Published Sep 03, 2026 by Xiph
Ubiquitous cameras, facial recognition, data fusion and social scoring already exist at national scale in one country. Australia is not that country — but much of the technology is the same, and it is worth looking honestly at where the infrastructure leads.
Every debate about surveillance in Australia eventually runs into the same objection: you're being paranoid — nobody is building a police state here. And the objection is right, as far as it goes. Nobody is. But the argument was never about intentions. It is about infrastructure — about what a network of cameras, databases and identity systems can do once it exists, regardless of what it was built to do.
That question is no longer hypothetical, because one country has finished building it. China operates the most developed surveillance apparatus on earth, and it offers something rare in this debate: not a prediction, but a case study. So it is worth walking to the end of the road and looking around — carefully, and anchored to documented fact rather than hyperbole.
The most-watched country on earth
Start with the visible layer. China is estimated to operate somewhere in the region of half of the world's roughly one billion surveillance cameras — the precise figure is unknowable, which is itself telling, but analysts have put the count in the hundreds of millions for years. Two national programs did the building. Skynet, launched in the mid-2000s, blanketed the cities. Sharp Eyes, announced in 2015, set out to extend coverage to every public space in rural China, with an official ambition summarised in three words: no blind spots.
A camera on its own is just glass and a sensor. What changed in the last decade is what sits behind it. Chinese public security bureaus routinely pair camera networks with facial recognition capable of matching a face against national ID databases in seconds. Domestic champions — SenseTime, Megvii, Hikvision, Dahua — built the analytics, and police procurement documents openly specify features such as tracking an individual across camera networks, flagging "abnormal" gatherings, and identifying people by gait when their face is obscured.
None of this is secret. It is advertised. That is the first lesson from the end of the road: total surveillance is not built in the shadows. It is procured, itemised and invoiced, one tender at a time.
Fusion — when the cameras meet the databases
The cameras are the least of it. The defining feature of the Chinese model is not watching but joining — fusing video feeds with everything else the state and its platforms hold. Police "cloud" systems documented by researchers link facial images to national ID numbers, home addresses, hotel check-ins, travel bookings, vehicle plates captured by automatic number plate recognition, and records pulled from utilities and telcos. The camera identifies you; the database explains you.
Then there is social credit, which deserves an honest treatment, because the Western caricature — a single Black Mirror score docking points for jaywalking — is largely a myth, and repeating it damages the case against the real thing. What actually exists is more fragmented and more mundane: financial credit systems, corporate compliance blacklists, and — most consequentially — the Supreme People's Court list of "discredited" judgment defaulters. Land on that list and the consequences are automatic: by 2019 the system had blocked tens of millions of flight and high-speed rail ticket purchases. No dystopian score required. Just databases, joined together, executing policy without a human in the loop.
That is the second lesson: the danger was never one scary number. It is fusion — the quiet plumbing that lets any record about you be looked up from any other, and lets a flag in one system become a consequence in all of them.
Xinjiang — the end state
Everything above reaches its extreme in the Uyghur region of Xinjiang, and here the documentation is unusually strong. In 2019, Human Rights Watch reverse-engineered a mobile app used by police in the region and found it connected to the Integrated Joint Operations Platform (IJOP) — a data fusion system that aggregates feeds from checkpoints, cameras, Wi-Fi sniffers and informants, and flags people for investigation. Among the behaviours the platform treated as suspicious: using a VPN, having WhatsApp installed, avoiding the front door of your own home, and buying more fuel than usual.
The flags had destinations. The UN's human rights office concluded in its 2022 assessment that the mass arbitrary detention of Uyghurs and other Muslim minorities — credibly estimated at upwards of a million people at its peak — may constitute crimes against humanity. Alongside the detentions came compulsory biometric collection, spyware mandated onto residents' phones, and cameras at mosque entrances. Procurement records examined by researchers showed Hikvision and Dahua winning substantial public security contracts in the region — a finding that put both companies on the US Entity List in October 2019 for their role in the surveillance of Uyghurs, and that surfaced again when camera analytics were found to include minority-detection features.
Hold on to that detail about the fuel purchases. Nobody who designed a fuel-sales database imagined it as an instrument of ethnic persecution. It was built for something ordinary. It was repurposed — because once data exists in a joined-up system, repurposing it costs nothing. That is function creep at its terminus, and it is the same dynamic Australia's own parliamentary committee documented, on a vastly smaller and less sinister scale, when councils and the RSPCA turned up in our metadata scheme.

