{"_id":"@csgaglobal/biometrics-ai","name":"@csgaglobal/biometrics-ai","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@csgaglobal/biometrics-ai","version":"1.0.0","description":"CSOAI Biometrics & Identity AI Governance — facial recognition, emotion detection, EU AI Act prohibited/high-risk biometric AI, and BIPA compliance","author":{"name":"CSGA Global — Cyber Security Global Alliance"},"license":"CC0-1.0","repository":{"type":"git","url":"git+https://github.com/csga-global/mcp-servers.git","directory":"packages/biometrics-ai"},"type":"module","main":"dist/index.js","bin":{"biometrics-ai-mcp":"dist/index.js"},"scripts":{"start":"node dist/index.js","build":"tsc"},"dependencies":{"@modelcontextprotocol/sdk":"^1.3.0","zod":"^3.23.0"},"devDependencies":{"@types/node":"^20.0.0","typescript":"^5.3.0"},"publishConfig":{"access":"public"},"engines":{"node":">=18.0.0"},"_id":"@csgaglobal/biometrics-ai@1.0.0","gitHead":"c7c0f8605f06b783f4bac5b541f4732ebce8b560","types":"./dist/index.d.ts","bugs":{"url":"https://github.com/csga-global/mcp-servers/issues"},"homepage":"https://github.com/csga-global/mcp-servers#readme","_nodeVersion":"22.16.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-m0qwG5syMZGDKEFpsgrUrmKTXBeX0mH6qL3PoJcM+uXXPkhzNt9jk1uWG2N5uA7tXoPUCNqoVORg4pC/TJu10w==","shasum":"6efa2aef09cc307161b6b5023637ad7560dabc00","tarball":"https://registry.npmjs.org/@csgaglobal/biometrics-ai/-/biometrics-ai-1.0.0.tgz","fileCount":11,"unpackedSize":51409,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDKduUUE4MKi7WeIG/9rQw4ctj7fIJVW2+544/u8gYqoAiAyuTa+kBl9GVXh/1ySYS80E1lqjGihWPCDaty4a8p1xw=="}]},"_npmUser":{"name":"csga_global","email":"Nicholastempleman@gmail.com"},"directories":{},"maintainers":[{"name":"csga_global","email":"Nicholastempleman@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/biometrics-ai_1.0.0_1772122498394_0.8034024134670836"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-26T16:14:58.293Z","1.0.0":"2026-02-26T16:14:58.537Z","modified":"2026-02-26T16:14:58.715Z"},"maintainers":[{"name":"csga_global","email":"Nicholastempleman@gmail.com"}],"description":"CSOAI Biometrics & Identity AI Governance — facial recognition, emotion detection, EU AI Act prohibited/high-risk biometric AI, and BIPA compliance","homepage":"https://github.com/csga-global/mcp-servers#readme","repository":{"type":"git","url":"git+https://github.com/csga-global/mcp-servers.git","directory":"packages/biometrics-ai"},"author":{"name":"CSGA Global — Cyber Security Global Alliance"},"bugs":{"url":"https://github.com/csga-global/mcp-servers/issues"},"license":"CC0-1.0","readme":"# @csoai/biometrics-ai — Biometrics & Identity AI Governance MCP Server\n\nComplete Model Context Protocol server for biometric AI risk assessment, EU AI Act compliance, bias detection, and BIPA litigation risk analysis.\n\n## Features\n\n- **EU AI Act Compliance**: Detects prohibited uses (emotion recognition in workplace/education, real-time facial ID in public spaces, social scoring)\n- **Bias Risk Assessment**: Documents demographic disparities in facial recognition accuracy (NIST FRVT studies), age estimation bias, lighting sensitivity, representation bias\n- **BIPA Litigation Risk**: Illinois Biometric Information Privacy Act private right of action assessment, per-scan violation accrual, class action exposure\n- **GDPR Compliance**: Special category data requirements, Data Protection Impact Assessment mandates, consent standards\n- **Technical Requirements**: ISO/IEC biometric standards, liveness detection, anti-spoofing, template protection\n- **Regulatory Coverage**: EU AI Act, GDPR, Illinois BIPA, Texas CUBI, Washington state laws, CCPA/CPRA\n\n## Tools\n\n### biometric_risk_assessment\nAssess EU AI Act classification, prohibited use check, bias risks, privacy requirements, and remediation for biometric AI systems.