EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · BIOMETRICS · IDENTIFICATION · CATEGORISATION

BIOMETRIC AI CAN CROSS FROM
HIGH-RISK INTO PROHIBITED USE.

Biometric AI cannot be governed as one generic category. Identification, verification, categorisation, emotion recognition, and remote identification sit on different legal pathways. The first question is what the system actually does—and whether that use is allowed at all.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Article 5, Article 6 and Annex III

The Regulation distinguishes biometric identification from verification, prohibits certain sensitive biometric categorisation and other biometric practices, and places specified biometric systems on high-risk pathways where the use is permitted and the relevant conditions are met.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

IS THE SYSTEM IDENTIFYING, VERIFYING OR CATEGORISING PEOPLE?

The Act distinguishes biometric identification, biometric verification/authentication, and biometric categorisation. Those are not interchangeable labels, and the legal route can change substantially depending on which function the system actually performs.

02

DOES A PROHIBITED-PRACTICE RULE APPLY?

Certain biometric uses are prohibited, including some sensitive-attribute categorisation, untargeted facial-image scraping to build or expand recognition databases, and emotion inference in workplaces or education except for medical or safety purposes.

03

IS THE SYSTEM ON A HIGH-RISK BIOMETRIC ROUTE?

Certain remote biometric identification, biometric categorisation, and emotion-recognition systems can fall within Annex III high-risk categories where the use is not already prohibited and the Regulation’s scope conditions are met.

04

CAN YOU PROVE AUTHORITY, PURPOSE AND OVERSIGHT?

Preserve the exact intended purpose, biometric function, data source, lawful authority, operator role, system version, access controls, human oversight, deployment context, exceptions relied on, and change history.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Define the biometric function precisely

Separate one-to-one verification, one-to-many identification, remote identification, categorisation, and emotion recognition. Do not classify a system merely as “facial recognition” if its actual function is different.

02

Test prohibited-practice rules before high-risk classification

A prohibited use should not be treated as merely a stricter compliance pathway. Establish whether Article 5 blocks the use before moving on to Annex III or other obligations.

03

Bind authority and evidence to the deployment

Connect lawful basis, intended purpose, data provenance, human oversight, technical documentation, logging, access controls, performance, limitations and exception claims to the exact deployed system.

04

Revalidate after purpose, dataset or deployment change

A new camera network, dataset, identification target, deployment environment, law-enforcement use, sensitive-category inference, or model change can materially alter the legal and evidentiary state.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Does the EU AI Act ban biometric AI?

No. It prohibits certain biometric practices and places some other biometric systems on high-risk pathways. The correct answer depends on the function, intended purpose, deployment context, operator, and any specific exception in the Regulation.

Is biometric verification the same as biometric identification?

No. The Regulation distinguishes identification from verification/authentication. Verification generally confirms that a person is who they claim to be, while biometric identification compares biometric data against a reference database to establish identity.

What biometric categorisation is prohibited?

The Act prohibits certain biometric categorisation used to deduce or infer sensitive characteristics such as race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation, subject to the Regulation’s stated exceptions.

What about emotion recognition?

Emotion-recognition systems are treated differently depending on context. The Act prohibits their use to infer emotions in workplaces and education institutions except for medical or safety reasons, while other emotion-recognition uses can fall into high-risk or transparency pathways.

Is real-time remote biometric identification in public spaces prohibited?

For law-enforcement use, the Act generally prohibits real-time remote biometric identification in publicly accessible spaces, subject to narrowly defined exceptions, necessity conditions, authorisation, and safeguards.

Does TA-14 certify a biometric AI system as compliant?

No. TA-14 can preserve the system identity, function, authority basis, evidence, exceptions, gaps, review history, and revalidation state. It does not itself provide legal advice, conformity assessment, certification, or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views