Why the Center for Democracy and Technology Is Sounding the Alarm
Facial recognition technology has become one of the most widely deployed forms of AI surveillance, and law enforcement agencies increasingly rely on it to identify suspects, monitor crowds, and track movement in public spaces. A new issue brief from the Center for Democracy and Technology (CDT) lays out a stark framing for why this matters: facial recognition is dangerous when it fails, and dangerous in a different way when it succeeds.
That framing cuts to the heart of the debate over facial recognition privacy laws. When the technology misidentifies someone, whether due to poor lighting, low-quality images, or well-documented accuracy gaps across different demographic groups, the result can be wrongful suspicion or worse. But when facial recognition works exactly as intended, it enables a different kind of harm: the ability to track individuals as they move through their daily lives, often without their knowledge or consent. CDT's brief argues that both outcomes deserve scrutiny, not just the failure cases that tend to dominate headlines.
Which Jurisdictions Actually Limit Facial Recognition Use
One of the core problems CDT identifies is that legal protection against facial recognition surveillance is inconsistent depending on where you live. Some jurisdictions have moved to restrict how police and other government agencies can deploy the technology, requiring warrants, banning real-time use, or limiting it to specific investigative circumstances. Other places have no meaningful restrictions at all, leaving decisions about deployment almost entirely to individual agencies or departments.
This unevenness means that two people standing in different cities, or even different neighborhoods within the same metro area, can have dramatically different expectations of privacy when a facial recognition camera or mobile unit is nearby. Without a consistent national framework, protection against surveillance becomes a matter of geography rather than a guaranteed right.
Where Legal Protections Fall Short and Surveillance Persists
Even where rules exist on paper, CDT's brief highlights how gaps in enforcement, oversight, and transparency can undercut their effectiveness. Facial recognition deployments are not always publicly disclosed in advance, and affected residents often have no reliable way of knowing when or where the technology is being used until after the fact.
This is not a hypothetical concern. Recent controversy in the UK illustrates exactly how this plays out on the ground. In the case covered in Lewisham Councillor's Live Facial Recognition Van Map Row, a local politician's decision to publicly share the location of a facial recognition van sparked a national debate, precisely because that kind of location transparency is not something residents can typically count on. The incident shows how surveillance can operate quietly in public spaces, with awareness of its presence often depending on chance disclosures rather than systematic notification requirements.
This is the core tension CDT's brief points to: even robust facial recognition privacy laws mean little if the public has no reliable visibility into when and where the technology is actually being used.
What This Means for You
For most people, the practical reality is that facial recognition surveillance can occur in public spaces without clear notice, regardless of what local laws technically permit. Since legal protections vary so widely by jurisdiction, and since disclosure requirements are often weak or nonexistent, individuals are left to navigate a landscape where they cannot always predict when they are being scanned or tracked.
This does not mean privacy protection is impossible, but it does mean relying solely on legislation is insufficient. Awareness of local deployments, support for stronger transparency requirements, and general digital privacy hygiene all play a role in reducing exposure, even if they cannot eliminate the risk of facial recognition in public settings.
Practical Steps for Protecting Your Privacy
While no individual can fully opt out of public facial recognition surveillance, there are steps that can reduce overall exposure and support broader accountability:
- Stay informed about local deployments. Follow local news and community groups that track when and where law enforcement uses facial recognition technology in your area.
- Support transparency requirements. Advocate for policies requiring public notice before facial recognition tools are deployed, similar to the disclosure debate seen in the Lewisham case.
- Understand your jurisdiction's rules. Research whether your city or state has any facial recognition privacy laws, since protections differ significantly by location.
- Protect your digital footprint elsewhere. While facial recognition targets physical movement, minimizing unnecessary data sharing online reduces the overall surveillance profile that can be built about you.
- Engage with policymakers. Public comment periods and local council meetings are often where decisions about surveillance technology deployment are actually made.
CDT's brief is a reminder that facial recognition privacy laws remain a patchwork rather than a uniform shield. Until legislation catches up with the technology's capabilities, informed public awareness and sustained advocacy remain some of the most effective tools available to individuals concerned about surveillance in their communities.




