Emotion recognition and biometric categorisation: the information duty of Article 50(3)
If you deploy emotion recognition or biometric categorisation, you must inform the people exposed to it. Article 50(3) of the EU AI Act has applied since 2 August 2026 and places that duty on you as the deployer. Embed AI maps your use cases, first tests whether they are permitted at all, and delivers the information texts and evidence that demonstrate compliance.
Paragraph 3 check
1 week
From biometric use case to a demonstrable information duty
First the prohibition test: is this use case allowed
Per use case: does paragraph 3 apply and who is the deployer
Information texts for employees, customers and visitors
Linkage to the GDPR, because this is almost always personal data
The first question is not how you inform, but whether you may deploy at all
Emotion recognition in the workplace and in education falls under the prohibited practices of the EU AI Act, and those have been enforceable since 2 February 2025. Only use on medical or safety grounds sits outside that prohibition, and that exception is narrower than vendors often suggest. Part of biometric categorisation is prohibited as well. Only once a use case passes that test does the information duty of Article 50(3), applicable since 2 August 2026, come into play. Embed AI always takes these two steps in that order, because a polished notice under a prohibited use case solves nothing.
When does your use case fall under the prohibited practices?
Embed AI reviews context, purpose and the people involved per use case. These situations need attention first.
Measuring emotions in the workplace
Sentiment scoring of employee customer conversations, stress or attention detection during screen work, and emotion scoring in job interviews touch the prohibition on emotion recognition in the employment relationship directly. The regulation allows one narrow exception here, for use on medical or safety grounds, and you must be able to substantiate it per use case.
Measuring emotions in education
Attention, engagement or stress detection among students and course participants falls in the same category, even when the vendor presents it as learning support.
Categorising by sensitive attributes
Biometric categorisation that sorts people by, for example, ethnicity, political opinion, religion or sexual orientation is prohibited, regardless of what the label is called inside the software.
What exactly does Article 50(3) require?
Paragraph 3 places the duty on the deployer, meaning the organisation that puts the system to use in practice. Your vendor does not take that duty off your hands.
Inform the people exposed
You inform the persons exposed to the system about its operation. That happens beforehand and in a place where they actually see it, not buried in general terms.
Process the personal data under the GDPR
Emotion recognition and biometric categorisation almost always run on personal data and often on special categories. Legal basis, DPIA and retention belong to the same decision, not to a separate track.
Do not lean on your vendor
Point 117 of Commission guidelines C(2026) 5054 final of 20 July 2026 is explicit: a deployer may not rely on the provider machine-readable marking. Your information duty stands on its own.
Arrange the chain and contractors contractually
Point 12 requires proportionate measures in distribution chains, including contractual arrangements. Point 14 states that a legal person remains the deployer even when freelancers or an agency actually operate the system.
Mind the scope of the transition period. The only transition runs through paragraph 2 and applies solely to systems placed on the market before 2 August 2026, until 2 December 2026. No such room exists for the information duty of paragraph 3: it applies now. Point 124 of the guidelines adds that the lighter transparency regime does not justify infringing intellectual property or data protection rights.
Where does this sit in your organisation?
This duty rarely appears under the name biometrics. It hides inside tooling that teams procured themselves.
HR and recruitment
Video interview tools with sentiment or enthusiasm scores, conversation analysis, and tooling that ranks candidates on voice or facial expression.
Customer contact and contact centre
Speech analytics that scores caller emotion, real-time coaching based on tone, and quality monitoring across conversations.
Retail and public space
Camera analytics that sorts visitors by age, gender or mood, and shelf analytics that pulls faces into the frame instead of products.
Security and access
Behaviour and emotion detection in surveillance footage, aggression detection, and access systems that do more than identify.
Research and market insight
Panel research with facial coding, advertising tests with emotion measurement, and user research using camera footage.
Legal, privacy and compliance
Teams that want the prohibition test, the information duty and the GDPR basis in one file instead of three separate tracks.
What the check delivers
Inventory of use cases with emotion recognition or biometric categorisation
Prohibition test per use case, with explicit attention to workplace and education
Role determination: are you deployer, provider or both
Concrete information texts for employees, customers, visitors and participants
Placement advice: where and when the notice must be visible
GDPR linkage: legal basis, DPIA signal, retention and data subject rights
Contractual points toward vendors and contractors per point 12 and point 14
Evidence pack and action list with owner and priority per use case
Approach in 1 week
Scope and intake
We collect which systems analyse faces, voices or behaviour, including tooling that entered through HR, marketing or facilities.
Prohibition test
Per use case we determine whether it falls under the prohibited practices. Workplace and education come first, because enforcement there has been possible since 2 February 2025.
Assessment against paragraph 3
For what remains we record who the deployer is, which persons are exposed, and what information they must receive beforehand.
