Part 1: The Watchers: How Britain Built a Surveillance State...
and Hoped You Wouldn’t Notice
You left your house this morning. You got in your car. You drove to work, to the shops, or to drop the children off at school.
You did nothing wrong. You broke no law. You gave nobody any reason to suspect you.
Yet by the time you reached your destination, the British state had almost certainly recorded your journey.
Your number plate was scanned, perhaps dozens of times, by automatic number plate recognition cameras. Your face may have been captured by CCTV. If you paid by card, your transaction was logged. If you carried a smartphone, your location was tracked by default. If you sent a text message or made a phone call, the metadata — who you contacted, when, and for how long — was retained by your service provider under a legal obligation imposed by the British government.
You were watched and logged and filed.
Unless you’re one of the relatively few people who have thought seriously about any of this, you probably never noticed.
That’s the point.
That’s how it works.
And that’s what this investigative piece is about.
The Architecture of Surveillance
Let’s begin with what actually exists. Not speculation. Not fear. Documented, operational systems that are already in place and continuing to expand across the United Kingdom.
Britain has an estimated 5.2 to 7.5 million CCTV cameras. That’s roughly one camera for every eight to thirteen people, depending on which figures you use. London alone is estimated to have between 690,000 and 940,000 cameras. The average Londoner is captured on camera around seventy times a day. With approximately 399 cameras per square kilometre, the capital has one of the highest CCTV densities outside Asia, placing it alongside cities such as Beijing and Shanghai.
Think on that for a moment.
London — the capital of one of the world’s oldest parliamentary democracies — has a camera density comparable to cities in a one-party state.
Then there is ANPR. The UK’s network of more than 13,000 automatic number plate recognition cameras submits around 60 million read records to national police databases every single day. Not every week. Not every month. Every day.
That data is retained for twelve months and is available to every police force in real time through the National ANPR Data Centre. In 2018 alone, the system carried out 10.1 billion number plate scans. The volume has only increased since.
The practical consequence is simple. Drive anywhere in Britain — to work, a hospital appointment, or a friend’s house — and your journey is almost certainly recorded, time stamped, and stored in a police database for a year.
You don’t have to be suspected of a crime. You don’t have to be wanted by the police. Your movements are logged routinely by a system that was originally introduced as a counter-terrorism measure.
We’ll come back to that phrase — “originally introduced as” — because it appears again and again throughout this investigation.
And that’s before we even get to your phone.
The Snooper’s Charter
The Investigatory Powers Act 2016 — dubbed the “Snooper’s Charter” by its critics — is the most significant surveillance legislation passed in modern British history. Edward Snowden described it as “the most extreme surveillance in the history of western democracy.”
Most of the British public barely noticed it becoming law.
It’s worth asking why.
The Act didn’t simply consolidate existing surveillance powers. It expanded them, substantially. It did so using carefully chosen language — “modernisation”, “safeguards”, “keeping pace with technology” — that made the scale of those new powers easy to overlook unless you examined the legislation closely.
Under the Act, internet service providers are legally required to retain every customer’s internet connection records for twelve months. Not the content of what you read or typed, but a record of every website your device connected to. Those records are stored and can be accessed by dozens of public authorities.
Not just GCHQ and MI5.
The Food Standards Agency. The Gambling Commission. The Welsh Ambulance Service.
All were granted access under the same legislation.
The inclusion of organisations such as the Gambling Commission raises an obvious question. What operational need justifies giving a gambling regulator access to the browsing history of British citizens?
The Act doesn’t answer it. It simply grants the power and moves on.
It went further still.
The legislation authorised bulk interception — the large-scale collection of communications data from entire populations rather than specific individuals. It authorised bulk equipment interference, or government hacking in plain English, allowing intelligence agencies to compromise the devices and networks of large numbers of people simultaneously. It also authorised the collection and retention of bulk personal datasets containing information on millions of people, the overwhelming majority of whom are of no intelligence interest whatsoever.
All of this was presented as being subject to what the government called “world leading” oversight.
So what does that oversight actually involve?
The most intrusive surveillance powers are authorised by the Secretary of State — the same politician whose agencies will use them. Judicial oversight comes afterwards through the Investigatory Powers Commissioner.
The politician signs the warrant.
The judge reviews it afterwards.
Whether that amounts to a robust democratic safeguard is something readers can decide for themselves.
In April 2024, the Investigatory Powers (Amendment) Act expanded these powers even further.
The timing is significant.
The legislation was passed during the final months of the Conservative government, pushed through, as the Centre for Strategic and International Studies (CSIS) observed, “under the radar” of media coverage on both sides of the Atlantic.
It broadened the state’s ability to collect citizens’ data in bulk, introduced new notification requirements compelling technology companies to inform the government before making changes that could affect surveillance capabilities, and extended provisions covering bulk personal datasets. It also weakened elements of the oversight framework ministers had relied upon in 2016 to reassure Parliament and the public that these exceptional powers would be subject to strong independent safeguards, including the so called “double lock” system of ministerial and judicial authorisation for certain warrants.
The government described the changes as “urgent” and “targeted”.
CSIS — hardly a civil liberties campaign group — described them as “unapologetically” weakening safeguards that had been “widely touted” when the original Act passed.
The bargain Parliament was asked to accept in 2016 was straightforward: unprecedented surveillance powers in exchange for robust independent oversight.
