A camera that recognizes a face is unsettling. A camera that recognizes a person without needing the face may be more consequential.
The underlying code associated with OS Investigate reportedly contains 69 preloaded artificial intelligence prompts designed to extend Flock cameras beyond ordinary license plate detection. The prompts turn a distributed network of roadside cameras into a behavioral surveillance system, including tools that identify people by how they move.
That distinction matters. Faces can be obscured. License plates can be changed. Clothing can be replaced. Movement, however, follows a person through space as a persistent physical signature. It can reveal identity without relying on a name, a photograph, or a traditional biometric database. A gait model does not need to know who someone is before it begins linking where that person goes.
The discovery places a familiar question about blockchain and digital identity in a harsher setting: who controls the data that makes a human being recognizable?
The Code Beneath the Camera
Flock Safety has built a large network of automated license plate recognition cameras used by law enforcement, neighborhoods, businesses, and public agencies. These systems generally capture vehicle images, read plates, record time and location, and allow authorized users to search historical movements. Their defenders describe the cameras as tools for solving theft, locating missing people, and investigating violent crime.
The reported OS Investigate code suggests a broader ambition. Rather than treating the camera as a narrow sensor, the system appears to use AI prompts as an interface for querying and interpreting visual data. The 69 preloaded prompts reportedly guide the model toward investigations involving people, vehicles, behavior, movement patterns, and relationships between events.
A prompt is not merely a sentence typed into a chatbot. In an operational surveillance system, a preloaded prompt can become a policy encoded in software. It can define which attributes are considered relevant, which images are compared, how a search is framed, and what kind of suspicion receives computational assistance. The prompt layer therefore sits between raw observation and institutional action.
This is where the phrase artificial intelligence can conceal more than it explains. The camera does not independently discover truth. It receives an image, extracts features, compares them against prior observations or learned patterns, and produces a probability. Human operators then decide whether that probability becomes a lead, a report, a stop, or an investigation.
The risk is not only that the model may be inaccurate. The deeper risk is that its uncertain output can acquire the appearance of objective evidence.
Gait As a Portable Identifier
Movement recognition is especially sensitive because it can operate when other identity signals are absent. A system may examine stride length, cadence, posture, body proportions, arm movement, direction changes, or the sequence in which a person approaches and leaves a vehicle. None of those features is a name. Together, they may create a stable representation that can be used to connect separate observations.
This is not the same as proving identity. A similar gait may belong to many people. Camera angles, distance, lighting, injury, age, clothing, and carrying objects can all change a person’s movement. Yet surveillance systems do not need certainty to be influential. A ranked list of possible matches may be enough to direct an investigator toward a particular person.
That is the crucial technical asymmetry. A false positive can generate consequences even when the underlying classifier is wrong, while the person affected may never know that a model made the connection. There may be no visible denial, no formal accusation, and no practical way to inspect the data that produced the suspicion.
Based on my audit experience, the most dangerous failures in security systems are often not dramatic exploits. They are ambiguous mechanisms that work well enough to be trusted and poorly enough to escape accountability. When I reviewed vulnerable multisignature logic during the early Ethereum era, the technical flaw mattered. The governance process surrounding disclosure mattered more. A system can be mathematically impressive and still place ordinary people in an ethically indefensible position.
The same principle applies here. A gait classifier may be technically novel, but the decisive question is who is permitted to search it, for what purpose, under what standard, and with what obligation to correct mistakes.
From Search Tool to Memory System
A single camera creates a moment. A network creates a memory.
When cameras share compatible data structures, a vehicle or person can become traceable across jurisdictions and time. The system does not need to store a complete biography. It only needs to preserve enough observations to infer routines: a repeated commute, a visit to a clinic, a meeting with a journalist, attendance at a protest, or movement between a home and a place of worship.
The 69 prompts are significant because they may provide reusable investigative pathways for this memory system. One prompt could ask an operator to identify vehicles associated with a location. Another could search for a person wearing particular clothing. A further prompt might correlate movement across several cameras. Individually, these requests may appear ordinary. In combination, they can transform scattered images into a map of social life.
This is how surveillance expands without a single dramatic decision. The camera network grows. The retention period becomes normal. Access is granted to another department. A new prompt is added because investigators want a faster answer. The exceptional becomes routine through small administrative steps.
