AIPolicyTracker
Legal requirement Governance and accountability European Union Partially applicable

Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually

Context fileUnder EU AI Act, Article 26(10)

Source-linked Open official source

What does it require?

A deployer using a high-risk post-remote biometric identification system in a criminal investigation must request authorisation from a judicial or independent administrative authority in advance or within 48 hours, unless the use is only the initial identification of a potential suspect on objective and verifiable facts. Use is limited to a targeted search; if authorisation is refused, use stops and the data is deleted. No adverse legal decision may rest solely on the output, each use is documented, and the deployer reports annually to the market surveillance and data protection authorities.

Practical action

Build the authorisation request, 48-hour clock and deletion step into the investigation workflow and schedule the annual report.

Who does it apply to?

Law enforcement authorities deploying post-remote biometric identification in criminal investigations; real-time use is governed by Article 5.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • supportsPolicyExecutive sponsor for AI · annual
    AI governance policy and accountability structure

    Serves 16 recorded duties · evidence: AI policy, Board or executive approval of the AI policy, AI governance forum minutes

    Authorisation workflow ownership.

  • supportsProcessAI system owner · once per ai system
    Human oversight design and override procedure

    Serves 11 recorded duties · evidence: Human oversight and override procedure, Human-involvement design rationale, Overseer training completion

    No adverse decision solely on the system's output.

  • supportsTechnical measureEngineering lead · continuous
    Automatic event logging and record retention

    Serves 8 recorded duties · evidence: AI system event logs, Log schema and retention standard, Log integrity and retention check

    Per-use documentation and annual reporting data.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
Authorisation request and decision recordrecord
Annual report on post-remote biometric identification usereport

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Annex A.9.2, A.9.4Processes for responsible use and intended use.low
NIST AI RMF 1.0GOVERN 1.1, MANAGE 1.3Legal requirements and documented use decisions.low

Cite this record

AIPolicyTracker (2026). “Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-26-10-post-remote-biometric-identification-authorisation (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.