EU AI Act Bans Untargeted Facial Recognition as US Cities Face Circumvention

EU AI Act Bans Untargeted Facial Recognition as US Cities Face Circumvention
Key Takeaways

  • The EU AI Act’s prohibitions, effective February 2025, ban the untargeted scraping of facial images for recognition databases and restrict real-time remote biometric identification by law enforcement in publicly accessible spaces.
  • San Francisco banned government use of facial recognition in 2019, the first city globally to do so; at least 10 US cities had followed by 2020, citing civil liberties concerns and documented racial bias in identification accuracy.
  • A May 2024 Washington Post report found that police in San Francisco and Austin, both cities with facial recognition bans, had submitted requests to neighbouring departments to run searches on their behalf, with some requests reportedly leading to arrests.

Police in cities that have banned facial recognition are, according to a May 2024 Washington Post investigation, quietly outsourcing searches to neighbouring jurisdictions with no such restrictions. The finding cuts to the core tension in facial recognition regulation: local prohibitions may constrain policy on paper while doing little to limit practice. Against that backdrop, the EU’s AI Act and a growing number of US state laws are attempting to build frameworks with enough reach to close the gap.

The European Approach: EU AI Act’s Sweeping Bans

The EU AI Act is the most comprehensive attempt to date to regulate facial recognition at a legislative level. The Act designates certain facial recognition applications as “unacceptable risk” and bans them outright. Among these is the creation or expansion of facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage, a practice the legislation frames as incompatible with the right to privacy and the right to remain anonymous. Those prohibitions took effect in February 2025.

The Act also establishes a general ban on “real-time” remote biometric identification in publicly accessible spaces for law enforcement purposes. Exceptions exist, targeted searches for victims of abduction or human trafficking, responses to substantial threats, identification of suspects in serious crimes, but they come with strict conditions, including fundamental rights impact assessments and registration in the EU database. The architecture is one of narrow, supervised exceptions rather than broad permission.

US Cities Lead Local Prohibitions

In the United States, the sharpest restrictions on facial recognition have come from local government, not federal action. San Francisco became the first city in the world to ban facial recognition software for public agencies in 2019, making it unlawful for any city department, including the police, to obtain, retain, access or use the technology or information derived from it.

Other cities followed quickly. Somerville, Massachusetts voted unanimously to ban government face surveillance in June 2019, becoming the first East Coast city to do so. Boston enacted a similar ban in June 2020. Additional Massachusetts municipalities, Brookline, Cambridge, Easthampton, Northampton and Springfield, have since passed their own restrictions. Outside Massachusetts, Oakland (2019), Portland (2020), Jackson and Austin have also enacted bans or significant limits on government use.

State-Level Actions and Emerging Requirements

Several US states have moved to restrict police use of facial recognition, with the pace of legislation increasing after 2020. Oregon was an early mover in 2017, with a narrow law governing facial recognition in conjunction with police body cameras. New Hampshire has a similar body camera restriction. Vermont and Maine have enacted stronger, broader limits.

Montana and Utah have gone further still, introducing warrant requirements for police use of the technology, with carve-outs for emergencies and the identification of missing or deceased persons. A separate cluster of states, including Alabama, Colorado, Illinois, Massachusetts, Minnesota, New Jersey and Virginia, has imposed notice requirements, restricted use to serious crimes, or prohibited facial recognition from serving as the sole basis for an arrest. By the end of 2024, roughly 15 states had enacted some form of guardrails, according to publicly available legislative records.

Why Jurisdictions Say No: Privacy, Bias and Surveillance

Documented inaccuracy is the sharpest argument against facial recognition in law enforcement contexts. The 2018 “Gender Shades” project found that facial recognition software performed worst on darker-skinned women, a result attributed to training datasets that skewed heavily toward white male subjects. Those findings have been cited repeatedly in legislative debates as evidence that deployment at scale creates unacceptable risk of wrongful identification and discriminatory enforcement outcomes.

The privacy objection runs alongside the accuracy concern. Critics argue that facial recognition, deployed without strong legal constraints, enables mass surveillance of public spaces, tracking individuals without consent or probable cause in ways that can deter free expression and assembly. A further concern, raised in regulatory submissions across multiple jurisdictions, is “automation bias”: the tendency for human decision-makers to defer to machine-generated outputs even when those outputs are unreliable. Where a facial recognition match becomes the primary basis for a stop or arrest, the risk of that bias causing concrete harm is direct.

The pace of deployment has often outrun the legislative response. In a number of US jurisdictions, police agencies adopted the technology before any legal framework was in place to govern its use.

Enforcement Challenges and Loopholes

The Washington Post’s May 2024 report identified a specific mechanism by which local bans are being circumvented. San Francisco police reportedly submitted at least five requests for facial recognition searches to outside agencies, while Austin police recorded 13 such requests to a neighbouring department, some of which reportedly led to arrests. Both cities have local bans in place.

The pattern raises a structural question for policymakers: a prohibition that applies only within a single jurisdiction creates an incentive to route requests elsewhere rather than to stop making them. Without state-level or federal alignment, local bans may constrain official use of the technology while leaving informal workarounds intact. How common this practice is across other cities with bans is not fully established from public reporting, but the documented cases suggest the loophole is known and in use. This is the same dynamic that AI liability cases have exposed in other domains, jurisdictional gaps that make local rules easier to route around than to enforce.

The Canadian and UK Context: Calls for Clearer Rules

Bill C-27, whose legislative status remains subject to change, recognises biometric data as sensitive, but critics argue it lacks mandatory Privacy Impact Assessments and real-time disclosure obligations for facial recognition systems specifically. The United Kingdom’s legal framework has been described by biometrics watchdogs as fragmented, with national oversight lagging behind the pace of deployment.

The United Kingdom’s legal framework has been described by biometrics watchdogs as fragmented, with national oversight lagging behind the pace of deployment. A public consultation on a new legal framework for law enforcement use of facial recognition was launched in December 2025 and concluded in February 2026, though no legislative outcome has been confirmed at the time of writing. Recent UK court rulings have rejected legal challenges to police use of the technology, a development that legal observers expect will encourage wider deployment by law enforcement agencies. For more coverage of AI policy and regulation, visit our AI Policy & Regulation section.

Jordan Mills
Jordan Mills

Jordan covers AI policy, regulation, and ethics across global markets. With a focus on governance frameworks and compliance, Jordan tracks the regulatory forces shaping the AI industry.

📰 Journalists welcome — cite Auton AI News with attribution. Press & Media → | press@autonainews.com