Biometric Privacy Compliance for AI Physical Security: The 2026 Standards Briefing on BIPA, CUBI, MHMDA, and the State Patchwork Reshaping Vendor Selection
How BIPA, Texas CUBI, Washington MHMDA, and the comprehensive privacy law wave are reshaping vendor selection for security directors, procurement teams, and general counsel.
Biometric Privacy Compliance In Three Numbers
Biometric privacy compliance for AI physical security has become a procurement gate, not an afterthought. A patchwork of state laws now treats fingerprints, voiceprints, retina patterns, and facial geometry as a regulated data class with private rights of action, statutory damages, and AG enforcement reaching into the billions. The Texas Attorney General's $1.4 billion settlement with Meta Platforms in July 2024 under the Capture or Use of Biometric Identifier Act (CUBI) put every general counsel on notice: biometric collection without compliant consent now carries existential financial risk, and the buyer of an AI security system inherits a meaningful share of that risk.
This report is a primary-source-grounded briefing on the biometric privacy regulatory landscape for U.S. physical security buyers. It maps the state-law categories that govern biometric processing, walks through the litigation reality of Illinois BIPA, distinguishes the narrow technical scope of "biometric identifier" from the broader marketing label of "biometric AI," and offers a compliance architecture for security directors evaluating computer-vision systems. Knowing the difference between a vendor that collects biometrics and one that operates upstream of the biometric question is now a buying-calculus variable.
Why Biometric Privacy Is Now A Procurement Variable, Not A Legal Footnote
For two decades, biometric privacy in the United States sat in an enforcement vacuum. That equilibrium collapsed in 2019 when the Illinois Supreme Court ruled in Rosenbach v. Six Flags Entertainment Corp. that a plaintiff need not allege actual harm to bring suit under the Illinois Biometric Information Privacy Act (BIPA). The decision unlocked a wave of class-action litigation that has since produced a $650 million Facebook settlement, a Rogers v. BNSF Railway jury verdict of $228 million, and the Cothron v. White Castle ruling that each individual biometric scan constitutes a separate, actionable violation.
The state-level legislative response accelerated in parallel. Texas's CUBI statute, dormant for years, became the basis of the Texas Attorney General's $1.4 billion 2024 settlement with Meta. Washington enacted the My Health My Data Act, effective for most regulated entities on March 31, 2024. Colorado, Virginia, Connecticut, Oregon, and Texas's HB 4 added biometric data as a "sensitive data" category under their comprehensive privacy laws, generally requiring opt-in consent before processing.
For physical security buyers, the practical effect is that a single deployment decision can expose an organization to private class-action exposure in Illinois, AG enforcement in Texas, regulatory inquiry in California or Washington, and contract-clawback risk under federal procurement law. Compliance is no longer a checkbox handled by legal post-installation. It is now part of the technical evaluation that decides whether a system can be installed at all.
Illinois BIPA: The Statute Every National Security Program Has To Plan Around
The Illinois Biometric Information Privacy Act is the most consequential biometric privacy law in the United States, and Illinois jurisdictional reach now drives compliance design for every multi-site security program. Enacted in 2008 as 740 ILCS 14, BIPA was the first U.S. statute to impose specific procedural duties on the collection of biometric identifiers and to grant a private right of action against violators. The drafters chose statutory damages over an actual-harm requirement: a plaintiff who proves a technical violation can recover $1,000 per negligent violation or $5,000 per intentional or reckless violation without showing financial injury.
BIPA imposes five core duties on any private entity that collects a biometric identifier from an Illinois resident: develop a publicly available written policy with a retention schedule and destruction guidelines; inform the subject in writing of the specific purpose and length of the storage and use before collection; receive a written release; not sell, lease, trade, or otherwise profit from the data; and protect the data with reasonable care.
The Cothron ruling in February 2023 made compliance economics severe. The Illinois Supreme Court held that the statute's per-violation damages accrue each time a person's biometric is scanned or transmitted. For a warehouse with 500 employees clocking in twice a day for five years, theoretical maximum exposure ran into the billions before the General Assembly intervened. Public Act 103-0769, signed August 2, 2024, capped per-person recovery at a single award for repeated collections from the same biometric identifier, but it did not repeal the underlying duties or the private right of action.
