EU AI Act 2026: Which Camera-Based People Tracking Is High Risk
The rules land August 2, 2026. Here is which camera-based tracking is high risk, which is banned, and how to design your CV product out of Annex III.
Camera-based people tracking is high risk under the EU AI Act when it biometrically identifies individuals, categorises them by biometric traits, infers emotions, or monitors workers. Anonymous detection, counting, and trajectory tracking that never identifies a person sits outside the Annex III high-risk list. The bulk of these obligations applies from August 2, 2026, with fines up to 35 million euros or 7 percent of global turnover for banned practices. Classify every camera feature now, then document it or redesign it.
Key takeaways
- August 2, 2026 is when Annex III high-risk obligations and Article 50 transparency duties apply to camera-based AI sold in the EU.
- Four camera uses trigger high-risk status: biometric identification, biometric categorisation, emotion recognition, and worker monitoring.
- Emotion recognition at work, sensitive-attribute categorisation, and untargeted face scraping have been banned since February 2, 2025.
- Anonymous counting, occupancy, and trajectory tracking sit outside Annex III because nobody is uniquely identified.
- Persistent cross-camera re-identification embeddings are the gray zone most likely to be treated as biometric data.
- Fines reach 35 million euros or 7 percent of global turnover for prohibited practices.
What actually happens on August 2, 2026?
The AI Act, Regulation (EU) 2024/1689, entered into force on August 1, 2024 with staggered deadlines. Prohibited practices have applied since February 2, 2025. General-purpose model rules landed August 2, 2025. August 2, 2026 is when the bulk of the Act applies, including the full obligation set for high-risk systems listed in Annex III and the Article 50 transparency duties that cover most camera analytics. AI embedded in already-regulated products, such as machinery and medical devices, gets until August 2, 2027.
Penalties scale with the violation: up to 35 million euros or 7 percent of global annual turnover for banned practices, and up to 15 million euros or 3 percent for breaking high-risk obligations.
Brussels has debated softening some Annex III timelines through the digital omnibus package while harmonised standards catch up. Nothing in that debate touches the prohibitions, which are already live, or the biometric provisions at the core of camera-based tracking. Plan for the statute, not for rumors.
Which camera-based people tracking counts as high risk?
Annex III lists the high-risk categories, and three hit camera products directly:
- Remote biometric identification: matching a face, gait, or body signature against a reference database to work out who someone is. Post-event or real-time, this is high risk wherever it is not outright banned.
- Biometric categorisation: sorting people by biometric traits, for example estimating age bands from faces at a store entrance.
- Emotion recognition: inferring emotional state from expressions or posture, outside the workplace and school settings where it is banned entirely.
The fourth trap is less obvious. Annex III point 4 covers employment, including AI that monitors or evaluates worker performance and behaviour. A warehouse camera system that scores picker speed or flags idle time is high risk even if it never runs a biometric model, because classification follows the use, not the algorithm. No face recognition needed to be high risk.
What is banned outright, not just high risk?
Article 5 prohibitions have applied since February 2, 2025 and carry the top fine tier of 35 million euros or 7 percent of turnover. Four matter for camera products:
- Real-time remote biometric identification in publicly accessible spaces for law enforcement, with narrow, judicially authorised exceptions.
- Emotion recognition in workplaces and education. A model that flags a frustrated shopper in an aisle may be merely high risk; point the same model at your cashiers and it is prohibited.
- Biometric categorisation that infers sensitive attributes such as race, political opinions, trade union membership, or sexual orientation.
- Untargeted scraping of facial images from the internet or CCTV to build recognition databases.
If a feature on your roadmap lands on this list, there is no conformity assessment path that gets it onto the EU market. Banned means banned, since February 2025.
When is people tracking not high risk?
The Act's biometric provisions hinge on unique identification. Article 3 defines biometric data as data from specific technical processing of physical, physiological, or behavioural characteristics that allows or confirms the unique identification of a person. A system that only detects that a person is present, counts entries, measures queue length, or follows anonymous trajectories through a store identifies nobody and appears nowhere in Annex III.
