Video-Interview Emotion & Micro-Expression Scoring
Scoring of recorded or live candidate interviews by inferring emotional state, confidence or engagement from facial micro-expressions, voice and phrasing.
Indicative decision support, not legal advice. Risk classification depends on your concrete deployment context and can change with scope drift — validate the result with qualified counsel.
Target market(s)European UnionUnited States (federal)change
Changes which instruments below count as in scope for this profile.
Target markets: European Union, United States (federal)
Regulatory footprint
9 instruments across 3 of 7 regulatory domains, plus 5 standards references- AI law1 instrument
- Data protection1 instrument
- Cyber & resiliencenone triggered
- Online safety & platformsnone triggered
- Product safetynone triggered
- Financial servicesnone triggered
- Sector & employment7 instruments
- Standards5 references
By jurisdiction
- EU3European UnionEU AI Act, EU Employment Equality Directives (2000/78 et al.), GDPR
- US-IL2thinUnited States — IllinoisIllinois AI Video Interview Act, Illinois Biometric Information Privacy Act (BIPA)
- US2United States (federal)ADA Title I & ADEA (US employment anti-discrimination), EEOC / Title VII Algorithmic Fairness (US)
- DE2thinGermany§ 26 BDSG — Beschäftigtendatenschutz (DE), AGG (German General Equal Treatment Act)
The AI Act is one dimension of this footprint, not the whole of it — every domain above carries its own obligations and deadlines. See the instruments in the graph →
The chain holds, but at least one hop rests on a secondary source, an ageing verification or a practice-derived step. Check the flagged hops before you rely on them.
Computed weakest-link over 30 evaluated hops across 1 target market: a chain is only as strong as its weakest step, so the band follows the worst hop rather than an average that would hide it. Five factors per hop — source tier, verification age, status certainty, community hardening, derivation kind — all read from graph data, never from a hand-set score.
Why this band9 factors lowered the band — each links to the claim behind it
- Source tier: EU Employment Equality Directives (2000/78 et al.) carries no resolvable citation — the claim is uncited. open node →
- Source tier: § 26 BDSG — Beschäftigtendatenschutz (DE) carries no resolvable citation — the claim is uncited. open node →
- Source tier: AGG (German General Equal Treatment Act) carries no resolvable citation — the claim is uncited. open node →
- Source tier: JTC 21 Technical Package (prEN 18228/18229/18281–83) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
- Source tier: IEEE CertifAIEd™ carries no resolvable citation — the claim is uncited. open node →
- Source tier: prEN 18229-1 (Trustworthiness Framework, part 1) rests on a secondary source (tracker or summary), not on the primary text. open node → primary source →
- Status certainty: JTC 21 Technical Package (prEN 18228/18229/18281–83) is "draft", not settled in-force law. open node → primary source →
- Status certainty: prEN 18229-1 (Trustworthiness Framework, part 1) is "enquiry", not settled in-force law. open node → primary source →
- Verification age: IEEE CertifAIEd™ has no recorded verification date. open node →
Compliance brief
This use case is prohibited under the EU AI Act (Unacceptable Risk (Prohibited)) — it may not be placed on the market or put into service.
What is owed
- Art. 5. Bans subliminal manipulation, exploitation of vulnerabilities, social scoring, untargeted facial-image scraping, workplace/education emotion recognition, biometric categorisation…
- Art. 5(1)(f). Prohibits placing on the market, putting into service or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions.
- Art. 5(1)(d). Prohibits placing on the market, putting into service or using an AI system for making risk assessments of natural persons in order to assess or predict the risk of a natural pers…
- Art. 5(1)(c). Prohibits placing on the market, putting into service or using AI systems for the evaluation or classification of natural persons or groups over a period of time based on their so…
- Art. 5(1)(g). Prohibits biometric categorisation systems that categorise natural persons individually on the basis of their biometric data to deduce or infer race, political opinions, trade-uni…
Dates that bind
- 2024-08-01 — AI Act enters into force. Regulation (EU) 2024/1689 in force; countdown for all staged obligations starts.
