The Law Can’t Keep Up With Flock’s AI Surveillance
It’s a windy day on the shore of Lake Michigan, and Maria is headed downtown from her home in Dolton, Illinois. As she has done several times this year, Maria plans to attend a peaceful protest at Grant Park against federal immigration policies. She has never been arrested and has even chatted cordially with police officers and federal agents stationed at previous events.
Agents working this protest have been instructed by their supervisors to be on the lookout for possible illegal immigrants and anti-government agitators. The agents activate a surveillance plan. Maria first encounters it shortly after pulling out of her driveway. As her red Honda Accord passes an automated license plate reader (ALPR), it captures an image of one of her bumper stickers with a pro-immigration slogan: “No human being is illegal.” The ALPR has been trained to recognize text such as bumper stickers, sending an automatic alert to a central computer. In turn, the computer sends signals to nearby artificial intelligence (AI)-enhanced “smart” street cameras to monitor the car’s movements.
A camera hanging from the W 71st St. overpass zooms in and captures an image of Maria’s face. The camera sends another ping to the computer, which identifies the driver as Maria (with, say, 91 percent confidence) based on her driver’s license photo and recordings of her at past rallies from officers’ body-worn cameras. The computer collects other data known about Maria from public records, including her registered nursing license. From the license, it pulls Maria’s home address. Next, the computer connects that information with recent police reports from the area. Nothing serious, but the report includes several mentions of pro-immigration graffiti on an abandoned building three blocks from where Maria lives. Possibly more significantly, the computer uncovers court records from 20 years ago, referring to a family dispute after Maria’s father was deported from the United States.
As the computer builds its profile of Maria’s life, she arrives near the park. Over the din of nearby traffic and speeches shouted through megaphones, she could not hear the whir of a police drone’s blades 400 feet above her even if she knew to listen. The drone’s cameras detect what they deem a suspicious bulge in Maria’s coat by her left hip and send that information to the computer, with, say, a 26 percent confidence calculation that she is a threat. The computer compiles that information with everything else it knows about Maria, crosses an unknown threshold determined by its algorithms, and alerts state and federal officers to be on the lookout for Maria. As she steps onto the green, an agent approaches.
“Hi, Maria,” the woman in camouflage fatigues says. “I’ve been waiting for you.”
Spooked, Maria returns to her car and goes home, passing another round of drones, cameras, and ALPRs. The federal government does not follow up. Maria wonders if the State of Illinois will turn its gaze on her next weekend—when she gets back in her red Honda Accord, with its other bumper sticker reading “a person is a person, no matter how small,” and heads to a pro-life sidewalk vigil.
Panopticon in 2026
Maria’s story is fictional. The surveillance it describes is not, and the coordination between devices required to make her story a reality is rapidly approaching due to advances in AI.
ALPRs (which, again, stands for “automated license plate readers”) are omnipresent and, at this point, misnamed. Over 6,000 cities nationwide have ALPRs, each of which can scan up to 2,000 vehicles per minute. Over 130,000 of these devices have been deployed across the U.S.
ALPRs are misnamed because they do not simply read license plates anymore. The leading ALPR manufacturer, Flock Safety, used to insist that this was all its technology could do. Yet according to August reporting by Wired, Flock “has now built ... an artificial intelligence tool for police that can identify drivers and track vehicles by their patterns of movement alone.” Flock’s AI-driven system “can pick out potential witnesses by how often their cars pass through a neighborhood, or surface a driver’s ‘associates’ from the cameras they pass together.” It combs through police files, 911 logs, commercial records, and other public information to connect tags to “names, home addresses, and relatives.”
According to Wired, an officer can use the system to “search for people in an area drawn on a map based on nothing more than a physical description.” The system is easy to use, supplying 69 prompts for officers “as a menu of canned searches,” for instance: “Find me witnesses based on vehicles most seen in [neighborhood] during [last 14 days] during [daily timeframe] *(will not include whitelisted vehicles).” Officers can also ask for a list of everyone “arrested more than twice in two years” for nondrug offenses, along with a map of their homes and detailed dossiers on “the top three individuals” who seem most suspicious, as selected by AI. With just one query, an officer can receive a report listing a person’s associated vehicles, any time they were mentioned as a witness in a police investigation, family members, phone numbers, and online accounts.
