Facial recognition is software that compares a human face in an image against one or more stored reference faces, either to confirm that a person is who they claim to be or to establish who an unknown person is. The technology exists because faces are the one biometric that cameras capture passively, at a distance and in bulk. That makes them useful for unlocking phones, boarding passengers and catching impostors in advertising, and troubling for the same reasons.
How a face becomes a match
Modern systems run a four-stage pipeline, which Facebook researchers summarised in their 2014 DeepFace paper as detect, align, represent and classify. A detector first finds the region of a frame that contains a face. An alignment step rotates and scales that region so the eyes and mouth sit in standard positions. A deep neural network then turns the aligned crop into an embedding, a list of numbers usually called a template or faceprint. Google's FaceNet, published in 2015, trained its network to output a compact 128-dimensional embedding in which the distance between two vectors directly reflects how alike two faces are. The last stage compares templates against a threshold: a similarity score above it counts as a match, one below it does not.
Two operating modes follow. Verification, or one-to-one (1:1) matching, asks whether a live face belongs to a claimed identity, as when a phone checks its owner or a banking app compares a selfie with a passport photo. Identification, or one-to-many (1:N) matching, searches a gallery of enrolled templates to find whose face has been captured. Each identity added to a gallery is another chance of a false hit.
Where the threshold is set governs two error rates. A false match, or false positive, admits the wrong person or names the wrong suspect. A false non-match, or false negative, rejects the right one. Raising the threshold reduces the first and increases the second. The US National Institute of Standards and Technology (NIST) measures that trade-off across vendors in a continuously running benchmark; developers may submit to its 1:1 and 1:N tracks once every four calendar months.
From hand-measured features to deep learning
The earliest systems were semi-automated. In the 1960s Woody Bledsoe, working with Helen Chan Wolf and Charles Bisson, had human operators mark the eyes, ears and nose on photographs, and a computer then matched those coordinates against stored images. Matthew Turk and Alex Pentland published "Face Recognition Using Eigenfaces" in 1991, representing faces as combinations of basis images derived through principal component analysis.
The deep learning turn arrived in June 2014. Facebook AI Research reported that DeepFace, trained on four million images of more than 4,000 identities, reached 97.35% accuracy on the Labeled Faces in the Wild (LFW) benchmark, cutting the previous best error rate by more than 27%. FaceNet reported 99.63% on the same dataset a year later. LFW consists largely of well-lit photographs of public figures, not surveillance footage.
Consumer deployment ran alongside the research. Facebook used facial recognition from 2010 to suggest photo tags, gave users an opt-out in 2017 and turned the feature off by default in 2019. On November 2, 2021, the company, newly renamed Meta, said it would shut the system and delete more than a billion individual templates. About 640 million daily users had opted in. Jerome Pesenti, then Meta's vice president of artificial intelligence, framed the decision as weighing benefits against concern, "especially as regulators have yet to provide clear rules".
On August 18, 2023, NIST split its long-running Face Recognition Vendor Test (FRVT) into the Face Recognition Technology Evaluation (FRTE), which covers identity matching, and the Face Analysis Technology Evaluation (FATE), which covers tasks such as age estimation and morph detection.
The legal architecture
In the European Union, the General Data Protection Regulation (GDPR) treats a facial template as biometric data when it results from specific technical processing and allows or confirms unique identification. Article 9 places such data in a special category that may not be processed without a narrow exception. Spain's data protection authority applied that test when it fined Yoti 950,000 euros in March 2026, rejecting the company's argument that a stored template matched one to one merely authenticates.
The Artificial Intelligence Act (AI Act) adds three layers. Article 5(1)(e) bans AI systems that create or expand facial recognition databases through untargeted scraping of images from the internet or CCTV footage. Article 5(1)(h) confines real-time remote biometric identification in publicly accessible spaces for law enforcement to a short list of exceptions. Both prohibitions have applied since February 2, 2025. Annex III classes remote biometric identification as high-risk but excludes verification whose sole purpose is to confirm that a person is who they claim to be. Those high-risk obligations were pushed to December 2, 2027 in the May 2026 Digital Omnibus agreement.
The United States has no federal equivalent as of September 2026. Illinois enacted the Biometric Information Privacy Act (BIPA) in 2008, with statutory damages of $1,000 per violation and $5,000 where a violation is intentional or reckless, plus a private right of action. Texas relies on its Capture or Use of Biometric Identifier Act (CUBI), under which the state attorney general announced a $1.4 billion settlement with Meta on July 30, 2024, over the tag suggestions feature, payable over five years.
