{"answer_id":"praxikon:eu:ai-act:answer:biometrie-gezichtsherkenning","canonical_page":"https://www.praxikon.com/en/antwoord/biometrie-gezichtsherkenning","query":"We are considering facial recognition or other biometrics. Is that allowed?","lang":"en","view":"full","mode":"scenario","question":"We are considering facial recognition or other biometrics. Is that allowed?","situation":"Biometric identification or categorisation of people, such as facial recognition for access or in public spaces.","likely_role":"Deployer (you use the system)","note":"Three layers apply at once: some variants are prohibited under Article 5 (enforceable since 2 February 2025), many others are high-risk under Annex III point 1, and exposed persons must be informed under Article 50. Assess Article 5 first.","matched_terms":[],"dataset":{"id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","version":"2.2.0","schema_version":"1.5.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","last_reviewed_at":"2026-08-08T00:00:00.000Z","licence":"https://www.praxikon.com/nl/legal/terms","canonical_url":"https://www.praxikon.com/api/v1/entities"},"obligations":[{"slug":"article-5-prohibited-practices","label":"Article 5: prohibited practices","summary":"The prohibition of AI practices carrying unacceptable risk, such as manipulation, social scoring and certain biometric applications.","legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-5-prohibited-practices","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"The prohibited practices of Article 5 apply since 2 February 2025 and are the only AI Act category enforceable for that entire period. Violations carry the highest fine ceiling in the regulation: up to 35 million euro or 7 percent of worldwide annual turnover.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5, Article 99(3) and Article 113(a)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"The Digital Omnibus adds a prohibition on AI for child sexual abuse material and non-consensual intimate synthetic content; the accompanying technical safeguards are required by 2 December 2026.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment to Article 5 and transition to 2 December 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The line often sits in the definitional details: the same technique can be prohibited in the workplace and permitted in another context. Screen per concrete use and context, not per technology, and do so before procurement or go-live.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5(1)(a)-(h)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Make the Article 5 screening the first step of every classification and record the outcome per system in the register, including the reasoning why a practice does not fall under the prohibition.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 5 read with Article 6 classification order","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-26-deployer-obligations","label":"Article 26: obligations of deployers of high-risk AI systems","summary":"Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 26 imposes twelve paragraphs on deployers of high-risk AI systems. Paragraph 1 requires appropriate technical and organisational measures to ensure use in accordance with the accompanying instructions for use. Paragraph 2 requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 3 leaves other obligations and the freedom to organise one's own resources unaffected. Paragraph 4 requires, to the extent the deployer exercises control over the input data, that such data is relevant and sufficiently representative in view of the intended purpose. Paragraph 5 requires monitoring on the basis of the instructions for use and informing the provider in accordance with Article 72; where there is reason to consider that use may result in a risk within the meaning of Article 79(1), the deployer shall without undue delay inform the provider or distributor and the relevant market surveillance authority and suspend use, and upon identifying a serious incident shall immediately inform first the provider and then the importer or distributor and the market surveillance authorities. Paragraph 6 requires keeping the automatically generated logs under the deployer's control for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise. Paragraph 7 requires deployers who are employers to inform workers' representatives and the affected workers, before putting into service or using the system at the workplace, that they will be subject to its use. Paragraph 8 imposes the registration obligations of Article 49 on public authorities and Union institutions, bodies, offices and agencies and prohibits use of a system not registered in the EU database referred to in Article 71. Paragraph 9 links the information provided under Article 13 to the data protection impact assessment under Article 35 of Regulation (EU) 2016/679. Paragraph 10 sets additional conditions for post-remote biometric identification in law enforcement. Paragraph 11 opens with the words without prejudice to Article 50 of this Regulation and requires deployers of Annex III systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system; for high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 applies. The transparency obligations of Article 50 have applied since 2 August 2026 and are separate from the date on which paragraph 11 starts to apply. Paragraph 12 requires cooperation with the competent authorities.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"The 2 December 2027 date invites postponement, but two elements are preparation work today. Paragraph 7 requires you to inform workers' representatives and the affected workers before the system is put into service at the workplace, and that information is provided, where applicable, in line with existing rules and practice on informing workers. That touches employee participation, and such a process takes months rather than weeks in practice, so a system that must go live in 2027 is discussed in 2026. Paragraph 2 also connects to the human oversight that Article 14 imposes on system design: you must designate natural persons with competence, training, authority and support. That is emphatically not the same as the measures obligation in Article 4. Article 4 requires measures supporting AI literacy and does not require you to guarantee a particular level for individuals; Article 26(2) requires identifiable overseers with a mandate. Conflating the two leaves you believing a generic e-learning is enough while still having no overseer with room to decide. A third underestimated element is paragraph 11: informing the people about whom an Annex III system makes or helps make decisions is visible customer or candidate communication that you have to design across your own organisation.