AI Policy Wiki
Dashboard

Surveillance Technology

medium confidence · updated 2026-08-16

AI-enabled and AI-adjacent surveillance technology — face recognition, behavioral monitoring, biometric identification, predictive policing, workplace surveillance, spyware (Pegasus, Predator). The substantive area Access Now, EFF, ACLU are most active on; intersects with concepts/ai-and-civil-liberties and concepts/ai-and-authoritarianism.

Surveillance technology refers to AI-enabled and AI-adjacent systems used to identify, track, and monitor people, including face recognition, behavioral monitoring, biometric identification, predictive policing, workplace monitoring, and commercial spyware. Civil-society organizations including Access Now, Electronic Frontier Foundation (EFF), and American Civil Liberties Union (ACLU) identify this stack as among the most consequential for civil liberties and for authoritarian use.

Sub-categories

CategoryExamplesCivil-society focus
Face recognitionClearview AI, NEC, ID.meACLU litigation; state moratoria
Behavioral monitoringWorkplace AI, school AI proctoringEFF advocacy
Biometric identificationFingerprint, face, and iris databases; DNA databasesAccess Now international advocacy
Predictive policingPredPol, ShotSpotter, internal law-enforcement toolsACLU litigation; data-quality challenges
Government commercial spywarePegasus (NSO), Predator (Cytrox), CandiruAccess Now Digital Security Helpline; export controls
State surveillance infrastructureSharp Eyes (China), Aadhaar-adjacent (India), various national systemsInternational civil-society
Workplace surveillanceMicrosoft Productivity Score, AI activity-monitoring, AI screen-watchingEFF and ACLU advocacy
Border surveillanceDHS, ICE, and CBP AI-enabled monitoring; Saudi border-AIDHS — Department of Homeland Security (AI Deployer), ICE — Immigration and Customs Enforcement (AI Deployer), CBP — Customs and Border Protection (AI Deployer)

Natural-language search over camera networks

Police departments have used Flock's FreeForm natural-language search at least hundreds of times to look for people rather than vehicles, according to network-audit data reviewed on July 16, 2026. Documented queries include the California Highway Patrol searching 274 cameras for a "gray shirt," the Texas Department of Public Safety querying 96 camera networks, Milford (CT) police searching more than a hundred cameras for a "male with tattoos," and Anne Arundel County (MD) police querying 198 networks for a "white jeep with trump flag." Some searches referenced race despite Flock's stated guardrail barring attribute searches on race, ethnicity, religion, or nationality. Flock said FreeForm "is not facial recognition" and that it has no facial recognition in development. The ACLU's Jay Stanley said AI video analytics mean "giant oceans of video data can now be searched the same way big text files can be," and the Center for Democracy & Technology's Tom Bowman called the deployment "a classic bait-and-switch" (Source: 404media.co). See American Civil Liberties Union (ACLU), AI and Privacy.

Policy approaches

Jurisdictions regulate surveillance technology through several distinct modes. Some states and cities ban face recognition by law enforcement outright, while more permissive jurisdictions impose only disclosure or oversight requirements. Surveillance-tech exports are restricted under existing export-control regimes, including the Wassenaar Arrangement and BIS commercial-spyware controls. State attorneys general and the FTC apply consumer-protection law to AI-driven employment, housing, and education surveillance. Constitutional litigation proceeds under the 4th Amendment, the 14th Amendment, and state-constitutional provisions.

Face recognition regulation in the United States

Face recognition is regulated in the United States almost entirely at state level; Congress has not enacted legislation, though bills to place guardrails on law-enforcement use have been introduced, including the Facial Recognition Act (H.R. 4695, 119th Congress). Oregon was the first state to act, in 2017, with a narrow law confined to use in conjunction with police body cameras. By the close of 2024, fifteen states had laws limiting police use of the technology, up from twelve in 2022, according to a survey by the Center for Democracy & Technology's Jake Laperruque (Source: techpolicy.press). Figures in this section are as of that survey's January 2025 publication and have not been re-verified against later sessions.

The survey groups the state laws into three tiers by strength. Two states — New Hampshire and Oregon — restricted use only in combination with body cameras. Six — Alabama, Illinois, Minnesota, Massachusetts, New Jersey and Vermont — imposed one stronger limit such as a warrant requirement, notice requirement or serious-crime limit. Seven — Colorado, Maryland, Maine, Montana, Utah, Virginia and Washington — imposed multiple such limits. Cross-cutting the tiers, the survey counted a warrant, probable-cause or court-order requirement in four states (Maine, Massachusetts, Montana, Utah); a serious-crime limit in six (Illinois, Maine, Maryland, Montana, Utah, Vermont); a defendant-notice requirement in five (Colorado, Maryland, Montana, New Jersey, Washington); testing and accuracy standards in two (Colorado, Virginia); and a rule that a face-recognition match cannot be the sole basis for an arrest in seven (Alabama, Colorado, Maine, Maryland, Montana, Virginia, Washington) (Source: techpolicy.press).

