
At the border, the people on the other side of our thermal cores have no claim on our restraint beyond the laws of armed conflict. That is the moral geometry of defense: the watcher and the watched belong to different sides.
That geometry is about to change for us. FX-Vision, the perception platform we built for the border, is beginning to read number plates on highways and watch intersections in cities. The technology is nearly identical. The ethics are not. On a highway, the person in the frame is not an adversary. She is a citizen — a taxpayer who funded the camera, a voter who authorized the government that deployed it, a commuter who never consented to being logged. When the camera turns inward, the watched and the watchers are the same society.
A surveillance company that does not stop at this threshold and think carefully has already failed, whatever its detection accuracy.
So before we ship the first kilometre of it, I want to write down what we believe — not as compliance language, but as the philosophical ground we intend to stand on and be held to.
The most instructive surveillance story of the past year is American. Flock Safety built the largest automatic number plate recognition network in the United States — over one hundred thousand cameras, sold city by city as a local crime-solving tool. Through 2025 and 2026, dozens of cities — by some counts approaching eighty — cancelled their contracts. Austin. San Diego. A wave of them.
Here is what interests me: the cameras worked. The cancellations were not about detection accuracy. Cities discovered that their local cameras had quietly become nodes in a national, centrally searchable database — and that federal agencies had queried their residents’ movements without the cities’ knowledge or consent. Communities that bought a local tool found they had joined a national surveillance network nobody had voted for.
The betrayal did not happen at the policy level. Flock had policies. It happened at the architecture level. A centralized database is a national tracking system, whatever the terms of service say. Once the architecture exists, every promise about its use is one administrative decision, one subpoena, one software update away from being revised. The citizens who protested understood this intuitively, and they were right.
In an earlier essay, we argued that responsibility in autonomous defense systems cannot be bolted on afterwards — it must be architecturally embedded, designed in from the first line of code. I want to extend that argument from the battlefield to the street, because it matters even more there.
Policies are revocable. Vendors get acquired. Governments change. Terms of service are rewritten in quiet quarters. The only commitments that survive all of this are the ones built into what the system cannot do. A camera that processes video at the edge and transmits only events cannot leak footage it never stored. A database that holds nothing older than its stated purpose requires cannot be mined for a citizen’s movement history. An access layer that logs every query cannot be searched in secret.
This is the deepest lesson defense engineering taught us, arriving in civilian clothes: do not trust intentions, including your own. Trust constraints.
In defense we call it rules of engagement, graded response, human command over machine execution. In civic space the same discipline has a different name — proportionality — and in India it happens to be constitutional law.
In Puttaswamy (2017), the Supreme Court held privacy to be a fundamental right, and gave the state a three-part test for intruding on it: legality, necessity, proportionality. The judgment is invoked often and operationalized rarely. India has no dedicated statute governing ANPR or public CCTV; the Digital Personal Data Protection Act largely exempts state surveillance; and meanwhile the smart-cities build-out proceeds at the speed of procurement. The regulation will come — it always does, usually after the first scandal. Until then, the proportionality test lives or dies in vendor design decisions. That is an uncomfortable amount of responsibility for private companies to hold. We hold it anyway, so we should say what we intend to do with it.
We should also be honest about what surveillance can and cannot deliver, because inflated efficacy claims are their own ethical failure. The best evidence — a forty-year meta-analysis of CCTV studies — finds cameras reduce crime modestly, on the order of thirteen per cent, concentrated in property crime and car parks, weakest against violence. Meanwhile the costs are better documented every year: empirical studies have shown that people measurably change what they read, search, and say when they believe they are watched — the chilling effect is not a metaphor, it is data. A society under comprehensive observation is not the same society, merely safer. It is a different society. Anyone selling cameras owes the public that sentence.
Now the part vendors prefer not to discuss: the business model. FieldX earns revenue from ANPR on a per-read basis. We are, in the plainest terms, paid to track vehicles. It would be dishonest to write an ethics essay and skip this.
But the structure of the incentive matters, and it is worth examining. Flock’s business model made the database the moat: a national lookup network whose commercial value grows with every camera added and every plate retained. The economic gravity of that model points toward centralization and hoarding — the architecture follows the revenue. Our model attaches revenue to the read event itself: a plate crosses a gantry, a match is made, a fee accrues. Nothing in our economics improves when data is retained longer, aggregated wider, or repurposed quietly. We are paid for perception, not possession.
I do not offer this as absolution — incentives can be redesigned, and a company’s character is tested precisely when someone offers to pay for the darker version. I offer it as something better than a promise: an incentive structure the public can inspect, aligned today with the constraints we are committing to below, and a standing invitation to call us out the day the two diverge.
These are design commitments for the FX-Vision platform in civic deployments. They are written to be checkable — by customers, by auditors, and by anyone this essay reaches.
Video is processed where it is captured. What leaves the camera is the event — a plate string, a timestamp, a classification — not the footage. Raw video is not the product and does not travel. A system that never centralizes imagery cannot silently become an archive of a city’s daily life.
Data exists as long as its stated purpose requires, and no longer. A toll-enforcement read has a lifespan measured against toll enforcement — not against some future, unnamed analytical use. When the purpose is served, the data does not linger as inventory. Movement history is not a by-product we quietly keep; it is a liability we deliberately do not create.
Every query against the system is logged: what was searched, by whom, under what authority. The watchers are watchable. If an agency’s use of the system cannot survive being written down, the system should not serve it.
This is the clause Flock’s cities learned to demand too late. An ANPR camera is a device the public can reason about. If a software update can turn it into a face recognizer or a behaviour classifier overnight, then the public consented to nothing. We commit to treating every new capability class as a new deployment — subject to the same scrutiny, contracting, and public visibility as the original installation. Capability expands in daylight or it does not expand.
There is a fifth commitment, and it may matter more than the other four: we do not intend to grade our own homework.
We are engineers. We know how to measure latency and detection accuracy. We are not the right people to be the only judges of proportionality, chilling effects, or the long-run civic consequences of infrastructure we profit from. So this is a standing, public invitation: if you are a policy analyst, a constitutional lawyer, a privacy researcher, a technologist — pose the hard questions. Tell us where these commitments are weaker than they sound. Remind us, specifically and on the record, of the dark side of centralized surveillance schemes, because every builder of such systems believes themselves the exception until the day they are not.
We will read what you send. Some of it will change what we build. The history of surveillance is a history of good intentions plus quiet drift — and drift is only corrected by outside voices with standing to be heard. Consider this essay the grant of that standing.
A closing thought on why a defense company believes it can write any of this credibly.
Defense taught us that perception systems fail most dangerously not when they miss, but when they overreach — when they escalate, when they act on low confidence, when they exceed their mandate. Everything we have learned about graded response, about systems that know their own limits, about machines that execute within humanly-set bounds, was learned where the cost of overreach is counted in lives. Civilian surveillance has, until now, mostly been built by companies that never had to internalize that discipline — and it shows, from threshold-tuned false alarms to national databases assembled by accident.
The camera is turning inward across the world, with us or without us. The question is not whether highways and cities will be instrumented — they will be. The question is whether the instrumentation is built by people who have thought hard about restraint, encoded it where it cannot be quietly removed, and invited society to check their work.