Texts and placement
You receive ready-to-use information texts plus advice on the moment and the place where the notice becomes visible.
GDPR and chain
We connect the findings to legal basis, DPIA and retention, and name the arrangements needed toward vendors and contractors.
Action list and evidence
You close with an action list carrying owner and priority, and an evidence pack you can use to show compliance.
Who this works for
HR leadership and recruitment leads
Who need to know whether their selection tooling may still be used and what candidates and employees must hear beforehand.
Customer contact directors
Who want to keep speech analytics and quality monitoring running without leaving the information duty open.
Security and facility management
Who deploy camera analytics and access systems and need the difference between identifying and categorising to be sharp.
Legal, privacy and compliance
Who want to bring the EU AI Act and the GDPR into one decision instead of two separate files.
Afterwards you know
Whether the use case is permitted at all
Who the deployer is per use case
Which persons you must inform beforehand
Which text becomes visible where and when
How the GDPR basis and retention stand
Which evidence you have ready when questions come
What it costs
Embed AI works with fixed fees, so you know where you stand up front.
AI governance scan
EUR 2,950
Compact scan that puts your use cases through the prohibition test and the duties of Article 50. The amount is deductible from a follow-up engagement.
AI Act Readiness Sprint
EUR 9,900
Broader sprint across your AI portfolio: roles, risk classes, duties, evidence and roadmap in one engagement.
Bundle
EUR 21,900
The sprint plus implementation and training support, for organisations that want it settled in one go.
What is at stake?
For a breach of Article 50 the supervisory authority can impose a fine of up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher. That is a ceiling and not an automatic outcome. The code of practice on transparency of AI-generated content of 10 June 2026 is voluntary to sign. Point 148 states that whoever does not sign must demonstrate through other appropriate means how they comply, and point 149 that adherence may count as a mitigating circumstance in a fine. That makes an ordered file practically valuable.
Logical next steps
Article 50 transparency check
For the broader view across all four transparency duties, including chatbots, synthetic content and deepfakes.
View routeFRIA and DPIA for AI systems
For the data protection side of biometric use cases: legal basis, risk and assessment in one file.
View routeAI inventory setup
For a compact inventory of AI systems with owner, purpose, role and evidence status.
View routeBackground and training
Legal depth on Praxikon and role-specific training via LearnWize:
- Article 50: the 2 August 2026 transparency deadline that was not postponed
- Article 50 for providers and deployers: who must arrange what
- Article 50 in practice: labeling and detection of AI content
Training for the teams that execute
Whoever switches on the camera or operates the interview tool must know when informing is mandatory. LearnWize delivers the role-specific transparency training for HR, customer contact, security and marketing.
View the Article 50 transparency trainingFrequently asked questions
May I use emotion recognition to support my employees?
Emotion recognition in the employment relationship falls under the prohibited practices of the EU AI Act, enforceable since 2 February 2025. A good intention or a positive framing such as wellbeing monitoring makes no difference. The regulation allows one narrow exception, for use on medical or safety grounds, and it is narrower than vendors often suggest. The same prohibition applies in education. Embed AI therefore first tests whether the use case is permitted and only then how you inform.
What is the difference between biometric identification and biometric categorisation?
Identification answers who someone is. Categorisation sorts people based on biometric data, for example by age, gender or mood. Article 50(3) covers emotion recognition and biometric categorisation and requires you to inform the persons exposed about the operation of the system. Categorisation by sensitive attributes may additionally be prohibited.
Our vendor says transparency is already handled. Is that enough?
No. Point 117 of Commission guidelines C(2026) 5054 final of 20 July 2026 is explicit: a deployer may not rely on the provider machine-readable marking. The information duty of paragraph 3 rests on you. What the vendor does you record contractually per point 12, but it does not replace your own duty.
We hire freelancers who operate the system. Does the duty shift?
No. Point 14 of the guidelines states that a legal person remains the deployer even when freelancers are engaged. The organisation using the system under its own authority keeps carrying the information duty. It is wise to record the working instructions and the arrangements with contractors in writing.
Is there still a transition period for paragraph 3?
No. The only transition runs through paragraph 2 and applies solely to systems placed on the market before 2 August 2026, until 2 December 2026. The information duty of paragraph 3 applies now. Regulation (EU) 2026/1744 has been in force since 27 July 2026 and moved high-risk Annex III to 2 December 2027 and Annex I to 2 August 2028, but left Article 50 untouched.
What does this cost and how much internal time does it take?
The AI governance scan costs EUR 2,950 and is deductible from a follow-up engagement. Internally it usually takes 1 to 2 short interviews, an overview of the systems involved and one review moment. Embed AI does the drafting, the texts and the evidence pack.
Know within a week whether your biometric use case is allowed and how you inform.
Start with the free transparency scan. Embed AI then determines per use case whether the prohibition test holds and which information duty rests on you.