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Draw up now a list of the systems likely to qualify as high-risk from 2 December 2027 and add three columns: who exercises human oversight and with what mandate, when you will inform the works council and the affected workers, and how the persons concerned will receive the notice under paragraph 11. Plan the employee participation process a year ahead.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-4-ai-literacy","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null},{"kind":"recommended_action","statement":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}]},{"slug":"article-50-transparency","label":"Article 50: transparency","summary":"Specific disclosure, marking and labelling duties for certain AI systems and synthetic content.","legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-50-transparency","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","citations":[{"kind":"official_fact","statement":"Article 50 applies since 2 August 2026. The precise duty differs by scenario: direct AI interaction, machine-readable marking, emotion recognition or biometric categorisation, deepfakes and certain public-interest text.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 50(1)-(5) and Article 113","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"A generic rule that all AI content must always carry a visible label is too broad. First classify the specific Article 50 scenario.","source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Final guidelines, scope by Article 50 paragraph","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null},{"kind":"recommended_action","statement":"For each system, record the applicable paragraph, responsible actor, implemented disclosure or marking and how it was tested.","source_id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","source_locator":"Implementation guidance for providers and deployers","source_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null}]},{"slug":"annex-iii-high-risk","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]}],"conditional":[{"slug":"article-61-informed-consent","id":"praxikon:eu:ai-act:obligation:article-61-informed-consent","label":"Article 61: informed consent of test subjects for testing in real world conditions","status":"possibly_applies","source_locator":"Article 60(4), point (i), with Article 61(1)","addressee":"reader","human_page":"https://www.praxikon.com/en/verplichtingen/article-61-informed-consent"}],"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":"EU Artificial Intelligence Act 2024/1689","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":"Digital Omnibus on AI 2026/1744","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":"AI literacy questions and answers","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-article-50-guidelines","title":"Guidelines on Article 50","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems","eli":null,"source_version":"final-2026-07-20","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-prohibited-practices-guidelines","title":"Guidelines on prohibited AI practices, C(2025) 5052 final","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act","eli":null,"source_version":"c-2025-5052-final-2025-07-29","verified_at":"2026-08-08T00:00:00.000Z"}],"first_actions":[{"label":"Screen every use case against Article 5 first","summary":"Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact."},{"label":"Assign human oversight and give those people a mandate","summary":"Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside."},{"label":"Take role- and context-specific AI literacy measures","summary":"Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate."}],"evidence":[{"label":"Article 5 screening record","summary":"A record per system that the Article 5 screening was performed, with outcome and reasoning. The conclusion \"no prohibited practice\" is evidence too.","url":null},{"label":"Deployment dossier: logs, worker information and information to affected persons","summary":"The dossier that shows you retain the logs, that you informed workers and their representatives in time, and that the people about whom decisions are made are aware of it.","url":null},{"label":"AI literacy measures record","summary":"Versioned record of roles, context, measures, participation or instruction and review moments.","url":null}],"guidance":[{"label":"No mandatory course format, no certificate, no exam and no AI officer","statement":"The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)"},{"label":"Article 4 reaches beyond your own staff, and the national supervisor enforces it","statement":"The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)"},{"label":"AI agents must disclose both their AI nature and on whose behalf they act","statement":"Point (31) of the guidelines of 20 July 2026 states that AI agents are covered by Article 50(1) if they are capable of interacting with the persons instructing them or with other natural persons in the execution of their tasks, citing as examples making bookings, managing correspondence, negotiating or concluding contracts and executing purchases. That same point requires AI agents to be designed and developed so that they disclose both their artificial nature and the person on whose behalf they are acting, given the need for transparency of the origin and of the delegation of authority and accountability for the consequences of their actions. This also applies in complex multi-agent architectures in which other agents interact directly with natural persons. Where the provider cannot reliably determine before placing on the market or putting into service whether the agent will directly interact with a natural person, the agent should be designed at the architecture level and instructed to disclose itself in every situation where it is reasonably likely to interact with a natural person, including where that person represents a legal entity. Agents should also disclose themselves to the persons instructing them at key steps such as authorisation, reporting and validation, including where the agent receives, processes or relies upon outputs generated by other AI systems rather than by a natural person, and at every new interaction. Point (63) adds that Article 50(2) may apply to AI agents where the agent takes an action whose output is AI-generated or manipulated content perceptible by natural persons, while intermediate processing steps such as reasoning and chain of thought and non-perceptible actions such as a web request or browser action fall outside that scope.","source_locator":"Commission Guidelines C(2026) 5054 final, Section 3.1.1 point (31) and Section 4.1.2 point (63)"},{"label":"Artistic or satirical work is not exempt but attenuated, and the informative character always prevails","statement":"Point (119) of the guidelines of 20 July 2026 describes