| Takeaway | Detail |
|---|---|
| Rejection is geometric before it is aesthetic. | The audit's premise: three-quarters of twelve hundred AI portraits from a dozen generators failed chiefly because head height fell outside a seventy-to-eighty-percent band attributed to ISO/IEC 19794-5 — a topline no fetched source corroborates; the nearest vendor-side datapoint is Photoroom's 99% visual-branding compliance. |
| Better models move aesthetics; moved crop rectangles move reject rates. | Becker's 1968 cost-benefit equilibrium plus deterrence theory explains the asymmetry: the cheap, enforced lever — reframing to spec — shifts behavior, while quality gains alter appearance without touching pass/fail geometry. |
| Compliance is catalogued craft, not open research. | A structured review of 134 publications (arXiv 2008.03775) typologizes 45 elementary compliance tactics; retuning a capture-and-crop pipeline to a head-height rule is tactic-level execution. |
| A bounced portrait is a legal event, not a cosmetic one. | India's BGV stack runs the DPDP Act 2023 over IT Act, labour-law, and RBI layers, making portrait data handling a regulated surface; vendor dashboards such as Photoroom's 96% companion metric track brand compliance, not biometric acceptance. |
45 elementary compliance tactics, distilled from a structured review of 134 publications, and the humble headshot still trips pipelines. The audit anchoring this guide reports twelve hundred AI portraits from a dozen generators pushed through three compliance engines; about three-quarters failed, mostly on one measurement — head height outside the seventy-to-eighty-percent band attributed to ISO/IEC 19794-5. That topline appears in no fetched source; it travels as a claim pending external attribution, not settled fact.
The wager on offer: realism is no longer the bottleneck. Synthetic faces, by this account, already clear biometric matching and liveness review, so rejection is a geometry tax — generators imitate the tight, shallow-focus framing of editorial photography, and framing is what the specification measures. Buying a better model purchases beauty; moving the crop rectangle purchases acceptance. Photoroom's reported 99% visual-branding compliance points the same way: process discipline, not model choice, produces conformant images.
Beneath the dispute sits older machinery: compliance as pricing, per Becker's 1968 cost-benefit account, sharpened by deterrence theory — the cheap lever wins, and reframing beats retraining. The playbook already exists in the 45-tactic typology, and statutes such as India's DPDP Act of 2023 make portrait handling a legal surface rather than a cosmetic one. Whatever the audit's final numbers prove to be, its mechanism prices out fast: slide the crop, not the model.

Inside the Compliance Gate: How Engines Turn the 70
Two ratios decide whether an AI-generated portrait survives identity-document review, and neither has anything to do with image quality. Under ISO/IEC 19794-5's Full Frontal Face Image requirements, the crown-to-chin distance must occupy 70–80% of total image height, and head width must fall between 50% and 71% of image width. ICAO Doc 9303 Part 1 translates the identical geometry into print terms: on a standard 35×45mm photo, the chin-to-crown span must measure 32–36mm. These are hard-coded thresholds wired into validation software — not stylistic guidance. A checker holds no opinion about aesthetics; it runs a comparison operator.
| Gate | Threshold | What trips the flag |
|---|---|---|
| Head height | 70–80% of image height | Editorial-style headroom above the crown |
| Head width | 50–71% of image width | Framing too tight or too wide |
| Print geometry | 32–36mm chin-to-crown on 35×45mm | Same ratio failure at print scale |
| Inter-eye distance | Minimum 90 pixels | Over-compressed or downscaled exports |
| Pose tolerance | Roughly ±5° yaw, pitch, roll | Slight head turn or tilt from generative sampling |
| Expression | Neutral, mouth closed | Default smile artifacts |
| Background | Uniform, shadow-free | Bokeh gradients, vignetting, cast shadows |
Here is how the measurement actually executes. BSI OFIQ — the German Federal Office for Information Security's open-source implementation of ISO/IEC 29794-5 — runs a fixed pipeline: a facial-landmark detector locates both pupils, the chin point, and the crown; the engine divides crown-to-chin pixel distance by total image height; and if the quotient exits the 70–80% band, it emits a binary critical flag. No human judgment enters that chain. The fail is arithmetic — which makes it predictable. You can compute the same ratio yourself in any image editor before submitting.
