Biometric Governance
Biometric AI Use Governance
What this control does
Apply enhanced approval and safeguards to biometric identification, categorisation and emotion-recognition use cases.
How to implement
Classify the actual biometric use before approving it: identification, verification, categorization or emotion recognition can have different requirements. Document the purpose, location, affected people and legal route. Check applicable prohibitions before considering controls for permitted use. For qualifying high-risk biometric identification, record the required logging and human-verification arrangements. Route law-enforcement authorization and reporting through the Biometric Law-Enforcement Authorisation and Reporting control. Do not assume that an ordinary access-control use or a human review makes every biometric use lawful.
Suggested timing and triggers
Before acquisition or deployment; after changes in purpose, setting or functionality; periodic review of permitted use.
Evidence examples
Biometric use-case and legal assessment Approval, restrictions and any required authorization Logging specification and human-verification procedure Configuration checks and records of use Review and escalation history
How to check this control
Trace one deployed biometric use back to its assessment. Verify the configured purpose and restrictions, and test the applicable logging or verification step. Escalate differences between the approved design and actual use.
Related EU AI Act obligations
Article 5(1)(e)
Do Not Create or Expand Facial Recognition Databases Through Untargeted Image Scraping
Article 5(1)(f)
Do Not Use AI Emotion Recognition in Workplaces or Educational Institutions Except for Permitted Purposes
Article 5(1)(g)
Do Not Use Prohibited Biometric Categorisation to Infer Sensitive Characteristics
Article 5(1)(h), 5(2)-(7)
Do Not Use Real-Time Remote Biometric Identification in Public Spaces for Law Enforcement Except Where Specifically Permitted
Article 12(3)
Provide Required Logging Capabilities for Annex III Remote Biometric Identification
Sub-obligation of Article 12: Enable Automatic Event Logging for High-Risk AI Systems
Article 14(5)
Enable Separate Verification for Specified Remote Biometric Identification Results
Sub-obligation of Article 14: Design High-Risk AI Systems for Effective Human Oversight