Logo
FrontierNews.ai

EU-Funded Facial Recognition System Deployed Across 4,000 Indian Cameras Violates Europe's Own AI Ban

A European company funded by EU research grants is operating facial recognition systems across India that would violate the EU's own artificial intelligence law if deployed at home. Herta Security, founded in Barcelona in 2009, has received more than €3.3 million in EU research funding since 2020. Yet the company's facial recognition technology now runs on approximately 4,000 cameras across Indian railway stations, prisons, pilgrimage sites, and city surveillance systems, according to a joint investigation by Investigate Europe, India's Reporters' Collective, and Tech Policy Press published on July 15, 2026.

The core issue is stark: the EU AI Act has banned real-time remote biometric identification in publicly accessible spaces for law enforcement purposes since February 2, 2025. Four legal scholars specializing in EU artificial intelligence and biometrics law told investigators that at least two of Herta's Indian deployments would violate European law if operated on EU soil. Yet because the EU AI Act only governs systems placed on the EU market or put into service in the EU, there is no legal mechanism to prevent European companies from exporting systems that would be illegal at home.

How Did EU-Funded Research Become an Illegal Export?

Herta's largest EU grant, worth €2.36 million and running from 2022 to 2024 under a project called FUTURE, was explicitly designed to perform crowd behavior analysis and identify people in "large gatherings, public events, and high-traffic areas" for law enforcement purposes. A project page, since removed but preserved in web archives, described the facial recognition component as a tool for law enforcement "to swiftly and accurately identify suspects and terrorists." That is precisely the use case the EU AI Act has prohibited on European soil.

When investigators asked Herta about the apparent contradiction, the company responded that EU research funding does not "finance, operate or subsidize specific commercial deployments in India or elsewhere," and that research knowledge "may contribute to the general evolution of our expertise, methodologies and product roadmap." The European Commission did not respond to requests for comment before the investigation was published.

The gap that allowed this outcome is structural. The EU's Dual-Use Regulation controls exports of some surveillance technologies, but facial recognition software as a category is not currently on the dual-use control list, according to a December 2025 report from the Center for Democracy and Technology (CDT) Europe. A Human Rights Watch report published in May 2026 documented the broader pattern: EU companies are exporting surveillance tools to rights-violating jurisdictions, and the regulatory framework has not caught up.

What Does Herta's Facial Recognition System Actually Do?

Herta's flagship product, BioSurveillance NEXT, runs on graphics processing units (GPUs), the same chips that power most current artificial intelligence systems. The system lifts each face from a live video feed, converts it to a numerical embedding using convolutional neural network models, and compares it against a watchlist database within milliseconds. One of Herta's Indian business partners described the throughput at a busy station: a single camera can process 10,000 people in five minutes.

At Howrah station in Kolkata, where more than one million commuters pass through every day, roughly 100 cameras scan each face and cross-check it against a database of approximately one million people flagged by Indian railway authorities as persons of interest. A match dispatches an alert to armed railway police with the subject's exact location. Most travelers are unaware the system exists.

The accuracy threshold matters significantly. Delhi Police stated in 2022 that they treat facial recognition matches at 80 percent similarity as positive identifications, the trigger for dispatching armed officers. Applied across millions of daily travelers against a watchlist of one million, even a modest false positive rate translates to large numbers of wrongful police stops, with no public record of incidents and no legal route for a misidentified person to seek redress.

Steps to Understand the Broader Regulatory Problem

  • Export Gap: The EU AI Act governs systems placed on the EU market or put into service in the EU, but does not prohibit EU companies from exporting systems that would be illegal at home, creating a regulatory blind spot.
  • Dual-Use Loophole: Facial recognition software as a category is not currently on the EU's dual-use control list, meaning surveillance technology can be exported without triggering export control mechanisms.
  • Training Data Concern: A former senior Herta researcher told investigators that data acquired through early Indian deployments beginning around 2014 was central to overcoming the algorithm's poor performance on non-white faces, raising questions about whether operational customer data improved the system's global performance.

Why Is This Happening Now, and What Does It Signal About EU Regulation?

The timing is particularly revealing. The EU AI Act has been in force for only 17 months, yet the European Commission is already modifying parts of its implementation framework through a "Digital Omnibus on AI" agreement. The omnibus delays certain obligations for high-risk systems, simplifies requirements for smaller companies, clarifies overlaps with sectoral legislation, and expands access to regulatory sandboxes.

This rapid simplification reflects a deeper tension in European AI regulation. When the AI Act was adopted, Europe positioned itself as the first major jurisdiction attempting comprehensive horizontal regulation of artificial intelligence. The legislation was widely presented as the global benchmark for "trustworthy AI," risk-based and rights-oriented. Yet less than two years later, the EU is already modifying implementation timelines and requirements.

The problem is operational reality. The AI landscape evolved dramatically between the moment policymakers first drafted the legislation and the moment companies actually began preparing for implementation. Generative AI systems expanded at extraordinary speed, foundation models rapidly reshaped commercial deployment patterns, and businesses suddenly found themselves attempting to interpret compliance obligations for technologies that barely existed when the original negotiations began. Many companies, particularly small and medium-sized enterprises (SMEs) and mid-sized firms, struggled not necessarily with the principle of AI governance, but with the cumulative complexity emerging around documentation, risk classification, transparency obligations, human oversight requirements, cybersecurity expectations, and interactions with existing sector-specific regulation.

The Herta case illustrates a different but equally serious problem: the EU's regulatory framework is strong within its borders but has no mechanism to govern the export of prohibited technologies. As one analysis noted, the irony is that the AI Act was originally intended partly as a competitiveness tool. European policymakers hoped that regulatory clarity would create trust, encourage adoption, and position Europe as the leading jurisdiction for safe and reliable AI deployment. Instead, parts of the debate have increasingly shifted toward concerns that Europe risks building the world's most sophisticated compliance framework around technologies largely developed elsewhere.

The case also raises uncomfortable questions about the relationship between EU research funding and global surveillance infrastructure. If EU grants funded research that produced technology now banned in Europe, what responsibility does the European Commission bear for its deployment abroad? And if the technology was improved using data from Indian deployments, does that create an ethical obligation to regulate its export? These questions remain unanswered as Herta continues to expand its operations across India's surveillance network.