CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
ai-regulationBy Cara Candelario

EU AI Act Compliance 2026: Annex III Rules Investigators Must Track

GDPR and Facial Recognition: The Line Investigators Keep Missing
An investigator reviews case-file images, illustrating how the eu ai act and gdpr distinguish comparison from mass biometric surveillance.

Here's a belief that's quietly killing perfectly legitimate investigative work: the idea that the moment you run AI-assisted facial analysis on an image, you've stepped into a GDPR minefield. Investigators pull back. Cases stall. Evidence that could answer a direct, specific question goes unexamined, not because the law requires it, but because someone misread what the law actually says.

EU regulators aren't coming for facial comparison inside your case file. They're coming for something very different. And understanding exactly what that difference is, technically, legally, and practically, is what separates the investigator who uses powerful tools confidently from the one who avoids them out of fear that turns out to be unfounded.

TL;DR

GDPR's most aggressive biometric protections target indiscriminate, large-scale identity collection, not controlled facial comparison within a defined case file, and recent EU regulatory decisions are making that distinction increasingly explicit.

The Myth, Stated Plainly

The myth goes like this: "If I use any AI on faces, I'm automatically in GDPR trouble." It's understandable. GDPR Article 9 lists biometric data as a special category requiring heightened protection, and the phrase "biometric data" sounds like it should cover anything a computer does when it looks at a face. But that reading is wrong, or at least, critically incomplete.

Think about a forensic document examiner. Hand them two signed contracts already sitting in evidence, and they'll tell you whether the same person signed both. Nobody calls that a privacy violation. Now imagine that same examiner photographing every handwritten document in a city, building a searchable signature archive of every resident, and running queries against it. Same underlying skill. Completely different legal and ethical universe.

Facial comparison inside a case file is the first examiner. Mass web scraping is the second. The technology touching the face is almost irrelevant. The dataset boundary is everything. This article is part of a series, start with Stress Test Facial Comparison Method Against Deepf.


GDPR Facial Recognition and Article 9: What's Covered

Here's where most people stop reading the regulation too early. Article 9's special-category protections apply to biometric data "processed for the purpose of uniquely identifying a natural person." That phrase is doing enormous legal work, and regulators have started leaning on it hard.

Running a comparison function, does Image A depict the same subject as Image B, both already in your possession, is structurally different from querying an unknown face against a mass database to produce an identity from scratch. The first is a closed-loop analytical question about evidence you already hold. The second is an open-ended identification sweep across a population. GDPR's drafters understood this distinction; it's baked into the text. The problem is that most practitioners never get past the words "biometric data" before they've already decided the regulation applies maximally.

Skadden's analysis of recent EU and UK GDPR decisions reinforces this reading: courts and regulators are increasingly focused on the context and purpose of processing, not just the category of data being touched. Purpose limitation, GDPR Article 5(1)(b), has become the load-bearing legal concept in facial analysis cases. Data collected for one specific purpose cannot be repurposed for a broader one. That principle cuts both ways: it restricts indiscriminate scrapers, and it protects controlled, documented, case-specific comparison.

Article 5(1)(b)
GDPR's purpose limitation principle, the legal concept that most directly separates lawful case-file comparison from unlawful mass biometric collection
General Data Protection Regulation, European Parliament

EU AI Act: How Facial Recognition Gets Split

If GDPR created the conceptual distinction, the EU AI Act drew it in permanent marker. The Act's risk-tier framework explicitly classifies real-time remote biometric identification systems operating in public spaces as high-risk, and in many law enforcement contexts, outright prohibited. That's the regulatory hammer everyone's been reading about.

But notice what's being described: a system that identifies people in real time, remotely, across public space, with no prior relationship between the system and the subjects. That is surveillance infrastructure. That is mass collection. The Act's prohibitions are calibrated to that architecture.

Controlled, documented, case-specific image comparison, where you have Image A, you have Image B, both came from your case file, and you want to know if they show the same person, sits in a structurally different category under the Act's own framework. The regulation distinguishes where and how broadly a system operates, not simply whether AI is involved in analyzing a face. White & Case's analysis of the EU Digital Omnibus proposals notes that upcoming revisions to GDPR and the AI Act are further sharpening these distinctions, regulators are actively working to reduce legal ambiguity around exactly this kind of tiered processing question. Previously in this series: Face Images Personal Data Gdpr Pseudonymisation.

"The EU AI Act introduces a tiered risk framework that classifies AI systems based on their potential impact, with the highest scrutiny reserved for systems that could affect fundamental rights at scale, particularly real-time biometric identification in publicly accessible spaces." White & Case, EU Digital Omnibus Analysis

Artificial Intelligence Risk Tiers and What They Mean for Investigators

The EU AI Act sorts artificial intelligence systems into risk tiers, unacceptable, high, limited, and minimal, based on what the system does and who it affects, not merely on whether AI is involved. An artificial intelligence tool that flags a document for review carries a very different risk profile than one that runs unsupervised identification sweeps across a public population. For investigators, this means the same underlying AI act logic that bans mass surveillance tools leaves room for narrower, case-bound uses of artificial intelligence when they are properly scoped and documented.

How the AI Act Supplements Existing Data Protection Principles

The AI Act supplements GDPR rather than replacing it. Where GDPR sets out data protection principles like purpose limitation and data minimization, the AI Act layers on system-level obligations, risk classification, technical documentation, human oversight, that apply specifically to how the AI system itself is built and deployed. An investigator relying on facial comparison tools should expect both frameworks to apply at once: GDPR governs how the underlying personal data is collected, used, and retained, while the AI Act governs the risk tier and technical safeguards of the system doing the comparing.

The EU's Approach to Fundamental Rights Protection

Both GDPR and the EU AI Act trace back to the same underlying commitment: protection of fundamental rights, particularly privacy and non-discrimination, as individuals move through a world increasingly mediated by automated systems. The EU's approach treats high-risk AI systems and large-scale biometric processing as areas where fundamental rights protection needs the most reinforcement, precisely because errors or abuse at scale are hardest to detect and hardest to undo. That is why the compliance requirements tighten sharply as a system's reach grows, rather than applying uniformly to every use of AI.

Act Implementation Timelines Investigators Should Track

Act implementation for the EU AI Act happens in stages rather than all at once, with different obligations becoming enforceable at different points after the regulation entered into force. Prohibited-practice rules take effect earliest, followed by governance obligations and, later, the full set of high-risk system requirements. An investigator does not need to track every implementation date to stay compliant, but understanding that act implementation is staggered helps explain why guidance and enforcement emphasis shift over time.

What the European Commission Has Signaled on Enforcement

The European Commission has repeatedly signaled that enforcement priority will follow scale and harm, not the mere presence of AI in a workflow. Guidance connected to the European Commission's rollout of the AI Act consistently points back to the same architecture this article describes: broad, unconsented identification systems draw scrutiny, while narrow, documented, case-bound comparison does not. That signal matters for investigators deciding how much documentation is enough.

The Parliament's Role in Shaping These Rules

The European Parliament negotiated the risk-tier structure that now defines the AI Act, pushing for stronger restrictions on real-time public biometric identification than earlier drafts contained. That legislative history is not just trivia, it explains why the final text draws such a sharp line between mass surveillance systems and narrower analytical tools. Investigators reading the Act's provisions are, in effect, reading the outcome of that Parliament debate.

Requirements for Data Controllers Handling Facial Data

A data controller responsible for facial comparison work carries specific requirements under GDPR: a documented legal basis, a defined retention period, and the ability to explain the processing to a data subject who asks. These requirements apply regardless of how sophisticated the underlying AI tool is, because GDPR obligations attach to the data controller's decisions about the data, not to the software itself. Investigators acting as or for a data controller should treat these requirements as the baseline, not the ceiling.

Compliance Requirements Annex III Actually Lists

The compliance requirements tied to Annex III are narrower than most investigators assume, because the list names specific use cases rather than sweeping in every AI system that touches a face. Biometric identification for open-population searches is named directly; a documented, case-bound comparison tool generally is not, because it does not perform the kind of unconstrained identification Annex III is written to catch. Reading the actual compliance requirements, rather than assuming the strictest possible reading applies, is often the fastest way to settle an internal debate about whether a given tool needs extra sign-off.

Harmonised Standards as a Shortcut to Demonstrating Conformity

Harmonised standards give a provider a concrete, testable way to show a system meets the AI Act's requirements instead of arguing the point from first principles every time. An investigator evaluating a vendor can reasonably ask whether the vendor's tool aligns with any published harmonised standards for its category, since alignment is usually documented and easy to request. That single question often reveals more about a vendor's compliance maturity than a lengthy sales conversation would.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Data Minimization: The Practical Discipline That Makes This Work

Understanding the legal distinction is necessary. Actually operating within it requires discipline. Three principles define the difference between an investigator who's legally exposed and one who isn't, and they map directly onto GDPR's own framework.

The Three Principles That Keep Comparison Lawful

  • âš¡ Purpose limitationThe comparison is answering a specific investigative question about specific individuals already connected to your case. You're not running a fishing expedition against an open dataset.
  • 📊 Data minimizationYou're working with images already in your case file. You're not scraping new images from social media, public cameras, or the open web to expand your comparison pool.
  • 🔮 Documented scopeYou can articulate, in writing, exactly what images were compared, why, and what question the comparison was designed to answer. That documentation is both a legal protection and a professional standard.

Here's where it gets interesting. That third principle, documentation, isn't just a compliance box to tick. It's actually what makes facial comparison evidence stronger in a legal context. A comparison conducted with a defined scope, on a controlled dataset, for a specific stated purpose is far more defensible than an undocumented query run against an undefined pool of images. The legal discipline and the evidentiary discipline turn out to be the same discipline. (That's the kind of alignment that should make investigators feel good about doing things right.)

For a deeper look at how facial comparison fits within a responsible investigative workflow, the mechanics of facial comparison as an investigative tool are worth understanding in detail, particularly how the technology is designed to function within case-bounded parameters rather than as an open search engine.

Requirements That Apply to High-Risk AI Deployments

When an AI system does fall into the high-risk category, real-time remote biometric identification in public spaces being the clearest example, the requirements are substantial: documented risk management, human oversight at defined checkpoints, logging of system activity, and demonstrated accuracy testing before deployment. These requirements exist precisely because high-risk systems operate at a scale where a single flawed identification can cascade into wrongful action against a real person. Investigators working with narrower, case-bound comparison tools generally sit outside this tier, but understanding the requirements clarifies exactly why the dividing line is drawn where it is.

Transparency Obligations Investigators Should Understand

Transparency obligations under the AI Act are meant to make sure a person affected by an AI system knows, in plain terms, that AI played a role in a process affecting them. For narrow, case-bound facial comparison, that often means noting in the case file that an AI tool assisted the comparison, so the transparency obligation is satisfied without needing a separate public disclosure process. Treating transparency obligations as a documentation task rather than a legal headache keeps the workflow simple.


Facial Recognition News: Where the Real Risk Lies

The regulatory cases that have generated headlines, the enforcement actions, the massive fines, the landmark rulings, share a common architecture. A company scrapes millions of faces from the open web without consent. A platform builds a searchable identity database from public social media. A vendor sells query access to that database to any paying customer with no documented purpose. Skadden's review of landmark EU data decisions consistently identifies scale and indiscriminate collection as the triggering conditions for maximum regulatory exposure.

What those cases are not about is an investigator comparing two photographs already in evidence to determine if they show the same person. The legal exposure lives in the dataset boundary, not in the fact that mathematics ran across a face. Up next: Biometric Privacy Crackdowns Coming For Investigat.

Look, nobody's saying this is entirely simple. There are edge cases. Using facial analysis on images obtained in legally questionable ways imports those legal problems regardless of how controlled your comparison methodology is. Expanding your comparison pool mid-investigation by pulling new images from outside your case file changes the analysis. The moment your "comparison" starts functioning as an identification sweep, searching an unknown face against a broad population to produce a name, you've crossed into the higher-risk category the regulations are actually targeting.

But the baseline case, two images, your case file, specific question, is not the scenario regulators are worried about. Understanding that distinction isn't just legally useful. It's what separates careful, precise investigative work from the kind of dragnet surveillance that GDPR was written to stop.

Compliance Steps That Connect GDPR and the AI Act in Practice

Practical compliance under both frameworks starts with the same habit: write down what you're doing before you do it. Identify the legal basis for processing under GDPR, confirm which risk tier your AI system or tool falls into under the AI Act, and keep records showing the comparison stayed within a defined case scope. This dual-track compliance approach, data protection compliance on one side, AI system compliance on the other, is exactly what regulators are pointing to when they describe how the EU AI Act supplements GDPR rather than duplicating it.

Key Takeaway

GDPR's most aggressive biometric provisions are targeted at scale and indiscrimacy, at systems that identify unknown individuals across large populations without prior connection to any specific case. Controlled facial comparison within a documented case file, answering a specific investigative question about subjects already known to the case, operates under fundamentally different legal logic. The risk isn't in the technology. It's in the dataset boundary.

So here's the question worth sitting with: when you're working a case involving faces, where do you personally draw the line between responsible comparison and going too far? Because the investigators who have a clear, articulable answer to that question, not a vague sense of caution, but a real answer, are the ones who can use powerful tools confidently, document their methodology cleanly, and hand their evidence to a court without flinching.

The forensic document examiner comparing two signatures in evidence isn't nervous about handwriting analysis. She's done the work to know exactly what she did, why she did it, and what question it answered. That confidence isn't bravado. It's precision. And precision, as it turns out, is what GDPR was designed to reward all along.

The relationship between the EU AI Act and GDPR is best understood as layered, not competing. GDPR asks whether personal data is being processed lawfully, fairly, and for a legitimate stated purpose. The AI Act asks whether the system doing that processing carries a level of risk that demands extra safeguards. An investigator who satisfies both, a documented legal basis for the data, and a clear-eyed read of where their tool sits on the AI Act's risk ladder, is operating well inside the lines both regulations actually draw.

It's worth being specific about what "risk" means in this context. Under the AI Act, risk ai systems are evaluated on factors like the number of people affected, the reversibility of harm, and whether a human reviews the output before any consequential decision is made. A case-bound comparison tool with a human investigator reviewing every result sits in a fundamentally lower risk band than an automated system making unsupervised identification calls across an open population. That single factor, human review, does more to lower practical risk than almost any other design choice.

Data protection and AI system compliance also intersect on the question of accuracy. GDPR has long required that personal data be accurate and kept up to date; the AI Act adds a parallel requirement that high-risk AI systems demonstrate tested accuracy rates before deployment and monitor for drift afterward. Together, these rules push toward the same practical outcome: don't rely on a tool you haven't tested, and don't stop testing once it's live. For investigators, that means keeping a record not just of what was compared, but of how confident the tool's output actually was.

None of this changes the core distinction this article opened with. Mass, indiscriminate biometric collection sits at the intersection of GDPR's toughest special-category rules and the AI Act's highest risk tier, which is exactly why regulators treat it as the priority enforcement target. Controlled, case-bound comparison, backed by documentation and human review, sits outside that intersection entirely. Knowing which side of that line a specific piece of investigative work falls on is the single most useful thing either regulation can teach an investigator.

Bringing the European Union's approach into focus helps explain why these two frameworks were built to work together rather than in isolation. The European Union treats data protection and AI system oversight as complementary layers of the same fundamental rights project, not as competing regulatory silos. An investigator who understands both layers is better positioned to ensure that a given piece of facial comparison work holds up under either framework's scrutiny.

Governance, in this context, is not an abstract compliance buzzword, it is the practical habit of writing down a legal basis before processing, assigning responsibility for a given comparison to a named person, and reviewing outcomes afterward. Good governance is what lets an investigator ensure that a documented, case-bound comparison stays inside the boundaries both GDPR and the AI Act draw. Without it, even a legally sound comparison can look reckless in hindsight simply because nothing was written down.

Privacy, at its core, is what both frameworks are trying to protect, and it helps to keep that plain goal in view when the technical language gets dense. GDPR protects privacy by controlling how personal data is collected, used, and retained; the AI Act protects privacy indirectly by controlling how risky the systems processing that data are allowed to be. An investigator who keeps privacy as the throughline, rather than treating each regulation as a separate checklist, tends to make better judgment calls in the edge cases this article already flagged. That single mental model, privacy first, mechanics second, is often the fastest way to decide whether a new use case needs a second look.

Data subjects retain rights under GDPR regardless of how a comparison is conducted, including the right to be informed about processing and to request an explanation of how their data was used. Investigators handling case-bound facial comparison should be prepared to address a data subject's questions with the same documentation that supports the comparison's legal basis in the first place. This is not an extra burden so much as the natural byproduct of doing the documentation work already described above.

