Skip to main content
How Iran's secret service built an AI video surveillance state
acquisitionSource type: independent reporting

How Iran's secret service built an AI video surveillance state

How Iran's secret service acquired and deployed AI video analysis technology to build a surveillance state, and the legal exposure this creates under sanctions, the EU AI Act, and international human rights law.

Companies mentioned: NtechLab

Updated

The most concrete account of Iran’s AI surveillance buildout does not begin with a camera on a Tehran street. It begins with a Russian facial-recognition company, an Iranian buyer, a later distributor tied to the security establishment, and licenses that reportedly reached the Ministry of Intelligence and Security and the Ministry of Defense and Armed Forces Logistics. That procurement trail is what turns a broad allegation about secret-service AI surveillance into a system with dates, intermediaries, software terms, and agencies attached.

In August 2019, according to a Le Monde investigation conducted with the Forbidden Stories consortium, Russia’s NtechLab sold its FindFace facial-recognition technology to the Iranian company Rasadco. Distribution was later taken over by Kama, described in the investigation as headed by a member of the Islamic Revolutionary Guard Corps. Licenses were then distributed to Iran’s Ministry of Intelligence and Security, known as MOIS, and MODAFL, the defense ministry responsible for Iran’s military-industrial apparatus. A November 2020 contract with BPO reportedly licensed FindFace for an “unlimited period” at about €80,000 and claimed the system could identify 100 million faces in under three seconds.[1]

Conceptual supply chain from Russian facial recognition software through intermediary companies to Iranian government ministries

The legal significance of that chronology is easy to overstate and just as easy to miss. The reported 2019 sale and 2020 contract came before NtechLab was sanctioned by the European Union in July 2023 and by the United States Treasury in December 2024. That does not make the transfer benign. It does mean the sharper sanctions question is not whether a later designation automatically makes an earlier sale unlawful. The more difficult questions concern continued support, software updates, maintenance, licensing, payment channels, facilitation, or any post-designation dealings after those sanctions attached.

The Procurement Trail Matters Because the Tool Is Not Passive

FindFace is not merely an archive search tool in the sources describing the Iranian contracts. Forbidden Stories reported that NtechLab’s technology could identify faces from a database of 500 million in under one second with “98% probability,” and that the system supported “interaction tracking” capable of mapping who meets whom, how often, and at which location.[2] Those are capability claims, not courtroom findings about every Iranian deployment. But they are materially different from a generic video-management system.

The distinction matters for lawyers and compliance teams because facial recognition changes what a camera network can do. A camera records that a person passed through an intersection. Face matching can attach that image to an identity. Interaction tracking can convert repeated co-presence into an inferred association. Once phone data or internet records are brought in, the state no longer needs a single perfect image or a single officer’s memory; it can assemble corroboration from multiple administrative systems.

That is the practical intimacy of the architecture. A protester appears near a gathering. A woman is flagged in a public place under hijab-enforcement rules. A dissident meets the same contact twice near a metro station. The software does not need to decide guilt. It only needs to route a person into a file, an interview, a summons, a phone search, or further monitoring.

Cameras, Drones, Phones, and ISPs Become One Enforcement Surface

The Russian software trail sits inside a wider domestic surveillance buildout. In April 2025, the National Council of Resistance of Iran reported that Tehran had announced 15,000 AI-powered surveillance cameras with a budget of about $30 million and a planned completion date by March 2026, citing Iranian government sources including ISNA and Tehran deputy mayor Hamid Baradaran.[3] The NCRI is an opposition organization, so its political framing should be separated from the underlying official statements it quotes. The useful point for this analysis is narrower: Iranian municipal and state actors publicly described a large AI-enabled camera deployment in the capital.

Tehran street scene with surveillance cameras and facial-recognition tracking overlays on pedestrians

At scale, cameras become more than street furniture. They create candidate sightings. Facial recognition supplies identity matches. Drone monitoring can extend observation into crowds or areas where fixed cameras are sparse. Phone-data extraction can supply contacts, messages, images, device identifiers, and location clues. ISP data-sharing rules can add subscriber and traffic-related information. Each layer reduces a different kind of uncertainty for the security services.

LayerWhat it can add to an investigationWhy it matters legally
AI-enabled camerasSightings, timestamps, locations, face imagesCreates the observable event that may trigger enforcement
Facial recognition softwareIdentity matching against existing databasesLinks a public image to a named person
Interaction trackingRepeated co-presence and inferred associationsTurns movement into a social graph
DronesAerial observation of gatherings or movement patternsExpands monitoring beyond fixed infrastructure
Phone and ISP dataContacts, accounts, device information, subscriber recordsCorroborates identity and association after a visual flag

Iran’s proposed Chastity and Hijab Bill gives this architecture a domestic legal channel. Article 28 explicitly authorizes “smart systems, fixed and mobile cameras, and artificial intelligence” to identify violations, while a separate parliamentary law requires internet service providers to share user data with security forces.[3] The result is not simply surveillance for intelligence collection. It is surveillance designed to feed administrative and criminal enforcement.

Diagram of drone monitoring, surveillance cameras, and smartphone data feeding a central monitoring hub

Chinese technology appears in the infrastructure picture as well, though the available record is less contract-specific than the FindFace trail. Forbidden Stories reported that Iran’s surveillance infrastructure has drawn on suppliers including Hikvision, Tiandy, Huawei, and ZTE, often through front companies, and described capabilities such as deep-packet inspection as part of a broader monitoring environment.[2] That evidence supports a supply-chain and infrastructure concern. It does not, on its own, prove that every named supplier knowingly supported a particular Iranian enforcement action.

Why Later Sanctions Do Not Answer the Whole Question

NtechLab’s sanctions timeline creates a familiar compliance problem: technology can be transferred before designation, embedded into a state system, and then continue to generate value after the supplier becomes restricted. The EU designation in July 2023 and the U.S. Treasury designation in December 2024 do not retroactively rewrite the reported 2019 sale.[1] They do, however, raise exposure for any covered person or entity that later provides prohibited services, updates, support, financing, brokering, or other dealings involving a sanctioned party.

That is where software frustrates older control assumptions. A shipment of restricted hardware has a border crossing, a bill of lading, and a physical point of seizure. A facial-recognition platform can involve license keys, remote access, software patches, reseller support, cloud or on-premise deployments, and documentation routed through intermediaries. If a system is licensed for an “unlimited period,” the next legal question is not only who sold it. It is who kept it usable, who had access to updates, who serviced the customer, and whether any post-sanctions act brought a regulated person back into the chain.

The front-company problem is similar. Rasadco, Kama, and BPO matter because intermediaries can separate the original developer from the end user on paper while leaving the functional destination unchanged. For sanctions counsel, that means end-use and end-user diligence cannot stop at the immediate buyer when the product is a state-security-grade biometric system. For enforcement authorities, it means documentary trails are likely to be incomplete unless contracts, support records, payment channels, and reseller communications are examined together.

The EU AI Act Frames the Gap More Than It Solves the Case

The EU AI Act is relevant here, but not because it supplies a simple answer against every actor in the record. Its value is diagnostic. It shows how European law now treats certain biometric identification and surveillance uses as prohibited or high-risk, while the Iran trail shows how capability can move through software licensing, distributors, and non-EU state-security agencies before the regulatory categories become operationally useful.

Export controls and sanctions have historically been more comfortable with items, lists, destinations, and named parties. AI video analysis stresses all four. The same class of technology may be marketed for airport access control, retail security, police watchlists, or intelligence work. Its most sensitive function may be enabled by software rather than a specialized physical device. Its deployment may be proven first through investigative reporting rather than customs records. Its most serious harm may occur after it has been integrated with domestic databases and enforcement laws.

That does not mean the law has no tools. Sanctions can reach designated parties and prohibited facilitation. Export-control regimes can be updated to address software, technical assistance, and end uses. AI regulation can clarify prohibited biometric practices and high-risk deployments. Human rights mechanisms can document state responsibility. The gap is that none of these tools alone maps neatly onto a system assembled across several years, several jurisdictions, and several layers of public and covert procurement.

Human Rights Accountability Starts With Use, Not Just Transfer

The UN Independent International Fact-Finding Mission on Iran documented AI surveillance as a tool of systematic repression in March 2025.[4] That finding shifts the analysis from supplier exposure to state conduct. The central question becomes how surveillance is used against protesters, women targeted under compulsory hijab enforcement, dissidents, journalists, and others whose everyday movement can be converted into evidence of nonconformity or association.

International human rights law is not interchangeable with sanctions law. Sanctions ask whether a person, entity, transaction, or service falls within a prohibited dealing. Human rights analysis asks whether the state’s collection, processing, identification, and enforcement practices violate rights such as privacy, freedom of expression, freedom of assembly, equality, and due process. Possible international accountability depends on proof of conduct, patterns, intent, and connection to broader repression. A procurement contract may help explain capability, but it is not the same thing as proof of a specific violation against a specific person.

Recorded Future’s 2026 analysis described AI as enhancing Iran’s asymmetric playbook while preserving caveats, including uncertainty around attribution of specific AI-generated propaganda content.[5] Check Point Research’s 2026 work on Iranian targeting of IP cameras and physical warfare adds operational context about the relationship between cameras, cyber activity, and conflict environments.[6] Those reports are useful because they prevent the domestic surveillance issue from being treated as isolated from Iran’s broader security behavior. They also require care: operational capability, targeting activity, and legally attributable abuse are related but distinct propositions.

A March 2024 Washington Institute analysis described Iran’s dual cybersecurity and surveillance strategy before the later camera-deployment claims and before the full 2026 conflict context.[7] Its timing matters. It is evidence of a preexisting domestic-security orientation, not a complete account of the more recent AI camera buildout. Iran Human Rights Monitor’s July 2026 reporting likewise places digital surveillance in the service of repression, but as human rights monitoring rather than a substitute for contract evidence.[8]

The strongest evidence now available supports a narrower and more serious conclusion than the usual “AI surveillance state” shorthand. Iran appears to have acquired advanced facial-recognition capability through a Russian supplier and Iranian intermediaries before major sanctions attached to that supplier. It then placed that kind of capability inside a broader enforcement architecture made of AI-enabled cameras, drone monitoring, phone searches, ISP data obligations, and legal provisions authorizing smart identification systems.

The hardest liability questions sit in the gaps between those facts. If support continued after July 2023 in the EU context or after December 2024 in the U.S. context, sanctions exposure may look very different from the original sale. If intermediaries concealed the end user, the issue becomes one of facilitation, knowledge, and due diligence. If the software was deployed to identify women, protesters, or dissidents for coercive enforcement, the state’s responsibility must be assessed through human rights law and, where the evidence supports it, possible international accountability mechanisms.

What remains is a surveillance apparatus that appears technologically integrated and legally fragmented. Cameras create sightings. Facial recognition supplies names. Interaction tracking produces associations. Phone and ISP data supply corroboration. Sanctions, export controls, AI regulation, and human rights law each see part of the machine. None yet offers a clean single frame for a system built across time, borders, intermediaries, and categories that were not designed for this kind of AI-enabled state security deployment.

References

  1. How Iran secretly acquired facial recognition technology through a Russian company, Le Monde, March 4, 2026.
  2. Eyes of Iran: How the regime secretly monitors its citizens, Forbidden Stories.
  3. Iran: Digital Surveillance in the Service of Repression, Iran HRM, July 2, 2026.
  4. Iran Fact-Finding Mission report, UN OHCHR, March 2025.
  5. AI Has Enhanced Iran's Asymmetric Playbook, Recorded Future, 2026.
  6. Interplay between Iranian Targeting of IP Cameras and Physical Warfare, Check Point Research, 2026.
  7. Navigating Cybersecurity and Surveillance: Iran's Dual Strategy, Washington Institute, March 2024.

Corrections & feedback

Submit corrections, flag outdated information, or provide additional market context. Comments are moderated.

Comments

Join the discussion with an anonymous comment.

Loading comments...
Blogarama - Blog Directory