- Non-compliance with the EU AI Act can cost a company €35 million or 7% of a company’s global annual turnover from the previous financial year.
- The Act defines four risk levels for AI-powered systems. Some fleet solutions may fall into the category of AI Act high-risk systems (second risk level).
- On June 29, 2026, the Council of the EU approved a Digital Omnibus package that has pushed the Act’s high-risk deadlines back to December 2, 2027, and August 2, 2028.
- Fleet managers using AI-powered solutions have time to determine whether their systems fit the Act’s security and quality requirements, as well as identify whether their solutions could possibly violate employees’ rights.
- A failure to comply with the Act’s reporting requirements can lead a company to a fine of €7,500,000 or 1% of total worldwide annual turnover.
Violating the key principles of the EU AI Act can result in fines of up to €35 million or 7% of a company’s global annual turnover from the previous financial year, according to the EU AI Act’s official portal. For fleet companies, the stakes are too high to overlook. Still, many operators continue to treat the EU AI Act as a legal compliance issue instead of an operational one.
The good news is that on June 29, 2026, the Council of the EU approved a Digital Omnibus package that has pushed the EU AI Act deadlines for high-risk systems. The worker-management pathway, most relevant to fleet managers, moved from August 2026 to December 2027. The product-safety pathway moved from August 2027 to August 2028. That gave fleet companies breathing room and time to determine which AI-powered features in their systems are actually subject to regulation.
In this article, I draw the line between AI-powered features of fleet software that sit outside the Act’s high-risk categories and those that can trigger compliance obligations. I’ll also break down where AI in fleet management tends to run into regulatory trouble – and how to build around it from the start.
It is important to note that the Act applies only to fleet businesses operating in the EU. Still, the US and other countries in the world have their own sector and industry-specific standards and regulations governing AI usage. That’s why the framework outlined in this article may be beneficial to companies operating outside the EU.
What is the EU AI Act and what does it regulate in fleet operations?
The EU AI Act is the European Union’s first law that directly regulates artificial intelligence, in force since August 2024. Instead of treating all AI the same way, it sorts systems into four risk levels:
- Unacceptable risk – AI that manipulates people, recognizes workplace emotions, or allows prohibited social scoring; banned outright.
- High risk (most relevant to fleet managers) – AI used in areas like employee monitoring, hiring, or safety-critical systems; subject to strict compliance requirements.
- Limited risk – AI chatbots or AI-generated content that must clearly disclose AI involvement.
- Minimal risk – routine workflows covered by AI; generally subject only to voluntary best practices.
This EU artificial intelligence regulation is being rolled out in stages. It started with the law taking effect in 2024, followed by bans on the riskiest AI practices and rules for general-purpose AI models in 2025. The two toughest requirements for high-risk AI systems were originally due sooner but got pushed back to December 2027 and August 2028 under a June 2026 EU package. The image below illustrates the EU AI Act’s compliance timeline, along with its key milestones.

Most AI tools already used by fleet companies, such as route optimization, predictive maintenance, and load planning, fall outside the EU AI Act’s high-risk categories. For instance, if your fleet software analyzes historical trip data to suggest better routes, you’re not in high-risk territory. Such a system doesn’t make decisions about a person’s safety, rights, or employment status.
The EU AI Act mainly applies to AI systems that directly affect safety or workers’ rights. For many fleets, that leaves one area of real concern: driver behavior monitoring. Not because cameras feel invasive, but because the output from a driver monitoring system (DMS) can trigger two separate legal categories. Which one applies depends on what you do with the footage after the camera captures it.
The risk lies in two specific uses: reading footage to infer a driver’s emotional state (banned outright under Article 5), or storing and reviewing it to evaluate or discipline drivers, which classifies the system as high-risk under Annex III. The same camera doing only real-time fatigue alerts for safety reasons triggers neither.
The delay doesn’t apply to every part of the Act. Rules on prohibited AI practices under Article 5, including the ban on workplace emotion recognition in certain cases, have been in force since February 2025. When reviewing compliance guidance, always check its publication date. The EU AI Act is introduced dynamically, so it’s important to know which provisions already apply and which are still to come.
That same February 2025 start date also brought Article 4 into force. It requires companies using AI systems to make sure their employees know enough about AI to use those systems responsibly. For fleet managers, it’s already an active obligation. Practically, that means dispatchers and safety managers who interpret DMS alerts, or ops staff who decide what to do with flagged footage, need enough understanding of what the system can detect and where its limits are.
For more on how these systems fit into a fleet stack, see my guide to fleet management software development.
Is your driver monitoring system “high-risk”?
A single truck driver behavior monitoring system can, theoretically, be classified as high-risk in two separate ways under the EU AI Act. The first route runs through vehicle safety law. The second runs through employment law. Which one applies, or whether both do, depends on how the fleet uses the output, not the hardware.
