How legal safeguards against AI authoritarianism fall short
- Authority
- European Union, European Court of Human Rights
- Rule type
- regulation, court opinion
- Jurisdiction scope
- US federal, European Union, Council of Europe, International
- Source text
- Read primary rule text ↗
When a government uses AI for biometric identification, predictive policing, or discriminatory targeting, the first legal question is not whether “AI authoritarianism” sounds unlawful. It is which safeguard can be cited against which actor, in which forum, and with what remedy. This article is editorial analysis, not legal advice; in a live matter, the answer turns on the governing instrument, the date of the conduct, the public authority involved, and the available procedural route.
The four frameworks most often invoked against AI-enabled repression each do some real work. None supplies a uniform shield.

| Framework | What it appears to offer | Where reliance breaks |
|---|---|---|
| US Fourth Amendment anti-authoritarian theory | A way to frame surveillance and police robotics as a constitutional power-design problem, not only an individual privacy intrusion. | The theory remains doctrinally untested; no federal court has adopted it as a holding on AI policing. |
| EU AI Act | Prohibitions on specified AI practices, including certain biometric and manipulative uses. | National-security activity is carved out, and the Act does not impose a general export ban on systems prohibited inside the EU. |
| ECtHR Article 8 and 10 jurisprudence in Glukhin | A strong ruling that facial recognition is highly intrusive and requires legality, safeguards, and pressing justification. | It binds within the Council of Europe system and is temporally tied to pre-September 16, 2022 conduct in the Russia context. |
| International human rights instruments and emerging AI principles | Normative language for dignity, privacy, expression, association, and accountability. | They do not yet create a binding, comprehensive control on surveillance exports or preventive repression. |
The Fourth Amendment Theory Is Useful, But Not Yet a Holding
Matthew Tokson’s anti-authoritarian reading of the Fourth Amendment is valuable because it does not wait for AI policing to become routine before asking how constitutional doctrine should respond. The point is not merely that a drone, robot, database, or biometric system may invade privacy. The point is that certain police technologies can alter the relationship between citizen and state before conventional Fourth Amendment categories catch up.
Tokson’s Lawfare account treats police robots, deadly-force authority, pervasive surveillance, and oversight structures as part of a broader anti-authoritarian design problem. It argues for proactive limits before dangerous capacities are entrenched, including constraints on police robots’ use of deadly force and civilian oversight mechanisms for high-risk deployments.[1]
That framing may matter in briefs, procurement objections, legislative testimony, and agency comments. It gives counsel a vocabulary for explaining why the injury is not exhausted by one improper search. A system that identifies political dissidents, maps associations, or enables robotic force can chill behavior before a plaintiff has a clean record of arrest, search, prosecution, or physical harm.
But the operational limit is decisive: this is not settled Fourth Amendment doctrine. The research basis here supports a narrower proposition than “the Fourth Amendment prohibits authoritarian AI policing.” It supports the proposition that an anti-authoritarian theory can be argued, and may illuminate why existing doctrine is under strain. A lawyer who needs a binding rule still has to identify the search or seizure, the reasonable-expectation or property theory, the state actor, the remedy, and the relevant circuit law.
The EU AI Act Prohibits More Than Most Regimes, Then Leaves Two Large Doors Open
The EU AI Act is closer to an enforceable contemporary safeguard than a constitutional theory or a nonbinding principle. It classifies and restricts AI systems through a risk-based structure and prohibits a set of specified practices, including certain uses of real-time remote biometric identification in publicly accessible spaces. For counsel reviewing a deployment in the EU market, that matters.
The difficulty is that the Act’s strongest language does not travel everywhere the risk travels. EDRi’s critique focuses on the national-security exemption in Article 2(3), describing it as a “digital rights-free zone” because AI systems developed or used exclusively for national-security purposes fall outside the Act’s protections.[2]
For risk analysis, that is not a footnote. National security is one of the areas in which biometric surveillance, movement tracking, social sorting, and predictive targeting are most likely to be defended as necessary. If the relevant authority can characterize the deployment as national-security activity, the practitioner cannot simply point to the AI Act’s prohibited-practices chapter and assume the same safeguards apply.
