Trust & Compliance

Assessment according to the AI Act

General information about the AI Act

The European Union's Artificial Intelligence Act (the "AI Act") introduces a risk-based framework governing the development and use of AI systems within the EU. AI systems are categorized into four levels of risk, each with corresponding obligations:

  • Prohibited AI: Certain AI systems are not allowed due to unacceptable risk, such as systems that manipulate behaviour or enable social scoring.
  • High-Risk AI: AI systems used in critical contexts are considered high-risk and are subject to strict regulatory requirements, including systems used in areas such as critical infrastructure, employment, law enforcement, and biometric identification.
  • Limited-Risk AI: These systems are subject to transparency obligations, such as informing users that AI is being used.
  • Minimal or No-Risk AI: Most AI systems fall into this category and are subject to limited or no regulatory requirements.

The classification of an AI system depends on its intended purpose, functionality, and deployment context.

Preventai's solution

Preventai provides an AI-based video analysis solution designed to transform existing camera infrastructure into intelligent, real-time sensing systems (the "Solution"). The Solution connects directly to existing cameras, enabling deployment across different types of operations. At the core of the Solution is a proprietary video language model, which allows users to define detection capabilities using natural language.

This enables flexible configuration of the Solution based on operational needs. The Solution continuously analyses video streams to detect certain actions and operational events. When such events are identified, alerts are generated to support timely response by on-site personnel. The Solution is designed as a decision-support tool, enhancing situational awareness while ensuring that all actions are taken by human operators.

Executive summary

This assessment sets out preventai's analysis of the classification and regulatory position of its AI-powered video analytics system under the AI Act. The Solution connects to existing camera infrastructure in selected environments and uses artificial intelligence to detect events indicative of, for example, shoplifting or other loss-prevention-relevant events in real time, sending notifications to personnel for assessment at their discretion. All images are automatically and irreversibly anonymised and the Solution does not perform emotion recognition or biometric identification.

Preventai has assessed the Solution against each layer of the AI Act's risk-based framework and concludes the following:

  • Prohibited practices (Article 5): The Solution does not fall within the scope of any prohibited AI practice. It does not perform emotion recognition, does not constitute a real-time remote biometric identification system for law enforcement, and does not engage in social scoring.
  • High-risk classification (Article 6): The Solution is not classified as high-risk. It does not fall within the scope of the EU harmonisation legislation listed in Annex I, and it is not referred to in any of the use-case areas listed in Annex III.
  • Transparency obligations (Article 50): Some transparency obligations under Article 50 apply to the Solution.
  • Applicable obligations: The Solution is subject to the general provisions of the AI Act applicable to all AI systems, including the AI literacy obligation under Article 4. No conformity assessment, EU declaration of conformity, CE marking, or registration in the EU database for high-risk AI systems is required.

Notwithstanding this classification, preventai has elected to voluntarily comply with the key substantive requirements applicable to high-risk AI systems under Chapter III, Section 2 of the AI Act — covering risk management, data governance and bias mitigation, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity — in recognition of the fundamental rights implications of AI-powered event monitoring in publicly accessible spaces.

The above conclusions are contingent on the Solution being deployed and used in accordance with its intended purpose of loss prevention, operational security and efficiency and risk detection. Use of the Solution outside this scope — including for employee monitoring, law enforcement, or the systematic sharing of outputs with law enforcement authorities — may alter its classification under the AI Act.

Background

This Assessment sets out preventai's analysis of the classification of the Solution under the AI Act and documents the measures taken to ensure compliance. It is provided to deployers and prospective deployers to enable them to understand the Solution's regulatory position and to support them in meeting their own obligations under the AI Act, including, where applicable, the fundamental rights impact assessment obligation under Article 27.

The Provider

Preventai ("preventai" or the "Provider") is the developer and provider, within the meaning of Article 3(3) of the AI Act, of the Solution described below.

The Solution

Preventai provides an AI-powered video analytics system designed for deployment in many different types of operations. The Solution connects to existing camera infrastructure and processes video feeds in real time to detect events indicative of, for example, shoplifting or other loss-prevention-relevant events, sending notifications to personnel to assess and respond at their discretion.

The Solution incorporates the following design characteristics that are material to its classification under the AI Act:

  • Automatic anonymisation: All images processed by the Solution are automatically and irreversibly anonymised. The Solution does not identify, or seek to identify, any natural person.
  • No emotion recognition: The Solution does not detect, analyse, infer, or otherwise process emotional states. It operates exclusively at the level of action detection.
  • No biometric identification: The Solution does not compare biometric data against any reference database, watchlist, or repository of biometric templates. It does not perform facial recognition or any other form of remote biometric identification.
  • Human-in-the-loop design: The Solution does not take autonomous action. It sends notifications to personnel, who retain full discretion as to whether and how to respond. The Solution does not trigger automated interventions without human intervention.

