EU AI Act compliance for facial recognition and biometric systems
Biometrics is the area where the Act says no rather than asking for documentation. Several practices are prohibited outright under Article 5 and have been since 2 February 2025, so the first question is never which documents you need.
What survives the prohibitions is high-risk under Annex III point 1, with the full deployer obligation set on top.
Are you a provider or a deployer?
Using a third-party biometric system makes you a deployer. Building one makes you a provider, and for most biometric systems that means third-party conformity assessment.
How this is classified under the Act
Annex III point 1 covers remote biometric identification, biometric categorisation according to sensitive attributes, and emotion recognition. Anything permitted in that space is high-risk. Article 5 removes several uses from the table altogether.
What changes the answer: Prohibited outright: untargeted scraping of facial images to build recognition databases, biometric categorisation inferring race, political opinions, trade union membership, religious beliefs, sex life or sexual orientation, emotion recognition in workplaces and schools, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside narrow judicially authorised exceptions.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 5 Prohibition check before anything else
Run the intended use against the Article 5 list first. If it lands there, no amount of documentation makes it lawful and the project has to change.
- Article 26(2) Human verification of identification
For permitted remote biometric identification, no action may be taken on an identification without separate verification by at least two competent natural persons in the cases the Act specifies.
- Article 27 Fundamental rights impact assessment
Public bodies and certain private deployers must complete a fundamental rights impact assessment before putting the system into use.
- Article 26(6) Logging
Keep logs of operation. For biometric systems these are also the evidence base for demonstrating the prohibitions were respected.
Common mistakes
- Starting with the documentation instead of the Article 5 prohibition check.
- Adding emotion recognition to a workplace access system, which is prohibited rather than high-risk.
- Buying a face database assembled by scraping the web, where the underlying collection is itself prohibited.
- Treating biometric consent under the GDPR as sufficient, when the AI Act bans certain uses regardless of consent.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.