Surveillance Without Social Licence: Lessons From Three Cautionary Cases

Surveillance Without Social Licence: Lessons From Three Cautionary Cases

Jason Scarborough

There is a gap that doesn't appear in any legislation, any policy framework, or any departmental risk register.

It sits between what communities expect regulators to do, what the law formally authorises them to do, and what the technology they deploy is actually capable of. For most of the past decade, that gap has been manageable — uncomfortable, but manageable. I think we are approaching the point where it isn't.

I've spent 25 years working in and around regulatory compliance and surveillance operations. What I'm seeing unfold in the United States, and to a lesser degree in the United Kingdom, looks less like isolated controversy and more like a preview. Three cases, in particular, have stayed with me.


The authorising environment is not the same as the law

Before getting to the cases, it's worth being precise about what I mean by the authorising environment.

In public administration theory, the authorising environment is the constellation of forces that give a regulator the legitimate mandate to act — legislation, yes, but also ministerial direction, community expectation, organisational culture, and the implicit social contract between a regulatory body and the people it serves. The law sets the floor. The authorising environment determines how high above that floor a regulator can operate without losing legitimacy.

Social licence is the community dimension of that environment. It is not a legal concept. It cannot be granted by parliament. It is earned — through transparency, through proportionality, through demonstrated alignment between what a regulator says it is doing and what it is actually doing. And it can be revoked, quickly and without formal process, by a community that has decided it no longer trusts the institution or the tool.

Legislative lag is what happens when technology and community expectations both move faster than statute. The law that authorised a particular kind of surveillance was written for a particular moment. The technology has since become something the drafters could not have anticipated. The community's understanding of what that technology does — and what it could do in the wrong hands — has shifted. But the statute hasn't.

These three forces — the authorising environment, social licence, and legislative lag — are in tension everywhere right now. The cases below illustrate what happens when that tension is left unmanaged.


Clearview AI: when the law exists but can't keep up

Clearview AI did not operate in a legal vacuum. Australia's privacy regulator found, in 2021, that the company had collected facial images of Australians without consent, in breach of multiple Australian Privacy Principles. The determination was clear. The order was clear: stop collecting, delete what you have.

The company continued collecting. The regulator, three years later, chose not to pursue further action. As of mid-2025, there is no evidence the original order was ever complied with.

This is not primarily a story about a bad actor, though Clearview's conduct was plainly troubling. It is a story about what happens when the authorising environment produces a determination that the legislative framework cannot actually enforce. The law existed. The social expectation that something would be done about it existed. The mechanism to make it stick did not.

Australian police departments used the technology anyway — in some cases without departmental oversight. The gap between what the law said and what operational practice looked like was, in the end, the whole story.

Canada tells a different version of the same cautionary tale. A joint investigation by federal and provincial privacy regulators reached identical findings — Clearview had collected biometric data on Canadians without consent, in breach of privacy law. Where Australia ultimately stepped back from enforcement, Canada pursued it through the courts.

In December 2024, the Supreme Court of British Columbia upheld a binding order requiring Clearview to stop collecting images of individuals in BC without consent — one of the first times a court had formally imposed regulatory limits on an AI company's conduct. Clearview has nonetheless stated its intention to eventually re-enter the Canadian market. A court can win a battle without resolving the war.


Flock Safety: when the authorising environment expands beyond its mandate

Flock Safety is an American company providing automated licence plate reader networks to more than 5,000 law enforcement agencies across the United States. The technology was procured, in most cases, for a straightforward purpose: solving vehicle-related crimes faster.

What it became was something different. Investigations by the Electronic Frontier Foundation documented law enforcement using the Flock network to monitor political protesters, conduct immigration enforcement operations, and — in at least one documented case — track a woman who had sought reproductive healthcare. These were not edge cases. They represented millions of database searches conducted without warrants, across agency boundaries, for purposes that bore no relationship to the authorising rationale for the original procurement.

By early 2026, at least 30 American municipalities had cancelled or deactivated their Flock contracts. Not because the law changed. Because communities withdrew consent.

This is the social licence mechanism in its rawest form. The authorising environment — the local government procurement process, the police department's operational mandate — was never designed to encompass mass surveillance of protesters or immigration enforcement. When communities understood what the technology was actually being used for, the mandate collapsed. The cameras came down.

The lesson for regulators is not that the technology was wrong. It is that the authorising environment was never clearly defined, never transparently communicated, and never meaningfully constrained. The technology filled the vacuum.


ULEZ: when consultation failure becomes physical conflict

London's Ultra Low Emission Zone is a different kind of case. The cameras themselves — automatic number plate recognition units — are not sophisticated AI systems. The policy objective, reducing toxic air pollution linked to thousands of premature deaths annually, is not seriously disputed by most public health experts.

And yet, when the scheme expanded to outer London in August 2023, more than 4,500 cameras were vandalised within the first year. Vigilantes calling themselves Blade Runners systematically cut wires and destroyed infrastructure worth tens of millions of pounds. In some outer boroughs, more than half of all cameras were rendered non-functional. Polling showed that among those who opposed the expansion, a majority actively supported the sabotage.

The legal authority was unambiguous. The policy rationale was defensible. Social licence had still completely broken down.

What failed in London was not the technology and not the law. What failed was the process by which communities were brought into the decision. The expansion moved faster than trust could be built. Outer London residents, many of whom depend on their cars for work and essential travel, experienced the scheme as something done to them, not with them. The cameras became the physical expression of that grievance.

When communities feel that a regulatory tool has been imposed without their meaningful participation, they find ways to remove it. Sometimes through formal channels. Sometimes not.


The pattern

Three cases, three different failure modes, one underlying dynamic.

In each case, technology was deployed into a gap between what communities expected, what the law authorised, and what the authorising environment could sustain. In Clearview's case, the technology moved faster than enforcement capacity. In Flock's case, the technology expanded beyond the mandate that justified its procurement. In London's case, the policy moved faster than community trust could be built.

The result in each case was the same: the technology lost its social licence. And once social licence is gone, it is extraordinarily difficult to recover — regardless of whether the legal authority remains intact.


A final thought

I work closely with people who enforce environmental law, manage public land, and respond to illegal activity in communities that expect results. They are, almost universally, under-resourced relative to the scale of the problem they are being asked to solve. The pressure to deploy technology quickly — because the community is demanding action — is real and constant.

What the cases above suggest is that speed of deployment is not the primary variable. Legitimacy of deployment is.

The questions worth asking before any surveillance technology goes into the field are not primarily technical. They are:

Does the community whose land or environment this is understand what we are deploying and why? Does the authorising environment — our legislative mandate, our ministerial direction, our operational policy — actually encompass this use case? And if the law hasn't yet caught up to what the community is asking us to do, how do we operate in that gap without burning the trust we'll need when the law does catch up?

These are not comfortable questions. They slow things down. But the alternative — deploying first and managing the fallout later — is exactly the trajectory that produced Clearview, Flock, and the Blade Runners.

Australia has not yet had its version of these cases at scale. That is an opportunity, not a guarantee.

Back to blog