Playbooks

Is AI-Assisted Workshop Analysis Legal Under the EU AI Act and GDPR?

Two separate EU laws govern AI analysis of a workshop: the AI Act decides which practices are banned, GDPR decides how personal data is handled. Here is what each one says about emotion detection, biometric data, gender analytics, and recordings.

Updated Jul 21, 202613 min read

Using AI to analyse a workshop or meeting is not banned in the EU. What the law does is set boundaries, and the boundaries come from two different regulations that answer two different questions. The EU AI Act, Regulation (EU) 2024/1689, decides whether a given AI practice is allowed at all, including a short list of outright prohibited uses in its Article 5. GDPR, Regulation (EU) 2016/679, governs how any personal data in that meeting is collected, stored, and used, no matter which tool does the work. A practice can clear one of these and still run into the other, so the honest way to answer "is this legal" is to take the two laws one at a time.

This is general information about how these two regulations work, not legal advice. Both the AI Act and GDPR turn on the specific details of a specific setup, and only your own counsel can tell you how they apply to yours. Where the law or its official guidance is genuinely unsettled, this piece says so rather than filling the gap with a confident-sounding guess.

Two laws, and what each one governs

The AI Act regulates AI systems as such. Its Article 5 lists practices that are prohibited outright, the ones the EU decided should not be on the market in any form. If what a tool does is not on that list and is not otherwise classed as high-risk, the AI Act is not the thing standing in the way. GDPR is broader and older. It applies whenever personal data about identifiable people is processed, whether or not any AI is involved, and it is what sets rules on consent, purpose, storage, and how long data is kept. Most questions people ask about "recording a workshop legally" are really GDPR questions. Most questions about "does the AI ban emotion detection" are AI Act questions. Keeping them separate is the first step to answering either one accurately.

Does the EU AI Act ban emotion detection in meetings?

Article 5(1)(f) prohibits putting into use "AI systems to infer emotions of a natural person in the areas of workplace and education institutions," with a narrow exception for medical or safety reasons. A facilitated professional workshop can sit inside "workplace," so this one is worth understanding rather than waving off. The reach of the ban depends on what "infer emotions" is anchored to. The Act's companion definition of an "emotion recognition system" in Article 3 describes a system that reads emotions "on the basis of their biometric data," and Recital 18 keeps it there: it lists the emotions in scope, and it excludes plain physical states like pain or fatigue as well as the mere detection of an expression that is not being used to infer an underlying feeling. Recital 44 explains the reason for the prohibition, pointing to weak scientific grounding for reading emotion off a person and the power imbalance that emotion-scoring creates in a classroom or an office.

The practical line falls on biometric data. The European Commission's guidelines on prohibited AI practices (C(2025) 884 final, published 4 February 2025) read the prohibition through the emotion-recognition definition and say directly that a system inferring emotion from written text, the kind of content or sentiment analysis that judges the tone of a passage, is not based on biometric data and so falls outside the ban. Behavioural biometrics such as keystroke dynamics or body posture are inside it; the words a person says, once they are transcript text, are not. One honest caveat belongs here. The operative words of Article 5(1)(f) say "AI systems to infer emotions" without repeating "biometric data," so the biometric limit rests on the Article 3 definition plus the Commission's guidance, and that guidance is not binding law. The Court of Justice of the European Union has the final say on how the Article reads, and it has not ruled on this. And whatever the AI Act does or does not cover, GDPR still applies to the underlying transcript.

What counts as biometric data under the AI Act?

Article 3(34) defines biometric data as personal data from specific technical processing of a person's physical, physiological, or behavioural characteristics, giving facial images and fingerprint data as examples. A voiceprint or a face scan is biometric. The transcribed words someone spoke are not biometric on their own, because they describe what was said rather than a measured bodily characteristic. That distinction does a lot of quiet work across Article 5. The two meeting-relevant prohibitions, emotion inference in Article 5(1)(f) and biometric categorisation in Article 5(1)(g), are both built on the idea of a system reading something off a person's body or voice. A tool that only handles the text of a conversation and metadata about it is on the far side of that line.

Is gender-based talk-time analysis legal, under the AI Act and under GDPR?

