By use case · Biometrics and facial recognition
Biometric and facial recognition AI: the rules that apply
Biometric AI is where prohibitions live. Real-time remote identification in public spaces, biometric categorisation by sensitive traits and emotion recognition in workplaces and schools are banned or tightly conditioned in several jurisdictions; where a biometric use is allowed it is almost always high-risk, with the full set of provider and deployer duties on top of data-protection rules for biometric data.
- Jurisdictions
- 7
- Evidence items
- 67
Screen for prohibited uses first
The prohibited-use gate is a control of its own below: an inventory question answered before any risk assessment, because a prohibited use has no compliant configuration.
Then the high-risk set
Accuracy across demographic groups, human verification of matches, logging and a data-protection impact assessment are the duties that follow. The controls are listed with the incident history of the risk areas they address.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| Privacy and data-protection controls for AI Process | 4 | 2 | Data protection officer · once per ai system |
| Automatic event logging and record retention Technical measure | 2 | 3 | Engineering lead · continuous |
| Prohibited and unacceptable-use screening gate Process | 2 | 1 | AI governance lead · once per ai system |
| Accuracy, robustness, fairness and security testing Technical measure | 2 | 0 | Quality or testing lead · at launch and on material change |
| AI governance policy and accountability structure Policy | 1 | 2 | Executive sponsor for AI · annual |
| Conformity assessment, declaration and registration Process | 1 | 1 | Regulatory compliance lead · once per ai system |
| Human oversight design and override procedure Process | 1 | 1 | AI system owner · once per ai system |
| Data governance and dataset documentation Process | 1 | 0 | Data governance lead · once per ai system |
| AI interaction and use disclosure notices Process | 1 | 0 | Product owner · at launch and on material change |
| Contractual allocation of AI duties across the supply chain Contractual term | 1 | 0 | Legal counsel · once per ai system |
| AI risk assessment and lifecycle risk register Process | 1 | 0 | AI system owner · once per ai system |
| Public-sector AI use-case register and algorithmic transparency Process | 1 | 0 | Agency AI officer · annual |
| AI incident management and regulatory reporting Process | 1 | 0 | Incident coordinator · continuous |
| AI impact and fundamental-rights impact assessment Process | 0 | 3 | AI system owner · once per ai system |
| Adversarial and red-team testing for generative AI Technical measure | 0 | 2 | AI security or safety lead · at launch and on material change |
| Post-deployment monitoring and drift detection Technical measure | 0 | 2 | AI system owner · continuous |
| Training-data provenance and copyright register Process | 0 | 2 | Model development lead · at launch and on material change |
| Technical documentation, model cards and instructions for use Process | 0 | 2 | Product or model owner · at launch and on material change |
| Quality management system for AI development and supply Policy | 0 | 2 | Quality lead · annual |
| AI system inventory and classification Process | 0 | 2 | AI governance lead · continuous |
| AI literacy and role-based training programme Training programme | 0 | 1 | Learning and development lead · annual |
| Vendor and third-party AI due diligence Process | 0 | 1 | Procurement or vendor risk lead · once per ai system |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
European Union 15 duties
-
Legal requirementEU AI Act · Article 15applies from 2 Aug 2026Achieve appropriate accuracy, robustness and cybersecurity
-
Legal requirementEU AI Act · Article 10applies from 2 Aug 2026Apply data governance and quality criteria to training, validation and testing data
-
Legal requirementEU AI Act · Articles 43, 47, 48 and 49; Annex VIIIapplies from 2 Aug 2026Complete conformity assessment, CE marking and EU database registration
-
Legal requirementEU AI Act · Article 26(9)applies from 2 Aug 2026Deployers must use the provider's transparency information in their data protection impact assessment
-
Legal requirementEU AI Act · Article 50(3)applies from 2 Aug 2026Deployers of emotion recognition or biometric categorisation must inform exposed persons
-
Legal requirementEU AI Act · Article 12; Article 26(6) for deployersapplies from 2 Aug 2026Design high-risk systems to log events automatically
-
Legal requirementEU AI Act · Article 5applies from 2 Feb 2025Do not deploy or provide AI for prohibited practices
-
Legal requirementEU AI Act · Article 14; Article 26(2) for deployersapplies from 2 Aug 2026Enable and assign effective human oversight
-
Legal requirementEU AI Act · Article 26(10)applies from 2 Aug 2026Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
-
Legal requirementEU AI Act · Article 22applies from 2 Aug 2026Non-EU providers must appoint an EU authorised representative for high-risk AI
-
Legal requirementEU AI Act · Article 16applies from 2 Aug 2026Providers must meet the full set of provider duties for high-risk AI
-
Legal requirementEU AI Act · Article 19applies from 2 Aug 2026Providers must retain automatically generated logs under their control
-
Legal requirementEU AI Act · Article 21applies from 2 Aug 2026Providers must supply conformity evidence and log access to authorities on request
-
Legal requirementEU AI Act · Article 26(8); Article 49(3) and 49(4)applies from 2 Aug 2026Public authorities must register their use of high-risk AI and must not use unregistered systems
-
Legal requirementEU AI Act · Article 73applies from 2 Aug 2026Report serious incidents to market surveillance authorities
Nepal 1 duty
-
Legal requirementNepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)Collect and use personal information only with consent and for the stated purpose
South Korea 1 duty
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must establish and operate a risk management plan
Texas (United States) 1 duty
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.054applies from 1 Jan 2026Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
United Arab Emirates 1 duty
-
Legal requirementUAE PDPL · Article on data protection impact assessment (reviewer to cite article number)Conduct a data protection impact assessment for high-risk processing using new technologies
United Kingdom 1 duty
-
Legal requirementICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance sectionCarry out a data protection impact assessment for high-risk AI processing
United States 1 duty
-
VoluntaryNIST AI RMF · MEASURE functionMeasure and test trustworthiness characteristics (Measure)
What evidence would a reviewer expect?