Why the marketing community pays attention
Advertising meets facial recognition in three places. First, fraud. Scammers paste celebrities' faces into investment adverts, and on October 21, 2024, Meta began testing a system that compares faces in suspected scam ads with the public figure's Facebook and Instagram profile pictures, stating that facial data from each one-time comparison is deleted immediately. Meta later said the technique more than doubled the volume of fraudulent ads detected during testing, a self-reported figure without independent audit. Meta's February 26, 2026 lawsuits against celeb-bait operators cited a protection programme covering over 500,000 public figures.
Second, measurement. TVision's in-home sensors use person and facial recognition to establish who is in the room and whether eyes are on the screen, data behind a February 2026 Video Advertising Bureau (VAB) report on connected TV. The same hardware underpins one of the passive methods for counting co-viewing.
Third, data governance. The Federal Trade Commission alleged on March 30, 2026, that OkCupid handed nearly three million user photos to a facial recognition developer, contrary to its own privacy policy. Biometric sign-up flows draw similar scrutiny, as the noyb complaint against Ryanair over mandatory facial verification for new accounts showed in December 2024.
Limitations, criticism and open disputes
Accuracy is uneven. NIST's demographic effects report of December 19, 2019, tested nearly 200 algorithms from close to 100 developers and found that false positive rates in one-to-one matching for Asian and African American faces were often 10 to 100 times those for white faces, depending on the algorithm. Patrick Grother, the lead author, said the team found "empirical evidence for the existence of demographic differentials" in most algorithms studied. Some algorithms developed in Asia showed no such gap, which points towards training data rather than the method itself.
Errors are costly when identification drives decisions. Angela Lipps, a Tennessee grandmother, spent five months in custody after a Clearview AI match tied her to bank fraud in North Dakota.
Clearview's database holds more than 60 billion images, and noyb filed a criminal complaint against its executives in Austria on October 28, 2025, after European fines of roughly 100 million euros went unpaid. "Facial recognition technology is extremely invasive," said Max Schrems, noyb's honorary chairman. PimEyes has operated in similar territory without a comparable European penalty; Hamburg's authority took more than five years to decide the original complaint.
The boundary between authentication and identification is disputed. After the Spanish ruling, Yoti withdrew its Digital ID app from Spanish stores from September 10, 2026 rather than offer a non-biometric route. The Hamburg data protection commissioner could not confirm active identification on Ray-Ban Meta glasses, whereas the Electronic Frontier Foundation and WIRED reported in June 2026 that the capability existed before Meta changed the software. Airports show the necessity test in practice: Spain fined operator AENA 1.8 million euros over inadequate impact assessments, after a 2024 European Data Protection Board opinion stressed passenger control over biometric data.
Not the same as
Face detection establishes only that a face is present in a frame, with no comparison against anyone.
Facial age estimation predicts an age range and identifies nobody. The UK Information Commissioner's Office accepted that estimation used purely for categorisation is not special category data, yet France's CNIL still rejected age-estimating cameras in tobacco shops as disproportionate.
Liveness detection checks that a living person, rather than a printed photo or replayed video, is in front of the camera. It protects a recognition system rather than performing the match.
Deepfake detection asks whether media is synthetic; facial recognition asks whose face appears. Meta's celeb-bait system applies the latter to ads that may contain deepfakes or edited photographs.
Recent developments
China's Cyberspace Administration set out its 2026 campaigns on April 2, 2026, including a ban on facial recognition as the sole authentication method where alternatives exist. Spain fined FC Barcelona 500,000 euros in March 2026 over an impact assessment covering facial and voice data from roughly 143,000 members. In Britain, Kent Police reported two arrests from its first live facial recognition deployment on September 11 and 12, 2026. In the United States, Lipps has filed a $10 million federal civil rights lawsuit against the City of Fargo and a former detective, reported on September 16, 2026, alleging that an uncorroborated match was treated as proof of identity.
