Facial recognition and beyond: the challenges of biometrics
Following the political debate, the growing use of technology raises the issue for public administrations, businesses and legislators of balancing trust and security
Key points
Following the controversy over the risks associated with rights and privacy, the introduction of safeguards for biometric identification in real time and facial recognition after the event. The Government has thus taken action on a particularly sensitive issue: the use of artificial intelligence systems in police work. Last week’s Council of Ministers meeting gave final approval to two legislative decrees bringing national legislation into line with EU Regulation 2024/1689, which establishes harmonised rules on AI, in implementation of Law 132/2025 (see *Il Sole 24 Ore* of 5 August).
The most hotly debated parts of the decree on police activities and civil and criminal liability centre on Article 8 – on real-time identification in public places or places open to the public – and 10 – which concerns CCTV systems already in place, which may be equipped with AI software capable of activating facial recognition.
In the first case, the Government has decided that biometric identification in real time is permitted only in exceptional cases, for limited periods and subject to authorisation by the judicial authority – the public prosecutor – whilst the creation of biometric databases through the mass, non-targeted collection of information from the web (known as scraping) is prohibited.
With regard, however, to the regulations governing video surveillance systems with facial recognition carried out retrospectively, the minimum requirements for the reference database have been defined, and the obligations regarding data erasure and the guarantees that the data used for biometric comparison cannot be expanded have been clarified. Here too, a judicial review by the public prosecutor has been introduced.
The European ecosystem
With these latest developments, Italian policy is therefore incorporating, for the first time, biometric technologies into the law enforcement system, whilst reiterating that the use of AI models in police work must remain subject to human oversight. It is doing so within the framework of a European project aimed at regulation and harmonisation of new technological tools, whether for public security or digital authentication. The European Union is, in fact, building an ecosystem in which cybersecurity, digital identity and artificial intelligence are no longer separate matters. The NIS2 Directive, the Cyber Resilience Act, the GDPR, the AI Act and eIDAS 2.0 set out a framework aimed at making digital infrastructure more secure and, at the same time, enabling citizens to use a digital identity recognised throughout the Union – by the end of this year, the 27 Member States will have to issue their citizens with the European digital identity wallet.

