Facial recognition is one of the applications of artificial intelligence that perhaps more than any other raises questions about the delicate balance between security and privacy protection. For this reason, the decree approved by the Council of Ministers with which Italy implements the AI Act, the European regulation dedicated to artificial intelligence, introduces precise rules on its use by law enforcement agencies, defining when this technology can be used and which authorizations are necessary to offer guarantees against possible improper uses of the same.
What facial recognition is and how it works
Before understanding what changes, it is useful to understand, at least briefly, the mechanisms underlying this technology. It is a biometric identification technology, i.e. based on the analysis of a person’s unique physical characteristics. In this specific case, elements of the face are analysed, such as the distance between the eyes, the shape of the nose, the position of the mouth or the profile of the face. This information is transformed into a mathematical model, also called a “biometric template”, which can be compared with other models in a database to check if there is a match.
It is important to distinguish facial recognition from simple video surveillance. While a traditional camera records images, a facial recognition system uses artificial intelligence algorithms to automatically analyze faces and compare them with already available data. Such a system, therefore, does not simply record what happens, but tries to establish the identity of the people present in the images. This is why we talk about “facial recognition”.
The limits and changes introduced by the decree
Precisely due to the particularly invasive nature of this technology, the decree transposing the AI Act introduces a series of limits and controls which have the aim of allowing the use of facial recognition in well-defined circumstances and with the control of the judicial authority, thus preventing the use of this system from turning into an instrument of mass surveillance.
One of the most relevant aspects is contained in Article 10 and concerns facial recognition carried out «in retrospect», that is, after a crime has already been committed. In practice, investigators can analyze already recorded images to verify the identity of a suspected person, but they must respect a precise procedure. The judicial police officer is in fact required to request authorization from the PM within 24 hours of activating the system. If this authorization does not arrive or the deadlines are not respected, the system must be deactivated immediately. Furthermore, all personal data collected, results produced by the software and other elements obtained through facial recognition must be deleted, «unless they constitute a crime», i.e. material elements that are directly linked to the crime and necessary to be used as evidence.
The text approved by the Council of Ministers further strengthens the guarantees by introducing a double level of control. In addition to the role of the public prosecutor, in fact, the involvement of the judge is also envisaged in the situations regulated by the decree, so as to ensure differentiated judicial control based on investigative needs. The principle underlying the rule is that artificial intelligence must not make autonomous decisions: the results produced by IT systems are essentially a support tool for investigations and therefore must always be evaluated by competent people.
The new provisions also clarify that it will not be possible to create permanent biometric archives powered by indiscriminately collecting photographs available online. This practice, called “scraping”, would conflict with the AI Act.
The role of the Guarantor for the protection of personal data is also strengthened. This independent authority has the task of supervising compliance with the legislation on privacy and processing of personal data, verifying that biometric technologies are used within the limits established by law.
In article 8, the text talks about video surveillance in public spaces, which is also regulated with greater precision. Images recorded in places and situations characterized by particular public order requirements may continue to be stored, provided that biometric processing is not carried out beforehand. Only in the event that a crime is committed will it be possible to subsequently apply facial recognition to the recordings already made. The images, however, will have to be deleted after seven days, thus limiting the data retention period.
Then there is the issue regarding the future development of artificial intelligence. Synthetic data, or anonymized and pseudonymized data, can be used to train new AI-based systems. In the case of anonymized data, any connection with the person’s identity is irreversibly eliminated; in pseudonymized ones, however, the identifying information is replaced by codes, in such a way as to reduce the risks to privacy while allowing, in specific cases authorized by law, to reconstruct the original identity of the subjects involved.








