Skip to content
Safety Tech Review
Menu

Regulation

The EU AI Act and Workplace Safety Systems: What Applies and When

How the EU AI Act applies to AI safety cameras and wearables: the emotion recognition ban, when systems become high-risk, deployer duties and the post-Omnibus dates.

By · Updated · 11 min read · 20 sources

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) affects workplace safety technology in two ways. Since February 2, 2025 it has banned AI that infers workers' emotions, except for medical or safety reasons. From December 2, 2027 it places obligations on employers and vendors when a safety system is used to monitor and evaluate workers or to make employment decisions, because those uses are high-risk. Many hazard detection systems will fall outside the high-risk category, but only if their purpose is defined narrowly and the employer sticks to it.

This article reflects the regulation as amended by the Digital Omnibus on AI and is current as of October 2, 2026. It is general information, not legal advice. Get a documented legal view for your own systems.

What is the timeline as of October 2026?

The AI Act entered into force on August 1, 2024 and applies in stages [1][5]. In 2026 the EU amended the schedule through the Digital Omnibus on AI. The Commission proposed it on November 19, 2025, the institutions reached political agreement on May 7, 2026, and it entered into force on July 27, 2026 [2]. Its main effect for employers was to postpone the high-risk obligations [2][4].

Date What applies Relevance to safety technology
February 2, 2025 Prohibited practices (Article 5) and AI literacy (Article 4) [3] Bans emotion inference at work; staff who use AI need support to understand it
August 2, 2025 Governance, general-purpose AI model rules, penalties chapter [3][5] Mostly affects model developers; national authorities and fines now in place
August 2, 2026 General application, including Article 50 transparency rules [3][4] Relevant to chatbots and generated content, such as EHS copilots
December 2, 2026 New prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material; end of the watermarking grace period for systems already on the market [3][4] Little direct relevance
December 2, 2027 High-risk rules for Annex III systems, including employment and biometrics (moved from August 2, 2026) [2][3] The main date for safety analytics that evaluates workers
August 2, 2028 High-risk rules for AI in products covered by Annex I legislation, such as machinery (moved from August 2, 2027) [2][3] AI used as a safety component of regulated products

The Omnibus also softened the AI literacy duty. Article 4 now requires providers and deployers to support the development of AI literacy among their staff rather than guarantee a particular level [4][16]. Training supervisors who act on alerts remains a sensible step.

Who is who: provider or deployer?

The Act assigns most duties by role. A provider develops an AI system, or has one developed, and places it on the market under its own name [8]. A deployer is any organization "using an AI system under its authority" [8]. In a typical safety project the vendor is the provider and the employer is the deployer.

Territorial scope is wide. The Act applies to providers placing systems on the EU market wherever they are based, to deployers located in the EU, and to providers and deployers in third countries where the system's output is used in the EU [17].

The roles can change. Under Article 25, a deployer becomes a provider of a high-risk system if it puts its own name or trademark on the system, makes a substantial modification, or modifies the intended purpose of a system so that it becomes high-risk [12]. An employer that buys a hazard detection product and then uses its output to score individual workers may be doing exactly that.

What does the emotion recognition ban cover?

Article 5(1)(f) prohibits the use of AI systems "to infer emotions of a natural person in the areas of workplace and education institutions", except where the system is intended for medical or safety reasons [6]. The Act defines an emotion recognition system as one that identifies or infers emotions or intentions from biometric data [8]. The Commission published guidelines on the prohibited practices on February 4, 2025 [18].

Recital 18 draws two lines that matter for safety teams [7]:

  • Physical states such as pain or fatigue are not emotions. The recital gives the example of systems that detect fatigue in professional pilots or drivers to prevent accidents. Drowsiness and fatigue monitoring is therefore outside the ban.
  • Detecting readily apparent expressions, gestures or movements, such as a raised voice or a hand movement, is not emotion recognition unless the system uses them to identify or infer emotions.

In practice, treat any feature marketed as detecting stress, frustration, anger, engagement or "mood" from faces or voices as off limits at EU sites unless counsel confirms it fits the medical or safety exception. Penalties for prohibited practices reach 35 million euros or 7% of worldwide annual turnover, whichever is higher [15].

