- The EU AI Act is risk and use-case based; not every AI CCTV or behavioural-analytics system is automatically high-risk.
- UK GDPR requires appropriate safeguards, but it does not make dedicated cable runs a universal legal requirement.
- Biometric recognition requires an Article 6 lawful basis and a separate special-category condition; explicit consent is not always the only or appropriate route.
Regulation is catching up with AI deployment
The EU AI Act entered into force in August 2024 and applies through a phased implementation timetable. In the UK, AI remains governed through existing law, sector regulators and developing policy rather than a direct copy of the EU Act. AI-enabled CCTV, biometrics, access control and occupancy analytics may also engage UK GDPR and sector-specific duties. The exact position depends on the use case, people affected and where the system is placed on the market or used.
This guide focuses on how infrastructure can support proportionate safeguards. It is general technical information, not legal advice, and the controller, data-protection lead or legal adviser should confirm the obligations for the proposed deployment.
The EU AI Act and UK AI regulation: infrastructure requirements
The EU AI Act uses a risk-based framework. Some biometric identification, biometric categorisation and emotion-recognition uses are prohibited, high-risk or subject to transparency duties, depending on the context and exceptions. AI-enabled CCTV or behavioural analytics is not automatically placed in one category solely because it uses AI. Classification must be assessed against the Act and current Commission guidance.
Where the AI Act or another regime requires logging, records, human oversight or security controls, the supporting network and storage should be designed to preserve availability, access control and auditability. The required retention period and log content depend on the applicable rule and system role.
For UK organisations, relevant controls may arise from UK GDPR, the Data Protection Act, surveillance guidance, equality law, sector rules and contractual requirements. The UK approach continues to evolve, so do not present EU obligations as automatically applying to a UK-only deployment.
An AI CCTV system that captures facial recognition data and stores it on a network that is not adequately segmented from other business systems creates a data protection liability, not just a technical risk.
UK GDPR requires data protection by design and appropriate technical and organisational measures. It does not prescribe dedicated cable runs. Logical segmentation, physical separation, encryption, identity controls, monitoring and comms-room security are design options whose proportionality should be assessed for the specific risk.
The network and storage infrastructure behind AI audit trails must be specified, documented and demonstrably fit for purpose.
ICO guidance on AI and surveillance
For biometric recognition, the ICO requires an Article 6 lawful basis and a separate condition for special-category biometric data, together with fairness, transparency, necessity and security. A DPIA is required where processing is likely to result in high risk. Signage and retention controls depend on the surveillance context and should be defined by the controller.
Infrastructure can support those obligations through controlled access, appropriate segmentation, encryption-capable systems, reliable time and logging, secure storage and documented change control. Dedicated physical infrastructure may be selected for higher-risk environments, but it is not a universal ICO requirement.
What compliance frameworks require at the physical infrastructure level is far less understood than their software and governance requirements.
The compliance checklist for AI infrastructure specification
- Network segmentation: place surveillance, access-control and other operational systems in an approved security zone using VLANs, firewalls or dedicated infrastructure as required by the risk assessment
- Comms room access control: restrict and record access where proportionate to the systems and data housed in the room
- Storage infrastructure: define access, encryption, backup, retention and secure deletion requirements with the controller and system provider
- Cabling documentation: maintain labels and as-built records so connections can be traced and changes reviewed
- DPIA records: document relevant infrastructure and security measures where the system’s DPIA or governance process requires them
- Transparency: provide notices and signage appropriate to the surveillance use and the controller’s ICO obligations
Biometric data used to uniquely identify a person is special-category data. The controller must identify an Article 6 lawful basis and a separate Article 9 condition before processing begins. Explicit consent may be suitable where people have a genuine choice, but it is not the only possible basis and may be inappropriate where consent cannot be freely given.
The infrastructure should implement the safeguards selected through the DPIA and security design, which may include encryption, restricted administration, segmentation, audit logs, resilience and controlled physical access. ACCL can deliver the agreed passive and physical-security elements, but legal compliance remains the responsibility of the controller.
Standards and sources
- European Commission: AI ActRisk-based EU regulatory framework and implementation information
- EU high-risk AI guidanceGuidance for assessing whether a system is high-risk
- ICO biometric recognition guidanceUK data-protection requirements for biometric recognition
- ICO DPIA guidanceAssessing high-risk processing
Frequently asked questions
Does the EU AI Act apply to UK businesses?
It can apply where a UK organisation places an AI system on the EU market, provides it for use in the EU or deploys it in circumstances within the Act’s territorial scope. A UK-only system is not automatically governed by the EU Act, although UK GDPR, sector rules and other law may still apply. Obtain legal advice for the specific deployment and implementation date.
Is AI-powered CCTV compliant with UK GDPR?
It can be, but compliance depends on purpose, necessity, lawful basis, transparency, retention, security and the rights and risks of the people affected. Facial or other biometric recognition adds special-category requirements. Behavioural analytics does not automatically create biometric data, but it can still process personal data. The controller should follow current ICO surveillance, AI and biometric guidance.
What is a Data Protection Impact Assessment and when is it required for AI systems?
A DPIA is a structured assessment required where processing is likely to result in high risk to individuals. Systematic monitoring, biometric recognition and other intrusive uses are common triggers. It should cover purpose, necessity, data flows, people affected, risks, safeguards, access, storage, retention and residual risk. The controller should complete it before deployment and keep it under review.
Does physical network separation count as a GDPR security measure?
It can be one technical measure, but UK GDPR does not make it mandatory for every AI or biometric system. The appropriate design may use logical segmentation, dedicated infrastructure or a combination of controls. The controller should select measures proportionate to the risk and document the reasoning in its security and data-protection process.
