EU AI Act

Is Biometric AI High-Risk Under EU AI Act?

Biometric AI under EU AI Act: prohibited uses, high-risk categories, compliance requirements. Facial recognition, emotion detection, biometric ID.

12 min read
Joe Braidwood
Joe Braidwood
CEO, GLACIS
12 min read

Quick Answer

Biometric AI classification under the EU AI Act depends on the specific use case. Some uses are prohibited under Article 5; Annex III lists other specified uses that require Article 6 analysis before applicable high-risk obligations are determined.

Prohibited (Article 5)
  • Untargeted facial image scraping
  • Real-time remote biometric ID in public
  • Emotion recognition in workplaces/schools
High-Risk (Annex III)
  • Post-remote biometric identification
  • Biometric categorization systems
  • Permitted emotion recognition uses
Feb 2025
Prohibitions Active
Dec 2027
Relevant Annex III Date
Article 12
Logging Required
Notified Body
Assessment Required

In This Guide

Prohibited Biometric AI Uses (Article 5)

Article 5 of the EU AI Act outright bans certain biometric AI applications that pose unacceptable risks to fundamental rights. These prohibitions took effect February 2, 2025. Organizations deploying prohibited biometric AI face penalties up to €35 million or 7% of global annual turnover.

Prohibited Biometric AI Applications

1. Untargeted Facial Image Scraping

Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage. This prohibition applies regardless of the database’s intended use: commercial, law enforcement, or otherwise.[1]

2. Real-Time Remote Biometric Identification in Public Spaces

AI systems that identify natural persons in real-time in publicly accessible spaces for law enforcement purposes. “Real-time” means identification occurs simultaneously with or without significant delay from the biometric data capture.[1]

Narrow exceptions exist: Article 5 specifies limited objectives involving particular victims or missing persons, threats to life or physical safety and terrorist threats, and locating or identifying suspects under the listed-offence conditions. Authorization and the Article’s other safeguards still apply.

3. Emotion Recognition in Workplaces and Schools

AI systems inferring emotions of individuals in workplace and educational institution contexts. This covers systems detecting stress, engagement, attention, satisfaction, or other emotional states.[1]

Exception: systems intended to be put in place or into the market for medical or safety reasons. Apply the statutory definitions and system-specific purpose rather than assuming an example qualifies.

4. Biometric Categorization Inferring Sensitive Attributes

AI systems categorizing individuals based on biometric data to infer race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation. Lawful filtering of biometric datasets by sex (e.g., for law enforcement searches) is permitted.[1]

High-Risk Biometric AI Uses (Annex III)

Annex III, Category 1, lists specified biometric identification, categorization, and emotion-recognition uses that do not fall within an Article 5 prohibition. Providers must apply Article 6, including Article 6(3), as well as the Act’s definitions and exclusions before determining the applicable Articles 8 to 15 requirements and conformity-assessment pathway. The AI Omnibus entered into force on 27 July 2026; relevant Annex III high-risk obligations apply from 2 December 2027.

High-Risk Biometric AI Categories

Post-Remote Biometric Identification

Systems identifying natural persons at a distance from recorded biometric data after capture may fall within remote biometric identification. Classification and permissibility require system-specific Article 5, Article 6, Annex III, law-enforcement, and data-protection analysis; “post-remote” alone is not a categorical answer.[1]

Biometric Categorization Systems

Some systems assigning natural persons to categories based on biometric data are prohibited under Article 5; others may fall within Annex III point 1(b), subject to the exact categories, intended purpose, and Article 6 analysis. A customer-demographic use is not categorically high-risk solely because of that label.[1]

Permitted Emotion Recognition

Permitted emotion-recognition systems may fall within Annex III point 1(c) when its conditions apply. Prohibitions, exceptions, and high-risk classification depend on the exact purpose and context; medical or driver-safety labels do not determine classification by themselves.[1]

Biometric Verification (Authentication)

One-to-one biometric verification systems (fingerprint authentication, face unlock, iris scanning for access control) are generally not high-risk under Annex III unless deployed in high-risk contexts or combined with other high-risk functions. Context determines classification.[1]

Key Determining Factors

The classification of biometric AI depends on several critical factors. Understanding these distinctions is essential for accurate risk categorization.

