I. From Data to Control
We are entering a new era of surveillance. Beyond facial recognition or location tracking, a new class of systems – known as affective computing or emotional AI – claims to decode and even influence human emotions. These technologies analyse facial micro-expressions, tone of voice, body temperature, and heart-rate variability to infer psychological states such as fear, anger, or joy. Developed for marketing, gaming, and healthcare, they are increasingly tested in law enforcement and border control to assess risk, detect deception or hostile intent, and enable preemptive security interventions at scale.
In this piece, I argue that emotional AI challenges not only privacy and data protection but also freedom of thought – the last stronghold of the human mind. The analysis that follows wants to complement the GDPR and AI Act frameworks by situating the discussion within the broader landscape of human rights. In particular, it highlights the European Court of Human Rights (ECtHR) as one of the central pillars of Europe’s constitutional order and one of the crucial safeguards of freedom of thought in the age of AI.
While fully acknowledging the relevance of the EU Charter of Fundamental Rights (CFR) and the jurisprudence of the Court of Justice of the European Union (CJEU), due to word constraints this piece focuses exclusively on the European Court of Human Rights, where freedom of thought under Article 9 ECHR has received sustained and autonomous judicial elaboration.
II. Law’s Blind Spot
At first glance, European law appears well-equipped to regulate emotional AI. The GDPR protects “special categories” of personal data, including biometric and health-related information, while the EU Artificial Intelligence Act classifies emotion-recognition systems as high-risk technologies. The AI Act even prohibits their use in education and workplaces, acknowledging their potential for manipulation.
However, both frameworks share a structural flaw: broad exemptions for national security, defence, and to certain extent, law enforcement. Under GDPR Article 23, Member States may restrict data-protection rights whenever “necessary for the prevention, investigation, detection or prosecution of criminal offences or the safeguarding of national security”. Similarly, the AI Act excludes systems “used exclusively for military, defence, or national security purposes”.
This architecture produces a paradox: emotional AI is prohibited in ordinary contexts but permitted where its power is most intrusive. The experience of post-9/11 counter-terrorism measures shows how technologies and data practices, once justified in the name of security, tend to migrate into everyday governance. Once emotion recognition is normalised under security rationales, it risks diffusing across society as a standard technique of control.
III. Beyond Privacy
The ECtHR has largely relied on Article 8 (right to privacy) to address surveillance. In Glukhin v Russia (2023), the Court’s first judgment on facial recognition technologies, it characterised such systems as highly intrusive and incompatible with democratic values (§90).
But privacy under Article 8 is a qualified right: it can be restricted for reasons of national security or public safety – the very grounds under which emotional AI could be justified. In an age of ubiquitous technology, we – and our governments – trade fragments of our privacy every time we unlock a phone, scroll, or speak to a device. Moreover, privacy protects information about the mind, not the mind itself. Freedom of thought, by contrast, protects the capacity to think and feel free from modelling, inference, or manipulation.
Emotional AI does not merely access data – it infers and interprets the affective foundations of cognition. Privacy governs informational boundaries; emotional AI threatens mental autonomy itself. What it extracts are not facts about us but the preconditions of how we think and feel.
In this sense, emotional AI exposes a conceptual blind spot in European law: it collapses the divide between the internal and the external, the voluntary and the involuntary. The GDPR can regulate data flows, but it cannot protect the inner life from algorithmic inference. For that, we must turn to a different legal tradition, one rooted in the inviolability of thought.
IV. Protecting our Inner Life
Article 9 of the European Convention on Human Rights guarantees freedom of thought, conscience, and religion. SinceKokkinakis v Greece (1993), the Court has described this right as one of the foundations of a democratic society (§31). The distinction it draws between the forum internum (the inner realm of thought and belief) and the forum externum (its outward manifestations) is decisive. While external manifestations may be limited in the name of public order or safety, the internal realm enjoys absolute protection: no interference is ever permitted.
Yet the Court’s conception of ‘thought’ remains narrow. In İzzettin Doğan v Turkey (2016), the protection extended only to views demonstrating a “certain level of cogency, seriousness, cohesion, and importance” (§68). This threshold excludes the spontaneous, pre-reflective mental states – emotions, impulses, or fleeting intuitions – that emotional AI captures or infers.
Affective computing destabilises the very distinction on which this doctrine rests. Emotional expressions are simultaneously internal (biological) and externally measurable. An algorithm detecting ‘anger’ during a protest or ‘fear’ during an interrogation translates involuntary reactions into data points, rendering the internal externally legible. The result is an unprecedented inversion: what the law treats as internal becomes externally legible, and therefore capable of being regulated.