An impact assessment is often the clearest way to formalize the analysis this article has walked through informally. Conducting an impact assessment before deploying a facial comparison tool, even an internal, informal version of one, forces an investigator to write down the purpose, the data involved, the risk tier, and the safeguards in one place. For higher-risk uses, GDPR's data protection impact assessment requirement and the AI Act's own risk documentation expectations largely point toward the same exercise, just from two different regulatory angles.

Gdpr compliance and AI Act compliance are best treated as a single combined workflow rather than two separate projects running in parallel. An investigator who documents legal basis, risk tier, and human oversight in one place has effectively satisfied the core asks of both frameworks at once. That combined approach is also easier to explain to a court, a supervisor, or a regulator than two disconnected compliance efforts would be.

The gdpr interplay between data protection obligations and AI system obligations is exactly why this article treats the two frameworks as layered rather than separate. Neither regulation was written in a vacuum; the AI Act's drafters built its risk-tier logic on top of concepts GDPR had already established, like purpose limitation and data minimization. Understanding that interplay is what lets an investigator apply one coherent mental model instead of juggling two unrelated rulebooks.

EU AI Act Compliance 2026: What Changes When Deadlines Arrive

EU AI Act compliance 2026 is the phrase investigators are starting to hear because several major compliance deadlines under the Act land in that year, including obligations tied to high-risk AI systems and their required conformity assessments. Companies deploying AI systems that touch biometric data, including facial comparison tools, should treat 2026 as the point when documentation habits stop being optional best practice and start being enforceable baseline obligations. For an investigator, the practical takeaway is simple: the case-bound, documented approach this article already recommends is also the approach that lines up with where enforcement is heading.

Annex III of the AI Act is the section that lists the specific use cases treated as high-risk, and it is worth knowing that biometric identification systems are named there explicitly. An AI system that appears on the Annex III list carries the full weight of high-risk obligations, post-market monitoring, human oversight, technical documentation, while a system that never performs identification against an open population generally does not. Investigators who understand where their tools sit relative to Annex III are better equipped to explain, in plain terms, why a given comparison workflow does or does not trigger the heavier compliance requirements.

Post-market monitoring is one of the newer obligations that AI Act compliance 2026 timelines bring into sharper focus for providers of high-risk AI systems. In practice, post-market monitoring means a provider cannot simply test a system once before launch and walk away; the system's real-world performance has to be tracked on an ongoing basis, with a process in place to catch accuracy drift or emerging harms. For an investigator relying on a vendor's facial comparison tool, asking whether the vendor has a post-market monitoring process is a fair and increasingly standard due-diligence question.

Transparency obligations under the AI Act require that people affected by certain AI systems be told, in an understandable way, that AI is involved in a decision or process that affects them. These transparency obligations sit alongside the risk-tier rules rather than replacing them, meaning a system can carry both a risk classification and a separate duty to disclose its use. Investigators documenting a facial comparison workflow should note, as part of that documentation, whether any transparency obligation applies to the specific case and whether it has been satisfied.

Providers of AI systems carry a different set of duties than the investigators or organizations that deploy those systems day to day, and the AI Act is explicit about this split. A provider builds and places the AI system on the market, so obligations like conformity assessments, technical documentation, and registration largely sit with them. An investigator acting as a deployer still has responsibilities, using the system as intended, monitoring for obvious malfunction, keeping logs, but the heaviest compliance lift for AI act compliance 2026 deadlines falls on the providers building these systems, not on the case workers using them responsibly.

Harmonised standards are the technical benchmarks that give companies a concrete way to demonstrate conformity assessments have been satisfied, rather than leaving compliance as a purely subjective judgment call. When a harmonised standard exists for a given type of AI system, following it creates a presumption that the system meets the AI Act's underlying requirement, which is why providers are racing to align with these standards ahead of the AI act deadlines that take effect in the coming years. Investigators do not need to master the technical detail of these standards, but knowing they exist helps explain why some vendors can answer compliance questions faster and more confidently than others.

Regulatory clarity around EU AI Act compliance 2026 obligations is still developing, and companies operating across the EU should expect further guidance as the deadline approaches rather than treating current interpretations as final. That said, the core structure is already stable enough to plan around: high-risk AI systems face the strictest obligations, transparency duties apply more broadly, and documentation is the thread connecting every requirement. Investigators who build good documentation habits now will not need to scramble when additional regulatory detail arrives.

