Responsible AI Platform
All answers

Direct answer

We are considering facial recognition or other biometrics. Is that allowed?

You describe: Biometric identification or categorisation of people, such as facial recognition for access or in public spaces. Likely role: deployer (you use the system).

This applies now

Coming up

Three layers apply at once: some variants are prohibited under Article 5 (enforceable since 2 February 2025), many others are high-risk under Annex III point 1, and exposed persons must be informed under Article 50. Assess Article 5 first.

Your first actions

  1. Classify the use case and document the outcome. Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
  2. Implement the applicable disclosure, marking or label. First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
  3. Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.

Record this

  • Article 6 and Annex III classification record
  • Transparency implementation record
  • AI literacy measures record

General interpretation, not legal advice. The official source remains authoritative.

Full map for your situation

Execution

Record the classification in an AI register

A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.

See the Embed AI approach