CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
ai-regulation

Your Bank's Selfie Check Just Got a €35 Million Watchdog

Your Bank's Selfie Check Just Got a €35 Million Watchdog

Here's something that might genuinely surprise you: a bank's AI identity check can make the right decision and still fail a regulatory audit. Not because the answer was wrong. Because nobody can prove how it got there.

TL;DR

Your bank's selfie verification isn't just an AI verdict — it's supposed to be a governed, logged, human-reviewed process, and starting August 2026, European law will require banks to prove all four parts of that chain or face fines up to €35 million.

Most of us picture a bank identity check as something like a bouncer at a door. You show your face. The AI either lets you in or it doesn't. Fast. Clean. Done.

That picture is missing about 90% of what's actually supposed to happen.

The Selfie Is Just the Beginning

When you hold your phone up and let a banking app scan your face to verify who you are, the AI does its comparison in a fraction of a second. It maps your facial geometry, checks it against your ID photo or stored profile, and produces a confidence score — basically a percentage that says "we think this is the same person." That part, the actual matching, is almost the easy part by modern standards.

What happens next is where banks are scrambling — and where regulators are about to start checking the receipts.

Under the EU AI Act, which becomes fully enforceable for high-risk AI systems on August 2, 2026, banks must demonstrate four things around every identity decision their AI makes: that the system was properly tested, that every check was logged automatically, that a human reviewed the result, and that the whole setup can hold up under pressure — including cyberattacks. Miss any one of those four, and it doesn't matter how accurate the AI was. This article is part of a series — start with Biometric Kiosk Mistakes What Can Go Wrong.

Think of it like a bridge inspection. The bridge might be perfectly sound. But if the inspector's logbook is missing — no date, no test results, no signature — the bridge still gets flagged. An accurate AI without a verifiable trail is the same problem in digital form.


Why "The AI Got It Right" Is Not Enough

Here's the misconception that catches most people off guard, and honestly, it's an easy one to have: accuracy feels like the whole story. A 99% match rate sounds bulletproof. Banks have spent decades competing on speed and precision. So the idea that a correct decision could somehow fail compliance seems almost backwards.

But regulators aren't asking "was the answer right?" They're asking "can you prove how you got there, and what you'd do if it went wrong?"

Those are very different questions.

5,000
potential false flags per day at a bank processing 100,000 identity checks — even at 95% AI accuracy
Based on EU AI Act compliance research via Kognitos and PredictionGuard

A 95% confidence score sounds reliable. Run the numbers though: a bank processing 100,000 identity checks per day at 95% accuracy still produces 5,000 mismatches daily. Some are real fraudsters. Some are real customers wrongly flagged. Without logs showing which human reviewed each one — and why they accepted or overrode the AI's call — the bank cannot answer a regulator's most basic question: "How do you know your decisions are sound?"

That's not a hypothetical problem. According to research published by Kognitos, the most common compliance gap in enterprise AI deployments is that AI systems access regulated data under a shared service account — basically a generic login — and no log records which actual human being directed that access. Regulators call this an attribution gap. In plain English: nobody can prove who was responsible for the decision.

"Purchasing a high-risk AI system from an external vendor does not exempt you from any of this. The deployer remains accountable for log retention and accessibility regardless of who built the system." — Summary of EU AI Act deployer accountability principle, as analyzed by TrueScreen

That last part matters more than most banks realize. You can't buy a clever AI tool from a vendor and then say "they're responsible for the governance." The law puts accountability squarely on the institution deploying the system — the bank, the fintech, the lender. Previously in this series: Applying For A Remote Job Your Face Is Now Evidence.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

What the Log Actually Has to Contain

This is where it gets surprisingly specific — and surprisingly demanding.

Under Article 12 of the EU AI Act, high-risk AI systems used for biometric identification (your face, voice, fingerprints — the body stuff that's uniquely you) must automatically generate logs that include: a timestamp for each use, which reference database was consulted, exactly what input data produced the match or no-match result, and the identity of the personnel who reviewed the outcome. Not "a staff member." A specific, attributable person.

These logs must be retained for at least six months. And "automatically generated" is doing real work in that sentence — notes written after the fact, or reconstructed from memory, don't count. The system has to capture the record as the decision happens, in a tamper-resistant format.

According to detailed compliance analysis published by Asqav, regulators treat the audit trail itself as the compliance mechanism — not just evidence of compliance. The log isn't a receipt you keep in case someone asks. It's the proof that the process existed at all.

For a bank running identity verification across thousands of loan applications or account openings per day, this becomes a serious engineering problem. It's not a policy you can write your way around. The logging infrastructure has to be built into the system from the start.

The Four Things Banks Must Prove (Not Just Do)

  • 🧪 Tested — The AI system went through documented performance testing before deployment, with records showing what was checked and what thresholds were set
  • 📋 Logged — Every identity check generates an automatic, timestamped, tamper-resistant record showing what data was used and what the system concluded
  • 👤 Reviewed — A specific, named human being verified the result — not a shared account, not "the team," an attributable individual
  • 🛡️ Resilient — The whole system can hold up under cyberattack or technical failure, with continuity plans that don't break the identity process

The Part About Cybersecurity That Nobody Mentions

There's a fourth requirement that gets less attention than the audit trail stuff, but it's quietly significant. Banks must also demonstrate what's called cyber resilience — meaning the identity system itself has to be designed to survive attacks, not just work smoothly when everything's fine. Up next: 1 In 30 Times The Face Scanner Rejects The Right Person Here.

This connects to a separate set of rules called DORA (the Digital Operational Resilience Act — basically a law that requires financial institutions to prove their critical tech systems won't collapse under stress). Identity verification counts as a critical system. Which means if a cyberattack disrupts the AI's ability to check identities, the bank needs documented plans for what happens next — not improvised workarounds.

This matters for you as a customer because it's part of why identity systems sometimes feel more cumbersome than you'd expect. A well-governed system may actually reject more checks, add more friction, or require callbacks, precisely because it's built for traceability and human override — not raw speed. At CaraComp, this is something we see consistently in facial recognition contexts: the systems that hold up best under scrutiny are rarely the fastest ones. They're the ones where every decision leaves a paper trail.

The fines for getting this wrong are not symbolic. The EU AI Act sets penalties for high-risk AI violations at up to €35 million — or 7% of a company's worldwide annual revenue, whichever is higher. For a large bank, 7% of global turnover is a number that gets a board's attention very quickly.

Key Takeaway

When a bank's AI checks your identity, the safety question isn't "did the AI get it right?" — it's "can the bank prove what the AI saw, who reviewed it, and what would happen if the system failed?" Starting August 2026, European law requires banks to answer all three. The log is the proof. Without it, even a correct decision doesn't hold up.

The deeper insight here — the thing worth sitting with — is that accuracy and accountability are two completely separate things. A system can be technically brilliant and operationally invisible. Or it can be imperfect but fully traceable, with every questionable decision reviewed by a real person who left a record. Regulators are increasingly demanding the second kind, because an explainable mistake you can fix is safer than a perfect black box you can't examine.

So next time a bank app makes you hold your phone at a weird angle, resubmit your ID, or wait for a manual review — that's not the system failing. That might be exactly what a governed, accountable identity process is supposed to look like. The annoying part and the safe part are sometimes the same part.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search