Worker-monitoring AI in supplier factories: AI Act and labour-law risks
Productivity tracking, camera analytics and emotion detection on factory floors raise legal and ethical questions for brands that source in Europe and beyond.

KEY TAKEAWAYS Summary by the editors
- Article 5 of the EU AI Act prohibits using AI to infer the emotions of people in the workplace, except where intended for medical or safety reasons, and this ban has applied since 2 February 2025.
- Annex III of the AI Act lists as high-risk the AI systems used to allocate tasks based on individual behaviour or personal traits, or to monitor and evaluate the performance and behaviour of workers, with obligations now applying from 2 December 2027.
- The Act can reach non-EU providers and deployers where the output of the AI system is used in the Union, but whether a given supplier factory falls within scope depends on the facts and needs legal advice.
- Under Article 26, employers that deploy a high-risk system at work must inform workers' representatives and affected workers before putting it into service.
- Brands face reputational and contractual exposure even where the AI Act does not apply directly, so buyers should ask suppliers what monitoring technology is in use and on what legal basis.
Worker-monitoring AI in supplier factories raises two kinds of risk for fashion brands: direct legal exposure under rules such as the EU AI Act, and indirect exposure through supply chain due diligence and reputation. The Act bans workplace emotion inference outright and treats AI used to monitor and evaluate workers as high-risk, so brands that source from factories using such tools should understand where the lines are, even when the factory is outside the EU.
What is worker-monitoring AI in a garment factory?
The term covers software that observes or scores workers. In apparel and footwear production the typical forms include camera analytics that track output per workstation, sensors and software that time sewing operations, systems that assign tasks or set targets from individual speed, attendance and access systems with biometric features, and tools that claim to read fatigue, attention or mood from faces or voices. Some are sold as efficiency or safety products. The legal question is what the system infers, how the results are used and who is affected.
What does the AI Act say about monitoring workers?
Two provisions matter most. First, Article 5(1)(f) prohibits the use of AI systems to infer the emotions of a natural person in the areas of workplace and education institutions, except where the system is intended to be put in place or on the market for medical or safety reasons. The prohibitions have applied since 2 February 2025. Fines for prohibited practices can reach EUR 35 million or 7 per cent of worldwide annual turnover, whichever is higher.
Second, Annex III treats as high-risk the AI systems intended to be used to make decisions affecting terms of work-related relationships, promotion or termination, to allocate tasks based on individual behaviour or personal traits or characteristics, or to monitor and evaluate the performance and behaviour of persons in such relationships. Following the digital omnibus, the obligations for stand-alone Annex III systems apply from 2 December 2027. Deployers under Article 26 must, among other things, use the system according to the provider's instructions, assign competent human oversight, keep logs under their control for at least six months and inform workers' representatives and affected workers before use at work.
| Tool | What it does | Likely AI Act position |
|---|---|---|
| Emotion or fatigue detection from faces or voices | Infers emotional state of workers | Prohibited in the workplace under Article 5(1)(f), unless for medical or safety reasons |
| Per-worker productivity scoring | Evaluates individual performance | Potentially high-risk under Annex III point 4(b), from December 2027 |
| Task allocation by individual speed | Assigns work based on behaviour or traits | Potentially high-risk under Annex III point 4(b) |
| Safety camera detecting missing protective equipment | Flags safety conditions | Depends on design and use; assess classification and data protection |
| Aggregate line-balancing software | Plans workloads without scoring individuals | Likely outside Annex III if it does not evaluate individuals; verify |

Does the AI Act apply to a factory outside the EU?
Not automatically. Article 2 covers providers placing systems on the EU market, deployers located in the EU, and providers and deployers in third countries where the output produced by the AI system is used in the Union. A factory in a non-EU country that monitors its own workers, with outputs used only locally, is a different case from an EU-based brand that buys a monitoring system, or that receives and uses per-worker outputs from supplier systems. Where the line falls depends on facts such as who operates the system, where the output is used and for what decisions. This is a point for legal advice, and the article should not be read as a ruling on any specific supply chain.
A further caution is that scope under the AI Act is only one layer. Data protection law, labour law and works council or consultation rules apply in the countries where workers are employed, and EU data protection law continues to apply alongside the AI Act. Local rules on workplace surveillance vary widely and need local advice.
Why should brands care even if the Act does not apply?
Brands have three reasons. First, reputation: monitoring of low-paid workers by AI attracts press and civil society attention, and brands are linked to their suppliers' conditions. Second, due diligence: buyers increasingly ask suppliers about working conditions, and intrusive monitoring that affects pay, breaks or dignity belongs in that conversation. Third, data flows: if monitoring data reaches EU-based buyers or group companies, the brand may become a user of those outputs and carry duties it did not anticipate.
What can buyers and sourcing teams ask suppliers?
A short questionnaire adds information without turning into an audit of every system. Useful questions include:
- Which AI or analytics systems monitor workers or score their performance, and who supplied them?
- What does each system infer: output, attendance, safety conditions, emotions or fatigue?
- Are workers and their representatives told about the monitoring, and how?
- Is the data used for pay, discipline, promotion or dismissal decisions?
- Is any monitoring data shared with the brand or its agents, and in what form?
- What local legal basis does the supplier rely on, and has it been reviewed?
How should a brand handle monitoring data it receives?
Treat it as sensitive. Prefer aggregate indicators, such as line efficiency or defect rates, over individual-level outputs. Avoid asking for per-worker scores unless there is a clear and lawful purpose, because holding them can create obligations and risks. Put restrictions in supplier agreements: no emotion inference, no use of monitoring data as the sole basis for dismissal, and a duty to inform workers.

What are the open questions?
Several questions remain unsettled. Regulators and courts have yet to say how far the Act reaches into non-EU supplier operations through the output-used-in-the-Union test. The boundary between safety uses, which are excepted from the emotion-inference ban, and welfare or productivity uses is likely to be argued. And the high-risk rules for worker management will only apply from December 2027, so guidance and standards are still developing. Brands can act early by mapping what their key suppliers use and setting expectations in contracts.
Frequently asked questions
Is emotion recognition in factories banned in the EU?
Article 5(1)(f) of the AI Act prohibits using AI to infer the emotions of a person in the workplace and in education, except for medical or safety reasons. The prohibition has applied since 2 February 2025.
Is productivity-tracking AI high-risk under the AI Act?
Annex III lists AI systems intended to monitor and evaluate the performance and behaviour of workers, and to allocate tasks based on individual behaviour or personal traits, as high-risk. Those obligations now apply from 2 December 2027, depending on the system's design and use.
Does the AI Act apply to my suppliers in Asia?
Possibly, but not automatically. Article 2 covers third-country providers and deployers where the AI system's output is used in the Union, so the answer depends on who operates the system and where its output is used. Seek legal advice for specific cases.
What must employers do before using high-risk AI on staff?
Under Article 26, employers deploying a high-risk system at work must inform workers' representatives and the affected workers before putting it into service or using it, in addition to oversight, input data and log-keeping duties.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- AI Act Service Desk (artificialintelligenceact.eu): Article 5, Prohibited AI practices
- AI Act Service Desk (artificialintelligenceact.eu): Annex III, High-risk AI systems
- AI Act Service Desk (artificialintelligenceact.eu): Article 26, Obligations of deployers of high-risk AI systems
- AI Act Service Desk (artificialintelligenceact.eu): Article 2, Scope
- AI Act Service Desk (artificialintelligenceact.eu): Article 99, Penalties




