The phrenological turn: On using, abusing, and regulating emotion recognition technology
- Stefan Tampu
- 8 minutes ago
- 9 min read

Imagine, dear reader, being selected for a virtual interview conducted by an AI. You dress sharply (at least from the waist up) and set your laptop on a stack of books in front of you to be eye-level with its camera. At the hour, you hit the “start interview” button. Your camera turns on and a friendly, inquisitive voice greets you before asking you to tell it about yourself. You see only yourself on screen as you succinctly tell your life story while mentally repeating “eye contact” like a mantra. Being a good candidate, you’ve rehearsed your answers many times. Sure, nothing could have prepared you to speak about yourself to yourself on camera while suppressing your response to the uncanny valley effect the AI interviewer’s voice provokes. But you push on.
You take a few extra moments when answering because you are thoughtful, modulate your voice to show excitement and interest, and establish confidence through the downward inflection that always accompanies the end of your sentences. And never ever do you forget: “eye contact”. The interview is highly competitive and the AI highly unpredictable, especially since the latter is not just asking you questions but also tracking your emotions using video and audio signals. How exactly it evaluates you is a mystery. Is it determining your Big Five personality traits? Assessing your psychological and emotional proclivities? Or just gauging your stress level and the sincerity of your interest in the company? You only know that a sophisticated algorithm will analyze every detail, and every performance point counts.
Your virtual interviewer’s ability to make inferences about your emotions makes it a type of emotion recognition technology (ERT). Such technology is already widely used for interviews – and for many other purposes besides.
What is emotion recognition technology?
Emotion recognition technology applies artificial intelligence to purportedly determine an individual’s emotional state based on bodily cues. The means vary. Video recordings can help analyze facial micro-expressions, speech patterns, head and body posture, and gait. ERT typically follows three steps for facial emotion recognition: detecting the face, detecting the facial expression based on the position of landmarks like the ends of the nose and eyebrows, and finally classifying the expression within an emotional category. Procedures can be even more intrusive, relying on signals like galvanic skin response, facial electromyography, electrocardiography, and electrodermal activity to interpret emotional states.
The uses of ERT are legion, so I will offer only a few examples. ERT supports vehicular transportation, such as by detecting driver fatigue and road rage, enhancing passenger experience in driverless vehicles, and monitoring aeroplane pilots’ alertness and maladaptive emotional states. In the medical sphere, ERT can help support early autism detection and socialization, assess social anxiety, predict depression, and assist with suicide prevention. Businesses can leverage ERT to enhance their advertising. Besides helping employers assess interviews, ERT can also monitor employees’ attention, concentration, energy and stress levels, and job engagement and satisfaction. Finally, ERT may also contribute to law enforcement and public security, such as by using it for predictive screening of public spaces for crime or terrorist activity, to detect fraud or shoplifting, enhance airport security, and to interpret criminal motive through analysis of crime scene footage.
ERT’s mass public adoption is already underway. According to one study, the global ERT market valued USD 42.83 billion in 2025, and is expected to grow at a compound annual growth rate of 14.30% between 2026 to 2034. Therefore, it is important to understand ERT’s potential harm to privacy and human rights and regulate the technology’s adoption proactively rather than waiting for its adoption and any associated harms to become commonplace.
The risks of emotion recognition technology
ERT’s adoption comes with three broad types of risks: privacy, accuracy and control. First, ERT affects privacy because it is highly intrusive. It may not only collect information about individuals, but does so to infer their interior states, potentially without their knowledge or consent. ERT frequently also relies on datasets of controversial origin. For example, Facebook’s model DeepFace, the first major breakthrough in facial recognition technology trained with deep learning, is based on a dataset of 4.4 million photos of 4,030 users’ profile images. Facebook has not made the DeepFace dataset public, but its success has in turn inspired further deep learning-based facial recognition training and commercialization – often without consent from the individuals’ whose images are used.
Besides foregoing procedural requirements for obtaining consent, ERT can also be at odds with the fundamental values underlying privacy law. This is not merely an issue of methods or consequences, but of guarding a “space” upon which no technology should intrude. Human emotions, and the hopes, desires, fears, and personal dramas that give birth to them, are precious things. They mold our lives and character, and give meaning to life. Because of the value of emotions, humans are selective about whom they share their emotions with, and how, where, when, and why they share them. ERT now threatens to unveil our inner world and reduce something complex, mysterious, and precious into standard emotional categories for the ERT user’s own purposes. This represents a threat to human dignity in so far as it requires individuals to monitor their own expressions, emotional performance, and bodies, or else risk having their inner life appropriated or otherwise mischaracterized through stereotypes. ERT therefore challenges privacy law to not only protect information about persons, but to guard the inner world of persons – something which never before could have been truly broached.
Second, ERT can also infer individuals’ emotions inaccurately, thus feeding erroneous and harmful information to decision-makers. The technology would perform perfectly if human expressions, emotions and the correlations between the two were uniform across all humans. Individual and especially inter-group (e.g., cultural, racial, and gender) variation often cause the technology to make inaccurate inferences. For example, one study showed that the facial recognition services of Face++ and Microsoft’s AI (both of which have emotion-recognition features) are more likely to interpret black NBA players as having negative emotions like anger than white players. Of course, better datasets could correct such biases, but the exercise of using outward cues to divine internal states and classify them into neat emotional categories may itself not be sound.
Third, totally accurate ERT is still undesirable if its use diminishes individuals’ control over their lives. For the state, ERT enhances the possibility of mass public surveillance, pre-crime action, and population control. ERT can also reinforce power disparities in the private sector, especially where the technology’s user has power over the one being recorded. For example, employers could use ERT to control employees more closely based on algorithmic scores around attention, stress levels, social interactions, and positive versus negative emotions. Businesses could use emotion-sensing marketing tools to better understand unsuspecting consumers’ emotions and manipulate them into purchases.
Regulating ERT through privacy law
Standard Canadian privacy laws would regulate ERT to some extent in so far as the technology collects personal information to infer emotions. Section 8 of the Charter may protect an individual in, for example, a criminal trial from ERT’s inferences if the preliminary recording of the individual’s facial expressions constitutes an unreasonable search or seizure. The Privacy Act regulates government institutions’ ability to collect personal information through ERT, for example forbidding collection of information that does not relate “directly to an operating program or activity of the institution” (s. 4). PIPEDA similarly constrains private organizations’ collection of personal information through ERT by limiting it to “purposes that a reasonable person would consider are appropriate in the circumstances” (s. 5(3)). Provincial laws may also apply. For example, in Ontario, PHIPA regulates use of ERT related to personal health information, such as for the medical purposes I listed earlier.
Yet, Canadian privacy law is currently lacking with respect to ERT in two ways. First, the boundaries of legitimacy for using personal information collected from or inferred through ERT are unclear and potentially too permissive. As with any other personal information under the Privacy Act, a government institution does not strictly need an individual’s consent to collect or use their information through ERT. So long as the institution collects information through ERT for reasons directly related to its programs or activities (s. 4), and uses the data for that purpose or for a consistent end (s. 7), then consent is not a barrier to collection and use. For example, law enforcement may be able to deploy ERT to assist criminal investigations (see a related use of facial recognition technology) or for security purposes (see China’s precedent). Under the Privacy Act, law enforcement may forego collecting information directly from individuals or informing them of the collection if doing so would “result in the collection of inaccurate information” (Privacy Act, s. 5(3)(a)) or “defeat the purpose or prejudice the use for which information is collected” (s. 5(3)(b)).
In the case of PIPEDA, the “reasonable person’s” view on “appropriate purposes" may become increasingly amenable to ERT’s use with the continued adoption of ERT and other AI technology. For example, if the general population becomes accustomed to emotion-based targeted advertising on online social media platforms, then adapting ERT towards this goal may not be so inappropriate from the “reasonable person’s” view. PIPEDA also allows organizations to collect, use and disclose personal information without consent in some circumstances where protection from ERT is needed most, such as for information produced in the course of employment (s. 7(1)(b.2), 7(2)(b.2) and 7(3)(e.2)).
Second, while Canadian privacy laws would regulate various personal information collection and use through ERT, they generally do not regulate de-identified and aggregated information. This is a common problem for regulating AI technologies, which may easily infer an individual’s identity from de-identified information. In the case of ERT, re-identification may also be a problem. However, de-identified and aggregated information may be even more useful for opening new vistas into people’s minds. Governments and private organizations may use these vistas to assert greater control over people, such as to create better models for public or workplace surveillance or for targeted advertising.
Solutions to consider
It may be useful for ERT and general AI regulation to patch up privacy laws to elaborate on the meaning of appropriate, reasonable or legitimate government and private organization handling of personal information, limit exceptions to consent, and bring de-identified information within privacy law’s purview. However, given ERT’s problems around accuracy and its potential and actual use for nefarious purposes (e.g., public and workplace surveillance, manipulative advertising), I believe ERT-specific legislation is necessary outside of privacy regulations.
The law may regulate ERT in two ways: by regulating research and development, or by regulating the use of ERT. Synergy between the two types of regulations would of course be ideal.
The legislature may regulate research and innovation around ERT by restricting the types of data researchers can collect. An ERT law could prohibit research using, for example, sensitive information such as health information or data obtained from minors, or images obtained from social media platforms (where whether users “consent” once they post their images is contentious). Alternatively, the law could set general principles for assessing permissible data types, tending towards restricting data that is more intrusive or which has greater associated risks, and leaving the particulars for specific official regulations and guidelines on best practices. Yet, research restrictions are not enough because they cannot block foreign ERT research and the nefarious use of ERT sourced abroad (or domestic ERT, even if based on clean data).
As for regulating use of ERT, the legislature must consider the evidence and its own moral compass to decide whether ERT is beneficial or harmful when used by certain institutions and organizations and in certain contexts. The final decision may be optimistic and lead to only narrow prohibitions, as in the European Union. Article 5(1)(f) of the EU’s Artificial Intelligence Act only bans use of ERT in workplaces and educational institutions – with caveats (i.e., it permits uses for medical or safety reasons) and additional considerations (e.g., “physical states” like “pain or fatigue” – relevant for monitoring pilots and drivers – do not count as emotions). Notably, the legislation distinguishes emotion inference from “the mere detection of readily apparent expressions, gestures or movements”, and bans only the former, potentially creating problematic legal ambiguities and loopholes which the legislature should not ignore.
However, if the legislature determines that ERT’s use is generally harmful, and that privacy and other types of laws do not address these harms, it may set a general prohibition accompanied by a narrow list of exceptions. For example, it may choose to only allow ERT’s use where it is not only not harmful, but decidedly contributes to the public interest, such as for healthcare and research.
A final option may be a blanket prohibition on ERT’s sale and use. The digital rights non-profit Access Now has promoted such a ban, arguing that ERT is inherently intrusive and detrimental to rights like privacy and freedom of thought, expression, and assembly. Due to ERT’s accuracy issues, Access Now has argued that even narrow exceptions for use in sensitive fields like healthcare would be unwise, as inaccurate and biased assessments would harm the individuals they are meant to serve. This is ultimately a question of fact, which the legislature must assess based on evidence about the current state of ERT and its potential for greater accuracy through innovation. Even with a full ban on ERT, however, the legislation may still be nuanced. For example, it may carefully distinguish recognition of “physical” states from recognition of “emotional” states to allow for technology that would assist with innocuous goals like safe driving.
Whether one path for regulating ERT is better than another must ultimately follow careful analysis of ERT’s potential benefits and harms. The correct answer will depend on answering three questions. First, are ERT’s inferences unreliable – even unscientific – either currently or following further R&D projects? Second, even if the inferences are accurate, is their use inherently undesirable from the point of view of ethics, privacy, or human rights? Third, if ERT proves accurate and its use does not conflict with our values, does its use by specific institutions and organizations have beneficial or harmful consequences in specific contexts? Answering these questions in succession will allow the legislature to wisely assess options from blanket prohibition to general permission with targeted restrictions and regulations.
The opinion is the author's, and does not necessarily reflect CIPPIC's policy position.



