Verdict: AI-powered facial recognition is now being deployed to monitor protesters in real time, with faces matched against government databases, identities displayed on screens inside surveillance vans, and biometric data retained for up to 75 years — yet most countries have no dedicated law governing when, how, or whether the technology may be used against citizens exercising their right to assemble. In the UK, a High Court ruling in April 2026 upheld the practice. In India, it runs on executive discretion alone. Only the EU has drawn a hard line, banning real-time biometric identification in public spaces starting August 2026. The pattern everywhere is the same: deploy first, legislate second, and let the courts sort out the fallout.
Last verified: 2026-07-31
- India's Criminal Procedure (Identification) Act 2022 allows biometric data retention for 75 years by the NCRB.
- The UK High Court upheld Met Police live facial recognition in Thompson v Commissioner of Police (April 21, 2026) — 3.1M faces scanned, 0.48% false positive rate, 80% of false positives on Black people.
- The EU AI Act bans real-time remote biometric identification in public spaces from August 2026, with narrow exceptions for victim searches and terrorism prevention.
- India has no dedicated facial recognition law; a private member's bill introduced in 2023 remains stalled.
- The DPDP Act (2023), India's data protection law, exempts law enforcement agencies from its privacy obligations.
What happened at the Delhi protest in July 2026?
In July 2026, Delhi Police deployed four AI-powered facial recognition vans at Jantar Mantar, a designated protest site in central New Delhi, during student demonstrations over an alleged exam-paper leak. Each van carried at least 13 CCTV cameras — 8 on the roof with 360-degree rotation — an LCD screen for real-time monitoring, and facial recognition software that displayed green boxes around faces as they were matched against police databases (The Telegraph).
The Delhi Police stated the system was deployed to identify wanted criminals, absconders, and habitual offenders — not ordinary protesters (India Today). But a heightened version of this technology — originally used at Republic Day parades and festivals — applied to a protest raised a different question: when surveillance built for crowds is pointed at dissent, does the purpose change?
The Cockroach Janta Party (CJP), a youth-led protest movement occupying the site for over a month, called the deployment "biometric harvesting" of citizens exercising a constitutional right (The Federal). Both descriptions may be technically accurate; the dispute is about scale, scope, and whose rights are implicated.
How does India's facial recognition system actually work?
India's Automated Facial Recognition System (AFRS) was approved by the National Crime Records Bureau (NCRB) under the Ministry of Home Affairs. The original RFP, issued in 2019 with an estimated budget of ₹308 crore, described a system designed to "capture face images from CCTV feed and generate alerts if a blacklist match is found" (PIB, Government of India).
The system was designed to integrate multiple databases, including:
| Database | Source | Stated purpose |
|---|---|---|
| CCTNS (Crime & Criminal Tracking Network Systems) | Police records (accused, prisoners, missing persons, unidentified dead) | Core criminal identification |
| Khoya Paya portal | Missing children database | Locating missing/found children |
| IVFRT (Immigration, Visa, Foreigners Registration & Tracking) | Passport and immigration records | Border security |
| State-specific police databases | Individual state police forces | Regional law enforcement |
What makes this problematic: a face can enter the system without that person ever being accused of a crime. The broad scope of "dynamic police databases" in the revised RFP means the data-sharing boundaries are deliberately open-ended — a design choice that civil liberties organizations like the Internet Freedom Foundation (IFF) have flagged as enabling "function creep" (Panoptic/IFF).
An 80% similarity index is reportedly sufficient for a facial match to be registered. Experts have noted that these systems can misidentify gender, and global research consistently shows higher error rates for certain skin tones and age groups — a bias problem baked into the training data itself.
How long does India keep your biometric data?
75 years. Under Section 4 of the Criminal Procedure (Identification) Act, 2022, the NCRB can retain biometric measurements — fingerprints, iris and retina scans, handwriting samples, photographs, and "any other measurements" — in digital form for 75 years from the date of collection (PRS Legislative Research).
This is effectively a lifetime: 75 years approximates the average Indian lifespan. The data is destroyed only if a person is acquitted after all appeals or released without trial — but a court or magistrate can override that destruction by recording reasons in writing.
The law replaced the colonial-era Identification of Prisoners Act, 1920, and expanded the scope dramatically: data can now be collected not just from convicted persons but from anyone arrested for any offence, including minor infractions like rash driving (maximum penalty: 6 months imprisonment and a ₹1,000 fine). The official authorized to collect this data can be as junior as a head warden.
Does India have a law specifically for facial recognition?
No. India does not have a dedicated law governing the use of facial recognition technology by police or any other authority. A private member's bill introduced in 2023 to regulate FRT deployment with judicial oversight has stalled in Parliament and has not moved forward (IFF/Panoptic).
The government has argued that the Digital Personal Data Protection Act (DPDP Act), passed in August 2023, covers the privacy angle. But the DPDP Act includes broad exemptions for law enforcement agencies, national security, and sovereign functions. In practice, this means the very bodies deploying facial recognition are exempt from the data protection law's consent, notice, and accountability requirements (Future of Privacy Forum, DLA Piper).
