Regulation
AI safety cameras in Europe: what differs between UK and US vendors
For EU sites buying AI safety cameras from UK or US vendors: data transfers, EU hosting, works councils, the 2026 to 2028 product law dates and contract clauses.
By LIPAI WANG · Updated · 7 min read · 13 sources
EU sites buying AI video safety analytics often end up choosing between a UK-based and a US-based vendor. On features the two can look alike. Under EU law, they differ in one important place, data transfers, and are treated the same almost everywhere else.
This article sets out what really differs when a UK or US vendor deploys AI safety cameras at an EU site, and what to put in the contract. It does not cover Chinese camera makers, which are covered in Hikvision and Dahua restrictions by country, or the full matrix of vendor origins, which is in our vendor-by-country matrix.
The one real difference: data transfers
AI safety analytics processes video of workers, which is personal data under the GDPR. If the vendor processes that data outside the EU, the transfer needs a legal basis.
UK vendors. On December 19, 2025, the European Commission renewed its adequacy decisions for the UK, which now run until December 27, 2031 [1]. Personal data can flow from the EU to the UK without standard contractual clauses (SCCs) or other transfer tools [1]. The Commission found that UK protection remains essentially equivalent after the changes made by the Data (Use and Access) Act [1].
US vendors. Transfers to certified US companies rely on the EU-US Data Privacy Framework (DPF). The EU General Court rejected a challenge to the DPF in September 2025, and that ruling has been appealed to the Court of Justice of the EU [2]. If the Court of Justice invalidates the DPF, US vendors would fall back on SCCs plus transfer impact assessments, as they did after earlier frameworks were struck down. In our assessment, that is a real but manageable risk.
The US answer: EU hosting. US vendors respond by processing data inside the EU. Verkada, for example, launched a version of its Command platform fully hosted in a European data center in September 2023 [3]. A US vendor with genuine EU-only processing, including support access and backups, and an EU legal entity removes most of the transfer difference in practice. Check the details: where support staff access data from, where logs and model training data go, and which sub-processors are outside the EU.
What could change the UK edge. UK data law is diverging. Most of the Data (Use and Access) Act's data protection changes commenced on February 5, 2026, including looser rules on automated decision-making except where special category data is involved [4]. In our view, further divergence would be the main threat to UK adequacy before 2031.
Works councils: same rules for every vendor
In Germany, the works council has an enforceable right of co-determination over technical systems that are objectively capable of monitoring employees' behavior or performance, under section 87(1) no. 6 of the Works Constitution Act (BetrVG) [5]. The employer's intent does not matter [5]. A camera system bought only for forklift safety still qualifies if it could be used to monitor people. When AI is introduced, the law treats the council's use of an outside expert as always necessary; the expert, the scope and the cost are then agreed with the employer, which pays [5].
Vendor origin makes no difference here. What helps is a product designed for these negotiations: configurable blurring, no identification of individuals by default, short retention, and clear limits on who can see what. Expect to be asked for these by European works councils regardless of where the vendor is based.
Regulators also look closely at warehouse monitoring. France's data protection authority, the CNIL, fined Amazon France Logistique €32 million over warehouse monitoring, and France's highest administrative court cut the fine to €15 million in December 2025 [6]. The guide chapter on privacy law and workers covers these cases in more detail.
The product law calendar: same for UK and US
From an EU product law perspective, a UK vendor and a US vendor are both suppliers from outside the EU. Four laws take effect over the next two years:
- Product Liability Directive (PLD). The revised directive covers software and AI-enabled products and applies to products placed on the EU market from December 9, 2026, regardless of where the responsible company is based [7]. Liability can extend beyond the manufacturer to importers, online platforms and fulfilment service providers [7].
- Machinery Regulation. Regulation (EU) 2023/1230 replaces the Machinery Directive on January 20, 2027 [8]. It applies with no transition period and adds safety requirements for autonomous systems, including AI [8]. This matters where safety analytics is built into or controls machinery, not for cameras that only send alerts.
- Cyber Resilience Act (CRA). Reporting of actively exploited vulnerabilities and severe incidents started on September 11, 2026, and the main obligations apply from December 11, 2027 [9].
- AI Act. The AI Omnibus, Regulation (EU) 2026/1744, moved high-risk obligations for Annex III uses, which include employment, to December 2, 2027, and for AI in regulated products to August 2, 2028 [10]. Gibson Dunn reports that AI in products covered by the Machinery Regulation is "largely exempted" from the AI Act [11]. The ban on AI that infers workers' emotions, except for medical or safety reasons, has applied since February 2, 2025 [12][10]. Our article on the EU AI Act and workplace safety systems explains when a safety system becomes high-risk.
The GDPR itself may change. The Digital Omnibus proposal to amend it has not been adopted: the Council set out its position on June 22, 2026, and the Parliament's position and negotiations are pending [13].