Prompts need not be based on criminal records. They include behavioral patterns as well. Law enforcement has searched using terms such as “heavy-set male with a black and white hat,” “person on skateboard,” and “person wearing orange vest and construction hat.” A study of 12 million searches submitted to Flock found that a fifth contained generic words such as “investigation,” “suspect,” or “query”—while hundreds of searches mentioned protest as a behavior of interest. (This is reason enough to doubt the effectiveness of Flock’s new policies requiring “officers to attach case codes to their searches.”) In 2019, California agencies scanned more than a billion tags, but “99.9% of this surveillance data was not actively related to an investigation when it was collected.” Some searches of Flock’s database have even been based on race or apparent political affiliation.
ALPRs will not stop here. Flock is hiring engineers to build new features, “including automated lead generation and cross-camera correlation.” Another company is developing a product called SignalTrace. It will enable ALPRs to read signals emitted by cellphones, wearable devices such as fitness watches and rings, and other Bluetooth-connected technology—enabling ALPRs to determine who and what is inside the cars passing them.
Moving up past eye level, public-monitoring security cameras have also become much more sophisticated. Many are “capable of 360-degree video, infrared vision, or the ability to pan, tilt, and zoom,” and they “can be equipped with real-time face recognition or license plate recognition software.” These cameras are often integrated with other devices such as ALPRs, drones, “smart” streetlights, gunshot-detection systems, and cell-site simulators that “mimic cell towers and trick phones” into sending them information. Security cameras are not the closed-circuit television devices of old. They can combine visual surveillance with audio and digital information-gathering to comprehensively monitor people within their range.
These devices can also be deployed on vehicles. News recently broke that Dallas garbage trucks have been equipped with AI cameras that photograph properties and assign a “blight score” based on suspected code violations. City officials expect the cameras to scan the entire city once a month. It is no stretch to imagine this technology quickly evolving from a means of punishing code violations into a massive database of images over time that government can use for whatever purposes it desires.
AI-enhanced cameras are the eyes on the ground of the modern surveillance apparatus. Yet the ones overhead are still more impressive.
Varying in size from “business jets [to] small enough to fit into the palm of someone’s hand,” drones can be “virtually undetectable.” They can carry cameras, thermal imaging sensors, microphones, ALPRs, facial recognition software, cell-site simulators, and even weapons. They can, and do, “observe individuals in previously private and constitutionally protected spaces, like their backyards, roofs, and even through home windows.”
More than 1,400 police departments now use drones, a number that is growing as cities continue to adopt “drone as first responder” programs. These programs deploy drones in response to 911 calls and nonemergency service requests, and drones can help officers assess a situation before arriving at the scene. However, they also enable around-the-clock warrantless—often, suspicionless—surveillance.
Since Chula Vista, California, began its drone-as-first-responder program in 2018, drones have “criss-cross[ed] the skies ... nearly 20,000 times.” The drones have amassed hundreds of hours of video footage of the city’s residents, routinely flying “over backyards and above public pools, high schools, hospitals, churches, mosques, immigration law firms, and even the city’s Planned Parenthood facility.” While Chula Vista maintains that the city does not use drones for routine surveillance, city records show that it is not uncommon for drones to be deployed in response to minor complaints, such as “reports of ‘loud music’, a ‘water leak,’ and someone ‘bouncing a ball against a garage.’” Other cities have used drones to surveil public events and protests, search for zoning and code violations, and enforce pandemic-era social distancing—even to monitor Labor Day backyard parties.
As with ALPRs and security cameras, the door remains open to even more terrifying technologies. Drones such as the military’s Gorgon Stare—which provide citywide, high-definition imagery from 25,000 feet in the air—could be deployed by law enforcement.
