The EU AI Act and User Research: What AI-Moderated Interviews Actually Require (2026)
AI-moderated customer interviews sit in the EU AI Act's limited-risk transparency tier, not the high-risk tier. Here is exactly what Article 50 requires from 2 August 2026, the two things that escalate a study to high-risk, and a compliance checklist you can run this week.
If you run AI-moderated interviews with participants in the EU, here is the short answer: customer research is almost certainly in the AI Act's limited-risk "transparency" tier, not the high-risk tier. Your core duty is one sentence long — tell participants they are interacting with an AI, before the conversation starts. That obligation, in Article 50, became applicable on 2 August 2026.
Two things escalate a study out of that comfortable tier:
- Inferring emotions from voice or face. Emotion recognition is prohibited outright in workplace and education settings under Article 5, and carries disclosure duties everywhere else.
- Using AI interviews to recruit, screen, or evaluate employees. That is Annex III territory, where the full high-risk regime applies.
Most product and UX teams never touch either. But the teams that do — HR tech, candidate experience, employee listening — are frequently the ones who assume "it's just a survey" and get it wrong. This guide draws the line precisely.
A note on scope. The AI Act governs the AI system. GDPR governs the personal data that flows through it. They are separate regimes with separate penalties, and satisfying one does not satisfy the other. If you have not already worked through lawful basis, retention, and sub-processors, start with our GDPR-compliant AI user research guide and treat this page as the second layer.
The four risk tiers, mapped to research
The AI Act sorts systems by what they do, not by how they are built. Here is where research activities land.
| Tier | What it covers | Typical research example | Your obligation |
|---|---|---|---|
| Prohibited (Art. 5) | Unacceptable-risk practices | Inferring employee emotions from voice tone in a workplace study | Do not do it. In force since 2 February 2025 |
| High-risk (Annex III) | Employment, education, essential services, and six other domains | AI interviews used to screen or evaluate job candidates | Full Chapter III regime: risk management, data governance, human oversight, logging, conformity assessment |
| Limited-risk (Art. 50) | Systems that interact directly with people, or generate synthetic content | AI-moderated customer discovery, VoC, concept testing, usability research | Disclose that the participant is talking to an AI. Mark synthetic content |
| Minimal risk | Everything else | Thematic analysis run over already-collected, de-identified transcripts | No specific AI Act duty |
The vast majority of commercial customer research — the discovery calls, the churn interviews, the pricing studies — lives in that third row. The obligation is real but light.
What Article 50 actually requires of you
Article 50(1) puts the design duty on the provider: a system that interacts directly with natural persons must be built so those people are informed they are dealing with an AI, unless it is already obvious from the context.
Article 50(3) puts a separate duty on the deployer: if you operate an emotion recognition or biometric categorisation system, you must inform the people exposed to it.
That provider/deployer split matters commercially, because it determines who owes what:
- If you use a platform like Koji, the platform is the provider of the AI system. The disclosure has to be engineered into the interview experience, and that is the vendor's job.
- You are the deployer. You choose the purpose, the audience, and the questions. You own the decision about whether your study strays into emotion inference or employment evaluation — and no vendor can make that call for you.
The practical bar for disclosure is low but specific. It must be clear, at the first interaction, and not buried. A line in a privacy policy does not satisfy it. "You're chatting with an AI interviewer" on the opening screen does.
There is also a "unless it is obvious" carve-out. Do not lean on it. A participant who clicked an email link labelled "share your feedback" has no reason to assume the interviewer is software, and regulators read obviousness narrowly.
The emotion recognition trap — and the nuance most guides get wrong
This is the part worth reading twice, because the distinction is genuinely subtle and it decides whether you are doing something regulated, something prohibited, or something entirely unremarkable.
The Act defines an emotion recognition system as one that identifies or infers the emotions or intentions of natural persons on the basis of their biometric data. That last clause does the work:
- Coding what someone said is not emotion recognition. If your analysis reads the words "I was really frustrated when the export failed" and tags that response as negative sentiment, you are processing language, not biometric data. This is ordinary qualitative analysis and falls outside the definition.
- Inferring emotion from how someone sounded is a different matter. Deriving affect from vocal tone, pitch, or facial expression uses biometric data, and that lands inside the definition.
So a voice interview is not a compliance problem in itself. A voice interview with a tone-based "sentiment from audio" feature is. And in a workplace or educational setting, that second thing is not merely regulated — Article 5(1)(f) prohibits it, at the top penalty band.
The safe posture, and the one Koji is built around: analyse what participants say, never how their voice sounds. Thematic analysis, quality scoring, and sentiment in Koji all operate on the transcript. There is no vocal affect model anywhere in the pipeline, which keeps voice studies in the limited-risk tier by design rather than by configuration.
When research becomes high-risk: the employment line
Annex III designates AI systems used to recruit, select, and evaluate people as high-risk. The trigger is the decision the output feeds, not the interview format.
Draw the line like this:
- Not high-risk: anonymous employee engagement research, exit interviews analysed in aggregate to find retention themes, candidate experience studies measuring how your hiring process felt.
- High-risk: an AI interview that scores, ranks, or filters candidates. Any output that influences who gets hired, promoted, or terminated at the individual level.
If you are in the second bucket, the full Chapter III regime applies — risk management system, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, and a conformity assessment before you go to market. That is a compliance programme, not a checklist, and it needs counsel.
If you are in the first bucket, keep it there deliberately: report at the cohort level, do not generate per-person scores that feed personnel decisions, and document that design choice. Our guides on anonymous employee research and exit interviews both assume aggregate-only reporting for exactly this reason.
The timeline, after the Omnibus
The compliance calendar shifted materially in 2026, and a lot of published advice is now stale. The AI Omnibus Regulation entered into force in July 2026, deferring the high-risk deadlines that had been set for 2 August 2026.
| Date | What applies |
|---|---|
| 1 August 2024 | AI Act entered into force |
| 2 February 2025 | Prohibited practices apply — including workplace and education emotion recognition |
| 2 August 2026 | Article 50 transparency obligations apply. This is the date that binds customer research |
| 2 December 2026 | Synthetic content marking and watermarking obligations |
| 2 December 2027 | Annex III high-risk obligations — deferred 16 months by the Omnibus |
| 2 August 2028 | High-risk AI embedded in products already covered by EU product-safety rules — deferred 12 months |
The headline for researchers: the deferral does not help you. What moved was the high-risk regime. Article 50 — the tier customer research actually sits in — was not postponed. If you are running AI interviews in the EU, your deadline is now, not December 2027.
What non-compliance costs
Penalties are tiered to match the risk tiers, and they are calculated on global turnover, which is why they get executive attention:
- Prohibited practices (Art. 5): up to €35 million or 7% of worldwide annual turnover, whichever is higher.
- High-risk and other obligations: up to €15 million or 3% of worldwide annual turnover for deployers who fail their duties.
Put plainly: switching on a vocal-emotion feature in an employee study is in the same penalty band as the Act's most serious violations. That single configuration choice is worth more scrutiny than most research programmes give it.
Your compliance checklist
Run this before your next EU study ships:
- Classify the study. Customer research, or employment decision? Write the answer down. This one line determines everything else.
- Disclose the AI up front. First screen, plain language, before the first question.
- Confirm no biometric emotion inference. Ask your vendor directly whether any model infers affect from audio or video. Get it in writing.
- Name the AI in your participant notice, alongside your GDPR disclosures — see research consent form templates.
- Keep employee research aggregate-only. No per-person scores feeding personnel decisions.
- Log your studies. Purpose, dates, audience, model used. If a regulator asks, your defence is documentation.
- Check the provider's posture. Providers carry the design duty — verify yours has actually met it rather than assuming.
- Re-check before 2 December 2026 if you publish AI-generated content externally, when synthetic content marking kicks in.
How Koji handles this
The AI Act rewards platforms that made the right architectural decisions early, because the obligations that matter here are engineered in, not toggled on:
- Disclosure is built into the interview experience. Every Koji interview identifies itself as AI-moderated at the outset. There is no configuration required and no way to accidentally ship a study that hides it.
- No vocal emotion inference anywhere. Koji's analysis operates on transcripts. Voice interviews transcribe speech and analyse language — tone is never modelled — which keeps voice studies in the limited-risk tier structurally.
- Aggregate-first reporting. Koji's report aggregation rolls findings up to themes and cohorts by default, which is exactly the posture that keeps employee research out of Annex III.
- Transcript-level traceability. Every theme in a Koji report links back to the quotes that produced it, so when someone asks how a conclusion was reached, the answer is a citation rather than a shrug.
- Structured questions instead of inference. This is the underrated compliance advantage. When you need to know how someone feels, the robust move is to ask them with a scale question rather than infer it from their voice. Koji's six structured question types —
open_ended,scale,single_choice,multiple_choice,ranking, andyes_no— give you quantified affect as self-reported data. A 1–7 satisfaction scale is better evidence than a tone model, and it is not regulated as biometric processing. Better methodology and lighter compliance load, from the same design decision.
The wider point: legacy survey tools were built before any of this existed, and bolt compliance on through settings you have to find and configure correctly. A platform designed in the AI Act era can make the compliant path the default one — which is the difference between a control you have to remember and a property of the system.
Related Resources
- GDPR-Compliant AI User Research — the data-protection layer that sits underneath AI Act compliance
- Structured Questions Guide — the six question types, and why self-reported scales beat inferred affect
- AI Interview Data Privacy & Security — how interview data is stored, encrypted, and retained
- Research Ethics Guide — the ethical duties that outlast any single regulation
- Research Consent Form Templates — copy-ready notices covering AI disclosure
- HIPAA-Compliant AI User Research — the parallel regime for health-related studies
- Anonymous Employee Research with AI Interviews — aggregate-only design that stays out of Annex III
Regulatory information current as of July 2026 and reflects the AI Omnibus Regulation. This guide is practitioner orientation, not legal advice — confirm your specific obligations with qualified counsel.
