Regulation · · 4 min

What the EU AI Act means for biometric identification

The Act bans some biometric practices outright and classes remote biometric identification as high-risk — while explicitly excluding pure 1:1 verification.

What the EU AI Act means for biometric identification

The EU AI Act (Regulation 2024/1689) was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024, with obligations phasing in over the following years. It is the first comprehensive, risk-based law governing AI — and it treats biometrics with particular care.

Some practices are banned outright. Article 5 prohibits biometric categorisation that infers sensitive attributes such as race, political opinions, religion or sexual orientation, and it prohibits most real-time remote biometric identification in publicly accessible spaces by law enforcement — allowing only three narrow exceptions (searching for victims of abduction, trafficking or missing persons; preventing a specific, imminent threat to life or a genuine terrorist threat; and locating suspects of serious crimes).

Other biometric systems — remote biometric identification, biometric categorisation and emotion recognition — are not banned but are classified as high-risk under Annex III, bringing obligations on data governance, transparency, human oversight and logging.

Crucially for many products, pure one-to-one verification — confirming a person is who they claim to be — is explicitly excluded from the high-risk category. The Act steers deployments toward consented, purpose-limited verification and away from untargeted public surveillance.

Source: EU AI Act — Article 5

All updates