# Unacceptable Risk AI Systems — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/unacceptable-risk-ai
> Sources are cited per item. Verify against the official texts before relying on them.

The content specifically addresses unacceptable-risk AI systems as a distinct category of prohibited practices, warranting a dedicated topic for this specific classification and its requirements.

## Overview

## Legal Framework

Unacceptable-risk AI systems are governed by Article 5 of the AI Act, which establishes a closed list of prohibited AI practices. These prohibitions target AI uses that fundamentally conflict with Union values, including human dignity, freedom, democracy, and non-discrimination. Recital 31 specifically addresses social scoring systems, prohibiting AI that evaluates or classifies natural persons based on social behaviour across multiple contexts or personal characteristics not inherently linked to the specific purpose. Such systems risk discriminatory outcomes and exclusionary effects that violate rights to dignity and equal treatment.

Recital 38 addresses real-time remote biometric identification in publicly accessible spaces for law enforcement purposes. The AI Act establishes itself as *lex specialis* with respect to Article 10 of Directive (EU) 2016/680 (the Law Enforcement Directive), regulating both the use of such identification systems and the associated biometric data processing in an exhaustive manner. Recital 34 clarifies that even where exceptions permit use, the deployment must be responsible and proportionate, requiring assessment of the nature of the situation, consequences for rights and freedoms, and applicable safeguards.

The territorial scope of these prohibitions follows the general application rules of the AI Act, which mirror established GDPR principles under Article 3 GDPR. Processing falls within scope where it occurs in the context of an establishment's activities in the Union, even if the actual processing takes place elsewhere. An establishment requires effective and genuine activity through stable arrangements, regardless of scale. The consent requirements drawn from Article 3:33 and 3:35 of the Dutch Civil Code, applied by analogy, demand that data subjects can express their will freely — meaning genuine choice without adverse consequences for refusal or withdrawal.

## Key Developments

The Court of Justice of the EU has shaped the interpretation of "in the context of activities of an establishment" through its jurisprudence on the nearly identical provision in Article 4(1)(a) of the 1995 Data Protection Directive. The Google Spain ruling established that a subsidiary promoting and selling advertising space constitutes a relevant establishment, bringing the parent company's processing within Union jurisdiction. This precedent directly informs how the AI Act's territorial scope applies to unacceptable-risk systems operated by non-EU providers.

The concept of "competent authority" under the Law Enforcement Directive, relevant to Article 5's law enforcement exceptions, encompasses not only government bodies such as judicial authorities and police but also any entity authorized under national law to exercise public authority and powers. This broad interpretation affects which entities may invoke the narrow exceptions for real-time biometric identification.

## Practical Guidance

- Conduct a systematic classification review of all AI systems against the Article 5 prohibited practices list, with particular attention to social scoring functionality that aggregates behavioural data across multiple contexts — any system touching multiple datapoints about social behaviour requires immediate legal assessment under Recital 31.
- For any biometric identification deployment in publicly accessible spaces, verify whether the use case falls within the exhaustively listed exceptions under Article 5 and document the proportionality assessment required by Recital 34, including analysis of the nature of the situation and consequences for all persons' rights and freedoms.
- Map territorial scope carefully: if your organization has any stable arrangement in the Union — including through a commercial agent collecting payments related to an online service — the AI Act's prohibitions apply regardless of where processing technically occurs.
- Ensure that any consent mechanisms associated with AI systems satisfy the genuine-choice standard: consent must be separately obtainable for different processing purposes, freely refusable, and withdrawable without adverse consequences, consistent with the principles underlying Article 3 GDPR and Recital 42.
- Verify that any law enforcement exception reliance is supported by explicit national authorization for the entity exercising public authority, as the definition of competent authority extends beyond traditional government bodies to any entity legally empowered to exercise public powers.

## Legislation (full text of key provisions)

### Recital 32 — risks of real-time biometric identification law enforcement

*Source: AI Act, aiact-rec-32-en, 2024-06-12 — https://overview.legal/posts/93746*

The use of AI systems for ‘real-time’ remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement is particularly intrusive to the rights and freedoms of the concerned persons, to the extent that it may affect the private life of a large part of the population, evoke a feeling of constant surveillance and indirectly dissuade the exercise of the freedom of assembly and other fundamental rights. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. Such possible biased results and discriminatory effects are particularly relevant with regard to age, ethnicity, race, sex or disabilities. In addition, the immediacy of the impact and the limited opportunities for further checks or corrections in relation to the use of such systems operating in real-time carry heightened risks for the rights and freedoms of the persons concerned in the context of, or impacted by, law enforcement activities.

