This is a really key problem. The main application of biometrics today is in cell phones, and for those we operate on the assumption that we're trying to distinguish between the authorized user and a quite small pool of non-authorized people who will have physical access to the device: family members, friends, co-workers, and the occasional thief. This threat profile allows the biometric algorithm to err on the side of usability—it's more important that the algorithm consistently open the phone when shown the user's fingerprint or face than it is that there be no other human being on the planet who could open it.
Worldcoin has a very different threat profile, and it's not obvious to me that is possible to have a usable biometrics system (with an acceptably low false negative rate) that also has absolutely zero risk of hash collisions when the pool of unique people you need to distinguish is the size of the entire planet.