Protesters Scanned: Italy’s Quiet Biometric Grab

Close-up of a human eye with digital interface overlay
Photo: Golden Dayz / Shutterstock

Italy’s new AI decree would let police quietly capture and store the biometric data of everyone at a protest or “sensitive” event, even if they have done nothing wrong.

Story Snapshot

  • Draft decree lets police collect and keep biometrics from all people in “sensitive” places for seven days, including protests and stadiums.
  • Government says the rules simply apply the European Union AI Act and are limited to serious threats and post-crime investigations.
  • Italy’s privacy regulator backs parts of the decree but warns the mass data collection at protests may break European Union law.
  • Real-time facial recognition is allowed in public spaces for terrorism and missing-person cases, with a judge’s order and strict time limits.

What Italy’s AI Decree Allows Police To Do

Italy’s Council of Ministers approved a draft legislative decree to govern how police use artificial intelligence and facial recognition for public order and crime control. The text creates two main tracks. First, real-time remote biometric identification of people in public places is allowed only to prevent serious threats, like an imminent terrorist attack or to find missing or trafficked persons, and only with prior judicial authorization. Second, it regulates “post-event” facial recognition that matches faces in already recorded footage to people suspected after a crime.

The real-time track is set out in Article 8 of the decree. A judge must issue a reasoned order that explains the purpose, defines a limited geographic area, and sets a maximum duration of fifteen days, which can be renewed with justification. Matching must use lawful reference databases, and the decree bans databases built by scraping the internet or breaking data protection rules. Supporters say this tight framework keeps live facial recognition as an exceptional tool for clear dangers, not routine street monitoring.

Biometric Data Collection At Protests And “Sensitive” Places

The most contested part is Article 10, which deals with facial recognition after an event and with biometric capture in places tied to public order. Under this article, police can plug artificial intelligence facial recognition into existing video surveillance to identify suspects after a crime, using images already on file, with local data kept for seven days and audit logs held for five years. But paragraph 3 also allows preventive collection and local storage of biometric data from everyone who enters places seen as sensitive for public order and safety, such as squares holding demonstrations, stadiums, train stations, and major events.

Reports say that in these locations, facial images of all passersby may be automatically processed to obtain biometric data, held for up to seven days. If a crime is found during that time, those biometrics become investigative material and can be compared to a suspect’s face. If no crime occurs, the data should be deleted at the end of the seven days. This means someone who only attends a peaceful protest or a soccer match may still have their biometric profile captured and stored “just in case,” even if they are never under suspicion.

Government, Privacy Regulator, And European Union Clash

The government argues this decree simply implements the European Union AI Act and Italy’s enabling law, Law No. 132 of 2025, rather than expanding police powers on its own. Supporters in the Senate’s European policies committee called the text coherent with the European Union Regulation on artificial intelligence and praised new limits on retention and mandatory audit logs. They stress that biometric systems are event-specific, area-specific, and time-limited, not a blanket green light for constant monitoring of all public spaces.

Italy’s privacy watchdog, the Garante for data protection, issued a favorable but conditional opinion on the decree. The Garante accepts the strict, judge-led real-time regime and the separate track for post-event facial recognition with short retention and traceable operations. However, it draws a hard line on mass biometric collection and warns that storing the biometrics of everyone in sensitive locations for seven days risks violating the European Union AI Act’s ban on general facial recognition in publicly accessible spaces. The Garante calls for stronger safeguards and a tighter balance between security needs and what is strictly necessary and proportionate.

Why This Matters For Freedom, Protests, And Police Power

European Union leaders have said that facial recognition in publicly accessible spaces is broadly prohibited under the AI Act, except in narrow, clearly defined cases. Critics across Europe now point to Italy’s decree as a test of whether governments will try to stretch those exceptions into quiet mass surveillance in squares, stadiums, and crowded streets. Media and civil-liberty groups describe the measure as “Big Brother” style control and warn that keeping biometric data from protests can chill free assembly and make people fear being tracked for their political views.

This Italian fight reflects a wider European struggle: police and interior ministries want stronger tools to respond fast to crime and terrorism, while privacy watchdogs and citizens warn that once biometric infrastructure exists, there is strong pressure to keep expanding its use. For Americans who value the Constitution, especially the First Amendment right to protest and the Fourth Amendment guard against unreasonable searches, Italy’s experience shows how quickly “limited” safety tools can become broad data nets over peaceful crowds. It is a reminder to watch closely any attempt to bring similar protest-focused biometric tracking to our own cities.

Sources:

reclaimthenet.org, tg24.sky.it, youtube.com, ictsecuritymagazine.com, instagram.com, ilpost.it, garanteprivacy.it