North Carolina DPS says security-system firms that sell, install, service, monitor or respond to security systems—including security cameras—need the appropriate Security Systems License. 2025 law changes broadened the definition to include analytic capturing and imaging systems used for security/intelligence purposes. Businesses should verify licensing and privacy scope before deployment.
This checklist is designed to stop a common mistake: treating AI video analytics as only a software project. Once cameras are installed, serviced, monitored or used for security/intelligence purposes, North Carolina licensing requirements can become central to the implementation.
This is educational information, not legal advice. The exact legal analysis depends on the project and should be confirmed with the state board and qualified counsel where appropriate.
Step 1: identify whether the project is a security-system project
North Carolina DPS states that a Security Systems License is required for any person or firm that sells, installs, services, monitors or responds to security systems, including security cameras. Senate Bill 710 / S.L. 2025-51 renamed and updated the law effective October 1, 2025, including analytic capturing devices and imaging systems used to detect illegal or unauthorized activity in the covered definition.
- Write the intended purpose of every camera/analytic.
- Identify who sells and specifies the security system.
- Identify who installs wiring, cameras, NVR/VMS and access-control components.
- Identify who services or monitors the system after launch.
- Verify qualifying-agent and firm licensing directly with the state where required.
- Keep AI software scope separate from licensed physical-security scope when using multiple partners.
Step 2: build a responsibility map across AI, security and IT vendors
| Area | Named owner should be explicit |
|---|---|
| Camera selection/placement | licensed security provider when part of regulated security system |
| Low-voltage wiring/PoE | qualified/licensed party as applicable |
| NVR/VMS | security provider / IT depending on scope |
| AI analytics models | AI/analytics provider |
| Network/VLAN/firewall | IT/network owner |
| Alert monitoring | authorized security/operations team |
| Retention/export | business data owner |
| Incident response | business/security/law-enforcement procedure |
| Software updates | vendor + business change-control owner |
Step 3: document purpose and use the least intrusive analytic that works
Write a one-sentence purpose for each use case. “Count lobby entries to compare staffing by hour” is clear. “Use AI to understand customers” is not. Then disable features the project does not need.
| Goal | Lower-intrusion approach |
|---|---|
| Foot traffic | anonymous line crossing/count |
| Queue | anonymous person count + dwell threshold |
| Restricted zone | person/object presence event |
| Vehicle flow | vehicle count/zone/dwell without identity |
| Shelf state | object/stock condition |
| Security evidence | recording + defined event alert; identification features only if separately justified |
Step 4: treat audio and biometric features as separate decisions
A microphone, face-matching feature or other identity technology changes the privacy profile. Do not enable those functions by default. Determine whether the business genuinely needs them, what notices or policies are appropriate, how data is stored, and what law applies.
Many operational computer-vision use cases do not require audio or biometric identification at all.
Step 5: define retention, access and export
- Set a retention period for raw video based on business need and applicable requirements.
- Set separate retention for derived analytics/events if the platform stores them.
- Limit live view and playback by role.
- Require individual accounts rather than shared admin credentials.
- Log exports where supported and define who can authorize them.
- Protect cloud links and shared clips from indefinite public access.
- Document how data is deleted when a vendor relationship ends.
Step 6: understand Fayetteville Police camera registry vs integration
The Fayetteville Police Department offers businesses two participation options through its camera-sharing program: camera registry and camera integration. Registry informs police that cameras exist at a location and allows the owner to share video when requested. Integration can provide the department direct live access through the Fusus Real-Time Intelligence Center, according to the city’s program page.
Those are materially different choices. A business should understand access, technical requirements, internal policy, customer/employee considerations and who can authorize participation before integrating live feeds.
Step 7: keep AI outputs out of unsupported high-stakes decisions
A model can be wrong. Use analytics to surface events for review, prioritize staff attention and measure operations. Do not treat an AI classification as unquestionable proof of theft, misconduct, identity or intent.
Require human verification before consequential action and preserve enough context to review what happened.
Step 8: audit the system after launch
Quarterly or after major changes, review cameras, analytic purpose, false alerts, user access, retained data, firmware/software updates, vendor accounts, integration permissions, signage/notices where used, and whether unused features can be disabled.
AI camera and computer-vision systems should become more controlled over time, not accumulate capabilities nobody remembers enabling.
Research sources and local evidence
These sources were used to ground the practical guidance in this article. Market estimates are directional; the business decision should still be based on the specific site, workflow, vendor agreement, and measured pilot results.
- North Carolina DPS — Security Systems licensing requirements — North Carolina license requirements for firms that sell, install, service, monitor, or respond to security systems including security cameras.
- North Carolina General Assembly — S.L. 2025-51 security systems changes — 2025 statutory changes expanding covered security-system activity to analytic capturing and imaging systems used for security/intelligence purposes.
- City of Fayetteville Police Department — camera registry and integration — Local business camera registration and optional Fusus real-time camera integration information.
- NVIDIA retail partner solutions — computer vision use cases — Current examples of visual AI for queue, inventory, footfall and store analytics.
- U.S. Census Bureau QuickFacts — Cumberland County — Local business, retail, healthcare, employment and commercial-sector context.
Frequently asked questions
What does North Carolina require for security camera businesses?
North Carolina DPS states that a Security Systems License is required for firms/persons that sell, install, service, monitor, or respond to security systems, including security cameras. Verify current scope and licensing directly with the state.
Did North Carolina change its security-system law in 2025?
Yes. S.L. 2025-51 updated and renamed the law, and the state summary says the covered definition includes analytic capturing devices, systems providing intelligence, and imaging devices used to detect illegal activities.
Can Fayetteville businesses share cameras with police?
The Fayetteville Police Department describes a voluntary registry option and a separate integration option that can provide live access through its Fusus Real-Time Intelligence Center. Businesses should review the program details before participating.
Map licensing, purpose and data responsibility before installation day.
A strong camera-AI project names the licensed/security owner, the AI owner, the IT owner, the business purpose, the retention policy and the human decision boundary in writing.
Editorial standard: practical, locally relevant, evidence-aware, and explicit about system boundaries. Last reviewed August 7, 2026.
