Try BGBlur

Blur faces instantly with AI-powered face detection

Automatically detect and blur faces in your videos No need for tracking, masking, or in-depth workflows

EU AI Act Facial Recognition Scraping Ban: US Guide [2026]

The EU AI Act's ban on building facial recognition databases from scraped internet or CCTV images has been fully enforceable since February 2025 — and unlike the Act's high-risk AI rules, it was not touched by the July 2026 Digital Omnibus delay. This guide explains what Article 5(1)(e) actually prohibits, why Clearview AI is its textbook target, and what US companies publishing photos or video with EU exposure should do about it.

EU AI ActFacial RecognitionBiometric PrivacyGDPRVideo Compliance
By Yash Thakker
Featured image

If you've read that the EU AI Act's biggest deadlines just got pushed to 2027 and 2028, you'd be forgiven for assuming the facial-recognition rules got a reprieve too. They didn't. The July 2026 "Digital Omnibus on AI" delayed obligations for high-risk AI systems — but Article 5, the Act's outright bans on specific AI practices, was never on that timeline. The prohibition on building facial recognition databases through untargeted scraping of faces from the internet or CCTV footage has applied since February 2, 2025, and it carries the Act's steepest penalty tier: up to €35 million or 7% of global turnover, whichever is higher.

This guide breaks down exactly what Article 5(1)(e) prohibits, why Clearview AI's business model is the textbook violation it was written around, what changed (and didn't change) in the 2026 Digital Omnibus, and what US-based companies publishing or storing facial images with any EU exposure should actually do about it.

What Does the EU AI Act's Facial Recognition Ban Actually Say?

Article 5(1)(e) of the EU AI Act prohibits AI systems that "create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage." Four things have to be true at once for the ban to apply: there's an AI system involved, it's building or growing a facial recognition database, the image collection is untargeted (bulk, indiscriminate — not a specific, individually justified search), and the images come from the internet or CCTV feeds.

That last distinction — untargeted versus targeted — matters. A single, individually justified biometric search tied to a specific investigation isn't what this article is aimed at. It's the industrial-scale scraping model: crawling billions of public photos, social media images, and news archives to build a searchable "who is this person" index, then selling or licensing access to it.

Unlike most of the Act's other prohibited practices, Article 5(1)(e) carries no law enforcement exception. Compare it to Article 5(1)(h), which bans real-time remote biometric identification in public spaces but allows narrow carve-outs for serious crime, missing-persons searches, and imminent terrorism threats. The facial-database-scraping ban has no such door — it applies equally to private companies and government bodies according to the Future of Privacy Forum's analysis of the Article 5 prohibitions.

Wasn't Everything in the EU AI Act Just Delayed?

Some of it, yes — but not this. On July 8, 2026, the EU signed the "Digital Omnibus on AI," which pushed back the compliance deadlines for high-risk AI systems: standalone Annex III systems (things like CV-screening tools, credit-scoring AI, and biometric categorization systems) now have until December 2, 2027, and AI embedded in regulated products (Annex I) has until August 2, 2028.

That delay applies to the Act's high-risk system obligations — documentation, conformity assessments, human oversight requirements. It does not touch Article 5's prohibited practices. Those have been legally in force since February 2, 2025 and were unaffected by the Omnibus, according to legal analysis tracking the EU AI Act's revised enforcement timeline. What does land on August 2, 2026 is a separate, unrelated deadline: transparency obligations for general-purpose AI providers and AI-content labeling under Article 50 — which we cover in our Article 50 deepfake disclosure guide. Conflating the two dates is an easy mistake, but a costly one if it leads a company to assume it has more runway than it actually does on facial data.

QuestionAnswer
What's banned?Building or expanding facial recognition databases via untargeted scraping of internet/CCTV images (Article 5(1)(e))
When did it take effect?February 2, 2025 — unchanged by any later delay
Was it delayed by the July 2026 Digital Omnibus?No — only high-risk system (Annex I/III) obligations were pushed to 2027/2028
Law enforcement exception?None — unlike the real-time biometric ID ban (Article 5(1)(h))
Maximum penaltyUp to €35 million or 7% of global annual turnover, whichever is higher
Does the ban cover publishing photos/video with visible faces?No — it targets database-building via scraping, not publishing per se
Does BGBlur help?Yes — irreversibly blurring faces before publishing removes the raw material scraping tools rely on

Is Clearview AI the Company This Law Was Written For?

