- Since 2 February 2025 it has been prohibited in the EU to put an AI system into service to infer the emotions of a person in a workplace, with narrow exceptions for medical or safety reasons.
- That is a prohibition, not a rule you can satisfy with consent or a notice. It sits alongside social scoring and untargeted facial scraping on the same banned list.
- Biometric categorisation to infer union membership, religious or philosophical belief, political opinion or sexual orientation is prohibited in the same article.
- Everything else, from CCTV to keystroke logging to vehicle tracking, is lawful in principle and heavily conditioned in practice.
- Consent is generally unsuitable as the lawful basis between an employer and a worker, because the power imbalance undermines it.
- An impact assessment is mandatory in the UK before keystroke monitoring or any processing of biometric data, whatever the size of the business.
The pitch arrives in an inbox once a quarter now. Software that watches your shop floor and tells you which staff are engaged, which are disengaged, and when somebody is having a bad day. Or a till system that reads faces. Or a productivity tool that scores attention from a webcam.
A good part of that category has been illegal in the European Union since February 2025, and most of the rest is legal only under conditions that vendors do not mention in the demo. The line is unusually clear, which makes this one of the easier decisions a small employer has to make about AI, once somebody tells them where the line is.
What is actually prohibited?
Inferring emotions at work. Not regulating it, not requiring consent for it, prohibiting it, alongside a short list of practices the regulation treats as incompatible with fundamental rights.
Article 5 of the AI Act forbids placing on the market or putting into service AI systems that infer the emotions of a natural person in the areas of workplace and education institutions, except where the system is intended for medical or safety reasons. It applied from 2 February 2025. The same article prohibits biometric categorisation systems that classify people based on their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
The company it keeps tells you how seriously this is meant. The European Commission's own overview of the AI Act lists workplace emotion recognition in the same set as social scoring, manipulation using subliminal techniques, individual predictive policing based solely on profiling, and untargeted scraping of internet or CCTV images to build facial databases. These are not compliance obligations with paperwork attached. They are things a business may not do.
Does this really apply to a shop with four staff?
Yes. The prohibitions in Article 5 are not scaled by company size, and there is no small business exemption attached to them.
This surprises people, because most of the AI Act's heavier obligations are aimed at providers of high risk systems and the compliance burden genuinely does fall differently by role. The banned list is different in kind. It applies to putting a system into service, which is what you do when you switch on a product you bought, and a café using an off the shelf tool to score staff mood is inside it exactly as a multinational would be.
The exception for medical or safety reasons is narrow and is about the purpose the system was built for, not about a justification you invent afterwards. A fatigue detection system for someone operating dangerous machinery is the shape of case it contemplates. Wanting to know whether your shop assistant seems enthusiastic is not.
What about the camera that is already there?
An ordinary security camera is not the problem. What changes its status is software that starts drawing conclusions about the people in the frame.
This is the distinction most small employers miss, and it is worth stating plainly. A camera recording your stockroom is a data protection question with a well worn answer. The same camera with an analytics layer that reports on staff attention, mood or engagement is a different thing that may sit on the prohibited list. The hardware did not change. The inference did.
The upgrade path is how businesses end up on the wrong side of this without deciding to. A security provider adds analytics in a firmware update, a point of sale vendor adds a staff insights dashboard, and nobody signs anything. The general problem of features arriving switched on is covered in our piece on the AI features your business tools enabled without asking, and it applies with particular force to anything pointed at your own employees.
What does the law require for ordinary monitoring?
A lawful basis, real transparency, and in several common cases a written assessment before you begin. The UK Information Commissioner's Office has the most practical guidance available and it treats monitoring broadly.
Its guidance on data protection and monitoring workers defines monitoring as any form of monitoring of people who carry out work on your behalf, and the list is wider than most employers assume: CCTV and cameras, webcams and screenshots, timekeeping and access control systems, keystroke monitoring and productivity tools, internet activity tracking, location tracking and audio recording. It covers both routine monitoring of everyone and occasional monitoring aimed at a specific concern.
| What you might switch on | Status | What it needs before you start |
|---|---|---|
| Software inferring staff emotion or mood | Prohibited in the EU at work | Nothing makes it lawful, including consent |
| Biometric categorisation by belief or union membership | Prohibited in the EU | Nothing makes it lawful |
| Keystroke or screen monitoring | Lawful in principle | An impact assessment is mandatory, plus a lawful basis and notice |
| Fingerprint or face based time clocks | Lawful in principle | Biometric data triggers a mandatory assessment and an extra condition |
| Vehicle tracking and location | Lawful in principle | Lawful basis, notice, and a rule about outside working hours |
Two rows deserve emphasis. Biometric data is special category data, which means a lawful basis is not enough on its own and an additional processing condition is required. And an impact assessment is mandatory, not advisable, before keystroke monitoring or biometric processing, regardless of how small the business is.
Why can you not just ask staff to agree?
Because consent given by someone who depends on you for their income is not considered freely given. The regulator says this directly rather than leaving it to interpretation.
The ICO's assessment of the six lawful bases is unusually blunt for guidance of this kind. Consent is generally unsuitable in employment because of the power imbalance. Contract is rarely appropriate and unlikely to be necessary for monitoring. Legal obligation requires you to name the specific legal requirement. Vital interests is for life or death situations. Public task is for public authorities. What is left, in practice, is legitimate interests, and that requires a three part test covering purpose, necessity and balancing.
Necessity is the part that stops most monitoring proposals if applied honestly. It does not mean useful or convenient. It asks whether the purpose could be achieved another way that intrudes less, and for a great many small business monitoring ideas the answer is that it could, usually by asking someone a question.
