AI Act
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – PROHIBITED AI PRACTICES
Chapter III – HIGH-RISK AI SYSTEMS
Chapter IV – TRANSPARENCY OBLIGATIONS FOR PROVIDERS AND DEPLOYERS OF CERTAIN AI SYSTEMS
Chapter V – GENERAL-PURPOSE AI MODELS
Chapter VI – MEASURES IN SUPPORT OF INNOVATION
Chapter VII – GOVERNANCE
Chapter VIII – EU DATABASE FOR HIGH-RISK AI SYSTEMS
Chapter IX – POST-MARKET MONITORING, INFORMATION SHARING AND MARKET SURVEILLANCE
Chapter X – CODES OF CONDUCT AND GUIDELINES
Chapter XI – DELEGATION OF POWER AND COMMITTEE PROCEDURE
Chapter XII – PENALTIES
Chapter XIII – FINAL PROVISIONS
Recitals (180)
Annexes
Recital 35
(35) Each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for the purpose of law enforcement should be subject to an express and specific authorisation by a judicial authority or by an independent administrative authority of a Member State whose decision is binding. Such authorisation should, in principle, be obtained prior to the use of the AI system with a view to identifying a person or persons. Exceptions to that rule should be allowed in duly justified situations on grounds of urgency, namely in situations where the need to use the systems concerned is such as to make it effectively and objectively impossible to obtain an authorisation before commencing the use of the AI system. In such situations of urgency, the use of the AI system should be restricted to the absolute minimum necessary and should be subject to appropriate safeguards and conditions, as determined in national law and specified in the context of each individual urgent use case by the law enforcement authority itself. In addition, the law enforcement authority should in such situations request such authorisation while providing the reasons for not having been able to request it earlier, without undue delay and at the latest within 24 hours. If such an authorisation is rejected, the use of real-time biometric identification systems linked to that authorisation should cease with immediate effect and all the data related to such use should be discarded and deleted. Such data includes input data directly acquired by an AI system in the course of the use of such system as well as the results and outputs of the use linked to that authorisation. It should not include input that is legally acquired in accordance with another Union or national law. In any case, no decision producing an adverse legal effect on a person should be taken based solely on the output of the remote biometric identification system.