Assessment

Prohibited AI practices (Article 5)

Article 5 of the AI Act prohibits AI practices posing an unacceptable risk. Preventai has assessed the Solution against each prohibited practice under Article 5(1) and concludes that none applies. The most relevant prohibitions are analysed below.

  • Emotion recognition in the workplace and educational institutions (Article 5(1)(f)): Article 5(1)(f) prohibits AI systems that infer emotions of natural persons in workplace and educational settings, except for medical or safety purposes. The Solution does not detect, analyse, or infer emotional states.
  • Real-time remote biometric identification for law enforcement (Article 5(1)(h)): The Solution does not constitute a remote biometric identification system and is operated by private entities for loss prevention, not by or on behalf of law enforcement.
  • Social scoring (Article 5(1)(c)): The Solution does not evaluate, score, or classify natural persons over time or across contexts. It detects discrete events in real time and does not maintain behavioural profiles, cumulative risk scores, or records attributable to identified or identifiable individuals.

High-risk classification (Articles 6 and Annex III)

Under Article 6, an AI system is classified as high-risk if it falls within the scope of the legislation listed in Annex I and requires a third-party conformity assessment, or if it is referred to in the use-case areas listed in Annex III. Preventai has assessed the Solution against each Annex III use-case area:

  • Point 1(a) — Remote biometric identification systems: The Solution does not identify natural persons or perform facial recognition. Point 1(a) does not apply.
  • Point 1(b) — Biometric categorisation systems: The Solution does not categorise natural persons on the basis of any sensitive or protected attribute. Point 1(b) does not apply.
  • Point 4 — Employment, workers management: The Solution's intended purpose is exclusively loss prevention; it is not designed or intended for employee monitoring. Point 4 does not apply.
  • Point 6 — Law enforcement: The Solution is operated by private businesses for commercial loss prevention, not by or on behalf of law enforcement. Point 6 does not apply.
  • Remaining Annex III categories: Preventai has assessed the Solution against Points 2, 3, 5, 7, and 8. None applies given the Solution's intended purpose of loss prevention in commercial environments.

Specific transparency obligations (Article 50)

Article 50 imposes specific transparency obligations on providers of certain AI systems, regardless of high-risk classification.

  • Article 50(1) — AI systems intended to directly interact with natural persons: The Provider recommends that deployers ensure that natural persons present in monitored premises are informed that AI-powered video analytics are in operation.
  • Article 50(2) — AI-generated or manipulated content: The Solution does not generate synthetic content; Article 50(2) does not apply.
  • Article 50(3) — Emotion recognition and biometric categorisation systems: The Solution does not perform emotion recognition or biometric categorisation; Article 50(3) does not apply.

Voluntary compliance measures

Notwithstanding the above classification, preventai recognises that the Solution operates in a context — real-time camera surveillance in publicly accessible spaces — engaging fundamental rights including privacy, data protection, and non-discrimination. Preventai has therefore elected to voluntarily comply with the key requirements applicable to high-risk AI systems under Chapter III, Section 2 of the AI Act:

  • Risk management (Article 9): Preventai maintains a risk management system covering the Solution's entire lifecycle, comprising identification, analysis, estimation, and evaluation of risks to health, safety, and fundamental rights.
  • Data governance and bias (Article 10): Training, validation, and testing data sets have been subject to appropriate governance practices. The detection mechanism is based on observable physical actions rather than appearance-based features, reducing the risk of discriminatory outcomes.
  • Transparency and instructions for use (Article 13): Preventai provides deployers with instructions covering the Solution's intended purpose, capabilities, known limitations, accuracy levels, foreseeable risks, and required human oversight measures.
  • Human oversight (Article 14): All notifications are directed to personnel who retain full discretion. Staff are informed that notifications are probabilistic and do not constitute a definitive determination that an offence has occurred.
  • Accuracy, robustness and cybersecurity (Article 15): The Solution has been designed to achieve an appropriate level of accuracy, robustness, and cybersecurity throughout its lifecycle.

