Select Page

Mobbeel complies with the AI Act, Regulation (EU) 2024/1689

by | Technology

The AI Act and biometric verification

When the first draft of the world’s first artificial intelligence law, the AI Act, was published, many companies using biometrics in their processes grew alarmed simply because they did not know what was in it. On 24 July 2026, the Digital Omnibus on AI was published in the Official Journal of the European Union. And once again, a good number of voices across the industry started spreading the wrong headline: that Europe had delayed the AI Act. The reality is rather different. Europe has not postponed the obligations as a whole — only those applying to high-risk systems, leaving everything else untouched.

So if your company or organisation verifies identities using biometrics to onboard customers, sign contracts or authenticate access, you need to know exactly which category of the Regulation the solution you are using falls into.

What the AI Act requires today, and what has moved to 2027

Regulation (EU) 2026/1744 of 8 July 2026 amends the AI Act and reschedules part of its timeline. Where things stand today:

Obligation Date of application
Prohibited practices (Art. 5) In force since 2 February 2025
AI literacy (Art. 4) In force since 2 February 2025
General-purpose AI models (GPAI) and penalty regime Since 2 August 2025
Transparency (Art. 50) Since 2 August 2026 — not postponed
High-risk, standalone systems (Art. 6(2) and Annex III) Deferred to 2 December 2027
High-risk embedded in regulated products (Art. 6(1) and Annex I) Deferred to 2 August 2028

The reason for the deferral is that the harmonised technical standards and the national governance frameworks were not ready in time, creating a heavier regulatory burden than anticipated.

The postponement to 2027 affects the high-risk category. Not the prohibitions, not AI literacy, not transparency.

Is verifying an identity with biometrics high-risk?

Annex III of the Regulation lists remote biometric identification systems among its high-risk systems. But that same Annex expressly excludes AI systems intended for biometric verification whose sole purpose is to confirm that a person is who they claim to be.

These are two scenarios that look alike technologically and are treated very differently in law:

Verification (1:1). A person starts a digital onboarding process, holds up their phone, presents their identity document and follows the instructions to take a selfie, so that their face can be compared with the one on their own document. That person knows they are being verified, has given consent, and can abandon the process at any point.

Remote biometric identification using video cameras. A camera in a public space records video in real time and compares the faces of passers-by against a database, with no active participation from those people and without their necessarily knowing that this remote identification is taking place.

The definition in Article 3 of the Regulation highlights precisely that aspect: the absence of active participation by the data subject.

Two systems both using facial recognition does not make them the same system for the purposes of the Regulation. What sets them apart is whether the person participates, knows and consents.

Mobbeel’s solutions operate in the first scenario. The user initiates the process, takes an active part in it and gives explicit consent for the processing of their biometric data. In line with the criteria set out in the Regulation and with the technical guidelines published by Spain’s National Cryptologic Centre (CCN), solutions of this kind generally fall within the low or limited risk levels.

1:N identification. A one-to-many comparison against a database of previously enrolled, consenting users (typically to prevent duplicate registrations or detect repeat fraud) is not the same as remote identification in a public space, but neither is it automatically equivalent to 1:1 verification. Classification depends on the specific use case: who is in that database, how they got there, for what purpose it is queried, and whether the person takes part in the process.

 

What we have done at Mobbeel to comply with the AI Act

In compliance with the obligations laid down by Regulation (EU) 2024/1689, laying down harmonised rules on artificial intelligence (hereinafter, the “AI Regulation” or “AI Act”), Mobbeel has carried out a comprehensive process of analysing, assessing and aligning the artificial intelligence algorithms used in its biometric technologies.

This process was carried out in collaboration with a specialist law firm, and all the phases required to ensure conformity with the applicable regulatory framework have been successfully completed.

As part of that analysis, the main biometric modules developed and marketed by Mobbeel were assessed, including:

  • Face detection.
  • Image quality analysis.
  • Face matching (1:1 and 1:N configurations).
  • Presentation attack detection (liveness detection).
  • Injection attack detection.

