Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

The Red Line That Wasn't

For a decade Europe told the world it would be the place that refused to scan every face. Article 5 of the AI Act named real-time face recognition in public a prohibited practice — the trophy clause, the line that was supposed to separate a free continent from the surveillance states. On Friday, July 10, 2026, Germany became the first major European country to switch it on. The Bundestag rewrote its Federal Police Act to let cameras at every train station, airport, and border scan the face of everyone who passes and match it, live, against a police list — and it did so not by breaking the AI Act but by using the trapdoors the AI Act built into its own ban. The biometric powers were added three days before the vote, after the only expert hearing, in World Cup quarterfinal week. And Germany was not alone that week: the day before, the European Parliament let mandatory message-scanning survive on a technicality, and the same Friday, Britain's regulator put Wikipedia on a watch list for identity checks. Three weeks before the AI Act becomes fully binding on August 2, the continent that wrote the red lines spent a week proving they don't hold.

Twenty million faces

Twenty million people move through Germany's roughly 5,700 railway stations every day. As of Friday, July 10, 2026, German law says a machine may look at all of them.

That morning — the last sitting day before the Bundestag's summer recess, in the middle of World Cup quarterfinal week, the country still arguing about the firing of national coach Julian Nagelsmann — parliament passed the rewritten Bundespolizeigesetz, the Federal Police Act. CDU/CSU and SPD voted for it; Greens and Left against; the AfD abstained. The trade press did not hedge. The digital-rights outlet netzpolitik.org ran its verdict as a headline within hours: the Bundestag "just rang in the age of automated surveillance."

The law's new Section 31b, "biometric real-time detection," authorizes federal police cameras at train stations, airports, and border areas to scan every passing face and compare it, in the live feed, against a police reference file. The same statute hands the Bundespolizei its first state trojan — source-telecommunications surveillance, malware slipped through security vulnerabilities to read messages before they are encrypted — for preventive use, with no regime governing the vulnerabilities it rides in on. And around those two headline powers it bolts a full estate: AI behavior analysis of station video, silent SMS, IMSI-catchers and Wi-Fi-catchers, licence-plate scanners, drones, airline passenger data, access to the EU's common identity database. The cost runs about €185 million a year, plus €18 million to build — layered onto 11,000 cameras at 750 stations that until Friday could record you but could not recognize you.

The most invasive of those powers did not exist in the bill the experts reviewed. The Interior Committee's public hearing took place on January 26, on a government draft that contained no real-time biometrics at all. The face-scanning clause and the behavior-analysis clause were inserted by coalition amendment on July 7, cleared committee on July 8, and were law by July 10 — "only three days before the vote," as netzpolitik counted. The deepest cut into fundamental rights in the entire package never faced a single expert witness, and it landed on the one week the country was watching football.

The ban that shipped with a switch

Here is the part that should unsettle even people who like the policy. Germany did not defy the European Union's flagship AI law to do this. It used it.

The AI Act's Article 5 makes real-time remote biometric identification in public spaces, for law enforcement, a prohibited practice — banned by default since February 2, 2025. That was the provision privacy advocates called a genuine red line, the first hard prohibition on live public face recognition anywhere in the democratic world. But the prohibition ships with three dormant exceptions built into its own text: targeted searches for trafficking victims and missing persons; a specific, imminent threat to life or a terrorist attack; and the hunt for suspects in serious crimes carrying at least four years. And Article 5 lets any member state wake those exceptions through national law, subject to procedural gates — prior authorization by a judge or independent authority, a fundamental-rights impact assessment, registration of the system in an EU database.

Section 31b is Germany's hand on that switch. It transposes the exceptions almost verbatim: a court order required except in exigent circumstances, two trained officers obliged to confirm every machine match before anyone acts, matching in real time only, no linking to other databases during a run. The government calls that narrow, and on paper it is narrower than what some feared.

