The classic trap
Recital 32 sheds light on the prohibition set out in Article 5 of the AI Act: real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is banned, save for strict exceptions. In practice, this recital broadens the risk reading well beyond police forces alone: any organisation (airport operator, municipality, shopping centre, stadium, casino, bank) deploying real-time facial recognition exposes itself to a purpose requalification if the footage is later made available to police. Luxembourg's CNPD has already recalled in its videosurveillance guidance that biometrics in publicly accessible places remains a high-risk processing under Article 35 GDPR, thus stacking AI Act and GDPR grievances.
Real-time biometric pitfalls in practice
- Confusing identification (1:N, match against a database) with authentication (1:1, consented access control): only the former is covered by recital 32.
- Believing that a de facto partnership with local police does not turn your private setup into a law enforcement tool under the AI Act.
- Underestimating demographic bias: error rates documented by NIST (FRVT) vary by a factor of 10 to 100 depending on the subject's age, gender or skin tone.
- Forgetting that the immediacy of the decision (door opening, alert triggered) removes any effective human review, tipping the system into prohibited practice.
- Neglecting the Article 35 GDPR DPIA and the Article 27 AI Act fundamental rights impact assessment (FRIA): both are cumulative for such systems.
- Storing biometric templates without an Article 9 GDPR legal basis: CNPD rarely considers consent freely given in a publicly accessible space.
How Luxgap automates this risk
Our Luxgap Biometric Exposure Radar makes the silent deployment of real-time biometric systems impossible in your organisation: the tool continuously scans your CCTV fleet, vendor contracts and network flows to detect any camera, NVR or middleware embedding a facial recognition engine, and qualifies it immediately against Article 5 and Annex III of the AI Act. It cross-references hardware fingerprints (Hikvision, Dahua, Axis, Bosch, Milestone, Genetec) with their active AI module catalogue, and inspects Active Directory and M365 flows to spot any biometric SDK integration (AWS Rekognition, Azure Face API, NEC NeoFace, Idemia).
- Automatically detects every camera or software embedding a facial recognition or attribute detection engine (age, gender, emotion) across your estate.
- Classifies each use case against the AI Act grid: prohibited Article 5, high-risk Annex III, or plain GDPR Article 6 videosurveillance.
- Generates a pre-filled Article 27 FRIA and Article 35 GDPR DPIA, with proportionality analysis and documented less intrusive alternatives.
- Triggers real-time Teams or email alerts whenever a vendor pushes a firmware update adding an undeclared biometric module (a frequent silent change among integrators).
- Produces a timestamped, cryptographically sealed PDF report, enforceable before CNPD and Luxembourg's future AI regulator, proving your setup does not perform 1:N identification in publicly accessible spaces.
- Tracks NIST FRVT error rates published for each identified model and flags documented demographic biases.
Available as an add-on to a Luxgap DPO or CISO mandate or as a standalone SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real CCTV fleet, with a free 48-hour blind audit to map your biometric exposure before any engagement.