The EU AI Act and Workplace Safety Vision Systems: A Practical Checklist for UK Buyers

The EU AI Act and Workplace Safety Vision Systems: A Practical Checklist for UK Buyers

The EU AI Act entered full application in August 2025. UK buyers with EU vendors or EU operations need to understand whether their workplace safety AI is classified as high-risk — and what that means in practice.

7 August 2026·SecureSafety·11 min read

\"SecureSafety deployed at a major port — an example of a workplace safety AI system subject to EU AI Act obligations.\"

In August 2025, the provisions of the EU Artificial Intelligence Act that most directly affect workplace monitoring systems entered application. For the EHS manager at a UK port operation reviewing vendor contracts that autumn, this prompted a question that had not appeared on any board agenda: "Do we need to require our AI vendor to demonstrate compliance with legislation that technically doesn't apply to us?"

The answer, as with most questions that begin with EU law and end with a UK-only company, is: it depends — and the things it depends on matter enough to work through carefully.

The EU AI Act is not UK law. It does not apply to systems deployed exclusively within the United Kingdom. But the legal environment around workplace AI is changing fast, the intersection between UK and EU operations is common, and EHS buyers whose vendors are headquartered in the EU — or whose organisations operate in EU member states — face direct relevance. This article explains what the Act actually requires, where safety AI sits within it, and what practical questions to put to any safety AI vendor before you sign.

What the EU AI Act actually says about workplace AI

The EU AI Act (Regulation (EU) 2024/1689) was adopted in May 2024. Most substantive provisions entered application on 2 August 2025. The regulation establishes a tiered risk classification: prohibited AI (certain biometric and social-scoring systems), high-risk AI (regulated with conformity obligations), limited-risk AI (transparency obligations only), and minimal-risk AI (voluntary codes of practice).

The high-risk classification that matters most for workplace safety AI is set out in Annex III, point 4. This covers AI systems intended to be used:

"…for making decisions on promotion and termination of work-related contractual relationships, for allocating tasks based on individual behaviour or personal traits or characteristics, or for monitoring and evaluating performance and behaviour of the persons in such work-related contractual relationships."

Read carefully, this provision targets AI that manages employment relationships, evaluates individual workers, or allocates tasks based on individual behaviour. A system that detects whether a hard hat is being worn in a controlled zone is not, on a straightforward reading, making employment decisions or evaluating individual worker performance. It is monitoring a physical safety condition. The European AI Office, in guidance published in 2025, indicated that AI systems used purely to detect workplace hazards — rather than to evaluate individual workers — are not within the scope of Annex III point 4.

However, the line is not absolute. Two deployment scenarios bring safety AI meaningfully closer to Annex III scope:

Where detection data is used in employment decisions. If a safety AI system generates individual worker behaviour records that feed into disciplinary proceedings, attendance reviews, or performance assessments, the system is being used to evaluate individual behaviour in a work-related contractual relationship — which is within point 4. The technology itself may be the same; the use determines the classification.

Where the system controls access to work. A system that prevents a worker from entering a site because they failed a PPE compliance check in a prior shift — or that restricts task assignment based on AI-detected behaviour patterns — is allocating tasks based on individual behaviour, which also engages point 4.

The practical implication: how you configure and use the system matters as much as what the system is technically capable of doing. A safety AI system deployed for hazard detection, with footage used only for real-time intervention and aggregate safety reporting, presents a straightforwardly different compliance profile from one whose outputs are linked to HR processes.

What high-risk classification means in practice

If a workplace AI system falls within the high-risk classification — whether now or under future guidance — the obligations on the provider and the deployer are substantial.

For the provider (the AI vendor), Articles 10 through 17 of the Act require:

  • A formal risk management system covering the AI system's entire lifecycle, including post-market monitoring
  • Data governance requirements for training, validation, and testing datasets — demonstrating that data is relevant, representative, free of known errors, and does not encode prohibited biases
  • Technical documentation sufficient to demonstrate conformity with the Act's requirements — this must be maintained and updated throughout the lifecycle, not produced once at launch
  • Automatic logging of events sufficient to enable post-hoc monitoring of the system's operation — the Act specifies minimum logging requirements under Article 12
  • Human oversight measures built into the system by design — under Article 14, high-risk AI systems must be designed to allow human intervention, monitoring, and override by the deploying organisation
  • Accuracy, robustness, and cybersecurity performance standards, with stated metrics
  • Registration in the EU database of high-risk AI systems (the EUAI database, managed by the European AI Office) before the system is placed on the market

For the deployer (the buyer), obligations include using the system as intended and in accordance with the provider's instructions, ensuring human oversight in operation, monitoring performance and reporting issues, keeping logs as required by the system, and not making the system available to untrained personnel.

The conformity assessment — the formal process by which a high-risk AI system demonstrates compliance before being placed on the market — is the centrepiece of the provider's obligations. For most high-risk AI systems, self-assessment by the provider against technical standards is permitted. For certain specific categories (notably real-time remote biometric identification), mandatory third-party assessment applies.

The UK regulatory landscape

The United Kingdom has not enacted domestic legislation equivalent to the EU AI Act, and has stated its intention to pursue a sector-led, principles-based approach rather than a horizontal AI regulation. The DSIT (Department for Science, Innovation and Technology) published the AI Regulation: A Pro-Innovation Approach white paper in March 2023, and the government has since confirmed that it does not intend to introduce an AI Act equivalent in the current Parliament. The GOV.UK AI regulation page (gov.uk/guidance/ai-regulation-a-pro-innovation-approach) sets out the current position.

