{"site":{"name":"Koji","description":"AI-native customer research platform that helps teams conduct, analyze, and synthesize customer interviews at scale.","url":"https://www.koji.so","contentTypes":["blog","documentation"],"lastUpdated":"2026-07-29T16:03:03.766Z"},"content":[{"type":"documentation","id":"3130ed02-69e5-4480-8fc5-24f3ea1e5cd7","slug":"eu-ai-act-user-research-compliance","title":"The EU AI Act and User Research: What AI-Moderated Interviews Actually Require (2026)","url":"https://www.koji.so/docs/eu-ai-act-user-research-compliance","summary":"AI-moderated customer research sits in the EU AI Act limited-risk transparency tier under Article 50, applicable from 2 August 2026, requiring only that participants be told they are interacting with an AI at the start. Two escalations matter: inferring emotions from biometric data such as vocal tone (prohibited in workplace and education settings under Article 5, penalties up to EUR 35M or 7% of global turnover), and using AI interviews to screen or evaluate employees or candidates (Annex III high-risk, deferred to 2 December 2027 by the July 2026 AI Omnibus Regulation). Analysing what participants say is not emotion recognition; inferring affect from how they sound is. Koji discloses AI moderation by default, models no vocal affect, and reports in aggregate.","content":"If you run AI-moderated interviews with participants in the EU, here is the short answer: **customer research is almost certainly in the AI Act's limited-risk \"transparency\" tier, not the high-risk tier.** Your core duty is one sentence long — tell participants they are interacting with an AI, before the conversation starts. That obligation, in Article 50, became applicable on **2 August 2026**.\n\nTwo things escalate a study out of that comfortable tier:\n\n1. **Inferring emotions from voice or face.** Emotion recognition is prohibited outright in workplace and education settings under Article 5, and carries disclosure duties everywhere else.\n2. **Using AI interviews to recruit, screen, or evaluate employees.** That is Annex III territory, where the full high-risk regime applies.\n\nMost product and UX teams never touch either. But the teams that do — HR tech, candidate experience, employee listening — are frequently the ones who assume \"it's just a survey\" and get it wrong. This guide draws the line precisely.\n\n> **A note on scope.** The AI Act governs the *AI system*. GDPR governs the *personal data* that flows through it. They are separate regimes with separate penalties, and satisfying one does not satisfy the other. If you have not already worked through lawful basis, retention, and sub-processors, start with our [GDPR-compliant AI user research guide](/docs/gdpr-compliant-ai-user-research) and treat this page as the second layer.\n\n## The four risk tiers, mapped to research\n\nThe AI Act sorts systems by what they do, not by how they are built. Here is where research activities land.\n\n| Tier | What it covers | Typical research example | Your obligation |\n| --- | --- | --- | --- |\n| **Prohibited** (Art. 5) | Unacceptable-risk practices | Inferring employee emotions from voice tone in a workplace study | Do not do it. In force since 2 February 2025 |\n| **High-risk** (Annex III) | Employment, education, essential services, and six other domains | AI interviews used to screen or evaluate job candidates | Full Chapter III regime: risk management, data governance, human oversight, logging, conformity assessment |\n| **Limited-risk** (Art. 50) | Systems that interact directly with people, or generate synthetic content | **AI-moderated customer discovery, VoC, concept testing, usability research** | Disclose that the participant is talking to an AI. Mark synthetic content |\n| **Minimal risk** | Everything else | Thematic analysis run over already-collected, de-identified transcripts | No specific AI Act duty |\n\nThe vast majority of commercial customer research — the discovery calls, the churn interviews, the pricing studies — lives in that third row. The obligation is real but light.\n\n## What Article 50 actually requires of you\n\nArticle 50(1) puts the design duty on the **provider**: a system that interacts directly with natural persons must be built so those people are informed they are dealing with an AI, unless it is already obvious from the context.\n\nArticle 50(3) puts a separate duty on the **deployer**: if you operate an emotion recognition or biometric categorisation system, you must inform the people exposed to it.\n\nThat provider/deployer split matters commercially, because it determines who owes what:\n\n- **If you use a platform like Koji**, the platform is the provider of the AI system. The disclosure has to be engineered into the interview experience, and that is the vendor's job.\n- **You are the deployer.** You choose the purpose, the audience, and the questions. You own the decision about whether your study strays into emotion inference or employment evaluation — and no vendor can make that call for you.\n\nThe practical bar for disclosure is low but specific. It must be **clear, at the first interaction, and not buried**. A line in a privacy policy does not satisfy it. \"You're chatting with an AI interviewer\" on the opening screen does.\n\nThere is also a \"unless it is obvious\" carve-out. Do not lean on it. A participant who clicked an email link labelled \"share your feedback\" has no reason to assume the interviewer is software, and regulators read obviousness narrowly.