### Recital 38 — real-time biometric identification law enforcement

*Source: AI Act, aiact-rec-38-en, 2024-06-12 — https://overview.legal/posts/93758*

The use of AI systems for real-time remote biometric identification of natural persons in publicly accessible spaces for the purpose of law enforcement necessarily involves the processing of biometric data. The rules of this Regulation that prohibit, subject to certain exceptions, such use, which are based on Article 16 TFEU, should apply as lex specialis in respect of the rules on the processing of biometric data contained in Article 10 of Directive (EU) 2016/680, thus regulating such use and the processing of biometric data involved in an exhaustive manner. Therefore, such use and processing should be possible only in as far as it is compatible with the framework set by this Regulation, without there being scope, outside that framework, for the competent authorities, where they act for purpose of law enforcement, to use such systems and process such data in connection thereto on the grounds listed in Article 10 of Directive (EU) 2016/680. In that context, this Regulation is not intended to provide the legal basis for the processing of personal data under Article 8 of Directive (EU) 2016/680. However, the use of real-time remote biometric identification systems in publicly accessible spaces for purposes other than law enforcement, including by competent authorities, should not be covered by the specific framework regarding such use for the purpose of law enforcement set by this Regulation. Such use for purposes other than law enforcement should therefore not be subject to the requirement of an authorisation under this Regulation and the applicable detailed rules of national law that may give effect to that authorisation.

### Recital 35 — real-time biometric identification law enforcement authorisation

*Source: AI Act, aiact-rec-35-en, 2024-06-12 — https://overview.legal/posts/93752*

Each use of a ‘real-time’ remote biometric identification system in publicly accessible spaces for the purpose of law enforcement should be subject to an express and specific authorisation by a judicial authority or by an independent administrative authority of a Member State whose decision is binding. Such authorisation should, in principle, be obtained prior to the use of the AI system with a view to identifying a person or persons. Exceptions to that rule should be allowed in duly justified situations on grounds of urgency, namely in situations where the need to use the systems concerned is such as to make it effectively and objectively impossible to obtain an authorisation before commencing the use of the AI system. In such situations of urgency, the use of the AI system should be restricted to the absolute minimum necessary and should be subject to appropriate safeguards and conditions, as determined in national law and specified in the context of each individual urgent use case by the law enforcement authority itself. In addition, the law enforcement authority should in such situations request such authorisation while providing the reasons for not having been able to request it earlier, without undue delay and at the latest within 24 hours. If such an authorisation is rejected, the use of real-time biometric identification systems linked to that authorisation should cease with immediate effect and all the data related to such use should be discarded and deleted. Such data includes input data directly acquired by an AI system in the course of the use of such system as well as the results and outputs of the use linked to that authorisation. It should not include input that is legally acquired in accordance with another Union or national law. In any case, no decision producing an adverse legal effect on a person should be taken based solely on the output of the remote biometric identification system.

### Recital 34 — responsible use of real-time biometric identification

*Source: AI Act, aiact-rec-34-en, 2024-06-12 — https://overview.legal/posts/93750*

In order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.

### Recital 95 — post remote biometric identification safeguards

*Source: AI Act, aiact-rec-95-en, 2024-06-12 — https://overview.legal/posts/93872*

Without prejudice to applicable Union law, in particular Regulation (EU) 2016/679 and Directive (EU) 2016/680, considering the intrusive nature of post-remote biometric identification systems, the use of post-remote biometric identification systems should be subject to safeguards. Post-remote biometric identification systems should always be used in a way that is proportionate, legitimate and strictly necessary, and thus targeted, in terms of the individuals to be identified, the location, temporal scope and based on a closed data set of legally acquired video footage. In any case, post-remote biometric identification systems should not be used in the framework of law enforcement to lead to indiscriminate surveillance. The conditions for post-remote biometric identification should in any case not provide a basis to circumvent the conditions of the prohibition and strict exceptions for real time remote biometric identification.

