EU AI Act facial recognition bans: how to stay compliant with privacy-first policing technology

The EU AI Act facial recognition bans are not just a legal issue. They also affect procurement, operational policy, staff training, and public trust. They are especially relevant for organisations working with facial recognition in law enforcement, biometric identification, and body worn video workflows.

For police and law enforcement organisations, the main risk is clear: problems begin when biometric AI starts to look like mass identification in public spaces. That is where the EU AI Act creates the strongest legal and operational pressure.

Under the EU AI Act, some uses of facial recognition and biometric identification are banned.

The clearest ban is on building facial recognition databases through untargeted scraping. This means organisations cannot collect facial images at scale from the internet or from CCTV footage just to grow a biometric database.

The Act also puts very strict limits on real-time remote biometric identification in public spaces for law enforcement. In most cases, this use is prohibited.

Only a few narrow exceptions may apply, for example when authorities need to:

  • find specific victims or missing persons
  • prevent a clear and immediate threat
  • locate suspects linked to certain serious crimes

Even in those cases, the use must be strictly necessary and legally authorised.

This is why the EU AI Act facial recognition ban is not just about technology. It is also about privacy, proportionality, and public trust.

What safeguards are required?

If an exception is used, law enforcement authorities must work within strict limits.

Each use must be limited by:

  • time
  • place
  • scope

In addition, prior authorisation is required from a judicial authority or an independent authority. Also important: no decision with negative impact on a person may be based only on the system output.

National law also remains important. EU Member States can apply stricter rules than the AI Act itself. That means organisations must check both the European framework and local legal requirements.

The European Commission has also published practical guidelines on prohibited AI practices. These guidelines are not legally binding, but they are useful when writing policy, preparing tenders, and reviewing suppliers.

The definition that helps avoid costly mistakes

The key term is remote biometric identification.

It means identifying a person from a distance, without their active involvement, by matching biometric data to a database.

This is different from biometric verification. Verification is a one-to-one check to confirm identity, for example for access to a device or building.

This matters in tenders. Many tools sold as facial recognition are actually identification tools, not verification tools.

How to navigate the bans with privacy-first technology

Privacy-first technology does not mean weaker policing. It means using video technology in a way that supports evidence collection, officer safety, and accountability, without turning it into an automated mass identification tool. This is highly relevant for agencies using body worn video and digital evidence platforms.

A practical approach includes the following measures:

1. Disable identification by default

Biometric identification should never be the standard setting. It should be treated as an exceptional capability that requires explicit approval for each case.

2. Redact footage before sharing

When video is shared outside the core investigative team, automatic face blurring and audio redaction help protect privacy and reduce unnecessary exposure of personal data.

3. Apply strong access control

Use role-based permissions, multi-level authorisation, and full audit logging for every video view, search, and export.

4. Reduce unnecessary data exposure

Set clear retention rules, automate deletion of non-evidence footage, and tightly restrict bulk export rights.

Policy and procurement checklist

Before approving any solution, organisations should ask the following questions:

  1. Does the solution perform remote biometric identification?
  2. If yes, is it used in real-time and in publicly accessible spaces?
  3. Can identification functions be fully disabled, including for integrators and sub-processors?
  4. What redaction features are available for faces and audio?
  5. How are exports, searches, and user access controlled and logged?
  6. What documentation is available for impact assessments, procurement review, and legal oversight?

Where ZEPCAM fits

ZEPCAM takes a privacy-first approach to body worn video. Privacy and GDPR compliance are treated as design requirements, not as optional extras.

ZEPCAM’s body worn video management platform can be deployed as SaaS or on-premise, depending on organisational requirements. ZEPCAM Manager also supports automatic redaction features, including face blurring and audio redaction, to support safer and more privacy-conscious evidence sharing.

A clear starting point for compliant policy

A strong policy starts with one simple principle: body-worn video should be used for safety, accountability, and evidence integrity, not for mass identification.

From there, organisations can build the right governance, technology controls, and operational processes to make that principle enforceable in practice.

If your organisation wants a privacy-first body-worn video programme that is better aligned with the EU AI Act, ZEPCAM offers a practical starting point.

Share This