The EU AI Act’s prohibition on real-time remote biometric identification in publicly accessible spaces is the regulation’s most dramatic provision. It is also, based on the evidence accumulating through mid-2026, its most contested and least enforced. The gap between what the text says and what is actually happening in European cities is wide enough to drive a surveillance van through.
Start with the text. Article 5 of the Act prohibits placing on the market or into service AI systems for real-time remote biometric identification in publicly accessible spaces for law enforcement purposes. The prohibition is categorical in its framing. It represents a direct legislative rejection of what Clearview AI built, what SenseTime sells, and what China has deployed at a national scale. On paper, this is the most significant legislative ban on a specific AI application in history.
The exceptions, however, are substantial. Real-time biometric identification is permitted for targeted searching for specific victims of crime, preventing specific substantial threats to public safety, and detecting and prosecuting perpetrators of serious crimes. These exceptions sound narrow. In practice, the definition of “specific substantial threat” is expansive enough that any law enforcement agency with competent legal counsel can draft justifications for most foreseeable deployments.
The Exceptions Swallowing the Rule
In March 2026, the Italian Ministry of Interior announced a trial deployment of real-time facial recognition cameras at Milan’s Centrale station, invoking the public safety exception. The Italian data protection authority, the Garante, issued a formal objection. The Ministry proceeded. As of August 2026, the cameras are operational. No enforcement action from the EU AI Office has been announced.
France has taken a more aggressive stance, though not the stance privacy advocates hoped for. Following the 2024 Paris Olympics, which included controversial AI-based crowd surveillance systems that technically operated in post-event review mode rather than real-time, France passed domestic legislation in June 2026 expanding the permissible scope of AI-based biometric surveillance for law enforcement. The EU AI Office’s initial assessment was that the French law operates within the exceptions framework, though civil liberties organizations are challenging this interpretation in the Court of Justice of the EU.
Germany, characteristically, has adopted the most procedurally rigorous approach. The Federal Constitutional Court’s long history of privacy jurisprudence — rooted in the 1983 census case that established “informational self-determination” as a constitutional right — creates domestic legal barriers that exceed the EU AI Act’s minimum protections. German federal police are permitted to use post-event biometric analysis but cannot deploy real-time systems without case-specific judicial authorization. This is more restrictive than the Act requires and reflects the BKA’s awareness that any deployment would face immediate legal challenge.
The result is a three-speed Europe on biometric AI enforcement: Italy and several other southern and eastern member states deploying relatively freely under broad exception claims, France legislating domestically in ways that test the Act’s limits, and Germany maintaining restrictions that exceed what Brussels requires. None of this was the intended outcome of a regulation that was supposed to harmonize AI governance across the bloc.
The Private Sector Parallel
Law enforcement biometric AI gets most of the attention, but the private sector situation is arguably more consequential and less examined.
The Act’s prohibition covers publicly accessible spaces used “for law enforcement purposes.” Private actors are subject to different provisions. A shopping mall deploying facial recognition to identify banned shoplifters is not a law enforcement actor. A concert venue using biometric access control is not a law enforcement actor. An employer using facial recognition for time and attendance is not a law enforcement actor. These deployments fall under the high-risk provisions rather than the prohibition, meaning they’re permissible with appropriate conformity assessment rather than banned outright.
Several large European retail chains deployed biometric identification systems beginning in 2024. Some — Unibail-Rodamco-Westfield, the shopping center operator, most prominently — faced legal challenges from local data protection authorities arguing the systems were prohibited regardless of private-sector status because they operated in “publicly accessible spaces” in a manner functionally equivalent to law enforcement biometric surveillance. Unibail-Rodamco-Westfield’s legal argument: their system identifies individuals against a watchlist of banned shoplifters, which is private security enforcement, not law enforcement. The CNIL (France’s DPA) disagrees. The litigation is ongoing.
This gap between private security and law enforcement in the EU AI Act is genuinely underexplored. The Act’s prohibition was written with state actors in mind. The commercial deployment of biometric identification technology in spaces that most people would consider public — train stations, shopping centers, sports arenas — is more ambiguous, and the ambiguity has created a compliance environment where legal teams advise their retail clients that deployment is defensible while advocacy organizations argue it’s clearly prohibited.
The technology itself has changed the stakes considerably. In 2019, when the debates that would eventually produce the AI Act were beginning, facial recognition technology had error rates — particularly for darker-skinned faces — that made deployment both technically impractical and legally vulnerable. The system didn’t work well enough to be dangerous. By 2024, state-of-the-art commercial facial recognition systems were achieving accuracy rates above 99.9 percent in controlled conditions. The technology caught up to the concern while the regulation was still being drafted.
Enforcement Architecture and Its Limits
The EU AI Office, which holds EU-level enforcement responsibility for prohibited AI practices, has a staff of approximately 300 people and a budget of €75 million for 2026. This sounds significant until you consider the scope of what they’re overseeing. The AI systems potentially covered by the Act number in the hundreds of thousands across EU member states. The Office’s enforcement capacity is necessarily triaged — major systemic violations, high-profile test cases that establish interpretive precedent, and strategic interventions that send signals to the market.
Real-time biometric AI enforcement is a natural priority for signal-sending, which is why the Milan Centrale situation is more significant than it might appear. If the EU AI Office doesn’t act on a national government operating cameras that prima facie violate Article 5 in a major train station, the market signal is that Article 5 is declaratory rather than enforceable. The private sector’s assessment of enforcement risk will be calibrated accordingly.
The Office has, as of this writing, opened a formal investigation into the Milan deployment — announced in June 2026. The investigation is expected to take at least 12 months. By the time any enforcement action is taken, the cameras will have operated for almost two years. The deterrent effect of an eventual fine, if one comes, is difficult to assess.
Civil society is playing an enforcement role that national authorities and the EU AI Office are struggling to fill. The European Digital Rights group (EDRi) and several national organizations — France’s La Quadrature du Net, Germany’s Gesellschaft für Freiheitsrechte, Italy’s Privacy Network — have developed sophisticated litigation strategies targeting both law enforcement biometric deployments and private sector ones. They’ve won some important early cases. A French administrative court issued an injunction against the Nice municipality’s facial recognition pilot in January 2026. The GFF successfully challenged a Berlin transit authority’s experimental biometric system in February 2026.
These wins are meaningful. They also require resources, legal expertise, and years-long commitment to individual cases. Civil society cannot be the primary enforcement mechanism for a regulation covering hundreds of thousands of AI systems. But in the current environment, it’s closer to that than most people admit.
The honest assessment of the biometric AI provisions eight months into enforcement: the prohibition has changed behavior at the margin. It has deterred some deployments that would have proceeded in its absence. It has created legal uncertainty that slows decision-making. But real-time biometric identification in European public spaces is happening, is contested, and is not consistently enforced. The Act’s most dramatic provision is, in practice, a slow-moving legal fight rather than a clean prohibition.
This was probably inevitable. The alternative — a clean, fully enforced prohibition — would require either dramatically more enforcement capacity than the EU AI Office has, or a political consensus at the member state level that doesn’t exist. France and Italy’s governments are not ideologically aligned with strict biometric surveillance restrictions. The Act, to the extent it represents a genuine restriction, will ultimately be as strong as the weakest enforcement link in a 27-member-state bloc. That link is not strong.
The Technology Keeps Moving
One factor that complicates biometric AI enforcement in ways the Act couldn’t fully anticipate: the technology is evolving faster than the regulatory framework.
When the Act was drafted, “real-time remote biometric identification” was primarily synonymous with facial recognition — camera systems processing visual data to match faces against a database. The regulatory concern was specific and visible: cameras in public spaces, AI matching faces, law enforcement using the matches to track or apprehend people.
By 2026, biometric identification technology has diversified. Gait recognition — identifying individuals by how they walk — doesn’t require high-resolution face imagery. It works from lower-quality cameras at greater distances. Voice biometrics can identify individuals through ambient audio. Behavioral biometrics — identifying people by how they move through a crowd, how they interact with objects, their postural signatures — are being deployed in ways that don’t obviously fall within the Act’s “remote biometric identification” definition.
Whether these technologies are covered by the Act’s prohibitions is genuinely unclear. The Act defines “biometric identification system” as a system using biometric data to identify individuals without their prior knowledge. Gait recognition and behavioral biometrics use biometric data in this sense. But the legal question of whether they’re “remote biometric identification” within the prohibition’s scope is contested. Chinese company Watrix, whose gait recognition technology has been deployed in China’s public security apparatus, has been marketing to European private security clients. Their legal position in EU sales presentations: gait recognition isn’t facial recognition, and the Act’s prohibition specifically references “remote biometric identification” in a way they argue doesn’t cover their technology.
This is almost certainly wrong as a matter of purposive statutory interpretation — the prohibition’s purpose clearly covers identifying people in public without their knowledge regardless of the biometric modality. But it will take an enforcement action and probably court proceedings to establish that definitively. In the interval, technology companies are deploying biometric surveillance systems in Europe under legal theories that range from defensible to opportunistic, and the enforcement machinery is too slow and under-resourced to respond in real time.
The cameras are getting smarter. The law is getting argued in slow motion.
One email a month: the upcoming live event + free recording access for subscribers. No spam, unsubscribe anytime.