\n\n## The emotion recognition trap — and the nuance most guides get wrong\n\nThis is the part worth reading twice, because the distinction is genuinely subtle and it decides whether you are doing something regulated, something prohibited, or something entirely unremarkable.\n\nThe Act defines an emotion recognition system as one that identifies or infers the emotions or intentions of natural persons **on the basis of their biometric data**. That last clause does the work:\n\n- **Coding what someone said is not emotion recognition.** If your analysis reads the words \"I was really frustrated when the export failed\" and tags that response as negative sentiment, you are processing language, not biometric data. This is ordinary qualitative analysis and falls outside the definition.\n- **Inferring emotion from how someone sounded is a different matter.** Deriving affect from vocal tone, pitch, or facial expression uses biometric data, and that lands inside the definition.\n\nSo a voice interview is not a compliance problem in itself. A voice interview with a tone-based \"sentiment from audio\" feature is. And in a **workplace or educational** setting, that second thing is not merely regulated — Article 5(1)(f) prohibits it, at the top penalty band.\n\nThe safe posture, and the one Koji is built around: analyse **what participants say**, never how their voice sounds. Thematic analysis, quality scoring, and sentiment in Koji all operate on the transcript. There is no vocal affect model anywhere in the pipeline, which keeps voice studies in the limited-risk tier by design rather than by configuration.\n\n## When research becomes high-risk: the employment line\n\nAnnex III designates AI systems used to recruit, select, and evaluate people as high-risk. The trigger is the **decision the output feeds**, not the interview format.\n\nDraw the line like this:\n\n- **Not high-risk:** anonymous employee engagement research, exit interviews analysed in aggregate to find retention themes, candidate experience studies measuring how your hiring process felt.\n- **High-risk:** an AI interview that scores, ranks, or filters candidates. Any output that influences who gets hired, promoted, or terminated at the individual level.\n\nIf you are in the second bucket, the full Chapter III regime applies — risk management system, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, and a conformity assessment before you go to market. That is a compliance programme, not a checklist, and it needs counsel.\n\nIf you are in the first bucket, keep it there deliberately: report at the cohort level, do not generate per-person scores that feed personnel decisions, and document that design choice. Our guides on [anonymous employee research](/docs/anonymous-employee-research-ai-interviews) and [exit interviews](/docs/exit-interview-survey-guide) both assume aggregate-only reporting for exactly this reason.\n\n## The timeline, after the Omnibus\n\nThe compliance calendar shifted materially in 2026, and a lot of published advice is now stale. The AI Omnibus Regulation entered into force in **July 2026**, deferring the high-risk deadlines that had been set for 2 August 2026.\n\n| Date | What applies |\n| --- | --- |\n| 1 August 2024 | AI Act entered into force |\n| 2 February 2025 | Prohibited practices apply — including workplace and education emotion recognition |\n| **2 August 2026** | **Article 50 transparency obligations apply. This is the date that binds customer research** |\n| 2 December 2026 | Synthetic content marking and watermarking obligations |\n| 2 December 2027 | Annex III high-risk obligations — deferred 16 months by the Omnibus |\n| 2 August 2028 | High-risk AI embedded in products already covered by EU product-safety rules — deferred 12 months |\n\nThe headline for researchers: **the deferral does not help you.** What moved was the high-risk regime. Article 50 — the tier customer research actually sits in — was not postponed. If you are running AI interviews in the EU, your deadline is now, not December 2027.\n\n## What non-compliance costs\n\nPenalties are tiered to match the risk tiers, and they are calculated on **global** turnover, which is why they get executive attention:\n\n- **Prohibited practices** (Art. 5): up to **€35 million or 7%** of worldwide annual turnover, whichever is higher.\n- **High-risk and other obligations**: up to **€15 million or 3%** of worldwide annual turnover for deployers who fail their duties.\n\nPut plainly: switching on a vocal-emotion feature in an employee study is in the same penalty band as the Act's most serious violations. That single configuration choice is worth more scrutiny than most research programmes give it.\n\n## Your compliance checklist\n\nRun this before your next EU study ships:\n\n1. **Classify the study.** Customer research, or employment decision? Write the answer down. This one line determines everything else.\n2. **Disclose the AI up front.** First screen, plain language, before the first question.\n3. **Confirm no biometric emotion inference.** Ask your vendor directly whether any model infers affect from audio or video. Get it in writing.\n4. **Name the AI in your participant notice**, alongside your GDPR disclosures — see [research consent form templates](/docs/research-consent-form-templates).\n5. **Keep employee research aggregate-only.** No per-person scores feeding personnel decisions.\n6. **Log your studies.** Purpose, dates, audience, model used. If a regulator asks, your defence is documentation.\n7. **Check the provider's posture.