Question From A Law Student: When Does AI Surveillance Become A Threat To Privacy?

What Constitutional Limits Should Apply To AI Surveillance?
Many of us have a tiny secret confession always on hand - our smartphones. While we are asleep, we give detailed instructions to our search engines, maps, and apps about where we plan to go, whom we plan to meet, and the things we wish to investigate. The state runs its own type of surveillance by using CCTV cameras with facial recognition that are set up in airports, shopping malls, and other parts of the urban landscape to identify us and track our movements in the physical world.
As law students, we learn that the state is permitted to enter that private space only with a valid justification. However, as artificial intelligence slowly but surely takes over that role of observing us, it becomes increasingly hard to evaluate the legitimacy of that reason, and the state has a ready-made justification – “national security”.
Knowing the history behind this dilemma provides background and perspective. The decision of Justice K.S. Puttaswamy vs. Union of India was handed down in 2017, where a bench of nine judges in the Supreme Court made a unanimous decision that right to privacy is a fundamental right and not a privilege granted by the state and is encompassed within the Articles 14, 19, and 21 of the Constitution. Additionally, if the Supreme Court is to be believed, then if there is an infringement on the right to privacy, the concept of proportionality would have to be applied. This would also mean that intrusions would be considered justified if they were limited and would not be considered excessive.
It is quite shocking to see how much this surveillance technology has been utilized until now. For example, the government's Safe City Project involves linking cities up with CCTV cameras, facial recognition systems, and behavioral analytics in the name of the security of women and children. Similarly, NATGRID, which is a database meant for allowing security agencies to access data stored in the databases of banks, telecommunication companies, and immigration systems together, got an additional layer of artificial intelligence and facial recognition analytics in December 2025. Nothing about these developments is necessarily evil; after all, if the camera helps in tracking down a missing child or the perpetrator of a hit and run, then it is precisely what it is supposed to do. But it may be pointed out that the very same surveillance infrastructure can equally well be deployed against protesters, strikes by workers, or journalists' activities.
This is evident from the ongoing case concerning Pegasus spyware. Many years after allegations had been made by the media as well as activists regarding targeting military spyware, it is still not clear what the results of a technical committee set up by the government are, because it has been classified as sensitive information for reasons of national security. In an earlier hearing, it was said that the Bench had commented that there was nothing wrong in the use of spyware by the country in question.
At the most recent student protests over examination leaks, there were reports of the use of facial recognition vans by the police to take photographs and identify the protesters. This is just one example among many of a serious legal lacuna – India has no law regulating the use of facial recognition technology by the police force.
Parliament tried to address the problem by introducing the Digital Personal Data Protection Act, but the notification for the Act was done much later in November 2025. Instead of plugging the hole, the law allows sweeping exceptions when the state processes personal data in the name of national security, public order, and foreign policy. In theory, this will allow the state to compile an entire profile of the person using AI-driven analysis techniques without getting consent or taking the necessary precautions a company would be obliged to take in dealing with this sort of information. The very law meant to make Puttaswamy’s dream come true becomes the means to sidestep this dream if the tagline “national security” is present in the dossier.
It seems clear that the state has the right to use these AI technologies. Like other state-based innovations in AI, assisted policing has proven to be useful in finding missing children and in controlling disorderly crowds during religious meetings and in the execution of emergency services. No privacy rights advocate of any substance will suggest that the state should cease to use these tools. However, the question is a bit narrower, and the current problem is faced by the courts of many countries, trying to find a balance between state security and personal freedom.
Is it necessary for the courts to review the government claims concerning necessity, and if yes, when? Do surveillance technologies need an ex-ante authorization by the judge like the wiretap or search warrant, or should the courts narrow down the interpretation of “national security” exceptions and require from the government the proportionality of the measure each time? Is it necessary for the courts to interpret the absence of facial recognition laws as the legislative intention to act carefully?
As a law student, I present this question to those who will answer it, the academics, the lawyers, and the judges, as we study proportionality. We are not asking the state to disarm, but we are asking that with each innovation, there still be those who are independent and courageous enough to ask why it is needed. When new additions to surveillance technology become available, we must ask what specific problem we are trying to solve.
'Question From A Law Student' Vertical, steered by Himanshi Hans
