A different question from "are they watching me"

This site's existing guide on AI monitoring at work covers observation: keyloggers, screen capture, productivity scoring, and the disclosure law around watching what an employee does. What it does not cover, because it is a distinct technology and a distinct legal question, is what happens after the observation: platforms that take that data, surveys, communications metadata, sometimes voice or video, build a predictive model of an individual employee's state, engagement, flight risk, sentiment, and then feed that prediction into an intervention designed to change how the employee feels or behaves, without the employee ever being told a model was built about them or that the intervention they received was AI-triggered.

Monitoring disclosure law asks whether you were told you were being watched. Behaviour-shaping raises a further question the law has not caught up to: were you told someone was trying to change you, and were you asked?

The technology is real, this is not speculative

Several well-known workplace platforms already sell, in their own marketing, exactly this predict-then-act capability. Microsoft Viva Glint documents an Attrition Risk Index built from engagement-survey responses, which it says flags at-risk employees with a precision of at least 80 percent; a separate Viva Insights product line then layers manager-facing productivity and wellbeing recommendations on top of the same platform. Qualtrics markets AI that predicts flight risk weeks in advance by combining HR data with survey feedback, and gives managers actionable recommendations to improve engagement and retention, including automated sentiment analysis of employees' own open-text survey comments. Visier advertises predictive attrition scoring for named individual employees, paired with an AI assistant that helps managers proactively identify and address attrition risks. Culture Amp's Retention Insights product claims to predict, for named employees, who is at risk of leaving and why, with an AI Coach generating a personalised action plan for their manager. IBM has publicly described, through its then chief executive in 2019, an internal system that predicted individual flight risk at 95 percent accuracy and prescribed actions for managers to engage the employee, reportedly saving the company hundreds of millions of dollars in retention costs.

None of this is an accusation of wrongdoing. Every claim above is the vendor's own public description of its own product. The point is narrower and more important: this is a mature, widely deployed product category, sold on the explicit premise of modelling an individual and then triggering a personalised intervention, and in none of these public descriptions is employee awareness of, or consent to, the modelling and intervention step part of the pitch.

Voice and camera-based versions of the same idea already exist too. Verint's Cogito platform, formerly a standalone vendor, acquired in 2024, analyses call-centre agents' tone of voice and speech patterns in real time to trigger live coaching prompts, and is reportedly used with thousands of concurrent agents. On the more cautionary side, HireVue, the video-interview company, built and then in January 2021 discontinued a facial-expression-scoring feature for job candidates, after its own internal review found facial data contributed less than 0.25 percent to the predictive value of its hiring scores and a complaint had been lodged with the US FTC over the practice. That withdrawal is itself a useful data point: even a company selling this kind of tool decided the specific technique was not defensible once scrutinised.

Where the law actually draws a manipulation line, and where it does not yet

Two separate provisions of the EU AI Act are relevant, and confusing them overstates or understates the risk, so it is worth being precise about which applies to what.

Article 5(1)(f) already bans emotion recognition in the workplace outright, full stop, with a narrow carve-out for medical or safety uses. Its exact wording prohibits AI used "to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons." This has applied since 2 February 2025. If a workplace platform is inferring how an employee feels from voice tone, facial expression, or sentiment-scored language, in the EU that is not a disclosure problem to fix, it is a use that is not permitted at all, bar the narrow exception.

Article 5(1)(a) is broader and applies generally, not only to protected groups. It prohibits AI that deploys subliminal techniques beyond a person's consciousness, or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting behaviour by appreciably impairing a person's ability to make an informed decision, causing them to take a decision they would not otherwise have taken, where that causes or is reasonably likely to cause significant harm. This is the manipulation ban, and unlike the neighbouring Article 5(1)(b), which only covers exploiting vulnerabilities tied to age, disability, or economic situation, 5(1)(a) is not limited to vulnerable groups. It is also, deliberately, a high bar: it requires purposeful manipulation or a subliminal technique, and it requires the effect to rise to significant harm. A retention platform that surfaces a survey-driven insight to a manager, who then has a genuine, disclosed conversation with an employee, does not obviously meet that bar. A system engineered to trigger interventions timed and personalised specifically to bypass an employee's conscious evaluation of whether they are being managed arguably moves toward it. Where any given real-world tool sits on that line is a case-by-case legal judgment, but the provision exists, and organisations building or buying these tools should be testing their design against it deliberately.

GDPR Article 22 is the other obvious candidate, and it is worth being honest about its limits too: it applies to a decision based solely on automated processing that produces legal effects or similarly significantly affects a person. Most retention-prediction tools above are designed as manager-facing recommendations, not fully automated actions, which likely puts them just outside Article 22's core trigger. That is a real gap, not a technicality: a system can be built specifically to influence someone's working life through a human intermediary and still fall outside the one GDPR provision written for automated decisions about people.

The academic term for this already exists

Legal and labour scholars got here before regulators did. Data and Society's foundational definition of "algorithmic management" explicitly names "the use of 'nudges' and penalties to indirectly incentivize worker behaviors" as a defining feature of the category, not an edge case. Ifeoma Ajunwa's The Quantified Worker documents how far AI-driven workplace quantification has already outpaced the law built to constrain it. The precise term for what a predict-then-nudge platform does is "hypernudge," coined by legal scholar Karen Yeung in a widely cited 2017 paper: AI-personalised, continuously updated behavioural steering built on big data, which she argues escapes the protections built for old-fashioned, one-size-fits-all nudges precisely because it is invisible, individualised, and constantly adapting.

What disclosure and consent should look like, in practice

Given the law does not yet spell this out cleanly, here is what a defensible practice looks like, built from the adjacent rules that do exist.

  • Tell employees specifically if a predictive model is being built about them individually, not a generic "we use analytics" line buried in a privacy policy, but a plain statement that engagement surveys, communication metadata, or other signals are used to generate an individual risk or sentiment score.
  • Tell them when that score triggers an action directed at them, a manager check-in, a targeted benefit offer, a change in project allocation, even if the action itself looks like ordinary good management.
  • Never infer emotion from biometric signals in the EU; it is prohibited outright, not a disclosure question.
  • Get a genuine opt-in for anything that uses camera or voice analysis, even where a jurisdiction might technically permit it with disclosure alone.
  • Give employees a way to see and contest the model's output about them, mirroring the GDPR Article 15 access right.

The honest bottom line

We did not find a single confirmed case of a company being found, by a regulator or a court, to have covertly used predictive AI to manipulate its employees specifically through retention or engagement nudging. The closest real precedent sits one step over, in gig-economy work rather than direct employment: Italy's data protection authority, the Garante, fined Deliveroo roughly 2.9 million euros and Foodinho and Glovo roughly 2.6 million euros in 2021 over opaque algorithmic-management systems that used automated scoring, ranking, and penalties to shape rider behaviour without adequate transparency. It is not the same pattern, task allocation and rating algorithms for platform workers, not sentiment-driven retention nudges for employees, but it shows a regulator has already been willing to act on nudges and penalties shaping worker behaviour as a category when the opacity was bad enough. What exists today is a mature commercial product category built, transparently, on modelling individual employees and triggering personalised interventions, a well-established academic vocabulary for exactly this pattern, a general EU manipulation prohibition broad enough to reach it in principle, and a genuine, still-open gap where the specific disclosure rule for this pattern has not yet been written by any regulator for direct employment. That combination is precisely the moment governance guidance is most useful, before the first enforcement case defines the rule for everyone after the fact.