Somewhere in the ethereal data “clouds” are the AI systems that make this information storable and usable by law enforcement. There are not enough human officers on Earth to meaningfully assess the infinite data points collected from the devices described above. Law enforcement relies on AI to swiftly navigate through the information housed in acres of data centers.
Yet how those systems function is a mystery by design. Any system simple enough for a human to neatly understand would not be sophisticated enough to enable the quantum leaps in investigation the modern panopticon promises. An entire field of computer science called “interpretability” recognizes this shift, moving from treating AI processes as readily understandable tools toward understanding them as “complex structures arising from unknown rules.” Like “galaxies and starfish and cancer cells,” stepping back and treating AI as a “black box” may prove the more honest approach. These systems use unknown processes to interpret data. They do so in ways that have proved to be dangerous.
The Weaponization Threat
AI-powered devices already enable disparate treatment according to viewpoint and federally protected characteristics. In 2019, the Department of Justice reported it had awarded the Chicago Police Department a grant to work with a state university and develop “algorithms to collect information and form initial groupings that focus on constructing social networks and performing analysis to determine potential high-risk individuals.” In other words, the Chicago Police Department would build “predictive policing” technologies to decide who in the community might pose a threat of violence.
Three years later, scholars researched the program’s effects. The academics determined that Chicago’s predictive-policing AI had yielded only “limited insight into the social system of crime” even as it “enhance[d] state power through criminal surveillance.” Data from Chicago and other cities using the system reflected that “the response to increased crime is biased by neighbourhood socio-economic status, draining policy resources from socio-economically disadvantaged areas.”
More broadly, a May RAND report commissioned by the Council on Criminal Justice (of which one of the co-authors is a member) warned: “AI applications relying on past criminal justice data tend to systematically reproduce racial and socioeconomic disparities.” As the American Civil Liberties Union explains, “bias is in the data used to train the AI—data that is often discriminatory or unrepresentative for people of color, women, or other marginalized groups—and can rear its head throughout the AI’s design, development, implementation, and use.”
In addition to targeting people based on federally protected characteristics, AI surveillance can readily be weaponized based on viewpoint. This is due to serious gaps in the constitutional jurisprudence that regulates law enforcement. The Supreme Court has yet to say whether the following count as a search or seizure for Fourth Amendment purposes:
- Collecting data about every call made to or from a number, as the Biden administration did with Republican members of Congress.
- Pulling data from 83,000 Flock cameras to track a woman who had an abortion, as a Texas deputy did.
- Accessing ALPR data over 100 times to track a veteran who lawfully recorded a traffic stop, as happened recently in Waukesha, Wisconsin.
- Spying into apartment bedroom windows using cameras on utility poles, as the New York Police Department could readily have done.
- Following someone’s every public move using military-grade Predator drones, as the Department of Homeland Security did at anti-Immigration and Customs Enforcement (ICE) protests last year.
- Demanding bank and internet records without notifying the person under investigation.
- Telling protest observers: “We have a nice little database, and now you’re considered a domestic terrorist. So have fun with that,” as an ICE officer did to a Maine woman.
- Demanding that Google hand over internet records and deploying investigators to the homes of critics, as the Department of Homeland Security did to a Pennsylvania retiree who sent an email in support of an Afghan refugee.
At least as far as the public can tell, not all of these measures have been used to pressure political dissenters—yet. But on Dec. 4, 2025, the Department of Justice ordered the FBI to make an unprecedented list of organizations it considers “domestic terrorists” who allegedly advance anti-American agendas, and then create a bounty system to reward tips. The Trump administration is also creating a previously unheard-of “reaction force” of National Guard troops to combat “civil unrest.” And it has vowed to “disband and uproot networks, entities, and organizations that promote organized violence, violent intimidation, conspiracies against rights, and other efforts to disrupt the functioning of a democratic society.” One of the first major operations appears to have been conducted in Minneapolis, where federal agents surveilled progressive, labor, and immigrant-rights groups.
