Technical

Biometric Categorisation System

An AI system that assigns individuals to categories (e.g., age, sex, ethnicity) based on biometric data.

Definition

Biometric categorisation system is an AI-specific term used in the EU Artificial Intelligence Act to describe an AI system whose purpose is to assign natural persons to specific categories on the basis of their biometric data. The Act’s legal definition states: “‘biometric categorisation system’ means an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons.” This definition appears in the AI Act's definition section (Article 3(40)) and is elaborated by Recital 16, which lists example categories (sex, age, hair/eye colour, tattoos, behavioural or personality traits, language, religion, membership of a national minority, sexual or political orientation) and explains the ancillary‑feature exception. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3?utm_source=openai))

Context and scope. The EU definition treats biometric categorisation as a category of biometric AI alongside related terms such as remote biometric identification and emotion recognition; where the Act treats certain uses as either "prohibited" or "high-risk" depending on the attribute inferred and the use context. The Commission’s Guidelines on prohibited AI practices and the AI Act’s recitals clarify that biometric categorisation which seeks to deduce sensitive attributes (race, political opinions, trade union membership, religion, sex life, sexual orientation) from biometric data is subject to the strictest rules and—where used to infer those protected characteristics—may be prohibited. Other categorisations (e.g., age, hair colour) may be classified as high-risk and thus subject to the Act’s compliance measures. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?utm_source=openai))

Jurisdictional Variations

European Union (primary): The formal legal definition and immediate regulatory consequences come from the EU AI Act (Regulation (EU) 2024/1689) — Article 3(40) provides the definitional text and Recital 16 explains scope and the ancillary‑feature exception. The Act (and subsequent Commission Guidelines) (i) bans certain biometric categorisation that infers sensitive characteristics, (ii) treats many biometric categorisation uses as high‑risk where not prohibited, and (iii) permits narrow technical exceptions (e.g., ancillary features strictly necessary for another commercial service or for labelling/filtering datasets). Businesses selling, deploying or importing such systems into the EU must therefore treat the EU text as the primary compliance baseline. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3?utm_source=openai))

United States (federal & state): There is no single, federal statutory definition of “biometric categorisation system” comparable to Article 3(40). U.S. federal policy instruments (e.g., NIST AI Risk Management Framework) provide voluntary, risk‑management guidance rather than prescriptive definitions; NIST focuses on governance, mapping, measurement and management of AI risks and flags biometric data as a privacy/security risk to be managed. The White House Executive Order on Safe, Secure, and Trustworthy AI (EO 14110) directs agencies to develop standards and testing but does not create an Article‑style definition. The FTC enforces consumer protection and has pursued cases involving facial recognition/biometric misuse and published guidance stressing privacy, accuracy and non‑deception obligations; state laws (for example Colorado’s recent biometric privacy amendments — HB24‑1130/HB24‑1130 amendments to the Colorado Privacy Act) define biometric identifiers/data and regulate collection/use but do not use the AI‑term “biometric categorisation system.” US companies therefore must combine federal guidance (NIST, EO), enforcement risk (FTC case law), and applicable state biometric privacy laws when assessing compliance. ([nist.gov](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10?utm_source=openai))

International/standards & soft law: International standards (ISO/IEC 22989 for AI terminology and ISO/IEC 2382‑37 / ISO biometrics vocabularies) provide technical definitions of AI and biometric concepts (biometric characteristic, biometric recognition) but generally do not recreate regulatory categories like the EU’s “biometric categorisation system.” Multilateral instruments and principles (OECD AI Principles; UNESCO Recommendation on the Ethics of AI) set ethical and policy expectations — emphasising human‑centred values, non‑discrimination and limits on surveillance/social scoring — that influence national approaches and inform interpretation of what biometric categorisation should or should not do in practice. Businesses operating internationally must therefore reconcile EU prohibitions, U.S. enforcement practice and state biometric privacy statutes with ISO/OECD/UNESCO norms. ([iso.org](https://www.iso.org/standard/74296.html?utm_source=openai))

Practical implications for businesses operating across jurisdictions. Organizations developing, distributing, or deploying systems that classify people using biometric inputs must: (a) perform careful use‑case scoping to determine whether a system falls within the EU’s Article 3(40) definition and whether it attempts to infer sensitive attributes; (b) apply privacy‑by‑design and risk‑management processes (NIST AI RMF-style) across the lifecycle; (c) comply with state biometric privacy rules (notice/consent, retention, security) in the U.S.; and (d) treat EU prohibitions and high‑risk categorisations as potentially dispositive for market access in the EU. In practice this means stronger data governance, explicit purpose limitation, impact assessments, technical testing for bias/robustness, documentation for auditors/regulators, and product controls that prevent prohibited inferences. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3?utm_source=openai))

Key requirements / criteria (practical checklist):

  • Is the system an AI system and does its stated purpose include assigning natural persons to categories using biometric data? If yes, treat per the EU definition. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3?utm_source=openai))
  • Does inference target sensitive attributes (race, religion, political opinion, sexual orientation, trade-union membership, sex life)? Such uses may be prohibited under the EU AI Act. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?utm_source=openai))
  • Is the feature merely ancillary and strictly necessary for an unrelated commercial service? If so, a narrow exception may apply — document objective technical necessity carefully. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/recital-16?utm_source=openai))
  • Perform AI impact assessments, TEVV (testing, evaluation, verification and validation), bias/fairness testing, and maintain records for regulators and post‑market monitoring. (NIST AI RMF and Commission guidance converge on these operational expectations.) ([nist.gov](https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook?utm_source=openai))

Examples:

  • Allowed/ancillary: a retail “try‑on” filter that adjusts product preview images by detecting skin tone to render clothing appropriately, where the categorisation cannot be used independently of the marketplace function and is objectively necessary — may fall within the ancillary exception under the EU Act (document and justify technical necessity). ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/recital-16?utm_source=openai))
  • Prohibited/high‑risk: an AI service that analyses uploaded photos to infer political orientation or sexual orientation from faces and then targets those individuals with political ads — this would fall squarely into the EU’s prohibited biometric categorisation for sensitive attributes. ([digital-strategy.ec.europa.eu](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?utm_source=openai))

Cross‑references: See biometric data (EU AI Act Article 3 and GDPR Article 4/9), remote biometric identification system (AI Act Article 3), emotion recognition system, and guidance on AI TEVV and governance in the NIST AI RMF. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3?utm_source=openai))

Sources

  • EU AI Act Article 3(40)
  • EU AI Act Article 5