The structural lesson is that BIPA's exposure is bound to collection. A system that never collects a biometric identifier in the statutory sense produces no Section 15 duties and no actionable scans under Cothron. That is the architecture argument behind the move toward computer-vision systems that detect objects, behaviors, and events rather than people. The privacy moat is a procurement moat.
Texas CUBI: AG Enforcement, No Private Action, And A $1.4 Billion Reset
Texas regulates biometric capture under the Capture or Use of Biometric Identifier Act, codified at Texas Business and Commerce Code Section 503.001, and the law sat largely dormant from its 2009 enactment until 2024. CUBI prohibits capture of a biometric identifier for a commercial purpose unless the person is informed before capture and consents, and it bars sale, lease, or disclosure without consent or specific statutory exceptions. Unlike BIPA, CUBI has no private right of action; enforcement is reserved to the Texas Attorney General with civil penalties up to $25,000 per violation.
The Texas AG's July 2024 settlement with Meta Platforms reset the enforcement calculus. The state alleged that Meta captured facial geometry from photos uploaded to Facebook over more than a decade without statutorily compliant notice and consent. The $1.4 billion settlement established that CUBI's commercial-capture prohibition can reach billions when the violation is widespread. A subsequent settlement with Google in May 2025 over similar allegations brought another $1.375 billion.
The CUBI definition mirrors BIPA's. Object detection on existing camera infrastructure is outside that definition when no measurable physiological characteristic of a particular individual is extracted and matched. For Texas-headquartered enterprises and multi-state operators with Texas facilities, the architecture decision drives the exposure profile: vendors that route detection through facial templates inherit CUBI duties on every Texas frame, while vendors that detect objects and events do not.
The Four-Tier State Landscape: Where The Compliance Bar Actually Sits
The fastest way for a security buyer to read the state landscape is by enforcement architecture, not by chronology of enactment. Four functional tiers organize the patchwork, and each tier carries a distinct compliance economics for an AI physical security deployment.
The Four-Tier State Biometric Privacy Landscape
Enforcement architecture and exposure profile by tier, Q2 2026.
Of Action
Illinois (BIPA, 740 ILCS 14). Strict written-consent regime, statutory damages of $1,000 negligent / $5,000 intentional per violation, class-action enabled.
Vendor risk: Every Illinois face-template scan is an actionable event. Object detection without template extraction sits outside the statute.
Statute
Texas (CUBI, Bus. & Com. Code §503.001), Washington (RCW 19.375). AG-enforced, civil penalties to $25K/violation, no private suit.
Vendor risk: AG-driven, episodic, but high-magnitude when triggered. Meta CUBI settlement: $1.4B.
Privacy Law
California (CPRA), Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Oregon, Texas DPSA, Montana, Tennessee, others. Biometric classified as "sensitive data."
Vendor risk: Opt-in consent typically required before processing. AG enforcement, often with cure periods. Lower magnitude, broad reach.
Frameworks
Washington MHMDA (consumer health data, RCW 19.373), New York City Local Law 3 (biometric in commercial establishments), city-level facial recognition bans (San Francisco, Oakland, Boston, Portland OR).
Vendor risk: Localized, but increasingly cited in vendor RFP exclusions for public-sector and education deployments.
Sources: 740 ILCS 14; Tex. Bus. & Com. Code §503.001; RCW 19.375 & 19.373; CPRA §1798.140; CRS §6-1-1303; IAPP State Privacy Tracker, May 2026.
Tier 1 is unique to Illinois and remains the highest-stakes regime in the country. The private right of action means a single deficient consent form can yield a certified class running into thousands of named plaintiffs. The 2024 reform narrowed Cothron-era exposure but left the underlying duties intact, and Illinois courts continue to read the statute strictly in favor of plaintiffs.
Tier 2 is the AG-enforcement model. Texas's $1.4 billion Meta settlement and Washington's enforcement under RCW 19.375 demonstrate the reach. Enforcement is episodic but the magnitude when triggered is severe enough to drive procurement behavior.
