Facial recognition technology uses computer vision and artificial intelligence to analyze facial features and compare them with images or biometric templates. Today, it can be used for everything from unlocking devices and verifying identity to improving accessibility, travel, and security.
Facial recognition is also a technology that requires careful consideration. A person's face is a biometric identifier, and unlike a password, it cannot simply be changed if biometric information is compromised. Accuracy can also vary depending on the algorithm, image quality, and demographic group being evaluated. NIST continues to evaluate these differences across facial recognition systems.
For businesses, that means facial recognition should not be treated as a simple replacement for passwords or identification cards. Organizations should consider the purpose of the technology, how biometric information will be protected, who can access it, how long it will be retained, and what choices people have.
Used thoughtfully, however, facial recognition and related facial analysis technologies can support a range of useful applications.
What is facial recognition technology?
Facial recognition is a biometric technology that analyzes characteristics of a person's face to determine whether an image matches a known identity.
There are two common types of facial recognition:
- One-to-one verification: A face is compared with a specific identity to verify that a person is who they claim to be. Device authentication is one example.
- One-to-many identification: A face is compared against a database of people to determine whether there is a potential match.
Facial analysis is related but can have a different purpose. For example, technology may estimate characteristics such as age from an image without attempting to identify the person. NIST evaluates both facial recognition and facial analysis technologies.
6 ways facial recognition technology can help
1. Finding missing people
Facial recognition can help authorities compare images of unidentified people against databases containing known individuals. This can potentially assist investigations involving missing children, vulnerable adults, and unidentified people.
The technology should still be treated as an investigative tool rather than definitive proof of someone's identity. A potential facial match can require additional verification, particularly when the consequences of an incorrect match are significant.
2. Improving digital security
One of the most familiar uses of facial biometrics is authentication.
Instead of entering a password every time they access a device, users can authenticate themselves with a supported facial recognition system. Windows Hello, for example, supports biometric authentication on compatible Windows devices.
Facial authentication can be particularly useful when combined with other security controls. Organizations can use a layered approach that includes strong authentication, device security, encryption, access controls, and security monitoring.
Biometrics should not necessarily replace every other form of authentication. Businesses should select authentication methods based on the sensitivity of the information being protected and the risks associated with the environment.
3. Supporting accessibility
Facial analysis can also help people interact with technology and understand visual information.
For example, computer vision systems can analyze faces and facial expressions in images and provide descriptions or other forms of feedback. This can help make digital content more accessible to people who cannot see or interpret an image in the same way as someone with typical vision.
The broader development of AI-powered image understanding is creating additional possibilities for accessibility tools, including systems that can describe people, objects, and scenes.
4. Streamlining travel and identity verification
Facial biometrics are increasingly being used in travel and identity verification.
Airports and border agencies can use facial matching as part of identity verification processes, potentially reducing the need to repeatedly present physical documents at different checkpoints.
The benefit is convenience, but the privacy considerations are significant. Travelers should understand when facial images or biometric information are being collected, why they are being collected, and how that information is handled.
5. Creating more convenient experiences
Facial recognition and facial analysis can support personalized experiences when people knowingly choose to use them.
Potential applications include:
- Verifying a customer's identity
- Unlocking accounts or devices
- Personalizing services
- Supporting age verification
- Automating access to facilities
- Helping employees authenticate to systems
Facial analysis can also be used for purposes that do not require identifying a person. For example, age-estimation technology can potentially help determine whether someone meets an age requirement without necessarily establishing their identity. NIST continues to evaluate the accuracy and demographic performance of age-estimation algorithms.
6. Supporting healthcare and research
Researchers are exploring facial analysis for a variety of healthcare and research applications.
Computer vision can be used to analyze characteristics that may be difficult for people to measure consistently, including certain facial movements or expressions. Researchers are also investigating how facial analysis could contribute to the study of genetic conditions and other health-related characteristics.
However, healthcare applications require particular care because facial information can be highly sensitive. A system used in a medical environment should be evaluated not only for accuracy, but also for privacy, security, consent, and the potential consequences of incorrect results.
What are the privacy concerns with facial recognition?
The convenience of facial recognition comes with important privacy considerations.
