CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
ai-regulationBy Cara Candelario

EU AI Act Requirements: Risk Tiers, GPAI Rules & Providers

Biometric Law Is Closing In: What Investigators Must Know Now
An investigator reviews facial comparison software, illustrating how eu ai act requirements separate lawful case-specific use from prohibited mass scanning.

Here's a thought experiment. Two investigators both run facial comparisons this week. The first has a folder of photos handed over by a client, specific subject, documented chain of custody, written scope of work, lawful authority to possess the images. The second scrapes social media profiles, cross-references a few public photos, and runs the same technical process. Same software. Same algorithm. Completely different legal exposure.

That distinction, which looks invisible from a purely technical standpoint, is exactly the line regulators are drawing right now. And the investigators who don't understand it aren't just behind the curve. They're standing in the path of something that has already cost other industries billions of dollars.

TL;DR

Facial recognition laws in both the EU and US are splitting biometric use into two categories, random public scanning (increasingly prohibited) versus consent-scoped, case-specific comparison (defensible), and investigators who can document which side they're on will own this industry in 2026.

Biometric Law: What Makes It Legally Real

Let's start with Illinois, because Illinois started this whole conversation back in 2008. The Biometric Information Privacy Act, BIPA, if you want to sound like you know what you're talking about at a conference, was the first US law to treat facial geometry and biometric identifiers as legally protected personal data. Not just sensitive. Protected. With private rights of action. Meaning anyone whose biometric data was collected without proper notice and consent could sue directly.

The numbers that followed are not subtle. BIPA litigation has generated over $2 billion in class-action settlements to date. Facebook paid $650 million. Google paid $100 million. TikTok settled for $92 million. These are not rounding errors. And here's the part that investigators consistently miss: the law doesn't care how big you are. Small businesses have been successfully sued under BIPA. The trigger is what you did with the images, not how many employees you have.

$2B+
in class-action settlements generated by BIPA (Illinois Biometric Information Privacy Act) litigation since 2008
Source: Public litigation records, multiple reported settlements

Illinois was first. But it's no longer alone. At least 12 US states enacted or significantly advanced biometric privacy legislation between 2022 and 2024, with active enforcement now running in Texas, Washington, and Colorado. This is not a patchwork anymore. It's a closing net, and it's moving faster than most solo investigators realize, because the news coverage tends to focus on big corporate defendants, not the small operators who face the same exposure with a fraction of the legal resources. This article is part of a series, start with Deepfake Detection Accuracy Gap Investigator Workf.


EU AI Act: Key Requirements for Investigators

Across the Atlantic, the regulatory architecture is even more explicit about the distinction that matters here. The EU AI Act, now in phased implementation and already being watched as a global benchmark by regulators from London to Singapore, draws a direct legal line between two categories of facial recognition use.

The first category: real-time remote biometric identification in public spaces. The Act classifies this as either high-risk or outright prohibited, depending on context. The reasoning is straightforward. Scanning a crowd, a street, or an airport gate without the knowledge or consent of the people being scanned treats every face as a data point to be harvested. That's the thing regulators have decided they don't want in a free society, and the legal architecture reflects that judgment with hard restrictions.

"Both European and American approaches to the technology face a common challenge: how to move fast enough to stay competitive with China and other authoritarian states while moving carefully enough to protect civil liberties." William Echikson and Jensen Enterman, Center for European Policy Analysis

The second category, and this is the one investigators should be paying close attention to, is controlled, case-specific image comparison conducted under human oversight with documented lawful authority. This occupies a categorically different legal space under the Act's framework. The architecture of the law actually rewards scope limitation and documented consent. It's not a loophole. It's a design principle.

Think of it like a search warrant versus warrantless surveillance. A detective operating with a warrant, specific subject, specific location, specific legal authority, works inside clear legal protection. A detective photographing everyone on a block "just in case" works in the opposite direction entirely. Consent-based facial comparison is the warrant equivalent: scoped, documented, defensible. The comparison is almost too clean, but that's exactly how regulators are thinking about it.

As Mayer Brown noted in their January 2026 Global Privacy Watchlist, "the global data privacy and online safety landscape is undergoing a period of unprecedented regulatory transformation", with AI and biometric technologies sitting at the center of that transformation across every major economic region simultaneously. This isn't one jurisdiction moving slowly. It's a coordinated global shift happening on an accelerated timeline. Previously in this series: Facial Comparison Triage Multi Camera Investigatio.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Consent Standards: What Regulators Enforce

Here's where it gets genuinely interesting, and practically useful. When regulators and courts evaluate biometric compliance, the question they keep returning to is what legal scholars call "purposeful collection scope." It sounds like jargon, but the concept is simple: Can you document why each image was used, whose consent or lawful authority permitted it, and what the comparison was limited to?

That's it. That's the test. Investigators who can answer those three questions clearly, for every comparison they ran, occupy categorically safer legal ground than those who cannot. Not because they found a technicality. Because they operated in a way that the legal framework was specifically designed to protect.

