Operational notes Regulation

Police facial recognition in Italy: which use will need a judge’s authorisation?

8 min read

A white CCTV camera fixed to a concrete wall, shot from below against the light, in black and white
The promised fix concerns whoever points it in real time at a specific person. The one left running above a stadium entrance follows a different rule, and for now nobody is proposing to change it.

On 31 July 2026, on the margins of a meeting at the Prefecture in Naples, Undersecretary Alfredo Mantovano said a sentence that promises to amend Italy’s decree on police facial recognition: “we are making explicit what, for us, was self-evident — that it requires the magistrate’s authorisation.” He did not say which of the three authorisation channels already written into the decree would be affected. The question is not rhetorical: we have already mapped the decree’s structure, and one of those three channels — precisely the one that stadiums and large events would actually use — currently requires neither a judge nor a prosecutor.

The facts of the last three days

On 30 July the Chamber of Deputies’ European Union Policies Committee (Committee XIV, responsible for opinions on EU-law compatibility for Government Bill No. 418) unexpectedly postponed the vote on its own findings. The following day a European Commission spokesperson stated, according to several Italian outlets: “Facial recognition in publicly accessible spaces is a practice banned by the AI Act.” Palazzo Chigi replied the same day: “On facial recognition in publicly accessible spaces, Italy will continue to comply with European law, starting with the AI Act.” A few hours later Mantovano announced the correction, aiming — the same sources report — to have it ready for the Council of Ministers meeting of 4 August 2026: two days from now.

Three channels, three different levels of authorisation

The text transmitted to Parliament on 24 June — we have read it article by article — does not have a single authorisation regime for biometric identification. It has three, and keeps them distinct.

Article 8: real-time biometric identification for prevention purposes or to search for missing persons and victims of specific crimes. The authorisation is requested by the police commissioner or the provincial commander from the public prosecutor, for a specific event and for a period “not exceeding fifteen days, renewable”; in urgent cases the system may be switched on following even an oral request to the prosecutor, who decides within 24 hours.

Article 359-ter of the Code of Criminal Procedure (inserted by Article 14): identification or location, within criminal proceedings, of persons suspected of offences punishable by at least four years’ imprisonment, or of fugitives. Here the request is made by the public prosecutor, but the decision rests with the preliminary investigations judge, by reasoned decree, again within the fifteen-day renewable window.

Article 10: after-the-fact facial recognition on video-surveillance systems, to identify persons already suspected of an offence on the basis of recorded footage. Here neither a prosecutor nor a judge appears: the data controller — by law, the Ministry of the Interior — carries out an impact assessment and “consults the Garante”, after which use falls under the direct responsibility of the officer designated by the police commissioner.

Three different control thresholds for three different uses. And here the reporting stops helping: the two major outlets that broke the story on 31 July headlined it differently. La Stampa wrote “A judge’s authorisation will be required”, which points to the real-time channel; Il Sole 24 Ore headlined “AI and video surveillance: examining the footage will require a magistrate’s authorisation” — and “video surveillance” and “examining the footage” are the language of Article 10, not Article 8. Which of the three regimes will be amended cannot, as things stand, be established from any public source. This is not a technicality: a prosecutor authorising for fifteen days, an investigating judge, and an officer designated by the police commissioner are three different models of accountability, and whoever installs the system needs to know which one they will fall under.

The channel stadiums would actually use is the one without a judge

Article 10, paragraph 12, says something that concerns anyone whose business is not public order: the installation and maintenance of the systems may be carried out by the operators of the venues, or by the organisers or promoters of the events — a stadium, an arena, a trade fair — who then hand them over “on free loan to the police headquarters”, which acquires “complete and exclusive availability” of them. Paragraph 3 adds that entry triggers the automated processing of the biometric data of anyone entering the venue or event, not only of whoever will later be sought: the comparison database is built first, and the suspicion arrives afterwards, if it arrives at all.

This is exactly the point the Garante had already flagged in opinion no. 531 of 14 July, asking for the privacy role of whoever installs the system to be clarified. But this week’s debate — Brussels, Palazzo Chigi, Mantovano’s announcement — has focused on the real-time channel, the one least likely to run through a private operator’s own installation. If August’s correction adds a judge only to Article 8, the regime a venue operator would actually use — Article 10 — is left with nothing more than the impact assessment and the Garante consultation as the only counterweight currently written into the text.

Why it matters even if you do not run a sports venue

You do not need to run a stadium to be caught by the same logic. Anyone who supplies or hosts a video-surveillance system with AI components on behalf of public security — an airport, a railway station, an exhibition centre, an industrial plant under the National Cybersecurity Perimeter — inherits the same three questions: which article applies to your case, who is the data controller even when the hardware is yours, and what record survives if a judge — or the Garante — one day asks to account for an identification. Waiting for the political fight over Article 8 to settle solves nothing for whoever will end up operating under Article 10.

What to do now

If you operate or supply an installation that could fall under Article 10, paragraph 12: put in writing, before the decree is finalised, who will be the controller and who the processor of the data — the text currently leaves this implicit, and it is exactly what the Garante has challenged. Prepare the fundamental-rights impact assessment required by Article 27 of the AI Regulation before the system is switched on, not after an inspection. Keep the decree’s two clocks separate: the biometric data collected must be erased after seven days, while the access log files must be kept for five years, unmodifiable — conflating the two is the easiest mistake to make reading the text too quickly. And watch 4 August: if the correction touches only Article 8, knowing that before writing it into a contract saves you from promising a judicial safeguard the text does not yet contain.

How we solve it

The problem is not deciding whether a judge is needed: it is knowing, article by article, which rule applies to the system you have switched on, and being able to prove it when someone asks — a Garante inspection, a request from police headquarters, a judge verifying a piece of evidence. We build the control that runs on your installation’s own logs — not an opinion that ends once the decree has been read — one that tells the seven days of the data apart from the five years of the logs on its own, flags a missing or expired authorisation, and prepares the file before anyone asks for it.

The same system holds together, in a single operating model, the data that today stays scattered between venue operator, police headquarters and Ministry — who installed it, who authorised it, who actually looked at that image — so that an AI proposes the match while an operator in command always remains the one who confirms it: it is the very principle Article 10, paragraph 9, already writes into the decree on its own, banning any decision based solely on the output of facial recognition. We do this for government and defence bodies as much as for large private operators of plants and infrastructure, always in two modes available together: on-premise, on self-contained machines that stay inside your own perimeter without deep integration into your existing network, or CSIDIA dedicated cloud — access over a reserved VPN, data centre in Italy, premises we staff ourselves.

Do you operate or supply a system that could fall under Article 10 of the facial-recognition decree? Half an hour with one of our experts is enough to work out which regime applies to you today, before the final decree tells you.

Sources

The statements by Mantovano, by the European Commission spokesperson and by Palazzo Chigi are as reported in the press: as at the date of publication no official text containing them exists. The content of the decree, by contrast, is verified against the text tabled in the Chamber of Deputies.