The Gist: Ireland's Biometric Laundromat
Ireland quietly passed a law in July potentially undermining every EU citizen's protections against law enforcement use of biometrics. This is the Gist.
As readers will know, in the Garda Síochána (Recording Devices) (Amendment) Act 2026 the Irish Department of Justice is trying to drive a coach and four through the EU AI Act's limits on police surveillance. It just seems like yesterday when I wrote about this questionable legislation on using facial recognition technology on camera footage (see Humpty Dumpty's Wall of Biometric Bamboozlement).
But, in the dying days of the Dáil term, the Department brought in an astonishing set of amendments to that same piece of legislation after it had already gone through Oireachtas debate and consideration. The effect of those amendments appears to be to turn Ireland into a State-sized loophole for police and security organisations across the EU (and possibly beyond) who might want to avoid their new responsibilities under the AI Act.
Let's take a look at the text, however little attention the Department hoped we would pay to it.
Biometric Laundering on Request
A member of An Garda Síochána can only use the Act's powers to run biometric analysis on video images for specified purposes.
They're set out in the Act's new text for Section 43C(2) of the original law;
"43C.
(2) A member of Garda personnel shall not carry out biometric analysis,
other than for one or more of the following principal purposes:
(a) the prevention, investigation, detection or prosecution of arrestable
offences;
(b) the protection of the security of the State;
(c) a search for one or more missing persons;"
Or at least, that was the language the Dáil passed on 13th May 2026.
But, just before the end of the term, with Acts being passed under the guillotine (a system where debate is curtailed so the Government can pass laws in a hurry), we got an amendment to that 'purposes' section. It was introduced through the Seanad, not the Dáil. Jim O'Callaghan didn't introduce it to the Dáil, though he had introduced the previous texts on behalf of the Government. It was left to Catherine Ardagh, the new Junior Minister in the Department of Justice to bring it forward to the House.
It added a fourth purpose, in pursuit of which a member of An Garda Síochána can use the Act's powers to run biometric analysis. Let's call it Purpose (d);
"43C.
(2) A member of Garda personnel shall not carry out biometric analysis,
other than for one or more of the following principal purposes:
(a) the prevention, investigation, detection or prosecution of arrestable
offences;
(b) the protection of the security of the State;
(c) a search for one or more missing persons;
(d) without prejudice to section 43B(b), cooperation with one or more
other law enforcement agencies in relation to the prevention,
investigation, detection or prosecution of criminal offences."
"Arrestable Offences" is a specific term defined in Section 2(1) of the Criminal Law Act 1997 as being an offence for which a person may "be punished by imprisonment for a term of five years or by a more severe penalty".
While the rest of the Act (and even the same section) was careful to limit its scope to those "Arrestable Offences" (a point made by Labour TD Conor Sheehan during the debate) this last-minute addition broadened the scope out to "prevention, investigation, detection or prosecution" of any form of criminal offence, no matter how minor.
So, with a stroke of a pen, the use of biometric analysis went from being limited to serious crimes to being investigated by the Irish police, to being open to cooperation with any 'other law enforcement agency', with no minimum threshold on the criminal investigation grounds cited.
The same sort of expansion was made to Section 6 of the new law, which now read
"(6) A member of Garda personnel may only carry out biometric analysis in
order to search for—
(a) an individual who the member has reasonable grounds to suspect—
(i) of the commission of an arrestable offence, or
(ii) is a threat to the security of the State,
(b) a missing person,
(c) an individual who the member reasonably suspects is or has been a
victim of an arrestable offence, or
(d) in respect of the principal purpose referred to in subsection (2)(d)
and without prejudice to the generality of paragraphs (a) to (c)—
(i) an individual who the member has reasonable grounds to
suspect—
(I) of the commission of a criminal offence, or
(II) is a threat to the security of the State or another state,
(ii) a missing person, or
(iii) an individual who the member reasonably suspects is or has
been a victim of a criminal offence."
So while Garda personnel may run biometric analysis only for serious crimes (Arrestable Offences) when they are investigating a matter on their own, that is expanded to any and all 'criminal offences' if it is done in cooperation with any other 'law enforcement agency'.
I previously set out how this Act attempts to evade the requirements of EU law by inventing an entirely spurious distinction between 'biometric identification' (which is what the EU law defines) and 'biometric analysis', which is a wholly Irish invention and, in effect, a distinction without a difference.
The AI Act (EU Regulation 2024/1689) sets out the accepted uses and limits on the use of AI in processing data. And it sets out a special category of processes as 'High Risk' in Annex III of the regulation. And the very first of those high-risk processes?
High-risk AI systems pursuant to Article 6(2) are the AI systems listed in any of the following areas:
1. Biometrics, in so far as their use is permitted under relevant Union or national law
In particular, Recital 54 says that "Remote biometric identification systems should therefore be classified as high-risk in view of the risks that they pose."
Recital 95 sets out the problem with the use of AI on CCTV footage which the Minister's Bill proposes to introduce:
"considering the intrusive nature of post-remote biometric identification systems, the use of post-remote biometric identification systems should be subject to safeguards"
And in Article 26.10 of the AI Act the general need for prior judicial oversight as the key safeguard on this intrusive technology is set down;
"the deployer of a high-risk AI system for post-remote biometric identification shall request an authorisation, ex ante, or without undue delay and no later than 48 hours, by a judicial authority or an administrative authority whose decision is binding and subject to judicial review".
Ireland's SaaS offering: Scofflaw as a Service
During the Seanad debate, the Minister outlined what his real idea was in all of this.
By introducing this baseless carve-out from the protections given to citizens against misuse of AI by the police, he would give courts and police an excuse to avoid the judicial oversight EU law has required.
"The court and the garda will not be going to a definition of “biometric analysis” or “biometric identification” in the AI Act. For the purpose of this legislation, it is the definition of “biometric analysis” set out here.
The part of the legislation we are discussing here is called the carrying out of biometric analysis by members of the Garda Síochána. What is clear from a plain reading of this legislation, if enacted, is that it establishes a distinction between "biometric analysis" and "biometric identification".
Irrespective of what the AI Act says, here we are establishing a distinction between the two and only biometric analysis is permitted in this legislation."
With this new expansion into international cooperation, the Department of Justice's text, written as the Minister says "Irrespective of what the AI Act says", has become a hole in the entire EU's regulatory framework for law enforcement.
Any law enforcement agency that wants to avoid its domestic and EU requirements for prior judicial oversight of its use of biometrics, such as facial recognition, as a High Risk process, can simply send the footage to An Garda Síochána and have them run the uniquely unregulated 'biometric analysis' for them. The foreign law enforcement agency never ran any analysis that required prior judicial oversight, and the Irish police who did will never have to go before a court to explain their actions. The perfect loophole.
Not Invented Here
This kind of grey evidence collection is known in the US as 'witness-washing' or 'parallel construction'. Human Rights Watch and the Cato Institute issued separate reports on the dangers of this kind of evasion of judicial oversight and statutory protections. In March 2026, the Denver Law Review published an article by the Acting Assistant Professor of Lawyering in New York University School of Law entitled "Witness Washing facial recognition technology" examining the specific dangers involved in unacknowledged use of facial recognition by law enforcement agencies. He points out that;
In the twenty-four years since FRT’s first formal deployment, appellate courts have examined it in only three decisions. None of these decisions evaluated the underlying reliability of the technology. Police have used this
technology regularly for almost a quarter of a century, but FRT has fully
evaded the processes by which courts purport to evaluate the use of new
technologies in the criminal law
It seems worthwhile to note that, on one dusty day last month, Ireland opened Europe's largest witness-washing laundromat for business.