This is the question most likely to be answered too quickly, so it is worth splitting by law. Under the AI Act, the relevant prohibition is Article 5(1)(g), which bans biometric categorisation systems that categorise people from their biometric data to infer race, political opinions, trade union membership, religious or philosophical beliefs, or sex life or sexual orientation. Two things keep a gender talk-time chart clear of it. Sex or gender is not on that list at all, which names sex life and sexual orientation rather than sex as such. And the prohibition only bites when a system infers the attribute from biometric data, so a gender label a person entered by hand is not biometric categorisation in the first place.

Under GDPR the question is different. Gender is personal data when it is attached to an identifiable person, but it is not one of the special categories listed in GDPR Article 9, which covers sex life and sexual orientation, not sex or gender in general. So the stricter Article 9 regime is not automatically triggered by a gender field. Gender still counts as ordinary personal data, which means it needs a lawful basis, a clear purpose, and no more collection than the purpose requires. Aggregation changes the picture: a count that reports "in this group, women spoke 40 percent of the time" is a statistic, and GDPR Recital 26 puts genuinely anonymous information, which cannot be traced back to an individual, outside the Regulation entirely. The gray area is real and worth naming. In a small group an aggregate can still point at one person. If a table has a single woman, a per-group figure about women is a figure about her. Whether a given aggregate is anonymous enough to leave GDPR's scope is fact-specific, and the law does not draw a bright line at a particular group size.

Is it safe to record a workshop under GDPR?

There is no yes-or-no answer, because "safe" is not a property a recording has. It is a description of how you handle it. GDPR does not forbid recording a workshop. It asks for a lawful basis under Article 6, usually the participants' consent or a documented legitimate interest. It asks for transparency, meaning people are told what is captured and why before it starts. It asks that you collect no more than the purpose needs, and that you keep it no longer than the purpose needs, the data minimisation and storage limitation principles in Article 5. One extra caution: if the discussion is likely to reveal something in a special category, such as health or beliefs, Article 9 can come into play and explicit consent becomes the usual route. Employee-monitoring rules in some member states can add requirements on top when the room is a workplace.

What is the difference between storing audio and storing only transcripts?

It is a data-minimisation difference, and it matters more than it first looks. A raw audio recording is personal data, and a voice can identify a speaker, so audio carries a heavier footprint than the text of what was said. Keeping only the transcript and metadata, and discarding the audio once it has been processed, is data minimisation and storage limitation put into practice: less sensitive data held, for less time, with less that can leak. The follow-up question to ask any tool is not whether it is "secure" in the abstract but whether raw audio is stored at all, and if it is, for how long. Two tools that both call themselves private can differ completely on that one point.

Is tracking who talks in a meeting considered surveillance?

Not inherently. Talk-time and participation metrics are behavioural analytics, and whether they tip into the kind of monitoring that raises legal or ethical alarm depends on a few things: whether participants know it is happening, whether the measure is proportionate to a real purpose, and whether it reports on named individuals or on the group. Covert, continuous monitoring of employees is a heavily regulated activity in much of the EU. A one-off facilitation exercise where everyone in the room knows talk-time is being measured, and where the output is a group-level balance rather than a per-person score, sits at the opposite end of that range. The surveillance concern is about secrecy and proportionality, not about the existence of a metric.

A worked example: how one tool's design maps onto these questions

To make the framework concrete, here is how the documented architecture of one tool, RoomRadar, lines up against the questions above. This is a description of where specific design choices land, not a compliance certificate. According to its own privacy guide, it stores no raw audio at rest: audio is processed live and only the text and metadata are kept, encrypted. In GDPR terms that is data minimisation and storage limitation by design, and it means no stored voiceprint, which keeps the material on the non-biometric side of the line that Article 5 draws. Data is stored in the EU (Finland) and encrypted in transit and at rest.

