Under the EU AI Act, some uses of facial recognition and biometric identification are banned.
The clearest ban is on building facial recognition databases through untargeted scraping. This means organisations cannot collect facial images at scale from the internet or from CCTV footage just to grow a biometric database.
The Act also puts very strict limits on real-time remote biometric identification in public spaces for law enforcement. In most cases, this use is prohibited.
Only a few narrow exceptions may apply, for example when authorities need to:
- find specific victims or missing persons
- prevent a clear and immediate threat
- locate suspects linked to certain serious crimes
Even in those cases, the use must be strictly necessary and legally authorised.
This is why the EU AI Act facial recognition ban is not just about technology. It is also about privacy, proportionality, and public trust.
What safeguards are required?
If an exception is used, law enforcement authorities must work within strict limits.
Each use must be limited by:
- time
- place
- scope
In addition, prior authorisation is required from a judicial authority or an independent authority. Also important: no decision with negative impact on a person may be based only on the system output.
National law also remains important. EU Member States can apply stricter rules than the AI Act itself. That means organisations must check both the European framework and local legal requirements.
The European Commission has also published practical guidelines on prohibited AI practices. These guidelines are not legally binding, but they are useful when writing policy, preparing tenders, and reviewing suppliers.
The definition that helps avoid costly mistakes
The key term is remote biometric identification.
It means identifying a person from a distance, without their active involvement, by matching biometric data to a database.
This is different from biometric verification. Verification is a one-to-one check to confirm identity, for example for access to a device or building.
This matters in tenders. Many tools sold as facial recognition are actually identification tools, not verification tools.
How to navigate the bans with privacy-first technology
Privacy-first technology does not mean weaker policing. It means using video technology in a way that supports evidence collection, officer safety, and accountability, without turning it into an automated mass identification tool. This is highly relevant for agencies using body worn video and digital evidence platforms.
A practical approach includes the following measures:
1. Disable identification by default
Biometric identification should never be the standard setting. It should be treated as an exceptional capability that requires explicit approval for each case.
2. Redact footage before sharing
When video is shared outside the core investigative team, automatic face blurring and audio redaction help protect privacy and reduce unnecessary exposure of personal data.
3. Apply strong access control
Use role-based permissions, multi-level authorisation, and full audit logging for every video view, search, and export.
4. Reduce unnecessary data exposure
Set clear retention rules, automate deletion of non-evidence footage, and tightly restrict bulk export rights.
Policy and procurement checklist
Before approving any solution, organisations should ask the following questions:
- Does the solution perform remote biometric identification?
- If yes, is it used in real-time and in publicly accessible spaces?
- Can identification functions be fully disabled, including for integrators and sub-processors?
- What redaction features are available for faces and audio?
- How are exports, searches, and user access controlled and logged?
- What documentation is available for impact assessments, procurement review, and legal oversight?
Where ZEPCAM fits
ZEPCAM takes a privacy-first approach to body worn video. Privacy and GDPR compliance are treated as design requirements, not as optional extras.
ZEPCAM’s body worn video management platform can be deployed as SaaS or on-premise, depending on organisational requirements. ZEPCAM Manager also supports automatic redaction features, including face blurring and audio redaction, to support safer and more privacy-conscious evidence sharing.
A clear starting point for compliant policy
A strong policy starts with one simple principle: body-worn video should be used for safety, accountability, and evidence integrity, not for mass identification.
From there, organisations can build the right governance, technology controls, and operational processes to make that principle enforceable in practice.
If your organisation wants a privacy-first body-worn video programme that is better aligned with the EU AI Act, ZEPCAM offers a practical starting point.
