Behavioural biometrics is surveillance with better branding
Behavioural biometrics promises security that costs the user nothing, by measuring how a person's body operates a device and comparing it against a stored profile. It is a detector, it is biometric, and it watches continuously. For authorising a consequential action, it is the wrong instrument, and that stays true no matter how accurate it gets.
Picture a woman on the phone to her bank on a Wednesday afternoon. She has her password. She has her phone. She has the card in her hand and she is standing in her own kitchen. The app will not let her move money, and the agent on the line cannot tell her why, because the agent does not know either. Somewhere in the risk stack, a model has decided that she is not typing the way she usually types.
She is not. She broke her wrist three weeks ago and she is typing with one hand.
Nobody in this story did anything wrong. The bank bought a control that promised security without asking customers to do anything, which is a reasonable thing to want. The vendor built a system that measures how people interact with a device and flags deviations, which is a legitimate engineering approach. The model did exactly what it was trained to do. And yet a real customer is locked out of her own money, with no explanation available to her, no correction she can make, and no appeal she can file, because the reason lives in a comparison against a statistical profile of her body that she has never seen and did not know existed.
This is the trade the industry made when it decided that the best security is invisible security. It is worth examining what was actually purchased, because two technologies now compete to answer the question "is this the right person", and they are close to opposites.
Short answer. Under the GDPR, behavioural characteristics are named in the definition of biometric data, and processing them to uniquely identify someone triggers the Article 9 special category regime. Under Illinois BIPA the position is weaker, because that statute lists specific physical identifiers. Either way, behavioural biometrics is continuous collection producing a probability. A signature is a deliberate act producing a fact.
What is behavioural biometrics actually measuring?
The category covers a family of techniques that build a profile of how a specific person operates a device. Keystroke dynamics: the dwell time on each key and the flight time between them, which is stable enough per person to be recognisable. Mouse kinematics: acceleration curves, path curvature, the small corrections you make approaching a target. Touchscreen behaviour: pressure, contact area, swipe velocity, the angle at which you hold a phone as measured by its accelerometer and gyroscope. Navigation patterns: which screens you visit in which order, how long you dwell, whether you scroll or search.
The engineering is genuinely clever and the vendors are not charlatans. These signals really do carry identity information, sometimes surprisingly strongly. Continuous collection means the system can notice a change mid session, which a check at login cannot do. The user experience really is invisible.
Now describe the same system in plain terms, because the plain description is the one that matters for the argument. It is a system that measures how a person's body moves, continuously, throughout their use of a service, stores the resulting profile, and compares future behaviour against it to estimate whether the person is who they claim to be.
Read that sentence again and notice three separate properties bundled inside it. It estimates, which makes it a detector, with everything that implies about the arms race described in detection debt. It measures the body, which makes it biometric in the ordinary meaning of the word and, as we will see, in at least one major legal definition. And it watches continuously, which makes it surveillance, in the neutral technical sense that it is a system of ongoing observation of a person who is not looking back.
None of those three words are insults. They are descriptions, and the vendors would broadly accept the first and the third. The argument of this piece is that the bundle is the wrong instrument for the specific job of authorising a consequential action, and that this is true regardless of how accurate the model gets.
Is behavioural biometrics biometric data under BIPA and GDPR?
This is the question that brings most readers here, and it deserves a careful answer rather than a convenient one. The honest answer is that the two major regimes point in different directions, and the one that most coverage leads with is the weaker of the two. What follows is a description of the legal position as we understand it, and it is not legal advice.
Under the GDPR, the answer is closer to yes
Article 4(14) of the General Data Protection Regulation defines biometric data as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that person.
The word "behavioural" is in the definition. It is not an inference, an interpretation, or a campaigning reading. It is the text. A system whose entire purpose is to process behavioural characteristics through specific technical processing in order to confirm the unique identification of a person is describing itself in the language of Article 4(14) with unusual precision.
