AI surveillance in smart cities: is privacy dead and what can be done
Photo: N43 and HermesSmart cities are deploying AI-powered cameras, sensors, and data systems at scale. The privacy implications are real, and the regulatory responses vary sharply by country.
01How smart cities use AI surveillance
A smart city uses networked sensors, cameras, and data systems to manage urban services. When AI is layered on top, these systems gain the ability to recognise faces, detect behaviours, read licence plates, track movements across camera networks, and flag anomalies in real time. The stated goals are usually public safety, traffic management, and operational efficiency.
The scale can be enormous. Some cities operate tens of thousands of connected cameras feeding into AI analysis pipelines. The data is not just video—it includes mobile phone signals, transit card swipes, vehicle telemetry, social media posts, and environmental sensors. When fused together, these streams can create a detailed picture of where specific people are and what they are doing.
02The technologies monitoring public spaces
The core technologies include AI-enhanced CCTV that can detect objects and behaviours automatically, automatic licence plate readers (ALPR) mounted on poles and police vehicles, facial recognition systems that match faces against databases, and drone surveillance for aerial monitoring. Cell-site location data tracks phone movements between towers, and social media monitoring tools scan public posts for keywords and sentiment.
Each technology has different capabilities and limitations. Facial recognition accuracy drops sharply in crowds and across demographic groups. ALPR captures every plate that passes, creating detailed travel histories. The combination matters more than any single tool—a face matched at one camera, a plate read at another, and a phone signal in the same area can triangulate an individual with high confidence.
03What data is being collected and who has it
The data collected includes location histories, facial biometrics, vehicle movements, behavioural patterns, social connections, and spending records. The holders of this data vary: municipal governments, police departments, private security contractors, telecommunications companies, and technology vendors. Each has different retention policies, access controls, and legal obligations.
A critical concern is data sharing. When police can access privately operated camera networks, or when municipal data is shared with national intelligence agencies, the practical scope of surveillance expands far beyond what any single system was designed for. Aggregation across systems is what creates a comprehensive surveillance capability.
04The privacy implications for residents
Mass surveillance creates a chilling effect on lawful behaviour. When people know they are being watched and identified, they may avoid protests, religious gatherings, medical appointments, or meetings with particular individuals. This is not hypothetical—it has been documented in cities with dense camera networks and in countries where surveillance is tied to social scoring systems.
There is also the problem of error. Facial recognition systems produce false matches, especially for people of colour and women. A false positive can lead to wrongful stops, searches, or arrests. The harm is not evenly distributed: it falls hardest on communities already subject to disproportionate policing.
05How different countries approach smart city surveillance
Approaches vary dramatically. China has deployed the most comprehensive urban surveillance system in the world, with millions of cameras linked to facial recognition and tied to a national identity system. The United Kingdom has one of the highest camera densities among democracies, with extensive public CCTV but more limited facial recognition. The United States has a patchwork of local systems with growing facial recognition use by police despite city-level bans in some jurisdictions.
The European Union has taken the most restrictive approach, with GDPR providing strong data protection rights and several cities restricting or banning facial recognition in public spaces. The contrast between these models illustrates that the technology does not dictate the policy—societies can choose how much surveillance they accept.
06What regulation and oversight exist
Regulation is fragmented. The EU GDPR requires a legal basis for processing personal data and gives individuals rights to access, correct, and delete their data. Some US cities have banned facial recognition, while others have adopted it without public debate. China has data protection laws but applies them selectively to government surveillance. International standards for surveillance oversight remain weak.
Effective oversight requires more than laws. It needs independent auditing of surveillance systems, transparency about what is deployed and where, public registers of data sharing agreements, and meaningful penalties for misuse. Without these, legal protections can exist on paper while surveillance expands in practice.
07What citizens can do to protect their privacy
Individual action has limited power against systemic surveillance, but it is not meaningless. Citizens can advocate for local ordinances limiting facial recognition and data retention, request records about surveillance in their communities, support organisations litigating against warrantless monitoring, and use privacy-protecting tools such as encrypted communications and opt-out settings where available.
The most effective response is collective. Surveillance policy is set at the municipal and national level, and public engagement—attending council meetings, commenting on procurement decisions, voting for representatives who support privacy protections—is what determines whether smart cities become surveillance cities or remain tools for public benefit with appropriate limits.
AI Is Watching You: Is Privacy Dead in Smart Cities? (2026) / Future Shock / ~50K views / August 2026
By N43 and Hermes for Sailor Bob News.




