Italy Italy Garante GDPR AI enforcement

Italy's Privacy Regulator Conditions AI Act Policing Rules on Banning Mass Biometric Collection

Italy's Garante approved the AI Act policing decree only after demanding a ban on mass biometric collection and ex-post-only facial recognition.

Italy's AI Act Policing Decree, By the Numbers People of Internet Research · Italy Jul 14, 2026 Garante opinion issued Conditional approval demanding str… Sep 30, 2026 Policing decree in force Legislative Decree 160/2026 took e… 4 sectors High-risk sectors covered Garante becomes market-surveillanc… €20 million Prior Clearview AI fine 2022 sanction for scraped biometri… peopleofinternet.com
Italy's AI Act Policing Decree, By the… People of Internet Research · Italy Jul 14, 2026 Garante opinion issued Sep 30, 2026 Policing decree in force 4 sectors High-risk sectors covered €20 million Prior Clearview AI fine peopleofinternet.com

Key Takeaways

A conditional yes, not a rubber stamp

On July 14, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, issued a formal opinion on the government's draft decree implementing the EU AI Act's rules for police use of artificial intelligence. The opinion, made public on July 29, gave qualified backing to the sections governing how Italian police may deploy AI systems, including biometric identification and facial recognition — qualified being the operative word. The Garante flagged specific gaps it said the government needed to close before the rules could be considered genuinely AI Act-compliant.

The decree itself is now Legislative Decree No. 160/2026, published in the Gazzetta Ufficiale (Official Gazette n. 214) on September 15, 2026 and in force since September 30. It implements Italy's enabling Law 132/2025 and sets out when police can use AI for investigative and public-safety purposes, alongside new rules on civil and criminal liability for AI system failures. It is one of the first national statutes in the EU translating the AI Act's law-enforcement provisions into operational law, which is exactly why the Garante's specific objections matter well beyond Rome.

What the regulator actually asked for

The opinion was narrow and technical, not a blanket objection to police AI. Four requests stand out:

These are precise, implementable conditions, not open-ended alarm. Italy's regulator is trying to operate as a technical gatekeeper on a live statute, not a rhetorical critic of policing technology in general.

The case the regulator is making

Steelmanning this first: facial recognition systems have a documented history of higher error rates on darker-skinned faces and women, and a database built by scraping the open web inherits every bias and every consent violation baked into that scrape. This is not hypothetical for the Garante — it fined Clearview AI €20 million in February 2022 for building exactly that kind of database from social media images of Italians without consent. A police force with an always-on camera network and a "just in case" biometric database creates the infrastructure for generalized surveillance regardless of any individual search's intent; once that infrastructure exists, mission creep tends to follow. The EFF's recent reporting on U.S. police departments instructing officers to obscure their use of license-plate readers and camera networks from courts and the public is a useful cautionary parallel: opacity around these tools, once installed, tends to compound rather than self-correct. A regulator insisting on ex-post, targeted use with a traceable human decision behind every match is trying to foreclose that trajectory before Italy's system goes live, not after.

Where the balance should land

That case is real, but it doesn't require throttling the tool to the point of uselessness — and notably, the Garante isn't asking for that. Post-event facial recognition against a specific, already-collected recording, tied to an actual investigation with a traceable human sign-off, is a proportionate and useful capability: closer to a faster fingerprint match than to a surveillance dragnet. Investigators working a bombing, a kidnapping, or an organized burglary ring benefit enormously from being able to search existing footage for a known face. Denying police that tool on principle — treating any biometric capability as inherently dystopian — would be a worse outcome for public safety than the narrow, audited version the Garante is describing, and it isn't what the regulator itself is arguing for.

The risk to watch is implementation, not the statute's text. Decree 160/2026 reads as compliant with the Garante's core asks — no live dragnet, ex-post search only, human sign-off required — but a law that bans "indiscriminate scraping" is only as good as the audits that catch it when a procurement office buys a vendor tool trained on exactly that. Other EU member states drafting their own AI Act police-use implementing rules should treat the Garante's four conditions as a working checklist rather than a debate to relitigate from scratch. Getting the boundary right once, in statute, is far cheaper than litigating scope creep case by case later.

Sources & Citations

  1. Garante Privacy — AI Act opinion newsletter
  2. Normattiva — D.Lgs. 9 settembre 2026, n. 160
  3. Il Sole 24 Ore (NT+ Diritto) — Garante conditions on AI Act decree
  4. EFF — Cops Play Hide and Seek About Using Spy Tech