The EU AI Act and Research: The AI Act Meets the Discussion Guide

Article M6-06

Market research once governed itself by voluntary codes; the EU has now turned parts of it into hard law. The risk map is not what most researchers expect: the emotion-recognition ban does not cover commercial research, while a less visible biometric-categorisation rule can.

In brief

The EU AI Act is the first hard law that applies to how research is collected, and it sorts every AI use into four risk tiers: prohibited, high-risk, limited-risk with transparency duties, and minimal. Most mainstream AI-enabled research falls into the limited-risk tier, where the only real duty is to tell people the system is being used. The well-known ban on emotion recognition applies to workplaces and schools, not to using emotion recognition to infer a customer's mood in a study. Biometric categorisation that sorts people by a sensitive trait, such as their politics, can be prohibited outright. Academic commentary on the Act is critical, and the tiers still require interpretation. No standards body or agency has published a map that places each research use in a tier, so each team has to do that work itself. When the Act is read together with data-protection law, helpful personalisation and manipulative targeting can end up in the same category.

What the theory says

The theory

For most of its history, market research was governed by agreement rather than statute. The industry wrote its own rules, most visibly the ICC/ESOMAR International Code, and firms signed up voluntarily. That tradition is described in the industry's self-regulation. A breach cost standing with peers, not a fine.

That changed with Regulation (EU) 2024/1689, the AI Act, a statute with staged start dates. Its prohibitions and its AI-literacy duty began to apply on 2 February 2025, while most of its transparency obligations take effect on 2 August 2026. Rules for AI built into regulated products come later still (Regulation (EU) 2024/1689). For the first time, a research team using AI to collect or analyse data is subject to a law with penalties, rather than only to a code it chose to join.

The Act sorts uses into four tiers of risk:

  • Prohibited: a small set of practices banned outright under Article 5.
  • High-risk: a larger set under Article 6 and the Annex III list, carrying heavy obligations.
  • Limited-risk: set out in Article 50 and requiring transparency and little else.
  • Minimal-risk: everything else, largely untouched.

Novelli and colleagues (2024) describe these four categories, and Ebers (2024) reads the structure as risk-based in practice. The burden is supposed to rise with the danger rather than to fall evenly on everyone.

At present, most mainstream AI-enabled research lands in the limited-risk tier. A chatbot that interviews respondents, a model that codes open-ended answers, and a tool that drafts survey questions are either systems a person interacts with or systems that generate content. The Act mainly asks that their use be disclosed. These tools may seem new and legally exposed, but the Act as written imposes little on them.

Because the Act prohibits emotion recognition, a reader could reasonably assume that a study inferring how a consumer feels about an advert is illegal. That assumption is not correct, because the prohibition has a limited scope. The European Commission's Guidelines on Prohibited AI Practices (European Commission, 2025), published on 4 February 2025, clarify the scope. The Article 5 ban on emotion inference applies to workplaces and educational settings, to protect workers and students, and does not reach a company inferring a customer's emotions in commercial research. Commercial emotion inference therefore falls under the transparency duties and the separate biometric rules. Whether emotion AI actually measures what it claims is a different question, and one we take up elsewhere.

Article 5 also operates in the opposite direction, prohibiting biometric categorisation that sorts people by a sensitive trait, such as race, political opinion, or sexual orientation. A system that reads faces or voices and groups respondents by an inferred protected characteristic is not in the transparency tier and can be prohibited. The emotion ban does not cover most commercial work, but a less noticed rule about categorisation can stop a study outright.

As far as this research could establish, no peer-reviewed source has yet mapped market-research uses tier by tier, and no standards body or named agency has published a tier map either. The mapping above is this article's own synthesis, based on the legal text and the Commission's guidance. Those sources describe what the law says rather than whether it is wise. The academic literature the article draws on still focuses on the Act in general, rather than on research in particular.

Controversies

The central dispute is where the Act's risk tiers are drawn, and Nannini (2025) describes a profiling paradox. When the Act's high-risk test is read alongside the data-protection definition of profiling, it creates a binary regime. That regime turns on whether personal data is processed, not on what is done with the data. A system that personalises helpfully and a system that manipulates can be treated the same way because both process the same kind of data. The rule can favour opaque systems over transparent ones. A tool that is open about how it targets people may look more like regulated profiling than an opaque tool that hides how it targets people. If that reading holds, the tier a research system lands in may have little to do with how much harm it can do.

Wörsdörfer (2023) weighs the law against its own promises, asking whether the law is hype or hope. The worry is that the law is broad enough to discourage legitimate work and too vague to be enforced. Autischer, Waxnegger and Kowald (2026) look at how high-risk systems demonstrate compliance, finding that the weak point is self-certification. Their example is facial emotion recognition, where a provider can attest to its own conformity with little outside checking. Both doubts remain open because the Act is too young to have produced evidence.

