Police forces and civil and criminal liability: here are the relevant regulations
The Legislative Decree amending the AI Act came into force on 30 September. The anthropocentric approach remains in place, with restrictions on facial recognition
Key points
It was published on Tuesday 15 September at Official Gazette. It will come into force on Wednesday 30 September: Legislative Decree 160/2026, which brings national legislation into line with the provisions of EU Regulation 2024/1689 (the so-called AI Act), which establishes harmonised rules on artificial intelligence, concerning the use of AI systems in policing and in relation to civil and criminal liability.
An anthropocentric and risk-based approach
Before analysing the measures contained in Legislative Decree 160/2026, it is worth noting that the Italian approach, like the European one, is and remains anthropocentric. Even when AI is used by the police, the guiding principle is that artificial intelligence serves as a tool to support human intervention and decision-making. Furthermore, the approach is proportionate and risk-based, in that it takes into account the classification of AI systems and the different categories of data subjects. The aim is to increase operational efficiency without undermining the judgement and oversight of human operators. Particularly for high-risk systems, the regulation requires constant human oversight by personnel trained in the use of the technologies to prevent security risks or infringements of privacy and fundamental rights.
Partnerships and training
In Articles 4, 5 and 6, Legislative Decree 160/2026 provides for the possibility for the police forces to enter into agreements and partnerships with universities, research bodies and public or private entities, provided that they ensure the protection of sensitive operational data, prohibiting its direct sharing whilst using aggregated, masked or pseudonymised data. It is also specified that regulatory sandboxes provide the legal basis for testing and developing high-risk AI systems in controlled environments, in collaboration with the Data Protection Authority (which has commented on these issues on several occasions) and the relevant national authorities.
In this context, staff training is essential. To this end, courses are organised at police training colleges to explain the functioning, potential, limitations and risks of artificial intelligence, whilst also addressing ethical issues and the protection of privacy.
Biometric identification
The third section of the new regulation – ‘Artificial intelligence systems used in police work for the tagging, filtering and categorisation of biometric data, for remote real-time biometric identification for the purposes of prevention or protection, and for retrospective facial recognition for the purposes of combating crime’ – is the one that, in recent months, has sparked most controversy and concern both in Parliament and amongst the Data Protection Authority. Handling biometric data with caution is essential both in the use of real-time AI systems and in facial recognition for retrospective purposes: misuse, discrimination, or use for purposes beyond those authorised by the judiciary is possible.

