Skip to content

AI Governance & Ethics

Start Your EU AI Inventory With Uses That May Be Banned

Before ranking hundreds of AI systems by risk, identify uses that may be prohibited outright. A focused interview can expose issues hidden by product names and vendor claims.

Irene VaskoGovernance & Ethics Writer

August 9, 2026 · 8 min read

Laptop displaying an AI intake record beside call-center documentation with a stress-score field marked for review.
Laptop displaying an AI intake record beside call-center documentation with a stress-score field marked for review.

The fastest way to find a serious EU AI Act problem may be to ignore the risk spreadsheet for a week.

Take a hypothetical call-center dashboard that transcribes employee conversations, scores each speaker’s apparent stress and sends low-scoring calls to a supervisor. Its inventory entry might say “quality analytics,” while the vendor describes coaching, sentiment or engagement. Neither label reveals the consequential mechanism: software is using voice signals to infer an employee’s emotional state in a workplace.

That detail matters because the EU AI Act prohibits certain uses rather than merely placing them in a demanding compliance tier. The prohibition covering workplace emotion recognition includes “the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions,” subject to an exception for medical or safety reasons. The prohibitions have applied since February 2025. They are not a future proposal, although European Commission guidelines on their interpretation are nonbinding and national authorities and courts will determine how disputed cases are treated.

An organization should still build a complete inventory and classify systems that may be high-risk. The sequencing is the point. If a use falls within Article 5’s prohibited practices, adding human review, better accuracy testing or a high-risk label does not turn that use into an acceptable deployment.

Start with behavior, not the product category

A useful first-pass record fits on one screen. Give each system a named owner, describe the people affected, identify the input data, record the model’s output and state what happens next. Add the intended purpose, deployment context and any claimed exception, with a link to evidence rather than a checkbox saying “compliant.”

For the call-center dashboard, that record would say that employee voice recordings enter a model, the model emits a stress or emotional-state score, and supervisors use the score to select calls for review. A data-flow diagram, which maps where information enters, moves and triggers an action, is more revealing than the procurement description. It also makes the fallback visible: if the emotional score is switched off, managers could review a sample of transcripts or evaluate objective events such as missed disclosures instead.

Do not begin the interview by asking whether the tool uses prohibited AI. A product owner may reasonably say no because the vendor has never used that phrase. Ask for a demonstration of one ordinary run, from input to user-visible result, then inspect the configuration panel and downstream automation. Features disabled by default still belong in the record if administrators can enable them.

The interviewer should preserve receipts: screenshots of settings, model or feature documentation, prompts used in production, sample outputs, integration diagrams and the contractual description of purpose. A model card, which documents a model’s intended uses and limits, can help, but it cannot establish how a customer configured the surrounding product.

Trace manipulation to the decision and the harm

The AI Act does not ban every persuasive interface. Its manipulation prohibition has several linked conditions, and dropping any of them creates an inaccurate screening rule.

Article 5 covers systems that deploy “subliminal techniques beyond a person’s consciousness or purposefully manipulative or deceptive techniques” when their objective or effect is to materially distort behavior by appreciably impairing an informed decision, causing that person to make a decision they otherwise would not have made, in a manner that causes or is reasonably likely to cause significant harm. A related provision addresses exploitation of vulnerabilities tied to age, disability or a specific social or economic situation, again with behavioral distortion and significant-harm conditions.

Translate that language into an interview about mechanics. Have the owner show how the system chooses a message, offer, ranking or conversational response; what outcome it optimizes; which user attributes change the treatment; and what consequential decision follows. Then ask what the person sees, what alternatives remain visible and whether the system adapts after hesitation or refusal.

A chatbot that changes sales pressure based on inferred financial distress deserves closer review than a static recommendation banner. That does not establish that the chatbot is prohibited. The organization still has to examine the technique, impaired decision-making, causation and significant-harm threshold, and other consumer, privacy or sector rules may apply even where the AI Act prohibition does not.

Avoid reducing this check to keyword scanning for “nudging” or “personalization.” The relevant evidence may sit in an optimization target, an experimentation dashboard or a prompt telling a model to persist until the user accepts. Interview the growth or operations owner who selected that target, not only the machine-learning team that supplied the model.

Inspect sensitive inferences at the signal level

Biometric data, in this context, comes from technical processing of physical, physiological or behavioral characteristics and allows or confirms unique identification. The prohibited-practices screen must look beyond facial recognition used to name someone.

Article 5 also covers biometric categorization systems that individually categorize people based on biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. The text contains limited exclusions, including labeling or filtering lawfully acquired biometric datasets and certain law-enforcement categorization, so teams should not paraphrase the rule as “all sensitive inference is banned.”

Ask the product owner to open the feature schema, meaning the list of signals supplied to the model, and the output labels. A field called “audience affinity” may be generated from a face, voice or gait and then mapped to a sensitive category elsewhere in the pipeline. Conversely, an inference based only on purchase history may raise serious data-protection concerns without fitting this biometric-categorization prohibition. Input route matters.

