EU-Funded Facial Recognition Technology Operating Illegally Across 4,000 Indian Cameras
A Barcelona-based company that received over €3.3 million in EU research grants is operating facial recognition technology across India that would be illegal if deployed in Europe, according to a joint investigation by Investigate Europe, India's Reporters' Collective, and Tech Policy Press. The discovery exposes a critical gap in how the EU regulates artificial intelligence exports, allowing companies to deploy systems abroad that domestic law explicitly forbids.
What Is Herta Security Doing in India?
Herta Security, founded in Barcelona in 2009, has deployed its BioSurveillance NEXT facial recognition system across an estimated 4,000 cameras in Indian railway stations, prison complexes, pilgrimage sites, and city surveillance systems. At Howrah station in Kolkata alone, roughly 100 cameras scan faces of more than one million daily commuters and cross-check them against a database of approximately one million flagged individuals. When the system identifies a match, it dispatches an alert to armed railway police with the subject's exact location.
The technology processes faces at remarkable speed. One of Herta's Indian business partners described the throughput at busy stations: a single camera can process 10,000 people in five minutes. The system lifts each face from a live video feed, converts it to a numerical embedding using convolutional neural network models, and compares it against a watchlist database within milliseconds.
Four legal scholars specializing in EU artificial intelligence and biometrics law told investigators that at least two of these Indian deployments would violate European law if operated on EU soil. The prohibition they cited has been in force since February 2, 2025, under the EU AI Act, which bans real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, with only three narrow exceptions.
How Did EU Research Funding Enable a Banned Technology?
The regulatory gap that allowed this outcome is structural and revealing. Herta's largest EU grant, €2.36 million running from 2022 to 2024 under a project called FUTURE, was specifically designed to perform crowd behavior analysis and identify people in "large gatherings, public events, and high-traffic areas" for law enforcement purposes. That is precisely the use case the EU AI Act has prohibited on European soil.
When investigators asked Herta about this apparent contradiction, the company responded that EU research funding does not "finance, operate or subsidize specific commercial deployments in India or elsewhere," and that research knowledge "may contribute to the general evolution of our expertise, methodologies and product roadmap". The European Commission did not respond to requests for comment before the investigation was published.
The EU AI Act governs systems placed on the EU market or put into service in the EU, but it does not prohibit EU companies from exporting systems that would be illegal at home. The EU's Dual-Use Regulation controls exports of some surveillance technologies, but facial recognition software as a category is not currently on the dual-use control list, according to a December 2025 report from the Center for Democracy and Technology Europe. A Human Rights Watch report published in May 2026 documented the broader pattern: EU companies are exporting surveillance tools to rights-violating jurisdictions, and the regulatory framework has not caught up.
What Are the Accuracy and Bias Concerns?
The accuracy threshold for these systems matters significantly for real-world consequences. Delhi Police stated in 2022 that they treat facial recognition matches at 80 percent similarity as positive identifications, the trigger for dispatching armed officers. Applied across millions of daily travelers against a watchlist of one million, even a modest false positive rate translates to large numbers of wrongful police stops, with no public record of incidents and no legal route for a misidentified person to seek redress.
There is an additional complication involving algorithmic bias. A former senior Herta researcher, speaking anonymously to investigators, said that data acquired through early Indian deployments beginning around 2014 was central to overcoming the algorithm's poor performance on non-white faces. Research going back years has documented that facial recognition systems trained primarily on lighter-skinned populations show error rates up to seven times higher for darker-skinned individuals. India's deployment environment, with millions of South Asian faces processed daily, may have served as the training data that made the system's global performance on darker skin viable. Herta denied using operational customer data to improve its algorithms as a "default mechanism" but did not exclude the possibility where a "clear legal basis" exists, the investigation reported.
How Is This Technology Funded and Justified?
The Eastern Railway contract was won in 2022 by a Delhi-based partner for €11.5 million. Eastern Railway announced in early 2025 that 540 facial recognition systems were operational at 143 stations, with the full program covering 392 stations. One of Herta's local partners told investigators the system could eventually extend to more than 1,500 cameras.
Herta also operates across three of Delhi's prison complexes, Tihar, Mandoli, and Rohini, under a government contract reportedly worth 352 million rupees, or approximately €3.2 million. The Ram Mandir pilgrimage site in Ayodhya runs similar systems, and Herta's own marketing materials state that 140 facial recognition cameras were deployed as part of Ahmedabad's safe-city program.
Part of this infrastructure was built with money from the Nirbhaya Fund, a pot of public resources created in 2013 after the gang rape and murder of a young woman on a Delhi bus sparked mass protests. By March 2025, approximately 58 billion rupees, around €532 million, had been disbursed from the fund. Indian government data released in February 2024 showed that roughly 50 percent of disbursements went to surveillance and policing functions, versus 31 percent for direct victim support services and emergency helplines.
Steps to Understand the Regulatory Gaps in AI Export Controls
- Domestic vs. Export Standards: The EU AI Act prohibits real-time facial recognition for law enforcement in public spaces within Europe, but contains no mechanism to prevent EU companies from exporting identical systems to other countries where such restrictions do not exist.
- Dual-Use Regulation Limitations: While the EU maintains a dual-use control list for certain surveillance technologies, facial recognition software is not currently included, leaving a significant regulatory blind spot for companies like Herta Security.
- Research-to-Deployment Pipeline: EU research grants fund development of technologies that are later commercialized in jurisdictions with weaker privacy protections, creating a pathway from public funding to controversial deployment with minimal oversight or accountability.
- Algorithmic Bias in Global Deployment: Systems developed and trained in one region may be deployed globally without adequate testing for bias across different populations, potentially amplifying discrimination in countries with less regulatory scrutiny.
Has This Surveillance Actually Reduced Violence?
The surveillance investment has not measurably reduced violence against women, the stated justification for the Nirbhaya Fund. In 2014, the year after the fund was established, India recorded 340,000 crimes against women, according to the National Crime Records Bureau. By 2023, the most recent year with available data, that figure had risen to approximately 450,000.
Flavia Agnes, a Mumbai-based lawyer who estimates she has worked on roughly 100,000 cases of violence against women over a 40-year career, told investigators she has never encountered a case in which railway-style surveillance helped identify an abuser. "About 95 percent of the rape cases take place by known people," she said, primarily in domestic settings where public cameras are irrelevant. Audrey D'Mello, who runs a Mumbai legal aid center for survivors of violence, drew a more critical conclusion about the mismatch between the surveillance infrastructure and the actual nature of violence against women.
This case illustrates a fundamental tension in AI governance: the EU has created strict rules for its own market, but lacks the regulatory tools to prevent companies from exporting systems that embody the same risks the domestic rules were designed to prevent. As AI systems become increasingly global, this gap between domestic regulation and export policy may become one of the most consequential regulatory failures of the AI era.