But read where the safeguards sit. Every one of them governs what happens after a match. Before the match, to find the face on the list, the system must template the face of everyone in the station — the commuter, the tourist, the schoolchild on a class trip, the woman leaving a shelter, the man going to a clinic. Suspicionless processing of the crowd is not a side effect of remote biometric identification. It is the mechanism. There is no version of "scan the station for one wanted face" that does not first scan the station.

And that is exactly the practice the AI Act named as prohibited — now switched on, lawfully, by the writing of a national statute, three weeks before the Act becomes fully applicable on August 2. When Hungary did a cruder version in March 2025, enabling face recognition for offences as trivial as attending a banned Pride march or jaywalking, European institutions treated it as a rogue stress-test of the red line. Germany's version arrives dressed in judges and impact assessments — which is what makes it more corrosive, not less. Hungary broke the line. Germany dissolved it into a compliance checklist that any interior ministry can complete. The CDU's interior spokesman, Alexander Throm, said the quiet part proudly from the floor: this law, he predicted, would become maßstabsbildend — "standard-setting" — "for the states of the Federal Republic." Sixteen German Länder run their own police forces. Twenty-six other member states run their own interior ministries. Templates travel; that is what a template is for.

The same week, across the continent

Germany's Friday was not an isolated national choice. It was the loudest note in a chord.

The day before, on July 9, the European Parliament held its second-reading vote on the revived "Chat Control" regulation — the rule that lets providers scan private messages for illegal imagery. A plurality of members present voted to reject it, 314 to 276. They lost anyway. Rejecting a Council position at second reading requires an absolute majority of all members — 360 by Parliament's own count — and roughly 112 legislators, two days before recess, simply were not in the room. The scanning regime the Parliament had killed in March came back to life until April 2028, resurrected on the arithmetic of absence. Parliament did win one thing: the first explicit carve-out for end-to-end-encrypted messages ever written into an EU scanning law. But it passed only because it drained the opposition — after the encryption exception carried, the coalition to reject the whole text collapsed from 314 votes to 276. The consolation prize bought the defeat.

And on the same Friday as the German vote, Britain's Ofcom published the first register under the Online Safety Act and, alongside it, a statutory "watch list" of services it may yet designate for the strictest duties — including the power to demand users verify their identity. Wikipedia, spared the top tier for now, was placed on that watch list, docketed beside iMessage and Messenger, with no published exit criteria and reassessment possible at any time. The Wikimedia Foundation, which had already lost a judicial review over exactly this, called continued designation "an existential threat" to the roughly 260,000 volunteers who could be pushed toward handing over legal identity to edit an encyclopedia — some of them in countries where being known as a Wikipedia editor is dangerous.

Three countries, one week: a face scanner switched on in Germany, message-scanning revived in Strasbourg, an identity-verification threat hung over the world's encyclopedia in London. Add the detail that surfaced days earlier — that a member of the European Parliament's own spyware inquiry had himself been hacked with Pegasus, according to Citizen Lab — and the theme is hard to miss. In the weeks before its landmark AI Act took full force, Europe was not tightening its red lines. It was walking across them.

The numbers the machine can't outrun

Germany has run this experiment before, and kept the receipts.

The 2017–18 pilot at Berlin's Südkreuz station produced the interior ministry's triumphant figure: better than 80 percent detection, a false-positive rate under 0.1 percent, success declared. The Chaos Computer Club called the report embellished and unscientific. But you do not even need to dispute the number to see the problem; you need only multiply it. At roughly 100,000 passengers a day through Südkreuz, a 0.1 percent false-alarm rate is about 100 innocent people flagged per day — at a single station. Berlin's then data-protection commissioner, Maja Smoltczyk, put the pilot's total at 80,000 to 100,000 people wrongly captured. The Max Planck Institute's statisticians filed the same point under their "Unstatistic of the Month": against Germany's 11.9 million daily rail travellers, a 0.1 percent rate is roughly 11,900 false alarms a day — more than 350,000 a month. A system can be called "successful" and still accuse the innocent at that rate, because the innocent are almost everyone.

