# Real-time remote biometric identification ban under the EU AI Act > Article 5(1)(h) bans real-time remote biometric identification, like live facial recognition, in publicly accessible spaces for law enforcement, with three narrow exceptions: locating trafficking or abduction victims, preventing an imminent terrorist threat, or identifying a suspect in a serious crime. In force since 2 February 2025. **Author:** Maarten Stolk **Last reviewed:** 17 August 2026 **Source:** https://deeploy.ai/eu-ai-act-hub/articles/real-time-remote-biometric-identification-ban-under-the-eu-ai-act/ ## Real-time, public, and law enforcement only Article 5(1)(h) is the most publicly recognised of the eight prohibited practices in the EU AI Act, the ban most people mean when they say the Act outlaws facial recognition. It's narrower than the title suggests as it only applies where three conditions are all present at once: the system operates in real time, it's used in a publicly accessible space, and it's deployed for law enforcement purposes. Miss any one of those three, and the system isn't banned outright, it instead falls under the ordinary [high-risk framework](https://deeploy.ai/eu-ai-act-hub/articles/high-risk-ai-system-requirements-compliance-checklist/) for biometric identification in Annex III, point 1, with its own separate set of obligations. A system that identifies people from recorded footage after the fact, rather than live, is a clear example: it sits outside this specific prohibition even though it's still biometric identification. Where all three conditions do apply, the ban holds by default, but not absolutely. Member states can authorise three narrow exceptions, each tied to a specific and serious objective, and each carrying its own procedural conditions before a law enforcement authority can actually use the system. ## **The three conditions that all have to apply**   | **Condition** | **What it means** | **If it's missing** | | --- | --- | --- | | **Real-time** | The system identifies people as they move through a space, using live biometric data, typically facial images, matched against a database, rather than analysing footage after the fact | Falls under Annex III, point 1 as an ordinary high-risk system | | **Publicly accessible space** | The location is open to the public: a street, square, station, or stadium | Sits outside this specific prohibition | | **Law enforcement purpose** | Used by, or on behalf of, a law enforcement authority | Regulated as high-risk biometric identification instead, not banned under this provision | All three have to be true at once, as this is a narrowly tailored ban, not a general prohibition on biometric identification technology. ## **The three exceptions, and what each one permits** - A targeted search for specific victims of abduction, human trafficking, or sexual exploitation, and for missing persons - Preventing a specific, substantial, and imminent threat to the life of persons, or a terrorist attack - Identifying a suspect in a serious crime carrying a maximum custodial sentence of at least four years in the relevant member state Even where one of these applies, the system can only be used to confirm the identity of a specifically targeted individual. It doesn't permit scanning a crowd generally in the hope of finding someone who matches a profile. ### **Before an exception can be applied** None of the three exceptions are automatically available across the EU. A member state first has to pass national law authorising their use domestically. Even then, deployment requires the law enforcement authority to weigh the nature, seriousness, probability, and scale of harm that not using the system would cause against the consequences for the rights and freedoms of everyone affected, and to comply with proportionate safeguards set in that national law, covering temporal, geographic, and personal limits on the deployment. Two further conditions apply before use: a Fundamental Rights Impact Assessment under Article 27 has to be completed, and the system has to be registered in the EU database under Article 49. In duly justified cases of urgency, use can begin before that registration, provided it's completed without undue delay afterwards. ## **A live example ** This provision is not just a theoretical concern. In July 2026, Italy's own data protection authority, the Garante, warned that a police facial-recognition decree cleared by the Italian Senate, which stores facial data from attendees of political demonstrations for seven days before any crime has taken place, conflicts with Article 5(1)(h). The episode illustrates the boundary this provision draws in practice: pre-emptive collection tied to attendance at a lawful demonstration, rather than a targeted search under one of the three exceptions, is exactly the kind of use the prohibition is built to catch. ## Frequently asked questions ## Frequently asked questions ### How do I know if my AI system is high-risk within the EU AI Act? There are two routes to high-risk classification. Under Article 6(1), an AI system that is a safety component of a product covered by EU harmonised legislation (such as medical devices or machinery) is high-risk, provided its failure or malfunction would endanger health or safety. Following the Digital Omnibus, AI used solely for non-safety purposes, such as user assistance, optimisation, service efficiency, automation, convenience, or non-safety quality control, no longer qualifies under this route. Under Article 6(2), standalone AI systems listed in Annex III are high-risk. Annex III covers eight sectors: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration and asylum, and administration of justice. ### What are the maximum fines under the EU AI Act? The Act sets three fine tiers. Violations of the prohibited practices under Article 5 carry fines of up to €35 million or 7% of global annual turnover, whichever is higher. Violations of high-risk system obligations carry fines of up to €15 million or 3% of global annual turnover. Providing incorrect or misleading information to authorities carries fines of up to €7.5 million or 1% of turnover. For SMEs, the lower of the two thresholds applies in each case. ### Does Article 5(1)(h) ban all facial recognition? No. It only bans real-time remote biometric identification used in publicly accessible spaces for law enforcement purposes. Facial recognition used by private companies, or used after the fact rather than live, or used outside a publicly accessible space, falls under different rules, typically the high-risk framework in Annex III, point 1, rather than this prohibition. ### What counts as a 'publicly accessible space' under Article 5(1)(h)? Locations that are open to the public, such as streets, squares, train stations, or stadiums. The prohibition is specifically tied to this kind of space. ### Are there any exceptions to the prohibited AI practices? Mostly no. Only one of the eight prohibited practices, real-time biometric identification by law enforcement, has narrow, tightly conditioned exceptions built in. The rest are banned without exception. ### Who do the prohibited AI practices apply to? Both providers and deployers. Building a banned system or simply using one someone else built are both violations.