Digital identity

Facial recognition and beyond: the challenges of biometrics

Following the political debate, the growing use of technology raises the issue for public administrations, businesses and legislators of balancing trust and security

 Adobe Stock

4' min read

Translated by AI
Versione italiana

4' min read

Translated by AI
Versione italiana

Following the controversy over the risks associated with rights and privacy, the introduction of safeguards for biometric identification in real time and facial recognition after the event. The Government has thus taken action on a particularly sensitive issue: the use of artificial intelligence systems in police work. Last week’s Council of Ministers meeting gave final approval to two legislative decrees bringing national legislation into line with EU Regulation 2024/1689, which establishes harmonised rules on AI, in implementation of Law 132/2025 (see *Il Sole 24 Ore* of 5 August).

 The most hotly debated parts of the decree on police activities and civil and criminal liability centre on Article 8 – on real-time identification in public places or places open to the public – and 10 – which concerns CCTV systems already in place, which may be equipped with AI software capable of activating facial recognition.

Loading...

In the first case, the Government has decided that biometric identification in real time is permitted only in exceptional cases, for limited periods and subject to authorisation by the judicial authority – the public prosecutor – whilst the creation of biometric databases through the mass, non-targeted collection of information from the web (known as scraping) is prohibited.

With regard, however, to the regulations governing video surveillance systems with facial recognition carried out retrospectively, the minimum requirements for the reference database have been defined, and the obligations regarding data erasure and the guarantees that the data used for biometric comparison cannot be expanded have been clarified. Here too, a judicial review by the public prosecutor has been introduced.

The European ecosystem

With these latest developments, Italian policy is therefore incorporating, for the first time, biometric technologies into the law enforcement system, whilst reiterating that the use of AI models in police work must remain subject to human oversight. It is doing so within the framework of a European project aimed at regulation and harmonisation of new technological tools, whether for public security or digital authentication. The European Union is, in fact, building an ecosystem in which cybersecurity, digital identity and artificial intelligence are no longer separate matters. The NIS2 Directive, the Cyber Resilience Act, the GDPR, the AI Act and eIDAS 2.0 set out a framework aimed at making digital infrastructure more secure and, at the same time, enabling citizens to use a digital identity recognised throughout the Union – by the end of this year, the 27 Member States will have to issue their citizens with the European digital identity wallet.

The Italian transposition

In Italia, this process involves the National Cybersecurity Agency, SPID, the electronic identity card and the transposition of NIS2. “Today, the problem is not so much the absence of regulations as their fragmentation, which gives rise to numerous issues of interpretation that businesses and public administrations find themselves having to deal with, often with uncertainty,” notes Luigi Fimiani, a lawyer, researcher at the Sant’Anna School of Advanced Studies and head of research on Identity, Identification and Technologies, a project also coordinated by the Deputy Vice-Chancellor of Sant’Anna, Gaetana Morgante, and researcher Giuseppe Di Vetta.

This view is shared by Carlo Nardello, president of COM.TEL. and head of the Research Centre, who believes that ‘the real challenge is not to chase after technology, but to build a framework of trust that allows innovation to be adopted within a clear regulatory framework’. It is precisely this need that gave rise to the research commissioned by the COM.TEL. Research Centre from the Sant’Anna School of Advanced Studies: to offer businesses and institutions practical tools to navigate a context that is evolving more rapidly than regulation.

Particularly when it comes to biometric technologies, such as fingerprint scanners or facial recognition, where the balance between risks and opportunities, everyday use and privacy protection, information management and data security, must be carefully weighed up.

Areas of application

Biometric applications, moreover, are already a reality in numerous sectors – from access to critical infrastructure to airport security checks, from banking onboarding to healthcare – improving the security and efficiency of processes. According to the Imarc Group’s 2026–2034 report, the Italian biometrics market was worth approximately $1.2 billion in 2025, with growth projected to reach $3.85 billion by 2034. In 2025, facial recognition accounted for around 34 per cent of the market share, whilst contact-based systems, such as fingerprints, accounted for 38 per cent. Geographically, the North-West led the market with a 25 per cent share, thanks to the concentration of financial institutions and technology companies, confirming that biometrics is becoming an established and strategic tool for authentication in Italian business processes.

Responsibility and trust

“The key issue is not to ban these technologies, but to clearly define who is accountable for decisions and any damage throughout the supply chain: manufacturers, developers, suppliers and users,” observes Fimiani, pointing out that it is precisely on this point that the European regulatory framework still has room for development. For Nardello, the issue is also an industrial one: “Europe can turn regulation into a competitive advantage if it manages to build trust. Security must not be perceived as a compliance cost, but as a factor that increases the value of technologies and encourages their adoption.” To this end, a dialogue-based model of proactive collaboration between businesses and the relevant public bodies is proposed, with shared risk management systems capable of reducing regulatory uncertainty.

Loading...

Because the challenge over the coming months and years will not centre on usage but on reliability. The question is not whether biometrics will become a permanent feature of digital services: it is already present in many areas. The real challenge will be to build trust in digital identity.

According to Fimiani, this means strengthening the principles of privacy by design, protecting data throughout the entire technological supply chain and overcoming the current grey areas through ongoing dialogue between regulators and businesses. Nardello also believes a cultural shift is needed: ‘Technology is advancing much faster than public awareness. This is why research, training and dialogue between the public, universities and businesses must accompany innovation, ensuring that the debate is not reduced to a conflict between security and privacy’. The aim, therefore, is to transform research into a practical tool capable of helping legislators and businesses to manage one of the most significant transformations of the digital economy.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti