Skip to content

Responsible Vision AI under GDPR, NIS2 and the AI Act

shopping center monitored by smart cameras

Cameras are becoming increasingly intelligent. Where video surveillance once mainly revolved around watching, recording and reviewing footage after an event, Vision AI can now recognise situations automatically, count objects, track movement and bring relevant events to immediate attention.

At the same time, the European legal and regulatory landscape for cameras, data, AI and resilience is becoming more demanding. The GDPR requires organisations to examine which personal data they process and why, while the EU AI Act sets requirements for the responsible use of AI. NIS2 and the Critical Entities Resilience (CER) Directive introduce a shared European framework for digital and physical resilience. However, these directives are implemented through national legislation, so their names, effective dates, scope and supervision can differ between countries.

This calls for a more critical look at existing security measures. Are cameras only there to retrieve footage after an incident, or do they actually help identify risks earlier and enable a faster response? This creates a clear tension: organisations need to see more, without processing more data than necessary. That is precisely where the next generation of Vision AI can play an important role.

More cameras are not automatically the answer

Many organisations already operate anywhere from dozens to thousands of cameras. The question is therefore no longer how to obtain more footage, but how to extract exactly the information that is needed from existing video. A traditional system records what happens and requires an operator to monitor live feeds or search retrospectively — a task that becomes increasingly difficult as the number of cameras grows.

Vision AI adds an intelligence layer: it recognises predefined events and only calls for attention when something relevant occurs, such as a person entering a restricted area, a blocked emergency exit or visible smoke. In this way, the camera increasingly becomes a sensor that delivers not only video, but information.

New legislation changes the question

NIS2 focuses on digital resilience, while the CER Directive addresses the physical resilience of critical entities. The exact obligations arise from each country’s implementing legislation. The relevant question is no longer simply whether a fence, access-control system or camera is present, but whether risks are identified in time and whether the organisation can respond effectively.

Vision AI is not an off-the-shelf compliance solution, but it can transform existing camera infrastructure from passive recording into active detection and verification. At the same time, the GDPR, the EU AI Act and applicable national laws continue to set boundaries for how the technology may be used.

Do not analyse everything simply because you can

A modern Vision AI platform can do a great deal: detect people and vehicles, analyse routes, measure waiting times and read licence plates. But that does not mean all these capabilities should be deployed at the same time. Responsible use of cameras begins not with the technology, but with the purpose: what does the organisation want to achieve, and what is the minimum information required to do so?

The question is therefore not what AI is capable of recognising, but what AI needs to recognise for this specific purpose. An airport analysing queues does not need to know the identity of individual passengers. A factory keeping an emergency exit clear does not need to determine which employee is nearby. For intrusion detection, it is often enough to establish that someone has entered a restricted area.

Seeing more can also mean processing less

That may sound contradictory, but AI can make data processing more targeted. Not everything that is technically visible is relevant to the purpose. Instead of requiring continuous human attention across hundreds of video streams, the system looks for a predefined situation: camera → AI analysis → relevant event → alert → human review. More intelligence does not automatically mean more personal data. Vision AI can instead define much more precisely which information is needed — and which is not.

From automated decisions to automated attention

Even after a detection, AI does not have to make the final decision automatically. Establishing that someone has remained in a restricted area for more than two minutes is a technical observation; concluding that the person has malicious intent is something entirely different. Human review is therefore essential in many applications. Vision AI primarily functions as a system for automated attention: not ‘AI has decided that this person is suspicious’, but ‘something here meets the predefined criteria — take a look’. Operators no longer need to monitor hundreds of camera feeds continuously. AI filters out the relevant moments, after which a person assesses the context.

From camera network to information infrastructure

European legislation on digital and physical resilience makes this development even more relevant. Many organisations originally purchased their camera network as a security measure. With Vision AI, the same infrastructure can become part of a broader information system, for example by detecting unauthorised access, tailgating or anomalies around critical assets. A camera system can therefore evolve from a passive resource for retrospective review into an active source of information for the here and now.

Technology alone, however, is not enough. Vision AI does not automatically make an organisation compliant with the GDPR, the EU AI Act or national legislation implementing NIS2 and CER. Responsible use ultimately depends on the application, configuration, processes, documentation and level of human oversight.

Start with the question, not the analytics

The best Vision AI projects do not begin with a list of features, but with one question: what problem are we trying to solve? Only then should an organisation determine which information is required, which data does not need to be processed and who ultimately makes the decision.

With the GDPR, the EU AI Act and the national frameworks implementing NIS2 and CER coming together, this way of thinking is becoming increasingly important. The future of video surveillance is not about deploying as much AI as possible, but about using the right AI, for the right purpose, at the right time. See more. Process less. Make better decisions.

Henk-Jan Hop

Smart cameras. Smarter insights.

Also interesting to read

Bas Commandeur

Sales Support
Contact

Contact

Bas Commandeur

Sales Support
Contact

Demo aanvragen

Bas Commandeur

Sales Support
Contact

Contact (ENG)

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Request a demo

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Demo aanvragen (DUI)

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Contact (DUI)

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Word een partner!

"*" indicates required fields

1Bedrijfsgegevens
2Persoonsgegevens
3Diensten
Bedrijfsnaam
Adres*

Bas Commandeur

Sales Support
Contact

Download de VAIBS Brochure (NL)

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Download de VAIBS Brochure (ENG)

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Download de VAIBS Brochure (DUI)

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Download de whitepaper gezichtsherkenning

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Download de VAIBS Brochure Zorg (NL)

"*" indicates required fields

Bas Commandeur

Sales Support
Contact

Become a Partner!

"*" indicates required fields

1Company details
2Personal data
3Services
Type of partner
Company name
Address*

Bas Commandeur

Sales Support
Contact

Werden Sie Partner!

"*" indicates required fields

1Unternehmensdaten
2Persönliche Daten
3Dienstleistungen
Partnerkategorie
Firmenname
Adresse*