FTFuture Technology
SECURITY

The EU AI Act's First Real Enforcement Actions Are Here, and They Are Targeting Biometric Systems

· 3 min read · By Nath Connell

Key takeaways

  • The European AI Office has opened formal investigations into three companies for biometric AI systems under the EU AI Act
  • Fines for prohibited AI practices can reach 35 million euros or seven percent of global annual turnover, whichever is higher
  • Targeted use cases include emotion recognition in retail stores, automated video interview analysis, and inferred characteristic access control

The EU AI Act became fully applicable for high-risk AI systems in August 2026, and the European AI Office has not wasted time signalling where its early enforcement attention is going. Biometric categorisation systems, the technology that identifies or categorises people by physical characteristics, are at the top of the list, and the first formal investigations have been opened against three companies operating such systems in public-facing contexts.

The details of the investigations are not public, because EU enforcement proceedings at this stage are confidential, but sources familiar with the process have confirmed to multiple outlets that the companies involved include a retail analytics firm using emotion recognition in physical stores, a recruitment technology company running automated video interview analysis, and an access control provider whose system infers characteristics beyond simple identity verification.

All three categories fall under what the AI Act classifies as unacceptable risk or high risk depending on the specific use case, and all three were areas that advocacy groups specifically flagged during the Act's drafting process as requiring strong enforcement. The fact that the Office has moved on all three simultaneously suggests a deliberate strategy of establishing precedent across the full range of prohibited and restricted uses, rather than picking off easy targets.

What the AI Act Actually Says About Biometrics

The Act prohibits real-time biometric identification in publicly accessible spaces for law enforcement purposes with only narrow exceptions. Beyond that, it places biometric categorisation systems that infer sensitive characteristics, including race, political opinion, and emotional state, in the highest risk category. Companies operating such systems must meet strict requirements including conformity assessments, technical documentation, human oversight mechanisms, and registration in a public EU database.

The emotion recognition prohibition in commercial contexts was one of the more contested elements of the Act during negotiation. Retail and marketing industries argued that aggregate emotion analytics, as distinct from individual surveillance, served legitimate commercial purposes. The final text drew a line that many in those industries felt was ambiguous, and that ambiguity is now being resolved through enforcement rather than further legislation.

For companies that have been operating these systems in good faith based on their reading of the law, the investigations are concerning. Legal uncertainty around the exact boundaries has been a genuine problem since the Act passed, and several industry bodies have published guidance that now looks like it may have been too permissive.

The future, in 3 minutes a day. The biggest tech story explained every morning, free. Get the briefing →

The Broader Enforcement Architecture

The European AI Office sits at the EU level and handles enforcement for general purpose AI models and systems with EU-wide reach. Member states have their own national supervisory authorities for most other AI Act matters, and the coordination between these layers is still being worked out. The current investigations appear to be running through national authorities with the European AI Office providing oversight, which is the intended architecture but has not been tested before.

Fines under the AI Act are structured as a percentage of global annual turnover, with prohibited AI practices carrying fines of up to 35 million euros or seven percent of global turnover, whichever is higher. For a large retail analytics firm, that could represent a very material sum. For smaller startups, the existential threat is obvious.

The Office has also indicated it will be looking at transparency obligations for high-risk systems more broadly, with a focus on whether companies have actually completed the required conformity assessments or are treating that as a box-ticking exercise. Early indications are that compliance levels are patchy, which gives regulators a lot of material to work with.

What Businesses Should Be Taking From This

If you are running any kind of automated analysis on people in the EU, now is a very good moment to audit what you are doing against the Act's requirements rather than relying on prior legal guidance that may have been optimistic. The enforcement signals from the Office are clear: biometrics are the priority, documentation requirements will be taken seriously, and the fact that a technology is common or commercially useful does not exempt it from the rules.

The AI Act was always going to matter most once enforcement began. That moment has arrived, and the approach the Office is taking looks like it means business.

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.