The EU AI Act and User Research: What AI-Moderated Interviews Actually Require (2026)
AI-moderated customer interviews sit in the EU AI Act's limited-risk transparency tier, not the high-risk tier. Here is exactly what Article 50 requires from 2 August 2026, the two things that escalate a study to high-risk, and a compliance checklist you can run this week.
If you run AI-moderated interviews with participants in the EU, here is the short answer: customer research is almost certainly in the AI Act's limited-risk "transparency" tier, not the high-risk tier. Your core duty is one sentence long — tell participants they are interacting with an AI, before the conversation starts. That obligation, in Article 50, became applicable on 2 August 2026.
Two things escalate a study out of that comfortable tier:
- Inferring emotions from voice or face. Emotion recognition is prohibited outright in workplace and education settings under Article 5, and carries disclosure duties everywhere else.
- Using AI interviews to recruit, screen, or evaluate employees. That is Annex III territory, where the full high-risk regime applies.
Most product and UX teams never touch either. But the teams that do — HR tech, candidate experience, employee listening — are frequently the ones who assume "it's just a survey" and get it wrong. This guide draws the line precisely.
A note on scope. The AI Act governs the AI system. GDPR governs the personal data that flows through it. They are separate regimes with separate penalties, and satisfying one does not satisfy the other. If you have not already worked through lawful basis, retention, and sub-processors, start with our GDPR-compliant AI user research guide and treat this page as the second layer.
The four risk tiers, mapped to research
The AI Act sorts systems by what they do, not by how they are built. Here is where research activities land.
| Tier | What it covers | Typical research example | Your obligation |
|---|---|---|---|
| Prohibited (Art. 5) | Unacceptable-risk practices | Inferring employee emotions from voice tone in a workplace study | Do not do it. In force since 2 February 2025 |
| High-risk (Annex III) | Employment, education, essential services, and six other domains | AI interviews used to screen or evaluate job candidates | Full Chapter III regime: risk management, data governance, human oversight, logging, conformity assessment |
| Limited-risk (Art. 50) | Systems that interact directly with people, or generate synthetic content | AI-moderated customer discovery, VoC, concept testing, usability research | Disclose that the participant is talking to an AI. Mark synthetic content |
| Minimal risk | Everything else | Thematic analysis run over already-collected, de-identified transcripts | No specific AI Act duty |
The vast majority of commercial customer research — the discovery calls, the churn interviews, the pricing studies — lives in that third row. The obligation is real but light.
What Article 50 actually requires of you
Article 50(1) puts the design duty on the provider: a system that interacts directly with natural persons must be built so those people are informed they are dealing with an AI, unless it is already obvious from the context.
Article 50(3) puts a separate duty on the deployer: if you operate an emotion recognition or biometric categorisation system, you must inform the people exposed to it.
That provider/deployer split matters commercially, because it determines who owes what:
- If you use a platform like Koji, the platform is the provider of the AI system. The disclosure has to be engineered into the interview experience, and that is the vendor's job.
- You are the deployer. You choose the purpose, the audience, and the questions. You own the decision about whether your study strays into emotion inference or employment evaluation — and no vendor can make that call for you.
The practical bar for disclosure is low but specific. It must be clear, at the first interaction, and not buried. A line in a privacy policy does not satisfy it. "You're chatting with an AI interviewer" on the opening screen does.
There is also a "unless it is obvious" carve-out. Do not lean on it. A participant who clicked an email link labelled "share your feedback" has no reason to assume the interviewer is software, and regulators read obviousness narrowly.
The emotion recognition trap — and the nuance most guides get wrong
This is the part worth reading twice, because the distinction is genuinely subtle and it decides whether you are doing something regulated, something prohibited, or something entirely unremarkable.
The Act defines an emotion recognition system as one that identifies or infers the emotions or intentions of natural persons on the basis of their biometric data. That last clause does the work:
- Coding what someone said is not emotion recognition. If your analysis reads the words "I was really frustrated when the export failed" and tags that response as negative sentiment, you are processing language, not biometric data. This is ordinary qualitative analysis and falls outside the definition.