The claim that biometric categorisation by a protected trait applies to mainstream studies is stated in the mapping above, but no published work has tested whether a routine research use actually triggers it in practice. The claim is a plausible reading of the text, not a documented enforcement outcome.

Limitations

The Act names four categories and gives detailed lists, but it does not place a real system into one of those categories automatically, nor does it explain how to decide which category a real system falls into. Novelli and colleagues (2024) treat that as the central gap and propose a scenario-based, proportional test to fill it. The test is modelled on how climate bodies reason about uncertain risk. A team cannot simply look up its tool in a table; it has to make a judgement. Reasonable people can reach different judgements about the same tool.

There is also a gap in how emotion data is treated. Häuselmann and colleagues (2023) argue that EU data-protection law still does not treat emotion data as a special category, so emotion data receives less protection than one might expect for something so personal. Their analysis has a caveat: it was written against an earlier draft of the Act, before the final prohibition text was fixed. It remains reliable on the data-protection gap, but it should not be read as authority on the final article numbers. Commercial emotion inference sits in the transparency tier. On the points it covers, the analysis shows that this tier is still not backed by strong underlying data rules.

Rintamäki and colleagues (2024) map where the high-risk categories of the Act and data-protection law overlap and where they diverge. The boundary between the two regimes remains unsettled. A research use can be caught by one framework, both, or neither, depending on fine distinctions that have not yet been resolved. For a practitioner, compliance with one law is not compliance with the other.

Classification remains a manual task. The industry codes that once governed this area predate the Act and still do not translate its tiers into research practice. A team that wants to know which tier applies has to do the placement work itself, with no reference answer to check against.

Open questions

The largest unknown is enforcement. The transparency duties do not start to apply until 2 August 2026. No regulator has yet tested a research use in practice, so there is no record of how strictly any of these duties will be applied and no basis for a confident prediction in either direction. Palmiotto (2025) traces how the Act's protections shifted through the legislative process. Those protections are still evolving. The Act's current text records a settlement that is still changing, not a fixed endpoint.

The second question is how far the Act applies. The Act is EU law, but its practical effect may extend well beyond the EU. A global agency often finds it cheaper to run one compliant process than to maintain two. It is often asserted that this so-called Brussels effect reshapes how non-EU researchers work, but as far as this research could establish no study has yet demonstrated it. The Brussels effect therefore remains an open question.

So what

Research that uses AI is now subject to a real law, and most of it is in the light-touch transparency tier. Two legal points are easy to get wrong. The ban on emotion inference misses commercial work, and categorising people by a sensitive trait can be prohibited. Because no reference mapping has been published, each team must work out its own placements, and each placement is a judgement to defend. No one can look up the correct answer.

For research practice

Classification is the first job, and it cannot be delegated to a vendor's marketing page. A team must place each AI tool in the pipeline. A system that people interact with or that generates content falls in the transparency tier, while a tool doing something that the Act treats as high-risk or prohibited falls elsewhere. Most tools will fall in the transparency tier, and in that tier the duty is honest disclosure that AI is being used. If a study infers emotion, it is probably outside the Article 5 ban but still inside the transparency and biometric rules, so disclosure and care with sensitive inferences matter more than fear of prohibition. If a tool sorts respondents by anything close to a protected trait, the team should stop and get advice, because in that situation a use can be banned, not just regulated. Because no reference mapping exists, the team should write down the reasoning for each placement, and the record makes the judgement defensible if anyone asks.

For companies

For a business, the change is that a research compliance failure is now a legal exposure, not just a reputational one. Regulation (EU) 2024/1689 sets its penalties in Article 99. Breaching the Article 5 prohibitions can draw administrative fines up to 35 million euro or 7 percent of worldwide annual turnover, whichever is higher, and breaching other duties, including the transparency obligations, can draw administrative fines up to 15 million euro or 3 percent. Those are ceilings in the statute, not observed fines. Enforcement has barely begun, but they still set the scale of the risk. The concrete duties for most commercial research are modest. Companies must disclose when respondents are dealing with AI, and they must mark AI-generated content. The finer points of how to make that disclosure are covered in the work on transparency by design. The main mistake is to assume that a vendor has already handled classification. As far as this research could establish, AI-interviewer and synthetic-respondent vendors do not publish their own tier assessments, and the responsibility to place the tool belongs to the buyer who deploys it.

For political parties

Political research is where the Act's strictest bans apply. Categorising people by inferred political opinion is one of the sensitive-trait cases that Article 5 treats as prohibited biometric categorisation, and the Act also bans manipulative techniques that exploit vulnerabilities to distort behaviour. A party tempted to use facial or voice analysis to sort voters by inferred allegiance is not in an unclear area of transparency duties, because the technique falls near the clearest prohibitions. Research that profiles a protected trait to create a targeted appeal is legally exposed and has no analytical value. A study built to justify a message you already chose tells you nothing you did not already believe. The defensible use of AI in political research is to understand a coalition more accurately and more cheaply. Researchers should apply the same instrument and standard to every group, and they should keep well clear of inferring sensitive traits from biometric signals. If a technique only makes sense as a way to target people on the basis of who they are, the team should stop.

