logo
أرسل رسالة
Wuhan Homsh Technology Co.,Ltd.
المنتجات
أخبار
المنزل > أخبار >
أخبار الشركة حول The Compliance Era of Biometric Recognition
الأحداث
الاتصالات
الاتصالات: Mr. Kelvin Yi
اتصل الآن
أرسل لنا

The Compliance Era of Biometric Recognition

2026-08-18
Latest company news about The Compliance Era of Biometric Recognition
      In 2026, the biometric recognition industry is undergoing a profound structural transformation — driven not by technological breakthroughs, but by the redrawing of regulatory boundaries.
      Nearly five years have passed since the implementation of the Personal Information Protection Law, the Regulations on Network Data Security Administration have been fully rolled out, and the Provisions on the Security Administration of Facial Recognition Technology Application officially took effect in August 2024. A series of intensive policy releases have turned "data compliance" from an optional practice for enterprises into a prerequisite for market access. Among all biometric traits, iris data, due to its immutability and uniqueness, is becoming a core asset subject to the strictest regulation yet with the highest market value.
      This is not a crisis, but a structural opportunity. Only by understanding the underlying logic of policies can enterprises find the right path to meet compliance requirements.

I. Why Iris Data Is the Top Priority of Regulation

      Facial features can be altered by plastic surgery, and fingerprints can change due to injury, but iris texture is basically formed 6 months after birth, remains stable throughout life, and is completely different between the left and right eyes — no two are identical among the 7 billion people worldwide.
      For this reason, iris data is legally classified as the highest level of "sensitive personal information", alongside genetic information. Article 28 of the Personal Information Protection Law explicitly stipulates that the processing of sensitive personal information requires separate individual consent, and must have specific purposes and sufficient necessity.
      In April 2026, the Ministry of Industry and Information Technology released the Guidelines for Data Security of Biometric Recognition (Draft for Comments), further refining four core requirements:

Core Requirements of the Guidelines for Data Security of Biometric Recognition

      ● Principle of data minimization: Over-scope collection is prohibited, and alternative authentication methods must be provided

      ● Priority for local processing: Feature extraction and matching on the terminal side is encouraged

      ● Encrypted template storage: Storing original texture images in plain text is prohibited

      ● Data sovereignty guarantee: Iris data is strictly prohibited from leaving the country in key scenarios

آخر أخبار الشركة The Compliance Era of Biometric Recognition  0

II. How Compliance Pressure Reshapes the Market Competition Landscape

      During the period of loose regulation, competition in the iris recognition market mainly focused on accuracy, cost and integration convenience. Low-price competitors could rely on massive cloud computing power to make up for the shortcomings of local algorithms — uploading iris images to the cloud for recognition saved terminal R&D investment and enabled rapid iteration.
      But with the arrival of the compliance era, this approach is being phased out.
      Government procurement scenarios: The new draft technical specifications for government procurement in 2026 explicitly require that recognition systems involving citizens' biometric traits must pass Classified Protection Level 3 certification, and original biometric images must not leave the collection terminal. This directly rules out solutions relying on cloud-based recognition.
      Enterprise scenarios: Article 27 of the Data Security Law imposes data security assessment obligations on handlers of "important data". Manufacturing, financial and medical institutions that widely use iris access control have begun to proactively require suppliers to provide offline solutions with "zero data exfiltration" to reduce their own compliance risk exposure.
      Multinational enterprise scenarios: The EU AI Act classifies remote biometric systems as "high-risk AI", with strict restrictions on real-time use in public places. Chinese hardware products exported to Europe with built-in biometric functions must comply with both the GDPR and the AI Act.
      The common conclusion across the three scenarios: algorithm and data processing capabilities must be shifted to terminals. Cloud dependency is no longer an advantage, but a compliance risk. Vendors with full-stack end-side capabilities are gaining systematic competitive advantages.

III. Homsh's Technical Roadmap for Compliance

      When Homsh launched the Qianxin chip project in 2021, one of its primary design goals was "zero local data exfiltration". This was not because it foresaw the policy tightening in 2026, but because users in real scenarios — port border inspection, coal mine safety, military bases — inherently reject solutions that transmit data externally.
      It is this scenario-driven engineering mindset that puts Homsh in a structurally advantageous position amid the wave of compliance.
      Compliance advantages of the Phaselirs™ phase encoding algorithm: Phaselirs™ does not store original iris images, but only extracts and saves 512-dimensional phase feature codes. These codes meet the irreversibility requirement, meaning iris texture images cannot be reversely restored from the feature codes; randomized hash transformation is adopted, so the same iris generates different templates in different systems to prevent cross-system tracking; feature extraction is completed within the Qianxin chip, and original images never enter any storage medium.
      This technical route is fully aligned with ISO/IEC 24745:2022 (Biometric Information Protection Standard), and also forms the technical foundation for Homsh's certification of biometric recognition products by the Ministry of Public Security.
آخر أخبار الشركة The Compliance Era of Biometric Recognition  1

IV. International Standards: The Highest Threshold and the Strongest Moat

      While domestic policies are tightening, the international biometric standard system is also evolving continuously.
      NIST IREX 10 is the world's most authoritative iris algorithm evaluation system. In the latest evaluation results released in 2025, participating algorithms came from more than 20 institutions across China, the US and Europe. Algorithms ranking high in recognition accuracy (TAR@FAR=0.01%) generally receive extra points in government procurement evaluations.
      ISO/IEC 19794-6 specifies the iris data exchange format and is a basic standard for cross-system interoperability. All iris recognition solutions participating in international port mutual recognition and e-passport systems must strictly comply with it.
      The biometric authentication standards of the FIDO Alliance are being extended to iris recognition, requiring that biometric matching must be completed in a local Trusted Execution Environment (TEE), and matching results only output boolean values without transmitting any biometric data.
      Homsh has currently obtained ISO/IEC 19794-6 certification, NIST IREX evaluation is in progress, and the FIDO iris authentication solution is expected to be submitted for certification in Q4 2026.

V. From Compliance Cost to Compliance Competitiveness

For participants in the biometric recognition industry, there are two ways to understand compliance:
      The first view: compliance is a cost. It requires certification, architecture modification, and restrictions on data usage, all at a high price.
      The second view: compliance is a barrier. Once compliance certification is obtained, access qualifications that are difficult for competitors to replicate quickly are established. In government procurement evaluations, the threshold of compliance certification directly filters out a large number of low-price competitors.
      Homsh has adopted the second view. From the end-side computing design of Qianxin chips, to the irreversible feature encoding of Phaselirs™, and to the classified protection support system of OVAI terminals, Homsh has embedded compliance logic into the underlying product design — not to cope with inspections, but because this is inherently the right way to build high-quality iris recognition products.
      Data security is not a barrier to the development of the biometric recognition industry, but an accelerator that eliminates low-quality solutions and makes room for high-quality products. The compliance era marks the maturity of the industry, and is the moment when technical barriers truly gain market recognition and value.