- Inferring emotion from how someone sounded is a different matter. Deriving affect from vocal tone, pitch, or facial expression uses biometric data, and that lands inside the definition.
So a voice interview is not a compliance problem in itself. A voice interview with a tone-based "sentiment from audio" feature is. And in a workplace or educational setting, that second thing is not merely regulated — Article 5(1)(f) prohibits it, at the top penalty band.
The safe posture, and the one Koji is built around: analyse what participants say, never how their voice sounds. Thematic analysis, quality scoring, and sentiment in Koji all operate on the transcript. There is no vocal affect model anywhere in the pipeline, which keeps voice studies in the limited-risk tier by design rather than by configuration.
When research becomes high-risk: the employment line
Annex III designates AI systems used to recruit, select, and evaluate people as high-risk. The trigger is the decision the output feeds, not the interview format.
Draw the line like this:
- Not high-risk: anonymous employee engagement research, exit interviews analysed in aggregate to find retention themes, candidate experience studies measuring how your hiring process felt.
- High-risk: an AI interview that scores, ranks, or filters candidates. Any output that influences who gets hired, promoted, or terminated at the individual level.
If you are in the second bucket, the full Chapter III regime applies — risk management system, data governance, technical documentation, logging, human oversight, accuracy and robustness testing, and a conformity assessment before you go to market. That is a compliance programme, not a checklist, and it needs counsel.
If you are in the first bucket, keep it there deliberately: report at the cohort level, do not generate per-person scores that feed personnel decisions, and document that design choice. Our guides on anonymous employee research and exit interviews both assume aggregate-only reporting for exactly this reason.
The timeline, after the Omnibus
The compliance calendar shifted materially in 2026, and a lot of published advice is now stale. The AI Omnibus Regulation entered into force in July 2026, deferring the high-risk deadlines that had been set for 2 August 2026.
| Date | What applies |
|---|---|
| 1 August 2024 | AI Act entered into force |
| 2 February 2025 | Prohibited practices apply — including workplace and education emotion recognition |
| 2 August 2026 | Article 50 transparency obligations apply. This is the date that binds customer research |
| 2 December 2026 | Synthetic content marking and watermarking obligations |
| 2 December 2027 | Annex III high-risk obligations — deferred 16 months by the Omnibus |
| 2 August 2028 | High-risk AI embedded in products already covered by EU product-safety rules — deferred 12 months |
The headline for researchers: the deferral does not help you. What moved was the high-risk regime. Article 50 — the tier customer research actually sits in — was not postponed. If you are running AI interviews in the EU, your deadline is now, not December 2027.
What non-compliance costs
Penalties are tiered to match the risk tiers, and they are calculated on global turnover, which is why they get executive attention:
- Prohibited practices (Art. 5): up to €35 million or 7% of worldwide annual turnover, whichever is higher.
- High-risk and other obligations: up to €15 million or 3% of worldwide annual turnover for deployers who fail their duties.
Put plainly: switching on a vocal-emotion feature in an employee study is in the same penalty band as the Act's most serious violations. That single configuration choice is worth more scrutiny than most research programmes give it.
Your compliance checklist
Run this before your next EU study ships:
- Classify the study. Customer research, or employment decision? Write the answer down. This one line determines everything else.
- Disclose the AI up front. First screen, plain language, before the first question.
- Confirm no biometric emotion inference. Ask your vendor directly whether any model infers affect from audio or video. Get it in writing.
- Name the AI in your participant notice, alongside your GDPR disclosures — see research consent form templates.
- Keep employee research aggregate-only. No per-person scores feeding personnel decisions.
- Log your studies. Purpose, dates, audience, model used. If a regulator asks, your defence is documentation.
- Check the provider's posture. Providers carry the design duty — verify yours has actually met it rather than assuming.
- Re-check before 2 December 2026 if you publish AI-generated content externally, when synthetic content marking kicks in.