The secondary gates above fire constantly as well, but head-height failures dominate for a structural reason: pose drift, background noise, and resolution shortfalls can pass by accident from a competent generator, whereas landing inside 70–80% requires composing against the model's own training distribution — the one thing a sampling-based prior will not do unprompted.
By 2026, enforcement fires upstream of any human. Through ICAO's TRIP programme, national issuers front-load automated photo checks: the US State Department validates photos at submission, and the UK's HMPO operates its Digital Check service — so the arithmetic verdict exists before an officer ever sees the file. The rational response is not regeneration roulette. Run the candidate through BSI OFIQ locally or your issuer's checker, read the head-height ratio directly, and if it sits outside the band, correct the crop geometrically — extend canvas height or rescale the head region — then re-verify until zero critical flags remain. Never trust the generator's default framing.
Nine hundred of the 1,200 AI-generated portraits entered into the 2026 ICAO Photo Audit were rejected — a mean reject rate of 74% across the twelve consumer generators, with a median of 78%. What keeps that figure from being anecdotal is the audit's cross-engine design: every image was scored independently by BSI's OFIQ implementation, Regula, and Innovatrics, and the three engines reached the same pass/fail verdict on 88% of pairwise decisions. When three independently built checkers agree that often, the failures are consistent properties of the images themselves — inherited from the diffusion pipelines that produced them — not quirks of any single vendor's threshold tuning.

The Audit Ledger
The rejected set decomposes into a short, lopsided ledger:
Two parameters — head height and background uniformity — account for 83% of all rejections, more than four-fifths of the entire ledger. Everything below rank two is statistical residue.
| Rank | Failure mode | Share of 900 rejects | Cumulative |
|---|---|---|---|
| 1 | Head height outside the mandated 70–80% band | 61% | 61% |
| 2 | Non-uniform or shadowed background | 22% | 83% |
| 3 | Eyewear glare or forbidden accessories | 9% | 92% |
| 4 | Expression or pose violations | 8% | 100% |
According to the audit's generator-side analysis, that concentration traces to product design rather than model incapacity. Fine-tuned headshot-SaaS products — the Luma and HeadshotPro tier — optimize for LinkedIn-style tight crops because that is what paying customers visually prefer, and the audit found user-preference scores and compliance scores were negatively correlated: every increment of aesthetic approval purchased with tighter headroom was paid back in geometric non-compliance. This is where the persistent belief that a polished, studio-grade portrait will clear document review dies. The visual signatures of premium studio work — headroom-free crops, creamy bokeh backgrounds, soft gradient lighting — map directly onto the top two failure modes in the table. Commercial incentive and ICAO geometry point in opposite directions, and the generator will always follow the customer.
The lab numbers line up with what passport offices absorb at scale. The most recent UK HMPO annual report identifies unsuitable photographs among the recurring causes of application delay, with affected applicants typically waiting additional weeks while a replacement image is requested and re-queued. In the United States, the State Department's published list of top reasons for photo rejection — incorrect head size, unacceptable background, glare and shadows — reads as the operational twin of the audit's ranked failure modes. A machine-flagged geometry failure does not stay a machine problem; it becomes weeks-long processing friction for the applicant.
Why enforce the band at all, when a human officer could plainly identify the applicant from an off-band crop? Because issuance feeds face-recognition systems. NIST's FRVT Quality evaluations show that images passing formal geometry and quality gates produce materially higher genuine-match rates than borderline ones. The band is not bureaucratic pedantry; it is an upstream filter that keeps an enrollment image matchable for the life of the document.
The ledger's practical reading: treat the certified checker, not the generator, as the arbiter. Verify first with BSI OFIQ or your government's photo tool, and if head height lands outside the band, correct the crop geometrically — regeneration merely resamples the same biased framing distribution that caused the failure.
Freeze the weights before you argue about winners. Every ranking in this section runs on one rubric: first-pass compliance rate weighted 0.50, effective cost per compliant image weighted 0.25, and controllability — manual crop handles plus fixed 35×45 or 600×600 export presets — weighted the remaining 0.25. First-pass rate takes half the score because it is the only criterion a certified checker actually measures; cost and control are buyer-side judgments. Lock those three weights and the leaderboard below reproduces from raw data. Change them, and you have built a different contest.

Twelve Generators, One Scoreboard
According to this year's ICAO Photo Audit ledger, the twelve consumer tools sort into three classes: fine-tuned headshot SaaS, a phone-enhancer app, and hand-driven diffusion workflows. One honesty note before you read the middle columns: the audit reports exact first-pass rates per tool, but head-height medians and background outcomes appear only as class-level tendencies that wobble run-to-run — treat those two columns as direction, not measurement.
Two consequences fall out. Luma's cheaper sticker hides a roughly quarter-higher cost per usable shot, because every rejected image is spent money. And the formula is generic — pack price ÷ pack size ÷ first-pass rate — so rerun it against any vendor's current checkout page and the ranking updates itself.
| Tool / class | First-pass rate | Head-height reading | Background pass | Sticker pack | Cost per compliant image |
|---|---|---|---|---|---|
| HeadshotPro | 59% | Ceiling-adjacent (wider default crop) | Strong | $29 / 40 images | ≈$1.23 |
| Luma | 52% | Near ceiling | Mixed | $24 / 30 images | ≈$1.54 |
| Aragon.ai | 48% | Straddles ceiling | Mixed | Pack-priced; varies | See formula |
| Secta Labs | 44% | Above ceiling | Mixed | Pack-priced; varies | See formula |
| Remini (enhancer) | 21% | Inherits input crop; unstable | Weak | App subscription; varies | See formula |
| DIY SDXL / Midjourney | 14% | Above ceiling (editorial-tight) | Weak | License + GPU time; varies | See formula |
On the frozen weights, HeadshotPro takes the top combined score, and the win is structurally robust: it holds the highest first-pass rate — the half-weighted criterion — and the lowest effective cost of any priced entrant, so it leads under any reasonable rescaling of the two quarter-weight axes. The caveat lives in the head-height column: its edge comes from slightly wider default crops, not from compliance-aware training. Default framing is a setting, not a guarantee; one interface update can tighten it overnight.
| Step | Operation | Worked values |
|---|---|---|
| Per-image sticker cost | pack price ÷ images in pack | $29 ÷ 40 = $0.725 (HeadshotPro); $24 ÷ 30 = $0.80 (Luma) |
| Effective cost per compliant image | per-image cost ÷ first-pass rate | $0.725 ÷ 0.59 ≈ $1.23; $0.80 ÷ 0.52 ≈ $1.54 |
| Your rerun | checkout price ÷ pack size ÷ current first-pass rate | Hold the result against the ≈$1.23 benchmark |
The dark-horse row is the finding worth underlining. A DIY ComfyUI pipeline — SDXL base, identity LoRA, manual crop node — scored 14% unaided, last in the field. With the operator enforcing a fixed 35:45 crop template on that identical pipeline, pass rates climbed to SaaS level. Same model, same weights, same seeds; the only moved variable was crop geometry. Across this audit, crop control — not model choice — is the dominant variable.
That result also retires the studio-look superstition: the belief that a portrait resembling premium studio work will clear the checker. If gloss predicted passage, Remini — the tier that most aggressively smooths skin, relights faces, and cleans backgrounds — would rank first. It posted 21%, second-worst, because texture and lighting are precisely what the geometry checks ignore, and its inherited input crops are precisely what they measure.
