# AI Surveillance at Work: AI Act Prohibitions Since 2025

> Since February 2, 2025, the AI Act prohibits the use of AI to infer emotions in the workplace. This article details the tools involved, exceptions, and obligations for employers in Europe.

- Tags: IA surveillance travail, AI Act interdiction émotions, Article 5 AI Act, outils analyse émotionnelle travail, RGPD surveillance salariés, systèmes IA haut risque travail
- Main keyword: IA surveillance travail

## Introduction

The AI Act, via its Article 5, formally prohibits the use of artificial intelligence systems aimed at inferring a person's emotions in the workplace. This measure, in effect since February 2, 2025, concerns all European companies, even if its concrete implications remain sometimes poorly understood.

Article 5(1) of the European regulation specifies that the placing on the market, putting into service, or use of AI solutions designed to infer an individual's emotions in a professional setting are prohibited. This includes, in particular:

## Content

## What the AI Act prohibits regarding AI surveillance since February 2, 2025

- The analysis of facial micro-expressions from video or camera feeds.
- The detection of stress or fatigue through voice recognition.
- The assessment of attention during meetings via voice or eye-tracking.
- Any system using biometric sensors to determine an emotional state.

The exceptions to this rule are very limited and primarily concern medical or safety uses, such as preventing drowsiness in professional drivers. Outside of these cases, the prohibition is strict.

> "Emotional inference at work is now a legal and ethical boundary set by Europe to guarantee the fundamental rights of employees."

## Emotional analysis tools: who must stop?

Many popular tools include emotional analysis features. Their status regarding the AI Act is now critical for employers.

Here are some examples of tools affected by the Article 5 prohibition:

**HireVue**

Video analysis of candidates, including emotion detection via facial expressions.

*Prohibited* for HR use in Europe since February 2, 2025.

**Affectiva**

Emotional analysis tool using facial and voice recognition, used in training or assessment.

*Prohibited* for professional use in Europe.

**Microsoft Teams (advanced features)**

Certain experimental features measure participant engagement in meetings based on voice or gaze.

*Under evaluation* by the AI Office. Use is discouraged at this stage.

**Otter.ai**

Automatic meeting transcription, with tone and engagement analysis.

*Under evaluation* for European professional use.

The providers of these tools have until November 2, 2026, to comply with the transparency requirements of Article 50, but the Article 5 prohibition already applies. Companies using these solutions face sanctions of up to 35 million euros or 7% of their total worldwide annual turnover.

## Productivity surveillance: a high-risk zone

The AI Act does not prohibit all forms of productivity surveillance, but certain practices may be classified as high-risk under Annex III.

Productivity tracking tools are not covered by Article 5, but they may fall under Annex III if:

- They are used for work management or access to employment (Annex III, point 4).
- They create behavioral profiles of employees.
- They automate performance evaluation.

Some examples and their likely status:

**Time Doctor**

Time tracking, random screenshots, keyboard/mouse activity analysis.

*Likely high risk* if used to evaluate performance.

**Hubstaff**

GPS tracking, screenshots, real-time monitoring.

*Likely high risk* for HR purposes.

**ActivTrak**

Habit analysis, distraction detection, activity reports.

*Likely high risk* if used for HR decisions.

**Microsoft Viva Insights**

Habit analysis, productivity recommendations, Teams/Outlook integration.

*Uncertain status*, depends on usage and settings.

The classification depends on the exact usage: simple time tracking remains low risk, but automated performance evaluation shifts to high risk. Employers must therefore precisely document their usage and conduct a case-by-case assessment.

## GDPR: complementary obligations to the AI Act for employee surveillance

GDPR remains fully applicable: the AI Act does not replace it. Companies must comply with both frameworks to avoid cumulative sanctions.

Employee surveillance is governed by GDPR, notably through:

- Data minimization (Article 5(1)(c)).
- The obligation to inform employees (Articles 13 and 14).
- The obligation to conduct a Data Protection Impact Assessment (DPIA) for high-risk processing (Article 35).
- Mandatory consultation with the Social and Economic Committee (CSE) for any surveillance system (Article L. 2312-38 of the Labor Code).

The CNIL has published [recommendations on employee surveillance in telework](https://www.cnil.fr/fr/teletravail-les-regles-applicables-la-surveillance-des-salaries). It reminds that surveillance must remain proportionate and transparent. For example:

- Random screenshots are authorized if their use is justified and limited.
- Real-time tracking of keyboard/mouse activity is considered too intrusive and should be avoided.
- Employees must be informed of the existence and objectives of surveillance devices.

The [Barbulescu II ruling by the CJEU (2017)](https://curia.europa.eu/juris/document/document.jsf?text=&docid=192562&pageIndex=0&doclang=fr&mode=lst&dir=&occ=first&part=1&cid=10000) has already set strict limits on the surveillance of employee communications. The AI Act reinforces this framework by prohibiting certain practices and classifying others as high-risk.

## How to implement AI Act and GDPR compliance?

To avoid sanctions and protect employee rights, employers must act methodically.

Here are the key steps:

1. **Inventory tools used**: Identify all AI systems involved in employee surveillance or evaluation. Verify their status regarding Article 5 or Annex III of the AI Act.
2. **Classify systems**: Determine for each tool whether it is prohibited, high-risk, or low-risk. Document this classification.
3. **Comply with GDPR**: Inform employees, conduct an impact assessment when necessary, consult the CSE.
4. **Adapt practices**: Disable prohibited functions (emotional analysis), limit high-risk uses to strictly necessary situations.
5. **Train teams**: Raise awareness among managers and HR regarding legal limits, inform employees of their rights.
6. **Document compliance**: Maintain a register of AI processing, keep proof of compliance, prepare responses in case of an audit.

Employers can rely on the [AI Office guidelines](https://artificialintelligenceact.eu/) and [CNIL recommendations](https://www.cnil.fr/fr/reglement-europeen-protection-donnees/chapitre4) to structure their compliance. In case of doubt, a [compliance diagnostic](https://compaia.eu/diagnostic) helps identify risks specific to each organization.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/ia-surveillance-travail-ce-que-l-ai-act-interdit-vraiment)