Tier 3 represents the dominant trajectory. As of May 2026, more than 20 states have enacted comprehensive privacy laws modeled on Virginia's VCDPA architecture, classifying biometric data as "sensitive data" subject to opt-in consent or data-protection-impact-assessment requirements. The patchwork now functionally requires national-scale operators to apply the strictest applicable rule across their footprint.
Tier 4 covers sector-specific or local frameworks. Washington's My Health My Data Act captures inferences about a consumer's health from any data source, with implications for fall-detection and behavioral analytics in healthcare or senior living. New York City's Local Law 3 of 2021 mandates conspicuous notice in any "commercial establishment" that collects biometric identifier information. City-level facial recognition bans in San Francisco, Oakland, Boston, and Portland (Oregon) complete the overlay.
What Computer-Vision Outputs Actually Trigger A Biometric Statute
Most computer-vision detection outputs do not produce a biometric identifier within the meaning of the major state statutes, but vendors and buyers frequently conflate the categories in vendor diligence. The comparison table below maps common detection modalities against the statutory triggers in the four highest-stakes regimes.
| Detection Output | Illinois BIPA (740 ILCS 14) | Texas CUBI (§ 503.001) | Washington RCW 19.375 | CPRA / VCDPA / CPA |
|---|---|---|---|---|
| Facial recognition with identity match | Regulated; written consent + retention policy required | Regulated; pre-capture notice + consent required | Regulated; enrollment in a database triggers duties | Sensitive data; opt-in consent typically required |
| Object class detection (firearm, vehicle, package) | Not regulated; no biometric identifier extracted | Not regulated; no measurable personal characteristic captured | Not regulated; outside the enrollment scheme | Not "biometric data"; standard CPRA logic applies to any associated PII |
| Behavioral and pose detection (fall, fight, slip) | Generally not regulated; no template extracted | Generally not regulated; no biometric capture | Generally not regulated | Caution under WA MHMDA when inference relates to health status |
| Face geometry templating without identity | Regulated; "scan of face geometry" is enumerated | Regulated; identical statutory language | Regulated; falls within definition | Treated as sensitive biometric data in most regimes |
| License plate recognition (LPR) | Not biometric; vehicle is not a person | Not biometric | Not biometric | Personal data when linked to a registered owner; LPR-specific state laws apply |
| Anonymous person count or zone occupancy | Not regulated when no identifier is generated | Not regulated | Not regulated | Not sensitive data when no identification is performed |
The table is descriptive, not legal advice; the application of any statute to a specific deployment depends on architecture, configuration, and retention behavior. The dominant compliance risk in computer-vision physical security is the facial recognition layer, not the detection function itself. Removing that layer collapses the regulated footprint to a narrow set of edge cases. The trend in state comprehensive laws is to expand the definition of "biometric data" through regulatory rulemaking and AG guidance, which makes architectural choices that minimize biometric collection a durable hedge.
The Federal Overlay: FTC, Section 889, EU AI Act Reach, And The HIPAA Question
There is no comprehensive federal biometric privacy statute in the United States as of Q2 2026, but several federal regimes apply to AI physical security deployments in ways that shape vendor selection.
The Federal Trade Commission has used its Section 5 authority under the FTC Act to bring enforcement actions against facial recognition deployments the agency deems unfair or deceptive. The December 2023 order against Rite Aid bars the retailer from using facial recognition for surveillance for five years, mandates a comprehensive monitoring program, and requires deletion of all collected biometrics and derivative models. The order functions as a regulatory signal that the FTC reads facial recognition through a substantive fairness lens covering accuracy bias, notice quality, and risk to vulnerable populations.
Federal procurement law adds an overlay through Section 889 of the FY 2019 National Defense Authorization Act, which prohibits federal agencies from procuring covered video-surveillance equipment from Hikvision, Dahua, and other listed Chinese-origin manufacturers. GSA, DoD, and an expanding list of state procurement codes have aligned with the federal restriction, making Section 889 compliance a baseline diligence point for any deployment touching federal funds.
