What the AI Act Means for Facial Recognition in Europe
Facial recognition has moved from science-fiction imagery into airports, police databases, retail stores, smartphones, and public streets. Its appeal is obvious: a camera can compare a face with a reference image in seconds. Its risks are equally significant. A mistaken match can affect someone’s liberty, employment, access to services, or ability to move through public space.
The European Union’s Artificial Intelligence Act is the world’s first broad legal framework for artificial intelligence. It does not create a single, simple rule saying that facial recognition is either legal or illegal. Instead, it divides AI systems by risk, prohibits some uses, imposes strict conditions on others, and leaves important decisions to national governments and existing privacy law.
That distinction matters. The AI Act changes the legal environment for facial recognition, but it does not replace the General Data Protection Regulation, law enforcement data-protection rules, constitutional safeguards, or national legislation. Understanding the result requires looking at the purpose of the system, who operates it, where it is used, and whether it identifies people in real time.
The law uses a risk-based structure
The AI Act classifies artificial intelligence according to the potential harm caused by a particular use. Minimal-risk systems, such as many spam filters or video game features, face few obligations. High-risk systems must meet detailed requirements involving data quality, technical documentation, human oversight, accuracy, cybersecurity, and record keeping.
Some practices are prohibited because the European legislature considers their risks fundamentally unacceptable. The ban covers several forms of biometric manipulation and exploitation. These include certain systems that infer emotions in workplaces and schools, biometric categorisation that attempts to assign sensitive characteristics, and the untargeted scraping of facial images from the internet or security-camera footage to create or expand facial-recognition databases.
This framework means the same technical capability can receive different treatment depending on its context. A face-matching tool used to unlock a phone is legally different from a system that scans a crowd for suspects. A system verifying whether a person matches their passport is different from one inferring their political opinions or emotional state.
Real-time identification in public spaces faces the strictest limits
The most politically sensitive issue is real-time remote biometric identification. This usually means using live camera feeds to identify people at a distance in publicly accessible places, such as streets, stations, demonstrations, or shopping areas. The AI Act generally prohibits law enforcement from using this technology in those spaces.
However, the prohibition has narrow exceptions. Authorities may seek to use real-time identification for a targeted search involving specific victims of crimes, to prevent a serious and imminent threat to life or physical safety, or to locate a person suspected of a serious criminal offence. The precise conditions include limits on the seriousness of the situation, temporal and geographic boundaries, and authorisation requirements.
These exceptions are not a general permission for continuous surveillance. They are intended to be exceptional, necessary, and proportionate interventions. Depending on the circumstances, a judicial or independent administrative authorisation is required. National authorities must also establish procedures, oversight, reporting, and safeguards for affected people.
The details will matter in practice. A broad statutory exception can become a routine operational tool if authorities define “serious” threats expansively. Courts, data-protection regulators, parliaments, journalists, and civil-society groups will therefore influence how much protection the rules provide beyond their wording.
Retrospective searches remain a major privacy issue
The AI Act distinguishes live identification from retrospective or post-event biometric identification. A system that searches recorded CCTV footage after an incident is not treated in exactly the same way as a live system scanning a crowd. This difference leaves law enforcement more room to use historical footage, subject to the relevant legal basis and safeguards.
That gap has attracted criticism because retrospective searches can still create extensive surveillance. Authorities may be able to collect large amounts of footage first and decide later whose faces to analyse. Even if a search occurs after an event, the process can reveal who attended a protest, visited a clinic, entered a religious building, or met with political groups.
The AI Act therefore should not be read in isolation. The GDPR generally restricts biometric data used to uniquely identify a person, while the Law Enforcement Directive governs processing by competent authorities for criminal-law purposes. The EU Charter of Fundamental Rights and national constitutional protections add requirements concerning privacy, data protection, equality, and effective remedies.
Accuracy creates another problem. Facial-recognition performance varies with image quality, lighting, demographic characteristics, age, and the design of the reference database. A high confidence score is not proof of identity. Human review, access to evidence, the ability to challenge a match, and meaningful investigation into false positives are essential safeguards.
Public authorities and companies inherit different duties
Public bodies that deploy high-risk AI systems will have to assess risks, keep logs, provide human oversight, and monitor performance. The Act also introduces a fundamental-rights impact assessment for certain public-sector deployers and private organisations providing publicly essential services. Such an assessment should examine foreseeable effects on groups and individuals before deployment.
Providers of high-risk biometric systems carry extensive responsibilities before placing them on the European market. They must establish risk-management processes, maintain technical files, use suitable data governance, meet accuracy and cybersecurity requirements, and report serious incidents. Deployers must follow operating instructions and ensure that people supervising the system have appropriate competence.
Private businesses cannot assume that facial recognition becomes acceptable simply because the police are not involved. Retailers, employers, venues, transport companies, and landlords must still comply with the GDPR and national employment, consumer, equality, and surveillance laws. Consent can be difficult to establish in places where refusing a scan means losing access to a service or opportunity.