Side by side
| Factor | UK vendor | US vendor | What to check |
|---|---|---|---|
| EU to vendor data transfer | Adequacy until December 27, 2031; no extra transfer tool [1] | DPF certification or SCCs; DPF under appeal [2] | Where every copy of the data, logs and support access sits |
| Hosting | Can process in the UK lawfully [1] | Often offers EU hosting [3] | Sub-processor list and locations |
| Product Liability Directive | Applies from December 9, 2026 [7] | Same | Which EU company would answer a claim |
| Machinery Regulation | Applies from January 20, 2027 where relevant [8] | Same | Whether the product controls machinery |
| Cyber Resilience Act | Reporting since September 2026; full duties December 2027 [9] | Same | Vulnerability reporting process and support period |
| AI Act | High-risk duties December 2027 or August 2028 [10] | Same | Provider's classification and documentation |
| German works council | Capability triggers co-determination [5] | Same | Configuration options for the agreement |
Contract clauses to ask for
Whether the vendor is from the UK or the US, the contract should cover:
- Processing location. Every location where video, metadata, logs and backups are stored or accessed, with notice before any change.
- Transfer fallback. For US vendors, what happens if the DPF falls: SCCs ready to sign, and the right to require EU-only processing. For UK vendors, the same fallback if UK adequacy is withdrawn or not renewed [1][2].
- Liability. The name of the EU-based company that will answer product liability claims for products placed on the market from December 9, 2026 [7].
- Security support. A security update period in years, a vulnerability reporting process consistent with the CRA, and notice of incidents [9].
- AI Act documentation. The provider's own classification of the system under the AI Act, and a commitment to supply the documentation a deployer needs if the system is high-risk [10].
- Works council support. Technical documentation in the local language, configuration options for blurring, identification and retention, and attendance at council meetings if requested [5].
- Machinery conformity. Where the product forms part of or controls machinery, conformity documentation under the Machinery Regulation from January 20, 2027 [8].
- Exit. Data export formats and deletion on termination.
The guide chapter on buying and piloting covers how to build these into a request for proposal.
What to do next
- Ask every shortlisted vendor for a data flow diagram that shows each processing location, including support access.
- For US vendors, confirm DPF certification and whether a full EU-only processing option exists.
- In Germany, open works council talks before the pilot, and budget for an outside AI expert for the council.
- Put the eight clauses above into the contract template now, since most will be signed before the 2027 dates.
- Record the vendor's AI Act classification and recheck it before December 2, 2027.
Frequently asked questions
+Does UK adequacy mean a UK vendor needs no data protection paperwork?
No. Adequacy removes the need for transfer tools such as standard contractual clauses for EU-to-UK transfers. You still need a lawful basis, a data processing agreement, a data protection impact assessment where required, and works council steps.
+Is it unlawful to use a US vendor that processes data in the US?
No. The EU-US Data Privacy Framework is in force for certified companies. The risk is that the Court of Justice could invalidate it on appeal, which would push transfers back onto standard contractual clauses and transfer assessments.
+Does the AI Act already apply to our safety cameras?
The ban on emotion recognition at work has applied since February 2025, except for medical or safety reasons. High-risk duties for Annex III uses, which include employment, now apply from December 2, 2027.
+Can we avoid the works council if the cameras are only for forklift safety?
Not in Germany. Co-determination is triggered when a system is objectively capable of monitoring behavior or performance, regardless of the employer's intent.
Related reading
Sources
- [1]Hunton Andrews Kurth, European Commission renews UK data adequacy decisions (2025)
- [2]WilmerHale, European Court of Justice to review challenge to EU-U.S. Data Privacy Framework (2025)
- [3]Verkada, Verkada launches Command fully hosted in European data center (2023)
- [4]DLA Piper Privacy Matters, UK: commencement of the data protection provisions in the Data (Use and Access) Act (2026)
- [5]Bitkom, Künstliche Intelligenz und Mitbestimmung (2026)
- [6]PPC Land, France slashes Amazon's GDPR fine from €32M to €15M over warehouse monitoring (2025)
- [7]EU Transition Pathways, New EU product liability rules will apply to online platforms and software from December 2026 (2026)
- [8]TÜV NORD, Machinery Regulation (EU) 2023/1230 (2026)
- [9]European Commission, Safer and more secure digital products (2026)
- [10]European Commission, AI Act: regulatory framework for AI (2026)
- [11]Gibson Dunn, EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes (2026)
- [12]EU Artificial Intelligence Act (Regulation (EU) 2024/1689), Article 5: prohibited AI practices
- [13]NautaDutilh, The Digital Omnibus: what changed, what survived and what remains open (2026)
Get the free Safety Tech Buyer's Toolkit
A 15-page PDF: the public evidence checklist, a weighted vendor scorecard, 40 RFP questions and pilot acceptance criteria. Subscribe and download it straight away; then one email a month when we publish or update guidance. No vendor promotions. Unsubscribe any time.