The power imbalance point cuts both ways in a very small business. In a shop of three, everyone knows what everyone is doing, and monitoring software is rarely solving an information problem. It is usually solving a conversation somebody does not want to have, which is a management problem that no amount of instrumentation fixes.
What do you have to do before switching anything on?
Five things, and the sequence matters because doing them in the wrong order means redoing them. The first one is the one people skip.
Name the actual problem first, in one sentence, without using the vendor's vocabulary. Stock is disappearing on Tuesday evenings is a problem. Improving team productivity is a capability you were sold. The distinction decides everything downstream, because necessity is measured against a specific purpose and cannot be measured against an aspiration.
Then check the prohibition list, because if the tool infers emotions you have finished and the answer is no. Then choose and record your lawful basis, which in most cases means writing down the three part legitimate interests test rather than ticking a box. Then consult your staff, which the ICO recommends doing at the early planning stage and involving them in the assessment.
That consultation step is the one small employers resist and the one that pays for itself. Objections raised before installation are cheap. The same objections raised afterwards arrive as a grievance, a resignation or a complaint to a regulator, and by then you have also paid for the hardware.
Finally, write it down and tell people. The guidance is explicit that transparency is fundamentally linked to fairness and that avoiding transparency is unfair. Workers have to be told how and why monitoring happens, in information they can actually access and understand, kept current when things change.
Does any of this reach people working from home?
It does, and the guidance says so in terms rather than leaving it to be argued about. Monitoring rules apply to homeworking, to monitoring outside working hours, and to activity on a worker's own device when that device is used for work.
That last case is the one small businesses walk into most often, because the arrangement is usually informal. A part time bookkeeper uses her own laptop. A shop assistant answers customer messages from his own phone because that is where the app is. Any monitoring capability attached to the software they use is now pointed at a personal device, and the fact that nobody intended it does not change what is being collected.
The related trap is time. Monitoring that continues outside working hours is explicitly within scope, which matters for anything always on: a location tracker in a van that keeps reporting after the shift ends, a messaging tool that logs activity at weekends, a device management agent that does not know what a rota is. The fix is usually a setting rather than a policy, and finding it is a ten minute job that nobody does until somebody complains.
Vehicle tracking deserves its own sentence because it is common in small trades and deliveries and it is genuinely useful. The guidance covers tracking work vehicles and vehicles provided to workers, which is a reminder that a van a worker takes home is a place where the line between the business and the person is physically blurred. A tracker that is off outside working hours, and that workers know is off, is both lawful and a great deal easier to live with than one that is not.
If work is happening on personal devices at all, the data question underneath it is worth settling separately, because customer information is moving through accounts you do not control. That is the same problem covered in our piece on what customer data may be pasted into which tools, and the answer in both cases begins with knowing where the work is actually being done.
Can you monitor covertly if you suspect theft?
Almost never, and the exceptions are narrow enough to be worth reading before assuming you qualify. Covert monitoring is described as unlikely to be justifiable outside exceptional circumstances.
Those circumstances involve suspected criminal activity or gross misconduct, authorisation by senior management, a completed impact assessment, and a strictly time limited investigation. There are places it may not happen at all, including toilets and changing rooms, and it must avoid capturing private communications. What is gathered may be used only for the purpose it was gathered for, with access controls, and destroyed after the investigation ends.
For a small retailer with a genuine shrinkage problem, this points away from watching people and towards watching transactions, which is both more effective and far less legally fraught. We went through the workable version of that in a piece on loss prevention in a small shop, where the useful signals sit in the till data rather than in the camera feed.
Does any of this apply outside Europe?
The prohibition does not, and the underlying caution should. There is no general equivalent ban on workplace emotion recognition in most other jurisdictions, and a business operating only outside the EU and UK is in a different legal position.
Two things still travel. Biometric data attracts specific rules in a growing number of places, frequently with private rights of action attached, which makes fingerprint and face based time clocks a disproportionate source of legal exposure relative to the convenience they buy. And the employment consequences are jurisdiction neutral: monitoring introduced without consultation damages trust in a small team in a way that is slow, expensive and hard to reverse.
If you employ people across borders, the practical answer is to apply the strictest standard everywhere rather than operating two policies, because the administrative cost of maintaining the distinction exceeds whatever the looser regime would have permitted. The same reasoning applies to how facial recognition is regulated differently on each side of the Atlantic, which we set out in the piece on two regimes for facial recognition.
What is actually worth doing instead?
Measure outputs, not people. The information a small business genuinely needs about its own operation is almost always available from things rather than from staff, and things do not have rights.
If orders are going out late, the data is in your fulfilment timestamps. If a shift is consistently slower, it is in the transaction log. If stock is disappearing, it is in the difference between what the till recorded and what the count says. None of that requires watching a person, all of it is more reliable than an inference about mood, and none of it sits anywhere near a prohibition. Scheduling is a good example of the same principle applied usefully rather than invasively, which we covered in scheduling a small team with AI.
Where AI genuinely helps in a small business with employees is in the parts of employment that are administrative rather than observational: drafting a rota, summarising a supplier call, keeping a training record current. Hiring is the notable exception, because screening applicants is treated as high risk rather than prohibited and carries its own obligations, which we covered in why AI resume screening is classified as high risk.
The security of whatever you do collect is a separate obligation that survives all of this, and it is worth knowing how the platforms you use handle it, which is why we publish our own security practices rather than describing them in general terms.
The summary for an owner with a few staff is short. Anything that claims to read how your people feel is prohibited at work in the EU and a bad idea everywhere. Anything that records what your people do is permitted and conditional, and the conditions are mostly about telling them first. And the thing you were trying to learn is usually sitting in your own transaction data, where nobody's rights are involved at all.