EU AI Act Compliance for Biometrics
EU AI Act compliance for biometric AI systems, covering prohibited practices, high-risk classification, and real-time identification.
Biometric AI systems in the EU must navigate a complex regulatory landscape. The EU AI Act divides biometric applications into prohibited, high-risk, and transparency-required categories.
Understanding which tier your system falls into is critical for compliance and market access.
Prohibited Biometric Practices
The EU AI Act bans certain biometric uses outright. Violations carry penalties up to €35 million or 7% of global turnover.
Real-time Remote Biometric Identification in Public Spaces
Law enforcement use of live facial recognition in publicly accessible spaces is prohibited, with narrow exceptions for child trafficking prevention, missing persons, and preventing imminent threats.
Biometric Categorization by Protected Attributes
Using biometric data to infer or categorize individuals by race, political opinions, religion, trade union membership, or sexual orientation is strictly prohibited.
Emotion Recognition in Work and Education
Emotion recognition systems in workplace or educational settings are banned unless the sole purpose is medical diagnosis or safety monitoring.
Untargeted Facial Image Scraping
Creating facial recognition databases through untargeted scraping of facial images from the internet or surveillance footage without explicit purpose is prohibited.
High-Risk Biometric Systems
Remote Biometric Identification Systems
Biometric identification systems that perform 1:many matching (e.g., airport border control, workplace access control) outside prohibited contexts are classified as high-risk and require documented accuracy, human review, and explicit legal basis.
Biometric Categorization Systems
Biometric categorization systems not covered by prohibitions (e.g., age estimation, gender classification for non-discriminatory purposes) require documentation, accuracy testing, and transparent disclosure to affected individuals.
Key Distinction: Verification vs. Identification
Biometric Verification (1:1 Matching)
Verification compares a biometric sample against a known profile to confirm identity (e.g., unlocking a phone, payment authentication). This is generally not high-risk under the EU AI Act.
Biometric Identification (1:many Matching)
Identification searches a biometric sample against a database of many profiles to find a match (e.g., searching a wanted persons database). This typically qualifies as high-risk.
Practical Examples
Phone Unlock with Face ID
Biometric verification on a personal device comparing a live face to a stored profile.
Verification system. Not high-risk unless deployed in a high-stakes context (e.g., border control).
Airport Biometric Border Control
Scanning travelers' faces against passport databases and watchlists at border checkpoints.
High-risk identification system. Requires accuracy documentation, human review, and legal basis.
Workplace Emotion Monitoring
Analyzing employee facial expressions to infer stress, engagement, or emotional state during work hours.
Strictly prohibited unless medically necessary or for safety monitoring.
Retail Facial Recognition for Marketing
Using in-store cameras to identify repeat customers or infer demographics for personalized advertising.
Prohibited if used for real-time mass identification or protected attribute inference; high-risk if limited to consent-based profiles.
Compliance Checklist
euAiAct.industryBiometrics.checklist1Desc
euAiAct.industryBiometrics.checklist2Desc
euAiAct.industryBiometrics.checklist3Desc
euAiAct.industryBiometrics.checklist4Desc
euAiAct.industryBiometrics.checklist5Desc
euAiAct.industryBiometrics.checklist6Desc
euAiAct.industryBiometrics.checklist7Desc
euAiAct.industryBiometrics.checklist8Desc
Compliance Penalties
Maximum penalty for prohibited biometric practices.
Maximum penalty for high-risk system non-compliance.
Frequently Asked Questions
Related Regulations and Resources
Article 5 – Prohibited Practices
Full legal text defining prohibited biometric AI uses.
Article 6 – Classification of High-Risk AI
Defines which biometric systems qualify as high-risk and required safeguards.
Article 50 – Transparency Requirements
Individuals exposed to emotion recognition or biometric categorization must be transparently informed.
Biometric Compliance Checklist
Step-by-step verification guide for biometric AI systems.
How Scanara Helps
Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.