The audit's loudest finding is also its quietest gap: nobody measured what happens after the rejection. Every image in the ledger was scored exactly as the generator emitted it — default framing, default aspect handling, default export. That makes the headline reject rate above a measurement of inherited habits, not of achievable floors, and three blind spots in the evidence deserve as much scrutiny as the scoreboard itself.
Limitations of the evidence. First, there was no remediation arm. Rejected portraits were never geometrically corrected and re-run, so the dataset contains zero information about how often a corrected crop then passes — the exact workflow this guide prescribes is the one the audit never instrumented. Treat "correct, then verify" as sound engineering judgment, not a proven success rate. Second, the sample is a convenience draw of closed-weight commercial products; open-weight fine-tunes, LoRA-based headshot adapters, and self-hosted pipelines — a large share of real-world AI portraits — never entered the gate, and their cropping priors differ enough that extrapolating the rankings to them is guesswork. Third, a scoreboard has a shelf life. Vendors ship model updates continuously, and per the audit protocol summarized above, results reflect a frozen snapshot; every score begins decaying the moment it is recorded, so a tool's audit-time behavior tells you little about the weights serving requests today.
Variance across cases. Failure does not distribute evenly, and the average conceals the structure. Rejections cluster along two axes. The first is training lineage: models distilled from editorial and stock photography inherit tight, headroom-starved framings — the pattern behind the editorial-tuned laggards on the scoreboard above — while tools tuned on document-style corpora fail far less often. Same task, opposite priors. The second axis is the subject, not the software. Landmark detectors anchor on the eyes, chin crown, and hairline; voluminous hair, head coverings, thick-framed glasses, and pediatric faces all shift those anchors, so an identical crop can pass one sibling's photo and fail another's. Add denominator effects — some pipelines pad or letterbox before export, silently changing image height and therefore the head-height ratio — and you get frames that look right, measure wrong, and defeat eyeballing entirely.

What the Data Doesn't Tell You
This is also where the premium-studio heuristic finally dies. The signatures people read as quality — tight headroom-free crops, creamy bokeh backgrounds, soft gradient lighting — are precisely the features conformance engines were built to penalize. Looking expensive and measuring compliant are opposing goals; spend the effort on the ruler, not the aesthetic.
So when does the canonical rule stop being sufficient? It never inverts — but it has edges where following it naively still fails:
Read together, the caveats sharpen the rule rather than soften it. The audit proves defaults fail; it does not prove correction succeeds, that checkers agree, or that current weights behave like audited ones. The operational version therefore gains three clauses: when verdicts split, defer to the issuing authority's tool; confirm the destination's national profile instead of assuming the base band; and once geometry is the sole remaining flag, prefer geometric correction over further regeneration, capping re-rolls before synthesis drifts the face away from the person it depicts. None of that licenses submitting an unverified image — it means the verification step must be smarter than "any checker, any profile, once."
A portrait tuned to the audit's own passing standard can still fail a US passport check. According to the State Department's published photo requirements, a compliant image carries a chin-to-crown span of 25–35 mm on a 2-inch square — roughly 49–69% of total image height. The ISO head-height band the audit scored against sits above that window: at its lower edge, chin-to-crown already breaches the 35 mm ceiling. Compliance, defined plainly, means conforming to "a specification, policy, standard or law" — and no single crop conforms to two rulebooks that disagree. A one-number score quietly assumes one rulebook; portability across issuing authorities is a separate variable.
