A Regulator Breaks With Its Own Government's Flagship AI Bill
Italy's data protection authority, the Garante per la Protezione dei Dati Personali, has done something unusual: it flagged its own government's flagship AI Act implementation decree as internally inconsistent with the very EU regulation it is meant to transpose. In a formal opinion issued July 14, 2026 on the draft legislative decree adapting Italian law to Regulation (EU) 2024/1689, the Garante gave a conditional green light — but singled out the provision letting police capture and store biometric data from people at protests, sporting events, and other "sensitive locations" for up to seven days before any crime has occurred (Garante opinion, doc. 10275606). A Senate committee cleared the decree regardless, prompting the Garante to restate its objection publicly and the Palazzo Chigi to insist the text is compliant (Biometric Update).
What the Decree Actually Does
The draft decree splits facial recognition into two tracks. Article 8 governs real-time remote biometric identification: it can only be used to confirm the identity of, or search for, a specifically targeted person, requires a prosecutor's motivated authorization, and is capped at 15 days, renewable. That tracks closely with the EU AI Act's own carve-outs. Article 10 is the flashpoint: it allows police to collect and locally store biometric data captured at designated "sensitive locations" — squares, stadiums, public gatherings — for seven days, with matching against that footage triggered only after a crime is confirmed (Garante opinion, doc. 10275606).
The Garante's objection is structural, not cosmetic: collecting biometric templates from everyone present at an event, before any suspicion attaches to any individual, is — in its reading — indistinguishable in practice from the kind of generalized, continuous biometric surveillance the AI Act was built to foreclose, even if the actual facial match is deferred to after an offense. The government's counter is that deferred, post-hoc matching is categorically different from prohibited "real-time" identification, since no comparison against a watchlist happens live.
The Legal Fault Line
The underlying EU rule is unambiguous about scope, if not about edge cases. Article 5(1)(h) of Regulation (EU) 2024/1689 bans "the use of 'real-time' remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement," subject only to narrowly listed exceptions: locating trafficking or missing-persons victims, stopping a specific and imminent threat to life, or identifying a suspect in a serious crime carrying at least a four-year custodial sentence — each requiring prior judicial or independent administrative authorization (Regulation (EU) 2024/1689, Art. 5). Those prohibitions have applied since February 2, 2025, months ahead of the rest of the Act, precisely because Brussels treated live biometric surveillance as the regulation's highest-priority red line. Violations sit in the AI Act's top penalty tier: fines up to €35 million or 7% of global turnover.
Italy's Article 10 doesn't deploy live matching against a watchlist, so it arguably clears the literal text of Article 5. But the Garante's point is that the collection itself — indiscriminate biometric capture of an entire crowd, retained precisely so it can later be searched — is the harm the AI Act's drafters were trying to prevent, and that deferring the match by a few days doesn't change the character of what's been gathered from everyone who showed up.
The Case for the Decree — and Where It Falls Short
The government's position deserves a fair hearing before it's dismissed. Post-hoc, targeted identification of a suspect from footage already lawfully collected at a public event is a genuinely different and lesser intrusion than live, continuous scanning of a crowd against a watchlist — it's closer to how CCTV evidence has always been used in criminal investigations than to dragnet surveillance. Public-order policing at large gatherings is also a real problem Italian authorities are entitled to address, and a seven-day retention window with judicial safeguards on the real-time track (Article 8) is a meaningfully narrower proposal than an unbounded biometric database.
But the distinction collapses under its own design. Article 10 doesn't require any individualized suspicion before collection — it authorizes capturing everyone's biometric data at a designated location on the mere basis that the location might later become relevant to an investigation. That inverts the AI Act's structure, which conditions biometric processing on a prior, specific justification, not a retrospective one. A regulator can only search what was collected, and if collection itself is unconditional, the seven-day retention cap and the post-crime trigger are downstream mitigations, not a cure for an upstream design flaw. Proportionate policing tools are a legitimate goal — but the AI Act's drafters deliberately built the real-time ban around the moment of collection, not the moment of use, for exactly this reason: retention windows can be extended by a future amendment, but data never collected can't later be exploited.
What Happens Next
The decree still needs final Council of Ministers approval, with parliamentary committees holding review authority into the autumn. The Garante's opinion is advisory, not binding — Rome can proceed over its objection, as it appears poised to do. If it does, the European Commission, which enforces AI Act compliance across member states, will face its first real test of whether a national government's creative reading of "real-time" holds up, or whether Italy becomes the Act's first high-profile implementation dispute.