The interview should follow derived data too. If the system creates a face embedding, a numerical representation of facial features, determine whether another service uses it to assign a listed sensitive trait. Splitting collection and categorization between vendors does not make the overall workflow disappear, although responsibility and legal characterization require case-specific analysis.

For each suspected inference, retain a sample output and the documentation that explains how it was produced. A vendor’s statement that it does not store photographs answers a storage question. It does not answer whether biometric data was processed to generate a category before deletion.

Separate workplace monitoring from emotion recognition

The call-center dashboard returns here because broad phrases create errors in both directions. The AI Act does not prohibit every form of workplace monitoring, and a rule saying “all employee analytics are banned” would stop legitimate inventory work without quoting the actual constraint.

The narrower screen asks whether AI infers emotions or intentions from biometric data in a workplace. Interviewers should request the output taxonomy, training objective and validation material, then compare those materials with what managers see. Labels such as sentiment, mood, engagement, frustration, enthusiasm or emotional risk deserve examination, but the marketing label alone does not settle whether the legal definition is met.

The medical-or-safety exception also needs evidence. An owner should identify the specific medical or safety purpose, show why the feature is configured for it and document which downstream actions remain within that purpose. “Employee wellness” is not self-proving, while a system presented as detecting fatigue still needs analysis of what it measures and whether it is inferring an emotion, a physical state or something else.

If the dashboard’s emotional scoring cannot be supported, the practical fallback is to disable that output and test the remaining workflow independently. Transcription, objective script checks and random quality sampling create their own privacy, labor and accuracy obligations, but they should not be treated as emotion recognition merely because they share the same interface.

Give every red flag an owner and a stop state

A prohibited-use screen should produce one of four operational results: no indicator found, more evidence required, counsel review or deployment stopped. The label should carry an owner, a dated evidence link and the product version or configuration examined. Without those fields, a later settings change can invalidate the assessment while the spreadsheet remains green.

Set a short evidence deadline for ambiguous cases. If the vendor will not disclose whether a voice score represents emotion, the organization should not resolve the uncertainty by accepting “AI-powered coaching” as a technical description. Disable the feature, isolate it from employee decisions or pause deployment while the responsible legal and governance teams review the facts.

After this pass, continue into risk classification. The AI Act separately identifies high-risk systems and imposes requirements concerning areas such as risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity. Some systems fall outside both the prohibited and high-risk categories while remaining subject to transparency duties, data-protection law, employment rules or internal policy.

The first inventory therefore stays narrow. For the call-center tool, the decisive artifact is not a hundred-column risk score. It is the settings screenshot showing that the stress field exists, the data flow showing employee voice as its input and the written decision to disable or escalate that feature.

Questions people ask

Should we classify high-risk systems before checking prohibited practices?

No. Run the prohibited-practices screen first because a high-risk classification and its controls cannot cure a use that Article 5 bars. Keep the first pass focused, then classify every system that remains in scope and document why each suspected prohibition did or did not apply.

Is all

AI-based workplace monitoring prohibited in the EU?

No. The AI Act’s workplace prohibition discussed here concerns using AI to infer emotions, subject to a medical-or-safety exception. Transcription, productivity measurement and objective quality checks require separate analysis under the AI Act and other laws, but they are not automatically prohibited emotion recognition.

Is a vendor’s compliance statement enough evidence?

No. Obtain the feature documentation, input signals, output labels, enabled settings and downstream actions for your deployment. A vendor may assess a default configuration while your administrators enable an optional score or connect it to an employment decision.

Do pilots and internal tests belong in the inventory?

Yes. Record pilots, sandboxes and disabled features when real personal data or affected people are involved, while noting the deployment state and access controls. If a questionable call-center score is off, preserve the settings screenshot and prevent administrators from enabling it until the review is complete.

ShareFacebook
ai governanceai regulationeu ai actprohibited ai practicesai inventorybiometric dataworkplace ai

One story a day

The story of the day, in your inbox

One real story about AI each morning — no hype, no alarm, just company for the road.

Read next

Laptop displaying a cropped airport image beside metadata fields and a Content Credentials verification panel.

AI Governance & Ethics

What an AI-Generated Image Label Can Actually Prove

A visible badge, file metadata, generation log, and signed Content Credential answer different questions. Cropping and reposting expose the gaps between them.

Irene Vasko · 8 min read

A support chat labeled Automated assistant beside a phone displaying an incoming customer-service callback.

AI Governance & Ethics

When a Customer-Service Bot Has to Say It Is a Bot

There is no blanket U.S. disclosure rule. A practical answer depends on where the customer is, what the bot is doing, and whether chat becomes an AI-generated call.

Irene Vasko · 8 min read

A laptop displaying a hiring bias-audit table beside a printed job notice and handwritten calculation notes.

AI Governance & Ethics

How to Read NYC’s Hiring-AI Bias Audit Before You Apply

A public audit can reveal which hiring system was tested, whose outcomes were counted, and where selection rates diverged. It can also conceal job-level differences and omit demographic groups.

Irene Vasko · 8 min read