It's hard to read Article 5(1)(e) without thinking of Clearview AI. The company built its entire product by scraping billions of publicly posted photos — social media profiles, news photos, public web pages — into a searchable facial recognition index sold to law enforcement and private clients. That's close to a word-for-word match for what the ban prohibits.

European data protection authorities had already been fining Clearview under pre-AI-Act biometric and privacy law for years before Article 5 existed: Italy, France, Greece, and the UK's ICO have collectively levied more than €100 million in penalties. Clearview has largely refused to pay, arguing it has no EU business presence subject to enforcement — a live illustration of the gap between "the law is clear" and "the law is collectible" for companies operating outside the bloc, per reporting tracked by State of Surveillance's ongoing enforcement coverage. The AI Act doesn't fix that jurisdictional gap on its own — but it does raise the ceiling on what a properly-served enforcement action can cost, and it gives EU regulators one unified statute to point to instead of a patchwork of national biometric rules.

Face anonymization for AI compliance and privacy protection

Does This Actually Apply to a US-Based Company?

The EU AI Act reaches outside the EU's borders in two ways that matter here. First, if your AI system's output is used within the EU — even if your company, servers, and staff are entirely US-based — you're in scope. Second, if you process facial images of people physically located in the EU, the same applies, mirroring how GDPR's extraterritorial reach already works.

Practically, that means: a US photo-archiving app with any EU user base, a fitness or dating platform that indexes user photos and has European members, or a security/analytics vendor whose facial-matching feature touches any EU-sourced footage all carry exposure — regardless of where the company is headquartered.

There's also a strategic reason to take this seriously even without direct EU exposure today. US states are moving toward their own biometric statutes modeled partly on Illinois's BIPA, and companies that build EU-compliant data-minimization habits now — deleting or blurring facial data they don't need to retain — spend less re-engineering later when a domestic law catches up. Our GDPR video content compliance guide covers the broader biometric-data framework this ban sits inside.

How Do You Actually Reduce Exposure Here?

Step 1: Audit What You're Storing

List every place your company stores facial images at scale — user-uploaded photo libraries, security camera archives, scraped or licensed image datasets, historical video content. For each, ask whether it was collected through targeted, consented means or bulk/automated collection.

Step 2: Blur or Anonymize Before Publishing or Indexing

Upload footage or images containing third-party faces to BGBlur and run AI-powered face blur before publishing, archiving publicly, or feeding content into any system that might later be scraped. BGBlur's motion-tracked detection locks onto faces across a video automatically — no manual frame-by-frame masking — and processes entirely in-browser.

Step 3: Export and Confirm

Preview the blurred output, export as MP4, MOV, or WebM, and confirm the redaction holds through fast motion and partial occlusion before publishing. Source files are deleted from BGBlur's servers within 24 hours, so no unredacted copy lingers anywhere you don't control.

Step 4: Document the Decision

Keep a short record of what was anonymized, when, and with what tool — the same accountability practice GDPR's Article 5(2) already expects, and one that pays off if a regulator or a platform ever asks.

Where BGBlur Fits (and Where It Doesn't)

BGBlur is a face-blur and anonymization tool, not a legal compliance product, and it can't advise on whether a specific dataset or business model falls under Article 5(1)(e) — that's a question for counsel. What it does solve is the practical half of the problem: removing identifiable facial data from content before it's published, stored long-term, or exposed to scraping, using motion-tracked AI face blur that holds through movement and partial occlusion rather than a static box overlay.

If your company's actual product is biometric identification or database-building — security vendors, ad-tech firms doing facial matching, identity verification providers — blurring existing content won't make that core function compliant; that requires a legal review of the business model itself, not a publishing-stage fix. For everyone else — content platforms, publishers, apps that incidentally handle user photos and video — anonymizing faces before they enter storage or go public is the highest-leverage step available today. See our comparison of face anonymization versus face blur for the technical distinction between the two approaches.