The safety route is mostly not your problem. Driver Drowsiness and Attention Warning systems fall under existing vehicle safety law (Regulation (EU) 2019/2144). Fleets do not handle that compliance through vehicle type-approval because it’s the fleet’s responsibility. The one exception: custom driver-monitoring systems you build yourself, outside vehicle type-approval, still fall under the AI Act’s general high-risk deadline of August 2, 2028.
The worker-management pathway
What actually matters in terms of the AI Act is how you use your AI systems.
The EU AI Act Annex III, point 4(b) covers AI systems used to monitor and evaluate worker performance and behavior. In plain terms, this is the category for AI that watches how someone does their job and generates a judgment about it – not just whether they’re safe in the moment, but how they’re performing over time.
If fleet managers reuse data from AI-powered safety monitoring systems for driver performance evaluations, scoring, disciplinary actions, or permanent driver records, they risk violating the provisions of the EU AI Act.
This route’s deadline is December 2, 2027, which is eight months earlier than the product-safety route. Fleets that took this shortcut have less runway to fix it than they might assume.
The same system can be compliant or non-compliant depending on how it is used. Safety monitoring is allowed, while using the same data for individual driver evaluations may violate the rules. Since the line is thin, fleet companies should clearly separate these scenarios and prepare a risk plan for edge cases.
For more insights on such monitoring systems, check out my guide to driver behavior monitoring.
Does fatigue detection violate the emotion recognition ban?
Here’s another common concern related to the EU AI Act: whether fleet systems can create unacceptable risks by using AI-powered fatigue detection capabilities.
In most cases, they cannot. Recital 18 of the AI Act draws a line between emotions and physical states. Fatigue sits on the physical-state side, not the emotional side. Most driver behavior monitoring systems measure drowsiness instead of emotional state, so they fall outside Article 5(1)(f)’s ban before any exception is needed. Even where that’s disputed, Article 5(1)(f) also carries an exception for medical or safety purposes.
Also, several legal commentators, including experts from the Future of Privacy Forum, argue that fatigue-detection systems should be clearly separated from the definition of emotion-recognition systems.
According to the road safety report from the European Commission, driver fatigue contributed to 15-20% of serious road crashes in the EU in 2021. AI systems that detect signs of fatigue and alert drivers or fleet operators can significantly improve road safety. That’s why the EU AI Act does not ban these systems outright. Instead, it regulates their use to ensure they improve safety without creating unnecessary risks for drivers’ rights.
A DMS flagging a drowsy driver may never touch Article 5’s prohibition in the first place. But if your DMS bundles fatigue alerts with broader “driver wellness” or stress-monitoring features, you’ve likely stepped past the exception’s edge. That’s an easy trap for vendors chasing feature parity.
Bottom line: Fatigue detection for safety purposes is not what Article 5 was written to stop. General emotion or wellness inference, layered on top of it, is a different story.
What are the EU AI Act penalties?
The EU AI Act has a relatively limited impact on most fleet management systems. But failing to comply with its requirements can lead to significant EU AI Act penalties. The table below summarizes the potential fines that can currently be imposed for different types of violations under the Act.
| Tier | Violation type | Maximum fine |
|---|---|---|
1 – Highest | Prohibited AI practices (Article 5) | €35,000,000 or 7% of total worldwide annual turnover, whichever is higher |
2 – Middle | Breach of provider, deployer, importer, distributor, or notified-body obligations (Articles 16, 22, 23, 24, 26, 31, 33, 34, 50) | €15,000,000 or 3% of total worldwide annual turnover, whichever is higher |
3 – Lowest | Supplying incorrect, incomplete, or misleading information to a notified body or national authority | €7,500,000 or 1% of total worldwide annual turnover, whichever is higher |
Source: Article 99, Regulation (EU) 2024/1689 – official AI Act Service Desk (European Commission)
The Act leaves exceptions for SMEs and startups. Instead of taking the higher of the fixed amount or the turnover percentage, AI Act fines are capped at whichever figure is lower. This meaningfully reduces exposure for smaller companies.
The AI Act isn’t the main constraint most fleets will hit. In practice, GDPR (lawful basis, DPIA obligations under Article 35, and national employment provisions under Article 88) and national labor consultation requirements shape DMS deployment far more directly. The Betriebsrat’s veto right in Germany, or a works council’s consent right in the Netherlands, applies regardless of how the AI Act classifies the system. A fleet operator in Frankfurt or Rotterdam will hit the Betriebsrat or works council question long before any AI Act deadline becomes relevant.
AI adoption is not the only aspect of fleet management covered by rules and standards. For more insights on other fleet software compliance, read my guide to fleet regulations in the U.S.
A practical EU AI Act compliance checklist for fleet managers

To stay on the safe side of the EU AI Act, work through a short compliance checklist before rolling out any DMS or driver-facing AI system. Ask yourself the five questions below. They’ll help you pinpoint exactly which category your system falls into and what obligations follow from it.
