Biometric Identification
The AI Act requires that, for remote biometric identification systems, no action be taken on the basis of an identification unless it has been separately verified and confirmed by at least two qualified individuals (Art. 14(5)), with both identities recorded (Art. 12(3)(d)). But a formal "two confirmations" requirement alone does not guarantee that the two confirmations were substantially distinct, nor that they concerned the same identical biometric result.
- The internal log shows two names, but no record distinguishes whether the two confirmations occurred separately or whether the second simply ratified the first
- No way to establish, months later, which input generated the originally confirmed match, or which system version produced it
- The authority declared by the two verifiers exists only in internal systems - no external anchoring supports it
- It cannot be established whether the two confirmations actually examined the same output, or two different readings of the same case
- Each confirmation carries an externally anchored declared identity and role, with distinct timestamps for the first and second verification
- The input that generated the match (matched_artefact_reference), the verified biometric output, and the system version remain anchored in the same record - not reconstructed after the fact
- The information basis declared by each verifier (review_basis) remains distinguishable: direct consultation of the reference database, pre-compiled summary, or a shared report with the first confirmation already visible
- The array structure of confirmations makes structural differences immediately examinable - a single confirmation, or more than two, remain visible as such instead of being absorbed into a fixed-field format
- 1 Are the two identities associated with the verification distinguishable, with separate timestamps?
- 2 What authority or declared role did each verifier hold at the moment of confirmation?
- 3 Did both confirmations concern the same identical biometric output, or distinct outputs?
- 4 Which input generated the match submitted for verification?
- 5 Are the two confirmations independent, or did the second depend on the first (same source, same moment, same channel)?
- 6 Which information basis (review_basis - illustrative values: direct database consultation, pre-compiled summary, shared report; not a closed list) did each verifier declare having consulted?
- 7 Which elements of the dual verification remain unverifiable with the available data?
Article 14(5) requires two qualified individuals to confirm a biometric identification, with both identities recorded under Article 12(3)(d). A recorded identity is not the same as a verified one - an internal user ID or a typed name in a review form declare who acted, but do not confirm it. Each confirmation in the record above carries its own DAPI-verified identity - closing the gap between "two people confirmed" and "we know who they actually were".
DAPI Identity Certification ↑EVIDE does not determine whether the underlying decision was correct, whether applicable procedures were followed, or whether the outcome was legally justified. It documents the evidentiary conditions that remain independently examinable after the event.
declared_as_independent: true is a declaration by the verifier or the system recording it - not an EVIDE certification that the independence was substantial. A structurally complete EVIDE record does not exclude the possibility that the two confirmations were produced by an interface that shows the second verifier the outcome of the first, or by a workflow that generates semi-automatic approvals: EVIDE documents what was declared independent, it does not verify the absence of conditioning in the interface that collected the declaration.