Skip to main content

EU AI Act for Biometric AI Systems — Scanara

EU AI Act compliance for biometric identification and categorisation AI systems. Article 5 prohibited practices intersection, Annex III §1 obligations, and scanning.

Article 5 + Annex III §1 — Prohibited Practices and High-Risk

Biometric AI systems face both prohibited practice risk (Article 5) and high-risk obligations (Annex III §1). Prohibited practice enforcement applies from February 2025. High-risk obligations apply from August 2026.

The unique compliance risk for biometric AI

Article 5 prohibited practices risk

Biometric AI is uniquely exposed to prohibited practice classification. Real-time remote biometric identification, biometric categorisation for sensitive attributes, and social scoring with biometric inputs can all trigger Article 5. Fines are up to €35M or 7% of turnover.

Annex III §1 high-risk exposure

Biometric identification and categorisation systems that are not prohibited are classified as high-risk under Annex III §1. Full compliance with Articles 9–49 is required, including demographic performance testing (Article 15) and WORM logging (Article 12).

Real-time remote restrictions

The prohibition on real-time remote biometric identification in public spaces for law enforcement is already in force from February 2025. Commercial systems that operate near this boundary need clear classification before deployment.

How Scanara helps biometric AI companies

Article 5 prohibited practice checker

Scanara scans your codebase for patterns associated with prohibited biometric practices: real-time location correlation, sensitive attribute inference, and social scoring pipelines. Findings are flagged with the specific Article 5 sub-clause for legal review.

Annex III §1 compliance scanning

Full scanning against all high-risk obligations that apply to biometric AI: risk management, data governance (including bias evaluation across demographic groups), transparency, human oversight, and accuracy/robustness requirements.

Demographic performance gap detection

Article 15 requires biometric AI to maintain consistent accuracy across demographic groups. Scanara flags code where demographic performance monitoring is absent or inadequate, and generates Article 15-specific finding reports.

Clear allowed/prohibited boundary documentation

Scanara generates documentation that clearly maps your biometric system's use case to the allowed/prohibited boundary, supporting internal legal review and external regulatory enquiries.

The stakes for biometric AI

€35M

Maximum fine for Article 5 prohibited practice violations: €35 million or 7% of global annual turnover. Prohibited practice enforcement applies now — from February 2025.

€15M

Maximum fine for Annex III §1 high-risk AI violations from August 2026. Biometric AI faces dual exposure across both enforcement regimes.

Frequently asked questions

Check your biometric AI for Article 5 and Annex III §1

Scan your biometric system and see exactly where it sits relative to the Article 5 prohibited boundary and Annex III §1 high-risk obligations.

See demo

How Scanara Helps

Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.