I was in Cardiff city centre a few weeks back, just picking up lunch, when I noticed a van parked near the entrance to St David’s shopping centre. White, unmarked, with what looked like a camera array pointed at the stream of people walking past. No signs explaining what it was doing. No one stopping to look at it. Just hundreds of people moving through its field of view, entirely unaware. That van was almost certainly running live facial recognition technology. And that scene, unremarkable as it felt, is now playing out in cities across Britain on a near-weekly basis.

The expansion of facial recognition technology UK-wide has accelerated dramatically since 2023. South Wales Police and the Metropolitan Police have both deployed live facial recognition cameras at public events, on high streets and at transport hubs. The Met alone ran over 30 deployments in 2024, scanning hundreds of thousands of faces against watchlists of wanted individuals. By early 2026, forces including Leicestershire, Northamptonshire and Merseyside have trialled or adopted the technology. And it is not just the police. Retailers including Frasers Group, which owns Sports Direct and House of Fraser, have been using facial recognition systems inside their shops for years, matching shoppers against internal databases of alleged previous offenders.
What is actually happening when a camera scans your face?
Live facial recognition works by converting your face into a numerical template the moment you walk into its field of view. That template is then checked against a watchlist in real time, typically within a second or two. If there is a match above a certain confidence threshold, an alert goes to an operator who can then decide whether to approach the person. The cameras do not store images of everyone they scan, according to police guidance, but the process of scanning and generating a template is itself a form of data processing under UK GDPR, which the ICO has been investigating for several years without reaching any definitive enforcement action.
The civil liberties organisation Big Brother Watch has been loudest in raising the alarm. Their research suggests that early iterations of Met Police facial recognition had error rates affecting a significant proportion of alerts, and that women and people with darker skin tones were disproportionately misidentified. The technology has improved, but the core question of whether it should be deployed in public spaces without explicit parliamentary authorisation has never been properly answered. There is, remarkably, no specific law governing the police use of facial recognition in the UK. Forces are operating under a patchwork of existing powers, data protection law and internal guidance. That is an extraordinary situation for a technology this invasive.
The private sector surveillance problem
The police deployments at least come with some form of public accountability, however imperfect. The private retail use is murkier. Frasers Group drew widespread criticism in 2022 when it emerged their stores were scanning shoppers without clear signage. The Information Commissioner’s Office looked into it. Small notices eventually appeared. But the fundamental question, whether a private company should be able to run facial recognition technology on everyone who walks through their door, remains legally unresolved. A 2025 report by the ICO found that many UK organisations using biometric surveillance were not meeting their obligations under data protection law, but enforcement has been sluggish.

My read of this is that Britain has drifted into a situation where the technology moved faster than the regulators, and now everyone is scrambling to catch up. I’ve covered enough of these stories to know how this goes. Something gets deployed quietly, becomes normalised through repetition, and by the time Parliament gets round to legislating it, the horse has long left the stable. We saw the same pattern with predictive policing algorithms, with a police service already under enormous strain turning to technology as a cheap force multiplier, often without the governance frameworks to match.
What makes facial recognition different from ordinary CCTV is the automated, real-time identification of individuals. Traditional CCTV is a passive recording system. Facial recognition is an active identification system. Every person who walks past a live camera is being checked against a database without their knowledge or consent. If you received an email from a company telling you they were running your photo through a criminal database every time you visited their website, you would probably be outraged. But when it happens on the pavement outside Primark, most people have no idea.
Is the UK becoming one of the most surveilled democracies?
Big Brother Watch and Liberty both argue that the UK is now among the most surveilled democratic nations in the world. Britain already had one of the highest densities of CCTV cameras per capita globally before facial recognition entered the picture. According to BBC reporting from 2024, the UK has an estimated 7 million CCTV cameras in operation, roughly one for every nine people. Layering live facial recognition onto that existing infrastructure is a qualitative shift in what surveillance actually means.
The comparison with China often gets deployed in these debates, usually by people who want to shut the conversation down. “We’re nothing like China” is the default response. And that is true in some obvious ways. But the relevant comparison is not authoritarian surveillance states. The comparison is with other democracies. Germany has strict constitutional protections that make mass biometric surveillance effectively illegal. France’s data protection authority, the CNIL, has taken a hardline approach to facial recognition in public spaces. The EU’s AI Act, which took effect in 2024, places stringent restrictions on real-time biometric surveillance in public spaces across member states. The UK, post-Brexit, is under no obligation to follow that framework, and shows no sign of doing so voluntarily.
What the government has actually said
The Home Office position, held across successive governments, is that facial recognition technology is a legitimate tool that helps catch criminals and protect the public, and that the existing legal framework is sufficient. A police recruitment crisis that has left forces with fewer officers than a decade ago makes that argument more politically convenient than ever. When you cannot hire enough officers to walk a beat, the temptation to deploy cameras that do some of the work for free is obvious. Keir Starmer’s government has not proposed specific facial recognition legislation, and as of mid-2026, none is expected imminently.
The technology companies selling these systems are not exactly neutral observers either. NEC, Idemia and a handful of UK-based firms have been marketing their products aggressively to both public and private sector buyers. The commercial incentives to expand deployment are enormous. And the procurement processes involved are rarely subject to the kind of public scrutiny that, say, housing policy failures receive. A council buying facial recognition cameras for its town centre does not generate the same headlines as a council that fails to fix damp in social homes, even though both decisions affect ordinary people’s lives in significant ways.
Oli and I have been talking about this one for a while, and we both keep coming back to the same point: the problem is not that the technology exists. The problem is that Britain has collectively decided not to decide. There is no democratic mandate for a surveillance infrastructure of this scale. There has been no proper parliamentary debate, no public consultation, no primary legislation. The facial recognition technology UK police are using today was approved through internal guidance documents and a scattering of judicial reviews, not through any process that resembles informed democratic choice.
If you want to understand just how normalised this has become, consider that some researchers have started using this provider to run tests on how surveillance-related communications are being handled by organisations, checking whether notification emails about data processing are even reaching the people they are meant to inform. It is a small detail, but it points to a larger dysfunction: systems that are supposed to provide transparency are not working as intended at any level, from the cameras on the street to the privacy notices in your inbox.
Parliament needs to legislate. The ICO needs real enforcement powers and the political backing to use them. And the rest of us need to at least notice the van parked outside the shopping centre. The surveillance state does not announce itself. It just quietly expands until one day you cannot remember a time when it was not there.














