Legal 12 min read

Biometric AI Under the EU AI Act: The Rules Every Company Must Know

Facial recognition, emotion detection, and biometric categorization are some of the most heavily regulated — and in some cases outright banned — AI applications under the EU AI Act.

By Thomas Klein, Privacy Counsel · Published

Biometrics: The Most Tightly Controlled AI Category

No category of AI systems faces stricter regulation under the EU AI Act than biometric AI. From facial recognition at airport borders to emotion-detection cameras in retail stores, biometric AI intersects with some of the EU's most fundamental rights: privacy, dignity, and non-discrimination. The AI Act establishes a multi-tier framework — some applications are outright banned, others are high-risk with extensive obligations, and some require only transparency measures.

Outright Bans on Biometric AI (Article 5)

The following biometric AI applications are prohibited under Article 5 of the AI Act: real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions for terrorism/missing children), AI systems that attempt to infer employees' or students' emotional states from biometric signals in workplaces and educational settings, and AI systems that categorize people by protected characteristics (race, political opinion, sexual orientation) using biometric data.

High-Risk Biometric AI (Annex III)

Beyond the prohibited uses, remote biometric identification systems, biometric verification/authentication for access control or banking, and biometric categorization affecting rights are classified as high-risk under Annex III, Section 1. These systems can be deployed — but only with full compliance including conformity assessment, Annex IV technical documentation, and bias testing across demographic groups.

Key Compliance Requirements for Biometric AI

For organizations operating high-risk biometric AI: accuracy and error rate documentation must disclose false acceptance rates (FAR) and false rejection rates (FRR) broken down by gender, skin tone, and age. Every biometric identification decision with consequential outcomes must be subject to human review. And biometric data being special category personal data under GDPR, compliance requires satisfying both the AI Act and GDPR simultaneously.

Operating biometric AI systems? Browse our directory of specialists in biometric AI compliance and GDPR/AI Act intersection.