A conventional camera records a scene. A camera connected to artificial intelligence can interpret it: detect faces, compare biometric features, follow a person between locations, recognise licence plates and flag behaviour considered anomalous. The decisive change is not more electronic eyes, but an automated memory capable of linking them.
In a city filled with cameras almost everyone is recorded. When footage remains separate and is consulted only after an event, surveillance has practical limits. AI removes many of those limits: it can search thousands of streams, convert a face into a biometric template and reconstruct routes in seconds. Surveillance can become continuous rather than episodic.
Facial recognition does not merely store a photograph. It extracts a numerical model and compares it with others. The EDPB stresses that biometric processing is a serious interference even when there is no match and the template is later deleted. Being scanned is already an act, not only the positive result of a search.
The promise is security: finding a missing person, identifying a suspect, controlling access or responding faster. These can be legitimate purposes. The danger begins when an exceptional tool becomes the ordinary infrastructure of public space. If searching for a few people requires biometric analysis of everyone, every passer-by is treated as a possible target before a concrete reason exists.
Accuracy does not settle the issue. Systems can generate false positives and affect groups unequally. Yet a nearly perfect system creates an even deeper problem: it makes it possible to know where a person goes, whom they meet, which protest or place of worship they attend and which habits they repeat. Risk comes not only from error, but from the power created by precision.
Knowing that identification is possible changes behaviour. A square may remain physically open but it is experienced differently when every presence can be archived and linked to an identity. Surveillance can chill assembly, association and expression without punishing anyone directly.
The EU AI Act generally prohibits real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes, with narrow exceptions that must be necessary, proportionate and authorised. It also prohibits certain forms of biometric categorisation and social scoring. Context, purpose, legal basis and the actor using the system still matter.
Facial recognition is not the only invisible layer. The same network can analyse gait, clothing, movement, crowd density, pauses and relationships. Even without naming someone, it can create persistent profiles. Asking only whether a face is stored is no longer enough.
A proportionate system should begin with a narrow purpose, minimise data, define retention, log every search, measure errors and discrimination, allow independent oversight and publish its rules. Watchlists need justification; a match must not become an automatic decision; people need a way to challenge the result.
The difference between protection and mass control lies in the architecture behind the camera. Who can query it? Which databases are connected? How long does memory last? Does a search require authorisation? Can data be reused? Without verifiable answers, “security” does not describe the power being installed.
AI cameras force us to discuss public space before their infrastructure becomes invisible. The choice is not between absolute security and no technology. It is whether the technical capacity to watch everyone will be mistaken for the right to do so.