The AI Act and biometric verification
When the first draft of the world’s first artificial intelligence law, the AI Act, was published, many companies using biometrics in their processes grew alarmed simply because they did not know what was in it. On 24 July 2026, the Digital Omnibus on AI was published in the Official Journal of the European Union. And once again, a good number of voices across the industry started spreading the wrong headline: that Europe had delayed the AI Act. The reality is rather different. Europe has not postponed the obligations as a whole — only those applying to high-risk systems, leaving everything else untouched.
So if your company or organisation verifies identities using biometrics to onboard customers, sign contracts or authenticate access, you need to know exactly which category of the Regulation the solution you are using falls into.
What the AI Act requires today, and what has moved to 2027
Regulation (EU) 2026/1744 of 8 July 2026 amends the AI Act and reschedules part of its timeline. Where things stand today:
| Obligation | Date of application |
|---|---|
| Prohibited practices (Art. 5) | In force since 2 February 2025 |
| AI literacy (Art. 4) | In force since 2 February 2025 |
| General-purpose AI models (GPAI) and penalty regime | Since 2 August 2025 |
| Transparency (Art. 50) | Since 2 August 2026 — not postponed |
| High-risk, standalone systems (Art. 6(2) and Annex III) | Deferred to 2 December 2027 |
| High-risk embedded in regulated products (Art. 6(1) and Annex I) | Deferred to 2 August 2028 |
The reason for the deferral is that the harmonised technical standards and the national governance frameworks were not ready in time, creating a heavier regulatory burden than anticipated.
The postponement to 2027 affects the high-risk category. Not the prohibitions, not AI literacy, not transparency.
Is verifying an identity with biometrics high-risk?
Annex III of the Regulation lists remote biometric identification systems among its high-risk systems. But that same Annex expressly excludes AI systems intended for biometric verification whose sole purpose is to confirm that a person is who they claim to be.
These are two scenarios that look alike technologically and are treated very differently in law:
Verification (1:1). A person starts a digital onboarding process, holds up their phone, presents their identity document and follows the instructions to take a selfie, so that their face can be compared with the one on their own document. That person knows they are being verified, has given consent, and can abandon the process at any point.
Remote biometric identification using video cameras. A camera in a public space records video in real time and compares the faces of passers-by against a database, with no active participation from those people and without their necessarily knowing that this remote identification is taking place.
The definition in Article 3 of the Regulation highlights precisely that aspect: the absence of active participation by the data subject.
Two systems both using facial recognition does not make them the same system for the purposes of the Regulation. What sets them apart is whether the person participates, knows and consents.
Mobbeel’s solutions operate in the first scenario. The user initiates the process, takes an active part in it and gives explicit consent for the processing of their biometric data. In line with the criteria set out in the Regulation and with the technical guidelines published by Spain’s National Cryptologic Centre (CCN), solutions of this kind generally fall within the low or limited risk levels.
1:N identification. A one-to-many comparison against a database of previously enrolled, consenting users (typically to prevent duplicate registrations or detect repeat fraud) is not the same as remote identification in a public space, but neither is it automatically equivalent to 1:1 verification. Classification depends on the specific use case: who is in that database, how they got there, for what purpose it is queried, and whether the person takes part in the process.
What we have done at Mobbeel to comply with the AI Act
In compliance with the obligations laid down by Regulation (EU) 2024/1689, laying down harmonised rules on artificial intelligence (hereinafter, the “AI Regulation” or “AI Act”), Mobbeel has carried out a comprehensive process of analysing, assessing and aligning the artificial intelligence algorithms used in its biometric technologies.
This process was carried out in collaboration with a specialist law firm, and all the phases required to ensure conformity with the applicable regulatory framework have been successfully completed.
As part of that analysis, the main biometric modules developed and marketed by Mobbeel were assessed, including:
- Face detection.
- Image quality analysis.
- Face matching (1:1 and 1:N configurations).
- Presentation attack detection (liveness detection).
- Injection attack detection.
The outcome has been formalised in an AI Management System with active controls across nine dimensions:
- Governance
- Impact
- Cybersecurity
- Data protection
- System lifecycle
- Use
- Supplier relationships
- Customer relationships
- Machine learning
As for the obligations that are already enforceable:
Prohibited practices (Art. 5). The analysis confirms that our systems do not engage in any of the practices set out in Article 5. We do not use biometric categorisation aimed at inferring sensitive characteristics (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership or sexual orientation), nor do we build or expand facial recognition databases through the untargeted scraping of images from the internet.
AI literacy (Art. 4). An internal training programme is in place, tailored to the duties and responsibilities of each role. It is not a generic course for the whole workforce: the people who build the engines, the people who deploy them at customer sites and the people who sell them each need something different.
Governance. An AI Committee with formal oversight duties, an approved internal use policy, and a roles-and-permissions model based on the principle of least privilege.
Human oversight. Our solutions allow human intervention in the system’s decisions to be configured according to each customer’s operating model. This ties in directly with Article 22 of the GDPR, which is where many customers’ real obligation lies.
Transparency. Technical and functional documentation of the facial and voice recognition engines is made available to the customer.
What underpins everything else
Alignment with the European Union’s AI Regulation also rests on the same body of controls we already had audited: an ISMS certified to ISO/IEC 27001:2022, conformity with Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS) at HIGH level under Royal Decree 311/2022, the qualification of MobbScan by the National Cryptologic Centre in the CPSTIC catalogue under the LINCE methodology at HIGH category, and the independent evaluation of our facial recognition engine by NIST in the FRTE 1:1, FRTE 1:N and FATE Quality Assessment programmes.
Compliance framework and certifications (September 2026):
| Framework | Nature | Status |
|---|---|---|
| ISO/IEC 27001:2022 | Information security management system certification | Certified |
| ENS HIGH level (RD 311/2022) | Conformity with Spain’s National Security Framework | Conformant — HIGH level |
| CPSTIC / CCN (LINCE methodology) | Product qualification for the public sector | MobbScan qualified — HIGH category |
| Regulation (EU) 2024/1689 — AI | Regulatory obligation on artificial intelligence systems | Alignment completed |
| GDPR (EU) 2016/679 and LOPDGDD 3/2018 | Regulatory obligation on data protection | Conformant |
Accordingly, the assessment carried out concludes that the artificial intelligence algorithms used in Mobbeel’s biometric technologies comply with the provisions of Regulation (EU) 2024/1689, are not subject to the prohibitions established in Article 5, and are aligned with the regulatory obligations currently enforceable.
Get in touch if you are looking for a facial recognition provider that complies with the European Artificial Intelligence Act (AI Act).

I’m a Software Engineer with a passion for Marketing, Communication, and helping companies expand internationally—areas I’m currently focused on as CMO at Mobbeel. I’m a mix of many things, some good, some not so much… perfectly imperfect.
DOSIER PRODUCTO
Descubre nuestra solución de verificación de identidad
Verifica la identidad de tus clientes en segundos a través del escaneo y validación de documentos de identidad y matching biométrico facial con prueba de vida.