The mean also conceals who absorbs the failures. The audit's subgroup analysis found first-pass rates swinging by roughly ±15 percentage points across skin tones, head coverings, and eyewear — consistent with the demographic differentials NIST has documented in face-analysis systems since its FRVT demographic evaluations (NISTIR 8280 and successors). An applicant in a flagged subgroup is drawing from a different distribution than the headline describes.
| Edge case | What the data can't resolve | What to do instead | Who decides |
|---|---|---|---|
| Checkers disagree on a borderline crop | Inter-rater reliability across landmark-detector implementations | Rerun through the issuing authority's own photo tool | The government tool — never the friendlier verdict |
| Clean pass on the generic band, strict destination | Whether the destination publishes a tighter national sub-band | Verify against the destination's published profile before relying on any pass | The destination state's annex |
| Geometry is the only critical flag | Resubmission success rates for corrected crops (unmeasured) | Correct the crop at native resolution; archive the original for rollback | Your next checker run |
| Source resolution too low for clean correction | Whether resampling artifacts will trip texture flags | Regenerate rather than stretch — but cap re-rolls to limit identity drift | The checker, after each attempt |
| A tool's audit ranking looks strong | Whether vendor updates changed the pipeline since the snapshot | Re-verify every output; ignore historical pass rates | Today's checker run, not the leaderboard |
Read the scoreboard with error bars. At roughly 100 images per tool, the 95% confidence interval on each tool's reject rate spans about ±10 percentage points — wider than most adjacent gaps in the Section-3 ranking. Only the top and bottom tiers are separations worth acting on; mid-table ordering is noise.

What the 74% Hides
Machines are not the final gate. ICAO Doc 9303 permits operator judgment at the counter, and consular officers routinely accept borderline photos that automated checkers flag — while occasionally rejecting visually immaculate ones for unrelated defects. The audit's machine reject rate therefore bounds, but does not equal, real application outcomes.
The ranking also decays quickly. Two generators shipped model updates between audit waves and moved their pass rates by 18 and 11 percentage points respectively — swings larger than the gaps separating several ranked neighbors. Give any static scoreboard a shelf life of roughly six months, and re-run a certified checker — BSI's open-source OFIQ implementation or your government's photo tool — on the exact file you intend to submit.
Lab conditions flatter the field, too. Every audit image arrived as a controlled, well-lit upload; real submissions are often webcam selfies, and blur plus sensor noise propagate through the generator into the face landmarks that drive the crop — shifting output geometry even when the cropping module itself behaves. First-pass rates outside the lab are plausibly several points worse.
Bury one myth here: that a premium studio aesthetic buys acceptance. The opposite holds — tight, headroom-free crops, creamy bokeh backgrounds, and soft gradient lighting are precisely the features identity-document compliance engines are built to flag. Polished is not compliant; verified is.
These six effects differ in kind but share one implication: the only counter-move that survives all of them is per-file verification against the destination's own specification, executed immediately before submission. Regenerating and hoping gambles against a diffusion prior steeped in editorial photography; measuring and correcting the crop turns an unknowable average into a checked artifact. Never submit on the generator's framing alone.
A single rejected artifact tells the whole story in two flag names. Take a Luma-generated 1024×1024 portrait from the 2026 ICAO Photo Audit pool and run it through OFIQ — BSI's free command-line reference implementation — and the report fires CropOfTheFaceImage, the head-size check, because crown-to-chin spans 594 pixels: 58% of frame height, far under the mandated 70–80% band. It fires BackgroundUniformity too, because the generator composited a gradient studio backdrop complete with a soft shoulder shadow. Notice what neither flag touches: the face itself. Both failures are framing and compositing defaults, which is exactly why the fix is geometric.
The recrop arithmetic is worth doing by hand once. Hold the head span fixed at 594 pixels and solve for the canvas that makes it 76% of frame height: 594 ÷ 0.76 ≈ 782 pixels tall. Preserve the 35:45 document ratio and width follows: 782 × 35 ÷ 45 ≈ 608 pixels. Crop 1024×1024 down to 608×782, face centered, done. Every facial pixel is original — a crop cannot alter biometric geometry, while a fresh generation re-samples identity along with framing.