The Bottom Line

Update — August 12, 2026: Article 5(1)(e) covers untargeted scraping. The mirror-image problem — targeted retrospective facial recognition run against footage you already store — sits in the deferred high-risk regime under Article 26(10), which does not apply until December 2, 2027. If you operate cameras rather than scrape the web, read our guide to retrospective facial recognition and your CCTV archive under the EU AI Act.

The EU AI Act's headline delays are real, but they belong to the high-risk system rules, not to Article 5. The facial-recognition scraping ban has been fully enforceable for a year and a half, carries the Act's highest penalty ceiling, and has no law-enforcement exception to soften it. For any company — American or otherwise — publishing, archiving, or indexing facial images with any EU touchpoint, the practical fix is straightforward: irreversibly blur or anonymize faces before that content becomes public or gets stored at scale. Try BGBlur to blur faces in photos and video before you publish.

Frequently Asked Questions

No. The July 2026 Digital Omnibus pushed back obligations for high-risk AI systems under Annex III (to December 2, 2027) and Annex I (to August 2, 2028), but it left Article 5's prohibited practices untouched. The facial-recognition scraping ban in Article 5(1)(e) has applied since February 2, 2025 and remains fully enforceable today, carrying the Act's steepest penalty tier of up to €35 million or 7% of global annual turnover.

Article 5(1)(e) prohibits placing on the market, deploying, or using AI systems that create or expand facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. Four conditions must all be met: an AI system, database creation or expansion, untargeted (bulk, non-selective) scraping, and a source of internet or CCTV images. Targeted, individual-consent-based image collection isn't covered by this specific ban, though it may still trigger GDPR obligations.

No, and that's what makes it unusual among the Act's prohibitions. Article 5(1)(h), which bans real-time remote biometric identification in public spaces, allows narrow law-enforcement exceptions (serious crime, missing persons, terrorism threats). Article 5(1)(e)'s ban on untargeted facial-scraping to build recognition databases has no such carve-out — it applies to private companies and public authorities alike.

The EU AI Act applies extraterritorially: any company whose AI system's output is used within the EU, or that processes facial images of people located in the EU, falls in scope regardless of where the company is headquartered. A US-based platform, app, or archive that stores or indexes facial images scraped from public content — and that has any EU users, customers, or subjects in the images — carries exposure. Several US states are also moving toward BIPA-style biometric statutes, so building EU-compliant practices now reduces duplicate work later.

Clearview AI is widely cited as the paradigm case Article 5(1)(e) was written to address — its business model of scraping billions of facial images from the open web to build a searchable recognition database matches the ban's text almost exactly. European data protection authorities (Italy, France, Greece, the UK, and others) have issued a combined total exceeding €100 million in fines against Clearview under pre-AI-Act biometric and data protection law, though the company has largely not paid, citing lack of EU presence. The AI Act formalizes and extends that enforcement theory across all 27 member states under one unified prohibition.

Yes, for the publishing side of the equation. Article 5(1)(e) targets the creation and expansion of facial recognition databases, not the act of publishing a photo or video that happens to show faces. If a face is irreversibly blurred or anonymized before an image is published, stored, or made scrapable, it can no longer be used as training or matching data for a recognition database — removing the raw material the ban is designed to protect, whether or not you're a company the ban directly targets.

GDPR Article 9 classifies biometric data used for unique identification as a special category requiring explicit consent or another narrow legal basis — it's a consent-and-processing framework enforced by national data protection authorities. The AI Act's Article 5(1)(e) is a flat prohibition on a specific business model (building recognition databases via untargeted scraping), enforced with AI Act penalties. The two overlap but aren't identical: a company could satisfy GDPR consent requirements for a narrow, targeted biometric use case and still fall outside Article 5(1)(e), since that ban is specifically about untargeted, bulk scraping.

Under Article 99 of the EU AI Act, violations of Article 5's prohibited practices carry fines of up to €35 million or 7% of the offending company's total worldwide annual turnover for the prior financial year — whichever figure is higher. For a company with €1 billion in global revenue, the 7% calculation (€70 million) would exceed the flat cap, making this the single highest penalty tier in the entire regulation, above even the €20M/4% GDPR ceiling.