AI Act, Article 26(10) (post-remote biometric identification authorisation)
Regulation (EU) 2024/1689, Article 26(10)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
An AI risk obligations rule binding public and private bodies.
As of 24 September 2026.
What it requires
- This duty does not yet apply. It takes effect on 2 December 2027 for a high-risk AI system classified under Article 6(2) and Annex III, and on 2 August 2028 for one classified under Article 6(1) and Annex I.
- If you are a law enforcement deployer using a high-risk AI system for post-remote biometric identification in a targeted search for a suspected or convicted person, request authorisation from a judicial authority or a binding, judicially reviewable administrative authority, in advance or without undue delay and no later than 48 hours, unless you are using the system only for the initial identification of a potential suspect on objective and verifiable facts directly linked to the offence.
- Limit each use to what is strictly necessary for the investigation of a specific criminal offence.
- If the authorisation is rejected, stop the linked use immediately and delete the personal data the use generated.
- Never use such a system in an untargeted way, without any link to a criminal offence, a criminal proceeding, a genuine threat of one, or the search for a specific missing person.
- Do not take, or let a law enforcement authority take, any decision producing an adverse legal effect on a person based solely on the system's output.
- Document every use in the relevant police file, and make it available to the market surveillance authority and the national data protection authority on request, excluding sensitive operational data.
- Submit annual reports to the relevant market surveillance and data protection authorities on your use of post-remote biometric identification systems.
If you get it wrong
Private right of actionNo
Penalty structure
Article 99(4)(e): non-compliance with the obligations of deployers under Article 26 is fined up to EUR 15,000,000 or 3% of worldwide annual turnover, whichever is higher. Article 99(6) requires the lower of the two amounts for an SME, including a start-up; Article 99(6a), inserted by Regulation (EU) 2026/1744, gives the same lower-of treatment to a small mid-cap enterprise, since both apply to paragraph 4 fines.
- Rule
- Lower of for SME
- As of
- 24 September 2026
- Currency
- EUR
- Fixed cap
- 15,000,000
- Turnover percentage cap
- 3
What it reaches
How the hook was established
express
What makes it apply
Operator establishment, Place of effect
Obligation class
Biometric, Governance, Reporting
What it makes you log
Who may demand the log
Regulator
What the log must hold
Decision basis, Affected person reference
Logging duty
Every use of a post-remote biometric identification system must be documented in the relevant police file, made available to the market surveillance authority and the national data protection authority on request (excluding sensitive operational data), and reported annually to those authorities.
- Kind
- Explicit
- As of
- 24 September 2026
- Provision
- Article 26(10), fifth and sixth subparagraphs
- Trigger
- high_risk_systems
Who checks it
Audit expectation
on_request
Also on the record
EEA status
- Status
- Pending
- Source link
- https://www.efta.int/eea-lex/32024r1689
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
In the framework of a targeted search for a suspected or convicted person, a law-enforcement deployer of a high-risk AI system for post-remote biometric identification must request authorisation, in advance or without undue delay and no later than 48 hours, from a judicial authority or a binding, judicially reviewable administrative authority, except when the system is used for the initial identification of a potential suspect on objective and verifiable facts directly linked to the offence.
Use is limited to what is strictly necessary for a specific criminal investigation; a rejected authorisation request stops the linked use immediately and requires deletion of the personal data it used; untargeted use unconnected to a specific offence, proceeding or threat is never permitted; and no adverse legal decision may rest solely on such a system's output.
Every use must be documented in the relevant police file and made available to the market surveillance authority and the national data protection authority on request, and deployers must submit annual reports on their use of post-remote biometric identification systems.
Article 26 sits in Chapter III, Section 3, so it takes effect on the schedule the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) wrote into Article 113: 2 December 2027 for a system classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for one classified under Article 6(1) and Annex I.
When LexLint raises it
high_risk_decisionsprocesses_biometrics
Read the law
official consolidated Official Journal text, EUR-Lex
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.