Italy is racing to become the first EU member state to fully transpose the bloc's Artificial Intelligence Act into domestic law. On July 14, 2026, its own data protection authority told the government that the flagship piece of that effort — the decree governing police use of facial recognition — does not do what the AI Act actually permits.
What the Decree Does
The measure, formally Atto del Governo n. 418, implements Law 23 September 2025, n. 132, which delegated the government to align Italian law with EU Regulation 2024/1689 (the AI Act) by October 10, 2026. Title I of the decree authorizes police to integrate AI-driven facial-recognition components into video surveillance already installed at locations designated for public-order reasons — squares, stadiums, railway stations, and streets during demonstrations, marches, sporting events, and concerts. At any such "sensitive site," cameras could capture and convert the faces of everyone present into biometric templates, retained for seven days. If no offense is flagged in that window, the data is deleted automatically; if one is, investigators can run comparisons against it.
The government's defense rests on a sequencing argument: collection and matching are separate legal moments, and only the second — searching for a specific suspect — triggers the AI Act's law-enforcement safeguards. The Garante, in its formal opinion on Titles I and III of the decree, rejected that framing. The regulation, it wrote, is "not coherent with" the AI Act, which permits post-event facial recognition "only for targeted searches" of persons already suspected or convicted of a crime, and only against footage already lawfully recorded — not a standing, generalized capability to biometrically fingerprint every attendee of a lawful gathering.
Processing should occur "exclusively on recordings already acquired and in the presence of a specific operational need, avoiding massive and preventive collections."
That maps onto Article 26(10) of the AI Act itself, which requires deployers using post-remote biometric identification for law enforcement to obtain judicial or administrative authorization — ex ante or within 48 hours — tied to a criminal offense, proceeding, genuine threat, or missing-person search, and bars untargeted use with no such link.
The Case for the Decree — Fairly Stated
The government's underlying concern is real. Stadium violence involving organized ultras, and the risk of attacks at mass gatherings, are genuine public-safety problems, and other EU states have used retrospective facial recognition to identify rioters and attackers after the fact — a capability civil-liberties groups themselves generally accept when it is narrowly targeted. A seven-day, auto-deleting window with a five-year audit-log requirement (one of the safeguards the Garante itself asked to have written into the text) is a meaningfully more constrained design than indefinite retention or unlogged use. If the only alternative is a police force scrambling to obtain footage after violence has already occurred, faster identification of specific perpetrators has genuine public value, and the government is not wrong that speed matters in these cases.
Where the Design Breaks Down
The flaw is that the AI Act's safeguard attaches to the processing of biometric data, not merely to the moment a name gets attached to a face. Converting every attendee's face into a searchable biometric template — before any offense exists, before any judicial authorization, before any specific target is identified — is itself the act the AI Act circumscribes. Relabeling that step "collection" rather than "recognition" does not change what happens to the data: a government agency builds a week-long, comprehensive biometric index of everyone who showed up to a protest, a football match, or a concert, on the chance that someone might commit a crime.
That has consequences beyond privacy on paper. Italian commentary on the decree has flagged that the mere perception of being biometrically catalogued at a demonstration chills the willingness to attend one — turning a public-safety tool into a quiet tax on assembly and speech, the exact harm the AI Act's targeted-search requirement was built to prevent.
What Should Happen Next
The Garante's opinion was not an outright rejection — it was, on the whole, favorable, asking for textual fixes rather than withdrawal. Those fixes are not exotic: require that biometric feature extraction happen only after a triggering offense, limit it to footage already lawfully recorded, and write in the non-incrementality and deletion guarantees the authority requested. That is a narrower, more defensible bill than the current draft, and one still capable of giving police the speed advantage the government wants.
The stakes reach past Italy. MEP Brando Benifei, the European Parliament's AI Act rapporteur, has announced an urgent question to the European Commission over the decree, warning it risks legitimizing mass biometric collection "contrary to the spirit" of the regulation Italy is nominally implementing. The Senate's EU Affairs Committee nonetheless cleared the text on July 29, 2026, over opposition objections, and it now moves through further committee review at the Chamber before a final return to the Council of Ministers ahead of the October 10 deadline. If Italy's flagship transposition law survives with the mass-collection language intact, it hands every other member state a template for redefining "targeted search" out of existence — precisely the drift the AI Act's drafters tried to foreclose.