A concert, a demonstration or a football match may appear to be an ordinary gathering of people. But as artificial intelligence becomes increasingly embedded in facial-recognition systems, such events can also become opportunities for governments to record, store and identify those who attend. What once sounded like a dystopian scenario associated with authoritarian regimes is increasingly part of a European debate over how far police should be permitted to use biometric technology.
Italy is now at the centre of that debate.
On 4 August, the government of Giorgia Meloni definitively approved, following an exchange of drafts with Parliament, a decree adapting Italian law to the European Union’s AI Act. The decree had not yet been published in the Official Gazette, and its contents were known only through a government statement. If implemented as described, Italy would become the first EU country to establish a detailed legal framework for the exceptions left open by the AI Act for police use of facial recognition.
The development matters because the AI Act establishes, in theory, a general prohibition on police biometric identification, while allowing exceptions for circumstances including terrorism, missing people and “serious” crimes. Individual states retain considerable room to determine how those exceptions operate in practice. Italy’s approach is therefore being watched closely by civil-rights organisations and digital-rights experts concerned that national rules could determine how restrictive the European framework ultimately becomes.
The Italian decree distinguishes between two forms of identification. Real-time identification is reserved for serious threats such as terrorism or searches for missing people and requires authorisation from a prosecutor. Identification after the event can be used once a crime has been committed to identify suspects who have already been singled out.
The most significant change from the first draft concerns events deemed to involve “public order needs”, including squares, stadiums and demonstrations. Police can record and retain images from such events, but facial recognition is no longer automatically activated on everyone present. Instead, it can be used only if a crime is committed, with judicial authorisation required within 24 hours. If nothing happens, the data would be deleted after seven days.
For civil-rights groups, however, the distinction does not resolve the central concern: people may still be recorded before any crime has taken place.
“There is nothing to do, starting from the fact that European regulators, in one way or another, allow governments to act in this way. My position is totally opposed to the uses they propose, but we are facing a trend that has been developing for years,” says Diletta Huyskes, a sociologist at the University of Milan and founder of the NGO Immanence, who was one of the prominent voices during the Italian parliamentary debate.
According to the government statement, pending the final text, some technical aspects have been altered, including requirements concerning databases, procedures for deleting information and the powers of the Privacy Guarantor. But the most controversial elements remain. Identification after the event in public spaces is still permitted. Judicial authorisation for real-time identification has not been strengthened, and authorities are not required to inform citizens when the system is active.
“The implementation of this technology creates an infrastructure of ubiquitous surveillance. Even with a change of government, it can easily be used for authoritarian purposes,” Huyskes says.
Journalist and biometric-control expert Fabio Chiusi argues that the concern extends beyond the current Italian government. “There are parties even more extreme than those in power, such as that of General Roberto Vannacci, who calls for drones with thermal cameras to guarantee security,” he says. His question is whether institutions guided by such instincts can reliably comply with the conditions imposed by the AI Act, and for how long.
Chiusi argues that the technological transformation has altered the meaning of surveillance itself. A few years ago, he says, cities watched by thousands of constantly operating technological eyes evoked images of China. Today, the issue reaches advanced democracies. In his view, the trend cannot be addressed through limited amendments but requires absolute prohibitions.
Another concern is the lack of transparency surrounding how systems are trained and how images are subsequently eliminated. Huyskes says such opacity obstructs democratic oversight and the protection of fundamental rights. Chiusi says the Italian government considers automatically registering everyone present at a demonstration — effectively mass surveillance — compatible with a democratic society.
Laura Carrer, a journalist and researcher at the Hermes Center Hacking for Human Rights, says the technology is normalising a form of surveillance that did not previously exist. The requirement that a crime must occur before facial recognition is used does not eliminate the concern, she argues, because the images have already been recorded.
The remaining safeguard is judicial oversight, Carrer says, but even this is contested because activation can be authorised by a prosecutor rather than a judge. “The prosecutor conducts the investigation and is more likely to authorise it,” she says.
Aljosa Ajanovic Andelic of EDRi, European Digital Rights, raises a related question: whether the authority granting approval genuinely assesses the necessity and proportionality of each deployment, or simply validates a police decision that has already been made.
For Ajanovic, Italy’s rules test the boundary between real-time and post-event facial recognition. If biometric data from everyone passing through a public space are continuously captured and stored, and authorities later decide whom to identify, he asks whether the system is genuinely post-event or merely achieving a similar surveillance effect through a different technical sequence.
The question has implications beyond Italy. Ajanovic points to Hungary, where rapid facial identification was excluded from the “real-time” category by using still images rather than live transmission. The system was subsequently threatened as a means of identifying and fining people who attended the Budapest Pride demonstration banned by the government of Viktor Orbán. According to EDRi’s analysis, the Hungarian system constitutes real-time identification because it can influence behaviour during a protest and therefore violates the AI Act.
The fear is that national legislation could become a mechanism for circumventing European restrictions and expanding biometric mass-surveillance systems.
The issue also reaches into migration. Ajanovic, who previously coordinated the Catalangate campaign from Òmnium Cultural concerning the use of Israeli Pegasus spyware against Catalan politicians, activists and journalists in the context of the procés, argues that judicial authorisation alone can be insufficient protection when surveillance systems are used against groups that authorities have labelled as security threats.
The retention of biometric information for a limited period is potentially auditable, he says, but secrecy and a lack of transparency can make verification impossible. For migrants and asylum seekers, the deterrent effect may be particularly significant because their relationship with authorities is already more precarious.
There is also the risk of “function creep”: biometric information initially collected for reasons unrelated to crime could later become accessible to police. With the EU’s new Return Regulation requiring states to register undocumented people, Ajanovic warns that interoperability between databases could emerge almost automatically. A mistaken biometric match, he says, could consequently have much more serious consequences.
Spain has yet to adopt specific legislation on facial recognition, although its draft Organic Law on the proper use and governance of AI is before Congress. According to the Xnet Institute, the Spanish project contains positive elements, including requirements to label deepfakes, prohibitions contained in the AI Act such as social profiling, and strong sanctions for the private sector. But it criticises the failure to impose the same sanctions when public authorities violate the law and describes the proposal overall as more a law of sanctions and surveillance than one of citizens’ rights.
Spain therefore retains a choice that Italy has already begun to make. It could reproduce the Italian approach or establish stricter national rules, including a prohibition on post-event biometric identification.
For Ajanovic, that choice is precisely where the wider European significance lies. The AI Act does not require Spain to adopt the most permissive interpretation of the European regulation. National legislators can determine where to place the threshold.
The question raised by Italy’s decree is consequently larger than whether facial recognition can be deployed after a crime. It is whether recording everyone first can remain meaningfully different from identifying everyone in real time — and whether legal safeguards can prevent a technology designed to find suspects from becoming an infrastructure capable of watching entire crowds.

