On June 23, the Metropolitan Police (the Met) announced plans to introduce static live facial recognition cameras across London’s West End and Soho by the end of the year. The force said the system would build on its pilot in Croydon, South London, where cameras mounted on existing infrastructure helped officers make more than 170 arrests. According to the Met, the West End and Soho cameras will be static but movable, allowing officers to reposition them as crime patterns shift. The same announcement described live facial recognition as part of a wider shift toward technology-led policing in the capital.
This captures something larger than one policing tool. Britain has built one of the most elaborate legal frameworks for surveillance in the democratic world. The 2016 Investigatory Powers Act placed interception, communications data, equipment interference and bulk powers into a single legal framework. It also introduced the “double lock,” under which the most intrusive warrants require authorization by a Secretary of State and approval by a judicial commissioner. Created by the Act as an independent supervisor of investigatory powers, the Investigatory Powers Commissioner’s Office (IPCO) authorizes and oversees their use, works with judicial commissioners and publishes annual reports. Its remit covers over 600 authorities, including intelligence agencies, law enforcement bodies, prisons, local authorities and regulators.
Together, these arrangements create dense administrative machinery that confines scrutiny to specialist institutions beyond most citizens’ reach. Citizens consequently encounter surveillance powers only after they affect ordinary life. This delay creates a slippery slope in which powers introduced for investigatory purposes can spread beyond security into wider public administration. Democratic accountability begins with citizens’ ability to understand and challenge these powers before they become normalized.
Facial recognition treats public movement as suspicious
Police forces in the UK use facial recognition technology to compare images against databases or watchlists. Parliamentary research published in April 2026 states that police use three main types of facial recognition: retrospective, live and operator-initiated. The same research states that live facial recognition scanned 4.6 million faces across England and Wales in 2024, while retrospective facial recognition was used more than 250,000 times.
The Home Office, the UK’s interior ministry, frames this expansion as a matter of public safety. In August 2025, it announced funding for ten new live facial recognition vans across seven forces, saying the technology would target “high-harm criminals” and operate under College of Policing guidance. The government’s January 2026 policing white paper then placed facial recognition inside a much wider program of AI-enabled policing. By June, the Home Office was presenting police AI as part of a national program of public-sector modernization, with investment in PoliceAI and live facial recognition vans.
That convergence also appears in recent litigation: On April 21, the High Court dismissed a challenge to the Met’s live facial recognition policy brought by Shaun Thompson and Silkie Carlo of the campaign group Big Brother Watch. Thompson, a Black community worker, had been mistakenly identified near London Bridge after the system matched him to an image of his brother. He was stopped, questioned and asked to prove his identity. The High Court’s judgment resolved the legal challenge to the policy, while leaving the wider democratic argument over public biometric scanning unresolved. The court emphasized that its role concerned legality rather than the merits of facial recognition as a policing tool.
Critics argue that such systems place large numbers of innocent people into a “digital police lineup” as they pass through public space. Accuracy and bias require direct scrutiny because facial recognition produces probabilistic judgments with social consequences. A wrongly flagged person can be publicly marked as suspicious during a police encounter, with the greatest burden falling on communities already subject to disproportionate police attention. Parliament should establish a statutory framework for biometric governance because this technology requires democratic authorization.
Bulk data has moved surveillance upstream
Earlier surveillance politics focused on interception. The 2024 amendments pushed the debate further upstream, toward bulk data processing before any individual becomes the subject of suspicion.
The 2024 Investigatory Powers (Amendment) Act updated the 2016 framework by expanding the legal treatment of bulk personal datasets: large collections of information that intelligence services may examine even when many people inside them are of no direct intelligence interest. The 2024 Act created a new regime, governed by a June 2025 code of practice, for datasets where there is a “low or no reasonable expectation of privacy.” The code applies to the Security Service (MI5), the Secret Intelligence Service (MI6) and the Government Communications Headquarters (GCHQ) when they retain and examine such datasets.
The government’s justification emphasizes operational speed because intelligence agencies now operate within data ecosystems that move faster than older legal categories can govern, creating the democratic risk of large-scale inference. Aggregation turns ordinary records into biography, so public oversight should focus on what the state can infer from data at scale. But data-collection systems do not stop at national borders. They depend on global infrastructure that brings British surveillance law into the technologies people use around the world.
Encryption brings British surveillance law into global infrastructure
Advanced Data Protection is Apple’s opt-in system that extends end-to-end encryption to additional iCloud categories. With this protection enabled, even Apple cannot access certain user data.
