The Disconnect Between Domestic Regulation and Global Export
The core of the issue centers on a Spanish firm, Herta Security, whose advanced BioSurveillance NEXT technology has been integrated into extensive surveillance networks across India. According to reports from Investigate Europe, this software powers facial recognition cameras in major railway stations, prisons, and public spaces, monitoring millions of citizens daily.
This widespread deployment stands in sharp contrast to the regulatory environment in the company's home market. The European Union's AI Act strictly limits the use of real-time remote biometric identification systems in public spaces for law enforcement, categorizing such applications as high-risk or unacceptable. The fact that technologies restricted under the EU AI Act and these stringent domestic laws are being actively exported highlights a significant gap in international technology governance and industry standards.
For organizations developing and exporting advanced technologies, this scenario presents complex challenges. Navigating differing international regulations while maintaining ethical standards requires more than simply adhering to local laws; it demands a comprehensive approach to AI governance compliance, AI risk management, and AI strategies throughout the AI life cycle.
The deployment of over 4,000 cameras utilizing European software in a region lacking equivalent data protection safeguards raises critical questions about accountability, privacy risks, contractual obligations, and the ethical implications of technology transfer. When developing systems intended to be AI embedded in products, companies must consider the downstream impacts of their technologies across varying jurisdictions. This includes real-world context testing, agency-defined test plans, and independent evaluation plans before production AI systems are released. The responsibility does not end at the border, making proactive governance and rigorous risk controls essential.
To mitigate risks and build international trust, organizations must integrate accountability into their operational DNA. This involves moving beyond basic regulatory adherence and implementing comprehensive management systems that address potential vulnerabilities before they manifest. An AI oversight committee can help establish operational control, while a compliance leader or chief data officer can align AI solutions with enterprise risk tolerance and existing data governance.
Adhering to recognized international frameworks, such as ISO/IEC 27701 for privacy information management, provides a structured foundation for protecting personal data globally. Furthermore, as new regulations emerge worldwide, understanding and preparing for compliance frameworks like the EU Digital Services Act helps companies anticipate and adapt to evolving digital accountability standards. Organizations should also establish an AI compliance plan with continuous monitoring, ongoing performance monitoring, and clear expectations for robustness.
The goal is to ensure that AI in products is developed with a clear understanding of its potential societal impact, regardless of where it is ultimately deployed. By prioritizing ethical considerations and aligning with global best practices, organizations can transform regulatory challenges into strategic advantages, support broader enterprise adoption, and build well-governed AI on a foundation of well-governed data.
As artificial intelligence and biometric technologies continue to advance, the scrutiny surrounding their global distribution will only intensify. The current disparity between the EU's protective stance on facial recognition and the widespread use of European technology abroad serves as a critical indicator of the work that remains in establishing unified global standards.
Organizations must take proactive steps to ensure their operations reflect a commitment to responsible innovation. Achieving consistent AI governance compliance requires a dedicated focus on transparency, ethical design, embedded safety, and the implementation of rigorous international standards. A layered governance framework - potentially including an AI governance board, an edge board, and defined runtime policy enforcement - can help organizations manage risks from development through deployment. By doing so, companies not only protect themselves from regulatory and reputational risks but also contribute to a safer, more accountable digital world. For further guidance on international data protection expectations, resources from the European Data Protection Board offer valuable insights into maintaining high standards across borders.