EDRi also identifies a second gap: the Act does not restrict the export of AI systems that would be prohibited inside the EU to governments outside the EU. That distinction is easy to miss in “gold standard” descriptions. A rule may protect people from certain uses within the regulated market while doing little to stop the same capability from being sold into jurisdictions where courts, regulators, and civil society face weaker constraints.[2]
Fundamental-rights impact assessments do not fully cure that problem. EDRi criticizes the framework for lacking mandatory stakeholder engagement and prevention obligations strong enough to guarantee that affected people can shape or stop harmful systems before deployment.[2] In a procurement review, the question is therefore not only whether an assessment exists. It is who participated, what consequence followed from a rights risk, and whether the assessment attaches to the actor and use case actually before counsel.
This is where the Act’s value and its weakness sit side by side. It creates hard-edged obligations that many jurisdictions lack. It also leaves a national-security zone and an export gap that are especially relevant to authoritarian and illiberal use cases. A company selling, customizing, financing, or integrating surveillance tools cannot treat EU compliance as a complete answer to downstream human-rights exposure.
Glukhin Gives Facial Recognition a Serious Article 8 Frame
Glukhin v. Russia is the sharpest judicial material in this comparison because it addresses a recognizable authoritarian policing pattern: public protest, identification through surveillance, and later enforcement action. The European Court of Human Rights held in 2023 that the use of facial-recognition technology was “highly intrusive” for Article 8 purposes and required a clear legal basis, robust safeguards, and a pressing social need.[3]
That language matters because it resists the casual administrative treatment of facial recognition as merely a faster way to do what officers could have done manually. A biometric search at scale changes the burden of anonymity in public space. It can let the state move from a face in a crowd to a named person, an address, an arrest history, an association map, or a protest record.
The Article 8 structure is also useful because it forces more than a generic security justification. The practitioner’s checklist becomes concrete: identify the legal basis, test its accessibility and foreseeability, examine safeguards against abuse, and ask whether the intrusion responds to a pressing social need. In protest, journalism, religious association, and opposition-politics settings, those questions can overlap with expression and assembly interests as well as privacy.
But Glukhin is not a global rule against facial recognition. The Federal Bar Association analysis by Mirzokhid Joldoshev emphasizes the judgment’s limits: it binds within the Council of Europe system and concerns conduct before September 16, 2022, the date on which Russia ceased to be a party to the European Convention on Human Rights.[3]
Those limits matter in exactly the cases where counsel may be tempted to overstate the precedent. Glukhin can be powerful authority in the right forum. It can also be persuasive material outside that forum. But if the deployment occurs in a non-Council of Europe jurisdiction, or if the relevant conduct falls outside the temporal reach of the Convention as applied to Russia, the ruling does not by itself supply an enforceable remedy.

Preventive Repression Creates an Evidentiary Problem
AI-enabled repression is not always a spectacular violation with a clean filing date. Its advantage to an illiberal state may be earlier and quieter: identify likely challengers, deter attendance, flag networks, deny benefits, increase questioning, or make ordinary civic participation feel individually costly.
Anastasopoulos and Lian describe this as part of AI’s preventive capacity in authoritarian settings: systems can help identify and deter challengers before observable violations occur.[4] That strains legal frameworks built around notice, individualized interference, proportionality review, and after-the-fact remedies.
The problem is not only proof. It is timing. If a person stays home from a protest because prior participants were identified by facial recognition, if an organizer stops contacting certain people because their network appears mapped, or if a minority community avoids public services because classification systems feel punitive, the legal injury may be real while the record remains thin.
