{
  "node_id": "eu-ai-act-high-risk-biometric-systems",
  "title": "EU AI Act - High-Risk AI in Biometric Identification and Categorisation (Annex III Point 1)",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2026-04-28",
  "bluf": "EU AI Act (Regulation 2024/1689) Annex III Point 1 designates as high-risk certain biometric AI systems - specifically (1a) AI systems intended to be used for post-remote biometric identification of natural persons (identification after the event using stored biometric data to identify individuals from recordings or databases) and (1b) AI systems intended to be used for real-time remote biometric identification of natural persons in publicly accessible spaces by law enforcement, which is conditionally permitted subject to Article 5(1)(h) authorisation requirements; critically, real-time remote biometric identification (RTBRI) in publicly accessible spaces is the EU AI Act's most restricted permitted use case - subject to mandatory judicial or independent administrative authorisation for three purposes only: targeted search for specific crime victims, prevention of specific imminent threats to life, and criminal investigation of listed offences; biometric categorisation AI (AI attributing physical or physiological characteristics to individuals) is addressed separately under Article 5(1)(g) as prohibited for law enforcement purposes; the conformity assessment for biometric identification AI under Article 43(1) mandates third-party assessment by a notified body rather than self-certification, making this one of the few Annex III categories requiring mandatory independent conformity assessment; EU AI Act Recital 14 clarifies that biometric verification (confirming a person's claimed identity) is not the same as biometric identification (identifying who a person is) and does not necessarily qualify as high-risk.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0",
    "l402_paywall_url": "https://bidda.com/api/v1/vault/nodes/eu-ai-act-high-risk-biometric-systems.json"
  },
  "crosswalks": {
    "_available_keys": [
      "gdpr",
      "iso_27001",
      "nist_csf"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-ai-act-2024",
    "eu-ai-act-article-5-prohibited-practices",
    "eu-ai-act-article-9-risk-management-system",
    "eu-ai-act-article-10-data-governance-training",
    "eu-ai-act-article-14-human-oversight",
    "eu-ai-act-annex-vii-notified-body-conformity-assessment",
    "eu-ai-act-annex-iii-high-risk-ai-systems"
  ],
  "primary_citations_count": 5
}