In February 2025, Apple withdrew Advanced Data Protection for new UK users after reports that the British government had demanded access to encrypted iCloud data. Privacy International and Liberty have continued to challenge the secrecy and operation of this regime, while further reporting has kept the dispute alive.
This episode places British surveillance law inside the infrastructure of global technology. Strong encryption loses its value when systems are redesigned for routine third-party access.
The Salt Typhoon telecoms hack in the United States exposed the same structural risk. Reports on Salt Typhoon suggested that hackers may have accessed infrastructure used for court-authorized wiretapping, showing how surveillance access points can become security liabilities. Britain’s encryption debate concerns public security because weakened protections expose sensitive communications at scale.
Scandals are part of oversight
Public accountability often arrives through disruptive scrutiny. Litigation, leaks, scandals, investigative reporting and whistleblowing make secret power visible.
The Agent X case is a clear example of this. In 2025, the prime minister directed the Investigatory Powers Commissioner to investigate MI5’s provision of incorrect evidence in the case. A written statement said the High Court had concluded that it, the Investigatory Powers Tribunal, the Investigatory Powers Commissioner and special advocates had been misled by MI5.
The case struck at the informational foundation of oversight. Courts, commissioners and special advocates can only scrutinize secret activity if the intelligence agencies before them provide accurate accounts. A failure at that level damages the public case for closed oversight.
There have also been signs of friction between oversight bodies and government departments. Coverage of IPCO’s 2024 annual report stated that David Cameron, while foreign secretary, had refused IPCO access to certain security documents in July 2024, before they were later provided in September 2024.
External scrutiny has caught what internal channels missed, too. In 2021, the Grand Chamber of the European Court of Human Rights ruled in Big Brother Watch and Others v. the United Kingdom, a case on bulk interception, that parts of the UK’s previous regime violated privacy and freedom of expression rights. The court emphasized the need for “end-to-end safeguards” in bulk interception systems.
Snowden’s 2013 disclosures and the later Agent X litigation show how surveillance failures often become intelligible to the public only after official channels have failed to explain themselves. Closed systems can appear carefully supervised while remaining difficult for the public to test.
Age checks extend surveillance into ordinary digital life
The surveillance debate has also moved into online childhood policy. In June 2026, the government published new rules to protect children online, including a planned social media ban for under-16s and stronger requirements for age checks. The first regulations are expected before the end of 2026, with implementation planned for spring 2027.
The policy is framed as child protection, a widely appealing justification that can still build digital identity infrastructure. Online age checks are supported by the same verification logic as wider surveillance policy: A narrow justification can still expand the state’s appetite for identity infrastructure. Public scrutiny should examine how age-verification data is generated, stored, reused and exposed.
Public-facing control should come next
Public reporting should become more intelligible. Oversight bodies should explain, in plain language, the kinds of risks they encounter, the errors they identify and the remedies they require, without disclosing operational secrets. The state should also treat journalists, civil society groups, researchers, litigants and whistleblowers as part of the accountability ecosystem because they translate secrecy and complexity into public language.
Parliament should legislate specifically on live facial recognition. A technology that scans faces in public should have a statutory regime for biometric governance. Judicial Commissioners should receive the authority and technical support needed to test necessity and proportionality with real independence. The double lock should apply meaningful scrutiny to necessity and proportionality.
Online age-check systems should also receive public scrutiny before they become embedded into ordinary digital life. Ministers should explain how online age checks create identity trails and how those trails will be limited.
Britain’s surveillance state needs an informed public capable of upholding accountability before surveillance overreach becomes ordinary.
[Francesca Collu edited this piece.]
The views expressed in this article are the author’s own and do not necessarily reflect Fair Observer’s editorial policy.
Support Fair Observer
We rely on your support for our independence, diversity and quality.
For more than 10 years, Fair Observer has been free, fair and independent. No billionaire owns us, no advertisers control us. We are a reader-supported nonprofit. Unlike many other publications, we keep our content free for readers regardless of where they live or whether they can afford to pay. We have no paywalls and no ads.
In the post-truth era of fake news, echo chambers and filter bubbles, we publish a plurality of perspectives from around the world. Anyone can publish with us, but everyone goes through a rigorous editorial process. So, you get fact-checked, well-reasoned content instead of noise.
We publish 3,000+ voices from 90+ countries. We also conduct education and training programs
on subjects ranging from digital media and journalism to writing and critical thinking. This
doesn’t come cheap. Servers, editors, trainers and web developers cost
money.
Please consider supporting us on a regular basis as a recurring donor or a
sustaining member.
Will you support FO’s journalism?
We rely on your support for our independence, diversity and quality.







Comment