Security is a thread that runs through both GDPR and the AI Act, even though neither framework treats it as the headline issue. GDPR requires appropriate technical and organizational measures to protect personal data, while the AI Act's high-risk requirements include safeguards against manipulation and unauthorized system access. An AI system handling facial comparison data should meet baseline security expectations under both frameworks simultaneously, since a security failure in the underlying system can just as easily become a data protection failure.

Taken together, the deadline pressure building around eu ai act compliance 2026 is less a reason for investigators to worry and more a reason to confirm that existing habits already point the right direction. Documented purpose, minimized data, human review, and a clear read of which risk tier a tool occupies are the same practices that satisfy both GDPR today and the AI Act's fuller obligations as they phase in. Companies and investigators who treat 2026 as a deadline to prepare for, rather than a deadline to react to, will find the transition far less disruptive than the headlines suggest.

Article by article, the AI Act builds toward the same enforcement architecture GDPR already established: a specific article sets an obligation, a related article defines the penalty for missing it, and a third article usually clarifies who is responsible for compliance. Investigators do not need to memorize every article number, but recognizing that the AI Act is structured this way, obligation, enforcement, responsibility, makes it far easier to read guidance summaries without feeling lost. When a vendor cites a specific article of the AI Act to justify a design choice, that citation is usually traceable back to one of these three functions.

The AI office, the EU body tasked with coordinating AI Act enforcement across member states, plays a role similar to the one national data protection authorities play for GDPR. Investigators are unlikely to interact with the AI office directly, but its guidance shapes how national regulators interpret ambiguous provisions of the Act, including where the line falls between high-risk and non-high-risk biometric tools. Watching for AI office guidance is a reasonable way for compliance-minded organizations to stay ahead of shifting interpretation rather than reacting after an enforcement action.

A general-purpose AI code, sometimes called the gpai code, sets out how providers of general-purpose AI models are expected to document training data, manage systemic risk, and cooperate with regulators. This matters less for narrow, case-bound comparison tools and more for the large underlying models some vendors build on top of, but investigators evaluating a vendor's overall compliance posture may reasonably ask whether the vendor's foundation model follows the gpai code. A vendor that can answer that question quickly is usually further along in its broader AI act compliance 2026 preparation.

Sovereignty concerns have entered the AI Act conversation as EU institutions weigh how much of the compliance infrastructure, testing labs, technical standards bodies, oversight capacity, should sit inside the EU rather than depend on outside providers. That debate mostly plays out at the policy level, above where individual investigators operate, but it helps explain why some AI Act guidance emphasizes EU-based conformity assessment bodies over international alternatives. For a working investigator, the practical effect is simply that documentation and testing evidence from EU-recognized bodies tends to carry more weight during any future review.

Put plainly, an ai system that only compares two images already sitting in a case file, with a person reviewing every result, is a different animal from an ai system built to scan open populations for unknown matches. The AI Act's entire risk architecture exists to tell those two systems apart, and every obligation this article has described, from Annex III to transparency obligations to harmonised standards, ultimately traces back to that one distinction. Investigators who keep that distinction in view will rarely find themselves surprised by how a new piece of guidance applies to their own casework.

Frequently asked questions

How does the eu ai act and gdpr apply to facial recognition used in investigations?

The eu ai act and gdpr work together rather than overlapping in conflict: GDPR governs how personal data used in facial comparison is collected, used, and retained under purpose limitation principles, while the AI Act governs the risk tier and technical safeguards of the system performing the comparison. Neither framework treats controlled, case-specific comparison the same as mass biometric collection.

Does GDPR ban AI facial comparison on evidence already in a case file?

No. GDPR Article 9's special-category protections apply to biometric data processed for uniquely identifying a natural person, which regulators increasingly interpret as targeting indiscriminate, large-scale identification rather than closed-loop comparison between two images already held in a case file. Purpose limitation under Article 5(1)(b) protects this kind of documented, case-specific use.

What does the EU AI Act classify as high-risk under eu ai act and gdpr rules?

The EU AI Act classifies real-time remote biometric identification systems operating in public spaces as high-risk, and in many law enforcement contexts prohibited, because that architecture involves identifying people remotely and in real time with no prior relationship to the subjects. Controlled comparison of two images from a defined case file sits in a structurally different, lower-risk category.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search