AIS-107
Control-room operator attention monitor
Already applicable: art.4 AI literacy and the art.50 transparency duties. Compliance is owed from placement, not from a future date. The art.50 transparency duties have applied since 2 August 2026. A system or model first placed on the market on or after that date must comply from placement — there is no separate future transition deadline.
⚠ Problems to check before validating (2)
⚠ Emotion recognition at work but art.5 not ticked.
Read this before the classification above. Inferring emotions in the workplace or in education is prohibited by art.5(1)(f), not merely high-risk. If that is what this system does, the verdict above is wrong in the one direction documentation cannot fix: the system may not be used at all.
⚠ Actual use diverges from the stated purpose — art.25(1)(c).
How this was decided
- CMYes — An AI system, with an art.2 connecting factor to the EU, and no exemption claimed.[CJ, CK, CL]From your answers to: Q1.1 — Does the tool produce predictions, content, recommendations or decisions — rather than simply displaying, storing or computing data? ; Q1.2 — Does the tool produce those outputs by LEARNING from data, or by applying a model — rather than by running rules a person wrote? ; Q1.3 — Does the output INFLUENCE something — a physical environment, a workflow, a document, a decision — rather than just sitting there? ; Q1.4 — Does the tool work on its own to some degree, producing its output without a person specifying every step? ; Q2.1 — Where is the tool used, and where are the people or the outputs it affects? (tick all that apply) ; Q2.2 — Does the tool fall into any of these cases?
- FLimited risk (transparency) — Not high-risk, but art.50 transparency duties apply: people must be told they are dealing with AI, or that content was generated by it.[DR]From your answers to: Q8.5 — Does the tool read emotions from people, or sort people into categories using biometric data?
Obligations that apply (10 of 61; 51 ruled out)
art.4 applies to every provider and deployer of any AI system in scope, whatever its risk level, and — on the value-chain reading of recital 20 — to a provider of a general-purpose AI model: the people who operate and are affected by it must have a sufficient level of AI literacy. (A GPAI model is not literally an "AI system", so the strict text is arguable; the register takes the broad, fail-safe reading, and this note flags it as such.)
- art.4AI literacy (art.4)
You deploy an emotion-recognition or biometric-categorisation system. art.50(3) requires the people exposed to it to be informed of its operation.
- art.50(3)Inform persons exposed to emotion recognition / categorisation (art.50(3))
At least one art.50 transparency duty applies. art.50(5) governs HOW it must be discharged: clearly and distinguishably, at the latest at the first interaction or exposure, and accessibly.
- art.50(5)Provide the information clearly and distinguishably at the latest at first interaction or exposure, meeting accessibility requirements (art.50(5))
Personal data is processed and the GDPR applies territorially. These duties are owed under the GDPR independently of anything the AI Act requires — a minimal-risk system can still carry all of them.
- art.6 / art.9(2)Legal basis identified & documented (art.6 / art.9(2))
- art.30Record of processing activities (art.30)
- art.13-14Information to data subjects (art.13-14)
- art.32Security of processing — technical and organisational measures (art.32)
A data protection impact assessment is mandatory under GDPR art.35(3): the processing is a systematic and extensive automated evaluation on which decisions with legal or similarly significant effect are based (point a), or it processes art.9 special categories or art.10 conviction data at a scale you have not ruled out (point b), or it systematically monitors a publicly accessible area (point c). Decided on those tests alone — the AI Act art.6 classification is a different question with different triggers. The DPIA must be done BEFORE processing begins, and it does not replace a FRIA where AI Act art.27 also applies. Note art.35(3) is a non-exhaustive list: where no limb is established, art.35(1) and the supervisory authority’s own mandatory list still have to be screened, which is what register column EP reports.
- art.35Data protection impact assessment — DPIA (art.35)
Personal data leaves the EU/EEA, or it is UNKNOWN whether it does — including via a supplier or sub-processor. Chapter V requires a transfer mechanism. "Unknown" is treated as a transfer on purpose: an unmapped data flow is the normal way an unlawful transfer happens.
- Ch. VTransfer safeguards outside the EU/EEA (Ch. V)
A third party processes this personal data on your behalf. art.28 requires a written processor agreement containing the mandated terms — a supplier contract that is silent on them does not satisfy it.
- art.28(3)Written processor agreement with each processor (art.28(3))
Compliance dates
- Art.4 AI literacy have applied since 2 February 2025. A system or model first placed on the market on or after that date must comply from placement — there is no separate future transition deadline.
- The art.50 transparency duties have applied since 2 August 2026. A system or model first placed on the market on or after that date must comply from placement — there is no separate future transition deadline.
- No GPAI model obligations apply to this system.
Answers behind it
- Q1 · What does THE COMPANY do with this tool?
- THE COMPANY buys or subscribes to an external AI system, or a foundation model, for internal usage
- Q2 · At go-live, whose name or trademark is on it?
- —
- [B] High-risk area — Annex III
- No
- Personal data present? (GDPR art.4)
- Yes
One worked example under the register v11 rules. Fictional data; no account, nothing stored.