That timing problem explains why safeguards based only on post-deployment complaints are incomplete. The person most affected may never receive notice. The most damaging state action may be the chill rather than the arrest. The most important decision may happen inside a procurement office, security ministry, or vendor customization meeting long before a court sees a plaintiff.
International Human Rights Law Names the Harm, But Rarely Stops the Tool From Moving
International human rights instruments are indispensable for naming the interests at stake: privacy, expression, association, equality, due process, and remedy. They help counsel describe why AI surveillance is not merely a data-governance issue. They also provide vocabulary for cross-border investigations, sanctions analysis, investor diligence, and public-facing human-rights commitments.
The gap is enforcement against movement of capability. The current materials do not support a claim that international law contains a binding, comprehensive prohibition on exporting AI surveillance systems to authoritarian states. Harold Hongju Koh’s discussion of protecting human rights in the age of AI points instead to emerging work such as the Oxford Process, a “last clear chance” accountability principle, and possible analogies to an Anti-Personnel Mine Ban Treaty-style instrument.[5]
Those proposals are important because they identify the missing layer. Domestic law can regulate use in one jurisdiction. Human-rights law can condemn abuses. Export controls, procurement restrictions, sanctions, and treaty-style commitments are the tools that may determine whether a surveillance capability reaches a government likely to use it for preventive repression. At present, the normative architecture is ahead of the binding control system.
For in-house counsel, this leaves an uncomfortable gap between legality and exposure. A transaction may avoid a direct statutory prohibition and still create human-rights, sanctions, contractual, investor, reputational, or future-regulatory risk. That is not the same as saying the transaction is unlawful. It is saying that the absence of a binding international export ban should not be mistaken for a clean risk profile.
How to Test a Claimed Safeguard
A useful legal-risk memo on safeguards against AI authoritarianism should not list protections as if they travel intact across borders. It should test each safeguard against the point where it may fail.
- Jurisdiction: Does the rule bind the government, vendor, integrator, funder, or platform involved?
- Actor: Is the deployment by law enforcement, intelligence, border control, military, a private contractor, or a hybrid body?
- Exception: Does national security, defense, public order, migration control, or emergency authority change the analysis?
- Date: Does the precedent or statute apply to the relevant conduct at the relevant time?
- Remedy: Can the affected person obtain notice, standing, disclosure, exclusion, damages, injunction, administrative review, or regulatory enforcement?
- Export path: Even if use is restricted in one market, is sale, customization, hosting, training, or maintenance restricted elsewhere?
The same system can produce different legal answers at each point in its life cycle. A biometric model may be trained by one company, integrated by another, sold through a third jurisdiction, deployed by a security ministry, and used against dissidents, migrants, journalists, or ethnic minorities. A privacy statute, constitutional doctrine, EU market rule, human-rights judgment, and export-control regime may each touch only part of that chain.
That is why the strongest safeguard is usually not a single citation. It is a map of enforceable obligations and missing remedies. Tokson’s Fourth Amendment theory helps identify the constitutional stakes of police automation. The EU AI Act supplies unusually concrete prohibitions but leaves national-security and export gaps. Glukhin gives facial recognition a serious Article 8 frame but must be cabined by jurisdiction and time. International human-rights work names the systemic harm and points toward future controls, but it does not yet close the export problem.
None of these regimes is empty. None should be cited as sufficient on its own. The disciplined answer for litigators and in-house counsel is to use the strongest available framework, then test it by jurisdiction, actor, exemption, date, and remedy before treating it as a safeguard against AI-enabled authoritarian governance.
References
- The Limits of Authoritarian AI, Lawfare
- EU’s AI Act fails to set gold standard for human rights, EDRi
- Glukhin v. Russia: The European Court of Human Rights’ First Judgment on Facial Recognition Technology, Federal Bar Association
- The Limits of Authoritarian AI, Journal of Democracy
- Protecting human rights in the age of AI, Harvard Law Today
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →