Skip to main content
Praxikon
All answers

Direct answer

We are considering facial recognition or other biometrics. Is that allowed?

This falls under Article 5: prohibited practices. That obligation applies today. There is one exception you have to assess yourself.

This could go the other way

  • The exceptions are narrow: among others, emotion recognition for medical or safety reasons, and the exhaustively defined law-enforcement situations with authorisation for real-time remote biometric identification in Article 5(2) to (7). The exception must be established and documented in advance.

First step: Screen every use case against Article 5 first.

You describe: Biometric identification or categorisation of people, such as facial recognition for access or in public spaces. Likely role: deployer (you use the system).

The conclusion and your first steps

This applies now

Coming up

Depends on your situation

These provisions only apply once the stated fact is established. The locator says which provision settles it.

Three layers apply at once: some variants are prohibited under Article 5 (enforceable since 2 February 2025), many others are high-risk under Annex III point 1, and exposed persons must be informed under Article 50. Assess Article 5 first.

Your first actions

  1. Screen every use case against Article 5 first. Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
  2. Assign human oversight and give those people a mandate. Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.
  3. Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Your route

From your situation, via your role, to what applies and when it starts.

3 now · 2 later

Your situation

Biometric identification or categorisation of people, such as facial recognition for access or in public spaces.

Role

Deployer (you use the system)

To record: Article 5 screening record · Deployment dossier: logs, worker information and information to affected persons · AI literacy measures record

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council, version original-oj-2024-07-12, checked on , ELI http://data.europa.eu/eli/reg/2024/1689/oj

    Locators in this source

    • Article 5, Article 99(3) and Article 113(a)
    • Article 5(1)(a)-(h)
    • Article 5 read with Article 6 classification order
    • Article 26(1)-(12)
    • Article 50(1)-(5) and Article 113
    • Article 6 and Annex III
    • Article 6(2)-(4), Article 49 and Annex III
  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Amendment to Article 5 and transition to 2 December 2026
    • Amendment of Article 4; entry into force 27 July 2026
    • Amended Article 113, Article 6(2) and Annex III application date
  • AI literacy questions and answers

    European Commission, version updated-2026-07-27, checked on

    Locators in this source

    • Questions on measures, formats, certificates and records
    • Implementation examples and evidence guidance
  • Guidelines on Article 50

    European Commission, version final-2026-07-20, checked on

    Locators in this source

    • Final guidelines, scope by Article 50 paragraph
    • Implementation guidance for providers and deployers

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0, schema 1.5.0.

Sharper for your situation

Do you build this system yourself or take it from a vendor?

This flips your role, and with it almost the entire set of obligations.

Execution

Record role and classification for each AI system

The boundary is set out in the rules above. The outcome becomes demonstrable when the facts, role, classification, owner and reassessment are recorded for each system. Embed AI guides that inventory and sets up the AI register. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the AI register approach
Does this answer your question?
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist