The hypothesis assumes the AI Act's broader biometric identification definition can displace GDPR restrictions on avatar-derived behavioral biometrics. No supplied source addresses the AI Act or GDPR directly; the available evidence is technical, but it bears directly on the hypothesis's factual predicate: whether gait, gaze, and keystroke data in immersive environments are functionally identifying.
Technical capability evidence. A context-aware multimodal fusion framework combining keystroke dynamics and gait achieved 98.25% accuracy with ~2.35β2.5% equal error rate on the BB-MAS dataset (117 subjects; >3.5 million keystroke events; >57 million gait readings), operating on-device with ~150β200 ms latency . Keystroke dynamics alone reached near-perfect static-text authentication (FOA optimizer: 100% accuracy, 0.00% EER), though on a small, fixed-text CMU dataset with overfitting and generalizability caveats . Keystroke logs from 761 middle-school writers show timing and edit patterns systematically discriminate users, confirming behavioral signatures are person-linked even outside authentication contexts .
Implication for the hypothesis. Because gait and keystroke modalities demonstrably achieve person-unique identification performance, GDPR Article 9 engagement (biometric data processed for unique identification) is a factual question about purpose, not a definitional gap. The AI Act and GDPR operate in parallel; the AI Act cannot lawfully authorize what GDPR prohibits. What the broader AI Act definition does do is expand which systems face AI Act obligations (e.g., remote biometric identification restrictions), while GDPR still governs processing lawfulness independently. Thus the hypothesized 'workaround' is better framed as scope divergence: an avatar-derived behavioral signal may escape the AI Act's biometric category (if not used for identification) yet still be personal data under GDPRβor vice versa. Known unknowns: gaze-based inference in metaverses is not covered by any supplied source; EDPS/EUCJ interpretive rulings post-2024 are not in the evidence base.
How to disprove: documented regulator guidance or case law explicitly permitting AI-Act-categorized behavioral biometric processing that GDPR Article 9 would restrict.
Know what changed, what holds up, and what remains uncertain. Every Friday. No ads.