The result: every FRT deployment — whether at a protest, a festival, or a metro station — runs on executive discretion and procurement decisions, not on a statutory framework passed by Parliament. There is no legal requirement to publish what data was collected, who has access, or how long it will be retained beyond the blanket 75-year window.
How many people did the Delhi facial recognition system identify?
Delhi Police reported that facial recognition technology identified 2,873 people with prior criminal records present at the Jantar Mantar protest site between July 20 and 25, 2026. Among them, 101 were booked for murder, with others linked to sexual assault, robbery, kidnapping, and violations of the Narcotic Drugs and Psychotropic Substances (NDPS) Act (The Hindu, Livemint).
Two things are worth noting about this number:
The watch list is broad. If 2,873 people with prior records were identified among roughly 100,000 protesters, that means the underlying criminal database is large enough to return matches for nearly 3% of a crowd at a student protest. The Delhi Police themselves acknowledged that being identified with a criminal record does not establish involvement in any violence during the protest.
The tool reaches beyond criminals. Reports emerged that after the facial recognition deployment, police sent notices to colleges and universities after identifying students who attended the protest — students not involved in any unlawful activity. These individuals became, in the words of journalists who investigated the story, "collateral damage."
This is the core tension: a system marketed as hunting criminals is functionally a panopticon that records everyone, and the data can be used for purposes far beyond the stated justification.
What did the UK High Court decide about facial recognition?
On April 21, 2026, the UK High Court dismissed a legal challenge to the Metropolitan Police's use of live facial recognition (LFR), ruling the technology does not violate the European Convention on Human Rights. The case — Thompson & Anor v Commissioner of Police of the Metropolis — was brought by Shaun Thompson, an anti-knife-crime campaigner who was wrongly flagged by a facial recognition camera near Croydon. Thompson presented his passport and bank cards to prove his identity, but officers told him the system's match was sufficient grounds for detention (BBC).
The Court found that the Met's policy included "clear, precise and effective safeguards" — crime hotspot restrictions, senior officer oversight, and immediate deletion of non-matching faces — making deployment lawful (CMS Law).
The numbers behind the ruling, drawn from the Met's own review data, tell a complicated story:
| Metric | Figure | Source |
|---|---|---|
| Faces scanned (latest review period) | 3,147,436 | Met Police data |
| Arrests attributed to LFR since 2024 | 2,100+ | Met Police / BBC |
| False alerts (total scans) | 2,077 | Met Police data |
| False positive rate | 0.48% | National Physical Laboratory testing |
| False positives involving Black people | 80% | NPL independent testing; The Register |
| Planned expansion | 10 → 50 vans across England & Wales | Home Office, January 2026 |
The Court acknowledged the bias data but ruled that "concerns about discrimination" did not "infect the legality of the policy" — a formulation that critics say treats a low aggregate error rate as proof of fairness while errors concentrate heavily on specific demographic groups. Thompson announced he would appeal.
The judgment matters beyond the UK because it establishes a judicial precedent that a sub-1% false positive rate constitutes an adequate safeguard, even when those false positives fall disproportionately on one community.
How does the EU approach facial recognition differently?
The EU has taken the most restrictive stance of any major jurisdiction. Under Article 5(1)(h) of the EU AI Act, real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is prohibited, with only three narrow exceptions:
- Targeted search for victims of abduction, trafficking, sexual exploitation, or missing persons
- Prevention of a specific, substantial, imminent threat to life or physical safety, including terrorism
- Identification of a suspect of certain serious offences (punishable by at least four years' custody)
Each exception requires prior judicial authorization and a fundamental rights impact assessment. The prohibition entered into force in February 2025, with full enforcement beginning August 2, 2026. Violations carry fines of up to €35 million or 7% of global annual turnover (European Commission AI Act Service Desk, Future of Privacy Forum).
The contrast is stark:
| Jurisdiction | Approach | Key law | Status |
|---|---|---|---|
| EU | Banned (with narrow exceptions) | EU AI Act Art. 5(1)(h) | Enforced from August 2026 |
| UK | Permitted with safeguards | Common law + Met Police policy | Upheld by High Court, April 2026 |
| India | No dedicated law | Executive discretion + Procurement contracts | No statute; DPDP Act exempts law enforcement |
Why does the bias problem matter for AI in law enforcement?
The error-rate story that courts and police chiefs cite — "only 0.48% false positives" — obscures the distribution story. Here is the problem in one sentence: a low aggregate error rate is not evidence of fairness if errors concentrate on one group.
The UK's National Physical Laboratory found that the Met's system was "more likely to incorrectly include some demographic groups" in its matches. The data: 80% of false positives involved Black people, despite Black residents making up roughly 13% of London's population (The Record).
The root cause is training data. Facial recognition systems learn from the data they are fed. If decades of crime records, arrest data, and enforcement actions — digitalized and uploaded as training sets — already encode historical bias, the AI will reproduce and amplify it. One expert quoted in the investigation put it plainly: "Your facial recognition is as good as the data you upload."