- Was your fleet system already installed before the Act’s application date?
If yes, that’s good news. According to the Act’s Article 111(2), if a camera system was already on the market or in use before August 2, 2026, the AI Act generally doesn’t apply unless the system is significantly redesigned after that date. There’s one exception: systems used by public authorities must comply with the AI Act by August 2, 2030, regardless of when they were originally deployed.
- Does your DMS output ever feed a performance, coaching, or disciplinary process?
If the answer is yes, you’re running or building a system that evaluates workers, which falls under the EU AI Act Annex III, point 4(b) and becomes subject to the high-risk rules from December 2, 2027. If possible, redesign the solution. At least, change your internal workflows so the system isn’t used for high-risk employment decisions.
- Have you informed workers’ representatives and affected drivers before putting the system into service?
Under Article 26(7), employers must inform workers’ representatives and the workers who will be affected that they’ll be subject to a high-risk AI system before it’s put into service. In fleet management, this rule applies as soon as a DMS is classified as high-risk.
- Is fatigue detection bundled with broader emotion or wellness inference?
Check what the system actually infers, not just what it alerts on. A drowsiness warning is one thing. A “driver mood” dashboard is another. If you are planning to build such a solution, draw the line between emotion recognition and wellness inference from day one.
- Does your vendor’s roadmap account for the August 2, 2028 product-safety deadline?
Ask vendors directly. If they can’t provide a clear answer, consider another provider – whether you’re buying an off-the-shelf product or developing a custom solution.
- Do you have a conformity assessment plan for any system that qualifies as high-risk?
Document every step to prepare a mechanism that proves fleet software compliance if a regulator asks.
The checklist above tells you whether you have a compliance issue. But fixing it is an architectural problem rather than a legal one.
In practice, that usually means keeping real-time safety features, such as fatigue or drowsiness alerts, completely separate from the data used for driver evaluation or reporting. That separation should be built into the system itself with schemas, permissions, and access controls. An engineer shouldn’t be able to join a safety-alert table with a driver scorecard just because it’s technically possible.
The same goes for storing or aggregating driver footage. That should be a deliberate decision with a clear audit trail. If your system wasn’t designed this way from the start, fixing it usually means changing the storage and access architecture. It’s much bigger than flipping a setting in the dashboard.
We’ve watched this pattern play out more than once. A safety feature ships first. Later, someone on the ops side asks, “Can we also use this for driver scorecards?” That question is usually where the worker-management pathway gets triggered. Nobody flags it as a legal event.
None of this means avoiding driver monitoring because of the EU AI Act compliance needs. It means being deliberate about what the data does after it’s collected. If your software wasn’t built with that separation in mind, retrofitting it is a real project, not a settings change. For more on the underlying workflow decisions, see my piece on improving fleet management workflow.
Final thoughts
The EU AI Act affects only a limited number of fleet management use cases, but the cost of non-compliance can be really high. Fleet managers still have time to assess how AI is used across their operations and find workflows that may fall under the Act. While existing processes can often be adjusted, building or modernizing fleet software with a clear separation between low-risk and high-risk AI use cases is the safest option.
Volpis, a team with over 10 years of experience in fleet management software development and strong expertise in compliance frameworks, is ready to help.
Contact us to create AI-powered fleet systems with compliance built into their architecture.
Questions & Answers
FAQ
Can a fleet still use driver fatigue detection systems under the AI Act?
Article 5(1)(f)’s emotion-recognition ban includes a specific exception for AI systems used for medical or safety reasons. Fatigue detection for accident prevention fits that exception. Mind that the exception doesn’t extend to broader wellness or mood scoring.
Does the EU AI Act apply to the UK and other countries outside the EU?
Only if they place systems on the EU market or their output is used in the EU. Companies operating solely outside the EU aren’t directly bound. Still, many other regions have their own emerging AI rules worth tracking separately.
Who does the EU AI Act apply to?
The Act applies broadly to providers and deployers of AI systems placed on the EU market or whose output is used within the EU. This includes fleet software vendors, in-house development teams, and third-party AI providers, as long as their systems touch the EU market.
Is the EU AI Act in force?
The Act has been in force since August 1, 2024, though its obligations roll out in stages rather than all at once. Bans on prohibited AI practices took effect in February 2025, and general-purpose AI model obligations followed in August 2025. The remaining high-risk system requirements are still ahead. They are now scheduled for December 2027 and August 2028 after the Digital Omnibus AI Act extensions.
Why were the EU AI Act deadlines pushed back?
The European Commission concluded that businesses and regulators weren’t ready to meet the original August 2026 compliance dates, mainly due to technical reasons. The Digital Omnibus AI Act package, approved by the Council on June 29, 2026, pushed back the two high-risk deadlines to give companies more runway. The worker-monitoring pathway moved to December 2027 and the product-safety pathway to August 2028. Prohibited-practice bans and GPAI obligations remain untouched.