The EU AI Act (Regulation 2024/1689) reaches U.S. operators where their systems process data of EU residents or where outputs are used in the Union. The Act's prohibitions on real-time remote biometric identification in publicly accessible spaces and its classification of biometric categorization systems as high-risk are extraterritorial concerns for any multinational with a centralized security operations center. IntelliSee's EU AI Act compliance briefing covers that overlay.
HIPAA does not regulate physical security cameras as such, but it regulates protected health information (PHI) created, received, maintained, or transmitted by covered entities. A camera system that captures patient identity and stores it in an audit log becomes a HIPAA-relevant data flow. Systems that detect events without identifying individuals and do not retain video are typically not new creators of PHI, but the architectural detail matters and should be confirmed in a written risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A).
The Compliance Architecture: A Five-Variable Checklist For Security Buyers
The compliance question for a security buyer is not "is this vendor BIPA-compliant" but "does the system create biometric obligations at all, and if so, are those obligations operationalizable across our footprint." Five variables organize the diligence inquiry.
Variable 1: Does the system extract a biometric identifier as defined by 740 ILCS 14/10?
The statutory enumeration is short: retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Vendor documentation should answer this yes or no, in writing, with reference to the architectural component that performs (or does not perform) the extraction. "No facial recognition" is the customary shorthand but incomplete: a system that builds a face template for internal use still extracts a biometric identifier under BIPA.
Variable 2: Where is the inference processed, and where is the data retained?
Edge and cloud inference have identical compliance implications at initial capture but diverge on data flow. A system that retains raw frames in the cloud creates a continuing record that triggers retention duties. A system that performs inference and discards the raw frame within seconds typically has no retained biometric to manage.
Variable 3: What is the vendor's written retention and destruction schedule?
BIPA Section 15(a) requires a publicly available written policy with a retention schedule and destruction guidelines. A vendor that cannot produce the document should be excluded from Illinois deployments and flagged in any other jurisdiction with a parallel duty.
Variable 4: Does the contract assign liability with adequate indemnification?
Vendor contracts should address responsibility for biometric privacy compliance under the laws of each state where cameras will be installed. Indemnification should cover class-action defense and statutory damages, not merely actual damages, because the dominant exposure profile is statutory.
Variable 5: Has the vendor performed a documented privacy-by-design review?
The NIST Privacy Framework's Govern-P and Protect-P functions provide an audit-ready vocabulary. A vendor that can produce a privacy-impact assessment, a data-flow diagram, and a written explanation of the architectural choices that minimize the regulated footprint is materially easier to defend in regulator inquiry.
The combined effect of the five variables is to push the procurement team toward systems that detect what is happening rather than who is present. The shift is not a marketing preference. It is a function of where the regulators have drawn the line. IntelliSee's broader framework for AI security buyers is documented in the AI Physical Security Procurement Compliance briefing, which extends this analysis to federal contracting and Section 889 alignment.
The Litigation Reality: What The BIPA Caseload Actually Looks Like
Filing data from the Northern District of Illinois and the Cook County Chancery Division shows a sustained increase since the Rosenbach decision in 2019, with class-action complaints reaching steady-state volume in the high hundreds per year. The defendant universe spans logistics, manufacturing, retail, financial services, hospitality, and increasingly the technology sector itself.
The Facebook settlement, which received final approval in 2021 under In re Facebook Biometric Information Privacy Litigation, established that BIPA claims against a national platform with Illinois users can reach $650 million on a class basis. The Rogers v. BNSF Railway verdict in October 2022, the first BIPA case to reach a jury, returned a $228 million award on a class of approximately 45,000 drivers whose fingerprints were collected at gate kiosks. The Cothron ruling expanded the per-violation arithmetic before the August 2024 reform amendment scaled it back to a single recovery per person for repeated collections from the same identifier.
The 2024 reform reduced theoretical maximum exposure but did not change the procedural duties that drive most claims: the failure to obtain written consent, the absence of a published retention policy, and the disclosure of biometric data to third-party vendors without disclosure to the data subject. Each duty is operationalizable through architecture, contract, and posted notice. The vendor selection decision is the cheapest place in the workflow to address all three.
