Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy prohibits using OpenAI services for real-time remote biometric identification in public spaces, building facial recognition databases without data subject consent, and evaluating or classifying individuals based on biometric data, social behavior, or personal traits including social scoring and profiling.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a categorical prohibition on a class of AI applications that regulatory frameworks including the EU AI Act designate as prohibited practices, creating a policy-level alignment with regulatory requirements that API customers and developers must independently satisfy under applicable law.
This provision establishes that OpenAI services may not be used to build systems that identify individuals in public spaces via biometrics in real time, create facial recognition databases, or score or profile individuals based on personal traits or social behavior without their authorization.
Cross-platform context
See how other platforms handle Prohibition on Real-Time Remote Biometric Identification in Public Spaces and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Respect privacy. People are entitled to privacy. So, we don't allow attempts to compromise the privacy of others, including to aggregate, monitor, profile, or distribute individuals' private or sensitive information without their authorization. And, you may never use our services for: facial recognition databases without data subject consent real-time remote biometric identification in public spaces use of someone's likeness, including their photorealistic image or voice, without their consent in ways that could confuse authenticity evaluation or classification of individuals based on their social behavior, personal traits, or biometric data (including social scoring, profiling, or inferring sensitive attributes)Excerpt from OpenAI's Usage Policies
(1) REGULATORY LANDSCAPE: This provision directly engages the EU AI Act's list of prohibited AI practices, which includes real-time remote biometric identification in publicly accessible spaces and AI systems used for social scoring by public authorities. It also engages GDPR provisions on processing biometric data as a special category, requiring explicit consent or another lawful basis. The relevant enforcement authorities include the EU AI Office, national data protection authorities in EU member states, and the European Data Protection Board. The policy commitment does not substitute for operator-level compliance obligations under these frameworks. (2) GOVERNANCE EXPOSURE: High. Developers or enterprise customers building applications that involve any biometric data processing, public-space identification, or individual scoring mechanisms must ensure their specific use cases fall outside this prohibition. The prohibition on 'inferring sensitive attributes' from biometric data is broadly worded and may require case-by-case legal assessment for applications involving any biometric or behavioral signal. (3) JURISDICTION FLAGS: EU and EEA customers face heightened exposure given the alignment of this prohibition with EU AI Act prohibited practices and GDPR special category data obligations. Illinois (BIPA) and Texas create additional state-level biometric privacy obligations for US-based operators. Applications involving employee monitoring or educational settings are specifically addressed by the emotion inference carve-out, creating distinct compliance considerations in those contexts. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers incorporating OpenAI services into products that process biometric data should assess whether their vendor agreements with OpenAI and their own downstream contracts adequately allocate responsibility for compliance with this provision. The policy does not specify audit rights or verification mechanisms, meaning compliance with this prohibition is asserted contractually but not operationally verified in terms disclosed here. (5) COMPLIANCE CONSIDERATIONS: Legal teams should map all use cases involving biometric, behavioral, or social data against this prohibition before deployment. For EU-based or EU-serving applications, a Data Protection Impact Assessment may be required under GDPR for biometric data processing regardless of this policy's terms. Consent mechanisms for any likeness or voice use should be documented and auditable.
This provision establishes a categorical prohibition on a class of AI applications that regulatory frameworks including the EU AI Act designate as prohibited practices, creating a policy-level alignment with regulatory requirements that API customers and developers must independently satisfy under applicable law.
This provision establishes that OpenAI services may not be used to build systems that identify individuals in public spaces via biometrics in real time, create facial recognition databases, or score or profile individuals based on personal traits or social behavior without their authorization.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.