Facial recognition technology is growing exponentially – in Australia and around the world. Yet, our laws were never drafted with this reality in mind.

In September 2022, the Human Technology Institute published a world-leading report, outlining a Model Law for facial recognition. This report responds to growing calls for reform from leading voices in civil society, the private sector, government and academic experts. Our law should protect against harmful uses of facial recognition, while also fostering innovation for public benefit.

Many of us will have experienced facial recognition unlocking a smartphone, organising photos of friends and family, in home security systems, at passport control, and in monitoring and surveillance by employers and law enforcement. While facial recognition is primarily used to identify an individual or to verify that they are who they claim to be, it is increasingly being used also to assess characteristics, such as a person’s age, gender or even emotions.

This report recommends reform to modernise our law, especially to address threats to Australians’ privacy and other human rights. It takes a risk-based legislative approach grounded in international human rights law. This also means that the reform principles set out in this report are applicable to other, comparable jurisdictions.

Australia needs a dedicated facial recognition law. This report urges the Federal Attorney-General to lead this pressing and important reform process.

In February 2023, the Federal Attorney-General’s Privacy Act Review report referred positively to HTI’s Facial Recognition Model Law as a way of striking the right balance, endorsing, in principle, a risk assessment approach to regulating facial recognition and other biometric technologies.

In its submission to the Attorney-General’s consultation on the Privacy Act Review report, HTI again calls for immediate action on dedicated regulation for facial recognition technology.

Facial recognition technology: Towards a model law

Read our media releaseNew report offers blueprint for regulation of facial recognition technology

Learn more about the process for researching and developing the model law.

l4u2lBJo2f8

Transcript

Australia currently has no laws in relation to facial recognition technology, despite the impact that such technology can have.

The risk of irresponsible use is probably greatest in the law enforcement realm. This is where irresponsible use of this technology really can impact on rights and freedoms of people, and what we know is often it disproportionately impacts on people of colour, women and people with disabilities.

Facial recognition technology is increasing exponentially. A lot of people know about facial recognition being used in their phones to unlock their devices, but it's also being used in much more hidden ways. Police are starting to use facial recognition to identify criminal suspects. Sometimes it's being used in recruitment or employment, and it's even being used by banks and other shops to identify people who might be doing the wrong thing.

As a human rights lawyer, I can see the really exciting potential for facial recognition to make our community more inclusive, but at the moment it's subject to quite significant rates of error. We need to be really clear on how to address that problem, as well as the problem that we do not want to become a society that is essentially one where there's mass surveillance.

We brought together a very diverse group of experts to advise us on the key elements of a model law. By gathering together those diverse views, we're able to really sense-test some of the work that we've been doing over the last six to nine months, and that gives us a much stronger sense of confidence that we're able to come up with a really robust proposal for a model law.

We commissioned some qualitative research to understand Australians' views on different uses of facial recognition technology. In designing our interactive facial recognition tool, we wanted to come up with four different scenarios which would reflect potential real-world cases where people might engage with facial recognition.

For scenario one, we used the example of entering a building with your face. For scenario two, we simulated the situation of verifying your identity to get a home loan application. For scenario three, we wanted to reflect a higher risk scenario: the use of one-to-many facial identification in an airport security setting. For scenario four, we came up with a fairly extreme risk example of facial recognition in the form of facial analysis, whereby security or police would actually use analysis technologies to assess people's level of aggressiveness in a public space, such as a stadium or a large event, and then use that assessment to decide whether or not to remove you from the venue.

Exposing people to different types of facial recognition through the simulation tool really allowed people to have a much more nuanced and sophisticated conversation around the different levels of concern, and also the protections that they wanted to see for different uses of facial recognition technology.

I questioned whether or not it made an accurate judgement of me based on my appearance.

A few of the really interesting findings around this were, first of all, that people do change their attitudes to facial recognition when they are exposed to how it affects them personally.

Once people feel what it's like to have a credit card application rejected, or be denied boarding to a plane, or even be judged as aggressive in a stadium—which are the kind of scenarios that the Face Value installation presents—they do start to reflect individually and with each other about what kind of rules should be there to protect their rights.

This is technology that we know has benefit. We want it to be able to flourish. We just want it to be done so in a way that is responsible and in a way that means that people's rights are protected.

We're keen to see that it gets taken up and used as an input into policymaking. In fact, we're incredibly pleased that that's already the case. We're deeply engaged at the federal, state and territory levels as we're producing this model law.

People in Australia want facial recognition technology to help make their lives more convenient, to make their community more inclusive—particularly for people with disability—but they also want to make sure that they are protected from harmful uses of facial recognition.

Our law has a crucial role to play in setting that framework, to setting the guardrails that make sure that we're able to have the future that we want and need using facial recognition, and not a dystopian future that we fear.