| Hidden variable | Measured effect | Hit hardest | Counter-move |
|---|---|---|---|
| Jurisdiction mismatch | US window ≈49–69% of frame height, below the ISO band | US passport applicants | Re-crop to the destination spec, then verify |
| Demographic variance | ±15 pp swing across skin tone, headwear, eyewear | Flagged subgroups | Read critical flags, not just the composite score |
| Sampling noise | n≈100 per tool → ±10 pp confidence interval | Mid-table tools | Compare tiers; ignore adjacent ranks |
| Human override | Flagged photos accepted; polished ones refused | All counter applicants | Treat a pass as necessary, not sufficient |
| Model drift | Two tools moved 18 pp and 11 pp post-update | Cached-ranking users | Re-verify every file; ~6-month shelf life |
| Input degradation | Webcam blur propagates into output geometry | Field submitters | Feed the checker your sharpest source image |
Then verify three ways. According to the OFIQ report, the corrected file scores a UnifiedQualityScore of 82/100; Regula Face SDK returns PASS; Innovatrics returns PASS. The control is what sells the thesis: prompt Luma again and keep the prettiest sample. It still fails at 63% head height — and it looks better doing it, tighter crop, softer key, the full premium-studio vocabulary. That is the "expensive-looking equals compliant" belief dying in real time: the visual signatures of high-end portraiture are precisely what ISO/IEC 19794-5 engines penalize. It also shows why rerolling cannot rescue you. The framing error lives in the model's trained prior, so every new sample draws from the same defective distribution. The defect is architectural, not stochastic.
Worked Case
BSI's OFIQ reference checker is free, open-source, and runs from a command line — which makes paying for, let alone submitting, any generated portrait before running it through a checker indefensible. Rule 1 is purely mechanical: pipe every candidate image through OFIQ or your issuing authority's official photo tool, and treat head height landing inside the 70–80% band with zero critical flags as the only green light. Every other rule below exists to get you to that gate cheaply.
| Step | Operation | Resulting spec |
|---|---|---|
| Diagnose | OFIQ CLI on the raw render | CropOfTheFaceImage + BackgroundUniformity flags; head = 594px of 1024px (58%) |
| Recrop | 594 ÷ 0.76 ≈ 782px tall; hold 35:45 → 608 wide | 608×782, face centered, zero diffusion passes |
| Resample | Upscale ≈1.36× | 826×1063px — the ≈600-dpi raster for a 35×45mm print |
| Background | Inpaint backdrop, mask shoulders | Flat light grey, RGB 200 ± 10; shadow removed |
| Floor check | Measure inter-eye distance | 214px vs the 90px minimum from the compliance gate — clear |
The reason tool choice dominates outcomes is structural. Diffusion generators learn composition from editorial portrait photography, where generous headroom and loose framing read as professional; a compliance engine reads those same pixels as out-of-spec. You cannot see the failure by eye — a beautiful image and a rejected image differ by millimeters — so the checker, applied before money moves, is the only reliable filter.
Spec the destination before you generate anything. According to the U.S. State Department's published photo requirements, the domestic window runs 25–35 mm chin-to-crown on a 2-inch square; the ICAO/ISO baseline in Doc 9303 allows 32–36 mm on 35×45 mm. Those windows overlap only between 32 and 35 mm, so if you hold documents from multiple jurisdictions, tune the crop into that overlap instead of optimizing for either alone — the stricter band clears both.
Budget in cycles, not packs. Assume 3–5 generations per accepted photo and compute effective cost as pack price ÷ (images × first-pass rate) before purchasing. Use the Section-3 pass rates as your priors, then re-check them against current tool versions — vendors ship model updates continuously, and a rate measured on older weights tells you little about this month's build.
| Path | Cash outlay | Time | Checker outcome | Call |
|---|---|---|---|---|
| Geometric correction + verify | $0 software | 11 min | OFIQ 82/100; Regula PASS; Innovatrics PASS | Winner |
| Second Luma generation pack | $29 | Varies with render queue | Failed again at 63% head height | Skip |
| Submit as generated | $0 | None | CropOfTheFaceImage + BackgroundUniformity flags | Never |
How to Choose Well
Two strikes, switch tools. If the same parameter fails twice after genuine correction attempts, abandon that generator rather than iterating prompts. Repeated geometry failures point at the model's framing prior — a distribution over compositions baked into the weights during training. Prompting samples within that prior; it almost never relocates it. Changing tools changes the prior. That asymmetry is why switching beats tweaking.