Factor Prohibited High-Risk
Timing Real-time (simultaneous/minimal delay) Post-remote (after recording)
Location Publicly accessible spaces Private/controlled environments
Context Workplace/school emotion recognition Medical/safety emotion recognition
Data Source Untargeted internet/CCTV scraping Targeted, consent-based collection
Purpose Inferring prohibited sensitive attributes Permitted categorization purposes
Operator Law enforcement (without exception) Law enforcement (with authorization)

Law Enforcement Exceptions

Article 5 provides narrow objectives under which specified real-time remote biometric identification may be considered, subject to authorization, necessity, proportionality, and the Article’s other safeguards:

Even when exceptions apply, prior judicial or independent administrative authorization is required. Post-hoc authorization is only permitted in duly justified urgent cases, with authorization sought within 24 hours.[1]

High-Risk Compliance Requirements (Articles 9-15)

Biometric AI systems classified as high-risk are subject to the applicable requirements in Articles 8 to 15. The conformity-assessment path depends on the system and Article 43: specified Annex III biometric systems may use the Annex VI internal-control route when its conditions, including applicable harmonized standards or common specifications, are met; otherwise notified-body involvement may be required.

9

Risk Management System

Continuous, iterative risk management throughout the system lifecycle. For biometric systems, this includes assessing risks of misidentification, bias across demographic groups, and fundamental rights impacts. Document foreseeable risks, mitigation measures, and residual risk acceptance rationale.

10

Data Governance

Training, validation, and testing data must be subject to appropriate governance. Biometric datasets require examination for representativeness, bias, and gaps across demographic groups. Document data sources, collection methods, and preprocessing procedures.

11

Technical Documentation

Prepare comprehensive technical documentation per Annex IV before placing the system on the market. For biometric systems, this includes detailed accuracy metrics (false acceptance rate, false rejection rate), demographic performance differentials, and testing methodology.

12

Automatic Logging

Systems must automatically record events enabling traceability of functioning. For biometric AI, logs must capture identification/verification requests, confidence scores, match decisions, and input data references. Those records are essential for post-incident investigation and ongoing monitoring.

13

Transparency

Provide clear instructions for use to deployers. Biometric systems must include information on accuracy levels, known limitations, demographic performance variations, and proper operating conditions.

14

Human Oversight

Design systems to enable effective human oversight. Critical for biometric identification systems: humans must be able to correctly interpret outputs, decide not to use the system, override decisions, and intervene in real-time when necessary.

15

Accuracy, Robustness, Cybersecurity

Achieve appropriate accuracy levels consistent with intended purpose. Biometric systems must be resilient against adversarial attacks (presentation attacks, morphing attacks) and errors that could lead to misidentification.

Article 12 logging for biometric identification

Article 12 requires high-risk AI systems to support automatic event logging appropriate to their intended purpose. Article 12(3) adds the specific minimum fields below for covered remote biometric identification systems; those fields should not be generalized to every biometric or high-risk system.

Article 12 Logging Requirements for Biometric AI

For remote biometric identification systems covered by Article 12(3), logging capabilities must record at least:

  • Periods of use: Start and end date and time of each use
  • Reference database: Which biometric database was queried for each identification
  • Input data: Reference to input data generating matches (enabling post-hoc verification)
  • Human verification: Identity of natural persons verifying identification results
GLACIS logo How GLACIS Helps

GLACIS can create signed records for selected logging and control events. Signatures can support integrity and independent verification of included fields, but they do not establish completeness, control effectiveness, conformity, or Article 12 compliance.

GDPR Biometric Data Requirements

Biometric AI systems face dual regulatory obligations: the EU AI Act governs the AI system itself, while GDPR governs the processing of biometric personal data. Organizations must achieve compliance with both frameworks.

GDPR Article 9: Special Category Data

Biometric data processed for identification purposes is special category data under GDPR. Processing is prohibited unless an Article 9(2) exception applies:

  • • Explicit consent (Article 9(2)(a))
  • • Employment law obligations (Article 9(2)(b))
  • • Substantial public interest (Article 9(2)(g))

AI Act Additional Requirements

Beyond GDPR compliance, biometric AI systems must meet AI Act requirements:

  • • Risk management for the AI system (Article 9)
  • • Data governance for training data (Article 10)
  • • Automated logging (Article 12)
  • • Human oversight mechanisms (Article 14)

Key overlap: GDPR Article 22 and AI Act Article 14 have different triggers and duties. Article 22 addresses qualified rights concerning decisions based solely on automated processing, while Article 14 requires providers to design covered high-risk systems for effective human oversight and deployers to use those measures. Assess each provision separately rather than treating both as a universal requirement for the same form of human involvement.