Why Canberra ripped the cameras out
If this were purely an overseas story, Australia's response to it would be hard to explain. In February 2023, an audit driven by Senator James Paterson's questioning of every federal agency found at least 913 Hikvision and Dahua devices — cameras, intercoms, access control systems — installed across some 250 Australian government sites, including Defence and Foreign Affairs. Home Affairs had been unable to say how many there were. Defence Minister Richard Marles ordered them found and removed; the US and UK had banned the same equipment from government buildings months earlier.
The reasoning was not that the cameras had been caught doing anything. It was structural: both companies are partly state-owned, and China's 2017 National Intelligence Law obliges any Chinese organisation to support intelligence work when asked. A camera is a networked computer with a lens; whoever can update its firmware ultimately controls it. The Australian government looked at that dependency and concluded the risk did not require evidence of misuse — the capability was the risk. It is worth noticing that this is precisely the logic privacy advocates apply to surveillance infrastructure generally, endorsed at cabinet level.
And the removal only covered government buildings. The same brands remain, by industry estimates, among the most widely installed CCTV equipment in Australian shops, offices, clubs and homes — often internet-connected, rarely patched, and exactly the class of edge device that state-sponsored intruders love to route through.
The uncomfortable overlap
Now the caveat, stated plainly: Australia is not China. We have courts that rule against the government, a free press, an opposition, and a privacy regulator that found Bunnings and Kmart breached the Privacy Act by running facial recognition on every customer who walked in. In China those sentences have no equivalent. The difference is real and it matters.
But look at the component list rather than the political system, and the overlap is uncomfortable. Australia already operates automatic number plate recognition networks, facial recognition in airports and stadiums, a mandatory two-year metadata retention scheme, expanding age-verification and digital ID rails, and encryption-access powers that predate Britain's. What separates our stack from theirs is not the technology — much of it comes from the same vendors — but the joins. Our databases are fragmented, warrant requirements and oversight sit between them, and fusing them is legally and politically hard.
That is genuinely reassuring, and genuinely fragile. Fragmentation is a policy choice, revisited every time a government proposes to link one more system to another for one more good reason. China shows what the completed jigsaw looks like; every individual piece was justified, at the time, as safety. The lesson from the end of the road is not that we are on it. It is that the road is paved with infrastructure, not intentions — and infrastructure outlives the intentions of the people who built it.
What you can do now
You cannot vote the world's camera supply chain out of office, but you can control what you deploy and what you leak.
-
Audit your own cameras. Know the make, model and firmware of every CCTV and access-control device on your network, isolate them on a segmented VLAN, and replace end-of-life or unpatchable units. If government buildings shouldn't run them, ask whether your boardroom should. A cyber security risk audit will surface what six years of installers left behind.
-
Treat biometric and identity data as a liability. The Bunnings ruling made the compliance risk clear, and a store of customer faces is a breach headline waiting to happen. Collect less; you cannot lose what you never held.
-
Shrink your data shadow. Hardened handsets, genuinely end-to-end encrypted communications and a private SIM keep your movements and conversations out of databases whose future uses you cannot predict.
-
Design for fragmentation. Inside your own organisation, segment networks, minimise privilege and avoid needlessly joining data sets. Fusion is as dangerous on a corporate scale as a national one — to you, when an intruder gets in.
A final word
The most useful thing about studying the end of the road is that it dissolves the comfortable idea that surveillance risk lives in intentions. Xinjiang's fuel database was not built for persecution; Australia's metadata scheme was not built for councils chasing illegal dumping. Capabilities found new purposes because that is what capabilities do. The honest response is not alarmism — it is refusing to build, buy or hold more watching capacity than you can justify, and hardening what you cannot avoid. At Xiph Cyber we help Australian organisations and individuals do exactly that: audit the exposure, strip out the risk, and secure the rest. To start the conversation, get in touch at enquiries@xiphcyber.com.
Further reading
-
Human Rights Watch, China's Algorithms of Repression (2019) — https://www.hrw.org/report/2019/05/01/chinas-algorithms-repression/reverse-engineering-xinjiang-police-mass
-
UN OHCHR, Assessment of human rights concerns in Xinjiang (2022) — https://www.ohchr.org/en/documents/country-reports/ohchr-assessment-human-rights-concerns-xinjiang-uyghur-autonomous-region
-
OAIC determination on Bunnings' use of facial recognition — https://www.oaic.gov.au/news/media-centre/bunnings-breached-australians-privacy-with-facial-recognition-tool
-
OAIC Facial recognition technology: a guide to assessing the privacy risks - https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/organisations/facial-recognition-technology-a-guide-to-assessing-the-privacy-risks
-
US Department of Commerce Entity List additions, October 2019 — https://www.federalregister.gov/documents/2019/10/09/2019-22210/addition-of-certain-entities-to-the-entity-list
Posted in: Security