Which Countries Ban Emotion Recognition AI?
Only the European Union bans it outright, and only in two settings. EU AI Act Article 5(1)(f) has prohibited emotion recognition in workplaces and educational institutions since 2 February 2025, except where deployed for medical or safety purposes. No other major jurisdiction prohibits it at all. The United Kingdom, United States, Singapore and Australia each permit emotion recognition in every setting, including recruitment, and regulate it through general data protection, discrimination and consent law instead. That makes the practical ranking close to the reverse of what buyers expect: Singapore is the most permissive, the EU the most restrictive, and the United States — despite having the fewest prohibitions of anywhere — carries by far the largest financial exposure, because Illinois BIPA lets individuals sue for $1,000 to $5,000 per violation without proving harm. California's AB 1883, presented to the Governor on 10 September 2026, would add the first US prohibition.
This is not legal advice. It is a buyer's orientation to a fast-moving area, written by a vendor in the category. Positions vary between practitioners and several of the instruments below are in force only in part. Take specific advice before deployment, and treat any vendor claim — including ours — as something to verify rather than accept.
One prohibition, four jurisdictions without one
The headline most buyers carry into procurement is that emotion recognition has been banned. That is true of exactly one jurisdiction, in exactly two settings. Everywhere else the technology is lawful in every setting, including the ones that attract the most objection, and the constraint arrives through data protection, consent and discrimination law rather than through a prohibition.
The consequence is that “is it legal?” is close to useless as a procurement question outside the EU. The useful question is what a deployment has to survive: which regulator, which claimant, which evidential burden, and what the documented answer looks like when someone asks for it eighteen months later.
The table below is a scoping aid for the conversation with your own counsel, not a substitute for it. Each jurisdiction links to the full treatment.
The five jurisdictions compared
| Jurisdiction | Prohibition? | What governs instead | Chief exposure |
|---|---|---|---|
| European Union → | Yes — workplaces and education | AI Act Article 5(1)(f), from 2 February 2025; GDPR alongside | Highest AI Act penalty tier; absolute prohibition, no consent gateway |
| United Kingdom → | None | UK GDPR, DPA 2018, Articles 22A–22D from 5 February 2026, Equality Act 2010 | ICO scrutiny plus Equality Act claims brought by individuals, not regulators |
| United States → | None federally; California AB 1883 pending | Illinois BIPA and AIVIA, Texas CUBI, Colorado SB 24-205, NYC Local Law 144, ADA and Title VII | BIPA private right of action, $1,000–$5,000 per violation, no harm required |
| Singapore → | None | PDPA; IMDA Model AI Governance Framework and AI Verify, both voluntary | Reputational and contractual rather than statutory; EU reach is the real constraint |
| Australia → | None | Privacy Act 1988, APP 3.3 consent, ADM transparency from 10 December 2026 | OAIC determinations; the Bunnings decision shows transparency failures sink deployments |
The same three use cases, in all five
Most enterprise deployments fall into one of three shapes. Reading them across jurisdictions is more useful than reading a single jurisdiction in depth, because it shows where a group-wide rollout breaks.
| Jurisdiction | Customer-facing | Recruitment | Employee monitoring |
|---|---|---|---|
| European Union | Permitted | Prohibited | Prohibited |
| United Kingdom | Low friction | Hard to defend | Hard to defend |
| United States | Low friction | Hard to defend | Hard to defend |
| Singapore | Low friction | Permitted, not advised | Permitted, not advised |
| Australia | Low friction | Hard to defend | Hard to defend |
Read down the customer-facing column and the picture is uniform: contact centre work is the most straightforward deployment everywhere. Read down the other two and it is not. Recruitment is prohibited in the EU, hard to defend in three jurisdictions, and available without consent in Singapore — which is exactly the spread that makes a single group-wide policy necessary rather than optional.
Why the EU position usually decides it anyway
Article 2(1)(c) of the AI Act brings providers and deployers established in a third country within scope wherever the output produced by the system is used in the Union. Scope follows the output, not the registered office, and that single provision collapses most of the comparison above for any organisation with an EU footprint.
A UK employer assessing candidates for a Dublin role, a Singaporean group running an engagement tool across European subsidiaries, a US contact centre scoring agents who handle EU customers — each sits inside the Article 5(1)(f) prohibition regardless of what its home jurisdiction permits. Article 5 is an absolute market prohibition with no consent, contract or legitimate-interest gateway, so none of the local consent machinery lifts it. Scope to the strictest jurisdiction in the footprint and the rest of the analysis becomes documentation rather than decision.
What is changing next
Three dates are worth carrying. 10 December 2026: Australian automated decision-making transparency obligations take effect under a new APP 1.7, requiring privacy policies to disclose the kinds of decisions made by computer programs. 30 September 2026: the deadline for the Governor of California to act on AB 1883, which would create the first US prohibition on workplace emotion inference and neural data collection, operative 1 January 2027. And Singapore's Workplace Fairness Act, which will add a discrimination route in the one jurisdiction that currently has none.
