Your Router Can Recognise You. The AI Act Isn’t Sure It Counts.
The EU banned real-time biometric identification in public spaces. Then researchers identified people through walls using ordinary Wi-Fi…
Your Router Can Recognise You. The AI Act Isn’t Sure It Counts.

The EU banned real-time biometric identification in public spaces. Then researchers identified people through walls using ordinary Wi-Fi signals, with no camera anywhere. This is the story of a definition that leaks.
In June I submitted a policy paper to the European Commission’s AI Office. It makes one argument, and I want to make the public version of that argument here, because it is not really a story about Wi-Fi. It is a story about how regulation can fails: not loudly, at the level of principles, but quietly, at the level of definitions.
Here is the short version.
The ban
Article 5 of the EU AI Act lists the practices Europe decided it does not want at all. One of them, Article 5(1)(h), prohibits real-time remote biometric identification (RBI) in publicly accessible spaces for law enforcement, with narrow exceptions. This is the “no mass facial recognition on our streets” rule. It has been in force since 2 February 2025. Unlike the high-risk obligations, whose dates moved under the omnibus package, the prohibitions did not move. They are live law today.
The ban is anchored to the concept of “biometric data” in Article 3(34), and to the RBI definition in Article 3(41). Keep those two definitions in mind. They are where the leak is.
The technology
Wi-Fi signals bounce around a room. A human body disturbs them in measurable ways. Two data streams on ordinary Wi-Fi equipment record those disturbances: Channel State Information (CSI) and beamforming feedback information (BFI), which devices broadcast unencrypted so access points can aim transmissions at them.
Researchers have been pulling information out of those disturbances for over a decade, and the arc is steady:
In 2012, researchers in London detected moving people through walls using the signals of an ordinary Wi-Fi access point. In 2018, MIT CSAIL estimated body poses behind walls in real time. In 2022, Carnegie Mellon reconstructed dense 3D body surfaces of multiple people from standard Wi-Fi antennas. And in 2025, researchers at the Karlsruhe Institute of Technology presented BFId at CCS, one of the main security conferences: a system that re-identified individuals with up to 99.5% accuracy in a study of 197 recorded participants, using gait and body signatures extracted from beamforming feedback.

Read that last one slowly. Commodity hardware. No access to the target network. The person carries no device at all. The signal is broadcast unencrypted by every Wi-Fi device around them.
Detection became pose estimation, pose estimation became body reconstruction, body reconstruction became identification. Thirteen years, one direction.
And one more thing: IEEE 802.11bf, published in 2025, makes sensing a native feature of the Wi-Fi standard itself. Every router implementing that amendment is, in principle, a passive human identification node. The KIT researchers themselves called for privacy safeguards. They saw where this goes.

The gap
So: a technology that can identify a person in a public space, at a distance, without their involvement. That sounds exactly like what Article 5(1)(h) wants to stop. Is a BFId-style system a prohibited RBI system?
The honest answer is: not unambiguously. Three problems stack up.
First, the processing-stage problem. Raw CSI or BFI is radio-frequency data. It describes how signals propagate through a space. On its face it is not “personal data relating to physical, physiological or behavioural characteristics”. The biometric character appears only after a model has processed the signal. The Act does not say at which stage of the pipeline “biometric data” comes into existence. A camera image of a face is biometric data at the point of collection. A radio echo of a walking body might not be, until the moment the model has already done its work.
Second, the architecture problem. Article 3(41) defines RBI through “the comparison of a person’s biometric data with the biometric data contained in a reference database”. That wording assumes a certain design: collect a template, compare against a database of templates. End-to-end neural systems do not have to work that way. The “reference” can live inside the model weights. No discrete template, no discrete database, no classic comparison step. Same outcome, different architecture, and the definition tracks the architecture.
Third, the enforcement problem. Definitional ambiguity is not neutral. It creates litigable space, it invites different national interpretations, and it hands operators a compliance pathway: not “we don’t identify people”, but “what we process is not biometric data within the meaning of the Act”. The harm the ban targets, covert identification of people in public spaces, is exactly the harm this technology can produce. The words just don’t reach it cleanly.
Gait, by the way, is expressly listed in Recital 15 of the Act as a behavioural feature usable for biometric identification. The lawmakers thought about gait. What they did not anticipate is gait arriving through a radio channel instead of a camera lens.
That is the pattern I keep finding, and it became the central argument of the book I am writing: the regulation leaks at its definitions. The principles are sound. The prohibition is broad in intent, “modality-silent” as the paper puts it. But in practice it is modality-dependent, because its definitions quietly assume the camera-and-microphone paradigm the drafters had in front of them.
Does GDPR catch it instead?
A reasonable hope. But GDPR’s biometric data definition, Article 4(14), is tied to “unique identification” and is arguably narrower, and it carries the same processing-stage question. A backstop with the same crack in it is not a backstop.
There is also a second, quieter gap. Article 5(1)(h) covers law enforcement use only. Commercial use of the same capability, retail analytics, workplace monitoring, insurance profiling, would be governed as high-risk under Annex III only if the system counts as RBI at all. The same definitional dependency controls that door too.
What I proposed
The paper puts the options in order of legal weight. Strengthen Recital 17 and add outcome-based language to Article 3(41), so that a system is RBI when it identifies a natural person without their active involvement, “whether or not a discrete biometric template is generated”. Use an Article 7 delegated act to clarify the commercial side through Annex III. And fastest of all: the AI Office can issue interpretive guidance tomorrow. No legislative procedure, no waiting for the next omnibus.
The fix is narrow on purpose. The point is not to ban Wi-Fi sensing, which has real and benign uses: fall detection for elderly people, presence detection, gesture control. The point is to make the ban’s coverage depend on what a system does, not on which sensor it uses.
Why I keep coming back to this
Because the prohibitions are the part of the Act everyone agrees on. If Europe’s strongest “never do this” rule can be sidestepped by changing the sensor, the problem will not stay in Article 5. Every definition in every regulation was written with some technology in front of the drafters. Technologies change. Definitions wait.
The uncomfortable question for all of us in this field is not “is Wi-Fi sensing banned?” It is: how many other definitions are quietly leaking right now, and who is checking?
I work in IT quality and risk and hold the ISO/IEC 42001 Lead Auditor certification. The full policy paper, “The Modality Gap in Article 5”, was submitted to the European Commission AI Office in June 2026.
메타데이터
- post_id
- f950af6a762d
- slug
- your-router-can-recognise-you-the-ai-act-isnt-sure-it-counts-f950af6a762d
- url
- https://medium.com/@Akyuerek/your-router-can-recognise-you-the-ai-act-isnt-sure-it-counts-f950af6a762d
- canonical_url
- https://medium.com/@Akyuerek/your-router-can-recognise-you-the-ai-act-isnt-sure-it-counts-f950af6a762d
- author_url
- https://medium.com/@Akyuerek
- status
- ok
- fetched_at
- 2026-07-16 12:18:32