Related Articles
Agent Trajectory Evaluation: How to Judge Multi-Step AI Agents with Real Users (2026)
Outcome-only scoring hides where AI agents actually break. Learn how to evaluate the full trajectory - every reasoning step, tool call, and hand-back to the user - using step-level rubrics and real participant evidence.
Conversation Memory and Long-Session Degradation: Why AI Interviews Get Worse After Turn 20 (2026)
AI moderators lose the thread in long conversations. The evidence, the four degradation symptoms, the session budget framework, and how to test your own moderator before it costs you a study.
AI Failure Mode Analysis: An FMEA Framework for AI Products (2026)
How to run Failure Mode and Effects Analysis (FMEA) on an AI product: the failure mode taxonomy, how to score severity, occurrence and detection when failures are probabilistic, and how user research supplies the numbers.
AI Governance for Customer Research: ISO 42001, the NIST AI RMF, and What Procurement Actually Asks
Security review is asking whether your AI research platform is ISO 42001 certified and NIST AI RMF aligned. Here is what each framework covers, what a certificate does and does not buy you under the EU AI Act, and how to answer.
Graceful Degradation for AI Features: Researching What Users Experience When the Model Cannot Deliver (2026)
AI features fail in four distinct ways: unavailable, too slow, too unsure, and out of scope. Learn how to design a degradation ladder for each, what the EU AI Act and NIST AI RMF require, and how to research the degraded state with real users.
AI Guardrail Testing: How to Measure False Refusals and Over-Blocking with Real Users (2026)
Your safety layer has a false positive rate, and it is costing you users you never hear from. How to measure false refusal rate, run an over-blocking study, and tune guardrails against real user harm instead of vibes.
AI-to-Human Handoff: How to Design and Research the Escalation Moment (2026)
The handoff from AI to a human is where most AI products actually fail. A practical guide to escalation triggers, why accuracy metrics mis-measure handoff timing, what to research at the transfer point, and how to test it with real users.
AI Incident Postmortems: How to Investigate Model Failures with User Evidence (2026)
Logs tell you what your model output. They cannot tell you what it cost the person on the other end. A practical guide to running blameless AI incident postmortems with real user evidence - and meeting the reporting clocks that now apply.
AI Interview Data Privacy & Security: A Buyer's Evaluation Guide
How to evaluate the privacy and security of an AI customer research platform — the questions to ask about data handling, PII, retention, sub-processors, and compliance — plus how Koji approaches each one.
AI Model Cards and User Disclosure: Documenting Intended Use, Limitations, and What You Tell People (2026)
A practical guide to model cards, system cards, and user-facing AI disclosure — what belongs in each section, what the EU AI Act's Article 50 has required since 2 August 2026, and how to source the Limitations section from real user research instead of guesswork.
Model Version Drift: What Happens to Your Research When the AI Changes Mid-Study (2026)
When the model behind your AI moderator or analyst is upgraded, your measuring instrument changed. The evidence, the three layers of drift, the bridge sample method, and how to make model version part of your method section.
AI Red Teaming with Real Users: How to Find Harms Before Your Users Do (2026)
A practitioner guide to adversarial testing of AI products with real people — harm taxonomies, recruiting adversaries, severity scoring, red-teamer wellbeing, and the EU AI Act and NIST obligations that now make it mandatory.
Staged Rollout for AI Features: Shadow Mode, Canary, and Kill Switches (2026)
A research-first guide to staging an AI feature launch. What shadow mode can and cannot measure, what to ask users at each canary ring, how to pre-register rollback thresholds, and why the EU AI Act made the kill switch a legal requirement.
Contestability and Redress: How to Design and Research the Appeal Flow for AI Decisions (2026)
EU AI Act Article 86 became applicable on 2 August 2026. Learn what GDPR Article 22 and the CJEU already require of an appeal flow, why appeal rates are a misleading metric, and how to research whether users can actually contest a decision.
DPIA for User Research: When You Need One and How to Write It (2026)
A practical guide to Data Protection Impact Assessments for customer and user research: the Article 35 triggers, the WP29 nine criteria, what belongs in each section, and a worked example for AI-moderated interviews.
GDPR-Compliant AI User Research: A Practical Guide
How to run AI-moderated customer interviews under GDPR. Lawful basis, consent flows, data minimization, retention, sub-processors, and how Koji handles each requirement.
HIPAA-Compliant AI User Research: A Practical Playbook for Healthcare and HealthTech
Run AI-moderated customer research in healthcare contexts without putting PHI at risk. Patterns for HIPAA alignment, anonymous-mode interviews, BYOK, sub-processor handling, and what Enterprise teams need from a vendor.
Research Provenance: How to Prove an Interview, a Quote, or a Report Is Genuine (2026)
When any text can be generated, a customer quote proves nothing on its own. Content Credentials, the EU AI Act marking rules, and the hash-anchored capture method that actually works for research text.
Research Consent Form Templates: GDPR-Compliant Forms for Every Study
Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.
Research Ethics and Informed Consent: A Practical Guide for UX Teams
A practical guide to ethical UX research — covering the Belmont Report's three principles, GDPR informed consent requirements, how to handle AI tools responsibly, and how to build ethical maturity in your research practice.
Structured Questions in AI Interviews
Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.