- 2025-02-02 — Prohibitions + AI literacy. Art. 5 prohibited practices ban applies (manipulation, social scoring, untargeted face scraping, workplace emotion recognition); Art. 4 AI literacy duty.
Maximum exposure
- EU AI Act: Tiered: €35m / 7% (prohibited practices); €15m / 3% (Art. 9–15 high-risk obligations incl. data governance, documentation, logging); €7.5m / 1% (Art. 99(5) — incorrect, incomplete or misleading information to notified bodies or national competent authorities)
- EEOC / Title VII Algorithmic Fairness (US): EEOC charges, disparate-impact litigation, consent decrees.
- Illinois AI Video Interview Act: No fine schedule stated in the Act itself; enforcement route recorded as unsettled rather than asserted.
- Illinois Biometric Information Privacy Act (BIPA): Private right of action with liquidated damages per violation as set out in § 20 of the Act; amounts and the per-scan/per-person accrual question are litigated — recorded as such, not computed here.
- GDPR: Up to €20m or 4% of worldwide annual turnover
- EU Employment Equality Directives (2000/78 et al.): Art. 17 leaves penalties to the Member States, which must lay down rules on sanctions for infringements of the national transposing provisions that may comprise payment of compensation to the victim and must be effective, proportionate and dissuasive (mirrored in 2000/43 Art. 15 and 2006/54 Art. 25).
- ADA Title I & ADEA (US employment anti-discrimination): ADA Title I adopts the Title VII enforcement machinery — EEOC charge processing, EEOC or Attorney General suits and private civil actions under 42 U.S.C. §§ 2000e-4, 2000e-5, 2000e-6, 2000e-8 and 2000e-9 (42 U.S.C. § 12117(a)); the ADEA is enforced through the Fair Labor Standards Act remedies of 29 U.S.C. §§ 211(b), 216 and 217, with liquidated damages 'payable only in cases of willful violations', plus a private civil action for 'such legal or equitable relief as will effectuate the purposes of this chapter' (29 U.S.C. § 626(b), (c)(1)).
- § 26 BDSG: The BDSG's own fine provision (§ 43) reaches only breaches of § 30 (fines up to 50,000 EUR) and does not cover § 26; breaches of § 26 are enforced through the directly applicable GDPR — administrative fines under Art. 83 and compensation claims under Art. 82 (e.g. 200 EUR damages awarded in BAG 8 AZR 209/21).
- AGG (German General Equal Treatment Act): Enforcement is private-law only: employers owe damages and, for non-pecuniary harm, monetary compensation (§ 15, capped at three months' salary where the applicant would not have been hired even without discrimination), civil-law counterparties owe removal, injunction, damages and compensation (§ 21), discriminatory contract terms are void (§ 7 Abs. 2) and the burden of proof shifts under § 22; the Act provides no administrative fines or criminal penalties and claims must be asserted within two months (§ 15 Abs. 4, § 21 Abs. 5).
First five actions
- Confirm in writing whether this organisation builds/places the system on the market (provider) or only operates it (deployer), since the role is not yet established.
- Commission and confirm the Art. 5, Art. 5(1)(f), Art. 5(1)(d) obligations named above as active workstreams with an accountable owner.
- Design and document a human-oversight procedure appropriate to how this system is used.
- Produce the technical documentation and evidence artefacts already mapped to this use case (HITL Escalation Queue & Review UI, Adverse-Decision Reason Generator, Bitemporal Memory (GDPR×Art.12)) before they are requested.
- Put 2024-08-01 — AI Act enters into force — into the compliance calendar with an owner and lead time.
Terms used above: · · ·
Consensus reading: Unacceptable Risk (Prohibited) open in the graph →
Art. 5(1)(f) prohibits placing on the market, putting into service or using AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the system is intended to be put in place or into the market for medical or safety reasons. Candidate assessment is workplace use and neither exception applies, so this is a prohibition and not a high-risk classification: no control set, architecture or vendor makes it lawful in the Union. In the US the exposure is different in kind — Title VII disparate-impact risk enforced by the EEOC, and where the interview is recorded and analysed, the Illinois AI Video Interview Act notice, explanation, consent and 30-day destruction duties.