Obligations of the deployer

While the Solution is not classified as high-risk, preventai draws deployers' attention to the following obligations and recommended actions:

  • AI literacy (Article 4): Deployers must ensure that staff operating the Solution have a sufficient level of AI literacy.
  • Data protection (GDPR): Deployers, acting as data controllers, must ensure a valid legal basis for processing and are likely required to carry out a DPIA under Article 35(3)(c) GDPR.
  • Fundamental rights impact assessment (Article 27): Deployers that are public bodies or private entities providing public services should assess whether the FRIA obligation is applicable to them.
  • Transparency to natural persons: Preventai recommends that deployers inform natural persons present in monitored premises that AI-powered video analytics are in operation.
  • Use within intended purpose: Deployers must not use the Solution outside this scope, including for employee monitoring, law enforcement, or systematic sharing of outputs with law enforcement authorities.

Conclusions

Based on this Assessment, preventai draws the following conclusions regarding the Solution's classification under the AI Act:

  • The Solution does not fall within any prohibited AI practice under Article 5. It does not perform emotion recognition, does not constitute a real-time remote biometric identification system for law enforcement, and does not engage in social scoring.
  • The Solution is not classified as high-risk under Article 6. It does not fall within Annex I or any Annex III use-case area.
  • The Solution triggers transparency obligations under Article 50, as it interacts directly with staff receiving notifications and indirectly by processing video material of natural persons.
  • The Solution is subject to the general provisions applicable to all AI systems, including the AI literacy obligation under Article 4.
  • Preventai has elected to voluntarily comply with the key requirements applicable to high-risk AI systems — covering risk management, data governance and bias mitigation, transparency and instructions for use, human oversight, and accuracy, robustness and cybersecurity.

These conclusions are contingent on the Solution being deployed in accordance with its intended purpose. Use outside that scope — including for employee monitoring, law enforcement, or systematic sharing of outputs with law enforcement authorities — may alter the Solution's classification and give rise to additional obligations or prohibitions.

DPIA (Data Protection Impact Assessment)

General information about DPIAs

Article 35 of the GDPR requires data controllers to carry out a data protection impact assessment ("DPIA") where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. A DPIA is mandatory where the processing meets any of the criteria set out in Article 35(3), including systematic monitoring of a publicly accessible area on a large scale (Article 35(3)(c)).

Given that preventai's solution involves AI-powered real-time analysis of video feeds from camera infrastructure in publicly accessible environments, a DPIA is considered necessary. This assessment identifies and evaluates the risks to data subjects arising from the processing and sets out the measures adopted to address those risks.

Data controller

Preventai's customers (the "Controllers") will determine the purposes and means of the processing and will therefore act as data controllers for the relevant processing activities.

Elevated risk activities

Does the processing include: Answer
Evaluation or scoring (including profiling)? No. Profiling within the meaning of Article 4(4) GDPR and the AI Act requires automated processing of personal data to evaluate personal aspects relating to an identified or identifiable natural person. The Solution does not constitute profiling because it does not maintain persistent profiles, cumulative scores, or behavioural histories linked to specific individuals over time or across contexts. Detection operates exclusively at the level of observable physical actions. The Solution does not compare data against any reference database and does not make autonomous decisions.
Automated decision making with legal or similar significant effect? No. The Solution only generates alerts and explanatory information. Any intervention or decision concerning an individual is made following human review. Alerts are triggered exclusively by the detection of objective, observable physical actions — such as concealment of merchandise or bypassing of point-of-sale infrastructure — and not by any form of emotion recognition or intent detection.
Systematic monitoring in a publicly accessible area? Yes. The processing entails ongoing observation and analysis of individuals in a publicly accessible environment. Camera surveillance involving personal data is typically regarded as systematic monitoring, and publicly accessible places are to be interpreted broadly.
Sensitive data or data of a highly personal nature? Yes. Although the solution does not use facial recognition or biometric identification and does not intentionally process special category data, the video material may incidentally capture information that could reveal health-related circumstances (for example, crutches or wheelchairs) or information regarding religion (for example, religious clothing). However, the images are subject to irreversible facial blurring/anonymisation, which reduces the privacy risk.
Data processed on a large scale? Yes. The solution is deployed in settings with material customer footfall. Large-scale processing is assessed by reference to the number of data subjects, the volume and variety of data, the duration, and the geographical extent of the processing.
Matching or combining datasets? No.
Data concerning vulnerable data subjects? Yes. The processing may concern vulnerable data subjects, in particular children and employees present in the monitored environment. It may also concern, for example, elderly persons or persons with mental illness. Employees may be considered vulnerable due to the imbalance in the employment relationship, and children and other vulnerable individuals may have limited ability to understand or object to the processing.
New technology such as processing of biometric data for the purpose of identifying a natural person? No.
Processing which in itself "prevents data subjects from exercising a right or using a service or a contract"? No.