Article 5(1)(g) also prohibits biometric categorization that infers sensitive traits such as race, political opinions, trade union membership, religion or sexual orientation [6]. No safety use case needs that, but check that a vendor's demographic analytics do not do it.

When does a safety system become high-risk?

There are two routes to high-risk status.

Route 1: Annex III use cases

Annex III, point 4(b) covers AI systems intended "to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationships" [9]. Point 1 covers remote biometric identification, biometric categorization by sensitive attributes and emotion recognition, while excluding verification that only confirms a person is who they claim to be [9].

How common safety configurations map onto that text:

Configuration Likely position
Detects vehicles, pedestrians in exclusion zones, blocked exits or spills; alerts go to a supervisor; no individual is identified Strong argument that it is not high-risk, because it does not monitor or evaluate individual performance or behavior
Detects missing PPE and sends anonymous site-level statistics Similar to the above, if the data is not linked to named workers
Links PPE or behavior events to named workers and reports them to managers Close to "monitor and evaluate the performance and behaviour" of workers; treat as likely high-risk
Feeds safety scores into appraisals, bonuses, task allocation or discipline Squarely within point 4(b)
Uses face recognition to identify workers from a database Remote biometric identification under point 1; high-risk
Badge or face verification only to open a door Excluded verification use under point 1, though GDPR biometric rules still apply

The Article 6(3) exception

An Annex III system is not high-risk if it does not pose a significant risk of harm and meets one of four conditions, such as performing a "narrow procedural task" or a "preparatory task" to a human assessment [10]. The exception never applies where the system profiles natural persons [10]. A provider that relies on the exception must document its assessment before placing the system on the market and register it [10]. Ask vendors whether they rely on Article 6(3) and request the documentation.

Route 2: Safety components of regulated products

AI that is a safety component of a product covered by EU product legislation listed in Annex I, such as machinery, can be high-risk through Article 6(1) [10]. These obligations apply from August 2, 2028 [3]. Separately, the new Machinery Regulation (EU) 2023/1230 applies from January 20, 2027 and includes provisions for machinery with AI-powered safety functions [19]. This route matters most to manufacturers of forklifts, cranes, robots and guarding systems with built-in AI, rather than to buyers of camera analytics.

What must an employer do if its system is high-risk?

From December 2, 2027, an employer that deploys an Annex III high-risk system has duties under Article 26 [11]:

  • Use the system in line with the provider's instructions for use, with appropriate technical and organizational measures.
  • Assign human oversight to people with "the necessary competence, training and authority" and support.
  • Monitor operation, tell the provider about risks and report serious incidents, suspending use where needed.
  • Keep the automatically generated logs under its control for at least six months, unless other law says otherwise.
  • Before putting the system into use at the workplace, inform workers' representatives and the affected workers.
  • Use the provider's information to carry out the GDPR data protection impact assessment.
  • Inform people when the system is used to make or assist decisions about them.

Article 86 adds a right for people affected by decisions based on Annex III high-risk systems to obtain "clear and meaningful explanations" of the role the AI system played in the decision [14]. If a safety alert ever contributes to a disciplinary outcome, expect to explain how.

Most private employers do not need a fundamental rights impact assessment. Article 27 limits that duty to public bodies, private entities providing public services and deployers of certain credit and insurance systems [13].

Breaching deployer obligations can lead to fines of up to 15 million euros or 3% of worldwide annual turnover, whichever is higher, with SMEs subject to the lower of the two [15].

What will vendors have to do?

Providers of high-risk systems carry heavier obligations: risk management, data governance, technical documentation, record keeping, transparency to deployers, human oversight design, accuracy and robustness, a quality management system and conformity assessment before placing the system on the market [1]. Harmonized standards that will give a presumption of conformity are still in development. The first, prEN 18286 on quality management systems, entered public enquiry on October 30, 2025 [20].

Questions to add to an RFP now:

  1. What is the documented intended purpose of the product, and does the vendor consider it high-risk under Annex III?
  2. If not, does it rely on Article 6(3), and can it share the assessment?
  3. Which features, if switched on, would change that classification (identification, individual scoring, HR integrations)?
  4. Does any feature infer emotions, stress or engagement?
  5. What is the plan and timeline for conformity with the high-risk requirements by December 2, 2027, if they apply?
  6. What logs does the system generate, and can the deployer retain them for six months?
  7. Will the instructions for use contain enough information for the customer's DPIA?

