The EU AI Act's First Major Enforcement Action Has Arrived and It Targets Biometric Surveillance
Key takeaways
- The EU AI Act prohibits real-time remote biometric identification in publicly accessible spaces for all private commercial operators, with no compliance pathway available
- The AI Office has opened formal proceedings against a facial recognition provider operating in at least three EU member states
- Maximum penalties for prohibited practice violations are 35 million euros or 7% of global annual turnover, whichever is higher
- The outcome will set precedents affecting dozens of similar biometric surveillance deployments across the EU
The EU AI Act has had its first genuinely consequential enforcement moment. European regulators have opened formal proceedings against a facial recognition provider operating in multiple EU member states, marking the first time the Act's prohibited practices provisions have been invoked against a commercial operator. The case centres on real-time biometric identification in publicly accessible spaces, which the Act categorises as an unacceptable risk and bans outright, with narrow exceptions for law enforcement under strict judicial oversight.
The company involved, whose name has not been officially confirmed pending proceedings, is reported to have provided real-time facial recognition infrastructure to private shopping centres and transport operators in at least three EU countries. That is precisely the use case the Act was designed to prohibit. The investigation is being coordinated through the newly established AI Office, the EU body created specifically to enforce the Act at a supranational level.
What the AI Act Actually Says
The EU AI Act, which entered full force in August 2024 with a phased implementation timeline, places facial recognition in public spaces under its strictest category. The prohibition applies to real-time remote biometric identification systems in publicly accessible spaces, with exceptions only for law enforcement seeking judicial or administrative authorisation, and only in cases involving terrorism, targeted searches for specific crime victims, or the most serious criminal offences.
Private commercial operators have no pathway to use real-time biometric identification in public spaces under any circumstances. That is not an interpretation. It is the plain text of the regulation. What makes this first enforcement action significant is that it demonstrates the AI Office is prepared to act, and act against commercial operators whose technology is already deployed and generating revenue, rather than waiting for a new entrant to test the rules.
The Enforcement Challenge
Bringing an enforcement action and winning it are different things. The company will have the opportunity to contest the proceedings, and the specific technical and operational facts will matter. Questions that will need to be resolved include whether the system was genuinely operating in real time or processing stored footage after the fact, and whether the publicly accessible spaces in question meet the Act's definition of that term.
These are not trivial distinctions. A system that captures and processes biometric data in batches rather than in real time might fall into the high-risk category rather than the prohibited category, which carries compliance requirements rather than an outright ban. The AI Office will need to establish its technical position clearly, and the outcome of this case will set precedents that affect dozens of similar deployments across the EU.
The maximum penalty under the AI Act for prohibited practice violations is 35 million euros or 7% of global annual turnover, whichever is higher. For a company with significant revenue, the financial exposure is real.
What This Means for the Industry
Facial recognition vendors have been operating in a state of regulatory uncertainty in Europe for several years, continuing to sell and deploy systems while waiting to see how enforcement would actually function. This first action ends that uncertainty in one important respect: the AI Office exists, it has teeth, and it is willing to use them against commercial deployments.
The ripple effects will extend beyond facial recognition. Companies deploying AI systems in any of the Act's prohibited or high-risk categories who have been taking a wait-and-see approach to compliance now have a clearer signal that the compliance window is closing. The Act's high-risk provisions, which cover areas from credit scoring to employment decisions to critical infrastructure, are already in effect. Formal enforcement actions in those categories are likely to follow.
For the civil liberties community, this is a moment that has been years in the making. Whether it represents a genuine shift in how biometric surveillance is governed in Europe, or the first step in a long legal battle that ends inconclusively, will depend on how robustly the AI Office pursues the case.