On August 2, 2026, the core of the EU AI Act became fully enforceable. The prohibitions have applied since February 2025 and the general-purpose AI rules since August 2025 — but this is the stage that reaches into physical operations: risk management, logging, transparency, human oversight, and conformity assessment for high-risk AI systems, with penalties reaching €35 million or 7% of global turnover.
If AI analytics runs on cameras that watch people at work — your plants, warehouses, sites, or stores — this applies to you. Not eventually. Now.
Why workplace camera AI is squarely in scope
The Act regulates AI systems by the risk they pose to people, and AI used for monitoring and evaluating people in employment contexts is one of the categories that can qualify as high-risk. A PPE-detection model watching a production line, a zone-intrusion rule protecting a forklift lane, a housekeeping score derived from camera feeds — each of these is an AI system making assessments in a workplace, and each needs to be able to answer the regulator's core question: prove it works, prove it's overseen, prove it's documented.
Two practices are banned outright, with the highest fines in the Act:
- Emotion recognition in the workplace. Inferring the emotional state of employees from camera feeds is prohibited — full stop.
- Untargeted biometric scraping. Building identification databases from camera footage is prohibited.
If a vendor's roadmap includes either capability, that is no longer a feature — it is a liability.
The five obligations that matter for camera estates
Strip the legal text to what an operations or compliance leader must actually operationalize, and five requirements remain:
- Record-keeping. The system must automatically log events over its lifetime, so any decision can be traced and reconstructed.
- Human oversight. Consequential decisions need meaningful human review — an approval step, not a rubber stamp.
- Transparency. Outputs must be interpretable enough for the people acting on them to understand what happened and why.
- Technical documentation. System descriptions, model information, and conformity evidence — maintained, not assembled in a panic before an audit.
- Data governance. Operational data handled with privacy in mind, retention enforced by policy, access logged.
Notice what these five have in common: none of them can be bolted on after the fact by the compliance department. They are architectural properties. A detection-only tool that fires alerts into a dashboard has nowhere to put a decision log, an oversight workflow, or a conformity pack.
The strategic reversal
For years, compliance teams slowed camera-AI projects down. From August 2026, the reverse is true: a governed, conformity-documented platform is the fastest way to satisfy obligations that now carry eight-figure penalties.
That is the part most coverage of the Act misses. Regulation did not make camera AI harder to buy — it made ungoverned camera AI impossible to defend, and governed camera AI the easiest path to obligations you already have. Enterprises that deploy deterministic rules, sealed evidence, and continuous conformity documentation get something their auditors have never had: an answer to “prove it” that takes hours, not weeks.
What to do this quarter
Start with an inventory: which cameras have AI on them today, from which vendors, making which decisions about people? Then map your exposure — the regulations that apply depend on where you operate, and the EU is rarely the only regime in play. Saudi PDPL is actively enforced, and ASEAN data-protection laws add residency requirements of their own. Finally, put every incumbent and candidate vendor through the five obligations above and ask for the documentation, not the roadmap.
Camnitive ships a conformity pack — decision logs, human-oversight records, AI Act and PDPL documentation — with every deployment, because the platform was designed after the specification regulation set, not before it.