Purpose of the processing

Personal data collected via the Solution is processed for the purpose of providing video analytics services in connection with existing camera infrastructure and converting camera-based input into actionable operational information. Personal data derived from video streams is first anonymised and thereafter processed to detect, classify, analyse and assess events, actions and other circumstances relevant to the applicable use case, and to generate alerts, analyses, recommendations and other operational outputs.

The processing is necessary to detect, classify, analyse and assess events, conditions and other circumstances relevant to the applicable use case. Less intrusive alternatives include not using video analytics, relying solely on manual monitoring or limiting processing to static images or heavily filtered footage. These alternatives have not been chosen because they would not achieve the purpose of the service, which depends on the interpretation of continuous video data, including its temporal and contextual information.

Legal basis

The legal basis for the processing is legitimate interest. Only personal data relevant to the applicable use case and required to analyse video streams, generate operational outputs, and maintain the Solution is processed. Faces of natural persons are blurred to reduce intrusiveness. Personal data deriving from video material is processed in real time and is not stored unless the Solution detects an action which triggers a notification to users.

Data processed

The following categories of personal data may be processed:

  • IP addresses.
  • Contact information.
  • Images containing individuals.

A large number of data subjects may be affected, as the processing may capture all individuals who enter the cameras' field of view within monitored areas. Personal data is collected primarily from the Controller's existing camera infrastructure through real-time video feeds covering monitored areas.

Data transfers

Only those individuals at the Controller, or where applicable at preventai as processor, who need access to personal data in order to perform their duties will have access to it. Personal data deriving from video material can only be transferred to a third party in an anonymised form. Categories of recipients may include:

  • Suppliers and subcontractors supporting technical operations, IT systems, maintenance, and related business functions.
  • The Controller's authorised personnel and, where relevant, other entities acting as independent data controllers.
  • Courts, supervisory authorities, law enforcement authorities and other public bodies where disclosure is required by applicable law, regulation, government decision or court order.
  • A buyer, investor or other third party in connection with a merger, restructuring, sale or transfer, subject to appropriate safeguards.

Security of personal data

Access to the data should, to the greatest extent possible, be allocated by the customer and limited on a strict need-to-know basis. Technical and organisational measures include:

  • Regular security scans of the codebase are conducted.
  • Identity and access management controls.
  • All employees undergo recurring data security training.
  • All security procedures are regularly assessed and evaluated.
  • All activities on servers are logged to identify potential suspicious traffic and unauthorised access.
  • All statistical output is anonymised.
  • All employees work on dedicated encrypted workstations with private access, secured by multi-factor authentication.
  • Personal data is processed only in secure physical locations with restricted access.
  • Remote access to internal systems is restricted to authorised users and devices via an encrypted VPN connection, using identity-based authentication as well as deny-by-default and least-privilege access policies.

Data subjects' rights

In connection with the camera surveillance, data subjects should be provided with clear information regarding the surveillance by the Controller. Preventai will assist the Controller in fulfilling data subjects' rights. Information provided to the data subjects by the Controller should include, as applicable:

  • The purpose of the camera surveillance.
  • The identity of the Controller.
  • Contact details of the Controller.
  • Information that data subjects have rights under the GDPR.
  • Any circumstances that may be unexpected for the data subject, such as audio recording or storage of surveillance material outside the EU/EEA.
  • How long surveillance material is stored, or the criteria used to determine the retention period.
  • Where data subjects can turn to obtain additional information about the surveillance.
  • The legal basis relied upon for the surveillance, usually legitimate interests.
  • If the legal basis is legitimate interests, information on why camera surveillance is necessary and how the balancing test has been carried out.
  • Whether recorded material will be shared with any third party, such as an alarm company or similar recipient.
  • The rights available to data subjects in relation to the processing, including the right to request erasure and the right to access surveillance material in which they appear.
  • Information that data subjects may lodge a complaint with the relevant data protection supervisory authority if they consider the surveillance to be unlawful.

Proportionality of interests

The expected attitude from data subjects is likely to be broadly neutral to cautiously accepting, provided that clear information is made available about the processing. The technology is an extension of already widely used camera surveillance and is intended to support security-related purposes. The impact on most data subjects is limited, since individuals are anonymised through facial blurring, personal data related to processed video is not stored, and no action is taken in relation to almost all data subjects.

