techpolicy.press web signal

Herta Security scales EU-banned facial recognition in India

TL;DR

  • Spanish firm Herta Security supplies facial recognition technology to about 4,000 cameras across India, from railway stations to Delhi prisons and the Ayodhya Ram Mandir.
  • Eastern Railway alone runs 540 Herta-powered facial recognition systems at 143 stations, with a €3.2 million estimated contract covering Delhi's Tihar, Mandoli and Rohini prisons.
  • Four EU legal scholars told reporters these Indian deployments would violate the EU AI Act, which since 2025 largely prohibits real-time remote biometric identification.

A Spanish company whose facial recognition tools would violate the EU's own AI Act if run at home now supplies technology to about 4,000 cameras across India. That is the reporting from Tech Policy Press, and the mismatch between what Europe permits at home and what a European vendor is selling abroad is the part worth sitting with.

The company is Herta Security, founded in Barcelona in 2009 by former Bosch biometrics specialist Javier Rodríguez Saeta. Its software reportedly runs on 540 facial recognition systems at 143 stations for Eastern Railway, across three Delhi prison complexes (Tihar, Mandoli and Rohini) with an estimated €3.2 million contract value, on 140 cameras in Ahmedabad, and at the Ram Mandir temple in Ayodhya. India's broader surveillance buildout has been backed by the Nirbhaya Fund, which by March 2025 had disbursed about €532 million, with roughly half directed at surveillance systems rather than direct victim services.

The uncomfortable twist is the funding trail on the other side. The European Union has given Herta at least €3 million in research grants over five years, the largest of which, €2.36 million from 2022 to 2024 for a project called FUTURE, went toward crowd behavior analysis to identify "abnormal activities and potential threats." Since 2025, the EU AI Act has largely prohibited real-time remote biometric identification in public spaces at home. Four EU legal scholars told the reporters the Indian deployments would clearly violate the Act inside a member state. Rita Matulionyte put it plainly, that such a deployment "would quite clearly violate the EU's AI Act." Apar Gupta added that "India is definitely one of the leading adopters of facial recognition technology in the world without any safeguards."

The honest caveat is that the reporting concentrates on one Spanish vendor with named Indian partners; it does not quantify how many other EU firms are doing the same thing, or give hard accuracy and false-match numbers for the deployed systems, or say whether Indian tenders ever asked for AI Act-equivalent safeguards.

What this teed up is a policy question Brussels has been ducking, whether EU research grants and export policy should match the standard the Act now imposes at home, or keep letting the two diverge. India's civil society lawyers now have a very clean example to argue from.

Shared on Bluesky by 2 AI experts