This distinction is foundational rather than merely personal. The forum internum represents a structural boundary that limits the epistemic reach of public power. It is the constitutional expression of a deeper idea: that democracy presupposes areas of radical inaccessibility, spaces that remain beyond the calculus of governance. To know emotions is to pre-empt deliberation; to predict intention is to curtail it.
In this sense, freedom of thought demarcates the outer edge of the larger EU constitutional order – the point at which the authority of the state and the autonomy of the individual are defined against each other. Emotional AI collapses that edge, reconstituting the subject as an object of measurement. Protecting the forum internum thus becomes a constitutional imperative.
V. From Non-Disclosure to Non-Externalization
The ECtHR has already hinted at this evolution. In Stavropoulos and Others v Greece (2020) it affirmed that Article 9 includes “the right not to be obliged to disclose one’s religion or beliefs” (§44). In Grzelak v Poland (2010) the absence of disclosure – refusing to indicate one’s faith – was held to fall within the negative aspect of freedom of thought (§88). Further, in Sinan Işık v Turkey (2010) the Court explicitly situated this right within the forum internum, elevating non-disclosure to absolute protection (§42).
While these cases concerned religious belief, the underlying rationale transcends the religious domain. What the Court protected was not a particular confession but the individual’s sovereign control over the revelation of their inner life. The same logic applies to emotional AI: individuals have not only the right not to disclose their beliefs, but the right not to have their mental or emotional states externalised through algorithmic inference.
When emotional AI decodes physiological signals into emotional categories, it performs an act of compelled manifestation – an algorithmic confession of the inner life. This forced externalisation bypasses agency and transforms the private into the public. Whether the inference is accurate is beside the point: the very act of rendering inner states legible undermines mental autonomy.
Such non-consensual externalisation should fall squarely within the forum internum and thus enjoy absolute protection. Just as compelled religious declarations were incompatible with Article 9, so too should algorithmic emotional inference be constitutionally impermissible.
VI. Reclaiming Rights
The technologies under examination here are primarily developed and deployed by private-sector actors – Affectiva, Beyond Verbal, iMotions – within commercial contexts: workplace monitoring, consumer analytics, marketing research, and healthcare screening. Yet, as with many emerging technologies, their dual-use nature and the broad national-security exemptions in both the GDPR and the AI Act create a clear pathway for migration into coercive state contexts. Once emotional AI becomes normalised in commercial applications the political resistance to its deployment by law-enforcement or intelligence agencies tends to erode.
This dynamic reveals the limits of relying solely on data-protection and risk-management instruments. The GDPR and the AI Act govern the procedural management of data and the classification of high-risk systems, but they might not fully address the substantive question of how far the state – or private actors acting on its behalf – may (un)constitutionally reach into the human mind. Their security exemptions open precisely where emotional surveillance poses the gravest threats: at the intersection of coercive power and mental autonomy.
Human-rights adjudication – particularly the ECtHR – offers an additional constitutional layer of protection that data-governance frameworks alone cannot (yet) provide. As part of Europe’s broader constitutional architecture, the Court’s case law on freedom of thought and the forum internum articulates not only individual entitlements but the structural boundaries of legitimate state knowledge. Its judgments can therefore guide the interpretation of both the GDPR and the AI Act, ensuring that European digital governance remains anchored in a human-rights-based constitutional perspective rather than in technocratic risk regulation.
This judicial function is especially vital at a time when the practical impact of the AI Act remains uncertain and when new forms of surveillance increasingly bypass privacy safeguards. Whatever definition one adopts of ‘thought’, the protection of the forum internum becomes the key constitutional principle for the technological age. As René Cassin observed during the drafting of the Universal Declaration of Human Rights, freedom of thought demands special protection precisely because “it can be attacked indirectly”. Emotional AI embodies that indirect attack – one conducted not through coercion but through technological inference.
VII. Conclusion: A Constitutional Architecture for the Digital Mind
Emotional AI transforms the relationship between power and the psyche. No longer confined to observation, it reaches into the biological and emotional strata of consciousness, predicting intentions before they are formed. The task ahead is not to replace privacy or data protection but to embed them within a broader human-rights framework capable of confronting the specific dangers of emotional surveillance. The ECtHR, through the evolving interpretation of Article 9 ECHR, is uniquely placed to articulate and enforce this framework.
Protecting the forum internum is therefore not an abstract ideal but a constitutional necessity. It affirms that certain dimensions of human experience – thoughts, emotions, pre-reflective impulses – must remain beyond the reach of algorithmic and institutional inference. As Europe moves toward implementing the AI Act, this principle should inform how regulatory authorities and courts construe its provisions. The task is clear: to protect the freedom of the mind from the reach of machines.

Alberto Rinaldi
Alberto Rinaldi is a human-rights scholar at the Faculty of Law, Lund University. His research explores the intersection of human rights and emerging technologies in the contexts of warfare, security, and democratic backsliding.