Montana in 2023 and Utah in 2024 were the first states to require a warrant for police use, each with exceptions for emergencies and for identifying missing or deceased persons. The two rules differ in scope: Montana requires probable cause that the person to be identified is the perpetrator, victim or witness of a serious crime, while Utah requires a warrant to "obtain biometric surveillance information" but exempts use at law-enforcement buildings, critical infrastructure, courthouses, public schools and airports, and where there is "a documented reasonable articulable suspicion of a threat to commit a violent felony by a specific individual." Laperruque argues that Montana's witness category invites "surveillance by association" and that Utah's preemptive exception would appear to permit untargeted crowd scanning; he notes no documented US law-enforcement use of untargeted scans, against United Kingdom pilot programmes reported to have high error rates (Source: techpolicy.press). Maryland's 2024 law (SB 182) combines a serious-crime limit with a requirement that prosecutors notify defendants that face recognition was used.

Courts have supplied regulation where legislatures have not. New Jersey's rule originates not in statute but in the 2023 appellate decision New Jersey v. Arteaga, which held that defendants must be notified of police use of face recognition to protect due-process rights to potentially exculpatory information. A separate line runs through wrongful-arrest litigation: Robert Williams, the first person known to have been wrongly arrested and jailed on a face-recognition error, settled with Detroit police through the ACLU in 2024 on terms requiring officer training on the technology's risks, corroborating evidence before a match subject is placed in a photo lineup, use of a different photo than the one the system returned, and a bar on telling a lineup witness that a match was found. Laperruque describes these terms as going materially beyond the "sole basis" rule adopted in seven states, on the ground that a sole-basis rule still permits a match to be the primary basis for an arrest and to seed confirmation bias (Source: techpolicy.press).

The trend has not been uniform. California's law barring face recognition in conjunction with body cameras expired in January 2023 and had not been re-enacted or replaced as of the survey (Source: techpolicy.press). Bills had previously been introduced in Georgia, Hawaii, Kentucky, Massachusetts, Minnesota, New Hampshire and West Virginia.

Commercial spyware and export controls

Commercial spyware is regulated in the United States chiefly through export controls administered by the Bureau of Industry and Security. In November 2021 Commerce added NSO Group and Candiru to the Entity List for developing and supplying spyware to foreign governments, subjecting them to a licence-review policy of presumption of denial; two other firms were added in the same action for other malicious cyber activity. Commerce Secretary Gina Raimondo stated that the United States was "committed to aggressively using export controls to hold companies accountable that develop, traffic, or use technologies to conduct malicious activities that threaten the cybersecurity of members of civil society, dissidents, government officials, and organizations here and abroad" (Source: commerce.gov; sanctionsnews.bakermckenzie.com). A 2025 assessment from the UC Berkeley Center for Long-Term Cybersecurity treats Entity List designation and sanctions as one instrument among several the US government has used to mitigate human-rights harms from the spyware trade (Source: cltc.berkeley.edu). The controls operate on vendors rather than on the underlying capability, and the wider export-control architecture is described on Export Controls (AI).

Debates and tensions

A face-recognition system can function as a law-enforcement tool for criminal investigation or as an instrument of mass surveillance of dissent, and policy treatment of the same technology often turns on which framing applies. The line between commercial and governmental surveillance is similarly contested: consumer-side surveillance in workplaces and smart homes is regulated under privacy law, while government surveillance is regulated under constitutional and statutory law, a distinction that becomes harder to maintain as public-private partnerships expand. US-allied surveillance technology is exported globally, and civil-society organizations monitor whether export controls track human-rights concerns.

Relationships

See also

Open questions

  • The state face-recognition counts above are as of January 2025; how many states restrict police use as of 2026, and whether California re-enacted a limit, is not established here.
  • Whether Entity List designation has measurably reduced commercial-spyware sales is not settled in the cited assessments.

Sources

  • Jake Laperruque (Center for Democracy & Technology) / "Status of State Laws on Facial Recognition Surveillance: Continued Progress and Smart Innovations," Tech Policy Press (2025-01-06)
  • US Department of Commerce / "Commerce Adds NSO Group and Other Foreign Companies to Entity List for Malicious Cyber Activities" (2021-11-03)
  • Baker McKenzie Sanctions News / "US Government Adds Four Entities on the Department of Commerce Bureau of Industry and Security Entity List for Malicious Cyber Activities"
  • UC Berkeley Center for Long-Term Cybersecurity / "Managing Commercial Spyware Through Export Controls" (2025-03)
  • 404 Media / "How cops use Flock to track people, not cars" (2026-07-16)
  • Congress.gov / H.R. 4695, Facial Recognition Act, 119th Congress

Page created as a stub 2026-05-11; substantively expanded 2026-08-16.