Comune di Trento fined 50,000 euros for illegal AI surveillance projects

The Italian Garante Privacy fined Comune di Trento €50,000 for deploying AI systems that violated GDPR rules through insufficient anonymization and lack of impact assessments. The city was ordered to delete the collected data from the MARVEL and PROTECTOR projects.

Comune di Trento · Incident Jan 25, 2024 · Indexed Jun 10, 2026 · 3 sources

The city deployed invasive AI surveillance without a required impact assessment or effective anonymization.
What
The Italian Garante Privacy fined Comune di Trento €50,000 for deploying AI systems that violated GDPR rules through insufficient anonymization and lack of impact assessments.
Incident date
Jan 25, 2024
Who
Comune di Trento
Failure mode
Policy Violation
AI surface
Computer Vision
Severity
Medium

What happened

The Italian privacy authority fined the city of Trento €50,000 for deploying two AI-driven urban surveillance projects, MARVEL and PROTECTOR. These systems processed video, audio, and social media data to detect public security risks. The regulator found the processing was unlawful and ordered the deletion of all gathered data.

What broke inside the model

Failure path · mode profile · Policy Violation
  1. 01 · TriggerA prompt pushes against a deployment boundary.
  2. 02 · Model stepThe model produces the disallowed output.
  3. 03 · Control gapNo enforcement blocks it at generation time.
  4. 04 · FailureThe output crosses the policy line.
  5. 05 · ConsequenceA limit the business set is breached in public.

The output crosses a policy boundary the deployment had defined.

The system's anonymization techniques were insufficient to prevent the re-identification of individuals. Additionally, the deployment failed to include a mandatory data protection impact assessment before processing invasive data.

Public visibilityHigh
Regulatory exposureActive
Customer impactMany customers
Financial impactDisclosed
Time to disclosureMonths
  1. PrimaryVideosorveglianza, no all'intelligenza artificiale che viola la privacygaranteprivacy.it
  2. PressItaly fines first city for privacy breaches in use of AIreuters.com
  3. PressItaly: Trento council fined for illegal AI video and audio surveillance projectsstatewatch.org
Permalinkhttps://failureindex.ai/failures/comune-trento-fined-000-euros-illegal
CitationAI Failure Index. "Comune di Trento fined 50,000 euros for illegal AI surveillance projects" (FI-0500). Realm Labs. https://failureindex.ai/failures/comune-trento-fined-000-euros-illegal (indexed Jun 10, 2026).
Share cardA branded image of this record for posts and slides.

Data fields CC-BY 4.0, prose citation permitted. Incident ID FI-0500. Full dataset at /data.

Note from Realm Labs, the Index steward

How Realm fits

Controls for this failure mode
  • Prism
  • OmniGuard

This entry sits in the index's predictive wing: a system that scores, ranks, perceives, or steers rather than generates. Realm's runtime layer is built for the generative and agentic systems now moving into these same decision seats, where it watches a model's internal state and holds an unsupported claim or an unchecked action before it commits. The control gap on this record, an automated decision that reached people with no runtime check in front of it, is the same gap. The index keeps predictive failures on the record because the pattern carries straight into the systems shipping today.