This checker walks through the four elements of EU AI Act Article 5(1)(f): whether the system is an AI system, whether it infers emotions, whether it uses biometric data, and whether it is deployed in a workplace or education context. All four must be present for the prohibition to apply.
What this checks
The prohibition in Article 5(1)(f) requires four elements to be present at the same time. Remove any one and the prohibition does not apply, though GDPR obligations continue regardless.
- An AI system within the Article 3(1) definition
- That infers emotions of a natural person
- From biometric data under the Article 3(34) definition
- In a workplace or education institution context
Plus one carve-out: use for genuine medical or safety reasons, construed narrowly.
The checker walks these in the order that resolves fastest, so most people exit after two or three questions rather than working through all six.
Why two of the answers are "grey area"
Because they genuinely are, and a tool that pretended otherwise would be worse than useless.
Gaze and eye tracking. Eye position is likely biometric data under the AI Act's broad definition, which drops GDPR's "unique identification" requirement. Whether tracking it is caught depends on the inference drawn downstream. Attention position may be defensible. An affective conclusion is not.
Secondary functionality. The Commission guidelines explicitly do not resolve whether a system whose primary purpose is something else — proctoring, say — but which also produces emotional inferences, falls within the prohibition. The literature uses exactly this example and leaves it open.
If you land in either, that is the useful output: you now know precisely which question to put to a lawyer, rather than asking them to review the whole deployment from scratch.
After the checker
A clean result on Article 5 is a screen, not a clearance. You will still need to complete a DPIA for any systematic monitoring of employees or students, because the power imbalance makes it high-risk processing regardless of how benign the signals are.
The good news is that a behavioural-only deployment makes that assessment dramatically simpler — no special category data, a much stronger proportionality argument, and a one-line answer to the AI Act section.
Frequently asked questions
Is this legal advice?
Is my data stored?
What if I get a grey-area result?
Got a result you did not want?
Signals measures engagement from behavioural telemetry alone — no camera, no biometric data, no Article 5 exposure.