Article 9 then makes biometric data a special category when it is processed for the purpose of uniquely identifying a natural person, which raises the bar for lawful processing considerably: you need an Article 9 condition, not merely an Article 6 lawful basis, and legitimate interests is not among the Article 9 conditions.
The vendor counterargument is real and should be stated fairly. It runs that the system does not uniquely identify a person from behaviour alone, it merely scores confidence that an already identified session is being operated by the expected account holder, which is verification rather than identification, and that some deployments never compare across users. That argument has force, it is made in good faith by serious lawyers, and it has not been comprehensively tested. It is also, notably, an argument about deployment configuration rather than about the technique, which means it can stop being true when someone changes a setting.
Under Illinois BIPA, the answer is probably no, and it is worth being clear about that
A great deal of writing on this topic reaches for BIPA because BIPA is where the money has been. Illinois BIPA litigation has produced very large settlements, the best known being the $650 million Facebook settlement approved in 2021 over facial recognition in photo tagging, and the Illinois Supreme Court has interpreted the statute broadly in cases including Rosenbach v. Six Flags in 2019, which held that a person need not plead actual injury beyond the statutory violation, and Cothron v. White Castle in 2023 on claim accrual.
But BIPA defines a biometric identifier as an enumerated list: a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. It is a closed list of physical characteristics, and the statute goes on to exclude a number of things explicitly, including writing samples and written signatures. Keystroke dynamics and mouse kinematics are not obviously on that list, and a straightforward reading suggests they fall outside it.
We think that is the correct reading, and we are pointing it out even though the opposite reading would be more convenient for our argument. If you are assessing behavioural biometrics for an Illinois deployment, the serious exposure is more likely to come from other theories than from BIPA's enumerated definition. Anyone telling you confidently that BIPA covers keystroke dynamics is ahead of the text.
The direction of travel
Beyond those two regimes, the European Union's AI Act introduces obligations touching biometric categorisation and related practices on a staged timetable through the middle of the decade, and the human oversight requirements in Article 14 apply to high risk systems, which we have written about in what human in the loop actually means under the EU AI Act. NIST's digital identity guidance has historically been cautious about behavioural characteristics as standalone authentication factors, treating them as supporting signals rather than as factors in their own right.
The practical summary for a privacy officer: the GDPR analysis is the one that will keep you up at night, the BIPA analysis is weaker than the headlines suggest, and the regulatory direction across jurisdictions is toward more scrutiny of continuous behavioural processing rather than less.
Three axes where the two approaches diverge
Consent: ambient versus deliberate
A behavioural system collects whether or not the user is thinking about it. That is the product. The disclosure lives in a privacy policy, and we all know what proportion of users read those. Even a user who has read it and genuinely agreed cannot meaningfully consent to each act of collection, because the collection is the ambient condition of using the service.
A signature is the opposite. Nothing is collected until the person does something deliberate, and the deliberate act is scoped to one action at one moment. The user knows it happened, because they did it.
This is not merely a compliance nicety. It is the reason one of these approaches can carry intent and the other cannot, which is the subject of the next section but one.
Data at rest: a permanent asset versus nothing much
A behavioural profile has to persist to be useful. It sits in a datastore, it is backed up, and it is an asset of the company that holds it. That means it can be breached. It can be subpoenaed. It transfers in an acquisition. It can be repurposed for a use nobody contemplated when it was collected, because the data is already there and someone will eventually have a good idea about it.
It is also difficult for a person to exercise rights over, in a very practical sense. What does a subject access request return for a keystroke model? What does rectification mean when the data is a statistical embedding of your motor patterns? What does the user do if it is wrong, as it was for the woman with the broken wrist?
The proof based approach stores a public key and, where a face match is used at enrollment, a one way key derived on the device. There is no template, no continuous feed, no behavioural history. The breach blast radius of a public key is zero, because it is public. That is not a security feature that had to be engineered so much as a consequence of not collecting the thing in the first place.
