A Conditional Yes, Not a Veto
On July 14, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, issued Opinion No. 531 — a "favorable opinion with conditions" on Titles I and III of the legislative decree implementing the EU AI Act (Regulation 2024/1689) domestically (Garante Opinion 10275606). The decree, drafted under the delegation in Law 132/2025, governs how Italian police and investigators may deploy AI systems, including biometric identification. The Garante did not block the decree. It approved the underlying framework while flagging specific provisions — chiefly automatic, blanket biometric collection at public venues — as incompatible with the AI Act itself.
That distinction matters. This is not a privacy regulator obstructing digitization for its own sake; it is a regulator checking whether the government's implementing text actually complies with the EU law it claims to implement.
What the Decree Would Have Allowed
As drafted, the decree let police designate "sensitive" locations — public squares, stadiums, railway stations, and streets during demonstrations, sports events, or concerts — where facial biometric data of everyone entering would be captured automatically and retained for seven days. If a crime occurred within that window, police could search the stored biometric data against known suspects; otherwise, it would auto-delete (Reclaim The Net). Authorization for a search would come from a police commissioner's appointee, not a judge.
The Garante's objection was precise: the AI Act's Article 5(1)(h) bans real-time remote biometric identification in publicly accessible spaces for law enforcement, carving out only narrow exceptions — searching for trafficking victims or missing persons, preventing imminent terrorist threats, or identifying suspects in serious crimes carrying four-plus-year sentences — each requiring prior judicial or independent administrative authorization (artificialintelligenceact.eu, Article 5). Blanket, preventive collection of everyone's biometrics on entry to a stadium is not a targeted search; it is exactly the dragnet the Act's drafters wrote Article 5 to forbid. The Garante's opinion states that biometric processing should occur "exclusively on recordings already acquired and in the presence of a specific operational need, avoiding massive and preventive collections" — ex post, targeted, and justified, not continuous and automatic.
Steelmanning the Government's Case
The government's position deserves a fair hearing before it is dismissed. Italian stadiums have a genuine hooliganism problem, and European capitals have faced a real wave of coordinated unrest at demonstrations and transit hubs. A seven-day retention window with automatic deletion is not indefinite surveillance, and requiring pre-designation of "sensitive" locations is at least an attempt at proportionality rather than nationwide always-on scanning. Law enforcement agencies also have a legitimate interest in being able to move quickly — 24-hour emergency authorization windows exist in the AI Act itself precisely because a judge is not always reachable in real time during a fast-moving public-safety incident.
But the decree's core defect is structural, not a matter of degree: it authorized collection of everyone's biometric data as a precondition for later, narrower search — inverting the AI Act's default. The Act permits identification of specific individuals for specific purposes; it does not permit hoovering up a crowd's faces on the chance that a match might later be useful, then calling the retrospective search "targeted" because only some of the data gets queried. A commissioner's appointee, not a judge, authorizing the search compounds the problem: the AI Act's exceptions for law enforcement biometric ID hinge on independent authorization precisely to prevent police self-certifying their own surveillance.
Beyond Biometrics: A Regulator Asking for Standing
The opinion's other conditions read less as objections to the decree's substance and more as the Garante asking not to be sidelined in its own domain. It wants explicit authority to issue guidelines and best practices "on par with" Italy's other AI Act authorities (AgID, which is the national notifying authority, and ACN, the market surveillance authority for high-risk systems) rather than being treated as a junior consultee (Federprivacy). It also asked to be formally "associated with" Italy's national AI regulatory sandbox wherever a project touches personal data, and it flagged that reference databases used for biometric matching need enforceable quality standards and "non-incrementality" guarantees — so a single search authorization cannot function as backdoor access to an ever-expanding comparison set.
What Happens Next
The decree is not final. The Senate's European Affairs Committee cleared the text on July 29, 2026, but a Chamber committee vote was postponed after objections within the governing coalition (Reclaim The Net). Additional committee opinions are due before the decree returns to the Council of Ministers, which must adopt it by October 10, 2026, when the delegation authority under Law 132/2025 expires.
For a publication skeptical of regulatory overreach, this case is a useful reminder that not every privacy intervention is anti-innovation friction. The Garante is not asking Italy to abandon police AI tools; it is asking the government to implement the AI Act as written rather than smuggling in a surveillance power the Act's own drafters expressly prohibited. Getting the transposition right the first time — rather than passing a decree likely to draw an EU infringement action or a constitutional challenge — is also the faster path to durable, usable law enforcement AI tools in Italy.