This is not unique to India or the UK. In the US, cities like San Francisco and Portland have banned government use of facial recognition entirely, while others have embraced it. The patchwork mirrors the broader AI-governance pattern: the protections you get depend on where you stand, literally.
This connects to a broader principle relevant to anyone building or deploying AI: knowing when not to use AI is as important as knowing how to use it. The question is never just "can this technology do X?" but "should it, and under what guardrails?"
What can you do if you are at a protest being surveilled?
The practical guidance that emerged from this investigation, from digital rights advocates and journalists who covered the Delhi deployment, falls into short-term and long-term actions:
Short-term (protecting yourself today):
- Record everything. Keep your phone camera running. If you are later accused of misconduct at a protest, your own footage is your evidence. The surveillance state's cameras point at you — yours should point back.
- Cover up. Masks, scarves, and sunglasses reduce facial recognition match probability. In India, this intersects with air-quality concerns that already normalize face coverings.
- Do not post others' faces on social media. Others' identities can be traced and they may face consequences they did not consent to.
- Be aware of metadata. Photos and videos carry location and time stamps. Police have reportedly traced people through social media posts from protest sites and served notices at their colleges and homes.
Long-term (pushing for accountability):
- Demand transparency on three things: what data was collected, who has access, and what the retention rules are. Publishing retention rules and access logs costs a police force very little operationally — the refusal to publish is itself informative.
- Push for a dedicated FRT law. Every country needs statutes that specify: who may deploy facial recognition, against which databases, for what purposes, with what judicial oversight, and with what data-destruction timelines. Executive discretion is not a substitute for law.
- Support legal challenges. An appeal was filed in the Delhi High Court challenging the Jantar Mantar deployment. The UK's Thompson case is headed to the Court of Appeal. Courts are currently the only check on executive deployment in jurisdictions without dedicated FRT statutes.
What this means for you
If you build, deploy, or rely on AI in any capacity — whether you're an engineer shipping models, a business owner deploying surveillance tech, or a citizen whose data is being processed — the Delhi-UK-EU triangle tells you three things:
Technology outpaces law by design. Every country is running an "act first, legislate second" model. If you wait for regulation to tell you what is responsible, you will already have overstepped. The same principle that guides building verifiable AI for high-stakes domains applies to surveillance: accountability must be engineered in, not retrofitted.
Aggregate metrics hide distributional harm. A 0.48% error rate sounds great until you learn that 80% of those errors fall on one community. Any AI system you deploy — hiring, lending, content moderation, security — should be audited for disparate impact, not just aggregate accuracy. If you aren't measuring who bears the cost of your errors, you aren't measuring fairness.
Transparency is the cheapest safeguard you can build. The argument for publishing what data is collected, who accesses it, and how long it is retained is not ideological — it is operational. Systems that publish retention rules and access logs are more trusted, more accountable, and less likely to generate the kind of backlash that forces a rollback. The refusal to be transparent is itself a signal.
For more on the framework of when AI should and should not be deployed — and how to build deterministic guardrails around probabilistic systems — see our guide on the deterministic-first rule for AI deployment.
FAQ
Q: Is facial recognition at protests legal in India?
A: India has no dedicated law governing facial recognition technology. The Criminal Procedure (Identification) Act 2022 governs biometric data collection and retention (75 years), but does not regulate FRT deployment itself. The DPDP Act exempts law enforcement. Deployments run on executive discretion.
Q: How accurate is police facial recognition?
A: The UK Met Police reported a 0.48% false positive rate across 3.1 million face scans. However, 80% of those false positives involved Black people, showing that aggregate accuracy can mask severe demographic bias. India's system reportedly uses an 80% similarity threshold for a match.
Q: How long can police keep your facial data in India?
A: Under Section 4 of the Criminal Procedure (Identification) Act 2022, the NCRB can retain biometric data — including facial images — for 75 years. Data is destroyed only on acquittal or discharge, unless a magistrate orders retention.
Q: What did the UK High Court rule about facial recognition in 2026?
A: In Thompson v Commissioner of Police of the Metropolis (April 21, 2026), the High Court upheld the Met Police's live facial recognition policy, finding its safeguards adequate. The claimant, Shaun Thompson, was wrongly flagged by the system and has appealed.
Q: Does the EU ban facial recognition?
A: The EU AI Act (Article 5(1)(h)) prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, enforced from August 2026. Three narrow exceptions exist: searching for victims, preventing imminent threats to life, and identifying suspects of serious crimes (4+ years' custody). Each requires judicial authorization.
Q: What databases does India's AFRS use?
A: The NCRB's Automated Facial Recognition System was designed to integrate with CCTNS (criminal records), Khoya Paya (missing children), IVFRT (passport/immigration), and state police databases. The revised RFP uses the open-ended term "dynamic police databases," which civil liberties organizations say enables function creep.

Discussion
0 comments