CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
ai-regulation

AI Just Decided Your Loan. Europe Says You Deserve an Answer.

AI Just Decided Your Loan. Europe Says You Deserve an Answer.

Here's something that might surprise you: under Europe's new AI law, a company that uses AI to scan your face during a job interview faces stricter rules than one that uses AI to write a product description. Not slightly stricter. Completely different category of rules. The kind of difference that determines whether a system is legal at all.

TL;DR

The EU AI Act sorts every AI system into one of four risk tiers — and which tier your system lands in determines whether it's allowed at all, heavily regulated, lightly regulated, or basically left alone. Higher stakes for you = stricter rules for them.

As of August 2, 2026, the EU's transparency rules are actively enforced — with fines up to €15 million or 3% of a company's worldwide annual revenue, whichever is bigger. That's not a threat on paper anymore. That's real money, and real deadlines. But the law itself is more interesting than the fine print suggests, because it does something genuinely new: it refuses to treat "AI" as one thing.

The Building Code Analogy That Actually Works

Think about how building codes work. A garden shed, a hospital, and a nuclear power plant all have walls, roofs, and electrical wiring. But nobody expects a shed to meet hospital fire-suppression standards. The rules scale with the consequences of failure. If your shed's wiring sparks, you lose a lawnmower. If a hospital's wiring sparks during surgery, people die. Same basic technology — radically different regulations.

The EU AI Act works the same way. Every AI system gets sorted into one of four tiers based on one question: how badly could this go wrong for the people it affects?

Tier one: unacceptable risk. Banned outright. Full stop. Tier two: high risk. Legal, but buried in requirements before you can deploy it. Tier three: limited risk. Lighter rules — mostly around telling people they're talking to AI. Tier four: minimal risk. Almost no mandatory rules at all.

The category your AI system lands in determines everything. And — this is the part companies are scrambling to understand — classification is based on what the system actually does, not what the marketing brochure calls it.


What "High Risk" Really Means — And Why It Matters to You Personally

High-risk AI systems are the ones making consequential decisions about real people's lives. According to Jaggaer's analysis of the EU AI Act risk categories, systems qualify as high-risk when they operate in domains like biometrics, employment and worker management, access to essential services, law enforcement, education, and the administration of justice.

So: the AI a bank uses to decide your loan application? High risk. The system a recruiter uses to screen résumés? High risk. A tool that compares your face to verify your identity for a benefits claim? Almost certainly high risk — and possibly bumping up against the outright-banned tier, depending on how it works.

What does "high risk" require? Before a system like that can go live, the company deploying it must complete a conformity assessment (basically a formal proof that the system does what it claims), produce detailed technical documentation, register the system in an official EU database, build in human oversight so a real person can catch and correct mistakes, and set up logging systems that track what the AI decided and when. According to Governance Docs, all of that must be in place before the system enters the market — not after something goes wrong.

~33%
of all organizations will face transparency obligations under Article 50 of the EU AI Act
Source: EU AI Act compliance analysis via multiple official sources

That statistic is worth sitting with. Most companies won't build high-risk systems — but roughly one in three will have to comply with transparency rules. That means disclosing when users are talking to a chatbot, labeling AI-generated content, or embedding invisible machine-readable markers (basically a digital fingerprint baked into the file itself) so other platforms can detect AI-made content automatically. The law's reach is wider than most people expect.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

The Part Where Faces Get Complicated

Facial recognition sits at the most tangled intersection in this entire law. And understanding why teaches you something important about how the whole system thinks.

Here's the distinction that matters: there's a difference between a system that compares faces and one that recognizes them at scale. Sounds like splitting hairs. It's not.

Imagine a fraud investigator who uploads two photos — "is this the same person?" — and an AI compares them. That's comparison. Case-specific. Targeted. The investigator chose those images deliberately.

