case — and the ICO has publicly warned that emotion detection technologies lack scientific reliability.
A practical orientation for people managing multi-jurisdiction deployments. Take advice on your specific circumstances.
Side by side
| European Union | United Kingdom | |
|---|---|---|
| Statutory ban | Yes — AI Act Art. 5(1)(f) | No equivalent |
| In force since | 2 February 2025 | — |
| Consent cures it? | No | Consent possible in principle, hard in employment |
| Data protection regime | GDPR | UK GDPR + DPA 2018 |
| DPIA required | Yes | Yes for employee monitoring |
| Max penalty | €35m or 7% global turnover | £17.5m or 4% global turnover |
| Regulator stance | Prohibited outright | ICO publicly sceptical |
| Works council | Often decisive | Less commonly a factor |
The EU position: a hard line
Article 5(1)(f) prohibits placing on the market, putting into service, or using AI systems to infer emotions of a natural person in the workplace and in education institutions, except for medical or safety reasons.
The critical structural point is that this is a prohibition, not a high-risk classification. There is no compliance pathway. You cannot document your way in, obtain consent, or negotiate with a works council. The practice is off the table, and both the vendor and the deploying employer are exposed.
The exception is narrow: medical use points at CE-marked devices used therapeutically, and safety means protecting life and health. General employee wellbeing monitoring qualifies as neither.
The UK position: no ban, but no free pass
The UK did not onshore the AI Act. There is no equivalent prohibition, and the UK's approach has been principles-based and regulator-led rather than prescriptive.
But "not prohibited" is a long way from "unproblematic." A UK deployment must clear:
- A lawful basis under UK GDPR. Employee consent is fragile because of the power imbalance; legitimate interests requires a balancing test that emotion inference struggles to pass.
- A special category condition where biometric data is processed for identification purposes.
- A DPIA, which is effectively mandatory for systematic employee monitoring.
- Necessity and proportionality — could you achieve the same purpose with less intrusive means? Given that behavioural signals are the stronger predictor of disengagement anyway, that question has an uncomfortable answer for anyone deploying facial analysis.
The ICO has taken a notably direct public position on biometric technologies claiming to detect emotional states, pointing to the weak scientific basis for inferring reliable emotional conclusions from physiological signals and warning that systems which do not work as claimed create discrimination risk.
That matters practically. If the regulator has already expressed doubt about the reliability of the technology, the necessity-and-proportionality argument becomes considerably harder to run.
The trap: extraterritorial reach
The most common mistake UK organisations make is assuming Brexit settled the question.
If you are a vendor, the AI Act applies to providers placing systems on the EU market irrespective of establishment. A UK company selling engagement analytics to a German customer is in scope.
If you are an employer, deployers located in the EU are in scope. A UK-headquartered company with employees in Dublin, Amsterdam or Madrid is deploying into the EU when those employees take the training.
If you are a training provider, delivering to a client's EU-based staff puts you in a context "related to" the workplace.
The practical answer for multi-jurisdiction employers
You have two options.
Option one: fork the deployment. Facial analysis for UK staff, behavioural-only for EU staff. This means two configurations, two DPIAs, two internal policies, and an unattractive conversation when UK staff discover they are subject to monitoring their EU colleagues are protected from. It also means your engagement data is not comparable across regions, which undermines the point of measuring it.
Option two: standardise on the stricter position. One behavioural-only configuration, lawful everywhere, comparable data, one policy, one DPIA, and no awkward internal narrative.
For almost every organisation, option two is straightforwardly better. The measurement you lose is the three percentage points of accuracy that the facial layer contributes; the complexity you avoid is substantial.
That is the logic behind Emotuit Signals — the same engagement measurement, derived entirely from behavioural telemetry, deployable without a jurisdictional fork.
Frequently asked questions
Can a UK company use emotion recognition on UK staff?
Does the EU AI Act reach UK companies?
Is the UK likely to introduce a similar ban?
What should a multi-jurisdiction employer do?
One configuration, both jurisdictions
Signals uses no biometric data, so the same deployment works for UK and EU staff without a compliance fork.