CCTV Privacy Law Mapper
Regimes

EU AI Act

The Act reaches CCTV through its analytics, not through recording. Art. 5 lists the practices the Act does not allow, among them emotion recognition in the workplace and in education (with an exception in Art. 5(1)(f) for medical or safety reasons, named, not quoted) and biometric categorisation inferring sensitive attributes; Art. 6 sets when a system is high-risk; Art. 26 sets what a deployer of a high-risk system does (oversight by competent people, logs kept at least six months, workers and their representatives informed where it is used in the workplace); Art. 50 asks a deployer of emotion recognition or biometric categorisation to inform the people exposed; Art. 4 asks for AI literacy for any AI system. Motion detection and line crossing are not what the Act is about.

Where it is placed
Placed for sites in the 27 EU member states, and only on analytics features that may be AI systems. Its lines on a camera are questions: whether a feature is an AI system, and whether it is high-risk under Art. 6, are for your lawyer.
Date last read
29 Sep 2026
Clauses cited
5 of 43 held
The standard itself
EU AI Act on compliance.theartofservice.com
Places
Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden

Clauses cited, and the findings that cite them

ClauseTitleFindings
EU AI Act Art. 4AI literacya coverage or analytics type
EU AI Act Art. 5The practices listed in Article 52, 3
EU AI Act Art. 6Classification rules for high-risk AI systems12
EU AI Act Art. 26Obligations of deployers of high-risk AI systems12
EU AI Act Art. 50Transparency obligations for providers and deployers of certain AI systems2, 3
EU AI Act Art. 4AI literacy

AI literacy. Providers and deployers of AI systems must take measures to ensure, to their best extent, a sufficient level of AI literacy among their own staff and any other persons who deal with the operation and use of AI systems on their behalf. The measures must be calibrated to those persons' technical knowledge, experience, education and training, to the context in which the AI systems are to be used, and to the persons or groups of persons on whom the systems are to be used. The duty attaches to every AI system regardless of its risk class.

What a reviewer asks to see: A register of the staff and contracted persons who operate or use AI systems on the organisation's behalf; Training content differentiated by role, prior technical knowledge and the deployment context; Attendance, completion and comprehension records per cohort; Evidence the literacy measures were revisited when a new AI system or a materially different use case was introduced; Material addressing the groups the system is used on, where that shapes the risks staff must be able to recognise
Where camera lists usually fall short: One generic awareness module issued to everyone regardless of role or technical starting point; Training that covers the internal AI policy but not the capabilities and limits of the systems actually in use; Contractors and outsourced operators excluded even though they operate the system on the organisation's behalf; No refresh when the system or its use case changes, so literacy reflects a version no longer running
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 5The practices listed in Article 5

Prohibited AI practices. Prohibits a defined set of AI practices, including subliminal/manipulative techniques causing significant harm, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in workplace/education, biometric categorisation inferring sensitive attributes, and real-time remote biometric identification (RBI) in publicly accessible spaces by law enforcement (subject to narrow exceptions).

What a reviewer asks to see: Pre-deployment screening against the Art.5 prohibition list; Documented assessment that the system does not fall under a prohibited category
Where camera lists usually fall short: Deploying an Art.5-prohibited practice; Treating exceptions as routine basis
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 6Classification rules for high-risk AI systems

Classification rules for high-risk AI systems. Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment, or where it falls within an Annex III use case. Where the provider concludes that an Annex III system is not high-risk because it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision patterns without replacing or influencing human assessment, or performs a preparatory task, that assessment must be documented before the system is placed on the market or put into service and produced to authorities on request. A system that performs profiling of natural persons is always high-risk and the derogation is not available to it.

What a reviewer asks to see: A classification record per AI system naming the Annex I legislation or the Annex III use case considered, and the conclusion reached; The documented Art.6(3) assessment where an Annex III system is judged not high-risk, dated before placing on the market; Evidence the profiling rule was applied, so any system profiling natural persons is classified high-risk regardless of the derogation; A trigger that re-runs classification when Annex III is amended or the intended purpose changes; Registration of the not-high-risk conclusion in the EU database as required by Art.49(2)
Where camera lists usually fall short: Classification decided once at design time and never revisited when the intended purpose broadened; The Art.6(3) derogation relied on without the documented assessment that is the condition of using it; A profiling system routed through the derogation, which the Regulation forecloses; Only Annex III considered, so a safety component falling under Annex I legislation is missed
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 26Obligations of deployers of high-risk AI systems

Obligations of deployers of high-risk AI systems. Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

What a reviewer asks to see: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable; Workforce information for workplace deployment
Where camera lists usually fall short: Deployer not following IFU; No human-oversight assignment; Logs deleted before 6 months
Source: EU AI Act, read 29 Sep 2026
EU AI Act Art. 50Transparency obligations for providers and deployers of certain AI systems

Transparency obligations for providers and deployers of certain AI systems. Providers and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interacting with AI, label synthetic content in a machine-readable format, and disclose deepfakes and AI-generated public-interest text (subject to free-expression and artistic exceptions).

What a reviewer asks to see: User-facing AI-interaction notification; Machine-readable labelling of synthetic content; Deepfake/AI-text disclosure
Where camera lists usually fall short: No disclosure that the user is interacting with AI; Synthetic content not machine-readably labelled
Source: EU AI Act, read 29 Sep 2026

See the specimen list run Map your own list