The honest caveats are part of the example. The same guide notes that some AI processing may use trusted providers outside the EU under standard contractual clauses, the transfer safeguard in Chapter V of GDPR, so it would be wrong to describe the default setup as fully EU-only. On higher-tier plans an optional Secure mode keeps transcription and AI summaries within EU infrastructure with zero retention, but it is off by default, available on request, and does not cover image or sketchnote generation, which still uses a non-EU model and warns before it runs. On the gender question, the talk-time-by-gender breakdown uses a gender label the facilitator sets by hand on transcript lines, never inferred by the system, and the breakdown is reported per group rather than per person. That is why it does not engage the biometric categorisation prohibition: there is no system inferring gender from anyone's body or voice. None of this decides your own compliance position. It shows how one set of concrete choices reads against one set of legal questions, which is the exercise to run against whatever tool you are looking at.

How to evaluate any tool against these questions

1
Ask what happens to the audio
Find out whether raw audio is stored at all, and if it is, for how long. Storing only text and metadata is a lighter GDPR footprint than keeping recordings.
2
Ask where data lives and whether any of it leaves the EU
EU hosting answers part of the transfer question, but processing can still route through non-EU providers. If it does, ask under what safeguard, such as standard contractual clauses.
3
Ask whether the tool reads anything off the body or voice
A system that infers emotion or an attribute from a face, a voiceprint, or posture is doing biometric processing, the thing Article 5 restricts. A tool that only analyses the words and metadata is not.
4
Ask how any personal attribute is set and shown
Check whether something like gender is inferred by the system or entered by a person, and whether analytics are per-individual or aggregate. Manual and aggregate are lighter-touch than inferred and individual.
5
Make sure you can cover the GDPR basics yourself
Whatever the tool does, you still need a lawful basis, a plain-language notice to participants before you start, and a retention limit you enforce.

FAQ

Is AI meeting analysis legal under the EU AI Act?

AI analysis of a meeting is not on the AI Act's list of prohibited practices in Article 5, and analysing the transcript of what was said is not one of the biometric practices that Article targets. The AI Act is not usually the obstacle. GDPR still governs the personal data involved, so the real work is meeting GDPR's requirements on lawful basis, transparency, and retention. This is general information, not legal advice for your specific case.

Does the EU AI Act ban emotion detection in meetings?

Article 5(1)(f) prohibits AI that infers emotions in workplace and education settings, with a medical or safety exception. Read together with the Article 3 definition of an emotion recognition system and the European Commission's 2025 guidance, the ban is aimed at inferring emotion from biometric data such as face, voice, or posture. The Commission's guidance treats inferring tone from written text or a transcript as outside the ban because it is not based on biometric data. That guidance is not binding, and the Court of Justice has not ruled on the point, so it is not fully settled.

What counts as biometric data under the EU AI Act?

Article 3(34) defines it as personal data from technical processing of a person's physical, physiological, or behavioural characteristics, with facial images and fingerprints as examples. A voiceprint or face scan qualifies. The transcribed words someone spoke do not, on their own, because they record what was said rather than a measured bodily trait.

Is gender-based talk-time analysis legal under GDPR?

Gender is personal data, but it is not one of GDPR Article 9's special categories, which cover sex life and sexual orientation rather than sex or gender as such. So the stricter Article 9 rules are not automatically triggered. Gender is still ordinary personal data needing a lawful basis and a clear purpose. Aggregated group-level figures move toward the edge of GDPR's scope, though in a small group an aggregate can still identify an individual, which is a fact-specific gray area rather than a settled rule.

Is it safe to record a workshop for GDPR compliance?

GDPR does not forbid it. It requires a lawful basis (usually consent or a documented legitimate interest), telling participants what is captured and why before you start, collecting no more than you need, and keeping it no longer than you need. If the conversation is likely to reveal special-category data like health or beliefs, explicit consent is the usual route, and some countries add employee-monitoring rules on top.

Which meeting recording tools are GDPR compliant?

No tool is "GDPR compliant" as a fixed property. Compliance depends on how a tool is configured and how you use it: your lawful basis, your notice to participants, your retention setting, and where the data is processed. EU hosting helps with the data-transfer question but does not settle the rest, since some tools still route processing through non-EU providers under standard contractual clauses. Judge the setup, not the label.

Is tracking who talks in a meeting considered surveillance?

Not by itself. Participation metrics become a concern when they are hidden from the people being measured, when they are out of proportion to any real purpose, or when they score named individuals rather than describe the group. A one-off exercise where everyone knows talk-time is measured and the output is a group-level balance is a long way from covert employee monitoring.