The Democratic Surveillance State - how AI changes what democracies can know and do.
- 15 hours ago
- 7 min read
By Elena Nikovski
What happens when liberal institutions inherit authoritarian capabilities?

Image : Cyber News https://cybernews.com/news/flock-cameras-data-vandalism-police/
On a lamppost near a Ventura intersection, a solar-powered camera photographs every car that passes. It doesn’t measure speed or issue tickets, but instead reads the plate, notes the model, and uploads all its identifiable features to a nationwide, searchable database. In Berkeley, California alone, 52 of these cameras now watch the streets. Nationwide, a crowdsourced mapping project called DeFlock has logged roughly 119,000 license-plate readers, more than four in five of them built by a single company, Flock Safety. Any of the thousands of police departments with a Flock contract - more than 4,500 of them, alongside 1,000 business- can query that database for any plate at any time, without a warrant.
Four thousand miles away, the European Parliament spent the summer debating whether messaging platforms should be allowed to scan private conversations for illegal content - even as the EU was simultaneously implementing the world’s most sweeping law restricting how AI can be used for surveillance. Democracies on both continents are living through the same contradiction; societies built on the premise that the state should not be able to see everything are now acquiring the technical ability to do exactly that.
The transition is more subtle than a sudden shift to dictatorship, which in some ways makes it harder to resist in our democratic state.
Before any developments in AI surveillance, the limit wasn’t the law, but the labour. For most of the twentieth century, the difference between a surveillance state and a free one was, in practice, a matter of arithmetic. Authoritarian regimes wanted total information but were held back by the manpower it took to watch, listen, and act on it.
In the past, democracies had the same technical constraints, plus constitutional ones added on top: warrants, judicial oversight, and legislative limits on data retention. And underneath all the legal infrastructure sat the fact that even a government determined to watch its citizens closely couldn’t physically do it at scale. For most people, privacy was protected equally by the state's limited capacity and the Fourth Amendment.
AI bypasses the arithmetic that democracies once relied on. One system can now read every license plate on every road, transcribe every intercepted call instantly, and flag patterns across millions of records without a human ever assigning the task. What’s changing isn't that governments have more data, because they have always had more than they can use. It’s that the processing constraint, which used to do democracy’s privacy-protecting work for free, is gone. Capability therefore no longer stands between citizens and total visibility. It's now something closer to policy - the laws and oversight bodies democracies now have to build on purpose because technology will no longer build the wall for them by accident.
Case Study 1: the U.S. building surveillance through the market
What’s striking is that in the U.S., it is not primarily the NSA or FBI who is building the new surveillance bureaucracy, but rather a private company.
Flock Safety, founded in 2017 and valued at roughly $8.4 billion, sells camera networks to homeowners’ associations, small-town police departments, and businesses, then stitches the results into a nationwide mass-surveillance system that's privately built rather than publicly run. The cameras don’t record video, but extract all identifiable features of automobiles - plate, model, bumper stickers - and store the information in cloud, typically for around 30 to 90 days. Flock has reported that its network supported over a million law-enforcement investigations last year and helped locate more than 10,000 missing people, which the company and many police chiefs point to as justification.
But the same infrastructure that finds missing people can just as easily track people the state has no business tracking. Last October, Texas deputies were able to search the Flock network to identify a woman seeking reproductive care that was illegal in her state - a search that only worked because plate data crosses state lines so easily. California restricts local agencies from sharing plate data with out-of-state or federal authorities - and is now suing the city of El Cajon for funnelling data to more than 100 agencies outside state lines. The case acts as a reminder that a rule on paper means effectively nothing without a technical system built to enforce it.
The narrative in American AI surveillance is that infrastructure is growing faster than the legal frameworks meant to govern it, largely because it is privately owned and voluntarily adopted. That makes it easier to evade the warrant requirements and legislative debate that would normally accompany a new government surveillance power. Nobody voted to create this searchable, real-time vehicle-tracking system that covers most of the country. It arrived through several thousand municipal contracts, and the country woke up living in it.
Case Study 2: EU debates on extent of surveillance
The EU’s Artificial Intelligence Act, which entered its broad enforcement phase in August 2026, is the most comprehensive AI law anywhere in the world. Within this framework, live public facial recognition is treated as a forbidden 'third rail' that crosses a strict legal boundary. Real-time public biometric identification like facial recognition is banned for police by default. It is permitted only for extreme emergencies - like kidnappings or terror threats - and still strictly requires prior court approval as well as time and geographic limits. On paper, this response sets a precedent: it identifies the worst dangers of the technology and builds legal walls before they can become normalized.