It is hard to imagine any such campaign, or any other targeting entire swaths of Americans for their political beliefs, being executed without the AI analysis of colossal amounts of data and the deployment of myriad AI-enhanced surveillance technologies. AI policy must be designed to prevent its misuse for illegal discrimination and political oppression.
Sensible Safeguards and Obstacles to Implementing Them
Experts have begun developing guidelines to ensure that AI enhances legitimate law enforcement purposes without sacrificing equality, privacy, and political freedom. The Institute for Justice has drafted model legislation with four key requirements: (a) judicial warrants for nonemergency police review of a person’s historical location data; (b) limits on the transfer of historical location data to third parties; (c) verifiable documentation of who accesses historical location data and for what purposes; and (d) mandatory officer training on these rules. The RAND report for the Council on Criminal Justice recommends policies around AI method verification, human oversight and final decision-making, bias reviews, transparency, accountability, education, and “clear boundaries for algorithmic influence in domains that can have grave consequences for individual liberty.”
Yet policy barriers will work only if law enforcement and AI providers accept democratic supervision.
Illinois law blocks the use of ALPR data for federal immigration enforcement—but state regulators found that Flock violated those limits and ran a pilot program anyway. While federal immigration officials do not have a contract with Flock, “the agency sources data from Flock’s cameras by making requests to local law enforcement,” with “more than 4,000 nation[al] and statewide lookups by local and state police done either at the behest of the federal government or as an ‘informal’ favor to federal law enforcement.” This practice has happened in Illinois despite its being illegal under state law. Even if one state agency is unwilling to share data with the federal government, it is often sharing it with other agencies that may acquiesce. Designing better laws to govern AI would be wise—and insisting on enforcing existing state limits on data-sharing is important, too.
Other reforms to criminal law would also help reduce the threat posed by AI-aided surveillance. Criminal law contains myriad offenses buried in regulations and codebooks, constructing a legal framework that tries to reach every social ill. Many of these provisions are crafted so vaguely that their enforcement depends almost entirely on the discretion of prosecutors and police. That enables undue surveillance: A government with an axe to grind against a critic can readily dream up excuses to put someone under its gaze.
Compounding this problem, the Supreme Court allows law enforcement to stop and search people using pretextual reasons. According to the Associated Press, the Border Patrol is using AI predictive algorithms to flag vehicles agents deem suspicious, which are then stopped by officers “for reasons cited such as speeding, failure to signal, the wrong window tint or even a dangling air freshener blocking the view. They are then aggressively questioned and searched”—all the while unaware that this is happening because of federal AI assessments. And these practices are not limited to what most people think of as America’s borderlands: The Border Patrol operates surveillance “near the Michigan-Indiana border to capture traffic headed towards Chicago or Gary, Indiana.”
Without civil liberty protections, these methods may even be used against critics of AI surveillance. Flock’s chief executive Garrett Langley recently called the company’s opponents “terroristic.” Joint intelligence centers run by federal, state, and local law enforcement are monitoring social media accounts critical of AI-enhanced surveillance. After Rhode Island police officer Noel Pichardo criticized his department’s use of Flock cameras, “he was subjected to five internal affairs investigations in less than two years.” Policymakers should address the risks faced by citizens critical of AI surveillance.
Lastly, lawmakers should abolish qualified immunity. That legal doctrine prevents victims of rights violations by state and local officers from receiving redress unless officers violate a right that is “clearly established.” Due to the rapid development of AI-powered surveillance, courts will struggle to issue precedents establishing what counts as a rights violation before the case law becomes effectively obsolete. The government will often be able to draw some factual distinction between whatever surveillance it uses and past case law, thwarting victims from a judicial remedy.
Law enforcement is using tools that can tell officers who you associate with, where you sleep, and what you believe. They call it safety. The law should call it a search and impose the safeguards and remedies that accompany one.
