A white van parks on a busy high street. Before you reach the coffee shop, your face has already been checked against a database of 16.5 million records.
I think this is one of the most consequential technology deployments in modern British history, and most people walking past those vans have no idea how the system actually operates. The critics are loud but often vague. The defenders are smug but often dishonest about the mechanics. So let me walk you through what really happens, step by step, because the details matter enormously.
The machine that scans you before you know it is there
There are two distinct systems running in the UK right now, and conflating them is a mistake most commentary makes. Retrospective Facial Recognition (RFR) is used after a crime: police pull images from CCTV, dashcams, or social media and run them against the Police National Database, which holds over 16.5 million facial records. Live Facial Recognition (LFR) is the one that should make you stop and think.
LFR uses mounted cameras in public spaces to capture live images of every single person who walks past. Those images are instantly compared against a watchlist of suspects wanted by police or the courts. If the algorithm flags a possible match, an officer nearby is notified and decides whether to intervene. You are scanned, checked, and either cleared or flagged in seconds, without ever being told it is happening.
Here is the part that should alarm you: no specific law passed by Parliament has ever authorised this. As Statewatch noted in its February 2026 submission to the Home Office, "No laws in the UK mention facial recognition, and the use of this technology has never even been debated by MPs."
“The use of live facial recognition technology effectively inverts the long-held principle of innocent until proven guilty.”
— Statewatch, submission to Home Office consultation, February 2026
The watchlist nobody voted on and the database behind it
The watchlist is the engine of the whole operation. Before each deployment, officers compile a list of wanted individuals, suspects, missing persons, or people deemed a risk to themselves or others. That list is loaded into the system and the cameras do the rest. The College of Policing sets national guidance on who can be included, but the categories are broad enough to drive a van through.
The RFR database is even more troubling. The Police National Database holds over 16.5 million facial records, and a significant portion of those belong to people who were arrested but never charged with any crime. The National Physical Laboratory independently tested the algorithm and found it is more likely to incorrectly flag certain demographic groups in some circumstances.
I remember reading that statistic and doing a double take. The system finds a correct match in 99% of searches when the person is on the database. That sounds impressive until you realise the database itself is contaminated with innocent people's biometrics.
From 10 vans to 50: the expansion nobody stopped
In January 2026, Home Secretary Shabana Mahmood announced the Home Office would fund 40 new LFR vans, taking the national fleet from 10 to more than 50. The government also committed £115 million over three years to a new National Centre for AI in Policing, branded Police.AI.
The scale is staggering. As of March 2026, 13 of the 43 police forces in England and Wales were already using LFR, with a full national rollout planned. The Metropolitan Police is now installing permanent fixed cameras across London's West End, covering Soho and major retail zones. A High Court challenge by privacy campaigners was dismissed in April 2026.
And it is not just vans anymore. This is the part everyone skips.
Police forces including Merseyside are now deploying officer-initiated facial recognition (OIFR) on individual smartphones, allowing any officer to photograph a face and run it against national databases on the spot. West Midlands Police has started using body-worn video cameras for real-time facial recognition searches. At least one force has discussed using drone-mounted cameras to identify people at protests.
The strongest argument for it, and why I still reject the framing
The honest case for this technology is not nothing. A single LFR deployment in Watford in February 2026 resulted in four arrests. A London trial reported more than 170 arrests by May 2026. Policing minister Sarah Jones has compared its impact to the breakthrough of DNA matching in the 1980s, and that comparison is not entirely absurd.
But here is the counterpunch: those arrest numbers tell you nothing about false positives, wrongful stops, or the chilling effect on people who simply do not want to be scanned. The Information Commissioner's Office audited Essex Police and found accuracy and bias risks serious enough that the force paused its own deployments. That is not a ringing endorsement of a system being rolled out nationwide.
Would you trust a system that was paused for bias issues in one county to be fair when deployed in every town centre in England and Wales?
Regulation is coming, but the infrastructure is already built
The government's consultation on a new legal framework closed in February 2026. New laws are expected in approximately two years. By that point, facial recognition will be embedded in every regional force, every major train station, and dozens of supermarkets including Sainsbury's and Iceland, which have both deployed the technology in their stores.
This is the real story: the regulatory framework will not prevent a surveillance state from forming. It will manage one that already exists. The Ada Lovelace Institute has argued the framework must set meaningful limits on the most intrusive uses and be backed by an empowered regulator. That is the right call. The question is whether Parliament has the spine to actually do it.
The good news, and I do believe there is some: the government has at least committed to a public register of AI systems deployed by police forces, and the new algorithm procured by the Home Office has been independently tested for bias with no statistically significant disparity at the settings police use. That is genuinely smart policy, and I will say so plainly.
But a public register and a better algorithm do not resolve the foundational problem: a technology that scans millions of innocent people to find a handful of suspects is not a targeted tool. It is mass surveillance with a policing justification bolted on. The UK is building infrastructure that other democracies are actively restricting, and doing it before the legal framework exists to govern it. That is unserious governance of a serious technology.
Tell me that is a reasonable way to run a democracy.