What "Consent-Based Analysis" Actually Requires

  • ⚡ Documented lawful authorityYou can show why you were legally permitted to possess and analyze each image in your case folder
  • 📋 Defined comparison scopeThe analysis was limited to specific subjects for a specific investigative purpose, not open-ended biometric harvesting
  • 👁️ Human oversight in the loopA qualified investigator reviewed and interpreted results rather than treating algorithmic output as a final determination
  • 🔒 Retention limitsImages and biometric data weren't stored beyond the scope of the case without a documented legal basis for doing so

The Bristol, Virginia Police Department offers a useful real-world model here. When they launched their facial recognition program in 2025, what distinguished them wasn't the technology, it was the policy architecture around the technology. Publicly accessible documentation. Annual oversight requirements. Strict accountability mechanisms. A commitment to running comparisons within clearly defined boundaries. The technology was the same software available to other agencies. The defensibility came from the documented process wrapped around it.

Solo investigators can take the same approach. In fact, understanding how to build that documentation trail, and being able to explain it clearly to a client or, if necessary, a court, is increasingly what separates professional-grade work from legally exposed work. If you want to understand how facial comparison technology fits into a privacy-conscious workflow more broadly, the breakdown at CaraComp's face recognition and privacy resource is worth reading alongside this regulatory context.


The Misconception That Gets People in Trouble

Most investigators, and most small business operators generally, assume that biometric law is a large-enterprise problem. The mental model goes something like: "BIPA is for Facebook, not for me." That model is wrong, and it's demonstrably wrong based on the litigation record. Up next: Brain Detects Deepfakes Facial Landmarks Visual In.

BIPA defines biometric identifiers broadly. A facial geometry scan extracted during image comparison is a biometric identifier under the statute. The law doesn't ask how many employees your firm has. It asks whether you collected, used, or stored biometric data without proper notice, consent, and a publicly available retention policy. Those requirements apply to a solo investigator with a laptop just as much as they apply to a Fortune 500 company, the only difference is that the Fortune 500 company has a legal department that told them about it years ago.

The good news, and there genuinely is good news here, is that the remedy isn't complicated. It's documentation, scope definition, and process. The investigators who will own this industry in 2026 aren't necessarily running more sophisticated algorithms than their competitors. They're the ones who can walk a client, a regulator, or a courtroom through exactly why every comparison they ran was legally clean.

Key Takeaway

The legal risk in facial comparison work has split into two distinct categories: random biometric harvesting (increasingly prohibited globally) and consent-scoped, case-specific comparison with documented lawful authority (defensible). Investigators who build their workflow around that distinction aren't just protecting themselves, they're building the professional credential that will define the industry's next tier.

So here's the question worth sitting with: if a client handed you a folder of face photos right now, could you clearly articulate, not just feel confident about, but actually articulate, which comparisons are safe to run, under what authority, with what retention limits, and why? Because the regulators writing the next round of rules are already assuming the answer is yes. The investigators who can actually say yes are the ones they'll never need to call.

EU AI Act Provider Obligations for High-Risk Systems

Under the EU AI Act, providers of high-risk AI systems carry specific compliance duties before those systems ever reach the market. Provider obligations include establishing a risk management system, maintaining technical documentation, and ensuring the AI system undergoes conformity assessment. For investigators working with vendors who build facial comparison tools, knowing whether that vendor treats its provider obligations seriously is a direct proxy for whether the tool itself is defensible to use.

Human Oversight Under EU AI Act Requirements

Human oversight is one of the core EU AI Act requirements for any high-risk AI system, including facial recognition and biometric comparison tools. The Act requires that a qualified person can understand the system's output, intervene when something looks wrong, and ultimately override or disregard an automated result. This is the same principle already visible in the Bristol, Virginia example above, a human, not the algorithm, makes the final call.

Risk Management Across the AI Act Framework

Risk management sits at the center of how the AI Act classifies systems as prohibited, high-risk, limited-risk, or minimal risk. A continuous risk management process means providers must identify foreseeable misuse, test for it, and document mitigations throughout the system's lifecycle, not just at launch. Investigators evaluating a facial comparison tool should ask whether the vendor can describe this process in plain language, vague answers are a warning sign.

Act Compliance Timelines for GPAI and High-Risk Systems

Act compliance rolls out in phases rather than all at once, with different deadlines applying to prohibited practices, general-purpose AI (GPAI) obligations, and high-risk systems obligations. GPAI providers face transparency duties around training data summaries and technical documentation, while high-risk system providers face the fuller set of conformity and post-market monitoring duties. Knowing which bucket a given AI tool falls into determines which set of rules actually applies to it.

AI Governance as a Practical Discipline

AI governance is the internal side of EU AI Act requirements, the policies, roles, and review processes an organization sets up to keep its use of AI systems inside legal lines. Good AI governance looks a lot like the documentation habits described earlier in this article: written scope, named responsibility, and a retention policy that can be produced on request. Investigators and vendors that build this discipline now will spend far less time reacting to enforcement later.

