Real-time biometric identification: the machinery of the exception
Lesson 3 of 4 in Prohibited AI Practices: The Unacceptable Tier.
The RBI prohibition is the only one of the eight with a built-in lawful pathway — and the pathway is deliberately arduous. Before a police force can lawfully run live facial recognition in a public square, five separate conditions must align:
1. A Member State opt-in law. The exceptions do not self-execute. A Member State must have chosen, in national law, to allow RBI use within the Art 5 limits — including rules on authorization, supervision, and reporting. No national law, no lawful RBI in that country, full stop.
2. One of the three exhaustive exceptions. Victim/missing-person search; specific, substantial and imminent threat to life or a genuine and present or foreseeable terrorist threat; or localising a suspect of a listed serious offence carrying at least four years’ detention. "General crime prevention" and "deterrence" are not on the list and never will be by interpretation — the list is exhaustive.
3. Prior authorization by a judicial authority or an independent administrative authority whose decision is binding. The urgency valve: in a duly justified emergency, use may begin without authorization, but authorization must be requested without undue delay, at the latest within 24 hours — and if refused, use stops immediately and all outputs are discarded.
4. Preconditions completed: a fundamental rights impact assessment (the Art 27 FRIA) and registration of the system in the EU database. The paperwork is a gate, not an afterthought.
5. Per-use limits and notification. Each use must be limited in time, geography, and target to what is strictly necessary; each use is notified to the market surveillance authority and the data protection authority. Member States report annually to the Commission on their RBI use.
Can this real-time RBI deployment be lawful?
Interactive decision tree — outcomes:
- Not Art 5 — but high-risk, with its own clock
Retrospective (post) RBI is not prohibited: it is high-risk under Annex III point 1, and deployers need authorization from a judicial or independent administrative authority — requested within 48 hours if used urgently (Art 26(10)), except for identifying an initial suspect based on objective facts. Different regime, still heavily gated.
- Outside 5(1)(h) — check the rest of the Act
The 5(1)(h) ban is specific to law-enforcement purposes. Private-sector live biometric identification is not caught by this prohibition — but it remains high-risk biometrics under Annex III, must survive the GDPR’s Art 9 rules on biometric data, and several Member States restrict it further. "Not prohibited" is the beginning of the analysis, not the end.
- Prohibited — no national gateway
The exceptions only exist where a Member State has legislated to open them. Without an opt-in law regulating authorization and supervision, real-time RBI for law enforcement is simply banned in that Member State.
- Prohibited — purpose not on the list
The three exceptions are exhaustive. General deterrence, routine surveillance, and "public reassurance" are not among them, and the top fine tier (€35M/7%) attaches to violations.
- Prohibited — authorization machinery bypassed
Prior binding authorization is the heart of the regime; the only alternative is the genuine-urgency route with a request at the latest within 24 hours and immediate stop-and-delete on refusal. Skipping it makes the use unlawful even if the purpose fits an exception.
- Prohibited — preconditions incomplete
The FRIA and EU-database registration are express preconditions, not paperwork to backfill. Deploying before they are complete takes the use outside the exception.
- Lawful — inside the narrow corridor
All five conditions align: national law, listed exception, binding prior (or properly regularised urgent) authorization, completed FRIA and registration, and per-use limits with notification to the market-surveillance and data-protection authorities. Note how narrow this corridor is — that narrowness is the policy.
| Dimension | Real-time RBI (live) | Post RBI (retrospective) |
|---|---|---|
Tier | Prohibited for law enforcement, save three exhaustive exceptions — Art 5(1)(h) | High-risk — Annex III point 1 |
Authorization | Prior binding judicial/independent-administrative authorization; urgency route with request at the latest within 24 hours | Judicial/administrative authorization; if used urgently, request within 48 hours (Art 26(10)) |
Preconditions | Member State opt-in law + FRIA + EU-database registration | Full high-risk regime: conformity assessment, oversight, logging, deployer duties |
Carve-outs | None beyond the three exceptions | No authorization needed for the initial identification of a suspect based on objective, verifiable facts directly linked to the offence |
Reporting | Per-use notification; annual Member State reports to the Commission | Standard high-risk monitoring and logging |
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.