← All posts
privacy · biometrics · trust

Why we do not do facial recognition, and why that is what makes the rest credible

Places and situations, never persons. The choice costs us use cases; it gives us a tool a works council can accept and a regulation can classify without ambiguity.

By Oussama Messai Published 25 September 2026 5 min read Lire cet article en français
Warehouse camera image with people blurred, the emergency exit zone highlighted

When we explain that Camly does not do facial recognition, the most common reaction is a polite nod. The second, less common but more interesting, is: “But you could.” Yes. We could. This post explains why we do not, what it costs us, and why it is precisely what makes the rest of the product credible.

The design choices, one by one

“No facial recognition” is not a box ticked. It is a series of decisions that hold together, and that only hold if you take all of them.1

DecisionWhat it guarantees
Findings are about places and situationsA blocked exit is a finding; “so-and-so blocked the exit” is not
People are blurred by default on stored imagesNo image in the history lets anyone be recognised
No biometrics, no identificationThe system has no notion of “who”
The chat refuses by design any question about an employee“Who was there at 10:20?” gets no answer, and the refusal is visible
Exported data are at zone levelTask, zone, camera, time, duration, description; never an operator identifier, a badge, a plate
No possible join with per-operator WMS recordsEven crossing Camly with scan logs does not reconstruct a person’s activity

Each line closes a door. Leave a single one open and the promise “we watch places, not people” becomes a commercial promise, that is, one the client is asked to believe. We prefer it to be a property of the product, one the client can verify.

The conversation with the works council

In a warehouse, any project touching the cameras goes through the works council. That is where the difference between “we do not do it” and “we cannot do it” becomes concrete.

A tool that could identify people but promises not to triggers the right questions: who guarantees the promise holds, what happens when the vendor changes, who controls the settings. These are legitimate questions, and they take months.

A tool that cannot identify people comes with a works council information pack, an information note and an impact assessment template, and with an offer: to present it together with the HSE manager.1 The questions are the same, but the answers can be checked in the product, in the meeting. It is the strongest argument we have with HSE managers, and it is not a sales argument: it is a description.

The regulatory context in 2026

The EU AI regulation classifies as high-risk the systems intended to monitor and evaluate the behaviour of persons in a work relationship, with obligations applicable since 2 August 2026, and it prohibits emotion recognition in the workplace.2 In December 2023 the CNIL fined an activity-monitoring system in warehouses 32 million euros.3

We do not cite these texts to frighten anyone. We cite them because they draw the same line we do: a system that checks states in zones is not a system that evaluates the behaviour of persons. Staying on the right side of that line is not a constraint we put up with; it is the definition of the product. This is not legal advice, and your data protection officer remains the right person for the qualification of your own deployment.

What it costs us

It would be dishonest to present this choice as free. It closes use cases that customers have asked us for and that competitors sell.

  • Individual productivity: how many pallets an hour for a given operator. We will not do it.
  • Badge-less access control by face recognition. We will not do it.
  • Matching a licence plate to a person, for example to know which driver left the dock too early. We can document that the trailer moved while the chock was absent; we will not say who was driving.

Each of these has a market. Each would turn Camly into a people-monitoring tool, with the regulatory classification, the works council process and the trust relationship that go with it. We chose the other product.

Why that is what makes the rest credible

A safety tool is only worth something if the site lets it run. A tool the works council has accepted, that IT has seen run without any identity leaving the site, and whose reports the insurer understands, runs. A tool that is tolerated until the next incident does not run for long.

The “no” to facial recognition is therefore also a “yes”: yes to periodic checks on zones, yes to episodes with a duration, yes to the near-miss report the HSE manager can put into the risk assessment document without wondering what else it contains. It is a smaller product than the technology would allow. It is the product that can be deployed.

Where to start

If one of your needs is on the list of what we will not do, it is better to know before a pilot. If your needs fit in “places and situations”, you have a works council file that writes itself in a page, and thirty days to check that the method holds.

Sources

  1. Camly AI, “Camly for warehouses” brochure, pilot edition, October 2026, page “Privacy and sovereignty”; Camly AI, integration study with warehouse systems, October 2026 (zone-level data, no per-operator joins).
  2. Regulation (EU) 2024/1689 on artificial intelligence, Annex III point 4 and prohibited practices. eur-lex.europa.eu
  3. CNIL, deliberation of 27 December 2023, Amazon France Logistique, €32M. cnil.fr