\n\n**Input Parameters:**\n- `system_name` — Name of the biometric AI system\n- `biometric_type` — Type of biometric (facial recognition, fingerprint, voice, iris, gait, emotion detection)\n- `use_case` — Use case (identification, verification, categorization, emotion recognition, social scoring)\n- `jurisdiction` — Operating jurisdiction (EU, US, UK, Illinois, etc.)\n- `deployment_context` — Deployment context (public spaces, workplace, education, law enforcement, border control)\n\n**Output:**\n- EU AI Act classification (PROHIBITED, HIGH RISK, or compliant assessment)\n- Prohibited use check with exceptions\n- Applicable regulations by jurisdiction\n- Demographic bias risks\n- Privacy requirements (GDPR Article 9, consent, DPIA)\n- Technical requirements (FAR/FRR testing, ISO standards, liveness detection)\n- Remediation roadmap\n- CASA (Continuous AI Safety Audit) tier and costs\n\n### bipa_compliance\nIllinois BIPA compliance assessment covering consent requirements, data handling, litigation risks, and penalty exposure.\n\n**Input Parameters:**\n- `system_name` — Name of the biometric system\n- `biometric_type` — Type of biometric identifier collected\n- `collection_method` — How biometric data is collected (camera, sensor, upload, etc.)\n- `operating_states` — US states where system operates (e.g., 'Illinois, California' or 'all states')\n\n**Output:**\n- BIPA applicability determination\n- Written consent requirements\n- Data handling and retention rules\n- Litigation risks (private right of action, class action exposure, per-scan accrual)\n- Penalty exposure ($1K-$5K per violation, recent settlements $39M-$650M)\n- Remediation steps (policies, consent forms, encryption, audit trails)\n\n## Resources\n\n- `biometrics://regulations/index` — Regulatory landscape (EU AI Act, US state laws, international frameworks)\n- `biometrics://tools/guide` — Tool documentation\n\n## Installation\n\n```bash\nnpm install\nnpm run build\nnpm start\n```\n\n## Regulatory Framework\n\n### Prohibited Uses (EU AI Act Article 5)\n- Emotion recognition in workplace/education (Article 5(1)(f))\n- Biometric categorization inferring race, political beliefs, sexual orientation (Article 5(1)(g))\n- Real-time remote biometric identification in public spaces (Article 5(1)(h)) — limited exceptions for missing children, terrorism prevention, serious crimes\n\n### High-Risk Biometric AI (EU AI Act Annex III)\n- Remote biometric identification systems\n- Post-remote biometric identification\n\n### US State Laws\n- **Illinois BIPA** (740 ILCS 14): $1,000-$5,000 per violation, per-scan accrual, private right of action\n- **Texas CUBI** (Tex. Bus. & Com. Code § 503.001): $25,000 per violation\n- **Washington State** (RCW 19.375): Biometric identifier protection\n- **NYC Local Law 144**: Automated employment decision tools\n- **CCPA/CPRA**: Biometric information as sensitive personal information\n\n## Key Statistics\n\n- **NIST FRVT Studies**: Facial recognition error rates 10-100x higher for darker-skinned individuals\n- **Meta/Facebook Settlement**: $650M BIPA class action (2021)\n- **TikTok Settlement**: $228M BIPA class action (2023)\n- **Clearview AI Settlement**: $39M consent + BIPA violations (2022)\n- **Per-Scan Accrual**: Cothron v. White Castle (2023) — each facial scan = separate BIPA violation\n\n## Author\nCSOAI — Council for the Safety of Artificial Intelligence\n\n## License\nCC0-1.0 (Public Domain)\n","readmeFilename":"README.md","_rev":"1-f24e59474592c1ead00a2336fc763785"}