The EU AI Act, Regulation (EU) 2024/1689, is now the framework every AI tool used in Europe is measured against, and AI meeting assistants sit squarely inside its scope. The good news for most teams is that a notetaker that transcribes and summarises is not a high-risk system. The catch is that one specific feature, inferring emotions from a person's voice at work, is not merely regulated but outright banned, and it has been since February 2025.
Here is what the AI Act actually requires of AI meeting assistants and the recordings they produce, which dates matter, and where the sharp edges are. This is an explainer, not legal advice; for your own deployment, take a lawyer.
The timeline: what applies, and when
The AI Act does not switch on all at once. It entered into force on 1 August 2024 and phases in over several years. The dates that matter for meeting assistants are these.
- 2 February 2025: the prohibited practices in Article 5 apply, including the ban on emotion recognition in the workplace. This is live now.
- 2 August 2025: obligations for general-purpose AI models apply.
- 2 August 2026: the general date of application, including the Article 50 transparency obligations and most high-risk obligations under Annex III.
- 2 August 2027: the remaining high-risk classification rules and delayed general-purpose AI deadlines apply.
So the transparency and high-risk rules are still ahead, but the emotion-recognition ban is already in force. If you want the wider picture of how these dates land on B2B software, we mapped it in the EU AI Act timeline for B2B SaaS.
Which risk tier does a meeting assistant fall into?
The AI Act sorts systems by risk. A handful of practices are prohibited outright. A defined set of use cases is high-risk and carries heavy obligations. Most other systems are limited-risk, where the duty is transparency, or minimal-risk, where there is essentially no specific obligation.
A meeting assistant that records a call, transcribes it, and produces a summary is generally in the limited-risk tier. It is not on the Annex III high-risk list simply for taking notes. That means the main thing it owes users is transparency: telling people an AI system is in use. It does not mean the assistant is unregulated, and it does not remove the separate, and heavier, obligations of the GDPR.
Under the EU AI Act, most AI meeting assistants are limited-risk systems whose principal obligation is transparency under Article 50. They are not high-risk merely for transcribing and summarising. Two things can change that: inferring emotions from voice at work, which is prohibited under Article 5, and using the output to evaluate or make decisions about employees, which can be high-risk under Annex III.
The prohibited line: emotion recognition at work
This is the part every buyer of conversation-intelligence tools should understand, because it is a ban, not a checkbox. Article 5(1)(f) prohibits placing on the market or using AI systems to infer the emotions of a person in the areas of workplace and education institutions, except for narrow medical or safety reasons such as fatigue detection for drivers.
The definition that makes this bite is in Article 3(39): an emotion recognition system identifies or infers emotions or intentions of people on the basis of their biometric data. Voice is biometric data. Recital 18 spells out that inferring emotions such as happiness, anger, or shame, including from characteristics of a person's voice such as a raised voice or whispering, is caught.
So a feature that listens to a sales rep's voice and infers their mood, stress, or emotional state during internal calls is exactly the kind of system the Act prohibits in a workplace. That is not a compliance burden you can document your way through; it is a red line that has applied since February 2025.
Where the line is not, and why it matters
The prohibition is narrower than it first sounds, and the boundary is where a lot of conversation-intelligence products actually live. Two things fall outside it.
First, analysis based on the transcript rather than on biometric data is not emotion recognition. Working out that a call spent too long on price, that an objection went unanswered, or that the rep talked seventy per cent of the time, is analysis of what was said and of conversational structure. It is not inferring emotion from biometric signals, so it is outside Article 5(1)(f). The Commission's February 2025 guidelines confirm that text-only content analysis is out of scope.
Second, Recital 18 is explicit that physical states such as pain or fatigue are not emotions, and that the mere detection of readily apparent expressions or gestures is not, by itself, inferring emotion. There are genuinely contested edges here, including whether a customer's voice on a sales call is even within the workplace scope of the ban, and legal scholars disagree about exactly where detecting an expression ends and inferring an emotion begins. Treat voice-based emotion inference as the highest-risk feature to avoid, and keep the analysis on the transcript.
Inferring emotion from a person's voice at work is prohibited, because voice is biometric data. Analysing what was said in the transcript, and conversational metrics such as talk-to-listen ratio and objection handling, is not emotion recognition, because it is not based on biometric data. The safe design keeps the intelligence on the words and the structure of the conversation, not on reading feelings from the sound of someone's voice.
The transparency duty: Article 50
From 2 August 2026, Article 50 requires that people are informed when they are interacting with an AI system, unless it is obvious. It also requires that AI-generated synthetic content, including AI-generated text, is marked as artificially generated in a machine-readable way. For meeting assistants, the practical hooks are two: tell participants an AI assistant is present and capturing the call, and treat AI-generated summaries as AI-generated content. A plain factual transcript of what was said is not a deep fake; an AI-written summary is AI-generated text and engages the marking duty.
In practice this lines up with what good privacy hygiene already demands. An assistant that joins the call as a visible participant, rather than recording silently from someone's laptop, satisfies the spirit of the transparency duty by design, because everyone can see it is there.
When a coaching or scoring tool becomes high-risk
Here is the nuance that catches sales and enablement teams. Transcription is not high-risk, but Annex III point 4 lists AI systems used in employment and worker management as high-risk, specifically those used to monitor and evaluate the performance and behaviour of workers, or to make decisions on task allocation, promotion, or termination.
That means the same call-scoring output can sit in different risk tiers depending on how it is used. A coaching score a rep uses for their own development is a very different thing from a score that feeds performance management, ranks reps for the purpose of promotion, or informs a termination. The moment the output drives employment decisions, the high-risk obligations, which include risk management, data governance, human oversight, and documentation, come into play from 2 August 2026.
The takeaway is not to avoid coaching. It is to be clear-eyed about how the output is used, and to keep a human making the employment decisions rather than the system. Separately, Annex III also lists AI intended for emotion recognition as high-risk in its own right, which is another reason to keep voice-emotion features out of the product entirely.
The AI Act does not replace the GDPR
A recurring mistake is treating the AI Act as the new single rulebook. It is not. The AI Act applies without prejudice to the GDPR; the two are complementary. The GDPR governs how personal data is processed, and the AI Act governs the risks of the AI system on top of that.
Meeting recordings, transcripts, and voice are personal data, and voice can be biometric and therefore special-category data under GDPR Article 9. Every GDPR duty still applies in full: a lawful basis for recording, informing participants, data minimisation, retention limits, and a data protection impact assessment where the processing is high-risk. And the question the GDPR keeps forcing, where does the data actually go, is not answered by the AI Act at all. We work through the recording-consent side of this for Germany in AI notetaker consent, §201 StGB, and the Betriebsrat, and the residency side in the GDPR-compliant AI meeting assistant comparison.
How Numi approaches it
Numi is a sales-call-intelligence and meeting-assistant product built for exactly this environment. Its analysis is grounded in the transcript and in conversational metrics, the talk-to-listen ratio, objection handling, coaching, and scorecards, rather than in inferring emotions from the biometric characteristics of a voice, which keeps it on the correct side of the Article 5 line. The meeting bot joins Teams and Google Meet as a visible participant, which supports the transparency the Act expects, and the whole pipeline is EU-resident, which answers the residency question the GDPR asks. None of that is a substitute for your own legal review, and how you use call scores in performance management is a decision that stays with you.
If you are building an internal case, the AI vendor due-diligence checklist for the EU turns these questions into something you can put in front of a vendor, and the case for AI meeting assistants covers why the category is worth adopting carefully rather than avoiding.