Prohibited Biometric AI Uses (Article 5)
Article 5 of the EU AI Act outright bans certain biometric AI applications that pose unacceptable risks to fundamental rights. These prohibitions took effect February 2, 2025. Organizations deploying prohibited biometric AI face penalties up to €35 million or 7% of global annual turnover.
Prohibited Biometric AI Applications
1. Untargeted Facial Image Scraping
Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage. This prohibition applies regardless of the database’s intended use: commercial, law enforcement, or otherwise.[1]
2. Real-Time Remote Biometric Identification in Public Spaces
AI systems that identify natural persons in real-time in publicly accessible spaces for law enforcement purposes. “Real-time” means identification occurs simultaneously with or without significant delay from the biometric data capture.[1]
Narrow exceptions exist: Article 5 specifies limited objectives involving particular victims or missing persons, threats to life or physical safety and terrorist threats, and locating or identifying suspects under the listed-offence conditions. Authorization and the Article’s other safeguards still apply.
3. Emotion Recognition in Workplaces and Schools
AI systems inferring emotions of individuals in workplace and educational institution contexts. This covers systems detecting stress, engagement, attention, satisfaction, or other emotional states.[1]
Exception: systems intended to be put in place or into the market for medical or safety reasons. Apply the statutory definitions and system-specific purpose rather than assuming an example qualifies.
4. Biometric Categorization Inferring Sensitive Attributes
AI systems categorizing individuals based on biometric data to infer race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation. Lawful filtering of biometric datasets by sex (e.g., for law enforcement searches) is permitted.[1]
High-Risk Biometric AI Uses (Annex III)
Annex III, Category 1, lists specified biometric identification, categorization, and emotion-recognition uses that do not fall within an Article 5 prohibition. Providers must apply Article 6, including Article 6(3), as well as the Act’s definitions and exclusions before determining the applicable Articles 8 to 15 requirements and conformity-assessment pathway. The AI Omnibus entered into force on 27 July 2026; relevant Annex III high-risk obligations apply from 2 December 2027.
High-Risk Biometric AI Categories
Post-Remote Biometric Identification
Systems identifying natural persons at a distance from recorded biometric data after capture may fall within remote biometric identification. Classification and permissibility require system-specific Article 5, Article 6, Annex III, law-enforcement, and data-protection analysis; “post-remote” alone is not a categorical answer.[1]
Biometric Categorization Systems
Some systems assigning natural persons to categories based on biometric data are prohibited under Article 5; others may fall within Annex III point 1(b), subject to the exact categories, intended purpose, and Article 6 analysis. A customer-demographic use is not categorically high-risk solely because of that label.[1]
Permitted Emotion Recognition
Permitted emotion-recognition systems may fall within Annex III point 1(c) when its conditions apply. Prohibitions, exceptions, and high-risk classification depend on the exact purpose and context; medical or driver-safety labels do not determine classification by themselves.[1]
Biometric Verification (Authentication)
One-to-one biometric verification systems (fingerprint authentication, face unlock, iris scanning for access control) are generally not high-risk under Annex III unless deployed in high-risk contexts or combined with other high-risk functions. Context determines classification.[1]
Key Determining Factors
The classification of biometric AI depends on several critical factors. Understanding these distinctions is essential for accurate risk categorization.
| Factor | Prohibited | High-Risk |
|---|---|---|
| Timing | Real-time (simultaneous/minimal delay) | Post-remote (after recording) |
| Location | Publicly accessible spaces | Private/controlled environments |
| Context | Workplace/school emotion recognition | Medical/safety emotion recognition |
| Data Source | Untargeted internet/CCTV scraping | Targeted, consent-based collection |
| Purpose | Inferring prohibited sensitive attributes | Permitted categorization purposes |
| Operator | Law enforcement (without exception) | Law enforcement (with authorization) |
Law Enforcement Exceptions
Article 5 provides narrow objectives under which specified real-time remote biometric identification may be considered, subject to authorization, necessity, proportionality, and the Article’s other safeguards:
- Victims and missing persons: Targeted search for specified victims of abduction, trafficking, or sexual exploitation, and for missing persons
- Threats: Preventing a specific, substantial, and imminent threat to life or physical safety, or a genuine and present or genuine and foreseeable terrorist threat
- Listed-offence suspects: Locating or identifying a person suspected of an Annex II offence meeting the statutory penalty threshold, for the purposes specified in Article 5
Even when exceptions apply, prior judicial or independent administrative authorization is required. Post-hoc authorization is only permitted in duly justified urgent cases, with authorization sought within 24 hours.[1]
High-Risk Compliance Requirements (Articles 9-15)
Biometric AI systems classified as high-risk are subject to the applicable requirements in Articles 8 to 15. The conformity-assessment path depends on the system and Article 43: specified Annex III biometric systems may use the Annex VI internal-control route when its conditions, including applicable harmonized standards or common specifications, are met; otherwise notified-body involvement may be required.