How Koji handles this
The AI Act rewards platforms that made the right architectural decisions early, because the obligations that matter here are engineered in, not toggled on:
- Disclosure is built into the interview experience. Every Koji interview identifies itself as AI-moderated at the outset. There is no configuration required and no way to accidentally ship a study that hides it.
- No vocal emotion inference anywhere. Koji's analysis operates on transcripts. Voice interviews transcribe speech and analyse language — tone is never modelled — which keeps voice studies in the limited-risk tier structurally.
- Aggregate-first reporting. Koji's report aggregation rolls findings up to themes and cohorts by default, which is exactly the posture that keeps employee research out of Annex III.
- Transcript-level traceability. Every theme in a Koji report links back to the quotes that produced it, so when someone asks how a conclusion was reached, the answer is a citation rather than a shrug.
- Structured questions instead of inference. This is the underrated compliance advantage. When you need to know how someone feels, the robust move is to ask them with a scale question rather than infer it from their voice. Koji's six structured question types —
open_ended,scale,single_choice,multiple_choice,ranking, andyes_no— give you quantified affect as self-reported data. A 1–7 satisfaction scale is better evidence than a tone model, and it is not regulated as biometric processing. Better methodology and lighter compliance load, from the same design decision.
The wider point: legacy survey tools were built before any of this existed, and bolt compliance on through settings you have to find and configure correctly. A platform designed in the AI Act era can make the compliant path the default one — which is the difference between a control you have to remember and a property of the system.
Related Resources
- GDPR-Compliant AI User Research — the data-protection layer that sits underneath AI Act compliance
- Structured Questions Guide — the six question types, and why self-reported scales beat inferred affect
- AI Interview Data Privacy & Security — how interview data is stored, encrypted, and retained
- Research Ethics Guide — the ethical duties that outlast any single regulation
- Research Consent Form Templates — copy-ready notices covering AI disclosure
- HIPAA-Compliant AI User Research — the parallel regime for health-related studies
- Anonymous Employee Research with AI Interviews — aggregate-only design that stays out of Annex III
Regulatory information current as of July 2026 and reflects the AI Omnibus Regulation. This guide is practitioner orientation, not legal advice — confirm your specific obligations with qualified counsel.
Related Articles
AI Interview Data Privacy & Security: A Buyer's Evaluation Guide
How to evaluate the privacy and security of an AI customer research platform — the questions to ask about data handling, PII, retention, sub-processors, and compliance — plus how Koji approaches each one.
Anonymous Employee Research with AI Interviews: Get the Honest Feedback Surveys Miss
Run truly anonymous employee research at scale with AI voice and text interviews. Capture honest feedback on culture, leadership, retention risk, and engagement — without HR ever knowing who said what. Koji removes intake forms, strips identifiers, and still produces aggregated themes and quotes you can act on.
DPIA for User Research: When You Need One and How to Write It (2026)
A practical guide to Data Protection Impact Assessments for customer and user research: the Article 35 triggers, the WP29 nine criteria, what belongs in each section, and a worked example for AI-moderated interviews.
GDPR-Compliant AI User Research: A Practical Guide
How to run AI-moderated customer interviews under GDPR. Lawful basis, consent flows, data minimization, retention, sub-processors, and how Koji handles each requirement.
HIPAA-Compliant AI User Research: A Practical Playbook for Healthcare and HealthTech
Run AI-moderated customer research in healthcare contexts without putting PHI at risk. Patterns for HIPAA alignment, anonymous-mode interviews, BYOK, sub-processor handling, and what Enterprise teams need from a vendor.
Research Consent Form Templates: GDPR-Compliant Forms for Every Study
Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.
Research Ethics and Informed Consent: A Practical Guide for UX Teams
A practical guide to ethical UX research — covering the Belmont Report's three principles, GDPR informed consent requirements, how to handle AI tools responsibly, and how to build ethical maturity in your research practice.
Structured Questions in AI Interviews
Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.