Prescriptive AI — Regulatory Watch: EU AI Act.

Prescriptive AI — Regulatory Watch

The EU AI Act Doesn’t Just Cover Emotion Recognition. It Names It — and Enforcement Already Started.

The short version: the EU AI Act didn’t arrive in one moment. It’s been phasing in since February 2025, and the deadline enterprises braced for this August was quietly split in two by a last-minute Omnibus. What didn’t get deferred: Article 50(3), which requires informing people exposed to emotion recognition, has been enforceable since 2 August 2026. Emotion recognition is also the Annex III category named for the 2 December 2027 high-risk deadline. The Act mandates transparency, oversight, and logging; the GDPR mandates the consent to do this in the first place. Both converge on the same layer — and it’s the one measurable today, not just promised.

The phased rollout, so far

2 February 2025
Prohibited practices took effect — including Article 5(1)(f), which bans emotion recognition in the workplace and in education outside narrow medical or safety exceptions. Regulatory guidance has flagged call-centre deployments by name. Fines reach up to €35M or 7% of global turnover. Customer-facing emotion recognition is not covered by this prohibition — it falls under Article 50(3) transparency instead.
2 August 2025
Governance rules and obligations for general-purpose AI model providers became applicable; national competent authorities had to be operational.
2 August 2026 In force now
Article 50 transparency duties apply — every chatbot and every piece of AI-generated content in scope. Article 50(3) specifically requires informing people exposed to emotion recognition. The AI Office’s enforcement powers over GPAI providers also activated.
2 December 2027 Deferred, not cancelled
High-risk obligations for stand-alone Annex III systems become enforceable: conformity assessment, registration, risk management, data governance, logging, human oversight. Annex III explicitly names emotion recognition alongside recruitment, credit scoring, education, law enforcement, and essential services.
2 August 2028
High-risk obligations for AI embedded in regulated products (Annex I) — medical devices, machinery, vehicles — come into force.

The Annex III deferral came via the Digital Omnibus on AI (Regulation (EU) 2026/1744), which entered into force on 27 July 2026 — six days before the original deadline. It replaced the Commission’s earlier proposal for a “moveable” high-risk start date, tied to when harmonized technical standards became available, with two fixed dates instead. That’s worth noting on its own: enterprises now have a real date to plan against, not a conditional one.

Why fifteen months isn’t as much time as it sounds

Conformity assessment, technical documentation, and post-market monitoring for a conversational AI system are not things a team stands up in a sprint. For any organization running AI-driven customer interactions at scale, the deferral changes the deadline, not the workload:

  • Human oversight mechanisms have to be designed into the system, not bolted on afterward.
  • Automated logging for high-risk deployments must be retained for at least six months once the regime applies.
  • Fundamental Rights Impact Assessments are required for deployers in the relevant use cases — work that depends on being able to show, not just claim, how a system behaves toward the people using it.

None of that is buildable retroactively in the weeks before a hard enforcement date. Teams that start now are the ones who’ll have documentation, not a data room full of last-minute retrofits, by December 2027.

Know which side of the line you’re on

Emotion recognition sits on two different sides of this regulation depending entirely on who it’s pointed at. Aimed at employees or students — outside narrow medical or safety exceptions — it’s prohibited outright under Article 5(1)(f), at the highest fine tier the Act has. Aimed at customers, it’s lawful and regulated: named in Annex III as a high-risk category for the 2027 deadline, and subject to Article 50(3) transparency duties today. Any vendor discussing this space without drawing that line first hasn’t read the text closely enough to be trusted with the rest of it.

Proof, not promises

None of the three obligations converging on conversational AI — provable oversight, turn-by-turn logging, evidence over assurance — are satisfiable by claiming compliance. They’re satisfiable by showing a reproducible record of what a system actually did. That’s a narrower, harder bar, and it’s the one worth measuring against now rather than in December 2027.

Where we stand today, measured rather than asserted: our latest compliance sweep reproduced 72 out of 72 conversations in English and 72 out of 72 in French, with zero violations across all 24 emotional dyads on consent timing and vulnerability handling — scored by deterministic evaluators that reproduce identically regardless of which underlying model runs them, and independently re-runnable from a SHA-256-verified bundle. We don’t yet have the formal high-risk apparatus — conformity assessment, Annex IV technical documentation, EU database registration, Article 14 human-oversight escalation, a configured log-retention policy, or a bias/disparity metric, which Annex III also expects. None of that is unusual fifteen months out from the deadline. What’s unusual is already having the per-turn evidence trail those requirements will eventually ask for.

What this means for your roadmap

If your conversational AI touches EU customers and infers emotional state, Article 50(3) already applies to you. The question worth asking now isn’t whether you’ll be ready for December 2027 — it’s whether you could show, today, a reproducible record of how your system behaved. That’s the gap worth closing while there’s still runway to close it properly.

Talk to ConsentPlace about AI Act readiness

EU AI Act dates reflect Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal 24 July 2026 and in force since 27 July 2026 — Article 50 unaffected by the Omnibus, Annex III deadline 2 December 2027, Annex I deadline 2 August 2028, Article 5(1)(f) in force since February 2025. ConsentPlace figures: v39.5 compliance sweep, 3 September 2026.

You are:
Name
Newsletter Subscription

Leave a comment

Your email address will not be published. Required fields are marked *