This is actually what they're building. They publish ZK proofs over the biometric data instead of publishing the biometric data itself.
And they only do irisis.
And they're doing the ZK at the wrong point in the chain. Publishing the actual, raw, unhashed biometrics wouldn't be a problem as long as they didn't tie them to anything but a key. And that future-proofs you.