AI Act
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – PROHIBITED AI PRACTICES
Chapter III – HIGH-RISK AI SYSTEMS
Chapter IV – TRANSPARENCY OBLIGATIONS FOR PROVIDERS AND DEPLOYERS OF CERTAIN AI SYSTEMS
Chapter V – GENERAL-PURPOSE AI MODELS
Chapter VI – MEASURES IN SUPPORT OF INNOVATION
Chapter VII – GOVERNANCE
Chapter VIII – EU DATABASE FOR HIGH-RISK AI SYSTEMS
Chapter IX – POST-MARKET MONITORING, INFORMATION SHARING AND MARKET SURVEILLANCE
Chapter X – CODES OF CONDUCT AND GUIDELINES
Chapter XI – DELEGATION OF POWER AND COMMITTEE PROCEDURE
Chapter XII – PENALTIES
Chapter XIII – FINAL PROVISIONS
Recitals (180)
Annexes
Recital 54
(54) As biometric data constitutes a special category of personal data, it is appropriate to classify as high-risk several critical-use cases of biometric systems, insofar as their use is permitted under relevant Union and national law. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. The risk of such biased results and discriminatory effects is particularly relevant with regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose. Such a classification excludes AI systems intended to be used for biometric verification, including authentication, the sole purpose of which is to confirm that a specific natural person is who that person claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having secure access to premises. In addition, AI systems intended to be used for biometric categorisation according to sensitive attributes or characteristics protected under Article 9(1) of General Data Protection Regulation (GDPR) on the basis of biometric data, in so far as these are not prohibited under this Regulation, and emotion recognition systems that are not prohibited under this Regulation, should be classified as high-risk. Biometric systems which are intended to be used solely for the purpose of enabling cybersecurity and personal data protection measures should not be considered to be high-risk AI systems.