Failure mode: illegible versus legible
When a behavioural system is wrong, the person on the receiving end gets an outcome with no reason attached. The model cannot articulate why, because the reason is a distance in a feature space. The support agent cannot explain it. The customer cannot correct it. And the false positives are not randomly distributed: they fall on people whose interaction patterns are unusual or changeable, which means disproportionately on people with disabilities, people with tremors or motor conditions, older users, people using assistive technology, people sharing a device, and people whose circumstances just changed, such as a woman in a cast.
When a signature check fails, the reason is a sentence. The signature did not verify, or the key is not enrolled, or the payload did not match. Every one of those is legible to the user, to the support agent, and to an auditor two years later. Legibility is not a luxury. It is the difference between a control you can operate fairly and one you cannot.
Why can passive inference never authorise an action?
This is the core of the argument, and it survives even if you grant a behavioural system perfect accuracy. Grant it. Assume a model that identifies the right human with certainty, from typing alone, forever. The argument still holds, and here is why.
Authorising something is not a fact about the world that can be observed. It is an act that a person performs. Philosophers of language call these performative utterances or speech acts: saying "I promise", "I agree", "I accept", or signing your name does not describe a pre existing state of affairs, it creates the obligation in the moment of saying it. There is no promise sitting in the world waiting to be detected. The promise begins when it is made.
Authorisation works the same way. A payment is authorised because a person with the standing to authorise it performed an act of authorising, at a moment, with respect to that payment. That is why we have signatures, seals, witnesses and ceremonies, and why we have had them for millennia across every legal tradition. They are not identification technologies. They are ways of performing and recording an act.
Now notice what a behavioural system can and cannot do with that. It can tell you, with whatever confidence, that the person at the keyboard is probably the account holder. It cannot tell you that they authorised anything, because authorising is not a property of their typing. The same keystrokes accompany a deliberate approval, an accidental double click, a coerced approval with someone standing behind them, and an agent replaying recorded input. The behaviour is identical. The act is completely different.
So the narrow claim that survives every steelman is this: you cannot infer a speech act from typing cadence. Identification is not authorisation, and no improvement in the accuracy of the first ever produces the second. That is a category error, not an engineering gap, and it cannot be closed with more data.
It is also why the agent era makes this worse rather than better. A computer use agent operating a browser on a person's behalf generates input events that look like a human's, because they are being produced to drive a human interface, and increasingly they are produced with human like timing. The behavioural signal cannot distinguish an agent the user asked to do something from an agent that read a malicious instruction on a web page, because both produce a legitimate looking session on the user's own device. We covered that failure mode in your agentic browser is logged into your bank.
What is the strongest case for behavioural biometrics?
An argument that does not survive its opposition is not worth publishing, so here is the best version of the other side, made as well as we can make it.
It genuinely removes friction, and friction has victims too. Every additional step in an authentication flow loses real users. Some of them are people who needed access to their money urgently. A control that protects people without asking anything of them is not merely convenient, it is more inclusive along one important axis, and dismissing that is easy for anyone who has never watched a conversion funnel.
It operates continuously, which a signature at a single moment does not. This is the strongest technical point against us. If an attacker takes over mid session, after every authentication has been passed, a behavioural system can notice and a login time check cannot. That is a real capability and we should not pretend otherwise. Our answer is not that continuous observation is useless, it is that the right response to a mid session takeover is to require a fresh proof at the consequential action rather than to watch the whole session, because the action is where the loss happens.
Some people will never complete an active check. There are users who cannot or will not perform an additional step, and a passive system protects them where an active one would exclude them. This is a serious point and any honest design has to answer it with a fallback rather than a shrug.
The legal position is unsettled, not decided. We have argued the GDPR text points one way, but there is no comprehensive body of enforcement specifically on behavioural biometrics, and reasonable practitioners disagree. Anyone who tells you the question is closed is overstating.
Take all of that seriously, and the surviving claim narrows to something quite specific and, we think, quite defensible: behavioural analysis may be a reasonable risk signal for deciding when to ask for something, and it is the wrong instrument for being the thing that authorises a consequential, irreversible action.
What does proof without watching actually look like?