The companion technology has a worse record. The behavior-analysis software the same law federalizes has been watched over squares in Mannheim since 2018 and still cannot reliably tell a punch from a hug. One of its flagged categories is "apparent helplessness," which in practice means the system reports people who are homeless. This is the class of machine that Section 31b promotes from municipal pilot to federal infrastructure.

The honest case for yes

The case for the switch is real, and it deserves its strongest numbers rather than its weakest.

From October 2025 to March 2026, London's Metropolitan Police ran fixed live-facial-recognition cameras on Croydon's high street: 173 arrests across 24 deployments — one every 35 minutes of operation — including people wanted for kidnap, rape, and serious sexual assault. In the pilot area, recorded crime fell 10.5 percent against the year before, and offences of violence against women and girls fell 21 percent. More than 470,000 people walked past the cameras; the Met records a single false alert in that whole run, and no arrest ever made on a false match. Throm's line — that train stations "must not be spaces of fear" — lands precisely because it is half true. For a woman who was going to be attacked and now will not be, the machine is not an abstraction about liberty. It is the thing that caught the man.

So the rebuttal cannot be that the machine never works. It is threefold, and it survives the Croydon numbers intact. First: station safety can also be bought with lighting, staff, and faster courts — measures that reduce fear without building a general-purpose identification machine that a future, worse government inherits fully assembled. Second: the objection to live biometric identification was never only about accuracy. A system that is 99.9 percent accurate still had to template the other 99.9 percent of the crowd to get there; the harm is the templating, not merely the error, because a country that can automatically recognize everyone at the station can recognize the striker, the protester, the reporter's source, and the woman leaving the shelter with equal ease and the same equipment. Third, and most Germanly: these powers only ever ratchet. They are introduced narrow, justified by the hardest cases, and widened later — which is the trajectory the digital-rights lawyer Michael Kolain named this week when he called Section 31b "the beginning of the end of anonymity in public space." Irene Mihalic of the Greens, a police officer before she was a member of parliament, put the institutional version plainly: with biometric real-time surveillance, "the coalition reaches deep into fundamental rights." Clara Bünger of the Left named the endpoint: blanket surveillance "becomes the normal state."

Track two, and who gets paid

The July 10 law is only half the German plan. On Wednesday, July 8, the Bundestag gave a first reading to a separate three-bill "surveillance package" from Interior Minister Alexander Dobrindt. Its centerpiece is retrospective biometric photo search of the open internet: a wanted person's image compared against "publicly accessible" pictures scraped from social media, team photos, stock footage — with suspects, witnesses, and mere contacts all in scope. Around it sit cross-database AI analysis of location data, DNA, call records, and police files, and permission to train AI on citizens' non-anonymized data where anonymizing would take "disproportionate effort."

The AI Act's Article 5 also bans building facial-recognition databases through untargeted scraping of the internet — the clause written with Clearview AI in mind. The German justice ministry's answer is a marvel of literalism: the ban, it argues, applies only if an AI system does the scraping. AlgorithmWatch's expert, the information scientist Dirk Lewandowski, calls the prohibition ausnahmslos — without exception — and notes that without a reference database the whole approach collapses both legally and practically. AlgorithmWatch delivered more than 167,000 petition signatures against the package that same Wednesday. The Green MP Konstantin von Notz told the coalition what waits for it: "If you pass this, you'll face the Constitutional Court again." He has the precedent on his side. In February 2023, the Federal Constitutional Court struck down Hesse's and Hamburg's Palantir-driven police data analysis for exactly this kind of boundless correlation.

Someone is paid at every step of this. Cognitec, of Dresden, has run the Federal Criminal Police Office's face search against a database of some four million images since 2007, and a €185-million-a-year mandate with a real-time requirement attached is a procurement windfall. Fraunhofer's institutes sell the behavior scanners. Dobrindt is reviewing the nationwide Palantir rollout his predecessor refused. And the internet photo search would let the federal police commission private providers to do the matching — the Clearview and PimEyes model, nationalized, two years after journalists with nothing more than a PimEyes subscription used exactly that kind of tool to help locate the long-hidden former militant Daniela Klette. The capability does not care who holds it. That is the point of building it.

