EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Biometric Identification, Categorisation and Emotion Recognition

Remote biometric identification, biometric categorisation and emotion recognition are high-risk under Annex III(1) of the EU AI Act, and several uses are banned outright. The full map.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

Depends on use

High-risk (Annex III, point 1); prohibited in several configurations (Art. 5); verification-only is out of scope

When it applies

Prohibitions apply since 2 February 2025. Annex III obligations apply from 2 December 2027.

Regulation (EU) 2024/1689, Annex III(1)(a)-(c); Art. 5(1)(e), (f), (g), (h); Art. 50(3); GDPR Art. 9

Biometrics is the area where the EU AI Act draws its hardest lines. Some uses are prohibited: untargeted scraping of facial images to build recognition databases, emotion recognition at work and in education, biometric categorisation that infers race, political opinions, trade-union membership, religion, sex life or sexual orientation, and real-time remote biometric identification in public spaces for law enforcement outside narrow exceptions. Other uses are high-risk: remote biometric identification generally, categorisation by sensitive attributes, and emotion recognition elsewhere.

One important exclusion: biometric verification whose sole purpose is to confirm that a person is who they claim to be (unlocking a phone, matching a selfie to an ID at onboarding) is not remote identification and is not on the list. The distinction is between “is this the person they claim to be” (verification, out of Annex III) and “who is this person among many” (identification, high-risk).

Classification

Why this classification applies

Annex III, point 1 covers (a) remote biometric identification systems, excluding verification; (b) biometric categorisation according to sensitive or protected attributes or characteristics based on inference of those attributes; and (c) emotion recognition systems.

Article 5 removes specific configurations from the market entirely. The emotion-recognition ban in the workplace and education, and the categorisation ban for protected characteristics, apply to private companies as much as to public bodies. The real-time public-space identification ban is addressed to law enforcement, with post-remote identification subject to judicial authorisation.

Article 50(3) adds a transparency duty: deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them, and GDPR Article 9 governs the underlying processing of biometric data as a special category.

Obligations

What you have to do

  • Map every biometric function against Art. 5 first; discontinue anything within a prohibition regardless of consent or contract.
  • For remaining Annex III(1) systems: full high-risk obligations, with a notified-body conformity assessment for remote biometric identification unless harmonised standards are applied in full (Art. 43(1)).
  • Human oversight with the “two-person rule”: for remote biometric identification, no action on an identification without verification by at least two competent persons, unless national law provides otherwise (Art. 14(5)).
  • Data governance with documented accuracy across demographic groups; accuracy disparities are the leading enforcement risk (Arts. 10, 15).
  • Inform exposed persons where emotion recognition or biometric categorisation is used (Art. 50(3)); GDPR Art. 9 legal basis and DPIA.
  • Registration in the EU database and, for public-sector or public-service deployers, a fundamental rights impact assessment (Arts. 27, 49).

Paperwork

Documents to have on file

Art. 5 prohibition review memo
Annex IV technical documentation
Risk management file with demographic accuracy analysis
Data governance records and GDPR DPIA
Human oversight procedure including the two-person verification rule
Notified-body certificate where applicable
Transparency notice for exposed persons (Art. 50(3))
EU declaration of conformity and EU database registration

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Calling an identification system “verification” because it matches against a watch-list. Matching one face against many is identification.
  • Retail “VIP recognition” or “known shoplifter” systems. These are remote biometric identification in publicly accessible spaces by private operators: high-risk, with strict GDPR limits on top.
  • Emotion or mood analytics in HR, call centres or classrooms. Prohibited since February 2025.
  • Inferring demographics such as ethnicity for “analytics”. Categorisation by protected characteristics is prohibited; categorisation by non-sensitive attributes remains high-risk.

FAQ

Frequently asked questions

Is face-unlock in our app regulated?

Biometric verification for authentication is excluded from Annex III(1)(a). GDPR still applies to the biometric template, but the AI Act’s high-risk regime does not.

Can we detect age from a face for age assurance?

Age is not a protected characteristic listed in Art. 5(1)(g), so age estimation is not prohibited. It is still biometric categorisation and may be high-risk under Annex III(1)(b) if based on inference of characteristics; assess it and apply Art. 50(3) transparency.

Do the bans apply to non-EU companies?

Yes, whenever the system is placed on the EU market or its output is used in the EU. Providers outside the EU must also appoint an authorised representative (Art. 22).

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-25. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026. Leer en español.

Related use cases

Depends on use

Predictive policing & law enforcement AI

Read →

High-risk

Migration, asylum & border control AI

Read →

High-risk

Employee monitoring & performance

Read →

Guide

EU AI Act compliance guide

Read →