The processing should generally be expected by data subjects, as it is carried out in connection with camera surveillance in monitored areas. That said, data subjects should be clearly informed that AI-based real-time analysis is used, as this may not otherwise be apparent to them.

The processing is proportionate because it serves a legitimate purpose — supporting security, loss prevention and operational awareness — while measures have been implemented to reduce the impact on data subjects' privacy. The impact is further mitigated by irreversible facial blurring, the absence of facial recognition or personal identification, no connection to external databases, and no storage of personal data from real-time analysis.

FRIA (Fundamental Rights Impact Assessment)

General information about fundamental rights

A Fundamental Rights Impact Assessment ("FRIA"), according to the European Union's Artificial Intelligence Act, evaluates how a system may affect individuals' rights and freedoms, even in cases where specific regulatory classifications do not require formal high-risk treatment. The purpose of such an assessment is to identify, analyse, and mitigate potential impacts arising from the deployment and use of the system, particularly in environments where individuals may be subject to monitoring.

Background and scope

Based on the assessment that the Solution does not classify as a high-risk AI according to the AI Act, there is no obligation for the Deployer to carry out a FRIA. However, preventai still provides a FRIA based on the key provisions of Article 27 of the AI Act to enable the Deployer to carry out an assessment of the Solution's impact on fundamental rights.

Description of the processes of the Deployer

The Solution connects to existing video surveillance infrastructure in certain environments and uses artificial intelligence to detect events indicative of, for example, shoplifting or other loss-prevention-relevant events in real time, sending notifications to personnel for assessment at their discretion. All images and video material are automatically and irreversibly anonymised. The Solution does not process the emotional states of any natural person. It operates exclusively at the level of action detection.

Time period and frequency

From the first day of deployment, the Solution will operate continuously during all hours, analysing camera footage to detect actions indicative of shoplifting or other loss-prevention-relevant events. The number of classification outputs generated will depend on the number of individuals present within the range of the camera surveillance system.

Categories of registered individuals

  • Visitors in the surveyed area.
  • Particularly vulnerable groups among customers or visitors, including elderly persons, children, and individuals whose appearance may reveal, for example, information regarding religion.
  • Employees and other personnel present during surveyed hours.
  • Third parties temporarily present in the surveyed area, for example, third party security personnel.

Specific risks of harm

Article 27(1)(d) of the AI Act requires that the FRIA specifically identify the risks of harm that the use of the AI system is likely to pose to affected individuals. Risk shall be understood as the combination of the likelihood of harm occurring and the severity of that harm.

Category Description of risk Fundamental right affected Likelihood Severity Cumulative impact
Customers and visitors Continuous recording and analysis of the individuals without the individual's knowledge. The right to privacy and the protection of personal data (Articles 7 and 8 of the EU Charter of Fundamental Rights). High. The system is active throughout the periods during which the individuals are surveyed. Low. None.
Employees and other personnel Constant surveillance during working hours. The right to privacy and the protection of personal data (Articles 7 and 8 of the EU Charter of Fundamental Rights) and workers' rights. High. Employees and other personnel are likely continuously within the surveyed range. Low. None.
Third parties temporarily present on the premises, such as security guards Third parties temporarily present on the premises are exposed to the Solution's continuous recording and analysis. The right to privacy and the protection of personal data (Articles 7 and 8 of the EU Charter of Fundamental Rights). High. Low. None.
Other individuals who are not present within the surveyed area but who move within the outer range of the cameras The use of a camera-based AI system with an operational range extending beyond the premises may produce an indirect effect on the freedom of assembly and movement of individuals present in the surrounding public space if the cameras are angled in a faulty way. The right to privacy and the protection of personal data (Articles 7 and 8 of the EU Charter of Fundamental Rights). Low. Requires that the Deployer angles surveillance cameras in a wrongful manner. Medium, following a possible expectation of privacy. Yes, in cases of wrongful continuous exposure where the camera covers a public area.

Measures for human oversight

The Solution does not take autonomous action in response to detected events. It sends notifications to users, who retain full discretion as to how, or whether, to respond. The Solution does not trigger automated interventions such as locking mechanisms, direct alerts to law enforcement, or any other measure that would produce legal or similarly significant effects on natural persons without human intervention.

To use the Solution, it is required to have knowledge of how to use it correctly. The users must also follow internal procedures on how to manage situations involving suspected theft, damage to property, and similar conduct. In those situations that have been identified due to the Solution, any potential measure and the rationale for the measure shall be documented in writing in an appropriate manner.

Every space can be intelligent.
Tell us what you need to detect. We'll show you how Antrino connects to your current setup.