Real-time biometric identification: the machinery of the exception

Lesson 3 of 4 in Prohibited AI Practices: The Unacceptable Tier.

The RBI prohibition is the only one of the eight with a built-in lawful pathway — and the pathway is deliberately arduous. Before a police force can lawfully run live facial recognition in a public square, five separate conditions must align:

1. A Member State opt-in law. The exceptions do not self-execute. A Member State must have chosen, in national law, to allow RBI use within the Art 5 limits — including rules on authorization, supervision, and reporting. No national law, no lawful RBI in that country, full stop.

2. One of the three exhaustive exceptions. Victim/missing-person search; specific, substantial and imminent threat to life or a genuine and present or foreseeable terrorist threat; or localising a suspect of a listed serious offence carrying at least four years’ detention. "General crime prevention" and "deterrence" are not on the list and never will be by interpretation — the list is exhaustive.

3. Prior authorization by a judicial authority or an independent administrative authority whose decision is binding. The urgency valve: in a duly justified emergency, use may begin without authorization, but authorization must be requested without undue delay, at the latest within 24 hours — and if refused, use stops immediately and all outputs are discarded.

4. Preconditions completed: a fundamental rights impact assessment (the Art 27 FRIA) and registration of the system in the EU database. The paperwork is a gate, not an afterthought.

5. Per-use limits and notification. Each use must be limited in time, geography, and target to what is strictly necessary; each use is notified to the market surveillance authority and the data protection authority. Member States report annually to the Commission on their RBI use.

Can this real-time RBI deployment be lawful?

Interactive decision tree — outcomes:

  • Not Art 5 — but high-risk, with its own clock

    Retrospective (post) RBI is not prohibited: it is high-risk under Annex III point 1, and deployers need authorization from a judicial or independent administrative authority — requested within 48 hours if used urgently (Art 26(10)), except for identifying an initial suspect based on objective facts. Different regime, still heavily gated.

  • Outside 5(1)(h) — check the rest of the Act

    The 5(1)(h) ban is specific to law-enforcement purposes. Private-sector live biometric identification is not caught by this prohibition — but it remains high-risk biometrics under Annex III, must survive the GDPR’s Art 9 rules on biometric data, and several Member States restrict it further. "Not prohibited" is the beginning of the analysis, not the end.

  • Prohibited — no national gateway

    The exceptions only exist where a Member State has legislated to open them. Without an opt-in law regulating authorization and supervision, real-time RBI for law enforcement is simply banned in that Member State.

  • Prohibited — purpose not on the list

    The three exceptions are exhaustive. General deterrence, routine surveillance, and "public reassurance" are not among them, and the top fine tier (€35M/7%) attaches to violations.

  • Prohibited — authorization machinery bypassed

    Prior binding authorization is the heart of the regime; the only alternative is the genuine-urgency route with a request at the latest within 24 hours and immediate stop-and-delete on refusal. Skipping it makes the use unlawful even if the purpose fits an exception.

  • Prohibited — preconditions incomplete

    The FRIA and EU-database registration are express preconditions, not paperwork to backfill. Deploying before they are complete takes the use outside the exception.

  • Lawful — inside the narrow corridor

    All five conditions align: national law, listed exception, binding prior (or properly regularised urgent) authorization, completed FRIA and registration, and per-use limits with notification to the market-surveillance and data-protection authorities. Note how narrow this corridor is — that narrowness is the policy.

Real-time vs post RBI — same technology, different regimes
DimensionReal-time RBI (live)Post RBI (retrospective)

Tier

Prohibited for law enforcement, save three exhaustive exceptions — Art 5(1)(h)

High-risk — Annex III point 1

Authorization

Prior binding judicial/independent-administrative authorization; urgency route with request at the latest within 24 hours

Judicial/administrative authorization; if used urgently, request within 48 hours (Art 26(10))

Preconditions

Member State opt-in law + FRIA + EU-database registration

Full high-risk regime: conformity assessment, oversight, logging, deployer duties

Carve-outs

None beyond the three exceptions

No authorization needed for the initial identification of a suspect based on objective, verifiable facts directly linked to the offence

Reporting

Per-use notification; annual Member State reports to the Commission

Standard high-risk monitoring and logging

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.