For government and policy

Government has two roles under this law. As a commissioner of research, a public body carries the same classification duty as any company, and the stakes are higher for a public body because official numbers guide decisions. A confusing or intrusive instrument often fails the people the research exists to serve. As a regulator, the position is that enforcement is not yet in place, and the transparency duties start to apply on 2 August 2026. No research case has been tested, and there is no empirical record of how the tiers will be enforced. Any claim about how strict the regime will be in practice is speculation for now.

The useful policy questions are the ones the literature already identifies. The tiers are not self-applying, which means agencies will need placement guidance that the Act does not provide (Novelli et al., 2024). The boundary with data-protection law is unresolved (Rintamäki et al., 2024). The profiling critique suggests that the current tiers may not track real harm well (Nannini, 2025). A system that looks compliant may still do damage, while a system that looks risky may be benign. Policy should take those three points seriously, and it should not treat the tier list as settled.

Case studies

European Commission, Guidelines on Prohibited AI Practices (4 February 2025). Two days after the Article 5 prohibitions became applicable, the Commission published guidance on how they should be read. The most consequential clarification for research is that the emotion-inference prohibition is aimed at workplaces and educational settings, protecting workers and students, and does not reach a company inferring a customer's emotions in commercial research (European Commission, 2025). That single scoping decision is why mainstream commercial emotion work sits in the transparency tier rather than under the ban, and it is a rare case of an official body spelling out a limit on its own prohibition. The guidance is non-binding, so it signals how the Commission reads the law rather than settling it, but it is the clearest statement available of where the line falls.

References

Autischer, G., Waxnegger, K. and Kowald, D. (2026) 'Self-certification of high-risk AI systems: the example of AI-based facial emotion recognition'. SSRN working paper (also arXiv:2601.08295). Available at: https://doi.org/10.2139/ssrn.6067906 (Accessed: 18 August 2026).

Ebers, M. (2024) 'Truly risk-based regulation of artificial intelligence: how to implement the EU's AI Act', European Journal of Risk Regulation, 16(2), pp. 684–703. Available at: https://doi.org/10.1017/err.2024.78 (Accessed: 18 August 2026).

European Commission (2025) Guidelines on prohibited artificial intelligence (AI) practices, as defined by the AI Act. Brussels: European Commission, 4 February 2025. Available at: https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act (Accessed: 18 August 2026).

Häuselmann, A., Sears, A.M., Zard, L. and Fosch-Villaronga, E. (2023) 'EU law and emotion data', in 2023 11th International Conference on Affective Computing and Intelligent Interaction (ACII). IEEE, pp. 1–8. Available at: https://doi.org/10.1109/acii59096.2023.10388181 (Accessed: 18 August 2026).

International Chamber of Commerce and ESOMAR (2025) ICC/ESOMAR International Code on Market, Opinion and Social Research and Data Analytics. 5th edn. Paris/Amsterdam: ICC/ESOMAR. Available at: https://iccwbo.org/news-publications/business-solutions/iccesomar-international-code-market-opinion-social-research-data-analytics/ (Accessed: 18 August 2026).

Nannini, L. (2025) 'From categorical to contextual: interpreting high-risk classification for profiling-based AI recommender systems in the EU AI Act', Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society, 8(2), pp. 1836–1847. Available at: https://doi.org/10.1609/aies.v8i2.36678 (Accessed: 18 August 2026).

Novelli, C., Casolari, F., Rotolo, A., Taddeo, M. and Floridi, L. (2024) 'AI risk assessment: a scenario-based, proportional methodology for the AI Act', Digital Society, 3(1), 13. Available at: https://doi.org/10.1007/s44206-024-00095-1 (Accessed: 18 August 2026).

Palmiotto, F. (2025) 'The AI Act roller coaster: the evolution of fundamental rights protection in the legislative process and the future of the regulation', European Journal of Risk Regulation, 16(2), pp. 770–793. Available at: https://doi.org/10.1017/err.2024.97 (Accessed: 18 August 2026).

Regulation (EU) 2024/1689 (2024) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 2024/1689, 12.7.2024. Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj (Accessed: 18 August 2026).

Rintamäki, T., Golpayegani, D., Celeste, E., Lewis, D. and Pandit, H.J. (2024) 'High-risk categorisations in GDPR vs AI Act: overlaps and implications'. OSF preprint. Available at: https://doi.org/10.31219/osf.io/6qhzj (Accessed: 18 August 2026).

Wörsdörfer, M. (2023) 'Mitigating the adverse effects of AI with the European Union's artificial intelligence act: hype or hope?', Global Business and Organizational Excellence, 43(3), pp. 106–126. Available at: https://doi.org/10.1002/joe.22238 (Accessed: 18 August 2026).

Explore the idea

Let’s talk

Invisible forces shape your world — until you hire Latenta®

Contact