Why the police still cannot identify you by your face

Real-time facial recognition is banned in Europe except in three cases. Fingerprints have been winning for a century, and there is a technical reason.

LA CIENCIA DEL BUCLE

Jose M. Aldasoro

9/27/20264 min read

Macro detail of a fingerprint scanner platen lit in amber on a dark metal desk
Macro detail of a fingerprint scanner platen lit in amber on a dark metal desk

In fiction, a camera catches a face, a system blinks and a name appears. Four seconds. In reality, your fingerprint has been identifying you for a century with a reliability no face comes close to, and real-time facial recognition is banned in Europe except in three very specific cases. Both things are true at once, and together they explain why the four-second scene does not exist.

Fingerprints have been winning for a hundred years

The Spanish National Police identifies fingerprints with SAID, the automated fingerprint identification system, run within the Comisaría General de Policía Científica. It is a database and a matching engine, and it works very well for a reason that almost never gets mentioned: the capture is controlled.

When a person is fingerprinted, the capture is standardised. Position, pressure, surface, order of the fingers, number of impressions. Every sample enters the system under conditions equivalent to every other. That is exactly what makes it possible to compare millions of records without the noise swallowing the signal. Fingerprint biometrics is not reliable because the ridge pattern is magic: it is reliable because the capture procedure has been refined for a century.

And there is a second detail fiction always erases: the system does not identify. The system proposes. It returns a list of candidates ranked by similarity, and the identification is signed by an examiner — a fingerprint analyst — who compares point by point and answers for that conclusion. The machine narrows the work; the responsibility still belongs to a person with a name, a surname and a badge number. On screen, that step simply does not appear.

A face is not a fingerprint

Facial recognition starts from the opposite situation: the capture is uncontrolled.

Angle, distance, lighting, movement, resolution, glasses, a mask, a beard, ten years of difference. None of those variables is under the control of whoever is comparing, and all of them degrade the result. What a facial system returns is not an identity: it is a similarity score. A number between two images. And that number means nothing until somebody decides where to place the threshold above which it counts as a match.

That is the real problem, and it is not technical, it is a decision. Lowering the threshold means finding more people and being wrong more often. Raising it means being wrong less often and finding almost nobody. There is no neutral position: somebody has to choose, and that choice is paid for in false positives, which in this context are not an abstract statistical error but people flagged as someone they are not.

If this way of reading the job interests you — what sits underneath the procedure rather than on top of it — the case file I share with my subscribers goes exactly there. It is here.

Europe has banned it, and left three doors open

Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024, and its list of prohibited practices has applied since 2 February 2025. Among them is the use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes.

The ban is not absolute. It allows narrowly defined exceptions, and there are three: the targeted search for specific victims, the prevention of a terrorist threat, and the location of suspects in certain serious offences. None of the three works on its own. They require prior authorisation, judicial or administrative, an impact assessment, strict limits in time and space, and notification to the competent authority. It is an exceptional regime, with the burden of justification that implies.

Two things get confused daily in public conversation and are worth separating. What is banned is real time: the camera comparing while people walk past. Retrospective biometric identification — comparing an already recorded image within a specific investigation — is not banned: it is classified as high risk, with its own set of obligations. They are two different legal regimes, and treating them as one is the most repeated error in the headlines.

On the timetable it is worth being precise, because there is a lot of noise: there is a proposal in progress, the Digital Omnibus, that would readjust the deadlines for high-risk obligations. As of today it is still under negotiation between the Council and Parliament, it is not law, and in no case does it touch the prohibitions, which already apply.

What fiction skips is the threshold, which is the only interesting part

Go back to the four-second scene. What makes it false is not the speed, which will arrive one day. What makes it false is that the system never doubts. There is no candidate list, no score, nobody deciding where the line sits, no examiner who can say no.

And that is, to me, the worst possible narrative surrender, because the drama is precisely there. A system that is right ninety-nine per cent of the time, applied to a population of a hundred thousand people, is wrong about a thousand of them. The dramatic question is not whether it works. The question is who set the threshold, on what criteria, and what happens to the person who falls on the wrong side of that number.

That is the axis of The Loop: an artificial intelligence that is neither evil nor prone to crude mistakes, but simply decides where the threshold sits, and decides better than we do in almost every case. Almost. I wrote about the other face of the same problem when I asked what happens the day the perpetrator is not a person.

The signature is the real requirement

There is an asymmetry here that strikes me as the core of all this. The fingerprint took a century to earn the trust of the courts, and it earned it for a concrete reason: there was always somebody who signed each identification and answered for it. The system proposes, the examiner confirms, the judge weighs it and the defence can argue with the examiner.

Facial recognition wants that same trust with nobody signing. Not because it could not be done, but because its commercial advantage is precisely scale: if every match needs an examiner to confirm it, the system stops being cheap and stops being instant, which are its only two arguments against what we already had.

So here is the question, and I do want an answer: if a system flags you at ninety-seven per cent similarity and no examiner confirms that result, who exactly do you complain to when the person in front of that camera was not you?