EU AI Act
The Act reaches CCTV through its analytics, not through recording. Art. 5 lists the practices the Act does not allow, among them emotion recognition in the workplace and in education (with an exception in Art. 5(1)(f) for medical or safety reasons, named, not quoted) and biometric categorisation inferring sensitive attributes; Art. 6 sets when a system is high-risk; Art. 26 sets what a deployer of a high-risk system does (oversight by competent people, logs kept at least six months, workers and their representatives informed where it is used in the workplace); Art. 50 asks a deployer of emotion recognition or biometric categorisation to inform the people exposed; Art. 4 asks for AI literacy for any AI system. Motion detection and line crossing are not what the Act is about.
- Where it is placed
- Placed for sites in the 27 EU member states, and only on analytics features that may be AI systems. Its lines on a camera are questions: whether a feature is an AI system, and whether it is high-risk under Art. 6, are for your lawyer.
- Date last read
- 29 Sep 2026
- Clauses cited
- 5 of 43 held
- The standard itself
- EU AI Act on compliance.theartofservice.com
- Places
- Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden
Clauses cited, and the findings that cite them
| Clause | Title | Findings |
|---|---|---|
| EU AI Act Art. 4 | AI literacy | a coverage or analytics type |
| EU AI Act Art. 5 | The practices listed in Article 5 | 2, 3 |
| EU AI Act Art. 6 | Classification rules for high-risk AI systems | 12 |
| EU AI Act Art. 26 | Obligations of deployers of high-risk AI systems | 12 |
| EU AI Act Art. 50 | Transparency obligations for providers and deployers of certain AI systems | 2, 3 |
EU AI Act Art. 4AI literacyAI literacy. Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.
EU AI Act Art. 5The practices listed in Article 5Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education, biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).
EU AI Act Art. 6Classification rules for high-risk AI systemsClassification rules for high-risk AI systems. Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.
EU AI Act Art. 26Obligations of deployers of high-risk AI systemsObligations of deployers of high-risk AI systems. Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.
EU AI Act Art. 50Transparency obligations for providers and deployers of certain AI systemsTransparency obligations for providers and deployers of certain AI systems. Providers and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interacting with AI, label synthetic content in a machine-readable format, and disclose deepfakes and AI-generated public-interest text (subject to free-expression and artistic exceptions).