The wider surveillance economy provides useful context here. Facial recognition is part of a larger system in which data is collected, inferred, traded, and used to shape decisions. The surveillance economy helps explain why the question is not merely whether a camera recognises a face, but who controls the resulting data and what incentives govern its use.
| Use of facial analysis | General position under the AI Act | Issues that still matter |
|---|---|---|
| Phone or device unlocking | Usually outside the strictest public-surveillance rules | Data security, consent, device privacy, and other product laws |
| One-to-one identity verification | May be permitted, depending on purpose and system design | Necessity, biometric-data rules, accuracy, alternatives, and retention |
| Live police identification in public spaces | Generally prohibited, with narrow exceptions | Authorisation, urgency, crime severity, geography, duration, and oversight |
| Retrospective police search of recorded footage | More legally permissive than live identification | Law Enforcement Directive, GDPR where applicable, warrants, retention, and redress |
| Emotion recognition in workplaces or schools | Generally prohibited, subject to limited exceptions | Purpose, inferred data, discrimination, coercion, and national employment law |
| Commercial crowd analytics | Potentially high-risk or otherwise restricted | Legal basis, transparency, profiling, discrimination, and deletion policies |
| Untargeted scraping of facial images | Prohibited when used to build or expand facial-recognition databases | Source legality, purpose limitation, copyright, privacy, and enforcement |
The rules do not eliminate private surveillance
The AI Act attracts attention because it regulates state power, but many facial-analysis systems are operated by commercial organisations. Shopping centres may want to identify repeat visitors, stadiums may screen for banned individuals, and employers may experiment with attendance or emotional-state monitoring. These uses can generate intrusive profiles even when no criminal investigation is involved.
A familiar consumer technology example shows how normalised monitoring can become. A smart TV surveillance perspective makes the broader point: people often buy devices or enter spaces without realising how much information is collected in the background. Facial recognition can extend that pattern from viewing habits and device identifiers to bodies, movements, associations, and presence.
Transparency is therefore more than a sign at a building entrance. People should be told that biometric processing is taking place, why it is necessary, who receives the data, how long it is retained, and how they can object or complain. A vague statement that cameras are used “for security” does little to explain whether faces are being matched, categorised, or shared.
The AI Act also cannot resolve every question about power. A lawful system may still alter behaviour by making people feel watched. It may discourage attendance at protests or community events, reinforce unequal treatment, or shift the practical balance between individuals and institutions. Those consequences belong in democratic debate even where a deployment passes a formal compliance test.
Enforcement will determine the law’s real effect
The Act provides substantial penalties for violations. For the most serious breaches, including prohibited AI practices, companies can face fines of up to €35 million or 7% of their worldwide annual turnover, whichever is higher. Other infringements carry lower maximums. Member states will designate national competent authorities, while the European AI Office will have a role in supervising certain general-purpose AI obligations and supporting consistent implementation.
The timetable is phased. The provisions on prohibited practices began applying in February 2025, while many other requirements, including major obligations for high-risk systems, become applicable later. This staggered approach gives organisations time to adapt, but it also creates a period in which systems may operate under changing interpretations and incomplete enforcement structures.
Regulators will need technical expertise and sufficient resources. They must be able to inspect procurement contracts, examine training and reference data, test accuracy across demographic groups, review logs, and investigate complaints. Formal compliance documents are not enough if authorities cannot determine what a system actually does in the field.
Individuals need practical remedies as well. A person wrongly flagged by a facial-recognition system should be able to find out that biometric processing influenced a decision, challenge the result, obtain human review, and seek correction or compensation where appropriate. Without accessible complaint routes, rights remain largely theoretical.
What residents and organisations should watch
The most useful way to read the new rules is as a baseline rather than a guarantee. European residents, journalists, and local communities can monitor procurement notices, public consultations, regulatory guidance, and the policies of organisations using biometric systems. Businesses should examine whether a proposed use is necessary at all before investing in a legally complex tool.
Several practical principles can guide that scrutiny:
- Ask whether the purpose can be achieved with less intrusive methods, such as access cards, human review, or anonymous counting.
- Identify whether a system verifies a person’s claimed identity or searches for unknown individuals in a crowd.
- Check where facial images, templates, logs, and match results are stored, who can access them, and when they are deleted.
- Demand independent testing for false matches, demographic disparities, security weaknesses, and performance in real operating conditions.
- Require a clear process for notice, refusal where possible, human review, complaints, and correction of inaccurate results.
The AI Act gives Europe a common vocabulary for discussing these systems, but national implementation and enforcement will shape the everyday experience. Courts may narrow broad interpretations, regulators may issue meaningful guidance, and legislators may adopt stronger domestic restrictions. Organisations that treat compliance as a paperwork exercise will remain exposed to legal, reputational, and social consequences.
Facial recognition deserves scrutiny because it changes the character of public and private space. A camera that records an image is invasive; a camera that turns the image into a searchable identity creates a much more powerful form of control. The European rules recognise part of that distinction, while leaving open difficult questions about historical footage, commercial monitoring, and technological expansion.
Follow the implementation of the AI Act through national regulators, scrutinise biometric deployments in your community, and support clear rules that preserve anonymity in ordinary public life. Organisations using facial recognition should pause high-impact projects, publish their safeguards, and provide real alternatives before asking people to surrender their faces as the price of participation.