(Editor’s note: This post on security tech is presented by Coram AI and is part of Dispatches Tech Tuesday series. Dispatches covers tech because so many of our highly skilled internationals are executives, managers and decision makers.)
Put a security camera on a wall in Austin and a security camera on a wall in Eindhoven and you may well be looking at the same hardware. What differs is the question the buyer asked before it went up.
In the US the question has become: who made this box, and where were the chips from? In Europe the question is: what is this thing allowed to do with what it sees, and who has to be told about it?
Those two questions have been pulling the industry in different directions for about five years now, and the gap is about to get wider in a way that will show up in products you actually use.

America is regulating the supply chain
The American approach started with procurement and never really left. Section 889 of the 2019 National Defense Authorization Act barred federal agencies, contractors and recipients of federal money from buying video surveillance gear from a named list of Chinese manufacturers. The FCC then added an equipment authorisation layer in 2022, which meant certain kit could not be certified for sale at all when destined for public safety or critical infrastructure use.
The interesting part is that this has not slowed down. It has accelerated. On 26 June this year the FCC issued a notice prohibiting the import and marketing of covered equipment that had been authorised before those 2022 rules came in, closing off legacy models that were still legally circulating. There is a wrinkle: the piece of that prohibition tied to physical surveillance of critical infrastructure is on hold until the Commission settles on a new definition of what critical infrastructure means, which tells you something about how fast the rules are being written relative to the vocabulary they need.
And the list keeps growing in scope. On 28 July, one day before I wrote this, the FCC added foreign-produced power inverters and robots to the same covered list. Cameras were the beginning, not the boundary.
None of this says anything about what a camera may record, how long the footage can be kept, or whether a company can run facial recognition on its own staff. That is left largely to individual states and, in practice, to whatever the vendor decides to ship.
Europe is regulating the behaviour
Europe went the other way, and mostly did not go after manufacturers at all. There is still no bloc-wide ban on Chinese camera makers. The European Parliament pulled Hikvision equipment from its own premises, Lithuania restricted it nationally, Amsterdam moved to get Chinese-made cameras out of city systems, but the EU as a body has never issued the sort of blanket procurement prohibition Washington reaches for first.
What Europe regulates instead is conduct. GDPR already made a camera pointed at a workspace a data processing activity that needs a lawful basis, a retention period and a defensible answer to why less intrusive means would not do. Then the AI Act layered rules on top of the analytics.
That second layer is arriving right now, and the timeline has been messier than anyone planned. The AI Act’s outright prohibitions, which include untargeted scraping of facial images and most real-time remote biometric identification in public spaces by law enforcement, have been in force since February 2025. The big compliance date for high-risk systems was supposed to be 2 August 2026, earlier this month.
It moved. The European Commission proposed a package known as the Digital Omnibus on 19 November 2025, largely because the machinery required to comply, harmonised technical standards and designated national authorities, was not ready. Parliament endorsed it on 16 June 2026 by 423 votes to 57 with 174 abstentions, and the Council signed off on 29 June. Standalone high-risk systems under Annex III, a category that explicitly covers biometric identification and categorisation as well as employment-related AI, now have until 2 December 2027.
AI embedded in regulated products gets until August 2028.
But the transparency duties did not move, and this is where people get caught out. From 2 August 2026, if you deploy a system that does emotion recognition or biometric categorisation, you have to tell the people subjected to it.
That obligation lands regardless of the delay everyone read about in the headlines. Marking rules for systems already on the market, plus some new prohibitions, follow on 2 December 2026.
There is a third layer that American vendors consistently underestimate. In Germany and the Netherlands, works councils have co-determination rights over the introduction of technical systems capable of monitoring employee behaviour.
A German employer cannot simply switch on a new analytics feature across its offices because head office in California pushed an update. Somebody has to sit in a room and agree to it first.
What this does to the products
Start with where the video lives. American buyers moved to cloud video fast, because the pitch was irresistible: no server room, automatic updates, watch your sites from a phone. The US cloud-native vendors built their whole product philosophy around that, Verkada and Coram among them, and they compete mainly on how quickly the software surfaces something a human should look at.
European buyers wanted the same convenience and then asked where the footage would physically sit, who could subpoena it, and what happens when a data protection authority asks for a processing record. So the European market kept hybrid and on-premise architectures alive far longer, and the region’s established vendors, Axis in Sweden, Milestone in Denmark, Bosch in Germany, built businesses on open platforms and local control rather than a single hosted stack.
The result is that the same product now ships differently on each side of the Atlantic. Retention defaults are shorter in Europe. Some analytics features are switched off or unavailable entirely. Audit logging is more detailed, because somebody may have to prove who looked at what. Consent and notice workflows exist in the European build and are often absent from the American one.
Look at the roadmaps and the divergence gets clearer. American product teams are mostly adding capability: more detection classes, more automation, more AI. European product teams are increasingly adding provable restraint. Documentation, explainability, data minimisation by default, region-locked processing. Those are features too, they just do not demo as well.
Why this matters if you work in tech here
If you are an engineer or product person at a European company, two things follow:
• The compliance layer is becoming the product, not a tax on it. Whoever can ship an AI system in Europe with the documentation, logging and notice flows already built in has a real commercial advantage over a competitor bolting it on in 2027. That is a genuine engineering problem and it is being staffed for now, not later.
• And the transparency obligations attach to deployers, not only to the companies that build the systems. If your employer runs anything that infers emotional state or categorises people biometrically – and plenty of retail analytics and workplace safety tools quietly do – the duty to inform people sits with your employer from 2 August. It is worth knowing whether anyone at your company has noticed.
What to watch
Three things over the next 18 months:
• Whether the Commission’s final Article 6 guidelines, due by the end of this year, pull ordinary building security analytics into the high-risk category or leave them outside it.
• Whether Europe ever follows the American instinct and names manufacturers rather than behaviours.
• And whether the US moves in Europe’s direction on use, which state privacy laws have started doing in patches.
This is not really a race, and neither side is obviously winning. Washington has bet that the risk lives in the supply chain, that the danger is who built the device. Brussels has bet that the risk lives in the use, that the danger is what the device is permitted to do once it is on the wall.
Both bets are defensible. They just produce very different buildings.