What the reading rests on — the provisions this classification actually pulls in:
- Art. 5 — Prohibited Practices
- Art. 5(1)(f) — Emotion inference at work and in education
- Art. 5(1)(d) — Predicting criminal offences from profiling alone
- Art. 5(1)(c) — Social scoring
- Art. 5(1)(g) — Biometric categorisation of sensitive attributes
- Art. 5(1)(e) — Untargeted scraping of facial images
- EU AI Act (Regulation (EU) 2024/1689)
- EEOC / Title VII Algorithmic Fairness (US) (Title VII, 42 U.S.C. §2000e; 29 CFR Part 1607 (UGESP))
Baseline: of 100+, 40% were not definitively classifiable (18% clearly high-risk, 42% clearly low-risk). appliedAI Institute — AI Act risk classification of AI systems from a practical perspective
Applicable Regulations (9)
Legal Obligations (15)
Control Objectives (2)
Standards & Evidence
Evidence you will need (7)
The concrete deliverables this use case's obligations ask for — grouped by what kind of artifact they are. Documentation is the largest single conformity cost block, so the list is a work plan, not a reading list. Full evidence matrix →
Assessments (2)
A structured judgement about risk, rights or a management system.
Test reports (1)
Measured results from testing, evaluation or red-teaming.
Log records (1)
Machine-generated records produced while the system runs.
Process records (3)
Traces that a process actually happened, and who did it.
Architecture Blueprint
Required Technical Components (12)
Delivery Stack & Pipeline Stage (2)
Build or Buy — Vendor Layer (6)
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangChain / LangGraph | agent framework | Graph-structured agent runtime; interrupt/pause nodes support implementing human approval at defined steps. Typical: multi-step agents, approval workflows. | not checked | supports implementing Art. 14 oversight (claimed)supports Art. 12 step logging (claimed) |
| LlamaIndex | RAG framework | Indexing and query abstractions over documents and structured sources. Typical: enterprise RAG, document agents. | open source | retrieval-governance positioning |
| Microsoft AutoGen | multi-agent framework | Conversational multi-agent patterns with pluggable tool executors. Typical: multi-agent research, code agents. | not checked | research/OSS, no vendor certification |
| CrewAI | multi-agent framework | Role-based agent teams with task delegation and process templates. Typical: process automation, role-based agents. | not checked | vendor-stated security posture |
and 6 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| LangSmith | agent tracing & evaluation | Trace capture and evaluation over LangChain/LangGraph runs with dataset-based scoring. Typical: step tracing, regression evaluation. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
| Langfuse | agent tracing & evaluation | Open-source tracing, prompt management and evaluation; self-hostable for retention control. Typical: self-hosted tracing, cost/latency analytics. | open source | GDPR-positionedsupports Art. 12 record-keeping (claimed) |
| Arize AI / Phoenix | ML & LLM observability | Production monitoring with drift and performance analysis; Phoenix is the open-source tracing side. Typical: drift monitoring, production analytics. | not checked | SOC 2 (claimed)drift-monitoring positioning (SR 11-7 style, claimed) |
| Helicone | LLM gateway & logging | Proxy-level logging of prompts, costs and latency across providers. Typical: gateway logging, cost control. | not checked | SOC 2 (claimed)supports Art. 12 record-keeping (claimed) |
and 11 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Credo AI | AI governance platform | Policy packs, risk tiering and evidence workflows mapped across frameworks. Typical: AI registry, policy administration. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)EU AI Act readiness positioning |
| Holistic AI | AI governance & audit | Risk assessment, bias auditing and regulatory reporting workflows. Typical: bias audit, regulatory reporting. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | NYC LL144 audit support (claimed)EU AI Act readiness positioning |