From Statute To Procurement: How To Operationalize The Diligence
Operationalizing biometric privacy compliance inside the procurement workflow requires three additions to the standard vendor evaluation: an architecture interrogatory, a contractual annex, and a deployment-specific privacy-impact assessment.
The architecture interrogatory is a short written instrument issued to every shortlisted vendor. It should ask, in plain language, whether the system performs facial recognition or face-geometry templating, whether it extracts any of the four enumerated biometric identifiers under BIPA, what raw data is retained and for how long, where the inference is processed, and whether the vendor maintains a publicly available retention and destruction policy. Vendors that cannot answer in writing should be excluded from Illinois-touching deployments and flagged in any other jurisdiction with parallel duties.
The contractual annex translates the architecture answers into binding commitments: a representation that the vendor will not enable facial recognition or biometric templating without separate written authorization, an indemnification clause covering statutory damages and class-action defense under BIPA, CUBI, and comparable state statutes, a data-flow representation, and an audit right.
The deployment-specific privacy-impact assessment satisfies the NIST Privacy Framework's Govern-P and Identify-P functions, the GDPR Article 35 requirement where applicable, and the data-protection-impact-assessment requirements under the Colorado Privacy Act and similar regimes. For a typical non-healthcare deployment, the PIA can be completed in a week of cross-functional work and updated whenever the system architecture changes materially.
Buyers who implement those three additions report two near-term effects. Vendor short-lists narrow as systems that depend on facial recognition fail the architecture interrogatory. Time-to-deployment compresses, because the legal review migrates to the vendor selection phase and stops being a deal blocker. The Joint Commission 2026 workplace violence standards briefing illustrates how privacy-by-design vendor selection intersects with sector-specific regulatory expectations.
What Changes In The Next Eighteen Months
Three movements at the federal and state level will reshape the biometric privacy landscape between mid-2026 and the end of 2027.
First, the federal American Privacy Rights Act (APRA) continues to circulate in Congress. Recent drafts include a specific biometric data category with opt-in consent requirements and a private right of action for certain violations. The probability of enactment in any single session remains modest, but the design choices borrow heavily from BIPA and CPRA, suggesting the federal floor when it arrives will be substantively close to existing state ceilings.
Second, state attorneys general are expanding the use of unfair-and-deceptive-practice statutes to reach biometric collection not covered by a dedicated biometric law. The Texas Meta and Google matters relied in part on the Texas Deceptive Trade Practices Act, not just CUBI. The pattern is spreading through Florida, Connecticut, and California enforcement priorities.
Third, the comprehensive state privacy law category continues to expand. Maryland's Online Data Privacy Act took effect October 1, 2025. Minnesota's Consumer Data Privacy Act took effect July 31, 2025. Tennessee's Information Protection Act took effect July 1, 2025. Each adds biometric data to the sensitive-data category and enforces through the state attorney general with enhanced powers. The aggregate effect is to make a national-scale AI physical security program contingent on an architecture that travels well across regulatory regimes.
For the security director, the durable strategy is to procure systems whose compliance footprint is small enough to absorb the inevitable expansion. Systems that detect objects and events rather than identifying individuals remain the structurally cheapest option to maintain as the regulatory perimeter grows.
Buyer Questions: Biometric Privacy For AI Physical Security
If our AI security system does not perform facial recognition, do we still have BIPA exposure in Illinois?
In most cases, no. BIPA's duties attach to the collection of a biometric identifier as defined at 740 ILCS 14/10, which is limited to retina or iris scans, fingerprints, voiceprints, and scans of hand or face geometry. A system that detects objects (firearms, falls, vehicles, package types) or event categories without extracting a measurable physiological characteristic of an individual generally operates outside the statute. The diligence step is to confirm in writing with the vendor that no face-geometry template is created at any stage of the pipeline, including for internal calibration. A representation in the contract that face-geometry templating is not enabled on the deployment closes the residual question.
How does the Texas Capture or Use of Biometric Identifier Act differ from BIPA in practical terms?
