There are no concerns for democracy regarding AI-powered facial recognition. Brozzetti (Luiss) speaks out

The provision on security cameras and the retention of footage contained in the legislative decree transposing the European AI Act has sparked much controversy. “But there is no indiscriminate data collection. Images alone do not constitute biometric data. The important thing is to strike the right balance between security requirements and the protection of individual rights,” says the professor


30 JUL 26
Last updated: 14:38
Translated by AI
Image of There are no concerns for democracy regarding AI-powered facial recognition. Brozzetti (Luiss) speaks out

Photo by Scott Webb on Unsplash

“Just images? They’re not biometric data. Retention periods? Reasonable. Ultimately, there is no indiscriminate data collection and no cause for democratic alarm. The important thing is to respect the balance between security requirements and the protection of individual rights.” This is what Filiberto Emanuele Brozzetti, a tenure-track researcher in the philosophy of law and lecturer in AI & Data Law at Luiss Guido Carli University, told "Il Foglio" regarding the legislation on facial recognition using CCTV cameras and artificial intelligence. Yesterday, in the Senate’s European Policies Committee, the majority approved the draft legislative decree transposing the European AI Act, which must then be approved by the government. The text has sparked controversy, with the opposition referring to it as ‘Big Brother-style surveillance’. The legislation provides that certain images captured by security cameras may be stored for seven days and, where necessary for public order or criminal investigations, will then be analysed using AI to extract biometric data.
One of the most contentious points is Article 10, which concerns the retrospective facial recognition of suspects following the commission of a crime and subject to authorisation by the public prosecutor’s office. The opposition views this as a means of implementing mass surveillance, but the professor reassures us: “This is not a case of bulk collection or indiscriminate surveillance. As long as there is a limit – namely, the possibility of reviewing the images only retrospectively, clearly within a limited timeframe, and only where criminally relevant conduct has taken place, and of identifying solely and exclusively suspects – then, provided this is done retrospectively by individuals expressly authorised to do so, there is no generalised pre-emptive profiling.”
However, paragraph 3 of Article 10 permits automated real-time biometric identification – which Article 5 of the AI Act permits only for the prevention of imminent threats (such as terrorism), to the extent that even a spokesperson for the European Commission has expressed doubts on this point – of all persons accessing places or events characterised by public order requirements, the retention of such biometric data for seven days, and its use where a criminal offence has been established in the meantime. It is in relation to this provision that reference is made to the application of the Data Protection Authority’s recommendations to remain compliant with the AI Act, which, as Brozzetti summarises, requires “balancing the need for security with what is strictly necessary and proportionate to the purpose pursued”. As mentioned earlier, the provision also stipulates that the images collected must be retained for seven days, and the professor considers this period to be "reasonable" because "it allows sufficient, yet limited, time to return and identify the images".
One clarification is, however, necessary. The broad spectrum of accusations has referred to the indiscriminate collection of biometric data, but a photographic image or one captured via a video system “is not in itself biometric data; it only becomes so when it is converted into a series of templates, such as the distance between the pupils, the distance between the ears, the width of the forehead, and the length of the nose. The image itself, therefore, is not biometric data. Otherwise, even when we take a photograph of a landscape and happen to capture a person without their knowledge, we would be processing biometric data.” Another issue that arises concerns who will be able to view the images collected: “Only a few designated individuals can access them, and every instance of access is logged and always takes place following a request and authorisation from the relevant public prosecutor. This, too, is a measure that strictly limits any potential abuse by the police.”
Brozzetti describes the statements made by the broader political spectrum – which has raised its voice to sound the alarm for our democracy – as “rhetorical exploitation” and explains that “with this provision, we are simply adopting the regulations of the European AI Act. The EU has no competence in matters of security, which remain with the Member States: the AI Act therefore leaves it to individual Member States to regulate as they see fit”. And the same thing happened with personal data, the professor comments: “In that case, there is a general regulation applicable to all 27 Member States for all matters except those relating to public order and security, for which there is a directive – a framework of rules – that is not directly applicable, but which each state must then implement individually.”
In essence, Brozzetti concludes, “once the Data Protection Authority’s recommendations have actually been implemented, I find the text to be consistent with the AI Act, both from a formal and a substantive point of view. Formally, because security is a matter falling within the exclusive competence of Member States; and substantively, because, once all those precautions have been taken, we can indeed consider the AI Act’s focus on high-risk artificial intelligence systems to have been fully respected.”