You probably rehearse your face.
Not for a camera crew (there is no camera crew). For the little rectangle in the corner of the screen, the one showing you what you look like to eleven other people in a meeting. You adjust your eyebrows before the call starts the way you'd straighten a collar. Interested, but not eager. Engaged, but not intense. It is faintly absurd, and almost everyone does it.
For most of the last decade that was just vanity with a webcam attached. What changed is that something on the other side of the glass started keeping score.
That is why a short, unglamorous California bill deserves your attention. Gavin Newsom signed it on September 30, 2026. It writes a flat prohibition on workplace emotion-reading into the Labor Code. And it charges employers up to five hundred dollars a pop to ignore it.
What the bill says, in two sentences
Assembly Bill 1883 runs to a few pages, and the heart of it is two sentences of operative text:
"An employer shall not use a workplace surveillance tool that uses artificial intelligence on employees for either of the following: (1) Recognizing, or making inferences or predictions about, an individual's emotional state. (2) Collecting neural data."
That is it. Two prohibited uses, written flatly, with none of the notice-and-consent scaffolding that usually softens this kind of law into paperwork. There is no "unless the employee agrees." It says shall not.
The scope around those two sentences is deliberately wide. A "workplace surveillance tool" is any system or device collecting employee data, activities, communications, biometrics, or behaviors "by means other than direct observation by a person" — which covers your laptop camera, your headset, your badge reader, and the analytics layer bolted onto your chat app. "Employer" includes the state, the University of California, charter cities, and labor contractors. There is a carve-out for tools used "to ensure safety," and another for aircraft and defense work. Everything else is in.
So far, so good. This is a serious prohibition, drafted by Assemblymember Isaac Bryan, and the Legislature heard the case for it in detail. The Assembly's own privacy committee was told that emotion recognition uses biometric data — facial expression, heart rate, skin conductance, tone of voice — to infer an emotional state, and that one vendor's tool had been used on call center workers at MetLife and Humana to make sure each worker delivered a happy and receptive tone to customers. The same analysis described neural recognition hardware as purported to capture brain activity to supposedly identify when a worker is concentrating, tired, or stressed.
Now here is where things get interesting.
The number
An employer who breaks this rule "may be subject to a penalty of up to five hundred dollars ($500) for each violation." HR Dive, covering the bill's passage, summarized it as a per-violation penalty of $500.
Five hundred dollars. Up to.
To be fair (the lazy version of this argument is wrong), that is not the only consequence in the bill. The same section lets a petitioner seek injunctive relief, punitive damages, and reasonable attorney's fees. An injunction is the part a general counsel actually fears, because it turns off the product. And the Legislative Counsel's Digest says the bill "would authorize the Labor Commissioner or a public prosecutor to enforce" it, which means a state enforcer with subpoena power, not just a worker with a grievance.
So what does the headline number signal? A legislature that wants a number to bite writes it like Illinois did, where the biometric privacy statute puts $1,000 and $5,000 per violation on the table along with attorney's fees, recoverable by any person aggrieved. California wrote $500 and routed enforcement primarily through a state agency. Different drafting choices communicate different levels of seriousness to the people writing compliance memos.
The word doing the quiet work: "measuring"
What have almost all the summaries missed? The two prongs are not symmetrical.
Prong one — emotional state — is broad. It reaches "Recognizing, or making inferences or predictions about," how you feel. Inference is squarely covered. If a tool watches your face and guesses you're frustrated, that is the prohibited act.
Prong two — neural data — is narrow, and it is narrow on purpose. The bill defines neural data as information "generated by measuring the activity of an employee's central or peripheral nervous system, and that is not inferred from nonneural information."
Everything turns on that trailing clause. An electrode on your scalp is neural data. Your keystroke cadence is not — even if a vendor markets it as a window into your cognitive load. A webcam estimating your fatigue from blink rate is not, because it never measured your nervous system; it inferred something about your nervous system from pixels.
That distinction is technically correct and it is good drafting. It is also slippery enough that summaries of the bill routinely fold facial expressions and voice characteristics into "neural data" — which is precisely what the statutory definition excludes. If the people paid to read this carefully collapse the two prongs, the HR manager evaluating a procurement deck next March will collapse them too, in whichever direction is convenient.
The practical upshot: an employer who wants the insight without the exposure doesn't need a loophole in prong two. They need a product that never uses the word "emotion" in prong one. Call the output "engagement." Call it "vocal energy." Call it a "coaching signal." The statute bans recognizing an emotional state; it does not ban building a number that correlates with one and declining to name it.
So that settles it — California fixed this. Right?
Not quite, and the strongest objections are not the ones you'd expect.
