Understanding Risk, Biometrics and Responsible AI Deployment
Artificial intelligence is increasingly used to help video security systems identify events, classify objects and assist operators in reviewing large volumes of video.
At the same time, regulators are paying closer attention to how AI may affect privacy, safety and fundamental rights.
The European Union Artificial Intelligence Act, commonly known as the EU AI Act, establishes a risk-based regulatory framework for AI systems made available or used in the European Union.
For the video security industry, understanding one principle is especially important:
Not every AI-enabled video function is treated the same way.
The regulatory assessment depends on what the AI system is intended to do, how it is used and the context in which it is deployed.
Where Does the EU AI Act Stand?
The EU AI Act entered into force in August 2024.
Major provisions became applicable on 2 August 2026, while certain requirements follow different implementation dates.
In particular, some rules governing high-risk AI systems have later application dates.
This phased approach means organizations should evaluate both the current requirements and the requirements that will apply to specific AI use cases in the future.
Regulatory classification should therefore be based on the actual intended purpose and deployment rather than on the presence of the term “AI” in a product description.
A Risk-Based Framework
The AI Act takes a risk-based approach.
Different AI applications may fall into different regulatory categories depending on their potential impact.
At a high level, the framework addresses areas including:
prohibited AI practices;
high-risk AI systems;
transparency requirements for certain AI systems;
AI applications that do not fall into those higher-risk categories.
For video security manufacturers and integrators, this makes accurate functional descriptions particularly important.
A system used to classify a vehicle or detect intrusion into a defined area is fundamentally different from a system intended to identify an unknown individual against a biometric database.
Both may use AI, but their regulatory analysis may be very different.
Video Analytics Are Not One Single Category
The term “video analytics” covers many different technologies.
Examples can include:
human and vehicle detection;
line-crossing detection;
intrusion detection;
object classification;
occupancy or counting analytics;
smoke or fire-related event detection;
license plate-related applications;
biometric authentication;
biometric identification.
The presence of AI in these functions does not by itself determine their regulatory classification.
The intended purpose, deployment context, users and consequences of the AI output all matter.
This is why product marketing should describe functions accurately rather than using broad statements such as “AI surveillance” or “fully AI Act compliant.”
Biometric Verification and Biometric Identification Are Different
One of the most important distinctions in the AI Act is the difference between biometric verification and biometric identification.
Biometric Verification
Biometric verification is generally a one-to-one process.
A person actively presents an identity or credential and the system checks whether that person matches previously provided biometric information.
A typical example is authentication for controlled access.
The AI Act distinguishes this form of verification from remote biometric identification.
Remote Biometric Identification
Remote biometric identification generally involves identifying a person, often without their active participation, by comparing biometric information against a reference database.
This distinction matters because certain biometric identification applications receive substantially greater regulatory attention under the AI Act.
Organizations should therefore avoid treating the terms authentication, verification, recognition and identification as interchangeable.
Accurate terminology helps both technical evaluation and compliance assessment.
Particular Attention to Sensitive Biometric Uses
The AI Act places strong restrictions on certain AI practices involving biometric information and fundamental rights.
Examples addressed by the regulation include certain forms of:
biometric categorisation involving sensitive personal characteristics;
untargeted collection of facial images for building or expanding facial recognition databases;
emotion recognition in specified contexts;
real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrowly defined conditions and exceptions.
For technology providers, this reinforces an important design and communication principle:
AI functions should have clearly defined purposes and should avoid unnecessary inference about individuals.
More data or more classification does not automatically make a security system more useful.
In many applications, purpose limitation and focused analytics can provide a more appropriate approach.
Human Oversight Still Matters
AI-enabled video analytics can help operators identify potentially relevant events more efficiently.
They should not automatically be treated as infallible decision-making systems.
Factors such as lighting, distance, camera angle, environmental conditions, scene complexity and configuration can influence analytic performance.
For this reason, AI outputs should generally be understood as part of a wider operational process.
Depending on the application, appropriate safeguards may include:
human review;
configurable confidence thresholds;
event verification;
clearly defined operating conditions;
logging and traceability;
deployment documentation;
periodic performance review.
Responsible AI deployment is therefore not just about the algorithm.
It also involves the people, procedures and environment around the system.
Transparency Starts with Product Communication
Regulatory transparency does not begin only after a product has been deployed.
It also starts with how manufacturers describe AI capabilities.
Product documentation should clearly explain what an analytic function is intended to detect or classify.
Marketing materials should avoid suggesting capabilities that are broader than the actual technical function.
For example, there is a significant difference between:
“Detects humans and vehicles within a configured detection area”
and
“Understands people and predicts suspicious behavior.”
The first describes a defined technical function.
The second may create unnecessary technical, regulatory and ethical implications.
Precise terminology is therefore increasingly important for responsible AI product communication.
Avoid Blanket “AI Act Compliant” Claims
Compliance with the AI Act can depend on more than the hardware itself.
Relevant factors may include:
the intended purpose;
the AI function;
who deploys the system;
where it is deployed;
how outputs are used;
whether biometric data is involved;
whether the application falls within a regulated high-risk category;
applicable national and EU requirements.
For this reason, a blanket statement that an entire camera range is “AI Act compliant” may be misleading without an appropriate use-case assessment.
A more responsible approach is to provide accurate product information and allow the specific deployment to be evaluated against applicable requirements.
Sunell's Approach to Responsible AI Communication
For AI-enabled video security products, Sunell focuses on describing functions according to their intended technical purpose.
Product-specific capabilities, software versions and available functions may vary between models and configurations.
Where regulatory or procurement requirements apply, customers and project stakeholders should evaluate the exact product, AI function and deployment scenario.
This approach helps distinguish technical capability from the legal assessment of how technology is ultimately used.
Moving Toward Responsible AI-Enabled Security
The EU AI Act does not mean that AI can no longer be used in video security.
Instead, it reinforces the need for a more disciplined approach to AI.
Manufacturers need clear technical definitions.
Integrators need to understand the intended purpose of the system.
Operators need appropriate governance and oversight.
And organizations deploying AI need to consider the regulatory requirements applicable to their specific use case.
As AI-enabled security continues to develop, responsible innovation will increasingly depend on combining useful analytics with transparency, proportionality and appropriate human oversight.
Need information about a specific AI-enabled function?
Contact Sunell for product-specific technical information and applicable documentation.
This article is provided for general informational purposes only and does not constitute legal advice or a determination of the regulatory classification of any specific AI system or deployment.
