Italy's AI Act Decrees: New Rules for Facial Recognition
On June 10, 2026, Italy became the first EU country to turn the AI Act into detailed national law. Two decrees spell out exactly when facial recognition can be used, who's liable when AI causes harm, and what now counts as a crime.
Key Takeaways
- Italy is the first EU member state with detailed national rules implementing the EU AI Act, in force since June 10, 2026.
- Real-time facial recognition now needs judicial authorization, applies only to serious threats or missing-persons searches, and is capped at 15 days per authorization.
- Mass or untargeted biometric surveillance is banned, as is building a face database from scraped web images.
- A dismissal decided solely by an algorithm is legally void — a human must make the final call on any employment decision.
- Article 437-bis of the Italian Criminal Code makes it a crime to skip required safety measures on high-risk AI systems; liability can extend to the company, not just individuals.
- The rules apply to any business placing an AI system on the Italian market, regardless of where that business is headquartered.
The Short Version
Two implementing decrees under Law No. 132/2025 now sit on top of the EU AI Act in Italy. One covers AI in education, professional work, and employment. The other covers law enforcement, biometric surveillance, civil liability, and new criminal offenses. Here's what actually changes on the ground:
Facial Recognition Just Got a Leash
Italy isn't banning facial recognition. It's fencing it in. Live biometric matching against video feeds now requires a judge to approve each use, tied to a specific person, a specific place, and a hard 15-day window. It can only be used to head off a serious public-safety threat or to find someone who's missing, trafficked, or kidnapped. And whatever database gets used for matching has to be one built lawfully — no quietly scraping the web to assemble a face index.
Post-event recognition, the kind used after a crime to identify a suspect from existing camera footage, is narrower still. Only the Ministry of the Interior can run it, only after an offense has actually occurred, and only following a privacy impact assessment. Local copies of the footage get deleted after seven days, though tamper-proof logs of how the system was used stick around for five years. No decision gets made on AI output alone.
For anyone building or relying on tools that touch AI-generated or manipulated video, this matters. Courts and regulators are now drawing sharp lines around how synthetic and biometric matching technology gets used against real people. Being able to independently verify whether footage or a face match is authentic is quickly becoming less of a nice-to-have and more of a compliance question.
A New Crime for Ignoring AI Safety
Article 437-bis of the Italian Criminal Code is the sharpest new tool in the decree. It targets two things: failing to put required safety measures in place on a high-risk AI system, or tampering with one, when either creates a real danger to life, public safety, or state security. Liability doesn't stop at the individual engineer or executive — under Italy's corporate criminal liability rules, the company itself can be on the hook.
There's a deliberate ceiling here. Prosecutors need to show concrete danger, not a hypothetical one, and negligence claims require gross negligence, not an ordinary bug or misconfiguration. The law isn't trying to criminalize every technical slip. It's targeting the cases where someone knew the safeguards mattered and skipped them anyway.
The decrees also give people harmed by an AI system new procedural ground to stand on: access to the system's technical documentation, a rebuttable presumption that the AI caused the harm, a nearby court to file in, and the option to sue an insurer directly. None of that changes what businesses are substantively required to do — it changes how much easier it now is for someone to prove they were wronged.
Why This Matters Beyond Italy
Any business placing an AI system on the Italian market, or using one there, falls under both the EU AI Act and these national rules — regardless of where the company is headquartered. That's a familiar pattern by now: European rules that look domestic on paper end up shaping product decisions everywhere.
For platforms dealing in synthetic media, the practical takeaway is narrower and more immediate. As biometric and facial-recognition evidence gets pulled into criminal proceedings under tighter legal rules, being able to tell real footage from manipulated footage — and prove it — stops being a technical nicety. It becomes part of how disputes get resolved. Tools built for exactly that, like an AI scam and deepfake detector, are the kind of thing that turns from "useful" into "necessary" once liability and evidentiary standards tighten up.
Common Questions
Does this ban facial recognition in Italy?
No. It restricts it heavily — real-time use needs judicial authorization and a 15-day cap, and mass or untargeted surveillance stays banned. It doesn't remove facial recognition as a tool; it puts it under court oversight.
Can an employer fire someone using only an algorithm's decision?
No. A dismissal made solely through automated processing is void under the new rules. A person with real decision-making authority always has to make the final call.
Who enforces these rules?
Enforcement is split across several bodies: AgID as the notifying authority, ACN for market surveillance, the Garante (Italy's data protection authority) for law enforcement and biometric uses, and Banca d'Italia, CONSOB, and IVASS for AI used in financial services.
Do these rules apply to companies outside Italy?
Yes, if they place an AI system on the Italian market or use one there. Location of headquarters doesn't exempt a business from either the EU AI Act or Italy's national implementing rules.
Verifying content just became part of doing business
As facial recognition, biometric evidence, and AI liability rules tighten across Italy and the EU, knowing what's real is no longer optional. UncovAI helps you check.
Get Started Free →