The blockchain industry should recognize the pattern. We spent years arguing that data becomes more valuable when it is composable. We praised open interfaces because they allow systems to work together. But composability also increases the power of systems that should remain separated. A location record, a vehicle record, and a behavioral profile can form a far more intimate picture than any one database reveals.
The protocol must serve the human spirit. That requires treating data combination as a security boundary, not merely an engineering convenience.
Where Decentralization Enters the Debate
At first glance, Flock cameras have little to do with decentralized finance, rollups, or public blockchains. Yet the same architecture question appears beneath all of them: where does authority reside, and can affected people contest its decisions?
A centralized surveillance provider can control the collection layer, the model, the access rules, and the audit logs. Public agencies may use the system, but the people being observed rarely receive comparable visibility. They cannot easily determine which camera recorded them, which prompt was used, which model generated a match, or how long the resulting data will remain available.
A blockchain cannot solve that problem by placing surveillance images on a public ledger. That would create an irreversible privacy disaster. Nor can a token make an abusive policy legitimate. Decentralization is not the multiplication of databases.
Its useful contribution is narrower and more practical: verifiable accountability. A system could record tamper-evident evidence of who accessed a search function, which authorization was presented, what policy version applied, and whether the query exceeded its permitted scope. Sensitive images would remain off-chain, encrypted, and subject to strict deletion controls. The ledger would prove institutional behavior without publishing the underlying identity data.
That design still requires law, governance, and independent oversight. Cryptography can show that an event occurred. It cannot decide whether the event should have occurred. Governance is not a vote; it is a vigil. It must include the people who are most exposed to the system, not only the agencies and vendors who operate it.
A privacy-preserving identity system should also separate recognition from disclosure. A person might prove that they possess a valid warrant, belong to an authorized investigative unit, or are searching within a defined time window without exposing unrelated personal information. Zero-knowledge methods can reduce unnecessary disclosure, but only if institutions accept limits on what they are allowed to ask.
The technical capacity to ask fewer questions is not the same as the political willingness to do so.
The Contrarian Problem: Better Controls May Increase Adoption
There is an uncomfortable possibility. Stronger accountability mechanisms could make surveillance systems easier to defend and therefore easier to deploy.
An agency may point to encrypted storage, access logs, independent audits, and privacy-preserving credentials as evidence that the system is responsible. Those safeguards are valuable. They can reduce abuse, identify unauthorized access, and provide meaningful remedies. But they can also create a compliance narrative around an architecture whose basic purpose remains persistent observation.
The question is not whether controls are useful. They are. The question is whether controls become a substitute for necessity. A system that is well logged can still be used too broadly. A model with a low error rate can still be inappropriate for tracking peaceful citizens. A cryptographically verifiable search can still violate dignity if the search itself lacks a legitimate basis.
We build bridges from the ashes of belief, but a bridge must lead somewhere worthy. The surveillance industry often asks whether a tool can be made safer. Communities must also ask whether the tool should exist in its current form, whether its benefits can be achieved through less invasive methods, and whether people have a real path to challenge its conclusions.
This is where technical journalism has a duty beyond repeating product claims. The existence of 69 prompts is not, by itself, proof of unlawful conduct. It is evidence of capability and intent that deserves independent examination. Reporters, researchers, civil liberties groups, and affected communities should inspect the code, document model behavior, test false matches, map retention policies, and identify every institution with access.
Listening to the silence between the blocks means investigating what the system does when no public incident appears. The absence of a scandal is not evidence of the absence of surveillance.
What Comes Next
The debate over OS Investigate should not be reduced to whether AI can recognize a person by movement. It already can, at least imperfectly. The more urgent issue is whether society will allow probabilistic identity to become a background layer of public life.
A face, a plate, and a gait are different signals, but a connected system can turn them into one persistent profile. Once that profile becomes part of an institutional memory, anonymity is no longer lost in a single moment. It is gradually worn away.
Truth is the only immutable asset, and truth requires more than a confident model output. It requires provenance, contestability, restraint, and a visible obligation to repair harm. The next generation of identity infrastructure should give people control over when they are recognized, why they are recognized, and how that recognition can be challenged.
The choice before us is not between technology and safety. It is between systems that make human beings permanently legible to power and systems that preserve room for dignity, privacy, and change. The future of decentralized identity will be judged by that boundary.