Feb 2, 2025 · in force
Prohibitions in force
Banned practices apply — including emotion recognition in the workplace. Fines for prohibited practices reach €35M or 7% of global turnover.
From August 2, 2026, high-risk AI obligations are fully enforceable — and AI systems that monitor people at work can qualify as high-risk. If video analytics runs on your cameras, you now need logs, human oversight, and conformity evidence. Camnitive was built so you already have them.
The Act entered into force in August 2024 and has been landing in stages ever since. The stage that matters for camera AI is the last one.
Feb 2, 2025 · in force
Banned practices apply — including emotion recognition in the workplace. Fines for prohibited practices reach €35M or 7% of global turnover.
Aug 2, 2025 · in force
Governance obligations for general-purpose AI models take effect, alongside the appointment of national authorities.
Aug 2, 2026 · the deadline
The core of the Act lands: risk management, logging, human oversight, transparency, and conformity assessment for high-risk AI systems — the category workplace monitoring can fall into.
Compliance is not a document written after deployment. It is a property of the architecture — logs, oversight, and explanations produced as a side effect of normal operation.
The Act requires
High-risk systems must automatically log events so decisions can be traced and reconstructed.
Camnitive ships
Every rule evaluation in Camnitive is recorded with its inputs and outcome. Decisions are deterministic and reproducible — the same input always yields the same call, and the log proves it.
The Act requires
Deployers must ensure meaningful human oversight of high-risk AI decisions affecting people.
Camnitive ships
High-impact actions route through governed approval workflows in CamCore. Humans stay in the loop by design, and every acknowledgement is part of the sealed record.
The Act requires
Outputs must be interpretable enough for deployers to understand and act on them correctly.
Camnitive ships
Every event ships with an AI-written explanation in the language of your own policies — what was detected, which rule fired, and why it mattered.
The Act requires
High-risk systems require technical documentation and conformity assessment before use.
Camnitive ships
The Camnitive Conformity Pack ships with every deployment: system documentation, model cards, rule inventories, and the audit trail to back them up.
The Act requires
Training and operational data must be governed, relevant, and handled with privacy in mind.
Camnitive ships
Zero custom training data is collected from your sites. Video is processed at the edge, retention is enforced by policy, and every access is logged.
The Act requires
Emotion recognition at work and untargeted biometric scraping are banned outright.
Camnitive ships
Camnitive monitors operations, not emotions. Rules evaluate objects, zones, and actions against your written policies — no emotion inference, no biometric profiling.

Every obligation above maps to controls the platform evaluates continuously — logs complete, oversight SLAs met, documentation current. The result is a 0–100 readiness score in your CamCore dashboard that moves the moment a control drifts, with an alert and an owner attached.
When the regulator or your board asks where you stand, the answer is on screen — and the conformity report behind it is one click away, generated from live evidence.
See the Full Conformity PackThe same design that satisfies Brussels satisfies Riyadh, Abu Dhabi, Jakarta, and Singapore: video processed at the edge, data resident in-country, and evidence sealed for auditors.
Saudi PDPL · UAE PDPL · Qatar PDPPL
Residency and privacy obligations are met by architecture: edge processing on-site with in-country or fully air-gapped hosting.
Indonesia PDP · Singapore PDPA · Malaysia PDPA · Thailand PDPA
Camera footage of employees and visitors is regulated personal data across the region. Edge-first processing keeps every deployment inside national boundaries.
GDPR · CSRD
On-prem processing, policy-driven retention, and access logging answer GDPR guidance for camera systems — while sealed evidence feeds audited CSRD safety disclosures.
On the cameras you already own. Start with a 10–50 camera pilot, see measurable ROI in weeks, and grow it into your operations system of record.