The outcome has been formalised in an AI Management System with active controls across nine dimensions:

  • Governance
  • Impact
  • Cybersecurity
  • Data protection
  • System lifecycle
  • Use
  • Supplier relationships
  • Customer relationships
  • Machine learning

As for the obligations that are already enforceable:

Prohibited practices (Art. 5). The analysis confirms that our systems do not engage in any of the practices set out in Article 5. We do not use biometric categorisation aimed at inferring sensitive characteristics (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership or sexual orientation), nor do we build or expand facial recognition databases through the untargeted scraping of images from the internet.

AI literacy (Art. 4). An internal training programme is in place, tailored to the duties and responsibilities of each role. It is not a generic course for the whole workforce: the people who build the engines, the people who deploy them at customer sites and the people who sell them each need something different.

Governance. An AI Committee with formal oversight duties, an approved internal use policy, and a roles-and-permissions model based on the principle of least privilege.

Human oversight. Our solutions allow human intervention in the system’s decisions to be configured according to each customer’s operating model. This ties in directly with Article 22 of the GDPR, which is where many customers’ real obligation lies.

Transparency. Technical and functional documentation of the facial and voice recognition engines is made available to the customer.

What underpins everything else

Alignment with the European Union’s AI Regulation also rests on the same body of controls we already had audited: an ISMS certified to ISO/IEC 27001:2022, conformity with Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS) at HIGH level under Royal Decree 311/2022, the qualification of MobbScan by the National Cryptologic Centre in the CPSTIC catalogue under the LINCE methodology at HIGH category, and the independent evaluation of our facial recognition engine by NIST in the FRTE 1:1, FRTE 1:N and FATE Quality Assessment programmes.

Compliance framework and certifications (September 2026):

Framework Nature Status
ISO/IEC 27001:2022 Information security management system certification Certified
ENS HIGH level (RD 311/2022) Conformity with Spain’s National Security Framework Conformant — HIGH level
CPSTIC / CCN (LINCE methodology) Product qualification for the public sector MobbScan qualified — HIGH category
Regulation (EU) 2024/1689 — AI Regulatory obligation on artificial intelligence systems Alignment completed
GDPR (EU) 2016/679 and LOPDGDD 3/2018 Regulatory obligation on data protection Conformant

Accordingly, the assessment carried out concludes that the artificial intelligence algorithms used in Mobbeel’s biometric technologies comply with the provisions of Regulation (EU) 2024/1689, are not subject to the prohibitions established in Article 5, and are aligned with the regulatory obligations currently enforceable.

Get in touch if you are looking for a facial recognition provider that complies with the European Artificial Intelligence Act (AI Act).

DOSIER PRODUCTO

Descubre nuestra solución de verificación de identidad

Verifica la identidad de tus clientes en segundos a través del escaneo y validación de documentos de identidad y matching biométrico facial con prueba de vida. 

Privacy by design in biometrics

Privacy by design in biometrics

​​Like the old handwritten letters that carried promises and secrets only their recipients could truly understand, some principles never go out of...

mobbeel
Cookies policy summary

We use first-party and third-party cookies to make our website work, analyse how users use the website in order to improve our services and create a profile of your browsing and content viewed in order to show you personalised advertising. Find out more by reading our Cookies policy.

Reject cookies

What is a cookie?

Cookies are files sent from a web server that obtain information from users’ devices, for example, about their preferences and browsing patterns.

Cookies are essential for the functioning of the Internet, as they offer technical solutions that allow the user to browse the different websites; they cannot damage the user’s equipment/device and can be used to identify and resolve possible errors in the functioning of the Website. They may also be used for advertising or analytical purposes.

Use of cookies by Mobbeel

Specifically, MOBBEEL uses its own cookies generated directly by this domain and third-party cookies generated from other websites outside MOBBEEL, belonging to third party companies, for the specific purposes described below. If in the future MOBBEEL uses other cookies for the purpose of providing more and better services, the user will be informed of this.