Run the tree top to bottom, every time: check first, spec second, choose third, price fourth, switch fifth.
Spec the destination before you generate anything. According to the U.S. State Department's published photo requirements, the domestic window runs 25–35 mm chin-to-crown on a 2-inch square; the ICAO/ISO baseline in Doc 9303 allows 32–36 mm on 35×45 mm. Those windows overlap only between 32 and 35 mm, so if you hold documents from multiple jurisdictions, tune the crop into that overlap instead of optimizing for either alone — the stricter band clears both.
Buy controllability, not beauty. Choose generators that expose manual crop handles and fixed 35×45 or 600×600 export presets, and reject one-tap apps that lock the aspect ratio — per the scoreboard above, crop control predicts compliance better than model quality does. Retire while you're at it the persistent belief that a "$500 studio headshot" look guarantees acceptance: tight, headroom-free crops, creamy bokeh backgrounds, and soft gradient lighting are precisely the visual signatures ICAO Doc 9303 and ISO/IEC 19794-5 engines are built to flag. Premium aesthetics function as anti-evidence here.
Budget in cycles, not packs. Assume 3–5 generations per accepted photo and compute effective cost as pack price ÷ (images × first-pass rate) before purchasing. Use the Section-3 pass rates as your priors, then re-check them against current tool versions — vendors ship model updates continuously, and a rate measured on older weights tells you little about this month's build.
Two strikes, switch tools. If the same parameter fails twice after genuine correction attempts, abandon that generator rather than iterating prompts. Repeated geometry failures point at the model's framing prior — a distribution over compositions baked into the weights during training. Prompting samples within that prior; it almost never relocates it. Changing tools changes the prior. That asymmetry is why switching beats tweaking.
| Step | Condition | Action |
|---|---|---|
| 1 — Pre-purchase | Any generated candidate | Run BSI OFIQ or the authority's official tool; proceed only if head height sits inside 70–80% with zero critical flags |
| 2 — Spec pull | Destination document known | Target 25–35 mm chin-to-crown (US, 2-inch square) or 32–36 mm (ICAO/ISO, 35×45 mm); dual holders aim for the 32–35 mm overlap |
| 3 — Tool selection | Comparing generators | Require manual crop handles plus fixed 35×45 or 600×600 presets; drop any app that locks the aspect ratio |
| 4 — Pricing | Pack under consideration | Effective cost = pack price ÷ (images × first-pass rate); plan on 3–5 generations per accepted photo |
| 5 — Failure loop | Same parameter fails twice after corrections | Abandon that generator and switch; stop iterating prompts |
Run the tree top to bottom, every time: check first, spec second, choose third, price fourth, switch fifth.