US Regulatory Comparison

Unlike the EU’s comprehensive framework, US biometric regulation is fragmented across state laws, municipal ordinances, and sector-specific requirements. Organizations operating transatlantically face divergent compliance obligations.

Jurisdiction Regulation Key Requirements
Illinois BIPA (2008) Written-notice/release duties and a private right of action; statutory damages can be $1,000 or $5,000 depending on the violation, subject to the 2024 single-recovery limits for repeated same-person, same-method collection or disclosure
Texas CUBI (2009) Consent required, AG enforcement only, $25,000 per violation
Washington HB 1493 (2017) Notice and consent for commercial purposes, AG enforcement
California CCPA/CPRA Biometric data is “sensitive personal information,” opt-out rights
San Francisco Ordinance (2019) Government agencies prohibited from using facial recognition
Federal None comprehensive Sector-specific only (HIPAA for health, FCRA for employment)

Key distinction: The EU AI Act creates systematic prohibitions and high-risk requirements that do not exist at US federal level. BIPA’s private right of action has driven significant litigation but focuses on biometric-information duties rather than AI-system governance. EU and US regimes overlap, but neither is a superset; map each applicable duty separately.

Implementation Checklist

Organizations deploying covered biometric AI systems should address applicable high-risk requirements ahead of the 2 December 2027 Annex III date. Classification, prohibited-practice analysis, and conformity-assessment planning should begin well before deployment.

Pre-Deployment Compliance Checklist

Frequently Asked Questions

Is biometric AI high-risk under the EU AI Act?

It depends on the specific use case. Some biometric AI practices are prohibited under Article 5, subject to definitions and exceptions. Annex III lists specified biometric identification, categorization, and emotion-recognition uses; providers must apply Article 6, including Article 6(3). Relevant Annex III obligations apply from 2 December 2027 under the AI Omnibus.

Is facial recognition prohibited under the EU AI Act?

Not entirely. Article 5 prohibits specified real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrow statutory objectives, authorization requirements, and safeguards. Untargeted scraping of facial images from the internet or CCTV to create or expand facial-recognition databases is prohibited. Other uses require system-specific Article 5, Article 6, Annex III, and data-protection analysis.

Can I use emotion recognition AI in my workplace?

Article 5 prohibits specified emotion-inference uses in workplaces and educational institutions, except where intended for medical or safety reasons. A permitted system may be listed in Annex III point 1(c), subject to Article 6 and the exact purpose and context; permission does not by itself settle high-risk classification.

Do I need a notified body assessment for biometric AI?

Specified biometric systems listed in Annex III may require a notified-body conformity assessment depending on the applicable Article 43 pathway and harmonized-standard use. Start pathway analysis early: relevant Annex III high-risk obligations apply from 2 December 2027 under the AI Omnibus.

What evidence do regulators expect for biometric AI compliance?

The evidence needed depends on the system, role, and conformity-assessment route. Relevant material can include Article 12 logs, risk-management records, data-governance documentation, human-oversight records, and accuracy testing across relevant groups. Cryptographically verifiable operational records can support that evidence set, but do not by themselves establish conformity or satisfy every evidentiary requirement.

Does GDPR also apply to biometric AI systems?

Either or both regimes may apply depending on territorial scope, processing role, biometric purpose, and AI Act classification. Where GDPR applies, biometric data used for uniquely identifying a person is special-category data under Article 9 and requires an applicable Article 9 condition as well as an Article 6 lawful basis. Assess any AI Act duties separately.

References

  1. [1] European Union. “Regulation (EU) 2024/1689 of the European Parliament and of the Council.” Official Journal of the European Union, July 12, 2024. EUR-Lex 32024R1689
  2. [2] European Commission. “Questions and Answers: Artificial Intelligence Act.” March 13, 2024. europa.eu
  3. [3] European Data Protection Board. “Guidelines on the Use of Facial Recognition Technology in the Area of Law Enforcement.” 2022. edpb.europa.eu
  4. [4] Illinois General Assembly. “Biometric Information Privacy Act (BIPA).” 740 ILCS 14. ilga.gov
  5. [5] Future of Life Institute. “EU AI Act Article-by-Article Analysis.” 2024. artificialintelligenceact.eu

Make Biometric AI Supervision Verifiable

GLACIS can preserve signed records of what configured control paths reported around a covered biometric-AI action. Reviewers can check supported signatures and covered fields; the records do not establish execution, effectiveness, complete coverage, or legal compliance and do not replace required documentation or assessment.

Talk to us

Related Guides