The mechanism is deliberately unremarkable. At a consequential action, the service asks the person to produce a signature over the exact details of that action, using a key held in hardware on a device they control. Between those moments, nothing is collected at all.
canonical = {
"action": "transfer.execute",
"amount": "9400.00",
"currency": "GBP",
"payee": "M. Okafor",
"account": "GB33BUKB20201555555555",
"issuedAt": "2026-09-18T14:41:07Z"
}
challenge = SHA256(canonicalJSON(canonical))
assertion = navigator.credentials.get({
publicKey: { challenge, userVerification: "required" }
})
What the service retains afterwards is a receipt: the payload, the signature, the key identifier, the timestamp. What it does not retain is any record of how the person moved, typed, held the phone, or navigated to get there, because none of that was ever collected. The receipt verifies against a published key with no callback, which means an auditor or a regulator can check it years later without the vendor's cooperation.
The contrast is worth putting in a table, because procurement teams need to compare these on the same axes.
| Property | Behavioural biometrics | Per action signature |
|---|---|---|
| Consent model | Ambient, disclosed in a privacy policy | Deliberate act, per action, per moment |
| Data collected | Continuous behavioural telemetry | Nothing between actions |
| Data at rest | A per person behavioural profile | A public key and signed receipts |
| Breach blast radius | Profiles of every user, not resettable | Public keys, which are already public |
| Explainability on failure | A distance in a feature space | A sentence a support agent can read out |
| What it establishes | A probability that this is the account holder | That this human authorised this payload |
| Effect of better generative AI | Signal degrades as input is synthesised | No effect, possession of a key is unchanged |
| Covers mid session takeover? | Yes, this is its genuine strength | Only at gated actions, which is where loss occurs |
| User friction | None, which is the entire pitch | Seconds, at a small number of moments |
| GDPR posture | Article 9 analysis needed, behavioural is in the Article 4(14) text | Ordinary personal data, no special category processing |
What this argument does not prove
- It does not prove behavioural biometrics is unlawful. The GDPR analysis is contested, BIPA's enumerated list probably excludes it, and deployment configuration matters enormously. We have set out how we read the text, not how a court has ruled.
- It does not prove these vendors are acting in bad faith. They are solving the friction problem their customers asked them to solve, and they solved it well. The critique is about instrument choice for one specific job.
- It does not mean passive risk signals have no place. Using risk to decide when to require a proof is a perfectly good design. The objection is to passive inference being the final word on an irreversible action.
- A signature does not stop a deceived human. If someone is manipulated into authorising a payment they understood, they will sign it and the signature will be valid. That limit runs through this entire series and it is a large share of real world loss.
- Friction is a real cost with real victims. Every gate loses some legitimate users. Choosing which actions deserve one is a judgment, and getting it wrong in the other direction causes harm too.
- A compromised device defeats both. If the attacker controls the endpoint, neither approach is doing what it claims.
The standard we should be held to
It would be cheap to make this argument without stating what it commits us to, so here is the standard, and readers should hold us to it rather than take it on trust.
A proof based control should store no behavioural telemetry, no biometric template, no keystroke or pointer data, and no continuous feed of any kind. Where a face match is used, it should happen on the device and yield a one way key that cannot reconstruct the face. The artifact produced should be readable by the person it describes. It should verify without calling the vendor, so that the vendor cannot become a gatekeeper or a single point of failure. And the list of what is never collected should be published, specific, and stable enough to paste into a data protection impact assessment.
Manav's architecture is built to that standard and the commitments are set out in why we will not sell identity data and in the developer documentation. If we ever ship something that quietly collects behavioural telemetry because it would improve a model, this post is the thing to hit us with.
What to do this week
- Find out whether you are already running this. Behavioural analysis is frequently bundled inside fraud platforms and bot management products rather than bought as a named line item. Ask your vendors directly what behavioural signals they collect and retain.
- Check whether your privacy notice describes it accurately. If the notice says you collect device information and you are in fact modelling typing rhythm, that gap is your problem, not the vendor's.
