Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
Context fileUnder EU AI Act, Article 26(10)
What does it require?
A deployer using a high-risk post-remote biometric identification system in a criminal investigation must request authorisation from a judicial or independent administrative authority in advance or within 48 hours, unless the use is only the initial identification of a potential suspect on objective and verifiable facts. Use is limited to a targeted search; if authorisation is refused, use stops and the data is deleted. No adverse legal decision may rest solely on the output, each use is documented, and the deployer reports annually to the market surveillance and data protection authorities.
Practical action
Build the authorisation request, 48-hour clock and deletion step into the investigation workflow and schedule the annual report.
Who does it apply to?
Law enforcement authorities deploying post-remote biometric identification in criminal investigations; real-time use is governed by Article 5.
- Sectors
- Law enforcement and justice
Applies from:
Which controls meet this duty?
Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.
-
supportsPolicyExecutive sponsor for AI · annualAI governance policy and accountability structure
Serves 16 recorded duties · evidence: AI policy, Board or executive approval of the AI policy, AI governance forum minutes
Authorisation workflow ownership.
-
supportsProcessAI system owner · once per ai systemHuman oversight design and override procedure
Serves 11 recorded duties · evidence: Human oversight and override procedure, Human-involvement design rationale, Overseer training completion
No adverse decision solely on the system's output.
-
supportsTechnical measureEngineering lead · continuousAutomatic event logging and record retention
Serves 8 recorded duties · evidence: AI system event logs, Log schema and retention standard, Log integrity and retention check
Per-use documentation and annual reporting data.
What evidence would a reviewer expect?
| Evidence | Type | Notes |
|---|---|---|
| Authorisation request and decision record | record | |
| Annual report on post-remote biometric identification use | report |
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
See every European Union duty mapped this way →
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Annex A.9.2, A.9.4 | Processes for responsible use and intended use. | low |
| NIST AI RMF 1.0 | GOVERN 1.1, MANAGE 1.3 | Legal requirements and documented use decisions. | low |
Cite this record
AIPolicyTracker (2026). “Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-26-10-post-remote-biometric-identification-authorisation (accessed 24 September 2026). Data licensed CC BY 4.0.
Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Similar obligations in other instruments
- Non-EU providers of GPAI models must appoint an EU authorised representative — EU AI Act, European Union
- Providers must meet the full set of provider duties for high-risk AI — EU AI Act, European Union
- Use high-risk AI as instructed, monitor it and inform affected people — EU AI Act, European Union
- Providers must supply conformity evidence and log access to authorities on request — EU AI Act, European Union
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI — EU AI Act, European Union
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold — EU AI Act, European Union
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures — Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust, South Korea
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.