Objection one: the bill got smaller on its way through. The version the Assembly privacy committee debated in April was much broader — it also barred tools that identified workers engaging in protected activity and tools that inferred protected characteristics. A business coalition including TechNet and the California Grocers Association pushed back, arguing that "a security camera is going to capture whatever footage it captures, which could qualify as 'identifying' someone under this language." Those clauses are gone now. The objection was aimed at a draft that no longer exists — which means the coalition largely won, and what reached the Governor is already the compromise.
Objection two: maybe the target is wrong. The Information Technology and Innovation Foundation argues that facial recognition has become "the villain of choice in the workplace surveillance debate," and that policymakers should "regulate what employers do with workplace data, not which device collects it." That is a genuinely good argument. A rule keyed to technique invites relabeling; a rule keyed to consequence — you may not discipline, fire, or rank someone on this basis — survives the next product cycle. I think ITIF underrates the harm that lands before any decision gets made. But technique-based bans do age badly.
Objection three — uncomfortable for everyone — the technology may not work. A 2019 review in Psychological Science in the Public Interest by Barrett, Adolphs, Marsella, Martinez and Pollak found that "a given configuration of facial movements, such as a scowl, often communicates something other than an emotional state," and that there is substantial variation in how people express the basic emotions across cultures, situations, and even within one situation. If the readings are noise, is a ban the right instrument, or is it consumer protection against a bad product?
My answer is that it is both, and that the noise is the harm. A tool that misreads you is not harmless; it is a tool that misreads you and then writes it down.
Cross the Atlantic, and this argument ended in February 2025
The European Union did not debate whether emotion inference at work is a disclosure problem. It made it a red line.
Article 5(1)(f) of the EU AI Act prohibits placing on the market, putting into service, or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions, with one exception — where the system is intended for medical or safety reasons. The text carries that single exception, and consent is not it. The prohibited-practices chapter has been binding since February 2, 2025, and the Commission published guidance on the prohibited practices two days later, on February 4, 2025.
Then there is the price. Breaching an Article 5 prohibition exposes a company to administrative fines of up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 % of its total worldwide annual turnover for the preceding financial year — whichever is higher. (Two precisions that get lost in headlines: that penalty chapter became applicable on August 2, 2025, six months after the prohibition itself. And SMEs — small and medium-sized enterprises, start-ups included — get the lower of the two figures, not the higher.)
Hold the two ceilings next to each other. Five hundred dollars per violation. Versus 35 million euros or seven percent of global revenue, whichever is higher. Same conduct, same year, priced tens of thousands of times apart.
And the EU wrote down why. Recital 44 states that there are "serious concerns about the scientific basis" of systems that identify or infer emotions, "particularly as expression of emotions vary considerably across cultures and situations, and even within a single individual," listing "the limited reliability, the lack of specificity and the limited generalisability" as key shortcomings. That is the Barrett review's own three-part critique, lifted into binding European law. The exemption is correspondingly tight: the prohibition "should not cover AI systems placed on the market strictly for medical or safety reasons, such as systems intended for therapeutical use."
Europe's version is not unlimited, and I won't pretend otherwise. The Future of Privacy Forum reads the prohibition as tied to inferences drawn from biometric data, which leaves plain text-sentiment analysis outside it, and notes that the ban covers the inference of emotions but not of intentions. Fine. A prohibition with gaps and a 7% ceiling is still a different species from a prohibition with a $500 ceiling.
Now picture January 2029
Newsom signed it. January 1, 2027 arrives, the prohibition switches on, and California becomes the place where your boss may not read your feelings. Two years later, what does an ordinary workday look like?
Your headset greets you at 7:04 a.m. Burger King has already introduced an AI voice named "Patty," powered by an OpenAI base model, which NBC News reported in February 2026 would live inside employees' headsets to collect data on "friendliness". That part is not speculation. By 2029 the version on your head does not claim to detect emotion. It produces a "hospitality index." No one wrote the word emotion anywhere in the documentation.
Your 10 a.m. video call runs a tool descended from the ones already here — apps that analyze meeting participants' emotions in real time, Zoom extension included. The 2029 build reports "participation quality." Your chair reports posture, which is a proxy for restlessness, which is a proxy for exactly the thing the statute forbids naming.
None of this is neural data. Nothing measured your nervous system. Everything inferred it.
And here is the twist: the compliance-safe version might be worse. A tool that says "this worker seems anxious" can at least be argued with. A tool that says "hospitality index: 71, tenth percentile" has laundered the same guess into a number that looks like a fact — and numbers that look like facts are what go into performance reviews. Emine Akar, a research fellow at the Institute for the Future of Work, warned that the danger is not only that machines fail to understand us; it is that "they may begin to discipline us", "nudging our expressions, altering our behaviour, and shaping our emotional lives in invisible ways."
We would all get very good at rehearsing our faces. Which brings us back to that rectangle in the corner of the screen — except it would not be vanity anymore. It would be labor.
What the people who study this think
The striking thing about this debate is how little of it is partisan.
The scientists are skeptical the readings mean anything, per the Barrett review. The public is not conflicted: Pew Research Center found Americans oppose using face recognition to analyze employees' facial expressions by 70% to 9% — a margin you almost never see in American polling. (That survey ran in December 2022 and is about face recognition specifically, so scope it accordingly.)
On the civil-liberties side, a coalition including Access Now, European Digital Rights, ARTICLE 19 and Bits of Freedom pressed Brussels for a prohibition rather than a disclosure regime — and the line they leaned on is not their own. It comes from a study commissioned by the European Parliament's own AIDA committee, whose authors wrote that emotion recognition systems "may have highly undesired discriminatory and dignity consequences, manipulative effects, and risk impact," and that "general prohibition might be an option to consider." Measured, as advocacy rarely is — and more persuasive for it.
On the market side, ITIF's objection is about instrument design, not about whether workers deserve protection. Almost nobody is publicly defending the proposition that your employer should own your interior life; the argument is about which lever to pull. Meanwhile the legislatures keep pulling them — states considered 155 bills addressing AI in the workplace in the 2026 session alone. This is not a fringe concern working its way up. It is a flood looking for a channel.
What does this mean for you?
Concretely, whether or not you live in California:
Read your monitoring disclosure, then read the vendor's marketing page. The disclosure says "productivity analytics." The vendor's site is where the words "sentiment," "engagement scoring," and "tone analysis" live. The gap between those two documents is the story.
Ask one question in writing: Does any tool used on me produce a score that reflects my mood, tone, or emotional state? Written questions create records. Records are what enforcement runs on.
Watch for renamed metrics. "Hospitality index," "vocal energy," "participation quality," "wellness score." If a number goes up when you sound cheerful, it is an emotion score wearing a different hat.
Know the two prongs. If your employer uses an actual brain-signal device — a headband, an earbud with EEG — that is neural data, and it is the clearest violation on the page. If they use a camera or a microphone, you are in prong one, which is broader but easier to argue about.
If you are in the EU or work for a company that operates there, your floor is higher. The Article 5(1)(f) prohibition binds the employer, not just the vendor, and it has been in force since February 2025.
If you are in California, weigh in on the cleanup. The Governor has asked the Legislature to refine this law. Tell your Assemblymember and state senator to fix the renamed-metric gap and the $500 ceiling, too.
The lesson, as I see it
There is one more detail worth knowing, and it is the most telling part of the story.
Newsom did not have to sign this bill. The Legislature passed it before September 1 and handed it over after, and the California Constitution says a bill in that posture that is not returned on or before September 30 of that year becomes a statute. Doing nothing would have enacted it. He signed it on the last day, with a letter attached.
Signing was a choice, from a Governor actively working the AI file — one who signed an AI disclosure bill on September 16, 2026 and two days later announced he was directing state agencies to develop artificial intelligence safety recommendations. He has vetoed worker-AI bills before for being unfocused. So what did he want fixed?
The definitions. His letter asks the Legislature to refine the law and names the problem: "Assembly Bill 1883 lacks key definitions, which may create confusion about which tools are covered." The fix he describes cuts both ways: protecting workers "without preventing the deployment of beneficial tools used for security or other legitimate purposes." A cleanup could shorten the list of covered tools as easily as lengthen it.
Which tools are covered. Not what it costs to use one anyway — the letter never mentions the penalty. (Fair enough: the "measuring" clause shows how much hangs on one definition.)
So the prohibition takes effect on January 1, 2027 with a price tag a mid-sized employer could absorb as a line item. That is not a failure. A ban with a weak penalty is still a ban — and most of what states have actually enacted here is a notice requirement, not a prohibition. Drawing the line is the hard part; legislatures amend numbers all the time, and the Governor has invited an amendment.
But I would rather we were honest about what we bought. California has declared that your inner life is not a workplace input — a genuinely radical thing for a government to say — and then set the cost of ignoring that declaration at roughly the price of a decent office chair.
My vote? Do the cleanup the Governor asked for — and while the Legislature is in there, fix the number. Principles are worth stating even when they are underpriced. Just don't mistake the statement for the enforcement — and don't stop rehearsing that question you are going to put in writing.
If your workplace already runs one of these tools and you've never been told, that is exactly the kind of thing worth forwarding to the person sitting next to you — and to the one who signs off on the software budget. Pass this along; the HAIA Foundation is here so that these arguments happen before the procurement, not after.





