Italy’s AI Policing Decree: Nessun Dorma on Constitutional Safeguards

—Federica Paolucci, Postdoctoral Research Fellow, Bocconi University Introduction After years in which the debate focused on the adoption of Regulation (EU) 2024/1689, the Artificial Intelligence Act, attention is now moving to its national application. This second phase is not merely technical, as the AI Act leaves Member States a margin of choice on several sensitive questions, especially in the law enforcement sector, where European rules must be translated into authorisation procedures, institutional controls, and safeguards governing the use of AI systems by police authorities. Italy is one of the MS that adopted a national law on AI, Law No. 132/2025. Following it, which delegates to the Government to adapt domestic law to the AI Act, the Italian Government has adopted a draft legislative decree on the use of AI systems in law enforcement, now before the parliamentary committees. Italy is, hence, taken as a case study because it shows how the implementation of AI rules in the security field may affect the distribution of constitutional safeguards. The central problem is not only the regulation of specific technologies, but the broader institutional setting in which they are introduced and controlled. This is particularly relevant in a context where recent legislative developments in the field of internal security have already raised concerns about the impact on civic space and fundamental rights (F. Venturi, 2026). As noted in the European Commission’s Rule of Law Report, new legislation has expanded police powers, introduced new criminal offences, and strengthened surveillance measures, prompting stakeholders to warn about restrictions on the right to protest and the exercise of fundamental freedoms. Against this background, this post relies on the Italian case to illustrate a broader constitutional question: whether the implementation of the AI Act in the field of law enforcement is reinforcing a tendency to concentrate security-related choices within the executive. A paradigmatic case Art. 24, of Law No. 132 of 2025, empowers the Government to implement the AI Act and, among the specific criteria governing the delegation, merely requires the “previsione di un’apposita disciplina per l’utilizzo di sistemi di intelligenza artificiale per l’attività di polizia”: the adoption of a specific rule for the use of AI systems in police activities. Such a rule is the draft legislative decree approved following a preliminary examination by the Italian Council of Ministers on 10 June 2026. The formula of Art. 24 is not only broad, but also does not determine who should authorise the use of biometric systems: it does not define the catalogue of offences for which they may be used; it does not set a threshold of gravity; nor does it specify the minimum procedural guarantees for the persons affected. It is the first link in a chain through which the essential choices concerning constitutional safeguards move away from Parliament. Thus, the most problematic provision is Article 10 of the draft decree, concerning post-remote biometric identification. This technique differs from real-time remote biometric identification as the comparison of recorded faces takes place after the image or video has already been acquired. The person is no longer necessarily in the monitored public space. The identification is then retrospective: within it, it is possible to reconstruct a person’s presence at a place, participation in an event, or movement through public space by comparing images and videos with biometric databases. It may be delayed in time, but it can be equally powerful in its effects. The European AI Act itself treats post-remote biometric identification as a high-risk use. Article 26(10) of that Act provides that, in the framework of an investigation for the targeted search of a person suspected or convicted of having committed a criminal offence, those deploying a high-risk AI system for post-remote biometric identification must request authorisation ex ante or, where necessary, without undue delay and no later than forty-eight hours, from a judicial authority or from an administrative authority whose decision is binding and subject to judicial review. Each use must be limited to what is strictly necessary for the investigation of a specific offence. Untargeted use is prohibited, and no decision producing adverse legal effects may be based solely on the output of the system. Each use must be documented and made available to the competent authorities, and Member States remain free to introduce more restrictive rules. That last point is crucial, as the European AI Act leaves Member States discretion in designing authorisation procedures, but also establishes a minimum institutional threshold. The authorising body must be external to the entity deploying the system: either a judicial authority or an administrative authority whose decision is binding and subject to judicial review. Member States may raise the level of protection. They may not replace external authorisation with internal administrative responsibility. The Italian draft appears to heed those instructions. For real-time biometric identification, the decree constructs a more demanding regime. In the preventive field, Article 8 requires external authorisation and identifies temporal, spatial, and substantive limits. In the investigative field, Article 15 of the draft introduces a new Article 359-ter of the Code of Criminal Procedure, modelled on the architecture of judicial authorisation familiar from interception law. The decree therefore knows how to build an external authorising mechanism. It simply does not extend it to post-remote biometric identification. For retrospective facial recognition, however, Article 10 of the drafttakes a different route. According to the text of the draft decree, the use of the technological system is placed under the “direct and exclusive responsibility” of a public security officer designated by the Questore. For non-Italian readers, the point is important: the Questore is not a judicial authority, nor an independent administrative body, but the senior State Police official responsible for public security at the provincial level. The authorising decision is therefore kept within the same public security apparatus that intends to use the technology. The asymmetry is difficult to justify. Real-time and post-remote biometric identification differ in their temporal application, but not in their capacity to interfere with fundamental rights (F. Paolucci, 2025). Analysis of the constitutional issues This is why the lack of precise “implementation” of the AI Act in Italian Law, with respect to the authorisation of