The AI Act’s Exclusion of Biometric Verification:

B. Sumer · European Data Protection Law Review · 2024

Biometric applications, like facial recognition, are typically categorised as either identification or verification. Recently, the AI Act (AIA) excluded biometric verification systems from high-risk applications, thereby exempting them from the regulatory requirements, such as accuracy, robustness, and cybersecurity. This article’s primary goal is to critically examine the AIA and GDPR provisions, focusing on biometric verification and highlighting the often blurry lines between biometric verification and identification. Substantial overlap between the two functions can be observed, suggesting that the distinction might be outdated and misleading regarding current trends in biometric recognition. Biometric verification algorithms, depending on the design choices, might pose a series of concerns, including discrimination, bias, surveillance, and function creep. It suggests that a more nuanced approach is needed to ensure accountability.

Read the paper · More papers on PaperTik