Eight years later, some of those safeguards had quietly been diluted.
The surveillance powers hadn’t.
They had grown.
By now, a clear pattern is beginning to emerge.
The War on Encryption
If the Investigatory Powers Act provides the legal framework for mass surveillance, the government’s campaign against encryption reveals where that framework is heading.
In early 2025, the Home Office issued a secret order to Apple under the Act’s Technical Capability Notice provisions. The demand was extraordinary.
Apple was instructed to build a backdoor into iCloud encryption.
Not for named suspects under specific warrants.
For every user worldwide.
Apple refused.
Rather than weaken the security of every customer, it withdrew its Advanced Data Protection encryption feature from users in Britain altogether.
Be clear about what happened.
The British government did not make its citizens’ data more secure.
It made it less secure.
People in Britain now have weaker protection for their photographs, messages, notes, and device backups than users in almost every other developed country.
Not because of a cyberattack.
Not because of a technical failure.
Because the British government demanded access, and one of the world’s largest technology companies concluded that removing the feature entirely was the only safe response.
If the government’s stated objective is public safety, an obvious question follows.
How does making British citizens’ personal data less secure than that of citizens in almost every comparable country make anyone safer?
The government later narrowed its demand to British users alone. Apple filed a fresh legal challenge before the Investigatory Powers Tribunal in July 2026.
That case continues.
The damage — the removal of encryption protections for millions of British users — has already been done.
At the same time, the Online Safety Act granted Ofcom the power to require technology companies to scan encrypted messages using so called client side scanning.
In plain English, every private message sent through affected platforms could be examined on the user’s device before encryption was applied.
Not targeted surveillance of named suspects under judicial warrant.
Blanket monitoring of everyone.
Signal, the encrypted messaging service relied upon by journalists, lawyers, whistleblowers, and millions of ordinary people who simply value privacy, warned that it would leave the United Kingdom rather than compromise its encryption.
WhatsApp indicated a similar position.
The story then takes a remarkable turn.
The government openly acknowledged that the technology needed to scan encrypted messages without breaking encryption does not yet exist.
It nevertheless placed the power on the statute book.
Dormant.
Waiting.
Requiring no further primary legislation when, or if, the technology eventually catches up.
The government legislated for a surveillance capability it admits cannot currently be built, then left that power waiting for the day it becomes technically possible.
That raises a deeper question.
What kind of legislative process creates surveillance powers before the technology needed to exercise them even exists? And what does that say about the safeguards that were supposed to accompany those powers?
The Face Scanners
If the legal framework raises questions, the operational reality demands answers.
The Metropolitan Police deployed live facial recognition technology 117 times during the first eight months of 2024, more than three times the 32 deployments carried out during the same period the previous year.
In the first four months of 2026, the force scanned 1.7 million faces across London — an increase of 87 per cent compared with the same period in 2025.
This isn’t gradual expansion.
It’s exponential.
But the results deserve just as much attention.
Between September 2024 and September 2025, police facial recognition cameras in London scanned more than three million people.
Of those three million, 962 were arrested.
That’s a hit rate of 0.03 per cent.
The remaining 99.97 per cent — more than 2.99 million people — were innocent members of the public going about their daily lives.
Their biometric data was captured, processed, and compared against police databases without their knowledge or consent.
They weren’t suspects.
They weren’t persons of interest.
They were shoppers, commuters, tourists, and residents who happened to walk past a camera.
If a police officer physically stopped and searched 99.97 per cent of people without cause, it would provoke national outrage.
When a camera does it, it’s called progress.
The Metropolitan Police is now expanding permanent live facial recognition cameras across central London, with installations planned across the West End and Soho by the end of 2026, followed by a wider rollout across London in 2027.
Commissioner Sir Mark Rowley has described this as an expansion rather than a trial.
The disclosures that have emerged under public scrutiny are equally revealing.
In February 2026, the Mayor of London disclosed — but only after persistent questioning from Green Party Assembly Member Zoë Garbett — that the Metropolitan Police had been secretly trialling handheld facial recognition devices.
Officers were carrying mobile technology capable of scanning and identifying people on the spot.
The public had not previously been told.
One detail should concern every reader.
At the time this information emerged, the Metropolitan Police’s own website explicitly stated that it did not use the technology.
Yet it was already being trialled.
Both statements cannot be true.
Then, in May 2026, live facial recognition was deployed at a political protest for the first time during the Unite the Kingdom demonstration in London.
Whatever view you take of that protest is beside the point.
The principle is clear.
The British state used real time biometric surveillance to monitor a lawful political gathering.
Once that line has been crossed, it’s difficult to see how it is easily uncrossed.
Behind all of this lies substantial public investment.
The Home Office has committed £115 million to a new National Centre for AI in Policing, branded Police.AI, to standardise the rollout of facial recognition and artificial intelligence across all 43 police forces in England and Wales.
A further £26 million has been allocated for a national facial recognition system, alongside £11.6 million for additional live facial recognition capabilities.
Part two to follow.
If you thought it couldn’t get any worse, think again.
Independent political analysis takes time and resources. To keep these articles free and accessible to everyone rather than locked behind a paywall, I rely entirely on voluntary reader support. If you value this work, please consider dropping a quick one-off tip in the coffee jar.





Excellent Article. Thank you 🙏
It’s a pity they don’t watch all the early release criminals!