Article 26(10)
UpcomingFrom 2 Dec 2027Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement
Applies to Law-Enforcement Deployer; Post-Remote Biometric Identification.
- Actors
- Law EnforcementDeployer
- Context
- BiometricsLaw Enforcement
- Themes
- Governance & AccountabilityMonitoring, Reporting & Improvement
Tracker Guidance
For law-enforcement use of a high-risk post-remote biometric identification system, apply all Article 26(10) safeguards, including the required authorisation, strict targeting and necessity limits, deletion if authorisation is refused, the prohibition on solely automated adverse legal decisions, documentation of each use and annual reporting.
Official text
10. Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence. If the authorisation requested pursuant to the first subparagraph is rejected, the use of the post-remote biometric identification system linked to that requested authorisation shall be stopped with immediate effect and the personal data linked to the use of the high-risk AI system for which the authorisation was requested shall be deleted. In no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems. [Excerpt - see official source for complete provision]
Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.
Sub-obligations
These are independently assessable parts of the parent requirement.
Article 26(10), first subparagraph
UpcomingObtain Required Authorisation for Post-Remote Biometric Identification Use
Tracker Guidance
For the targeted search of a person suspected or convicted of an offence, request ex ante authorisation for post-remote biometric identification or, where the Article 26(10) conditions allow, request it without undue delay and no later than 48 hours. The initial-identification exception must be assessed separately.
Official text
Article 26(10), first subparagraphOfficial source 10. Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence.
Article 26(10), first-third subparagraphs
UpcomingLimit Post-Remote Biometric Identification to a Specific Investigation and Stop/Delete if Authorisation Is Rejected
Tracker Guidance
Limit each use of post-remote biometric identification to what is strictly necessary for investigating a specific criminal offence. If authorisation is refused, stop the linked use immediately and delete the personal data linked to that use. Do not use the system in an untargeted way without the required connection to a specified law-enforcement purpose.
Official text
Article 26(10), first-third subparagraphsOfficial source 10. Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence. If the authorisation requested pursuant to the first subparagraph is rejected, the use of the post-remote biometric identification system linked to that requested authorisation shall be stopped with immediate effect and the personal data linked to the use of the high-risk AI system for which the authorisation was requested shall be deleted. In no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems.
Article 26(10), third subparagraph
UpcomingDo Not Base Adverse Legal Decisions Solely on Post-Remote Biometric Identification Output
Tracker Guidance
Ensure that law-enforcement authorities do not make a decision producing an adverse legal effect on a person based solely on the output of the post-remote biometric identification system.
Official text
Article 26(10), third subparagraphOfficial source In no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems.
Article 26(10), fifth subparagraph
UpcomingDocument Each Post-Remote Biometric Identification Use and Make Records Available on Request
Tracker Guidance
Document every use of a post-remote biometric identification system in the relevant police file and make that documentation available to the relevant market-surveillance and national data-protection authorities on request, excluding sensitive operational data.
Official text
Article 26(10), fifth subparagraphOfficial source Regardless of the purpose or deployer, each use of such high-risk AI systems shall be documented in the relevant police file and shall be made available to the relevant market surveillance authority and the national data protection authority upon request, excluding the disclosure of sensitive operational data related to law enforcement. This subparagraph shall be without prejudice to the powers conferred by Directive (EU) 2016/680 on supervisory authorities.
Article 26(10), sixth subparagraph
UpcomingSubmit Annual Reports on Post-Remote Biometric Identification Use
Tracker Guidance
Submit annual reports to the relevant market-surveillance and national data-protection authorities on the use of post-remote biometric identification systems. The reports may aggregate multiple deployments and should exclude sensitive operational data.
Official text
Article 26(10), sixth subparagraphOfficial source Deployers shall submit annual reports to the relevant market surveillance and national data protection authorities on their use of post-remote biometric identification systems, excluding the disclosure of sensitive operational data related to law enforcement. The reports may be aggregated to cover more than one deployment.