Texas CUBI (Tex. Bus. & Com. Code § 503.001) covers the same statutory enumeration of biometric identifiers but reserves enforcement to the Texas Attorney General. There is no private right of action. The practical difference is that BIPA produces a high volume of moderate-stakes class actions, while CUBI produces a low volume of very high-stakes AG enforcement matters. The July 2024 $1.4 billion Meta settlement and the May 2025 $1.375 billion Google settlement illustrate the magnitude possible when the AG concludes a violation is widespread. Compliance posture under both statutes is similar: avoid the collection of an enumerated identifier where possible, secure compliant consent where collection occurs, and maintain the architectural documentation to support the position.
Does the Washington My Health My Data Act apply to AI cameras in a non-healthcare facility?
It can. MHMDA defines "consumer health data" broadly to include inferences about a consumer's physical or mental health, regardless of where those inferences are generated. A fall-detection system in a senior living community, a vital-sign-estimation system in a workplace wellness program, or any system that infers a health condition from camera output falls within the statute's reach when the inference is associated with an identified or identifiable consumer. The opt-in consent and data-minimization duties apply. For systems that detect events without identifying individuals and without inferring health status, the statute typically does not apply. Documentation of the architecture is the cheapest defense.
What does the comprehensive privacy law trend mean for a multi-state deployment?
As of May 2026, more than 20 states have enacted comprehensive privacy laws that treat biometric data as a "sensitive data" category requiring opt-in consent or formal data-protection-impact assessments before processing. The practical effect for a multi-state operator is that the strictest applicable rule typically governs the architecture, because retrofitting consent flows or impact assessments state-by-state is more expensive than designing the deployment to avoid the regulated footprint entirely. Procuring systems that do not extract enumerated biometric identifiers is the durable hedge.
What contractual indemnification language should we require from an AI security vendor?
Indemnification should cover statutory damages, attorneys' fees, and class-action defense costs under BIPA, CUBI, the comprehensive state privacy laws, and any future federal biometric privacy statute. The clause should survive termination and not be capped at contract value. The vendor should warrant that the system does not extract a biometric identifier as defined by 740 ILCS 14/10 unless expressly enabled by written authorization. A data-flow representation should be attached as an exhibit and updated whenever the architecture changes materially.
Does an FTC consent decree like the Rite Aid order set a national standard?
Not formally. FTC consent decrees apply by name to the parties to the order. But the Commission's December 2023 Rite Aid order is widely read as a regulatory signal of how the FTC views unfair facial recognition deployments under Section 5 of the FTC Act. The order's substantive elements (no facial recognition for surveillance, comprehensive monitoring program, deletion of collected biometrics and derivative models) function as a de facto compliance benchmark for retail and consumer-facing deployments. Buyers who can demonstrate that their architecture is consistent with the Rite Aid order's substantive principles materially reduce FTC inquiry risk.
How do these state statutes intersect with HIPAA in a healthcare deployment?
HIPAA regulates PHI created, received, maintained, or transmitted by covered entities. A system that detects events without identifying individuals and does not retain video is typically not a new creator of PHI, though a written risk analysis under 45 C.F.R. § 164.308(a)(1)(ii)(A) is the supporting documentation. State biometric statutes operate as a separate layer regulating consent and retention rather than disclosure of treatment information. The combined posture is most defensible when the architecture minimizes both PHI creation and biometric extraction.
Where To Go Next
Three IntelliSee Intelligence reports extend the analysis in this briefing:
- The EU AI Act and Physical Security AI: A Compliance Intelligence Briefing: extraterritorial reach into U.S. operators, real-time biometric identification restrictions, and high-risk AI classification.
- State-by-State AI Security Legislation: Q2 2026 Tracker: bill-level monitoring of biometric and AI security legislation across all 50 states.
- AI Physical Security Procurement Compliance: The 2026 Federal and State Regulatory Framework: Section 889, vendor diligence, and the broader procurement compliance architecture.
Learn more about how IntelliSee's computer-vision architecture detects threats and safety events without facial recognition, video storage, or PHI collection, or review the full solutions overview for detection categories that operate outside the biometric statutory perimeter.
Request a Risk AssessmentMore intelligence like this
New IntelliSee research drops monthly at most. Subscribe and get the next sector playbook, technology briefing, or threat intelligence report in your inbox the day it ships.
Request a Risk Assessment
Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.
Request a Risk Assessment