A practical plan for the next 14 months

  1. Inventory. List every AI feature in your safety stack, including wearables, proximity systems and EHS software, with its purpose and whether it identifies individuals.
  2. Remove prohibited features. Confirm in writing that no emotion inference is enabled at EU sites.
  3. Fix the purpose. Write down the intended purpose of each system in procurement documents, the DPIA and the worker notice. Decide whether safety data may be used for individual evaluation or discipline, because that choice largely determines classification.
  4. Classify. For each system, record whether it is likely high-risk and why.
  5. Prepare deployer processes for any high-risk system: oversight roles, training, log retention, incident reporting and worker information.
  6. Engage worker representatives early. Article 26(7) requires information before use, and national law may require more.
  7. Track guidance. Commission guidance and harmonized standards will fill in detail before December 2027.

Summary

The EU AI Act already bans emotion inference about workers, with exceptions for medical or safety reasons and with fatigue detection outside the definition of emotion. After the Digital Omnibus, which entered into force on July 27, 2026, high-risk obligations for employment and biometric systems apply from December 2, 2027, and those for AI in regulated products from August 2, 2028. Whether a safety system is high-risk depends mostly on its intended purpose: hazard detection that does not evaluate named workers has a strong case for staying outside Annex III, while individual scoring, discipline links and face recognition bring it inside. Employers should fix and document that purpose now, remove any emotion features, and ask vendors how they will meet the provider requirements if their product is high-risk.

Frequently asked questions

+Does the AI Act apply to a UK or US company?

It applies to providers that place AI systems on the EU market wherever they are based, to deployers located in the EU, and to providers and deployers outside the EU where the system's output is used in the EU. A UK company running safety cameras at its own UK sites only is outside scope, but a UK group with EU sites is a deployer for those sites.

+Is driver fatigue or drowsiness detection banned?

No. Recital 18 says emotion does not include physical states such as pain or fatigue, and gives fatigue detection for professional pilots and drivers as an example. Fatigue monitoring still processes personal data, so GDPR rules and a DPIA still apply.

+Do we need a fundamental rights impact assessment for safety cameras?

Usually not. Article 27 requires one from public bodies, private entities providing public services and deployers of certain credit and insurance systems. A private manufacturer or logistics company deploying a high-risk employment system is not on that list, although it still needs a GDPR DPIA.

+What are the fines?

Up to 35 million euros or 7% of worldwide annual turnover for prohibited practices, and up to 15 million euros or 3% for breaches of other obligations, including deployer duties. For SMEs, the lower of the two figures applies.

+Could the dates move again?

The current dates are set in the amended regulation, and further change would need new legislation. Watch for Commission guidance and harmonized standards, which are still being developed and will shape what compliance looks like in practice.

Sources

  1. [1]Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
  2. [2]European Commission, AI Act: regulatory framework for AI (including the Digital Omnibus timeline)
  3. [3]AI Act implementation timeline (artificialintelligenceact.eu)
  4. [4]Gibson Dunn, EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changes
  5. [5]AI Act, Article 113: Entry into force and application
  6. [6]AI Act, Article 5: Prohibited AI practices
  7. [7]AI Act, Recital 18
  8. [8]AI Act, Article 3: Definitions
  9. [9]AI Act, Annex III: High-risk AI systems
  10. [10]AI Act, Article 6: Classification rules for high-risk AI systems
  11. [11]AI Act, Article 26: Obligations of deployers of high-risk AI systems
  12. [12]AI Act, Article 25: Responsibilities along the AI value chain
  13. [13]AI Act, Article 27: Fundamental rights impact assessment
  14. [14]AI Act, Article 86: Right to explanation of individual decision-making
  15. [15]AI Act, Article 99: Penalties
  16. [16]AI Act, Article 4: AI literacy
  17. [17]AI Act, Article 2: Scope
  18. [18]European Commission, Guidelines on prohibited artificial intelligence practices (February 2025)
  19. [19]European Commission, Machinery: Regulation (EU) 2023/1230
  20. [20]European Commission, Standardisation of the AI Act

New chapters and updates, once a month

One email when we publish or update guidance. No vendor promotions. Unsubscribe any time.