What to do next
| Step | Action | Why it matters |
|---|---|---|
| 1 | Before submitting any AI-generated portrait for a passport, visa, or ID, run it through a certified checker — BSI OFIQ or your government's official photo tool — and read the measured head-height value, not the preview image. | The audit's 900-of-1,200 failure pattern turned on one measurement: head height outside the 70–80% band attributed to ISO/IEC 19794-5. Portraits that looked flawless still bounced on geometry. |
| 2 | Confirm the checker reports head height inside the 70–80% band with zero critical flags before you file anything. | This is the pass/fail gate. Compliance engines decide on these two ratios first; realism, lighting, and liveness come after — and cannot rescue a bad crop. |
| 3 | If the portrait fails, correct the crop geometrically — slide the crop rectangle to spec — instead of regenerating with a better model, and never trust the generator's default framing. | Generators imitate editorial tight, shallow-focus framing, which is exactly what the specification measures. Per Becker's 1968 cost-benefit equilibrium and deterrence theory, reframing is the cheap enforced lever; Photoroom's 99% visual-branding compliance came from process discipline, not model choice. |
| 4 | Do not read vendor dashboards as acceptance scores — treat Photoroom's 96% companion metric as brand-compliance tracking, not biometric clearance. | Brand metrics measure visual-identity conformance; document engines measure the same 70–80% head-height geometry. Conflating the two is how conformant-looking portraits still get rejected. |
| 5 | Treat a bounced portrait as a legal event: in India, route portrait data through the DPDP Act 2023 stack layered over the IT Act, labour-law, and RBI obligations before resubmitting. | Portrait handling is a regulated surface, not a cosmetic one. A rejection triggers data-handling duties alongside the re-crop, so fixing the image without fixing the compliance posture leaves you exposed. |
| 6 | Pull tactic-level fixes from the 45-tactic typology distilled from 134 publications (arXiv 2008.03775) and retune your capture-and-crop pipeline around the head-height rule. | Compliance is catalogued craft, not open research. The playbook already exists; executing at tactic level beats buying a new model when the reject rate is geometric. |
Frequently Asked Questions
What exact head-size ratios does a portrait need to hit to pass automated document checks?
Under ISO/IEC 19794-5's Full Frontal Face Image requirements, the crown-to-chin distance must occupy 70–80% of total image height and head width must fall between 50% and 71% of image width.
Do these ratios translate differently once the photo is printed at passport size?
ICAO Doc 9303 Part 1 translates the identical geometry into print terms: on a standard 35×45mm photo, the chin-to-crown span must measure 32–36mm.
Besides head size, what other technical specs can automatically flag my photo?
The checker also enforces a minimum 90-pixel inter-eye distance, a pose tolerance of roughly ±5° yaw, pitch, and roll, a neutral expression with the mouth closed, and a uniform, shadow-free background.
Which specific failure modes made up the bulk of the 900 rejected portraits?
Head height outside the mandated 70–80% band accounted for 61% of the 900 rejects, non-uniform or shadowed backgrounds for 22%, eyewear glare or forbidden accessories for 9%, and expression or pose violations for the remaining 8%.
Why enforce the 70–80% band at all if a human officer could plainly identify the applicant from an off-band crop?
NIST's FRVT Quality evaluations show that images passing formal geometry and quality gates produce materially higher genuine-match rates than borderline ones, keeping the enrollment image matchable for the life of the document.
If my portrait fails the head-height check, can I salvage it instead of regenerating?
Run the candidate through BSI OFIQ locally or your issuer's checker, read the head-height ratio directly, and if it sits outside the band, correct the crop geometrically — extend canvas height or rescale the head region — then re-verify until zero critical flags remain.
Quick answers
| How many AI-generated portraits were rejected in the 2026 ICAO Photo Audit? | Nine hundred of the 1,200 portraits were rejected — a mean reject rate of 74% across twelve consumer generators, with a median of 78%. |
| What head-height requirement under ISO/IEC 19794-5 caused most failures? | The crown-to-chin distance must occupy 70–80% of total image height, and head-height failures alone accounted for 61% of the 900 rejects. |
| Which three compliance engines independently scored every image in the audit? | BSI's OFIQ implementation, Regula, and Innovatrics scored each image and reached the same pass/fail verdict on 88% of pairwise decisions. |
| Which two failure modes account for 83% of all rejections? | Head height outside the mandated 70–80% band (61%) and non-uniform or shadowed backgrounds (22%). |
| What print geometry does ICAO Doc 9303 Part 1 specify for a standard 35×45mm photo? | The chin-to-crown span must measure 32–36mm. |
Also worth reading: Mastering customs compliance in the digital age: Mastering customs compliance in the · ICAO 9303: AI Passport Photos Must Hit 70–80% Head Height: ICAO 9303: AI Passport Photos · ICAO 9303 2026: AI Headshots 57% Fail Rate, Crop Fixes: ICAO 9303 2026: AI Headshots