The gray zone is cross-camera re-identification. Appearance embeddings that follow shopper 47 from aisle to aisle without a name can still single out an individual, and a persistent, matchable embedding starts to look like biometric data to a regulator. Three design choices keep distance: keep embeddings short-lived, never persist them beyond the visit, and never match them against stored galleries.
One duty never goes away: GDPR applies to any footage containing people, whatever the AI Act risk tier. Anonymous by design keeps you off Annex III.
A compliance checklist for CV products before the deadline
Run this in order, starting now:
- Inventory every deployed model that processes images of people, including third-party SDKs inside your product.
- Classify each function against Article 5 and Annex III. Do it per feature, not per product; one banned feature poisons the release, not the codebase.
- For high-risk functions, stand up the Chapter III obligations: a risk management system (Article 9), training data governance (Article 10), technical documentation and automatic logging (Articles 11 and 12), human oversight (Article 14), and accuracy and cybersecurity testing (Article 15). Then complete a conformity assessment, affix CE marking, and register in the EU database under Article 49.
- For everything else that interacts with people, meet Article 50 transparency: people must know an AI system is operating on them.
- If you deploy workplace cameras, inform workers and their representatives before switch-on.
Most of this is documentation and process, and none of it compresses well under deadline pressure. Budget quarters for compliance, not weeks.
The cheapest compliance strategy: track items, not identities
Most builders reading this do not need to know who a person is. They need to know where a package, a pallet, a cart, or an infusion pump is. That distinction is the entire regulatory game: a camera system that tracks objects and treats humans as transient obstacles never touches remote biometric identification, biometric categorisation, or emotion recognition, and skips the Annex III conformity work entirely.
This is where licensing beats building. Position Imaging licenses hundreds of granted patents in computer vision and real-time positioning, including camera-based tracking patents such as US 11,774,249 and US 12,000,947, developed for tracking items rather than identities. The portfolio is cited by Apple, Bosch, and other major firms. Licensing proven, identity-free tracking IP means your engineers ship location features in months while a competitor's counsel is still mapping their people-tracking stack to Annex III. Track the package, skip the paperwork.
Frequently asked questions
Is anonymous people counting high risk under the EU AI Act?
No. Counting, occupancy, and anonymous trajectory analytics do not appear in Annex III and do not process biometric data as defined in Article 3, because nobody is uniquely identified. You still owe GDPR compliance for the footage and, where relevant, Article 50 transparency. The classification changes the moment you add identification, categorisation, or worker evaluation.
Does the EU AI Act apply to a US company with no EU offices?
Yes, if your system is placed on the EU market or its output is used in the EU. The Act follows the market, the same way GDPR did. A US retail analytics vendor selling to a single EU grocery chain is in scope, and EU importers and distributors of your product carry their own obligations.
Is cross-camera re-identification considered biometric identification?
It is the sharpest gray zone in camera analytics. If your appearance embeddings can single out and consistently recognise an individual, a regulator can treat them as biometric data even without names attached. Short-lived, session-scoped embeddings that are never matched against a stored gallery are the defensible design. Get written legal analysis before shipping persistent re-identification in the EU.
What are the penalties for shipping a non-compliant computer vision system?
Up to 35 million euros or 7 percent of global annual turnover for prohibited practices such as workplace emotion recognition, and up to 15 million euros or 3 percent for violating high-risk obligations. National market surveillance authorities can also pull products from the market while you remediate.
Has the August 2026 deadline been delayed?
The date written into the regulation is August 2, 2026. The Commission's digital omnibus discussions have floated easing some Annex III timing while harmonised standards mature, but the prohibitions have applied since February 2, 2025 and are not part of that debate. Build your plan on the statute and treat any relief as upside.
Send us a one-paragraph description of what your cameras track and we will map it against the portfolio, and against Annex III, before your next sprint.
Tell us the product. We map the exact scope, what a license covers, and how fast you can ship, all in a 20-minute call.
Book a 20-minute call