CCTV Privacy Law Mapper
Analytics

Are CCTV behaviour and emotion alerts allowed in a workplace under the EU AI Act?

Alerts on what people appear to be doing or feeling: aggression, loitering, a fall, a fight, a mood. Some of these may infer emotion and some detect movement only; the vendor documentation says which. Loitering and object alerts detect movement and presence, not emotion.

Biometric identification
no
May infer emotion
it may; some alerts of this type detect movement only, and the vendor documentation says which
May infer a sensitive characteristic
no
May be an AI system
yes
Read from words such as
aggression detection

Art. 5 of the EU AI Act lists emotion recognition in the workplace and in education among the practices the Act does not allow, with an exception in Art. 5(1)(f) for systems put in place for medical or safety reasons (named here, not quoted). A behaviour alert may or may not infer emotion: aggression and mood alerts may; loitering, fall and object alerts detect movement and presence only. The questions for your lawyer are which this alert is, and whether the exception applies.

Findings it can raise, with the list

Clauses this analytics type adds

3 clauses
EU AI Act Art. 4AI literacy

AI literacy. Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.

What a reviewer asks to see: A register of the staff and contracted persons who operate or use AI systems on the organisation's behalf; Training content differentiated by role, prior technical knowledge and the deployment context; Attendance, completion and comprehension records per cohort; Evidence the literacy measures were revisited when a new AI system or a materially different use case was introduced; Material addressing the groups the system is used on, where that shapes the risks staff must be able to recognise
Where camera lists usually fall short: One generic awareness module issued to everyone regardless of role or technical starting point; Training that covers the internal AI policy but not the capabilities and limits of the systems actually in use; Contractors and outsourced operators excluded even though they operate the system on the organisation's behalf; No refresh when the system or its use case changes, so literacy reflects a version no longer running
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 5The practices listed in Article 5

Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education, biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).

What a reviewer asks to see: Pre-deployment screening against the Art.5 prohibition list; Documented assessment that the system does not fall under a prohibited category
Where camera lists usually fall short: Deploying an Art.5-prohibited practice; Treating exceptions as routine basis
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 50Transparency obligations for providers and deployers of certain AI systems

Transparency obligations for providers and deployers of certain AI systems. Providers and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interacting with AI, label synthetic content in a machine-readable format, and disclose deepfakes and AI-generated public-interest text (subject to free-expression and artistic exceptions).

What a reviewer asks to see: User-facing AI-interaction notification; Machine-readable labelling of synthetic content; Deepfake/AI-text disclosure
Where camera lists usually fall short: No disclosure that the user is interacting with AI; Synthetic content not machine-readably labelled
Source: EU AI Act, read 29 Sep 2026

See the specimen list run Map your own list