For workplace safety specifically, HSE published its position statement on AI in health and safety management in 2024, affirming that AI systems used in safety processes must comply with existing health and safety law — the Health and Safety at Work Act 1974, the Management of Health and Safety at Work Regulations 1999, RIDDOR, and associated guidance. HSE's position does not create new obligations; it confirms that existing duties of care apply when AI-assisted processes are used to discharge them, and that those duties cannot be delegated to the AI system itself.

For UK buyers, the practical implications are:

UK-only deployments of workplace safety AI are not subject to the EU AI Act. Compliance with existing HSE law, the ICO's AI and data protection guidance, and UK GDPR is the relevant obligation set. The ICO's guidance on AI (ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/ai-and-data-protection) and its guidance on monitoring workers (November 2023) are the most directly applicable documents.

UK companies using EU-manufactured systems should understand what obligations the manufacturer's EU AI Act compliance framework imposes on the deployment conditions. Conformity assessments may contain requirements about how the system is deployed and monitored that the buyer must meet in order for the manufacturer's conformity certificate to remain valid.

UK companies with EU operations that deploy safety AI in EU member states are fully subject to the EU AI Act for those deployments.

UK companies exporting AI outputs — for example, a UK-based port operation that sends AI-generated safety data to an EU-based parent company — may engage EU data protection rules depending on the nature of the transfer.

On-premise deployment and EU AI Act data obligations

One dimension of the EU AI Act deserves specific attention for UK safety AI buyers: the data governance and logging obligations under Articles 12 and 17.

For cloud-based AI systems, these obligations are often discharged by the provider through centralised log storage and remote performance monitoring. The provider retains access to model inference data, aggregated performance metrics, and, in some cases, video footage used for model improvement. For a UK buyer, this means that compliance with both UK GDPR and the EU AI Act's data provisions depends on the cloud provider's compliance framework — a dependency that is often invisible until a DPIA or an audit surfaces it.

For on-premise systems — where AI processing happens entirely within the customer's network, footage never leaves the site, and model performance data is retained under the customer's direct control — the picture is different. The customer holds the log data that the EU AI Act requires. There is no footage leaving site to require an international data transfer assessment. The human oversight obligations are discharged by the customer's own control room team rather than by a remote monitoring arrangement.

SecureSafety deploys exclusively on-premise. Footage never leaves the customer's site. This architecture was built originally to satisfy the security requirements of oil and gas operators who operate under strict data sovereignty obligations on the UK Continental Shelf. For EU AI Act compliance purposes, on-premise deployment provides a cleaner foundation for the data governance and logging obligations than cloud-based alternatives — regardless of the ultimate jurisdiction question.

Buyer checklist: 8 questions to ask your safety AI vendor

Use the following questions when evaluating any safety AI vendor in the context of EU AI Act compliance. For UK-only deployments, these questions remain useful as a proxy for general regulatory maturity.

1. How have you classified your system under the EU AI Act, and what is the reasoning? A vendor who cannot articulate whether their system falls under Annex III point 4, and why, does not have the legal awareness to be a reliable compliance partner. Ask for a written position, not a verbal summary.

2. If your system is classified as high-risk, what is the status of your conformity assessment? Under Article 43, high-risk AI systems must complete a conformity assessment before being placed on the market. Ask to see the assessment documentation or the certificate.

3. What technical documentation do you maintain under Article 11? Article 11 requires technical documentation covering the system's intended purpose, the data used for training and testing, accuracy and robustness metrics, and the risk management framework. Ask for a summary that covers these elements.

4. How are event logs generated and maintained under Article 12? Article 12 requires that high-risk AI systems generate automatic logs covering the operating period and the data processed. Ask where those logs are stored, who can access them, how long they are retained, and what happens to them if you terminate the contract. For cloud-based systems, this question is critical.

5. What human oversight measures are built into the system under Article 14? A high-risk AI system must be designed to allow effective human monitoring and override. Can the system be paused, overridden, or shut down by a named individual at the deploying organisation? If not, it does not meet the Article 14 requirement.

6. Is your system registered in the EU database? From August 2025, providers of high-risk AI systems must register them in the EU database before placing them on the market. Ask for the registration number if the system is classified as high-risk.

7. What DPIA support documentation do you provide? The ICO requires a DPIA for AI processing of personal data that is likely to result in high risk to individuals — which includes most workplace AI monitoring systems. A responsible vendor will provide template documentation, processing records, and a description of their own safeguards to support the DPIA, rather than leaving the buyer to construct it entirely unaided.

8. What is your serious incident reporting process under Article 73? Article 73 requires providers of high-risk AI systems to report serious incidents — events that result in, or could have resulted in, death, serious harm, or a fundamental rights violation — to the relevant national authority. Ask the vendor what qualifies as a serious incident under their definition, how they would notify you, and what the timelines are.


The offshore deployments through which SecureSafety established its operating pedigree predate the EU AI Act by several years — but the regulatory environments of the UK Continental Shelf (Offshore Installations Regulations, PFEER Regulations, the Safety Case Regime) required equivalent standards of technical documentation, human oversight, and event logging by design. The architecture built to satisfy those obligations — on-premise processing, human-in-the-loop alert acknowledgement, complete event logging, no footage leaving site — maps directly onto the EU AI Act's framework for any future high-risk classification, without requiring structural changes to the deployment model. If you want to discuss how a SecureSafety deployment would interact with your specific regulatory obligations — EU, UK, or both — book a demo.

Live demo · ~20 minutes
See it in action

See the detectors running on a live deployment.

Book a demo and we'll show SecureSafety at work — real hazards, real cameras, live.