I remember the first time someone told me that my walk was readable. It was 2019, at a privacy workshop in Berlin โ a former police intelligence officer casually mentioned that gait recognition had become "good enough to identify you from 50 meters in any direction." I laughed. It sounded like science fiction. Six years later, I'm not laughing.
A new investigation by civil liberties researchers has uncovered something that should disturb anyone still clinging to the idea of public anonymity: the underlying code for "OS Investigate" contains 69 preloaded AI prompts that transform standard Flock safety cameras into a precision surveillance network capable of identifying individuals by the unique biomechanical signature of how they walk. This isn't facial recognition with extra steps. This is something far more insidious โ and far harder to opt out of.
The Infrastructure Already Exists
Let me break down what's actually happening here, because the technical details matter more than the headlines.
Flock Safety, the Atlanta-based company behind these cameras, has positioned itself as a community safety solution. Their cameras are deployed across neighborhoods, homeowner associations, and increasingly, commercial districts. The pitch is clean: help solve property crimes, catch car thieves, make streets safer. Reasonable people can disagree about whether neighborhood watch apps are good for community trust โ I've written about that tension before โ but OS Investigate represents a qualitative leap beyond what most buyers likely imagined they were purchasing.

The 69 AI prompts embedded in the system aren't just basic license plate readers. These are sophisticated behavioral analysis modules that extract gait vectors, posture profiles, and movement kinematics from video footage. Your height, your stride length, the angle of your shoulders, how your arms swing when you walk โ these aren't just data points. They're a biometric signature as unique as your fingerprint, and unlike a fingerprint, you can't wear gloves to hide it.

Here's what makes this technically remarkable and morally concerning simultaneously: gait recognition works even when a person's face is obscured, when they're wearing different clothes, or when they've changed their hairstyle. The system doesn't need to see your identity document. It doesn't need a clear shot of your face. It just needs to see you move for a few seconds.
I spent three years auditing smart contract vulnerabilities in DeFi protocols, and one thing I've learned is that security failures compound in ways their designers never anticipated. The same principle applies here. A surveillance system designed to catch car thieves gets repurposed โ whether through police requests, data sharing agreements, or future product iterations โ to track individuals across entire metropolitan areas. The infrastructure doesn't have to be rebuilt. It just has to be queried differently.

The Privacy Architecture Nobody Voted For
Let's talk about consent, because this is where the institutional trust architecture completely breaks down.
When a homeowner association signs a contract with Flock Safety, their residents don't get a say. When a business district installs these cameras, the pedestrians walking through don't sign anything. The movement signature of every person passing through these camera fields is being digitized, processed, and stored โ often without meaningful disclosure, let alone consent. This is the surveillance infrastructure problem in microcosm: decisions made by a small number of gatekeepers reshape the privacy expectations of entire populations.
The blockchain space taught me one thing above all else: code is law, but community is conscience. We spent years arguing about whether DeFi protocols were truly decentralized, whether the code was immutable enough, whether the governance structures held up. We were asking the right questions about institutional design, just applied to the wrong domain. The same scrutiny should apply to surveillance infrastructure. Who controls the data? Who can query it? Under what circumstances? Can individuals access, correct, or delete their biometric signatures?
Gait data raises stakes that traditional surveillance debates haven't adequately addressed. Facial recognition, for all its problems, at least operates on a visible feature. You know, at some level, when a camera might capture your face. But gait recognition captures something you can't see, can't easily perceive, and until very recently, couldn't be extracted at scale. The technical capability arrived before the ethical framework โ a pattern we've seen play out repeatedly in AI development.
The 69 prompts in OS Investigate reportedly include modules for activity classification, direction detection, and what researchers describe as "unique identifier extraction" โ industry language for biometric profiling. This isn't paranoia about what might be possible. This is documented functionality in a commercially deployed system.
The Contrarian Case (Because Nuance Matters)
I want to be precise about something, because hyperbolic framing undermines credible analysis.
Gait recognition technology isn't inherently evil. There are legitimate law enforcement applications โ identifying missing persons with cognitive impairments who can't self-identify, reuniting lost children, solving violent crimes where traditional evidence is lacking. The technology itself is neutral; the question is always governance. And this is where my skepticism toward both Big Tech and Big Brother becomes hard to disentangle.
The problem isn't that the capability exists. The problem is the deployment model: centralized infrastructure, opaque data practices, limited accountability mechanisms, and zero recourse for the surveilled. If this same technology operated on a decentralized protocol with strong privacy guarantees, individual data sovereignty, and transparent governance, my concerns would be substantially different.
We're not building that future. We're building the surveillance architecture of the present and calling it community safety.
The uncomfortable truth is that many communities want this. Property crime is real. Car theft is frustrating. Parents worry about their neighborhoods. The demand for security solutions isn't manufactured โ it reflects genuine anxieties that decent people experience. But we've been here before. The post-9/11 security apparatus was also built in response to legitimate fears. The question isn't whether the problem is real; it's whether the solution we're accepting is proportionate, accountable, and reversible.
I don't see those properties in OS Investigate.
What Comes Next
The regulatory conversation around AI surveillance is lagging years behind the deployed technology. Europe has made more progress than the United States โ GDPR creates some friction, though its application to behavioral biometrics remains legally murky. But legislation moves slowly, and the cameras are already installed. The gait signatures are already being extracted.
What I'm watching for is whether civil society organizations can force meaningful transparency requirements before this infrastructure becomes too embedded to reform. The American Civil Liberties Union has flagged Flock Safety's data retention practices before. Congressional hearings on AI surveillance have been largely performative. The window for meaningful intervention is closing.
My prescription: we need technical standards for surveillance infrastructure that mirror what we've been trying to build in blockchain โ verifiability, auditability, user consent controls, and ideally, decentralized alternatives that don't concentrate this power in private companies with minimal oversight.
The walk we take in public spaces shouldn't be anyone's intellectual property to harvest, analyze, and store. That feels like a reasonable line. The question is whether we'll draw it before the infrastructure makes it permanent.