On 2 February 2025 the first operative provisions of the EU AI Act became applicable: the prohibitions of Article 5. Social scoring, emotion recognition in workplaces and schools, untargeted scraping of facial images to build recognition databases, and several other practices are now banned outright across the Union.
Verification is not surveillance
It is worth being precise about what the ban does not cover. One-to-one biometric verification, comparing a live face to the photo in a passport chip to confirm the person presenting the document is its holder, is not remote biometric identification and is not prohibited. The Act draws the line between identifying people in crowds and verifying a claim an individual makes about themselves. Identity verification sits firmly on the lawful side, with obligations arriving later as high-risk system requirements mature in 2026.
Architecture decides your exposure
The regulatory direction is nonetheless clear: biometric data hoarding is a liability. Systems that centrally store face images will carry the heaviest compliance burden under both the AI Act and the GDPR. WeVerify was engineered for this future: raw biometric data never leaves the user's device, the platform stores only a cryptographic proof of the verification result, and every check is evidenced. When the high-risk obligations land in August 2026, that architecture is the difference between a documentation exercise and a re-engineering project.
Liveness & Deepfake Detection · Compliance centre · Book a demo