Timeline
- 1960s: Woody Bledsoe, Helen Chan Wolf and Charles Bisson build semi-automated face matching systems
- 1991: Matthew Turk and Alex Pentland publish "Face Recognition Using Eigenfaces"
- October 3, 2008: Illinois Biometric Information Privacy Act signed into law
- 2010: Facebook begins using facial recognition to suggest photo tags
- June 2014: Facebook AI Research presents DeepFace, 97.35% on LFW
- June 2015: Google researchers present FaceNet, 99.63% on LFW
- 2017: Facebook lets users opt out of facial recognition
- 2019: Facebook turns facial recognition off by default
- December 19, 2019: NIST publishes its demographic effects report
- November 2, 2021: Meta announces shutdown of Facebook's system and deletion of more than a billion templates
- February 2022: Texas attorney general sues Meta under CUBI
- August 18, 2023: NIST splits FRVT into FRTE and FATE
- May 2024: European Data Protection Board adopts opinion on facial recognition at airports
- July 30, 2024: Texas announces $1.4 billion settlement with Meta
- August 8, 2024: EU AI Act enters into force
- October 21, 2024: Meta begins testing facial recognition against celeb-bait ads and for account recovery
- December 19, 2024: noyb files GDPR complaint against Ryanair
- February 2, 2025: AI Act prohibitions, including untargeted facial scraping, begin to apply
- July 11, 2025: CNIL rejects AI age-estimation cameras in tobacco shops
- October 28, 2025: noyb files criminal complaint against Clearview AI executives in Austria
- November 2025: Spain announces 1.8 million euro fine against AENA
- March 2026: Spain fines FC Barcelona 500,000 euros and Yoti 950,000 euros
- March 30, 2026: FTC files complaint against OkCupid over photo transfer
- April 2, 2026: China announces 2026 personal information enforcement campaigns
- September 10, 2026: Yoti withdraws its Digital ID app in Spain
- September 11-12, 2026: Kent Police conducts its first live facial recognition deployment
- September 16, 2026: Lipps lawsuit against the City of Fargo reported
- December 2, 2027: Scheduled application of AI Act high-risk obligations for biometric identification
Related PPC Land coverage
- Spain fines Yoti 950,000 euros over biometric data and consent failures - How the AEPD classified a stored template matched one to one as special category data.
- Yoti halts its Digital ID app in Spain on September 10 - The company's decision to exit rather than offer a non-biometric route.
- EU AI Act gets its first real haircut - high-risk deadlines pushed to 2027 - The Digital Omnibus deal moving Annex III biometric obligations to December 2027.
- Swedish publishers back Meta's expulsion from IAB - Includes Meta's claim that facial recognition doubled scam-ad detection in testing.
- Meta sues scam advertisers in Brazil, China and Vietnam over celeb-bait and cloaking - Litigation against operators using celebrity faces in fraudulent ads.
- VAB and TVision report: premium video beats YouTube on every CTV metric - Describes TVision's sensor stack combining facial recognition and content recognition.
- Explaining co-viewing - Passive panel methods, including facial recognition, for counting viewers.
- OkCupid gave nearly 3 million user photos to a facial recognition startup - The FTC complaint over a 2014 photo transfer.
- Ryanair faces GDPR complaint over mandatory facial recognition for new accounts - noyb's challenge to biometric verification as a condition of purchase.
- AI facial recognition locked up the wrong woman for 5 months - The Angela Lipps misidentification case.
- Criminal charges filed against Clearview AI after regulatory fines fail - noyb's escalation from administrative complaints to criminal referral.
- noyb sues Hamburg DPA as PimEyes keeps scanning faces unhindered - Enforcement gaps around a face search engine.
- Hamburg regulator finds Ray-Ban Meta glasses expose bystanders without consent - Technical teardown separating face detection from identification.
- Spain's AENA receives 1.8 million euro fine for airport facial recognition failures - Impact assessment failures in airport biometric boarding.
- Facial recognition in airports: EDPB prioritizes user control over biometric data - The May 2024 EDPB opinion on passenger biometrics.
- Explaining facial age estimation - How age estimation works and why its legal status differs.
- French data watchdog rejects AI age cameras in tobacco shops - CNIL's July 2025 position on in-store face analysis.
- Explaining liveness detection - Presentation attack detection and its relationship to recognition.
- Explaining deepfake - Synthetic media and its role in advertising fraud.
- China's 2026 privacy crackdown targets adtech, apps, and facial recognition - Enforcement campaigns restricting facial recognition as sole authentication.
- Spain fines FC Barcelona 500,000 euros for failing biometric data protection assessment - A deficient impact assessment for facial and voice data of club members.
Summary
Who: Developers such as Meta, Google, Clearview AI and TVision build or operate facial recognition; platforms, airlines, banks, police forces and measurement panels deploy it; NIST benchmarks it; data protection authorities, the European Commission, the FTC and US state attorneys general regulate it.
What: Software that converts a detected face into a numeric template and compares it with stored templates, either one to one to verify a claimed identity or one to many to identify an unknown person.
When: Semi-automated work began in the 1960s, deep learning systems arrived in 2014 and 2015, Meta shut its Facebook system in November 2021 and reintroduced narrow uses in October 2024, and AI Act prohibitions have applied since February 2, 2025.
Where: Smartphones, account recovery flows, airports, in-home TV panels, retail counters and public streets, under GDPR and the AI Act in Europe and a patchwork of state laws such as BIPA and CUBI in the United States.
Why: Faces can be captured without contact and at scale, which makes recognition useful against fraud and for measurement, and contentious because of demographic error gaps, wrongful identifications and databases built from scraped images.
Discussion