Under EU AI Act requirements, not every AI system is treated the same way, and that distinction matters as much in practice as it does on paper. A system posing no risk or only minimal risk to health, safety, or fundamental rights faces light-touch rules compared to a high-risk system, which is exactly why classification is the first step in any real compliance project. The EU AI Act and the broader push toward AI act compliance both share the same underlying logic already discussed in the biometric law context above: scope, documentation, and human oversight turn a legally exposed AI system into a defensible one.

European regulators designed the EU AI Act to apply broadly across sectors, meaning providers, deployers, and importers of AI systems marketed or used within the EU all carry some level of obligation. Providers building GPAI models face requirements around documentation and copyright-related transparency, while deployers of high-risk systems in areas like law enforcement, employment, or biometric identification face their own separate set of duties. Public services that adopt AI tools for eligibility decisions or resource allocation typically fall into the high-risk category, which triggers the fuller risk management system requirement described above.

Key provisions of the Act also address transparency obligations that apply even to systems that are not classified as high-risk. Chatbots, deepfake generators, and emotion-recognition systems must generally disclose to users that they are interacting with or being analyzed by an AI system. This transparency requirement exists precisely to prevent the kind of harmful AI-based manipulation that regulators across the EU have identified as a distinct category of concern, separate from the high-risk classification itself.

Post-market monitoring is the ongoing half of act compliance that many organizations underestimate when they first read the requirements. It is not enough to pass a conformity assessment once; providers of high-risk systems must keep monitoring performance, log incidents, and report serious malfunctions after deployment. This obligation connects directly back to the risk management system requirement, since new risks discovered after launch have to feed back into the same documented process used before market entry.

Risk Tiers That Define EU AI Act Requirements

The EU AI Act sorts every AI system into one of four risk tiers: prohibited, high-risk, limited-risk, and minimal risk. Which tier an AI system lands in determines almost everything else, the paperwork, the oversight, and the penalties that follow if a provider gets the classification wrong. Investigators working with facial comparison tools should ask their vendor directly which of these risk tiers the underlying AI system falls into, because a vague or evasive answer usually means nobody has done the classification work yet.

No Risk and Minimal Risk AI Systems Under the Act

Not every AI system triggers heavy compliance obligations. Systems that pose no risk or only minimal risk to health, safety, or fundamental rights face light-touch treatment under the Act, often limited to voluntary codes of conduct rather than mandatory conformity assessment. A spam filter or a basic recommendation engine typically sits here, which is a useful contrast against the high-risk facial recognition tools discussed throughout this article.

Why the Act Chose to Establish Clear Categories

Regulators chose to establish a tiered system rather than a single blanket rule because AI systems used in hiring, law enforcement, or biometric identification carry very different real-world stakes than a chatbot that recommends products. This design choice means compliance effort scales with actual risk, so a provider building a minimal-risk tool isn't buried under the same documentation burden as one building a high-risk biometric system. For investigators, this is exactly why the earlier question, which risk tier does your vendor's AI system fall into, is the fastest way to size up how seriously that vendor takes EU AI Act requirements.

The EU AI Act framework makes providers responsible for getting this classification right, because an AI system wrongly labeled minimal risk when it should be high-risk exposes both the provider and any deployer downstream to enforcement action. This is why serious vendors document their risk-tier reasoning in writing rather than asserting it verbally, and why investigators evaluating facial comparison AI systems should ask to see that documentation rather than take a sales pitch at face value. The same scope-and-documentation discipline that protects investigators under BIPA protects AI providers under the EU AI Act, the details differ, but the underlying logic of the ai act is identical.

Recital language throughout the EU AI Act reinforces that risk tiers are meant to track real-world harm, not the sophistication of the underlying model. An AI system built on cutting-edge technology can still land in the minimal-risk tier if its use case carries low stakes, while a comparatively simple AI system used for biometric identification in public spaces can land in the prohibited or high-risk tier. This is the detail investigators most often miss when they assume that "advanced AI" automatically means "heavily regulated AI" under EU AI Act requirements, regulation tracks the use case, not the technology's complexity.

Frequently asked questions

What are the main EU AI Act requirements for facial recognition?

The EU AI Act draws a direct legal line between two uses of facial recognition. Real-time remote biometric identification in public spaces is classified as high-risk or outright prohibited, since scanning crowds without consent treats every face as a data point to be harvested. Controlled, case-specific image comparison done under human oversight with documented lawful authority sits in a categorically different, more defensible legal space.

Does the EU AI Act ban all facial recognition technology?

No. Eu ai act requirements distinguish between random public scanning, which is treated as high-risk or prohibited, and consent-scoped, case-specific comparison, which the law's architecture actually rewards through scope limitation and documented consent. This isn't described as a loophole but as a design principle built into the framework, meaning targeted, documented biometric analysis occupies safer legal ground than open-ended harvesting.

What documentation satisfies eu ai act requirements for biometric comparison?

Regulators focus on purposeful collection scope: whether you can document why each image was used, whose consent or lawful authority permitted it, and what the comparison was limited to. Meeting eu ai act requirements in practice means showing documented lawful authority, a defined comparison scope, human oversight rather than pure algorithmic determination, and retention limits so biometric data isn't kept beyond the case's documented legal basis.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search