Biometrics: is it high-risk under the EU AI Act?
Remote biometric identification, biometric categorisation according to sensitive/protected attributes, and emotion recognition — in the cases not already prohibited under Article 5.
Classification test
Falling in this domain is necessary but not sufficient. Under Article 6(2) the system is high-risk only if it also performs one of the specific functions the domain's text lists. Some biometric uses are outright prohibited under Article 5; Annex III covers the high-risk (permitted-but-regulated) remainder.
Example systems
- Remote identification of individuals from camera feeds
- Biometric categorisation systems
- Emotion-recognition systems outside the prohibited workplace/education contexts
If it is high-risk, these obligations apply
- Declare accuracy metrics in instructions for use — Provider
- Evidence robustness / resilience — Provider
- Evidence AI-specific cybersecurity — Provider
- Run a lifecycle risk-management system — Provider
- Govern training, validation and test data — Provider
- Assign human oversight and use per instructions (deployer) — Deployer
- Draw up & maintain the Annex IV technical file — Provider
- Classify the system against Article 6 / Annex III — Provider, Deployer
- Register in the EU database — Provider, Deployer
- Complete conformity assessment before market — Provider
All high-risk (Annex III) obligations → · How to classify under Article 6 →
Legal source
FAQ
Is biometrics AI high-risk under the EU AI Act?
It is high-risk under Article 6(2) if it matches the Annex III biometrics domain and performs a listed function. Some biometric uses are outright prohibited under Article 5; Annex III covers the high-risk (permitted-but-regulated) remainder.
What must I do if it is high-risk?
Run a risk-management system, govern your data, keep the Annex IV technical file, evidence accuracy/robustness/cybersecurity, complete conformity assessment and register in the EU database.
Stay audit-ready as the Act changes
EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.
Subscribe — free, weeklyNot legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.