biometric systems in law enforcement, cannot be reduced to technical compliance. In a constitutional democracy that collapses the different institutional functions into the same executive chain, the legal framework may retain the language of safeguards while losing their substance. The Italian draft raises precisely this concern. As mentioned, Law No. 132 of 2025 delegates the power to adopt rules on the use of AI by law enforcement to the Government in very broad terms. The draft decree then defers important elements of implementation, including operational thresholds, technical requirements, accuracy, reliability, and modalities of biometric processing, to subsequent ministerial decrees. The result is a chain of delegation: from Parliament to the Government; from the Government to ministerial regulation; and, finally, from external authorisation to internal public security responsibility. The second displacement concerns judicial authorities. In the Italian legal tradition, the rationale for the “reservation of jurisdiction” – meaning that the law defines the cases and conditions of the interference, but the concrete decision authorising it must come from a judge –  is expressed most clearly in Article 15 of the Constitution. Precisely, the constitutional logic is that the more an investigative technique expands the State’s ability to identify individuals and reconstruct their conduct, the stronger the need for an external authorisation. Hence, the authority that benefits from the measure should not be the same authority that decides whether its use is justified. The Italian Constitutional Court has applied this logic beyond its textual perimeter: judgment no. 252 of 2020 struck down a rule allowing telephone-authorised searches without subsequent validation, holding that reasoned control by a third party is required even where it might appear redundant. Thus, by the text of the Italian Constitution, a public security officer designated by the Questore cannot perform the same guaranteed function as a judge or an independent authority. European Union law points in the same direction. In its case law regarding access to retained data, the Court of Justice has insisted that public authorities’ access to data capable of revealing important aspects of private life must be subject to strict necessity and effective safeguards. In Prokuratuur, this Court held that prior review must be carried out by a court or by an independent administrative authority, and that a public prosecutor involved in directing criminal investigations cannot provide the required degree of independence. If a prosecutor may lack the necessary distance when functionally involved in the investigation, an officer organically inserted in the public security apparatus is even less capable of providing external authorisation. The case law of the European Court of Human Rights also supports this reading. In the field of covert and technologically mediated surveillance, the Strasbourg Court has repeatedly required a legal framework of sufficient quality, effective safeguards against abuse, and independent supervision (i.e., Glukhin v. Russia). Seen through this lens, the Italian draft is more than an imperfect implementation of Article 26(10), AI Act: security needs are increasingly framed as technical problems requiring speed, expertise, and administrative flexibility. Those are legitimate concerns, but when they are used to relocate the guarantees of liberty within the executive, they alter the constitutional balance between security and rights. This drift should not be misunderstood as an exceptional or authoritarian rupture. Its danger lies precisely in its ordinary form. The language remains that of safeguards. There are rules on human oversight, logging, data retention, and prohibition of fully automated adverse decisions. There are references to proportionality and targeted use. Yet the core decision, whether the state may activate a highly intrusive identification technology, is placed within the same apparatus that pursues the security objective. The safeguard becomes administrative self-control. A constitutionally adequate framework for retrospective biometric surveillance would require a different architecture. First, the essential conditions of use should be determined by legislation: the catalogue of offences, the gravity threshold, the categories of persons who may be searched, the databases that may be used, temporal and spatial limits, retention periods, deletion duties, and the consequences of unlawful use. Second, any use of such surveillance for investigative purposes should be subject to prior judicial authorisation or, at a minimum, to authorisation by a genuinely independent administrative authority whose decisions are binding and subject to judicial review. Third, any use must be targeted, based on objective and verifiable facts, and strictly necessary for a specific offence or proceeding. Fourth, technical safeguards must be made reviewable: accuracy thresholds, false positive rates, logs, audit trails, and documentation should not remain opaque matters of internal administration. Fifth, effective remedies must be available, including deletion, exclusion of unlawfully obtained results, and information to the person concerned when this no longer jeopardises concrete investigative needs. These conditions would not prohibit the use of biometric technologies by the state. They would restore the constitutional structure within which such use may become legitimate. The question is not whether police authorities may ever rely on artificial intelligence. The question is whether constitutional democracies can allow the executive to become the user of the technology, the evaluator of necessity, and the locus of the safeguard. Conclusion Italy’s draft decree is important beyond Italy. It shows how AI governance may become a vehicle for the securitarian expansion of executive power without openly rewriting constitutional guarantees. In an age of AI policing, the separation between those who seek to use a surveillance technology, those who authorise it, those who execute it, and those who control it is not a procedural luxury. It is the institutional form of liberty. Retrospective facial recognition brings this point into sharp relief. The constitutional issue is not simply whether the state may identify individuals after the fact; it is whether it may do so by entrusting the control of that power to the very executive chain that exercises it. Suggested citation: Federica Paolucci, Italy’s AI Policing Decree: Nessun Dorma on Constitutional Safeguards, Int’l J. Const. L. Blog, Aug. 6, 2026, at: http://www.iconnectblog.com/italys-ai-policing-decree-nessum-dorma-on-constitutional-safeguards/
AI Article