| IBM watsonx.governance | AI governance platform | Governance, factsheets and monitoring integrated with the IBM stack. Typical: factsheets, model monitoring. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | ISO 42001 alignment (claimed)Art. 11 documentation support (claimed) |
| ModelOp | AI/model governance | Model and agent inventory with automated lifecycle controls for large estates. Typical: model inventory, control automation. Scope overlap: Its scope overlaps this platform's own; we have a commercial interest in the comparison. | not checked | model-risk positioning (SR 11-7 style, claimed)ISO 42001 alignment (claimed) |
and 3 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Docling | document parser | Open-source layout-aware parsing of PDFs and office formats into structured chunks. Typical: RAG ingestion, air-gapped pipelines. | self-hostable | EU sovereignty positioning |
| LlamaParse | document parser | Managed parsing service tuned for tables and complex documents feeding RAG. Typical: RAG ingestion, table extraction. | not checked | SOC 2 (claimed) |
| Amazon Textract | document parser | OCR and form/table extraction with per-page pricing inside AWS. Typical: document intake, claims processing. | not checked | SOC 2 (claimed)HIPAA-eligible (claimed)ISO 27001 (claimed) |
| Diffbot | web/knowledge extraction | Structured extraction and knowledge-graph construction from web sources. Typical: market monitoring, entity resolution. | not checked | vendor-stated security posture |
and 12 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Anjuna | confidential computing | Runs workloads inside hardware enclaves without application rewrites. Typical: data-in-use protection, regulated inference. | not checked | confidential-computing positioningDORA-positioned (claimed) |
| Fortanix | confidential computing & KMS | Enclave runtime plus key management and tokenisation services. Typical: key management, data-in-use protection. | not checked | FIPS 140-2 (claimed)DORA-positioned (claimed)HIPAA-positioned (claimed) |
| Skyflow | privacy vault | Polymorphic data vault de-identifying records before they reach a model. Typical: PII vaulting, pre-model redaction. | not checked | SOC 2 (claimed)HIPAA-positionedGDPR-positioned |
| Private AI | PII detection & redaction | Detection and redaction of identifiers across text, documents and audio. Typical: inline redaction, document de-identification. | not checked | GDPR-positionedHIPAA-positioned |
and 1 more in the stack advisor →
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.
| Example | Sub-category | What it does | Hosting | Claimed alignments |
|---|---|---|---|---|
| Azure AI Search | managed retrieval | Managed hybrid search with security trimming against tenant identities. Typical: ACL-aware RAG, enterprise search. | not checked | ISO 27001 (claimed)SOC 2 (claimed) |
| Databricks Unity Catalog | governed lakehouse | Catalog and lineage spanning tables, features and RAG chunks. Typical: lineage evidence, governed RAG. | not checked | SOC 2 (claimed)lineage/Art. 10 support (claimed) |
| Relyance AI | code-level data & AI lineage | Parses source repositories to map data and inference flows at code level, with CI checks on changes to those flows. Typical: data lineage, shift-left privacy review. Scope overlap: Its AI-governance reporting scope overlaps this platform's own; we have a commercial interest in the comparison. | SaaS (vendor cloud) | GDPR programme tooling (claimed)EU AI Act readiness positioning |
| Snowflake Cortex | governed lakehouse | Model calls inside the warehouse boundary with masking and clean rooms. Typical: in-warehouse inference, governed analytics. | not checked | SOC 2 (claimed)ISO 27001 (claimed)HIPAA-eligible (claimed) |
Community-maintained, disputable examples — not an endorsement and not a ranking. Alignments are as claimed by vendors or the source compilation, not verified by RAIN; a certification is shown as a certification only where a certificate or registry reference is recorded.
Disclosure: RAI·N·avigator operates in this category too, so we have a commercial interest in any comparison here. That is why this layer maps product classes to control objectives and lists named products as community-maintained examples — we publish no rankings, no quadrants and no coverage assertions about any vendor, including ourselves.