Artificial intelligence · Surveillance · Humanity

Unlocking a phone with your face and searching for someone in a crowd are not the same operation. Understanding the difference is the first step towards a serious discussion of facial recognition.

The face as password, the face as suspect

From one-to-one verification to biometric identification in CCTV footage: where facial recognition is used, the limits set by the EU AI Act and its connection with The Age of Silence.

Cover of Cronache al di là del tempo, featuring The Age of Silence, a story about artificial intelligence and surveillance

In brief: facial recognition is not a single technology, and it does not read thoughts. It can verify that the face in front of a camera matches the one already associated with a device or document; or it can search for a person by comparing their face with many profiles in a database. The first operation is one-to-one verification. The second is one-to-many identification, a far more sensitive process when it happens remotely, in a public space and without the active participation of the people being filmed.

How does facial recognition actually work?

A system detects a face in an image, measures some of its features and turns them into a numerical biometric template. It does not necessarily retain a photograph in the ordinary sense: it creates a mathematical representation to compare with a reference template. The output is not metaphysical certainty but a similarity score. Camera quality, lighting, distance, database, algorithm, age, gender and the characteristics of the subject can all affect accuracy.

A result should therefore be treated as an element requiring verification, not as an automatic verdict. The European Commission notes that even an apparently very low error rate can have a significant impact when a system is applied to large populations, for example in a railway station.

Where is it used?

Personal authentication. This includes unlocking a smartphone or verifying identity at a border crossing: a face is compared with a template already supplied by the same person or with the photograph in a travel document. The Commission distinguishes this one-to-one verification from remote identification. That does not make it rule-free: data protection, security and the need for a legitimate purpose still apply.

Remote identification. A camera records people who are not actively presenting their identity and a system searches for matches in a database. This may happen in real time, as footage arrives, or later, using recorded material. Law-enforcement, migration and border-control uses are among those treated as particularly sensitive under the AI Act when they are not prohibited outright.

Mirrored photographic portrait about the face, biometric identity and facial recognition by Massimo Scognamiglio

A face is presence, identity and data at the same time.

Photographic portrait by Massimo Scognamiglio. Its symmetry makes visible the difference between recognising a person and comparing a biometric template.

What does the AI Act prohibit, and what does it allow?

European rules do not simply say “yes” or “no” to facial recognition. They prohibit untargeted scraping of images from the internet or CCTV systems to create or expand facial-recognition databases. They also prohibit in principle real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes.

Narrow exceptions exist: targeted searches for victims or missing persons, prevention of a threat to life or a terrorist attack, and law-enforcement activity linked to a list of particularly serious crimes. A use must be necessary and proportionate, limited in time and geographic scope, and subject to judicial or independent administrative authorisation. Identification carried out later on previously collected footage is not prohibited outright, but it also requires prior authorisation and notification to the relevant authorities. The European Parliament summarises the principle as a general prohibition accompanied by exhaustively listed cases and specific safeguards.

The Italian case: Sari Real Time

In 2021, Italy’s Data Protection Authority issued an unfavourable opinion on the Interior Ministry’s Sari Real Time project. Precision matters: the system under review was not yet active. The proposal envisaged cameras in a defined area, real-time analysis of faces and comparison with a watch-list containing up to ten thousand profiles. A possible match would have generated an alert for police operators.

The Authority did not reject the abstract existence of every biometric tool. It found no adequate legal basis for that processing and identified the risk that targeted monitoring could become indiscriminate surveillance of everyone present, including people taking part in political or social demonstrations. It also stressed the need for rules governing watch-list criteria, false positives and performance in relation to ethnic minorities.

This technology is not Neuralink

Facial recognition observes external images and produces statistical comparisons; it does not access brain activity. Neuralink belongs to another field: implantable brain-computer interfaces. The public ClinicalTrials.gov record describes PRIME as an early feasibility study of the safety and functionality of the N1 implant and R1 surgical robot in people with tetraparesis or tetraplegia, with the goal of controlling external devices. It is a circumscribed, invasive medical investigation, not a remote surveillance technology capable of reading thoughts or intentions. Keeping these realities separate avoids both alarmism and naïveté.

From biometric data to The Age of Silence

In The Age of Silence, the opening story in my book Cronache al di là del tempo, control does not need to present itself as a threat. It arrives through convenient services, reassuring devices and systems that anticipate desire. The face becomes the perfect threshold: intimate as the body, practical as a password, exposed as a number plate.

The point is not to imagine an omnipotent camera. It is to understand when a probabilistic match changes function: from a voluntarily chosen key into a signal of suspicion. There are technical, legal and human differences between these uses. If we confuse them, we risk fearing what the technology cannot do while failing to see clearly what it can already do.

The book is available on the Cronache al di là del tempo page and from Amazon.

Explore further

Artificial intelligence, surveillance and humanity

Technology, facial recognition, language and power. Here current events meet twenty-five years of research into the relationship between humans, machines and perception.

Open the thematic path