Regulatory classification of an anonymous counting system

EU AI Act, people counting and risk classes; Cyber Resilience Act, video analytics and security duties; and procurement documents: people counter buyers ask for them in every tender. How we classify Vicodis — and why.

This page sets out our own assessment. It is not legal advice; for a binding classification, involve your legal department or data protection officer.

EU AI Act

How a people counter is classified under the EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) sorts AI systems by risk. It prohibits a small number of practices, sets strict rules for high-risk systems and leaves everything else largely free. AI Act classification — counting system or surveillance tool? The decisive lists are the prohibitions in Article 5 and the high-risk areas in Annex III — above all biometric identification, biometric categorisation and emotion recognition.

Anonymous counting does none of these. In our assessment it is a minimal-risk application. Two details matter:

  • The detection itself is done by AXIS Object Analytics, the analytics built into the Axis camera. Vicodis receives its counting events and turns them into figures.
  • Organisations that use AI systems have a general duty to ensure sufficient AI literacy among the staff who work with them (Article 4) — a short briefing usually covers this for a counter.
The key distinction

Why anonymous counting is not biometric categorisation

Biometric categorisation assigns individuals to categories based on their biometric data — for example by age, sex or ethnicity. Biometric data, in turn, is data from specific technical processing of physical features that allows or confirms the unique identification of a person.

A counter that recognises “a person” crossing a line uses neither. It does not identify anyone, does not sort anyone into categories and keeps nothing but the number.

  • No identification of individuals, not even within a visit.
  • No categories such as age, sex or ethnicity.
  • No emotion recognition and no behavioural profiling.
Cyber Resilience Act

Cyber Resilience Act obligations

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets security requirements for products with digital elements, which includes software such as Vicodis. Its reporting duties for actively exploited vulnerabilities apply from 11 September 2026; the main obligations follow from 11 December 2027.

For manufacturers, the core duties are security by design, handling vulnerabilities over a defined support period, providing security updates and documenting the product, including its software components. Several properties of Vicodis help here:

  • Small attack surface: no cloud connection, no remote service, no own user database — access runs through the camera’s accounts.
  • Signed licences: licence and deletion keys are cryptographically signed and checked offline.
  • Known components: third-party software (such as SQLite and OpenSSL) is listed in the app.

Security updates for Vicodis are provided free of charge for every licence, independent of Vicodis Care: when something critical is fixed, every customer receives the new version. New versions with additional functions are part of Vicodis Care and supplied on request.

Support period: every Vicodis licence receives security updates for at least five years from purchase — the minimum the CRA sets for products expected to be used at least that long. The exact end date of the support period is stated at purchase.

Deletion

The Sensor Master Key deletion mechanism

Counting data on a Vicodis camera cannot be deleted from the dashboard. Deletion needs a Sensor Master Key: a signed, one-time key that we issue on request for one specific camera.

For procurement this matters twice: figures used in reports cannot be wiped by accident or without authorisation, and there is still a controlled way to delete them — for example when a camera moves to another site or a rental set comes back.

Sensor Master Key
Issued byData Components, on request
Valid forone camera, once
Deletescounting data
Keepslicence and configuration
Tenders

Documents available for procurement

Procurement documents for a people counter answer the questions a tender asks: where data is processed, what is stored, which components are inside and how the product is classified. Ask us for the current set at sales@datacomponents.de; the data protection side is explained on people counting and the GDPR, the company behind it on who builds Vicodis, and maintenance on support and Vicodis Care.

  • Description of the data flow
  • Technical product description
  • List of third-party software components
  • Our AI Act classification in writing
FAQ

Questions about regulation

01

Is people counting a high-risk AI system under the EU AI Act?

In our assessment, anonymous people counting is not. The high-risk and prohibited categories concern identifying people, categorising them by sensitive traits or recognising emotions. A counter that detects a person crossing a line and keeps only the number does none of that. Your own legal assessment remains decisive.

02

When does the Cyber Resilience Act apply to counting software?

The reporting duties for actively exploited vulnerabilities apply from 11 September 2026, the main obligations from 11 December 2027. From then on, software such as Vicodis must meet security requirements over a defined support period, including vulnerability handling and security updates. Vicodis receives free security updates for at least five years from purchase.

03

Can the counting data be deleted for good?

Yes, with a Sensor Master Key. It is a one-time deletion key that we issue for one specific camera on request. It deletes the counting data only; licence and configuration stay. Because the key works once and only on that device, no one can wipe figures by accident or without authorisation.

How many visitors does your entrance really have?

Tell us your camera model or your project — we check compatibility and come back with a concrete proposal.