What you can actually do

Be honest about the tools, because the honesty is the argument. No VPN hides your face from a camera in a public station. Against Section 31b, the only defenses are political — and two of them are live right now. One is the petition against the companion surveillance package, which still has to pass. The other is the Bundesrat, the chamber of the states: this law requires the state governments' consent this autumn, abstention counts as a no, and Green-co-governed Länder killed a nearly identical federal-police reform in June 2021 by doing exactly that. The place this gets decided is a letter to your state interior ministry, not a setting on your phone.

The state trojan is where the technical fight is real, and it points the opposite way from despair. Source surveillance exists because encryption works: the state has to compromise the device precisely because the wire has gone dark. So keep the wire dark and make the endpoint expensive — updated hardware, end-to-end-encrypted messengers, and open, auditable, minimal-power transport like Tor, WireGuard, and decentralized networks such as URnetwork. None of that is a rhetorical flourish; it is the difference between surveillance that has to be aimed, at a named person, with a warrant, and surveillance that comes free with the infrastructure and points at everyone by default. That is the entire stake of the week. Keep identification expensive, individual, and answerable to a judge — because July 10 was a demonstration of how quickly it becomes ambient, automatic, and free.

The AI Act becomes fully applicable on August 2. Its biometric red line either holds when the Bundesrat votes this autumn, in sixteen state capitals, or it stops being a line anywhere on the continent that drew it. Europe spent a decade telling the world it would be the one place that refused to scan every face. It has three weeks to mean it.


References (2 sources)

References

  • Deutscher Bundestag, plenary record and Drucksachen for the Federal Police Act (Bundespolizeigesetz) modernization, vote of July 10, 2026; Interior Committee report of July 8, 2026; Interior Committee expert hearing of January 26, 2026 — bundestag.de.
  • netzpolitik.org, "Der Bundestag hat gerade das Zeitalter der automatisierten Überwachung eingeläutet" and related coverage of §31b, the behavior-analysis powers, the state trojan, and the July 8 first reading of the surveillance package (2026).
  • heise online, "Federal Police: Coalition OKs AI real-time tracking, state trojans" (2026); taz, "Modernisierung des Bundespolizeigesetzes" (2026); digitalrechte.de, Michael Kolain (July 8, 2026).
  • EU AI Act, Article 5 (prohibited practices; real-time remote biometric identification, exceptions and Article 5 procedural conditions); full applicability August 2, 2026 — AI Act Service Desk (European Commission); artificialintelligenceact.eu.
  • Federal Ministry of the Interior, Südkreuz facial-recognition pilot results (2018); Chaos Computer Club and Max Planck Institute "Unstatistik" critiques; Berlin DPA (Maja Smoltczyk) false-alarm arithmetic.
  • Metropolitan Police, "Met makes one arrest every 35 minutes during live facial recognition pilot" (Croydon, May 13, 2026); ITV News London; The Register.
  • AlgorithmWatch/Campact, "Stoppt Dobrindts Überwachungspläne" petition (167,000+ signatures, delivered July 8, 2026); Bundesverfassungsgericht, 1 BvR 1547/19 & 2634/20 (Feb 16, 2023, Palantir/Hessendata).
  • European Parliament second-reading votes on the CSA/"Chat Control" derogation, July 9, 2026 (rejection 314–276; E2EE exclusion adopted 369/362); EP press office; netzpolitik; heise.
  • Wikimedia Foundation, "Wikimedia Foundation challenges UK Online Safety Act regulations" (July 10, 2026); Ofcom Register of Categorised Services and emerging Category 1 list (July 10, 2026); Online Safety Act 2023, ss. 64, 97.
  • Hungary biometric-surveillance amendments (March 2025) and AI Act challenge — ECNL/EDRi/Liberties. Citizen Lab, Pegasus infection of a PEGA committee member (Report 194, July 2026).

