
Privacy · 11 min read
Live Facial Recognition in Public Spaces: The Surveillance Debate Comes to a Head
In August 2026, the EFF and civil society groups called on Nottinghamshire Police to halt the use of live facial recognition. The technology raises fundamental questions about privacy, consent, and the future of public life — and the answers vary dramatically by jurisdiction.
In August 2026, the Electronic Frontier Foundation and a coalition of civil society groups called on Nottinghamshire Police to halt the use of live facial recognition technology (LFR). The demand is the latest flashpoint in a growing global debate about whether automated surveillance belongs in public spaces — and whether the legal frameworks designed for an earlier era are adequate for the technologies of today.
Key Takeaways
- Live facial recognition (LFR) identifies individuals in real time by comparing camera captures against a watchlist, often without their knowledge or consent.
- The EU AI Act bans real-time biometric surveillance in public spaces, with narrow exceptions for specific threats.
- The UK is not bound by the AI Act, and police forces there continue to deploy LFR despite legal challenges.
- The EFF argues that LFR disproportionately affects marginalized groups and creates a chilling effect on public life.
- The Nottinghamshire case tests whether existing data protection and human rights frameworks are sufficient to regulate LFR.
How Live Facial Recognition Works
LFR uses cameras positioned in public spaces to capture images of people passing by. These images are processed in real time, compared against a watchlist of faces — typically compiled from police databases, custody photographs, and other sources — and matched against a biometric template. When a match is found, the system alerts operators, who can then decide whether to intervene.
The technology has improved significantly in recent years. Modern systems can identify faces at a distance, in low light, and even when part of the face is obscured by masks or sunglasses. But accuracy varies dramatically by demographic group. A 2019 study by the National Institute of Standards and Technology (NIST) found that many facial recognition algorithms had higher false-positive rates for women and people with darker skin. Subsequent research has shown that while accuracy has improved, demographic disparities persist.
Unlike traditional CCTV, which records footage for later review, LFR identifies individuals as they pass. This means the identification happens before any intervention, and it happens without the individual's knowledge or consent. The individual is not simply being recorded; they are being identified, checked against a database, and potentially flagged for attention.
The Core Objections
Civil society groups raise several objections to LFR in public spaces, and these objections are grounded in both legal and ethical concerns:
**Lack of consent**: People in public spaces cannot reasonably opt out of being scanned. Unlike a website that asks for cookie consent, a camera on a street corner offers no choice. You cannot decline to participate and still use the street.
**Disproportionate impact**: The demographic accuracy disparities documented by NIST and other researchers mean that LFR systems are more likely to misidentify certain groups. This creates a disproportionate risk of false positives — being incorrectly flagged as a match — for women, people with darker skin, and older adults.
**Function creep**: Even if LFR is deployed for a narrowly defined purpose — such as finding a wanted suspect — the infrastructure can be used for broader surveillance. The cameras, the databases, and the operational procedures can be applied to additional purposes once they are in place, often without the same level of public debate.
**Chilling effect**: The knowledge that one might be identified and tracked changes behaviour. People may avoid certain areas, refrain from protesting, or modify their movements simply because they know they are being watched. This is perhaps the most significant cost of LFR, but it is also the hardest to measure.
The Legal Landscape
The legal status of LFR varies dramatically by jurisdiction. The EU AI Act, which entered into force in 2024 and began enforcement of core rules in August 2026, bans real-time biometric surveillance in public spaces outright, with limited exceptions for specific threats such as a confirmed terrorist attack or the search for a missing person. These exceptions are narrow and require judicial authorisation.
The UK, however, is not bound by the EU AI Act. Police forces in several countries, including the UK, have continued to deploy LFR despite legal challenges. In 2020, the UK Court of Appeal ruled that the South Wales Police's use of LFR was lawful, but the case highlighted significant gaps in the legal framework. The Nottinghamshire case is significant because it tests whether existing legal frameworks — including the UK's data protection law and the European Convention on Human Rights — are sufficient to regulate LFR, or whether new legislation is needed.
The EFF's legal argument focuses on the lack of a specific legal basis for LFR in public spaces, the absence of meaningful public consultation, and the failure to conduct adequate data protection impact assessments as required by the UK GDPR.
What Is at Stake
The debate over LFR is not just about one technology. It is about the kind of public spaces we want to live in. Automated surveillance changes the relationship between individuals and the state: it shifts the default from "you are not being watched" to "you may be identified at any moment."
Once deployed at scale, LFR is difficult to reverse. The infrastructure — cameras, databases, watchlists — becomes embedded in policing operations, and the cost and political difficulty of dismantling it increase over time.
Age of Algorithms Perspective
The key question is not whether the technology works — it does, within limits — but whether its use is compatible with a society that values privacy, consent, and the freedom to move through public life without being tracked. The demographic accuracy disparities in current systems mean that the risks of LFR are not evenly distributed. The people most likely to be affected by false positives are those who already face disproportionate scrutiny from law enforcement.
For readers of Age of Algorithms, the practical takeaway is that the legal framework for LFR is still being written. The outcomes of cases like the Nottinghamshire challenge will shape the rules for years to come. In the meantime, the most effective protection is to support organisations like the EFF that are working to establish clear legal boundaries for automated surveillance.