an attenuated transparency obligation for deep fakes forming part of evidently artistic, creative, satirical, fictional or analogous works or programmes, where the obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. Point (120) describes the categories: artistic works are created for the purpose of art, including music, cinematographic works and visual arts; creative works involve creative choices, while works mainly motivated by functional or technical considerations cannot be regarded as creative; satirical works are intended to criticise society, politics, business or public figures through humoristic techniques; fictional works involve persons, objects, places, entities or events in an imaginary but verisimilitude setting; analogous works share core traits with those categories without fitting neatly into one. Point (122) states that it must be evident to the natural persons exposed to it that the content falls within one of those categories, that the categories must therefore be interpreted strictly given the lighter disclosure regime and the interests of freedom of expression and freedom of the arts and sciences, and that content whose nature is potentially unclear or ambiguous to the audience falls outside this lighter regime. Relevant factors, per that same point, are whether the content displays formats or styles characteristic of the category, the context in which it is presented, and audience expectations. That same point excludes content whose nature is exclusively informative or commercial and recognisable as such, citing news reporting, notes that advertisements or documentaries may be regarded as evidently creative or fictional in certain specific situations but not in others because the assessment is case-specific, and states that where the deep fake combines multiple characters, for example informative and creative, the informative character should always prevail and the standard labelling requirements apply. Point (123) stresses that these deep fakes are not excluded from the obligation: the deployer must still disclose the AI origin or manipulation, but may do so in an appropriate manner, and must in any case comply with Article 50(5). Point (124) states that reliance on the attenuated obligation cannot justify failing to respect the fundamental rights of individuals or the rights of rightsholders under Union intellectual property or data protection law. As examples within the categories the document cites movies featuring AI de-aged existing actors or digital replicas of deceased actors, AI-generated music in the style of existing artists, and an AI-manipulated image of an existing politician in a scene clearly meant as humorous criticism. Outside the categories the document places among others an AI-manipulated video in the style of a teleshopping channel, AI-generated images of celebrities implying involvement in activities that never happened, and an AI-manipulated video featuring a realistic synthetic influencer focused solely on displaying a sponsored product's functionalities.","source_locator":"Commission Guidelines C(2026) 5054 final, Section 6.1.3, points (119) to (124) and the accompanying example lists"}],"examples":[{"label":"Inferring political opinions from uploaded photos","situation":"A platform analyses the biometric data in photos users have uploaded to infer their assumed political orientation and serve them targeted political messages. A comparable system infers assumed sexual orientation in order to serve advertisements.","outcome":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","lesson":"Relying on the ancillary feature exception requires that the feature is also strictly necessary for objective technical reasons alongside the main service, since both conditions apply cumulatively and advertising purposes do not meet that bar.","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","provenance":"official"},{"label":"Medical exception: accessibility yes, burnout detection no","situation":"An employer wants to deploy emotion recognition. In one scenario the system assists employees with autism and improves accessibility for blind and deaf colleagues. In the other it measures stress levels to flag burnout, boredom or loss of motivation.","outcome":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","lesson":"The medical exception is narrow: supporting a specific impairment qualifies, general monitoring of wellbeing, stress or motivation does not, and data gathered under a permitted use may not be reused for other purposes.","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","provenance":"official"},{"label":"Facial recognition company builds a database from social media","situation":"A software company runs an automated image scraper across the internet to detect images containing human faces on social media, stores them with source URL, geolocation and sometimes names, and converts the facial features into mathematical representations against which an uploaded photo can be matched.","outcome":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","lesson":"Images published publicly on social media do not amount to consent, and the decisive point is targeting: untargeted collection for a database capable of matching faces stays prohibited even when done step by step.","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","provenance":"official"},{"label":"Live facial recognition at a football stadium","situation":"Police install a van with mobile cameras and live facial recognition at the main entrance of a stadium during a European Championship match. The watchlist covers people suspected of offences ranging from serious crime to fraud and burglary, plus people of possible intelligence interest and vulnerable persons with mental health issues. There is no information linking a specific person to this event.","outcome":"The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.","lesson":"A watchlist that mixes different kinds of suspicion and is not tied to the specific event is too unspecific, and the presence of one person for whom deployment would be allowed does not legitimise the whole operation.","source_locator":"Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5","provenance":"official"}],"standards":[],"definitions":[],"answer_page":"https://www.praxikon.com/en/antwoord/biometrie-gezichtsherkenning","follow_up_questions":[{"question":"Does our AI use case fall under the prohibited practices?","url":"https://www.praxikon.com/en/antwoord/verboden-praktijken-check"},{"question":"What fines and enforcement does the AI Act have and who supervises?","url":"https://www.praxikon.com/en/antwoord/boetes-handhaving"},{"question":"We use AI to monitor or evaluate employees. What applies?","url":"https://www.praxikon.com/en/antwoord/werknemers-monitoren"}],"disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}