Risk Management System
Continuous, iterative risk management throughout the system lifecycle. For biometric systems, this includes assessing risks of misidentification, bias across demographic groups, and fundamental rights impacts. Document foreseeable risks, mitigation measures, and residual risk acceptance rationale.
Data Governance
Training, validation, and testing data must be subject to appropriate governance. Biometric datasets require examination for representativeness, bias, and gaps across demographic groups. Document data sources, collection methods, and preprocessing procedures.
Technical Documentation
Prepare comprehensive technical documentation per Annex IV before placing the system on the market. For biometric systems, this includes detailed accuracy metrics (false acceptance rate, false rejection rate), demographic performance differentials, and testing methodology.
Automatic Logging
Systems must automatically record events enabling traceability of functioning. For biometric AI, logs must capture identification/verification requests, confidence scores, match decisions, and input data references. Those records are essential for post-incident investigation and ongoing monitoring.
Transparency
Provide clear instructions for use to deployers. Biometric systems must include information on accuracy levels, known limitations, demographic performance variations, and proper operating conditions.
Human Oversight
Design systems to enable effective human oversight. Critical for biometric identification systems: humans must be able to correctly interpret outputs, decide not to use the system, override decisions, and intervene in real-time when necessary.
Accuracy, Robustness, Cybersecurity
Achieve appropriate accuracy levels consistent with intended purpose. Biometric systems must be resilient against adversarial attacks (presentation attacks, morphing attacks) and errors that could lead to misidentification.
Article 12 logging for biometric identification
Article 12 requires high-risk AI systems to support automatic event logging appropriate to their intended purpose. Article 12(3) adds the specific minimum fields below for covered remote biometric identification systems; those fields should not be generalized to every biometric or high-risk system.
Article 12 Logging Requirements for Biometric AI
For remote biometric identification systems covered by Article 12(3), logging capabilities must record at least:
- Periods of use: Start and end date and time of each use
- Reference database: Which biometric database was queried for each identification
- Input data: Reference to input data generating matches (enabling post-hoc verification)
- Human verification: Identity of natural persons verifying identification results
GLACIS can create signed records for selected logging and control events. Signatures can support integrity and independent verification of included fields, but they do not establish completeness, control effectiveness, conformity, or Article 12 compliance.
GDPR Biometric Data Requirements
Biometric AI systems face dual regulatory obligations: the EU AI Act governs the AI system itself, while GDPR governs the processing of biometric personal data. Organizations must achieve compliance with both frameworks.
GDPR Article 9: Special Category Data
Biometric data processed for identification purposes is special category data under GDPR. Processing is prohibited unless an Article 9(2) exception applies:
- • Explicit consent (Article 9(2)(a))
- • Employment law obligations (Article 9(2)(b))
- • Substantial public interest (Article 9(2)(g))
AI Act Additional Requirements
Beyond GDPR compliance, biometric AI systems must meet AI Act requirements:
- • Risk management for the AI system (Article 9)
- • Data governance for training data (Article 10)
- • Automated logging (Article 12)
- • Human oversight mechanisms (Article 14)
Key overlap: GDPR Article 22 and AI Act Article 14 have different triggers and duties. Article 22 addresses qualified rights concerning decisions based solely on automated processing, while Article 14 requires providers to design covered high-risk systems for effective human oversight and deployers to use those measures. Assess each provision separately rather than treating both as a universal requirement for the same form of human involvement.
