By use case · Written by Yobel Tzegai · Last checked 9 October 2026

Is biometric AI allowed under the EU AI Act?

Biometric AI under the EU AI Act: what is prohibited, what is high-risk under point 1 of Annex III, and why one-to-one verification is left out.

Check your AI systems, freeBook a 30-minute walkthrough

The answer, in detail

Where a biometric use sits
UseOutcomeProvisionApplies from
Face or fingerprint login, one-to-one verificationNot in point 1 of Annex IIIPoint 1(a) of Annex III, which excludes it; Article 3, point (36)Not a high-risk use under that point
Remote biometric identificationHigh-risk; prohibited in real time in public spaces for law enforcement, with exceptionsPoint 1(a) of Annex III; Article 5(1), first subparagraph, point (h)2 December 2027 for the high-risk duties; 2 February 2025 for the prohibition
Categorising people to infer race, beliefs or sexual orientationProhibitedArticle 5(1), first subparagraph, point (g)2 February 2025
Categorising by other sensitive or protected attributesHigh-riskPoint 1(b) of Annex III2 December 2027
Scraping faces to build a recognition databaseProhibitedArticle 5(1), first subparagraph, point (e)2 February 2025

Which biometric uses are high-risk?

Which biometric uses are prohibited?

What does a deployer owe?

Your customer asks. You answer with proof.

  1. 1List every AI system

    Add the AI you use. Each system gets a role, a risk class and the article it rests on.

    Live
  2. 2Attach the proof

    Link each duty to a file and the page it stands on: a policy, a log setting, a training record.

    Live
  3. 3Answer their questionnaire

    Answering a customer's questionnaire inside the app, from the proof you already linked.

    Coming soon

What Complipath does

  • Risk classification Answers go through rules in code, never a language model, so the same answers always give the same result. Rules decide. AI only drafts. A person confirms.
  • AI inventory Every AI system you build or use, with its owner and risk class
  • Obligations per system Confirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence
  • Deadlines Each obligation carries the date it applies from, derived from where the provision sits rather than written onto the row

Rules decide. AI only drafts. A person confirms.

What it does not do yet

  • Customer questionnaires (audit room) Coming soon Coming soon: answering a customer's AI questionnaire from your own register.
  • Domain-specific guidance Not supported Guidance written for one sector.

What is live today

Checked against the app on 8 October 2026
Starter

€499 a month

Prices exclude VAT.

  • Up to 20 AI systems
  • Every duty, deadline and article
  • Evidence and the audit log
  • Your first system is free, with no end date
Check your AI systems, free

All plans

Questions

Is face ID to unlock a device high-risk?

No. Point 1(a) of Annex III excludes AI systems intended to be used for biometric verification the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be. Article 3, point (36) defines verification as automated one-to-one verification, including authentication.

Is age estimation from a face biometric categorisation?

It can be: Article 3, point (40) covers assigning natural persons to specific categories on the basis of their biometric data, unless ancillary to another commercial service and strictly necessary for objective technical reasons. Point 1(b) of Annex III lists categorisation according to sensitive or protected attributes or characteristics.

Read next
See what your customers will ask about your AI.No account needed. Every answer cites the article it rests on.