### Recital 17 — remote biometric identification system definition

*Source: AI Act, aiact-rec-17-en, 2024-06-12 — https://overview.legal/posts/93716*

The notion of ‘remote biometric identification system’ referred to in this Regulation should be defined functionally, as an AI system intended for the identification of natural persons without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database, irrespectively of the particular technology, processes or types of biometric data used. Such remote biometric identification systems are typically used to perceive multiple persons or their behaviour simultaneously in order to facilitate significantly the identification of natural persons without their active involvement. This excludes AI systems intended to be used for biometric verification, which includes authentication, the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having security access to premises. That exclusion is justified by the fact that such systems are likely to have a minor impact on fundamental rights of natural persons compared to the remote biometric identification systems which may be used for the processing of the biometric data of a large number of persons without their active involvement. In the case of ‘real-time’ systems, the capturing of the biometric data, the comparison and the identification occur all instantaneously, near-instantaneously or in any event without a significant delay. In this regard, there should be no scope for circumventing the rules of this Regulation on the ‘real-time’ use of the AI systems concerned by providing for minor delays. ‘Real-time’ systems involve the use of ‘live’ or ‘near-live’ material, such as video footage, generated by a camera or other device with similar functionality. In the case of ‘post’ systems, in contrast, the biometric data has already been captured and the comparison and identification occur only after a significant delay. This involves material, such as pictures or video footage generated by closed circuit television cameras or private devices, which has been generated before the use of the system in respect of the natural persons concerned.

### Recital 31 — prohibition of social scoring AI

*Source: AI Act, aiact-rec-31-en, 2024-06-12 — https://overview.legal/posts/93744*

AI systems providing social scoring of natural persons by public or private actors may lead to discriminatory outcomes and the exclusion of certain groups. They may violate the right to dignity and non-discrimination and the values of equality and justice. Such AI systems evaluate or classify natural persons or groups thereof on the basis of multiple data points related to their social behaviour in multiple contexts or known, inferred or predicted personal or personality characteristics over certain periods of time. The social score obtained from such AI systems may lead to the detrimental or unfavourable treatment of natural persons or whole groups thereof in social contexts, which are unrelated to the context in which the data was originally generated or collected or to a detrimental treatment that is disproportionate or unjustified to the gravity of their social behaviour. AI systems entailing such unacceptable scoring practices and leading to such detrimental or unfavourable outcomes should therefore be prohibited. That prohibition should not affect lawful evaluation practices of natural persons that are carried out for a specific purpose in accordance with Union and national law.

### Recital 39 — biometric data processing compliance requirements

*Source: AI Act, aiact-rec-39-en, 2024-06-12 — https://overview.legal/posts/93760*

Any processing of biometric data and other personal data involved in the use of AI systems for biometric identification, other than in connection to the use of real-time remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement as regulated by this Regulation, should continue to comply with all requirements resulting from Article 10 of Directive (EU) 2016/680. For purposes other than law enforcement, Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 prohibit the processing of biometric data subject to limited exceptions as provided in those Articles. In the application of Article 9(1) of Regulation (EU) 2016/679, the use of remote biometric identification for purposes other than law enforcement has already been subject to prohibition decisions by national data protection authorities.

### Recital 54 — high-risk biometric AI classification

*Source: AI Act, aiact-rec-54-en, 2024-06-12 — https://overview.legal/posts/93790*

As biometric data constitutes a special category of personal data, it is appropriate to classify as high-risk several critical-use cases of biometric systems, insofar as their use is permitted under relevant Union and national law. Technical inaccuracies of AI systems intended for the remote biometric identification of natural persons can lead to biased results and entail discriminatory effects. The risk of such biased results and discriminatory effects is particularly relevant with regard to age, ethnicity, race, sex or disabilities. Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose. Such a classification excludes AI systems intended to be used for biometric verification, including authentication, the sole purpose of which is to confirm that a specific natural person is who that person claims to be and to confirm the identity of a natural person for the sole purpose of having access to a service, unlocking a device or having secure access to premises. In addition, AI systems intended to be used for biometric categorisation according to sensitive attributes or characteristics protected under Article 9(1) of Regulation (EU) 2016/679 on the basis of biometric data, in so far as these are not prohibited under this Regulation, and emotion recognition systems that are not prohibited under this Regulation, should be classified as high-risk. Biometric systems which are intended to be used solely for the purpose of enabling cybersecurity and personal data protection measures should not be considered to be high-risk AI systems.

