· By Marcus Webb

The EU AI Act's Emotion Recognition Ban: What It Actually Means for Your Meeting Assistant

The EU AI Act reached general applicability on 2 August 2026, and a lot of coverage claimed sentiment analysis in meeting tools is now illegal. That is not quite right — and the real rule is narrower, older, and more interesting.

On 2 August 2026 the EU AI Act reached general applicability, the last major milestone in its staged rollout. Within a week the AI-tooling corner of the internet had produced a lot of headlines announcing that sentiment analysis in meeting software was now illegal, that Read.ai and Avoma were about to be banned in Europe, and that anyone running conversation intelligence on EU staff was facing a 7% turnover fine.

Most of that is wrong, or at least wrong enough to be useless if you are the person who has to make a decision about it. The actual rule is narrower than the headlines and more specific than most vendors are being asked about. It is worth getting right, because the part that is prohibited is genuinely prohibited, and consent will not save you.

What the rule actually says

The relevant provision is Article 5(1)(f). It prohibits placing on the market, putting into service, or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions. Read with the Article 3(39) definition of an emotion recognition system and the Commission’s guidelines, the inference in question is one drawn from biometric data — voice, face, keystroke dynamics, posture.

Three things about that sentence do the work.

It is a prohibition, not a restriction. Article 5 is the Act’s list of banned practices. This is a different category from the high-risk regime, which imposes conformity assessments and documentation. A prohibited practice is simply not allowed, and the ceiling for administrative fines under Article 99 is the higher of €35 million or 7% of worldwide annual turnover.

Consent does not cure it. This is the point most commentary misses, and it is the most important one for anyone used to thinking in GDPR terms. Under GDPR, consent is one available lawful basis for processing; get it and you may proceed. Article 5 does not work that way. A prohibited practice remains prohibited even if every employee in the building signs a form agreeing to it. Employers reaching for a consent checkbox here are solving the wrong problem.

It hinges on biometric data. This is the limiting condition, and it is where the “your tool is now illegal” claims fall apart. Strictly, the operative text of Article 5(1)(f) bans inferring emotions in workplace and education settings; the biometric limb comes from the Article 3(39) definition of an emotion recognition system, read together with the Commission’s guidelines.

The distinction that decides your case

The Act defines biometric data as personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a person.

The European Commission’s guidelines on prohibited practices then draw a line that matters enormously for meeting software: inferring emotions from written text does not fall within the scope of the prohibition.

Think about what that means mechanically. Most meeting assistants that advertise “sentiment analysis” are not analysing your voice. They transcribe the call to text, then run a language model over the transcript to judge whether the customer sounded positive or negative about pricing. That is text analysis. On the Commission’s reading, it sits outside Article 5(1)(f).

Now consider the other implementation. Some conversation-intelligence systems analyse the audio signal itself — tone, pitch, pace, prosody — to infer emotional state. Voice is a behavioural and physiological characteristic. That is far closer to the line, and in a workplace context it is the implementation most likely to be caught.

So the question is not “does this tool do sentiment analysis.” The question is “does it infer emotion from the audio, or from the transcript?” Those two products look identical in a feature list and sit on opposite sides of a prohibition carrying a 7%-of-turnover ceiling.

A few more boundaries worth knowing. The prohibition does not cover inferring intentions, does not cover physical states like fatigue or drowsiness, and does not cover emotions derived from non-biometric sources. The exceptions for medical and safety purposes are read narrowly: strictly therapeutic uses with CE-marked medical devices, or protecting life and health. General workplace wellness monitoring — burnout detection, stress scoring — is not covered by the exception.

The guidelines also make clear the prohibition binds deployers, not only providers. An employer cannot rely on a vendor’s terms forbidding workplace emotion use as a defence for having deployed it that way.

There is also a separate, lesser duty in Article 50(3): where an emotion recognition system is permitted at all, deployers must inform the people exposed to it. That is a transparency obligation, and it applies in contexts outside the workplace and education settings that Article 5 bans outright. Do not confuse the two — satisfying Article 50 does nothing for you if Article 5 applies.

Two date corrections, because they keep getting repeated

A great deal of August coverage stated that the emotion recognition ban “took effect” on 2 August 2026. It did not, and neither did the penalties.

The Article 5 prohibitions have applied since 2 February 2025. The administrative fines that back them, under Article 99, have been available since 2 August 2025 — Article 113(b) brought Chapter XII into application then. What arrived on 2 August 2026 is general applicability of the Act’s remaining obligations, including the Article 50 transparency duties.

So if your tool has been inferring employee emotions from voice data in an EU workplace, the exposure is not new and it has been enforceable for a year. The August 2026 milestone is real, but it is not the starting gun that most of the coverage claimed.

What this means for the tools we review

Of the 28 AI meeting assistants we rank, three ship features that put this question in play: Read.ai, whose engagement and sentiment scoring was its original product; Avoma, which extracts buyer sentiment as part of its revenue intelligence; and Fireflies.ai, which includes sentiment analysis in its conversation intelligence suite.

None of the three publishes, as far as we can find, a clear statement of whether their sentiment inference runs on audio characteristics or on transcript text. That is not an accusation. It is a documentation gap, and it is one that every European buyer of these tools should now be closing in writing.

We have added a note to each of those three reviews rather than adjusting scores, because the honest position is that we do not know which implementation each uses, and guessing would be worse than saying so.

There is a second-order point worth making. Read.ai’s analytics were already the subject of internal pushback in the organisations we spoke to, well before any of this — people dislike being scored on talk time and engagement by software their manager can see. The regulation has now given that discomfort a legal shape in Europe. Tools whose value proposition rests on measuring participants rather than capturing content are in a structurally harder position than they were two years ago.

The questions to actually ask your vendor

If you are deploying a meeting assistant to employees in the EU, put these in an email and keep the reply.

Does any feature infer emotional state? Get a yes or no covering sentiment scoring, engagement analytics, mood tracking, and any coaching feature that grades tone.

If yes: does it infer from audio characteristics, or from transcript text? This is the determinative question. Ask for a technical answer, not a marketing one.

Can the feature be disabled at the workspace or tenant level? For most organisations, the cleanest response is to turn it off for EU staff and move on. If the vendor cannot switch it off per-region, that is itself a finding.

Which entity is the provider and which is the deployer for this feature? Article 5 binds both. You do not get to point at the vendor.

What is the contractual position on Article 5? Reputable vendors will have thought about this by now. Ones that have not are telling you something.

The broader pattern

Something consistent is happening across the regulatory picture this year, and this is the second instance of it in a month. In the Otter.ai ruling a US court held that a vendor which independently collects, retains, and uses meeting recordings for its own commercial purposes can be treated as a third-party eavesdropper. Here, European law says certain inferences about employees are off the table regardless of what anyone consents to.

Both point the same direction: the legal system is becoming less interested in whether you clicked agree, and more interested in what the software actually does with what it hears. Architectures that minimise what leaves the room age well under that pressure. Architectures built on collecting as much as possible and sorting out the paperwork later do not.

That is not an argument for any particular product. It is an argument for asking a specific question — where does this data go, and what is inferred from it — before you deploy, rather than after a regulator does.

For teams working through the European compliance picture more broadly, our GDPR and EU data residency guide covers residency, subprocessors, and no-training commitments across every tool we rank.


This article is analysis, not legal advice. The application of Article 5(1)(f) to any specific product depends on technical facts about that product and on guidance that continues to develop. Take advice on your own deployment.