CCTV Privacy Law Mapper
Finding 12 of 18

High-risk AI use in an EU workplace

If this system is high-risk under Art. 6, Art. 26 of the EU AI Act asks the deployer to assign human oversight to competent named people, keep its logs for at least six months, and inform workers and their representatives where it is used in the workplace. In Germany the works council's say on devices that monitor employees is named, not quoted.

When it is raised
Raised on a face matching camera at an EU site where staff are present (or the coverage could not be read).
The question
If this system is high-risk under Art. 6: who are the named people overseeing it, are its logs kept at least six months, and were workers and their representatives informed?
For
your lawyer
The column that settles it
the analytics or coverage column
On the row
a numbered delta and the words "if high-risk" in small capitals; an outlined delta where it rests on a blank column

Clauses by regime

EU AI Act

EU AI Act Art. 26Obligations of deployers of high-risk AI systems

Obligations of deployers of high-risk AI systems. Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

What a reviewer asks to see: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable; Workforce information for workplace deployment
Where camera lists usually fall short: Deployer not following IFU; No human-oversight assignment; Logs deleted before 6 months
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 6Classification rules for high-risk AI systems

Classification rules for high-risk AI systems. Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.

What a reviewer asks to see: A classification record per AI system naming the Annex I legislation or the Annex III use case considered, and the conclusion reached; The documented Art.6(3) assessment where an Annex III system is judged not high-risk, dated before placing on the market; Evidence the profiling rule was applied, so any system profiling natural persons is classified high-risk regardless of the derogation; A trigger that re-runs classification when Annex III is amended or the intended purpose changes; Registration of the not-high-risk conclusion in the EU database as required by Art.49(2)
Where camera lists usually fall short: Classification decided once at design time and never revisited when the intended purpose broadened; The Art.6(3) derogation relied on without the documented assessment that is the condition of using it; A profiling system routed through the derogation, which the Regulation forecloses; Only Annex III considered, so a safety component falling under Annex I legislation is missed
Source: EU AI Act, read 29 Sep 2026

Named, not quoted

See the specimen list run Map your own list