- AI customer or deployer clause set Contract clause or supplier term
- AI data-flow and legal-basis record Register entry
- AI governance forum minutes Governance meeting record
- AI impact assessment Impact assessment
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI intake and classification procedure Procedure or standard operating process
- AI interaction or use notice Disclosure or notice
- AI policy Policy document
- AI quality management system manual Policy document
- AI responsibility map Register entry
- AI supplier and component register Register entry
- AI supplier clause set Contract clause or supplier term
- AI supplier due-diligence assessment Supplier assessment
- AI system event logs Access or activity log
- AI system register Register entry
- AI system risk assessment Risk assessment
- AI training completion records Training record
- AI training curriculum and materials Policy document
- Adversarial findings tracker Risk register
- Algorithmic transparency statement for one use case Disclosure or notice
- Board or executive approval of the AI policy Approval or sign-off record
- Conformity evidence pack Technical documentation file
- Contract clause index against the AI register Register entry
- Copyright and rights-reservation policy Policy document
- Data protection impact assessment for an AI system Data protection impact assessment
- Data quality and bias check report Evaluation or test report
- Dataset approval for use Approval or sign-off record
- Dataset documentation sheet Dataset documentation
- Declaration of conformity or certificate Conformity declaration or certificate
- Human oversight and override procedure Procedure or standard operating process
- Human-involvement design rationale Approval or sign-off record
- Impact assessment approval Approval or sign-off record
- Impact assessment procedure and template Procedure or standard operating process
- Incident report to an authority Regulatory filing or notification
- Independent data audit or DPO review Audit or assurance report
- Instructions for use Disclosure or notice
- Internal audit of the AI management system Audit or assurance report
- Inventory review and publication sign-off Approval or sign-off record
- Log integrity and retention check Audit or assurance report
- Log schema and retention standard Procedure or standard operating process
- Management review minutes Governance meeting record
- Model card or deployer information pack Model documentation
- Monitoring dashboard or periodic monitoring report Monitoring record
- Monitoring review decision Approval or sign-off record
- Notice catalogue Register entry
- Notice wording approval Approval or sign-off record
- Overseer training completion Training record
- Per-system AI risk register Risk register
- Post-market monitoring plan Procedure or standard operating process
- Pre-release test report Evaluation or test report
- Privacy notice section on AI use Disclosure or notice
- Prohibited-use screening record Approval or sign-off record
- Public AI use-case inventory Register entry
- Public summary of training content Disclosure or notice
- Red-team exercise report Evaluation or test report
- Red-team rules of engagement and scenario library Procedure or standard operating process
- Registration record in the relevant database Regulatory filing or notification
- Release test sign-off Approval or sign-off record
- Residual-risk acceptance Approval or sign-off record
- Risk-tier classification sign-off Approval or sign-off record
- Role-to-curriculum training matrix Procedure or standard operating process
- Screening list and escalation procedure Procedure or standard operating process
- Supplier onboarding decision Approval or sign-off record
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Training source register Register entry
Latest changes to these instruments
Texas TRAIGA takes effect
European Commission proposes Digital Omnibus adjustments to AI Act timelines
EU AI Act general-purpose AI, governance and penalty provisions start to apply
European Commission publishes the General-Purpose AI Code of Practice
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is verification (one-to-one) treated like identification (one-to-many)?
- Generally no: one-to-one verification such as unlocking a device is often excluded from the strictest categories, while one-to-many identification is the prohibited or high-risk case. The duty page cites the definition.
- What evidence does a permitted biometric use need?
- The prohibited-use screening record, the impact assessment, accuracy testing by group, the human verification procedure, the notice, and the logs.