The Dark Side of AI · Report
Thank you for reading this post, don't forget to subscribe!
Home / Indexes / The Dark Side of AI / Surveillance & Privacy
AI Surveillance & the Privacy Crisis 2026
One company scraped an estimated 50 billion faces off the open web without asking anyone. By 2019 at least 75 governments were already running AI surveillance — and the technology has only spread since.
Updated July 2026. Every figure below is linked to its primary source and dated.
The database of 50 billion faces
Modern facial recognition did not arrive through a government program. It arrived through a startup. Clearview AI built its product by scraping photographs from public websites and social media — images that people posted for friends, employers or dating profiles, never for a police line-up. The company told the public it held roughly 3 billion images when The New York Times first exposed it in January 2020; it has since described a database that grew past 10 billion, then 30 billion, and in later court filings and press statements referenced a target of 100 billion, with independent reporting placing the working collection at 50 billion or more images. Whatever the exact count on any given day, the mechanism is the same: a face posted anywhere becomes a searchable biometric identifier without the subject’s knowledge or consent.
That model collided immediately with data-protection law. In May 2022 Clearview settled a lawsuit brought by the American Civil Liberties Union (ACLU) under Illinois’ Biometric Information Privacy Act (BIPA), agreeing to a nationwide ban on selling its faceprint database to most private businesses and individuals in the United States. European regulators went further and treated the scraping itself as illegal. The pattern that emerged — a single vendor, a global database, and a scramble of national regulators trying to claw it back — is the story of AI-era privacy in miniature.
The surveillance layer over public life
Clearview is the most notorious name, but it is one supplier in a market that has quietly become a standard feature of statecraft. The Carnegie Endowment for International Peace’s AI Global Surveillance (AIGS) Index, published in September 2019, compiled empirical data across 176 countries and found that at least 75 were actively deploying AI surveillance tools: 64 using facial recognition systems, 56 building “smart city” or “safe city” platforms, and 52 running smart-policing programs. Carnegie noted that this cut across regime types — liberal democracies were among the buyers, not just autocracies — and that Chinese firms including Huawei, Hikvision, Dahua and ZTE were supplying the technology to dozens of countries.
Freedom House has tracked what happens next. Its Freedom on the Net reports for 2023 and 2024 describe AI as an amplifier of digital repression: automating censorship, scaling up monitoring of online speech, and letting governments watch more people with fewer officers. The organization’s central finding is not that AI invented state surveillance, but that it removed the human labor that once limited its reach. The enforcement record below shows how regulators have responded where the law gave them standing.
| Action | Authority & date | Outcome |
|---|---|---|
| Italy — Garante fine | Garante per la protezione dei dati personali, March 2022 | €20M penalty; ordered deletion of Italian residents’ biometric data and a ban on further processing |
| United Kingdom — ICO | Information Commissioner’s Office, May 2022 | Fine of £7.5M and an enforcement notice to delete UK residents’ data (later contested on jurisdiction) |
| France — CNIL | Commission Nationale de l’Informatique et des Libertés, 2021–2022 | Order to cease collection and delete data; subsequent overdue-compliance penalties |
| United States — BIPA settlement | ACLU v. Clearview AI (Illinois), May 2022 | Nationwide ban on selling the faceprint database to most private entities |
When the match is wrong
The privacy argument is often framed as a trade against security. But facial recognition also fails, and it fails unevenly. In 2019 the U.S. National Institute of Standards and Technology (NIST) published a landmark evaluation of demographic effects in its Face Recognition Vendor Test, examining 189 algorithms from 99 developers. It found false-match rates that were often ten to one hundred times higher for Asian and Black faces than for white faces in one-to-one matching, with women and older adults also disproportionately misidentified. An error rate that looks small in aggregate is not distributed evenly across the population being searched.
Those differentials have real names attached. In January 2020 Robert Williams was arrested outside his home in front of his family in Detroit after a flawed facial-recognition match — the first documented case in the United States of a wrongful arrest driven by the technology. He was not the last; several more wrongful arrests, disproportionately of Black men, have since been reported and litigated. The same statistical bias reappears in predictive policing. Systems such as PredPol (later Geolitica) direct patrols toward areas with historically high recorded crime; because those records reflect where police already concentrated, the software can manufacture a feedback loop that sends officers back to the same neighborhoods and calls the result objective. The problem is not a single buggy model but a compounding one: biased inputs producing confident outputs that justify more of the same inputs.
Pushback: bans, fines and the EU AI Act
The counter-movement has three fronts. The first is data-protection enforcement, already visible in the table above: European regulators have treated indiscriminate face-scraping as unlawful processing and levied fines even where collection was cross-border. The second is local prohibition. In May 2019 San Francisco became the first major U.S. city to ban government use of facial recognition, and a cluster of cities — including Boston, Portland (Oregon) and others — followed with their own restrictions on public-agency use.
The third and most sweeping is the European Union’s AI Act, which entered into force in 2024 with obligations phasing in through 2025 to 2027. Among its prohibited practices are the untargeted scraping of facial images from the internet or CCTV to build recognition databases — effectively outlawing the Clearview model in the EU — and most real-time remote biometric identification in publicly accessible spaces by law enforcement, permitted only under narrow, judicially authorized exceptions. Whether these rules constrain the underlying market or simply relocate it is the open question of the next several years; enforcement capacity, not statutory text, will decide it. For now, the law has drawn a line that the technology’s first decade crossed without asking.
Frequently asked questions
How many faces has Clearview AI actually collected?
The company has never published an audited figure. Its stated database grew from around 3 billion images at the time of the January 2020 New York Times exposure to figures cited in the tens of billions, with a publicly referenced target of 100 billion and independent reporting placing the working set at 50 billion or more. The precise number is unverifiable; the scale is not in dispute.
Is facial recognition accurate enough to rely on?
It depends heavily on the subject. NIST’s 2019 demographic study found false-match rates often ten to one hundred times higher for Asian and Black faces than for white faces, with women and older people also more likely to be misidentified. Documented wrongful arrests — beginning with Robert Williams in Detroit in 2020 — show the consequences of treating a probabilistic match as proof.
Does any law actually stop this?
Increasingly, yes. The EU AI Act (in force 2024, phasing in through 2027) prohibits untargeted face-scraping and most real-time public biometric identification by police. Italy’s Garante fined Clearview €20M in 2022, and U.S. cities such as San Francisco have banned government use since 2019. Enforcement remains uneven, but the legal default is shifting from permissive to restrictive.
Related
The Dark Side of AI — the index · AI Misinformation · AI Surveillance: the Authoritarian Toolkit
Sources
European Data Protection Board / Garante per la protezione dei dati personali, Facial recognition: Italian SA fines Clearview AI EUR 20 million, March 2022 — edpb.europa.eu/news/national-news/2022
American Civil Liberties Union, ACLU v. Clearview AI settlement (Illinois BIPA), May 2022 — aclu.org
Information Commissioner’s Office (UK), Enforcement action against Clearview AI Inc, May 2022 — ico.org.uk
Commission Nationale de l’Informatique et des Libertés (France), Facial recognition: order to Clearview AI to stop reusing photographs, 2021–2022 — cnil.fr
National Institute of Standards and Technology (NIST), Face Recognition Vendor Test Part 3: Demographic Effects (NISTIR 8280), December 2019 — nist.gov
Freedom House, Freedom on the Net 2023 and 2024 — freedomhouse.org
The New York Times, The Secretive Company That Might End Privacy as We Know It, January 2020 — nytimes.com
European Union, Regulation (EU) 2024/1689 (AI Act) — prohibited practices, in force 2024 — eur-lex.europa.eu