EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · LAW ENFORCEMENT · HIGH-RISK · PROHIBITED USE

BEFORE LAW-ENFORCEMENT AI ACTS,
THE AUTHORITY AND EVIDENCE HAVE TO HOLD.

Law-enforcement AI sits at one of the Act’s strictest boundaries. Some uses are prohibited, others are high-risk, and biometric deployment can trigger additional necessity and authorisation conditions. The governance question is not only whether the model performs—it is whether the use remained legally and evidentially bounded at the moment of consequence.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Article 5, Article 6 and Annex III

The Regulation prohibits certain criminal-risk assessments and tightly restricts real-time remote biometric identification for law-enforcement purposes, while Annex III places specified law-enforcement systems on high-risk pathways. Biometric and other personal-data processing remains subject to additional Union and Member State law.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

IS THE USE PROHIBITED BEFORE YOU EVEN REACH HIGH-RISK?

Article 5 prohibits certain law-enforcement uses, including criminal-risk assessment based solely on profiling or personality traits, subject to the Regulation’s narrow distinction for human assessment already grounded in objective and verifiable facts.

02

IS THE SYSTEM ON AN ANNEX III LAW-ENFORCEMENT ROUTE?

Annex III includes specified law-enforcement uses such as victim-risk assessment, polygraph or similar tools, evaluation of evidence reliability, certain offending or reoffending assessments, and profiling during detection, investigation or prosecution.

03

DO BIOMETRIC IDENTIFICATION RULES APPLY?

Real-time remote biometric identification in publicly accessible spaces for law enforcement is generally prohibited, with tightly bounded exceptions requiring necessity, safeguards and authorisation conditions.

04

CAN YOU PROVE AUTHORITY, NECESSITY AND DEPLOYMENT SCOPE?

Preserve the legal authority, operational purpose, case or deployment scope, system version, data sources, human decision role, approval path, logs, oversight, exception relied on, and evidence that use stayed within the declared boundary.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Test Article 5 prohibitions first

Do not treat a prohibited practice as simply a higher compliance tier. Determine whether the intended law-enforcement use is allowed before moving into Annex III or other operational requirements.

02

Classify the exact law-enforcement function

Separate victim-risk assessment, evidence evaluation, profiling, biometric identification, polygraph-like functions, offending-risk assessment, and other uses. Each function can sit on a different legal route.

03

Bind authority and human judgment to evidence

Connect legal authority, necessity, proportionality, objective case facts, human review, logging, technical documentation, access controls, performance limits and approval evidence to the exact deployment.

04

Revalidate whenever purpose, facts or authority change

A new investigation type, jurisdiction, target population, model, dataset, biometric capability, profiling purpose, approval basis or legal source can materially change whether the prior deployment remains governable.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Does the EU AI Act prohibit predictive policing?

It prohibits AI systems used to assess or predict a natural person’s risk of committing a criminal offence when that assessment is based solely on profiling or on personality traits and characteristics. The Regulation distinguishes this from AI used to support a human assessment already based on objective and verifiable facts directly linked to criminal activity.

Which law-enforcement AI systems are high-risk?

Annex III lists specified law-enforcement uses, including systems for assessing a person’s risk of becoming a crime victim, polygraph or similar tools, evaluating evidence reliability, certain offending or reoffending assessments not solely based on profiling, and profiling during criminal detection, investigation or prosecution.

Is real-time facial recognition by police allowed?

Real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes is generally prohibited, subject to narrowly defined exceptions and strict necessity, safeguard and authorisation conditions.

Do law-enforcement high-risk systems require the same controls as other high-risk AI?

The high-risk framework still matters, but law-enforcement systems also operate inside additional Union and Member State legal constraints, including rules on personal-data processing, criminal procedure, necessity, proportionality and competent authority.

What evidence should be preserved?

Preserve system identity and version, intended purpose, legal authority, case or deployment scope, objective facts relied on, data provenance, human decision role, approvals, logs, technical evidence, limitations, exceptions, changes and the basis for continued reliance.

Does TA-14 determine that a police AI deployment is legally authorised?

No. TA-14 can preserve the authority claim, classification basis, evidence, scope, gaps, review history and revalidation state. It does not itself provide legal authorisation, legal advice, conformity assessment, certification or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views