Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Article 26(10)

UpcomingFrom 2 Dec 2027

Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement

Applies to Law-Enforcement Deployer; Post-Remote Biometric Identification.

Actors
Law EnforcementDeployer
Context
BiometricsLaw Enforcement
Themes
Governance & AccountabilityMonitoring, Reporting & Improvement

Tracker Guidance

For law-enforcement use of a high-risk post-remote biometric identification system, apply all Article 26(10) safeguards, including the required authorisation, strict targeting and necessity limits, deletion if authorisation is refused, the prohibition on solely automated adverse legal decisions, documentation of each use and annual reporting.

Official text

Article 26(10)Official source
10. Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence. If the authorisation requested pursuant to the first subparagraph is rejected, the use of the post-remote biometric identification system linked to that requested authorisation shall be stopped with immediate effect and the personal data linked to the use of the high-risk AI system for which the authorisation was requested shall be deleted. In no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems. [Excerpt - see official source for complete provision]

Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.

Sub-obligations

These are independently assessable parts of the parent requirement.

  1. Article 26(10), first subparagraph

    Upcoming

    Obtain Required Authorisation for Post-Remote Biometric Identification Use

    Tracker Guidance

    For the targeted search of a person suspected or convicted of an offence, request ex ante authorisation for post-remote biometric identification or, where the Article 26(10) conditions allow, request it without undue delay and no later than 48 hours. The initial-identification exception must be assessed separately.

    Official text

    Article 26(10), first subparagraphOfficial source
    10. Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence.
  2. Article 26(10), first-third subparagraphs

    Upcoming

    Limit Post-Remote Biometric Identification to a Specific Investigation and Stop/Delete if Authorisation Is Rejected

    Tracker Guidance

    Limit each use of post-remote biometric identification to what is strictly necessary for investigating a specific criminal offence. If authorisation is refused, stop the linked use immediately and delete the personal data linked to that use. Do not use the system in an untargeted way without the required connection to a specified law-enforcement purpose.

    Official text

    Article 26(10), first-third subparagraphsOfficial source
    10. Without prejudice to Directive (EU) 2016/680, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review, for the use of that system, except when it is used for the initial identification of a potential suspect based on objective and verifiable facts directly linked to the offence. Each use shall be limited to what is strictly necessary for the investigation of a specific criminal offence. If the authorisation requested pursuant to the first subparagraph is rejected, the use of the post-remote biometric identification system linked to that requested authorisation shall be stopped with immediate effect and the personal data linked to the use of the high-risk AI system for which the authorisation was requested shall be deleted. In no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems.
  3. Article 26(10), third subparagraph

    Upcoming

    Do Not Base Adverse Legal Decisions Solely on Post-Remote Biometric Identification Output

    Tracker Guidance

    Ensure that law-enforcement authorities do not make a decision producing an adverse legal effect on a person based solely on the output of the post-remote biometric identification system.

    Official text

    Article 26(10), third subparagraphOfficial source
    In no case shall such high-risk AI system for post-remote biometric identification be used for law enforcement purposes in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine and present or genuine and foreseeable threat of a criminal offence, or the search for a specific missing person. It shall be ensured that no decision that produces an adverse legal effect on a person may be taken by the law enforcement authorities based solely on the output of such post-remote biometric identification systems.
  4. Article 26(10), fifth subparagraph

    Upcoming

    Document Each Post-Remote Biometric Identification Use and Make Records Available on Request

    Tracker Guidance

    Document every use of a post-remote biometric identification system in the relevant police file and make that documentation available to the relevant market-surveillance and national data-protection authorities on request, excluding sensitive operational data.

    Official text

    Article 26(10), fifth subparagraphOfficial source
    Regardless of the purpose or deployer, each use of such high-risk AI systems shall be documented in the relevant police file and shall be made available to the relevant market surveillance authority and the national data protection authority upon request, excluding the disclosure of sensitive operational data related to law enforcement. This subparagraph shall be without prejudice to the powers conferred by Directive (EU) 2016/680 on supervisory authorities.
  5. Article 26(10), sixth subparagraph

    Upcoming

    Submit Annual Reports on Post-Remote Biometric Identification Use

    Tracker Guidance

    Submit annual reports to the relevant market-surveillance and national data-protection authorities on the use of post-remote biometric identification systems. The reports may aggregate multiple deployments and should exclude sensitive operational data.

    Official text

    Article 26(10), sixth subparagraphOfficial source
    Deployers shall submit annual reports to the relevant market surveillance and national data protection authorities on their use of post-remote biometric identification systems, excluding the disclosure of sensitive operational data related to law enforcement. The reports may be aggregated to cover more than one deployment.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Article 26(10): Apply Required Safeguards When Using High-Risk AI for Post-Remote Biometric Identification in Law Enforcement | EU AI Act Library