** Providers carry the design duty — verify yours has actually met it rather than assuming.\n8. **Re-check before 2 December 2026** if you publish AI-generated content externally, when synthetic content marking kicks in.\n\n## How Koji handles this\n\nThe AI Act rewards platforms that made the right architectural decisions early, because the obligations that matter here are engineered in, not toggled on:\n\n- **Disclosure is built into the interview experience.** Every Koji interview identifies itself as AI-moderated at the outset. There is no configuration required and no way to accidentally ship a study that hides it.\n- **No vocal emotion inference anywhere.** Koji's analysis operates on transcripts. [Voice interviews](/docs/ai-voice-interviews) transcribe speech and analyse language — tone is never modelled — which keeps voice studies in the limited-risk tier structurally.\n- **Aggregate-first reporting.** Koji's [report aggregation](/docs/research-repository-guide) rolls findings up to themes and cohorts by default, which is exactly the posture that keeps employee research out of Annex III.\n- **Transcript-level traceability.** Every theme in a Koji report links back to the quotes that produced it, so when someone asks how a conclusion was reached, the answer is a citation rather than a shrug.\n- **Structured questions instead of inference.** This is the underrated compliance advantage. When you need to know how someone feels, the robust move is to *ask them* with a scale question rather than infer it from their voice. Koji's six [structured question types](/docs/structured-questions-guide) — `open_ended`, `scale`, `single_choice`, `multiple_choice`, `ranking`, and `yes_no` — give you quantified affect as self-reported data. A 1–7 satisfaction scale is better evidence than a tone model, and it is not regulated as biometric processing. Better methodology and lighter compliance load, from the same design decision.\n\nThe wider point: legacy survey tools were built before any of this existed, and bolt compliance on through settings you have to find and configure correctly. A platform designed in the AI Act era can make the compliant path the default one — which is the difference between a control you have to remember and a property of the system.\n\n## Related Resources\n\n- [GDPR-Compliant AI User Research](/docs/gdpr-compliant-ai-user-research) — the data-protection layer that sits underneath AI Act compliance\n- [Structured Questions Guide](/docs/structured-questions-guide) — the six question types, and why self-reported scales beat inferred affect\n- [AI Interview Data Privacy & Security](/docs/ai-interview-data-privacy-security) — how interview data is stored, encrypted, and retained\n- [Research Ethics Guide](/docs/research-ethics-guide) — the ethical duties that outlast any single regulation\n- [Research Consent Form Templates](/docs/research-consent-form-templates) — copy-ready notices covering AI disclosure\n- [HIPAA-Compliant AI User Research](/docs/hipaa-compliant-ai-user-research) — the parallel regime for health-related studies\n- [Anonymous Employee Research with AI Interviews](/docs/anonymous-employee-research-ai-interviews) — aggregate-only design that stays out of Annex III\n\n*Regulatory information current as of July 2026 and reflects the AI Omnibus Regulation. This guide is practitioner orientation, not legal advice — confirm your specific obligations with qualified counsel.*\n","category":"Research Operations","lastModified":"2026-07-29T03:21:12.817673+00:00","metaTitle":"EU AI Act & User Research: What AI Interviews Require (2026)","metaDescription":"AI-moderated customer interviews fall under the EU AI Act's Article 50 transparency tier, applicable 2 August 2026. Learn the disclosure rule, the emotion-recognition trap, when research becomes high-risk, and a practical compliance checklist.","keywords":["eu ai act user research","eu ai act ai interviews","ai act article 50","ai act transparency obligations","ai act high risk research","emotion recognition ai act","ai act compliance checklist","ai moderated interviews eu","ai act annex iii employment","ai act penalties"],"aiSummary":"AI-moderated customer research sits in the EU AI Act limited-risk transparency tier under Article 50, applicable from 2 August 2026, requiring only that participants be told they are interacting with an AI at the start. Two escalations matter: inferring emotions from biometric data such as vocal tone (prohibited in workplace and education settings under Article 5, penalties up to EUR 35M or 7% of global turnover), and using AI interviews to screen or evaluate employees or candidates (Annex III high-risk, deferred to 2 December 2027 by the July 2026 AI Omnibus Regulation). Analysing what participants say is not emotion recognition; inferring affect from how they sound is. Koji discloses AI moderation by default, models no vocal affect, and reports in aggregate.","aiPrerequisites":["Basic understanding of user research methods","Familiarity with GDPR fundamentals"],"aiLearningOutcomes":["Classify a research study into the correct EU AI Act risk tier","Meet Article 50 transparency obligations in an AI-moderated interview","Distinguish transcript sentiment analysis from regulated biometric emotion recognition","Recognise when employee or candidate research crosses into Annex III high-risk territory","Apply the post-Omnibus 2026-2028 compliance timeline","Run a pre-launch AI Act compliance checklist"],"aiDifficulty":"intermediate","aiEstimatedTime":"14 min read"}],"pagination":{"total":1,"returned":1,"offset":0}}