A decree that collects first, asks questions later
On July 29, 2026, a Senate committee cleared a decree provision that lets Italian police preemptively capture and store biometric data — facial images pulled from video surveillance — on everyone entering a location the government designates as sensitive for public order: a demonstration, a stadium, a railway station, a concert. The data sits for seven days. If a crime occurs in that window, it becomes investigative material. If nothing happens, it is deleted (ANSA).
Within hours, Italy's own data protection authority, the Garante, confirmed it had already flagged the mechanism. In a formal opinion dated July 14, 2026 on the schema implementing Regulation (EU) 2024/1689 — the AI Act — into Italian law, the Garante gave conditional approval to the broader decree but singled out this provision, warning that the automatic, indiscriminate processing of biometric data from everyone accessing a public place or event is not coherent with the AI Act, which is built around targeted, post-event searches rather than mass collection (Garante Privacy opinion, Registry No. 531). Premier Giorgia Meloni's office pushed back the same day, insisting Italy "will continue to comply with European regulations regarding facial recognition in accessible public spaces" and noting it was the first EU member state to adopt and implement a comprehensive AI Act framework (ANSA).
The steelman: a state does have to plan for the worst
The government's case isn't frivolous. Bologna and the Susa Valley have both seen serious public-order unrest this year, and stadium violence remains a persistent enforcement problem across Italian and European football. Investigators genuinely lose ground when they can only start pulling footage after a crime is already reported — by then, faces have moved on, camera loops have overwritten, and witnesses have scattered. A short, bounded retention window that auto-deletes if nothing happens is, on its face, a more modest ask than a permanent biometric database: it's closer to a fire drill than a panopticon, and seven days is not indefinite. If the aim is genuinely to solve stadium brawls and riot injuries after the fact rather than to build a standing watchlist of protesters, there's a real operational argument for it.
Why the Garante's line is the right one anyway
The problem is that the EU AI Act didn't ban indefinite biometric surveillance of public spaces — it banned real-time and generalized biometric identification in them, full stop, with only narrow, judicially authorized exceptions. Article 5(1)(h) of Regulation (EU) 2024/1689 prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, permitting it only for targeted searches for specific abduction or trafficking victims, imminent threats to life, or the pursuit of a suspect already tied to a serious listed offense — and even then only with prior judicial or independent administrative authorization (EUR-Lex, Regulation (EU) 2024/1689). Those prohibitions have been in force since February 2, 2025. The decree's own domestic post-event mechanism — activated only after a crime, with Ministry of Interior control and Garante consultation — already tracks that logic reasonably well, per Italy's June 10, 2026 implementing decrees, which explicitly reject mass or untargeted biometric surveillance and cap local retention at seven days (Gaming Tech Law).
The provision the Garante is objecting to breaks that logic at the front end. It doesn't wait for a crime, a suspect, or a judicial order — it captures and stores biometric data on everyone who shows up, on the theory that a crime might happen later. That inverts the Act's structure: targeting becomes retroactive rather than a precondition. A demonstrator who never breaks a single law still has their face harvested and held for a week simply for attending. That's not investigative necessity; it's a standing capability to build a profile of who attends protests, applied indiscriminately and then quietly deleted before anyone notices — unless something happens to go wrong, in which case the data was there all along.
The precedent problem
Italy isn't a stranger to overreach on biometric data — its Garante fined Clearview AI €20 million in March 2022 for unlawfully scraping and processing Italians' facial and geolocation data without a legal basis. The regulator has form here, and its skepticism of blanket biometric capture is consistent, not opportunistic. That consistency is precisely why this dispute matters beyond Rome: Italy was the first EU state to fully operationalize the AI Act domestically, and other capitals are watching how much elasticity the "public security" carve-out actually has. If a national regulator's own conditional-approval opinion can be overridden by a government that simply asserts compliance, the AI Act's public-space biometric ban is only as strong as each member state's willingness to listen to its own watchdog — a weaker guarantee than the regulation was written to provide.
The fix is not to abandon post-event facial recognition for genuine public-order threats; Italy's broader framework, judicial authorization requirements, and seven-day cap on the post-crime mechanism are a defensible model. It's to strike the pre-emptive, everyone-gets-scanned trigger and replace it with what the Act already demands: authorization tied to a specific, articulable threat, not attendance at a lawful gathering.