Further Discussion

The Machine Catches Rapists

**Position.** Take the strongest version of the case for the switch, because it is real and the numbers are not on the privacy movement's side. From October 2025 to March 2026 the Metropolitan Police ran fixed live-facial-recognition cameras on one Croydon street and made 173 arrests in 24 deployments — one every 35 minutes of operation — including people wanted for kidnap, rape, and serious sexual assault. In the pilot area, recorded crime fell 10.5 percent and violence against women and girls fell 21 percent. More than 470,000 people walked past those cameras and the force logged exactly one false alert, and never once arrested anyone on a false match. Germany's new Section 31b brings that capability to stations where 20 million people move each day and where, until Friday, a woman being followed had only the hope that a human happened to be watching the right monitor. "Train stations must not be spaces of fear," the CDU's Alexander Throm said, and for the specific woman who was going to be attacked and now will not be, that is not a slogan about liberty — it is the man in handcuffs. The uncomfortable truth for this publication is that the abstraction we defend, the right to move through a public station unrecognized, is a right whose costs are paid disproportionately by people who will never be victims and whose benefits, when we win, are collected disproportionately by the man the camera would have caught. A privacy politics that cannot say plainly what its position costs at the platform edge is not serious — it is comfortable. **Headline candidates.** - The Machine Catches Rapists · The Uncomfortable Numbers Behind the Face-Scanning Fight - One Arrest Every 35 Minutes · What the Croydon Cameras Actually Did - 470,000 Faces, One False Alarm · The Steelman Privacy Advocates Keep Dodging - Anonymity Has a Body Count Too **Kicker.** Croydon: 173 arrests, one every 35 minutes, violence against women and girls down 21 percent, one false alert in 470,000 faces. Germany just brought that to stations carrying 20 million people a day. Say plainly what opposing it costs — at the platform edge, in the specific case — or concede the other side is arguing about real people and you are arguing about a principle.

A Ban With a Switch Built In

**Position.** Now read the same week as what it actually was: the collapse of the most celebrated privacy law of the decade, on schedule, by design. The EU AI Act's Article 5 was supposed to be the red line — real-time face recognition in public, *prohibited*. But the prohibition shipped with three exceptions folded into its own text and a clause letting any member state switch them on by national law, and on July 10 Germany became the first big country to do it — with judges and impact assessments attached, which is precisely what makes it worse than Hungary's cruder version, because it converts a red line into a checklist every interior ministry can complete. The CDU's floor manager didn't hide it: this law will be *maßstabsbildend*, "standard-setting," for the sixteen German states — and twenty-six other member states run their own police. Watch the mechanism, not the marketing: every safeguard governs what happens *after* a match, while getting to the match requires templating the face of everyone in the station — the commuter, the child, the woman leaving a shelter. A system that is 99.9 percent accurate still had to scan the other 99.9 percent to get there, which is why Berlin's own pilot math means about 100 innocent people flagged per day at a single station. And it never came before an expert witness: the biometric clause was slipped in three days before the vote, in World Cup week, after the hearing was over. German surveillance powers only ever ratchet — introduced narrow, widened later — and this one arrived pre-widened. The same seven days revived EU message-scanning on an absent-legislator technicality and hung identity checks over Wikipedia. Three weeks before the AI Act takes full force, the continent that wrote the red lines walked across them, and there is no VPN for your face — only the Bundesrat this autumn, the courts, and whether a "prohibition" that can be switched on by statute was ever a prohibition at all. **Headline candidates.** - A Ban With a Switch Built In · How Europe's Red Line Became a Checklist - The Prohibition You Can Turn On · Article 5, and the Trapdoors in Its Own Text - Standard-Setting · The Government's Own Word for What Comes Next - There Is No VPN for Your Face **Kicker.** The AI Act "banned" live face recognition — then let any member state switch it on by national law, which Germany just did, three days after inserting the clause, in World Cup week. Every safeguard governs the match; getting there scans everyone, ~100 innocents flagged a day at one station. A red line you can enable by statute was never a line. The counter isn't a tool — it's the Bundesrat this autumn, and refusing to let "prohibited" mean "available on request."

Comics

#1The Machine Catches Rapists
#2A Ban With a Switch Built In