Law / European Union

AI Act, Article 26(10) (post-remote biometric identification authorisation)

Regulation (EU) 2024/1689, Article 26(10)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

An AI risk obligations rule binding public and private bodies.

As of 24 September 2026.

What it requires

  • This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
  • If you are a law enforcement deployer using a high-risk AI system for post-remote biometric identification in a targeted search for a suspected or convicted person, request authorisation from a judicial authority or a binding, judicially reviewable administrative authority, in advance or without undue delay and no later than 48 hours, unless you are using the system only for the initial identification of a potential suspect on objective and verifiable facts directly linked to the offence.
  • Limit each use to what is strictly necessary for the investigation of a specific criminal offence.
  • If the authorisation is rejected, stop the linked use immediately and delete the personal data the use generated.
  • Never use such a system in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine threat of one, or the search for a specific missing person.
  • Do not take, or let a law enforcement authority take, any decision producing an adverse legal effect on a person based solely on the system's output.
  • Document every use in the relevant police file, and make it available to the market surveillance authority and the national data protection authority on request, excluding sensitive operational data.
  • Submit annual reports to the relevant market surveillance and data protection authorities on your use of post-remote biometric identification systems.

If you get it wrong

Private right of actionNo

Penalty structure

Article 99(4)(e): non-compliance with the obligations of deployers under Article 26 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.

Rule
Lower of for SME
As of
24 September 2026
Currency
EUR
Fixed cap
15,000,000
Turnover percentage cap
3

What it reaches

How the hook was established

express

What makes it apply

Operator establishment, Place of effect

Obligation class

Biometric, Governance, Reporting

What it makes you log

Who may demand the log

Regulator

What the log must hold

Decision basis, Affected person reference

Logging duty

Every use of a post-remote biometric identification system must be documented in the relevant police file, made available to the market surveillance authority and the national data protection authority on request (excluding sensitive operational data), and reported annually to those authorities.

Kind
Explicit
As of
24 September 2026
Provision
Article 26(10), fifth and sixth subparagraphs
Trigger
high_risk_systems

Who checks it

Audit expectation

on_request

Also on the record

EEA status

Status
Pending
Source link
https://www.efta.int/eea-lex/32024r1689

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

In the framework of a targeted search for a suspected or convicted person, a law-enforcement deployer of a high-risk AI system for post-remote biometric identification must request authorisation, in advance or without undue delay and no later than 48 hours, from a judicial authority or a binding, judicially reviewable administrative authority, except when the system is used for the initial identification of a potential suspect on objective and verifiable facts directly linked to the offence.

Use is limited to what is strictly necessary for a specific criminal investigation; a rejected authorisation request stops the linked use immediately and requires deletion of the personal data it used; untargeted use unconnected to a specific offence, proceeding or threat is never permitted; and no adverse legal decision may rest solely on such a system's output.

Every use must be documented in the relevant police file and made available to the market surveillance authority and the national data protection authority on request, and deployers must submit annual reports on their use of post-remote biometric identification systems.

Article 26 sits in Chapter III, Section 3, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for one classified under Article 6(1) and Annex I.

When LexLint raises it

  • high_risk_decisions
  • processes_biometrics

Read the law

official consolidated Official Journal text, EUR-Lex

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app