US Regulatory Comparison
Unlike the EU’s comprehensive framework, US biometric regulation is fragmented across state laws, municipal ordinances, and sector-specific requirements. Organizations operating transatlantically face divergent compliance obligations.
| Jurisdiction | Regulation | Key Requirements |
|---|---|---|
| Illinois | BIPA (2008) | Written-notice/release duties and a private right of action; statutory damages can be $1,000 or $5,000 depending on the violation, subject to the 2024 single-recovery limits for repeated same-person, same-method collection or disclosure |
| Texas | CUBI (2009) | Consent required, AG enforcement only, $25,000 per violation |
| Washington | HB 1493 (2017) | Notice and consent for commercial purposes, AG enforcement |
| California | CCPA/CPRA | Biometric data is “sensitive personal information,” opt-out rights |
| San Francisco | Ordinance (2019) | Government agencies prohibited from using facial recognition |
| Federal | None comprehensive | Sector-specific only (HIPAA for health, FCRA for employment) |
Key distinction: The EU AI Act creates systematic prohibitions and high-risk requirements that do not exist at US federal level. BIPA’s private right of action has driven significant litigation but focuses on biometric-information duties rather than AI-system governance. EU and US regimes overlap, but neither is a superset; map each applicable duty separately.
Implementation Checklist
Organizations deploying covered biometric AI systems should address applicable high-risk requirements ahead of the 2 December 2027 Annex III date. Classification, prohibited-practice analysis, and conformity-assessment planning should begin well before deployment.
Pre-Deployment Compliance Checklist
Frequently Asked Questions
Is biometric AI high-risk under the EU AI Act?
It depends on the specific use case. Some biometric AI practices are prohibited under Article 5, subject to definitions and exceptions. Annex III lists specified biometric identification, categorization, and emotion-recognition uses; providers must apply Article 6, including Article 6(3). Relevant Annex III obligations apply from 2 December 2027 under the AI Omnibus.
Is facial recognition prohibited under the EU AI Act?
Not entirely. Article 5 prohibits specified real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, subject to narrow statutory objectives, authorization requirements, and safeguards. Untargeted scraping of facial images from the internet or CCTV to create or expand facial-recognition databases is prohibited. Other uses require system-specific Article 5, Article 6, Annex III, and data-protection analysis.
Can I use emotion recognition AI in my workplace?
Article 5 prohibits specified emotion-inference uses in workplaces and educational institutions, except where intended for medical or safety reasons. A permitted system may be listed in Annex III point 1(c), subject to Article 6 and the exact purpose and context; permission does not by itself settle high-risk classification.
Do I need a notified body assessment for biometric AI?
Specified biometric systems listed in Annex III may require a notified-body conformity assessment depending on the applicable Article 43 pathway and harmonized-standard use. Start pathway analysis early: relevant Annex III high-risk obligations apply from 2 December 2027 under the AI Omnibus.
What evidence do regulators expect for biometric AI compliance?
The evidence needed depends on the system, role, and conformity-assessment route. Relevant material can include Article 12 logs, risk-management records, data-governance documentation, human-oversight records, and accuracy testing across relevant groups. Cryptographically verifiable operational records can support that evidence set, but do not by themselves establish conformity or satisfy every evidentiary requirement.
Does GDPR also apply to biometric AI systems?
Either or both regimes may apply depending on territorial scope, processing role, biometric purpose, and AI Act classification. Where GDPR applies, biometric data used for uniquely identifying a person is special-category data under Article 9 and requires an applicable Article 9 condition as well as an Article 6 lawful basis. Assess any AI Act duties separately.
References
- [1] European Union. “Regulation (EU) 2024/1689 of the European Parliament and of the Council.” Official Journal of the European Union, July 12, 2024. EUR-Lex 32024R1689
- [2] European Commission. “Questions and Answers: Artificial Intelligence Act.” March 13, 2024. europa.eu
- [3] European Data Protection Board. “Guidelines on the Use of Facial Recognition Technology in the Area of Law Enforcement.” 2022. edpb.europa.eu
- [4] Illinois General Assembly. “Biometric Information Privacy Act (BIPA).” 740 ILCS 14. ilga.gov
- [5] Future of Life Institute. “EU AI Act Article-by-Article Analysis.” 2024. artificialintelligenceact.eu
