Direct answer
We are considering facial recognition or other biometrics. Is that allowed?
This falls under Annex III: high-risk AI. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
First step: Justify the Article 6(3) exception against each individual condition.
You describe: Biometric identification or categorisation of people, such as facial recognition for access or in public spaces. Likely role: deployer in credit or insurance.
This applies now
- Article 5: prohibited practicesApplicable
- Article 50: transparencyApplicable
- Article 4: AI literacyApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
- Article 27: FRIAfrom 2 December 2027
Besides public organisations, Article 27 also names deployers of high-risk systems for creditworthiness and for risk assessment and pricing in life and health insurance. If you assess people with such a system, the fundamental-rights assessment applies to you as well, whether you are public or private.
Your first actions
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Screen every use case against Article 5 first. Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
- Implement the applicable disclosure, marking or label. First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
Record this
- Article 49(2) registration record for the system assessed as not high-risk
- Article 5 screening record
- Test report per touchpoint: disclosure visible, timely and accessible
biometrics and identification
Face comparison at the border gate: verification or identification
An automated border gate uses biometric facial recognition to compare a traveller’s face with the photo in the passport chip. The same camera could technically also compare against a law-enforcement database, and exactly that difference decides whether this biometrics is high-risk.
Provenance: The Commission draft guidelines of 19 May 2026 state that biometric verification falls outside the high-risk classification: one-to-one comparison of presented biometrics with previously stored biometrics, for the sole purpose of confirming that a person is who they claim to be. Where the same capture is additionally compared against a law-enforcement database, it does become remote biometric identification. The document is a consultation version: non-binding and not yet final.
Test your biometric application on purpose rather than technology: the same camera and the same model stay outside the high-risk route as long as the comparison is one-to-one and only confirms identity, and fall inside it as soon as that same capture is also held against a database. Record per application what the comparison runs against, because that single design choice moves the entire regime.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraph (136)
biometrics and identification
Facial recognition at access control: the guard behind the camera counts too
An organisation secures the entrances to its buildings with facial recognition and uses that biometric access control to register visitors as well. When the system returns no match, a security officer reviews the camera images and decides personally whether someone may enter. The question is whose measures have to reach that officer: those of the supplier of the model, those of the department that deploys the system, or both.
Provenance: Article 4(1) provides that providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf. In doing so they must take into account technical knowledge, experience, education and training and the context the AI systems are to be used in, and consider the persons or groups of persons on whom the AI systems are to be used. The same provision states that this obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
We read the phrase about the persons on whom the system is used as the centre of gravity for biometrics: whoever stands in front of the camera is subject to the outcome and has little to set against it. That argues for equipping the officer who decides for himself when no match comes back more substantively than the colleague who merely switches the system on and off. The article itself names no sufficient level and expressly states that you need not guarantee one, so where the floor lies for each role stays open. In our assessment a record kept per role, stating the choice made and the reason for it, is easier to defend than one organisation-wide session backed only by an attendance list.
Editorial example. The rule above is in the Regulation. The situation was written by us to show how that rule plays out in this sector, and is not taken from a worked case in official guidance.
Artikel 4, lid 1
biometrics and identification
Camera at the entrance: access control versus biometric categorisation
An organisation admits staff through facial recognition at its access control gate and additionally runs a camera in the visitor area that sorts faces into age groups. Both applications run on the same biometric infrastructure and the same images. The question is which of the two requires the people involved to be actively informed.
Provenance: The Commission guidelines of 20 July 2026 count automated facial-recognition access controls among the systems that merely collect data passively and are not capable of an exchange with natural persons, and therefore do not interact within the meaning of Article 50(1). For Article 50(3) they state that, unless the use is prohibited under Article 5(1)(g), the information duty applies to any biometric categorisation system, including outside the high-risk scope, and they give classification by age or gender on the basis of biometric data as an example. Article 50(3) itself carries a further exception for systems permitted by law to detect, prevent or investigate criminal offences. As a way of informing people the guidelines describe a visible notice at each possible entrance to an exhibition room stating that facial images are captured to assign visitors to an age group, provided at the latest at the moment of first exposure.
Our reading is that you should map this per processing purpose rather than per camera: the same lens that stays outside Article 50(1) at the access control gate moves inside Article 50(3) as soon as those images place people in a category. Record for each setup what happens to the capture and who the deployer is, because that decides whether a notice belongs at the entrance. The guidelines prescribe no fixed form, but they do fix the moment: the notice has to be there before someone walks into frame, and a line in the privacy statement rarely makes that moment, in our reading.
Commission Guidelines C(2026) 5054 final, 20.7.2026, point (30) and points (104) to (108)
biometrics and identification
Inferring political opinions from uploaded photos
A platform analyses the biometric data in photos users have uploaded to infer their assumed political orientation and serve them targeted political messages. A comparable system infers assumed sexual orientation in order to serve advertisements.
Provenance: The Commission guidelines on prohibited AI practices treat this case as a worked example under Article 5. The document is non-binding: authoritative interpretation rests with the Court of Justice.
Relying on the ancillary feature exception requires that the feature is also strictly necessary for objective technical reasons alongside the main service, since both conditions apply cumulatively and advertising purposes do not meet that bar.
Commission Guidelines C(2025) 5052 final, 29.7.2025, worked examples under Article 5
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
High-risk does not mean prohibited, and not high-risk does not mean permitted
The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)
Split and agentic architectures are assessed as a whole
The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.
Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationExecution
Record the classification in an AI register
A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.
See the Embed AI approach