The case, explained

AI Regulation and Biometrics: The Legislative Path Between Security and Privacy

6 min read · Updated August 2026 · Editorial oversight: Avv. Federico Papa

The issue of real-time facial recognition in public spaces represents one of the most heated battlegrounds between public safety needs and the protection of fundamental rights. According to press reports over recent years, attempts by law enforcement to implement biometric surveillance systems have triggered a complex regulatory process aimed at balancing crime prevention with individual liberty, reaching a crucial phase of European regulatory implementation. In this analysis, we reconstruct the key stages of this development, starting from the blocking measures issued by national authorities up to the final approval of Regulation (EU) 2024/1689. Through the analysis of a specifically reconstructed twin case, we will examine how the new artificial intelligence (AI) rules will transform law enforcement operations and the limits imposed on technology to prevent forms of indiscriminate mass surveillance.

AI Regulation and Biometrics: The Legislative Path Between Security and Privacy

In brief

The approval of the implementing decrees in August 2026 stabilized the Italian regulatory framework for the AI Act, establishing a clear governance structure between AgID and ACN. The transition from general principles to operational obligations introduces reinforced protections, such as the new Article 437-bis of the Penal Code and mandatory judicial authorization for biometric use. This framework provides legal certainty for businesses and data protection for citizens, marking the definitive transition from the legislative proposal phase to the full operational capacity of national supervision.

  1. The fact

    The case stems from the Ministry of the Interior's attempt to introduce the SARI Real Time system for automated facial recognition. According to reports from Agenzia Dire, in March 2021, the Italian Data Protection Authority issued a negative opinion, blocking the initiative due to a lack of legal basis and a violation of the proportionality principle.

    Subsequently, with the Decreto Capienze (D.L. 139/2021), the legislator imposed a moratorium on the use of such systems until December 31, 2025. With the final approval of the AI Act in May 2024, the issue transitioned to an institutional adaptation phase: Italy must now define the procedures for exercising the derogations provided for preventing serious crimes and terrorist threats.

  2. The rules at play

    The central pillar is Regulation (EU) 2024/1689 (AI Act). Art. 5 prohibits real-time remote biometric identification (RBI) in public spaces, allowing exceptions only for specific and exhaustive purposes. These exceptions must comply with Art. 9 of the GDPR, which protects biometric data as special categories of personal data.

    At the national level, Articles 13 and 15 of the Constitution on personal liberties are relevant, imposing the statutory reserve: only Parliament can authorize limitations on such rights. Finally, the Privacy Code (D.Lgs. 196/2003) requires a specific legal basis for any processing carried out by public authorities.

  3. What case law says

    Jurisprudence and supervisory authorities have established strict principles. The Data Protection Authority clarified that indiscriminate biometric surveillance is incompatible with the data minimization principle. The Court of Justice of the European Union has reiterated that any monitoring must be limited to what is strictly necessary and based on objective criteria.

    Furthermore, the European Court of Human Rights has highlighted how the use of facial recognition can act as a deterrent, the so-called *chilling effect*, for citizens intending to exercise their civil rights in public spaces.

  4. Analysis drafted and verified with edit.legal

    To verify the provisions cited in this article, we used edit.legal. Test our legal AI on official sources and apply it to your own matters.

    Try edit.legal AI
  5. What it teaches professionals

    Firstly, the obligation to conduct a DPIA (data protection impact assessment) before implementing AI systems. Secondly, the need to verify the existence of the statutory reserve, as in Italy remote biometrics cannot be based on simple local resolutions.

    Finally, it is crucial to distinguish between ex post identification, allowed for ordinary criminal investigations, and real-time identification, which is subject to much more stringent constraints and a special authorization regime.

  6. Developments: National governance structure and new offenses

    On August 4, 2026, the Council of Ministers gave final approval to the legislative decrees adapting the Italian legal system to Regulation (EU) 2024/1689 (AI Act), completing the process initiated by Law 132/2025. As highlighted by Agenda Digitale and Key4biz, the Italian oversight architecture is based on a dual system: the Agency for Digital Italy (AgID) acts as the Notifying Authority, while the National Cybersecurity Agency (ACN) takes on the role of Market Surveillance Authority. Regarding sanctions, the journal Sistema Penale analyzed the inclusion of Article 437-bis in the Penal Code, intended to punish the failure to adopt security measures in high-risk AI systems. Concerning biometrics, the Privacy Guarantor reiterated that real-time identification by law enforcement remains restricted to exceptional cases and requires prior judicial authorization, prohibiting indiscriminate scraping for biometric databases.

References: Regolamento (UE) 2024/1689 (AI Act)Regolamento (UE) 2016/679 (GDPR)Decreto Legislativo 196/2003 (Codice Privacy)Articoli 13 e 15 Costituzione ItalianaD.L. 139/2021 (Decreto Capienze)

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAMContent drafted with AI support and subject to editorial source checks. Despite these controls, inaccuracies may remain: reports and rectification requests are welcome. Report a correction

Frequently asked questions

What are the penalties for unlawful use of biometric AI?

The AI Act provides for very high administrative fines, which can reach 35 million euros or 7% of global annual turnover for companies, in addition to possible civil actions for damages.

Is facial recognition always prohibited for the police?

No, but real-time use is limited to specific cases (terrorism, searching for victims, serious crimes) and requires prior authorization from a judge or an independent authority, except in cases of extreme urgency.

What can a citizen do if they suspect abusive biometric surveillance?

A complaint can be filed with the Data Protection Authority or an action can be brought before the ordinary judicial authority to request the cessation of processing and possible damages.

Verified legal research and drafting with edit.legal

Legal research and drafting with citations checked against official databases. edit.legal is free to try, no credit card.

Try edit.legal for free