The direction is consistent even where the instruments are not. No jurisdiction is loosening, and the two that have moved most recently have both moved toward restricting workplace deployment specifically.
Where EchoDepth sits
EchoDepth reports observable delivery signals using the Facial Action Coding System — 44 Action Units calibrated across 14 cultural cohorts in 6 countries — together with vocal and language measures. It reports what the signals did and leaves interpretation to context-aware human review, rather than returning an emotion label.
We scope to the strictest jurisdiction in a client's footprint as a matter of course. Contact centre, investor and executive communication, market research and message testing are supported everywhere we operate. We do not scope candidate-facing recruitment assessment or employee monitoring deployments in any jurisdiction, including the ones that permit them, and we say so at the first conversation rather than the last.
Primary sources
Read the instruments rather than summaries of them. Regulation (EU) 2024/1689 is on EUR-Lex. UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025 are on legislation.gov.uk, and the ICO publishes its biometrics and AI positions. Illinois BIPA (740 ILCS 14) and California AB 1883 are on the Illinois General Assembly and California Legislature sites respectively. Singapore's PDPA is on Singapore Statutes Online. The Privacy Act 1988 is on legislation.gov.au and the OAIC publishes the Bunnings determination. Where this page and a primary source disagree, the primary source is right.
Frequently Asked Questions
Which countries ban emotion recognition AI?
As of September 2026, the European Union is the only major jurisdiction with a prohibition, and it is narrower than it is usually reported. EU AI Act Article 5(1)(f) prohibits AI systems that infer emotions in workplaces and educational institutions, except where used for medical or safety reasons, and it has applied since 2 February 2025. Emotion recognition outside those two settings — customer-facing contact centre use, market research, an executive rehearsing a presentation — remains lawful in the EU subject to transparency and GDPR obligations. No prohibition exists in the United Kingdom, the United States, Singapore or Australia. Those four regulate the technology through general data protection, consent and anti-discrimination law instead, which means the question is never whether a deployment is allowed but whether it can be defended.
Is emotion recognition banned in the United States?
No. There is no federal statute prohibiting emotion recognition, no general federal privacy law covering it, and no federal equivalent of EU AI Act Article 5(1)(f). But the United States is the most financially dangerous jurisdiction in the world for this technology despite having the fewest prohibitions, because Illinois' Biometric Information Privacy Act gives individuals a private right of action worth $1,000 for negligent violations and $5,000 for reckless or intentional ones, with no requirement to prove harm. That combination produces class actions rather than regulatory correspondence. California's AB 1883 would change the picture: it would bar employers from using workplace surveillance tools that infer an employee's emotional state or collect neural data. It passed both chambers and was presented to the Governor on 10 September 2026, and has not been signed as at the date of this page.
Which country is the most permissive for emotion recognition?
Singapore. There is no AI statute, no prohibition in any setting, and no special-category data regime — under the PDPA, biometric and emotion-derived data are ordinary personal data with no elevated statutory status. Singapore goes further than merely permitting it: the evaluative purposes exception lets an organisation collect, use and disclose personal data without consent where the purpose is evaluating someone for employment, promotion or continued employment. That is the precise deployment the EU prohibits outright, available in Singapore without candidate consent. Governance comes from IMDA's Model AI Governance Framework and the AI Verify toolkit, both voluntary. Permissive is not the same as advisable, and for any group with EU operations the Singapore position is not the one that binds.
Does the EU AI Act apply to companies outside the EU?
Yes, where the output is used in the Union. Article 2(1)(c) brings providers and deployers established in a third country within scope where the output produced by the AI system is used in the EU, so scope follows the output rather than the registered office. A UK, US, Singaporean or Australian employer running emotion analysis on candidates for a Dublin or Frankfurt role sits inside the Article 5(1)(f) prohibition. Article 5 is an absolute market prohibition with no consent, contract or legitimate-interest gateway, so none of the consent paperwork that satisfies BIPA, the PDPA or the Australian Privacy Principles lifts it. For most multinationals the EU position is the binding constraint and the local analysis is academic.
How should a multinational scope an emotion recognition deployment?
To the strictest jurisdiction in the footprint, not to each jurisdiction separately. Maintaining five postures produces a system that is lawful in Singapore and prohibited in Munich while running on one contract, and the first regulator or claimant to look at it will look at the whole thing. In practice that means treating the EU Article 5(1)(f) line as the design constraint — no workplace or education deployment anywhere — then layering the local requirements that survive it: BIPA written release in Illinois, APP 3.3 consent in Australia, a DPIA and Article 22 safeguards in the UK. That is cheaper than fifty processes and considerably easier to defend.
Scope your use case before you procure
Tell us the deployment you have in mind and where your people are. We will tell you what it has to survive in each jurisdiction — including if the answer is that we cannot support it.
Talk to us about scoping →