Now imagine a system that hoovers up millions of photos from social media to build a giant database of faces, then matches new images against it automatically. That's mass recognition. And under the EU AI Act, that second thing — the indiscriminate scraping of facial images to build recognition databases — is placed in the unacceptable risk tier. Banned. Not regulated more heavily. Banned. According to EU AI Act compliance analysis, this prohibition has been in effect since February 2025.

The targeted comparison tool? That lands in the high-risk tier — legal, but requiring judicial authorization when used in a criminal investigation context, plus all the documentation and oversight requirements. Same underlying technology — face-matching algorithms — completely different legal category based on how it's used.

"Misclassifying your system can mean either unnecessary compliance costs or penalties for non-compliance with requirements you didn't know applied. Classification is based on what the system does, not how it's marketed, making self-assessment complex and enforcement unpredictable." — EU AI Act compliance analysis, GDPR Local

This is where the law gets genuinely sharp. The terminology companies use — "facial comparison" versus "facial recognition" — isn't just marketing language. It's now a legal distinction with real consequences. And biometric data (your face, voice, fingerprints — the physical and behavioral stuff that's uniquely you) already sat under heavy GDPR protections before the AI Act added another layer on top. These systems now face both frameworks simultaneously.

At CaraComp, this distinction between comparison and recognition sits at the center of how we think about building responsible facial analysis tools. The architecture of a system — not just its marketing label — determines where it lands in the regulatory stack.


The Misconception That's Tripping Everyone Up

It's completely understandable why most people — and honestly, most companies — assumed "AI regulation" meant one set of rules for everything AI-related. Media coverage talked about "the AI Act" as if it were a single speed limit applied to all vehicles equally. The phrase sounds like one law doing one thing.

But the Act is really a classification system wearing the clothes of a single law. Every AI system that falls under its scope gets evaluated individually. The question isn't "do you use AI?" The question is now "which tier does each of your AI systems fall into, and can you prove it?"

That shift — from a yes/no question to a classification problem — is the real story here. Travers Smith's legal analysis of the Act's Article 50 obligations makes clear that companies aren't just accountable for using AI — they're accountable for knowing exactly what each system does, documenting it, and proving they've applied the right level of oversight.

A company that deploys an AI chatbot for customer service and an AI hiring screener faces two completely different compliance situations — even though both are "AI." Getting that wrong in either direction is costly. Over-classify a low-risk tool and you've buried your team in unnecessary paperwork. Under-classify a high-risk system and you're facing fines and, worse, potentially making unreviewed AI decisions about people's jobs and money without the safeguards the law requires.

What You Just Learned

  • 🧠 Four tiers, not one rule — The EU AI Act sorts every AI system by potential harm: unacceptable (banned), high risk (heavily regulated), limited risk (disclosure required), and minimal risk (mostly free).
  • 🔬 Biometric AI is the most complex case — Facial recognition for mass database building is outright banned; targeted face comparison for specific investigations is high-risk; same technology, completely different legal category based on use.
  • ⚖️ Classification beats marketing — What a company calls their AI system doesn't determine its tier. What the system actually does determines its tier.
  • 💡 One in three organizations — About 33% of companies will face transparency obligations, even if they never touch a high-risk system. Disclosure rules are broader than most people realize.
Key Takeaway

When AI makes a consequential decision about you — your job application, your loan, your identity check — the EU AI Act now requires the company to prove they knew what their system was doing, kept records of it, and had a human available to catch mistakes. "We used AI" is no longer a complete answer. "We used this specific tier of AI, with these controls, and here's the documentation" is what accountability looks like now.

So here's the question worth sitting with — and maybe asking out loud the next time an organization tells you they use AI to make decisions: what risk tier is that system in, and who reviews it when it gets something wrong?

If they can't answer that, they probably haven't done the classification work the law now requires. And you'd know more about how the system is supposed to work than the people running it.

That's not a comfortable place for them to be. But for you — knowing the question exists — that's exactly the kind of thing that makes you harder to push around.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search