Unlike a password, your face is inherently connected to you. A business that collects facial biometric information therefore needs to think carefully about how that information is collected, stored, protected, used, shared, and eventually deleted.
The Federal Trade Commission has warned businesses about risks associated with biometric information, including unexpected collection, inadequate security, misleading claims about accuracy, and insufficient evaluation of third-party providers.
Businesses considering facial recognition should ask:
- Why are we collecting this information?
- Do we actually need biometric information for this purpose?
- What notice will people receive?
- Is consent or another legal basis required?
- How will biometric information be protected?
- Who can access it?
- Will it be shared with third parties?
- How long will it be retained?
- How will people exercise applicable privacy rights?
- What happens if the technology produces an incorrect match?
Privacy and security requirements also vary by jurisdiction and by the specific application, so organizations should work with their legal and privacy teams before deploying biometric systems.
Facial recognition accuracy matters
Facial recognition is not equally accurate in every situation.
NIST's ongoing evaluations have found demographic differences in the performance of facial recognition algorithms. Image quality can also affect results. Lighting, camera positioning, exposure, and other image characteristics can influence whether a system correctly matches two images.
That makes independent testing important.
Businesses should evaluate the actual system they plan to deploy rather than assuming that every facial recognition solution performs the same way. They should also consider what happens when the system cannot confidently make a match.
For higher-risk applications, facial recognition should generally be one part of a broader identity or decision-making process rather than the sole basis for an important decision.
How businesses can use facial recognition responsibly
If your organization is considering facial recognition, start with the business problem rather than the technology.
A responsible implementation should include:
Define the purpose
Clearly document what the technology is supposed to accomplish and why facial biometrics are necessary.
Minimize the data collected
Collect only the information needed for the stated purpose and avoid retaining biometric information indefinitely.
Protect biometric information
Use appropriate technical and organizational safeguards to protect facial data from unauthorized access, disclosure, or misuse.
Be transparent
People should receive understandable information about when facial recognition is being used and how their information will be handled.
Evaluate accuracy
Test the system under realistic conditions and evaluate performance across relevant populations and environments.
Consider alternatives
For some applications, a password, security key, access card, PIN, or another authentication method may accomplish the same goal with less biometric data collection.
Monitor the system
Technology and risks change over time. Continue evaluating accuracy, security, privacy practices, and third-party providers after deployment.
The future of facial recognition
Facial recognition is becoming part of a much larger ecosystem of biometric authentication, computer vision, and AI-powered analysis.
The most useful applications may not always involve identifying someone. Facial technologies can also help verify identity, improve accessibility, estimate characteristics such as age, and support more convenient interactions with digital and physical environments.
At the same time, the technology's ability to identify people creates responsibilities for organizations that deploy it. Privacy, security, accuracy, transparency, and appropriate human oversight should remain part of the conversation.
The goal isn't simply to make facial recognition more widespread. It is to make sure that when organizations use it, they have a clear purpose and understand the technology's capabilities, limitations, and potential impact.
Frequently asked questions about facial recognition
Is facial recognition the same as facial analysis?
No. Facial recognition generally involves comparing a face with another image or biometric reference to verify or identify someone. Facial analysis can involve examining characteristics of a face without necessarily identifying the person.
Is facial recognition secure?
Facial recognition can be used as part of a secure authentication system, but its security depends on how the technology is implemented. Businesses should consider spoofing protections, encryption, access controls, data retention, and the security of any vendors or systems handling biometric information.
Can facial recognition be inaccurate?
Yes. Accuracy can vary by algorithm, image quality, environment, and demographic group. NIST regularly evaluates facial recognition technologies and reports differences in error rates across demographic groups.
Can a face be used instead of a password?
In some situations, yes. Compatible devices and services can use facial biometrics as an authentication factor. However, organizations should consider the sensitivity of the account or information being protected and whether additional authentication factors are appropriate.
Should businesses use facial recognition?
Facial recognition can provide useful security, accessibility, authentication, and convenience benefits, but it is not appropriate for every business application. Organizations should evaluate the specific purpose, privacy requirements, security risks, accuracy, legal obligations, and available alternatives before deploying it.