Since 2021, EU law has let messaging platforms voluntarily scan unencrypted messages for known child sexual abuse material (CSAM) and report matches to police - this is coined as the 'Chat Control' rule. It never touched encrypted apps like WhatsApp or Signal, because those platforms can't read the message in the first place. That voluntary rule needed periodic renewal, and on March 26, 2026, Parliament rejected the latest extension by a margin of roughly one vote, effectively ending it after years of on-and-off fights over whether to keep it alive.
But that whole debate was only ever about the voluntary, unencrypted version. The bigger debate is over a separate proposal - the permanent Child Sexual Abuse Regulation, still stuck in closed-door talks - which would require platforms to scan messages before they're encrypted on your own device. That would mean even a WhatsApp message could be flagged. Technologists on all sides agree that keeping strong encryption and scanning every message's contents aren't two compatible goals.
The EU is currently writing history's most careful rules around biometric surveillance while (behind closed doors) negotiating a law that would scan the private conversations of everyone who owns a phone.
This demonstrates a contradictory reality: while online behaviour is increasingly subject to policing in Europe, physical behaviour is increasingly subject to the same in the US. Yet, despite this growing surveillance, the governments and private companies carrying out this policing are themselves becoming less and less regulated.
How does this really change from surveillance we’ve had historically?
Exactly how alarmed should we be by this transition? Governments have always kept records, wiretapped suspects, watched borders, etc., but what's really changed is scale. The U.S. Supreme Court itself recognized the quantity of this scale in Carpenter v. United States (2018). The case asked whether police needed a warrant to obtain someone’s historical cell tower location data. This information is technically held by a third party (the phone company). The Court ruled 5-4 that they did, reasoning that location tracking over time was categorically invasive and exposed someone’s associations, habits, and private life. Courts are now debating whether the same logic should apply to license plate networks, which can reconstruct a person’s movements across an entire state or country with no warrant at all.
A single camera on a corner isn't a surveillance state. A hundred thousand networked cameras, searchable in seconds by anyone with a login, is something else - a person's entire pattern of life, 'queryable' on demand. The old line between democracies and authoritarian states - "yes, we could theoretically watch everyone, but we can't actually do it" - has quietly stopped being true on the democratic side too. What separates a democracy's camera network from an authoritarian one isn't capacity anymore. It's whether anyone bothers to build the oversight.
What governing AI requires
If the defining political question of the twentieth century was whether governments should be allowed to collect information at all, the defining question of the twenty-first century may be ‘what should be allowed once they can know almost everything?’. Several institutional answers are plausible though none have been fully built anywhere. For example:
Warrant requirements that track data sensitivity rather than data source; Carpenter pointed this out already - location data deserves protection based on what it reveals, not on which company happens to be holding it.
Retention limits with a real technical enforcement rather than just a written policy. While California’s rule against sharing plate data out of state exists on paper, the El Cajon lawsuit shows that a policy without enforced technical control is really just a suggestion.
There needs to be mandatory disclosure of who is searching the database and why. Investigative reporting across both Flock cameras and Chat Control continues to be the only reason abuses come to light. This probably signals that transparency requirements are doing the work that internal compliance isn’t.
Independent auditing of the private contractors who are building and operating a large share of this infrastructure, since companies like Flock sit largely outside of the oversight regimes that are designed for public agencies.
None of these suggestions require refusing the technology outright, and it can be assumed that few voters would even want that. Face-matching and plate-reading tools have real, documented value in finding missing people and solving crimes. But the tools continue to advance in engineering timelines while oversight advances on legislative pace - and these two clocks aren’t running at the same speed. The previous century’s response to state power was to limit what governments were capable of doing. Our century will need to be sturdier than that, because for the first time our own capabilities are not the limiting factor at all.
This article is part of our 2026 online summer series.
Sources:
Flock Safety
DeFlock camera count, company scale: CBS News – Colorado license plate readers, TechCrunch – Americans destroying Flock cameras
Flock company background, valuation, employee count: Wikipedia – Flock Safety
Texas deputy searching Flock/ALPR network for a woman who'd had an abortion: EFF – "She Got an Abortion. So a Texas Cop Used 83,000 Cameras to Track Her Down", Axios – Illinois says Texas breached abortion protection law
El Cajon lawsuit: California AG press release, Oct. 3, 2025, follow-up motion, Jan. 21, 2026
EU AI Act
Chat Control background and outcome: Wikipedia – Chat Control — confirms the interim extension ("Chat Control 1.0") was rejected March 26, 2026
Council of the EU information note, 27 March 2026 — trilogue failed to reach agreement on March 16, and Parliament voted at first reading March 25–26



Comments