### Recital 33 — law enforcement biometric identification exceptions

*Source: AI Act, aiact-rec-33-en, 2024-06-12 — https://overview.legal/posts/93748*

The use of those systems for the purpose of law enforcement should therefore be prohibited, except in exhaustively listed and narrowly defined situations, where the use is strictly necessary to achieve a substantial public interest, the importance of which outweighs the risks. Those situations involve the search for certain victims of crime including missing persons; certain threats to the life or to the physical safety of natural persons or of a terrorist attack; and the localisation or identification of perpetrators or suspects of the criminal offences listed in an annex to this Regulation, where those criminal offences are punishable in the Member State concerned by a custodial sentence or a detention order for a maximum period of at least four years and as they are defined in the law of that Member State. Such a threshold for the custodial sentence or detention order in accordance with national law contributes to ensuring that the offence should be serious enough to potentially justify the use of ‘real-time’ remote biometric identification systems. Moreover, the list of criminal offences provided in an annex to this Regulation is based on the 32 criminal offences listed in the Council Framework Decision 2002/584/JHA (18), taking into account that some of those offences are, in practice, likely to be more relevant than others, in that the recourse to ‘real-time’ remote biometric identification could, foreseeably, be necessary and proportionate to highly varying degrees for the practical pursuit of the localisation or identification of a perpetrator or suspect of the different criminal offences listed and having regard to the likely differences in the seriousness, probability and scale of the harm or possible negative consequences. An imminent threat to life or the physical safety of natural persons could also result from a serious disruption of critical infrastructure, as defined in Article 2, point (4) of Directive (EU) 2022/2557 of the European Parliament and of the Council (19), where the disruption or destruction of such critical infrastructure would result in an imminent threat to life or the physical safety of a person, including through serious harm to the provision of basic supplies to the population or to the exercise of the core function of the State. In addition, this Regulation should preserve the ability for law enforcement, border control, immigration or asylum authorities to carry out identity checks in the presence of the person concerned in accordance with the conditions set out in Union and national law for such checks. In particular, law enforcement, border control, immigration or asylum authorities should be able to use information systems, in accordance with Union or national law, to identify persons who, during an identity check, either refuse to be identified or are unable to state or prove their identity, without being required by this Regulation to obtain prior authorisation. This could be, for example, a person involved in a crime, being unwilling, or unable due to an accident or a medical condition, to disclose their identity to law enforcement authorities.

## Guidance

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

### Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework

*Source: EDPB, statement-32024-on-data-protection-authorities-role-in-the-en, 2024-07-16 — https://overview.legal/posts/125732 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32024-on-data-protection-authorities-role-in-the_en*

Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted the following statement: 1 BACKGROUND AND PURPO SE OF THIS STATEMENT 1. On 12 July 2024, Regulation (EU) 2024/1689 laying down harmonised rules on a rtificial i ntelligence (Artificial Intelligence Act, hereinafter the “ AI Act ”) and amending certain Union Legislative Acts was published in the Official Journal 1 . 2.…

### Statement on the Digital Services Package and Data Strategy

*Source: EDPB, statement-on-the-digital-services-package-and-data-en, 2021-11-18 — https://overview.legal/posts/125982 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-digital-services-package-and-data_en*

1 Adopted Statement on the D igital Services Package and Data Strategy Adopted on 18 November 2021 The European Data Protection Board has adopted the following statement: Since November 2020 , the European Commission has presented several legislative proposals as part of its digital and data strategies, most notably the Digital Services Act (DSA), the Digital Markets Act (DMA), the Data Governance Act (DGA) and the Regulation on a European appr oach for A rtificial I ntelligence (AIR). A fifth…

## Recent developments

### Manipulatie door algoritmes. Een onderzoek naar de driehoek van oneerlijke commerciële praktijken, gegevensbescherming en privacyrecht.

*Source: SSRN, 2022-10-09 — https://overview.legal/posts/51794*

Machine learning kan worden gebruikt om verkoopstrategieën in de consumentenmarkt te optimaliseren, maar het roept ook zorgen op over manipulatie. Volgens dit artikel is het belangrijk om te begrijpen hoe oneerlijke handelspraktijken, gegevensbescherming en privacywetgeving met elkaar samenhangen, om deze risico's te beperken.

