Researched by BEAST Library Curator | Verified by Harper | Quality: 8.5/10

BLUF: The EU AI Act's Digital Omnibus (provisional agreement 7 May 2026) deferred the high-risk worker-monitoring obligations to 2 December 2027 — so the "August 2 occupancy cliff" that has been circulating is, for identity-linked monitoring, wrong. But two things are already real: the ban on workplace emotion-inference AI has been in force since 2 February 2025, and the Article 50 AI-transparency duty still lands on 2 August 2026. The line that actually governs your occupancy program is not a date — it is the technical split between anonymous presence sensing and identity-linked monitoring. Here is the part most facility teams miss: the anonymous-presence side of that line is both the compliance-safe choice and the side that feeds demand-controlled ventilation for a 10–40% ventilation-energy saving, according to established DCV field studies. You do not have to trade privacy for value.

The line that split the sensor market

For three years the occupancy-analytics conversation on this site has been about measurement disagreement — sensors vs. badges vs. bookings, peak vs. average, the 18-point gap that reshapes a lease renewal. That is still the right fight for space planning. But a second fault line has opened underneath it, and it is a procurement question, not a data-science one: does your sensor produce a count or a dossier?

Presence sensing answers "how many people are in this zone, right now." Activity or identity tracking answers "who is at which desk, for how long, doing what." Both are marketed as "occupancy analytics." Legally and operationally, they could not be more different — and in 2026 the vendor market has bifurcated cleanly along exactly this line.

Where the named vendors sit

The privacy architecture is now a headline spec, not a footnote. Each vendor's approach below is the vendor's own stated design and self-reported accuracy — treat the accuracy figures as manufacturer claims to validate on your own floor, not independent benchmarks:

Platform Sensing method Privacy posture (vendor-stated) Accuracy (vendor-reported)
Butlr Thermal (heat signature) No PII captured; privacy enforced at the hardware level ~95% detection
VergeSense Optical + computer vision Imagery processed on-device; only anonymized occupancy data transmitted 95%+ occupancy detection
XY Sense Edge-processing high-resolution cameras Advanced privacy controls via edge processing (no imagery leaves the device) Approaching ~99%
Density Depth/radar-class area sensing Anonymous-by-design people counting Vendor-reported high accuracy
Basking / Mapiq Wi-Fi + access-control + sensor fusion (hardware-agnostic) Aggregate signals; privacy depends on how identifiers are handled Varies by data source

The pattern is unmistakable: the growth end of this market — one widely-cited 2026 projection puts the desk-occupancy-sensor category near US$1.3 billion by 2033, up from roughly US$500 million in 2025 — is competing on anonymity. AI processing has moved to the edge specifically so that the raw sensing (thermal maps, camera frames) never leaves the device and only an anonymous count is transmitted. That is not a marketing accident. It is the market pricing in the regulatory line before the regulators fully arrive.

What is actually enforceable (and when)

Precision matters here, because the wrong deadline drives the wrong 90-day plan. Three separate clocks are running, and they are not the same clock. (This is intelligence, not legal advice — confirm your own obligations with qualified counsel before you change a compliance posture.)

Provision Status Relevance to occupancy tech
Art. 5 — ban on workplace emotion-inference AI In force since 2 Feb 2025 Any sensor/analytics inferring mood, stress, engagement, or attention is already prohibited in the EU
Art. 50 — AI transparency / disclosure Applies 2 Aug 2026 (unaffected by the Omnibus) Where occupants interact with an AI system, disclosure is required
Annex III — high-risk worker-monitoring obligations Deferred to 2 Dec 2027 (Digital Omnibus, provisional agreement 7 May 2026; formal adoption pending) Identity-linked staff monitoring gets ~16 more months — but the direction is fixed

So the honest read is: the emotion-inference ban is a today problem, not a future one. If any part of your workplace-experience stack claims to read the room's "vibe" or score an individual's engagement, that feature is your immediate liability — kill it now. The heavy Annex III monitoring compliance, by contrast, has real runway. And the whole thing is moot for anonymous aggregate counts: presence data with no path back to an individual generally sits outside both the high-risk worker-monitoring scope and the GDPR definition of personal data. Penalties for prohibited practices reach up to €35 million or 7% of global turnover — enough that "we think it's anonymous" is not a posture you want to be defending.

The APAC angle: same logic, softer instruments

Robin's portfolio is APAC-weighted, and the regulatory instruments differ even though the underlying test converges. Singapore has no dedicated employee-monitoring statute; the PDPC's advisory guidelines govern, and the anonymous-presence test is the same — aggregate counts with no identifier fall outside PDPA personal-data obligations. But note the teeth: 2026 PDPA penalties run up to 10% of annual turnover or S$1 million, whichever is higher. Taiwan's Personal Data Protection Act turns on notice and consent for personal-data collection; anonymized presence counts sit outside that scope, which is precisely why a TSMC-class occupier can run building-wide presence sensing without a consent campaign. China's PIPL is the strict pole — explicit consent, tighter cross-border rules — so a multinational running one sensor platform across EU + SG + TW + CN should standardize on the most restrictive common denominator: anonymous, edge-processed, no identity linkage. That single architectural choice satisfies all four regimes at once.

The part that pays for itself: presence data feeds O-DCV

Here is why the compliance-safe choice is not a cost. The anonymous count you keep for privacy reasons is the exact signal that occupancy-based demand-controlled ventilation (O-DCV) needs. DCV modulates fresh-air supply to real occupancy instead of running constant airflow. It needs to know how many people are in the zone — it does not need to know who they are. Presence sensing and O-DCV want the identical data, and neither wants a dossier.

The energy case is well established: DCV typically saves 10–40% of ventilation-related energy in variable-occupancy spaces, with up to ~30% in buildings with strongly fluctuating occupancy. In controlled research on a high-resolution office dataset, occupancy-based control delivered the largest reduction — on the order of ~50% of the relevant power draw, with temperature-based control at roughly ~37% — as reported in the MDPI Sustainability high-resolution occupancy-and-climate study. And in 2026, LEED, WELL, and BREEAM practically expect DCV for new construction and major renovation, per current industry guidance — so the sensor you buy for headcount can also close a certification requirement and a utility line item.

What I'd do if this were my building — the 90-day plan

  1. Days 1–15 — Classify every sensor. Walk the stack and label each source presence (anonymous count) or identity-linked (badge, named-desk, camera-with-recognition). You cannot manage the line you have not drawn.
  2. Days 1–15 — Kill emotion inference immediately. Any "mood," "engagement," "wellness sentiment," or "attention" analytics is already prohibited in the EU and radioactive everywhere else. This is the one item with zero runway.
  3. Days 15–45 — Rewrite the next RFP. Make "edge processing, anonymous output, no PII at rest, no cross-zone re-identification" a pass/fail requirement, not a nice-to-have. Ask each vendor to state, in writing, where raw data is processed and what leaves the device.
  4. Days 30–75 — Wire presence into O-DCV. If you already have anonymous presence counts and a BMS with modulating ventilation, the marginal cost of DCV is integration, not hardware. Model the ventilation-energy line against your own occupancy variability before you commit.
  5. Days 60–90 — Document the anonymization decision. Write the one-page rationale (what is collected, why it is not personal data, who reviewed it). If a regulator or an enterprise legal team asks, a documented "we designed for anonymity, and here is the record" is the position you want to be in — not "we think it's fine."

The strategic point for anyone building a building operating system: privacy-preserving presence data is not a constraint you route around — it is the same signal that powers space planning, ventilation, and — with a privacy broker adding differential-privacy noise and a k-anonymity floor — even badge-fused occupancy products your enterprise legal team will actually approve. The buildings that treated occupancy privacy as an architecture decision in 2026, rather than a legal patch in 2027, are the ones that will have a compliant, valuable data asset instead of a liability to unwind.

Related reading: the US USE IT Act's 60% floor for the mandate side of occupancy, and the occupancy data trap for why peak and average tell different stories.


Have a question about this topic? Ask our CRE AI Agent →