The Italian Government is moving ahead with legislation to regulate artificial intelligence in law enforcement, raising urgent questions for anyone living in Italy: How will facial recognition affect your privacy when you're walking through city streets? Will police use AI to profile citizens? What protections exist?
Commissioner Elisa Giomi, a member of Italy's broadcasting regulator Agcom, has submitted formal warnings to Parliament insisting that biometric data collection must remain exceptional and that police forces need specialized training before deploying AI tools. Her concerns reflect a fundamental tension: balancing security innovation with the fundamental right to privacy.
What This Means for You Living in Italy
Starting in August 2026, new rules will govern how police can use facial recognition and biometric surveillance—but they're being debated right now. Here's what matters:
• Your face in public spaces: Police will only be allowed to identify you in real-time through cameras in very limited cases—searching for missing persons, preventing imminent serious threats, or identifying suspects in grave crimes. Even then, a judge must approve it.
• Everyday privacy: Authorities cannot build facial recognition databases by scanning social media or collecting data indiscriminately from public spaces. Mass surveillance of your daily movements is prohibited under EU rules.
• What happened before: In 2021, Italy's Data Protection Authority blocked the State Police's "SARI Real-Time" facial recognition system, calling it unlawful mass surveillance—setting a precedent that this new law aims to clarify.
The Debate Over Biometric Surveillance
Giomi, who is also an Associate Professor in Sociology at Roma Tre University and a member of AIRIA's Scientific Committee, submitted a formal contribution to the Constitutional Affairs and Justice Committees of the Chamber of Deputies as they review the draft legislation implementing the EU AI Act (Regulation 2024/1689).
Her position is direct and practical: Algorithmic results are probabilities, not proof. She warned that AI must support human judgment—not replace it. "AI can certainly support law enforcement activities, but it must not turn a probabilistic algorithmic result into certain proof, nor a technological option into ordinary surveillance," she wrote publicly.
The current draft allows remote biometric identification in real-time only in narrow circumstances: searching for missing persons, preventing imminent and serious threats, or identifying suspects in particularly grave crimes. Judicial authorization is required.
However, Italy's Data Protection Authority (Garante) has raised serious objections. The agency flagged a provision that would allow collecting biometric data in sensitive locations for public order purposes—with retention for up to seven days—as potentially violating the EU AI Act. The European Commission has been explicit: widespread surveillance of citizens' daily movements is forbidden.
How Italian Police Will Use AI: The New Requirements
The Italian Parliament is using a legislative decree to transpose the EU AI Act into national law—a procedure that has drawn criticism from opposition parties who argue ordinary legislation would allow more robust scrutiny.
The draft introduces binding requirements for police AI deployment that directly affect how technology will be used:
• Mandatory specialized training for officers on AI limitations, including understanding algorithmic errors and data protection rules—not casual deployment.
• Human oversight documented and traceable: Decisions involving AI must always be assigned to specifically designated personnel and remain human decisions. No automated surveillance.
• People first, technology second: AI is explicitly framed as a support tool. Officers retain personal responsibility and decision-making autonomy.
• Quality data only: Biometric databases must be accurate, lawfully obtained, and cannot be built through indiscriminate web scraping or mass data collection.
Non-compliance carries sanctions, with the Digital Italy Agency (AgID) and National Cybersecurity Agency (ACN) overseeing enforcement.
The European AI Act: What's Banned, What's Allowed
In broader context, the EU AI Act—which entered into force on August 1, 2024—represents the world's first comprehensive legal framework for artificial intelligence. Prohibited practices took effect February 2, 2025, with full enforcement beginning August 2, 2026.
The regulation sets out what law enforcement categorically cannot do:
• Real-time facial recognition in public spaces for routine law enforcement (with extremely limited exceptions).
• Predictive policing based on profiling individuals as likely criminals.
• Using biometric data to categorize people by race, political beliefs, or sexual orientation.
Retrospective identification (finding someone after an event, not in real-time) is not banned but will have additional procedural safeguards from mid-2026.
The Training Gap and Real Implementation Challenges
Giomi emphasizes that police forces must have advanced, specific training before managing AI systems. This concern is not theoretical. Research on law enforcement's use of AI—including the EU-funded ALIGNER project involving police agencies from the Basque Country, Munich, and Sweden—has identified personnel capability as critical for ethical deployment.
Italy's draft requires training on algorithmic limitations and data protection. But the practical details remain unclear: How many hours? What standards? Who delivers training? How is competency verified?
A persistent concern across Europe: facial recognition systems discriminate. These tools produce higher error rates for women, people with darker skin tones, and migrants. Italy's law attempts to address this by requiring high-quality, lawfully obtained training data for AI systems—but whether enforcement mechanisms will be adequate remains under discussion.
What Comes Next
The draft legislation is still under parliamentary review and may be amended following feedback from parliamentary committees, the Data Protection Authority, and civil society organizations.
Key outstanding issues residents should monitor:
• How narrowly "exceptional use" is defined to prevent authorities from gradually expanding surveillance.
• Whether human oversight is meaningful or merely bureaucratic.
• Independent audit mechanisms to ensure transparency and accountability.
• Clear consequences for unlawful use of biometric systems by police.
Italy is attempting to position itself as balancing technological innovation with fundamental rights protection. But the tension between security imperatives and civil liberties remains unresolved. The outcome will shape how Italian citizens experience public space, privacy, and the presumption of innocence in an increasingly AI-mediated society.