### Manipulation by Algorithms. Exploring the Triangle of Unfair Commercial Practice, Data Protection, and Privacy Law

*Source: SSRN, 2022-10-09 — https://overview.legal/posts/6262 — original: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3835259#entry-1001*

Machine learning can be used to optimize sales practices in consumer markets, but it also raises concerns about manipulation. According to this article, in order to mitigate these risks, we need to understand how unfair commercial practice, data protection, and privacy law interact.

## Literature

### Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act

*Source: Zeszyt Prawniczy UAM, 2025-12-22 — https://overview.legal/posts/132565 — original: https://doi.org/10.14746/zpuam.2025.15.4*

Celem artykułu jest wskazanie przestępstw, w przypadku których służby państwowe mogą korzystać z systemów zdalnej identyfikacji biometrycznej w czasie rzeczywistym w przestrzeni publicznej. Zostanie to uczynione przez analizę przesłanek umożliwiających posługiwanie się tą technologią oraz przyrównanie ich do czynów zabronionych przez polski kodeks karny. Rezultatem powyższego jest stworzenie katalogu przestępstw, odnośnie do których służby mogą zastosować system zdalnej identyfikacji biometryczn

### The Artificial Intelligence Act (AI Act) as the basis for legal regulation of artificial intelligence in the EU: review of the main provisions

*Source: Analytical and Comparative Jurisprudence, 2025-07-12 — https://overview.legal/posts/132431 — original: https://doi.org/10.24144/2788-6018.2025.03.3.44*

This article reviews the main provisions of the Artificial Intelligence Act (AI Act), which entered into force as an EU Regulation in 2014. It is indicated that one of the main global trends in recent years is the active development of artificial intelligence and its application, and it is argued that since the AI Act is one of the first legal acts in the world designed to regulate artificial intelligence, and also taking into account Ukraine’s course towards European integration, it is importan

### Artificial Intelligence in Decision-making: A Test of Consistency between the “EU AI Act” and the “General Data Protection Regulation”

*Source: Athens Journal of Law, 2025-01-02 — https://overview.legal/posts/132443 — original: https://doi.org/10.30958/ajl.11-1-3*

The recent Regulation that sets down harmonised rules on Artificial Intelligence in the European Union, known as the "AI Act," includes a significant requirement for human oversight in high-risk AI systems during their use (art. 14). This requirement embodies the "human-in-command" approach, ensuring both legal and ethical compliance. The AI Act is intended to complement the General Data Protection Regulation (hereinafter GDPR), thereby forming a consistent and comprehensive legal framework. Thi

### The Path of Formulating the Basic Law of Artificial Intelligence in China — Analysis of the Desirability of the EU Artificial Intelligence Act

*Source: Studies in Law and Justice, 2023-09-01 — https://overview.legal/posts/132567 — original: https://doi.org/10.56397/slj.2023.09.09*

The European Commission released the proposed Regulation on Artificial Intelligence (the EU AI Act) on 21 April 2021, which reflects the EU’s leadership orientation in establishing norms and standards in emerging fields, and also reflects the urgent need for legal unity of the EU as a unified market entity. The Act sets out harmonized rules for the development, placing on the market, and use of AI in the European Union. The ideas of a risk-based approach and experimental governance are of great

### The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act

*Source: Ethics & bioethics, 2026-07-06 — https://overview.legal/posts/83515 — original: https://doi.org/10.2478/ebce-2026-0014*

Abstract The paper provides a critical analysis of the EU AI Act (Regulation 2024/1689) within the broader context of contemporary AI developments. Starting from an historical overview on the development of advanced AI systems, it moves the focus onto the intrinsic meaning of Artificial Intelligence to highlight how, despite such fascinating wording, there cannot be a shift of responsibility onto the systems themselves—as was proposed, for example, by the European Parliament resolution of 16 Feb

## Related topics

- **Identification** — https://overview.legal/topics/identificatie
  Methods and processes for identifying individuals
- **Biometric Data** — https://overview.legal/topics/biometrie
  Unique physical characteristics used for identification
- **Biometric Data** — https://overview.legal/topics/biometric-data
  Processing of biometric data for identification
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons

---
Generated by overview.legal · https://overview.legal/topics/unacceptable-risk-ai · 2026-08-22