- Run the Article 9 question properly. If you process behavioural characteristics to confirm unique identification of a person in the European Union, work out which Article 9 condition you are relying on, and get an answer in writing.
- Ask for the false positive rate broken down by user segment. Specifically for users with accessibility needs and users over sixty five. If the vendor has never measured it, that is your answer about who bears the cost of errors.
- Read your lockout tickets. Pull a month of access denials attributed to behavioural risk and read the customer's account of what happened. This exercise changes minds faster than any argument in this post.
- Separate the two decisions. Use risk signals to decide when to ask for a proof. Do not let them be the proof. Write that split down as policy so it survives the next re-platforming.
- Pick one irreversible action and put a real signature on it. One action class, one quarter, measured friction. Try the flow in the signing demo before you write the requirements.
Frequently asked questions
Is behavioural biometrics considered biometric data under BIPA and GDPR? The GDPR is the stronger case: Article 4(14) names behavioural characteristics in its definition of biometric data, and Article 9 applies when such data is processed to uniquely identify a person. Illinois BIPA is weaker, because it enumerates specific physical identifiers such as fingerprints and face geometry, and behavioural signals are not obviously on that list. This is not legal advice.
What is continuous authentication? Systems that keep evaluating identity throughout a session rather than once at login, typically by comparing ongoing behavioural signals against a stored profile. The genuine benefit is noticing a takeover mid session. The costs are continuous collection, a probabilistic answer, and failures the user cannot understand or appeal.
Does behavioural biometrics stop session hijacking? Sometimes, and this is its strongest claim. It can flag a session whose interaction pattern changes after authentication. It degrades against attackers who replay recorded input and against agents that produce human like timing, and it produces a probability rather than a decision, so a threshold has to be set somewhere between locking out real customers and letting attackers through.
What is the privacy preserving alternative to behavioural biometrics? Requiring a deliberate signature from the user's own device at consequential actions, and collecting nothing between those moments. It stores a public key rather than a behavioural profile, produces a legible reason when it fails, and yields a receipt that verifies offline without contacting the vendor.
Why can a very accurate behavioural model still not authorise a payment? Because authorising is an act a person performs, not a fact about them that can be observed. Identical typing accompanies a deliberate approval, an accidental click, a coerced approval, and a replayed session. Identification and authorisation are different questions, and accuracy on the first never produces the second.
Who is most affected by false positives in behavioural systems? People whose interaction patterns are unusual or changing: users with motor conditions or tremors, users of assistive technology, older users, people sharing a device, and anyone whose circumstances recently changed such as an injury. Ask your vendor for false positive rates by segment, because these errors are not evenly distributed.
Should banks stop using behavioural risk signals entirely? No. Using them to decide when to ask for a stronger proof is reasonable and useful. The objection is narrower: passive inference should not be the final authority on an irreversible, high value action, because it answers a different question from the one that action requires.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 4(14) definition of biometric data and Article 9 on special categories of personal data. eur-lex.europa.eu
- Illinois Biometric Information Privacy Act, 740 ILCS 14, including the definition of biometric identifier. ilga.gov
- Rosenbach v. Six Flags Entertainment Corp., Illinois Supreme Court, 2019. Illinois courts
- Cothron v. White Castle System, Inc., Illinois Supreme Court, 2023, on claim accrual under BIPA. Illinois courts
- Facebook biometric privacy class settlement, approved 2021, reported at $650 million. Court records via CourtListener
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), provisions on biometric practices and Article 14 human oversight. eur-lex.europa.eu
- European Data Protection Board guidance on biometric data processing. edpb.europa.eu
- NIST Special Publication 800-63B, Digital Identity Guidelines, on authenticators and biometric characteristics. pages.nist.gov
- Information Commissioner's Office guidance on biometric data and recognition technologies. ico.org.uk
- J. L. Austin, How to Do Things with Words, 1962, for the account of performative utterances used in the authorisation argument.
You cannot infer a speech act from typing cadence. Identification is not authorisation, and no amount of accuracy on the first will ever produce the second.