Executive Summary and Public Interest
The codification of artificial intelligence systems within criminal justice and law enforcement operations marks an unprecedented transformation in state investigative powers. The establishment of specific statutory boundaries governing real-time remote biometric identification, predictive filtering, and automated dataset categorization directly determines the operational perimeter between public security measures and constitutional guarantees of privacy.
As legislative instruments establish procedures for judicial authorization, cross-database matching, and algorithmic sandboxes, the legal standards governing evidence acquisition and processing transparency require rigorous oversight. This investigation examines the primary architecture implemented under the statutory delegation of Law No. 132 of September 23, 2025, detailing how algorithmic models operate within investigative branches and preliminary inquiries.
The central public concern rests upon the concrete thresholds for algorithmic intervention, the mandatory dual-validation procedures during urgent operations, and the explicit prohibition of untargeted data harvesting. Establishing verifiable compliance mechanisms represents the cornerstone for preventing systemic fundamental rights infringements across municipal and national operational theaters.
The structural transformation shifts law enforcement technology from passive digital records toward proactive analytical processing, creating an enduring impact on preliminary judicial determinations, evidentiary admissibility, and data retention thresholds.
Context and Institutional Framework
The legislative mechanism stems from the formal execution of delegated powers under Article 24, paragraphs 2(h) and 5(a)(e) of Law No. 132 of September 23, 2025. This overarching legislation mandated the introduction of a specialized statutory discipline governing artificial intelligence systems deployed by police forces, alongside the structural definition of accompanying civil and penal liability regimes.
The national codification directly integrates the requirements set forth in European Union artificial intelligence harmonized standards, notably Article 14 on human oversight and Article 59 regarding operational sandboxes. These provisions operate in close conjunction with Legislative Decree No. 51 of May 18, 2018, which constitutes the national transposition framework for personal data protection within judicial and criminal prevention contexts.
Within this normative progression, Title I of the draft legislative decree delineates the scope and operational criteria applicable to police commands, offices, and investigative units. The structural intent focuses on establishing clear operational definitions, creating regulatory testing grounds, and defining precise restrictions on high-risk computational processing applied to biometric information.
The trajectory follows earlier regulatory milestones, specifically Presidential Decree No. 15 of January 15, 2018, concerning police data retention terms, and Legislative Decree No. 271 of July 28, 1989, whose procedural coordination mechanisms are adapted to resolve emergent questions surrounding algorithmic evidentiary integrity.
Key Institutional Actors
The regulatory and operational deployment of algorithmic systems involves distinct institutional bodies operating across judicial, administrative, and supervisory jurisdictions:
- Legislative and Judicial Branches: Responsible for the enactment of Law No. 132/2025 and preliminary investigative oversight under the amended code of criminal procedure.
- National Police Commands and Offices: The primary deploying authorities charged with utilizing artificial intelligence models for public security functions, prevention, and judicial police activities.
- Garante per la protezione dei dati personali ([[Garante per la protezione dei dati personali|Q3758604]]): The national data protection authority mandated to receive formal notifications regarding biometric AI deployment following judicial clearance.
- National Artificial Intelligence Authorities: The designated bodies tasked with direct coordination, regulatory sandbox oversight, and collaborative compliance monitoring pursuant to Article 59 of the European AI framework.
- Judicial Police Officers: Operational investigators authorized to initiate urgent biometric identification mechanisms subject to mandatory judicial validation.
Critical Analysis of Evidentiary Standards and Gaps
Operational Definitions and Prohibited Practices
Article 2 of the draft decree formalizes core definitional frameworks aligned with Union rules, establishing strict parameters around sensitive operational data. Critically, Article 8, paragraph 3, enforces an absolute prohibition against untargeted web scraping for facial or biometric data, reflecting the explicit bans established in Article 5(1)(e) and Recital 43 of the European Artificial Intelligence Regulation.
The regulatory framework introduces a specific ban on untargeted scraping while establishing definitive operational boundaries for sensitive investigative information across all phases of technological integration.
While the ban on untargeted scraping provides an essential baseline, structural questions remain regarding the precise perimeter of targeted dataset acquisition during preliminary research phases. The operational distinction between generalized aggregation and specific target identification depends heavily on internal agency verification procedures.
High-Risk Systems, Sandboxes, and Mandatory Human Oversight
Article 3 governs research, experimentation, development, training, validation, and operational deployment of AI models. For high-risk applications, Article 3(5) mandates effective human oversight, requiring specialized technical training to prevent or mitigate risks to health, safety, and fundamental rights pursuant to Legislative Decree No. 51/2018.
Under Article 4 and Article 5, regulatory sandboxes for law enforcement are structured in compliance with Article 59(2) of the AI Regulation. These controlled testing environments establish a lawful basis for personal data processing when strictly necessary for police purposes. However, the operational text maintains that full data ownership and processing liability remain exclusively with the deploying administrations, even during external research collaborations.
Biometric Categorization and Remote Identification in Criminal Procedure
Article 7 establishes explicit restrictions on AI systems used for labeling, filtering, and categorizing lawfully acquired biometric datasets. Under paragraph 2, these capabilities may operate exclusively to confirm the identity of targeted persons or to execute targeted searches for individuals specifically identified or identifiable in direct connection with an active threat or lawful search warrant.
The evidentiary regime is reinforced through Article 7(9), which applies an analogical extension of Article 226, paragraph 5, of Legislative Decree No. 271/1989. This mechanism strictly governs the conditions under which elements gathered during preventive algorithmic operations may be entered as evidence within formal criminal proceedings.
The most consequential procedural evolution appears in Article 13, which introduces Article 359-ter into the Italian Code of Criminal Procedure. This provision establishes real-time remote biometric identification as a formal investigative means of obtaining evidence during preliminary investigations. To govern urgent field operations, the statute creates a double-validation system modeled on interdictory wiretapping standards under Article 267(2) of the Code of Criminal Procedure, permitting immediate activation by judicial police officers subject to rapid judicial confirmation.
Unresolved Issues and Unanswered Questions
Despite detailed procedural sequencing, critical operational questions persist. The statute relies on post-hoc facial recognition frameworks (Article 10) and retention periods established under Presidential Decree No. 15/2018, yet the technical boundaries separating post-hoc retrospective processing from near-real-time remote scanning require ongoing forensic scrutiny.
Furthermore, the mechanism governing mandatory notification to the Data Protection Authority under Article 5(4) of the AI Regulation is conditioned on prior judicial clearance (nulla osta). The precise criteria for withholding or delaying notification to protect operational secrecy remain an open area of procedural application.
Transparency and Legal Framework
This dossier is constructed from official institutional proceedings and primary legislative texts governing the implementation of delegated powers established in Law No. 132 of September 23, 2025. The source documentation represents an official opinion rendered by the national supervisory authority on the draft legislative decree regulating police AI deployment.
In accordance with Article 5 of Italian Law No. 633/1941, official acts of state administrations, judicial records, and public regulatory opinions are excluded from copyright protection and reside in the public domain. The complete administrative documentation is accessible through institutional archives via the Garante per la protezione dei dati personali Official Register.

