Western Australia became the first Australian jurisdiction to scan crowds with live facial recognition technology — and to do so while the state's own privacy watchdog was locked out of the process. In the five weeks since Western Australia Police launched their mobile biometric trial on June 22, 2026, the technology has scanned more than 131,000 faces, generated 33 alerts, and contributed to 19 arrests — all before the state's Privacy and Responsible Information Sharing Act 2024 (PRIS Act) had fully come into force, and without any input from the independent regulator whose job it is to protect the public from exactly this kind of program.
The state's Office of the Information Commissioner (OIC WA) confirmed in a formal statement on July 9 that it "was not invited to participate in any formal consultation process with WA Police and did not provide input into the design of the trial." That same watchdog now says the trial is the first real test of the PRIS Act — Australia's first law to directly govern how personal data is used in automated decision-making. The primary Information Privacy Principles under that Act came into force on July 1, 2026, nine days after the trial began.
With further deployments scheduled for Joondalup on July 23 and Perth on July 24, the trial is continuing this week.
How the System Actually Identifies People — and Why It Differs From Any Camera You've Seen Before
The distinction between this technology and ordinary CCTV is not a matter of degree but of kind. A standard security camera passively records video; what happens with that footage is a separate decision, made after the fact, usually by a human. Live facial recognition is something structurally different: every face that enters the camera's field of view is actively identified in real time.
According to NEC Corporation's technical documentation and the WA Police Force's own published FAQ, the system operates in four steps. First, the camera detects and segments individual faces from the background. Second, each detected face is aligned and normalized to account for lighting, head angle, and image resolution — NEC's NeoFace software can work with images containing as few as 24 pixels between the eyes. Third, the system measures specific geometric relationships between facial landmarks — eye spacing, nose width, cheekbone distance, jawline shape — and encodes them into a mathematical feature vector: a unique biometric template. Fourth, that template is instantly compared against the approximately 4,000 entries on a police watchlist that can include people wanted on outstanding warrants, registered sex offenders, missing persons, and those considered a risk to themselves or others.
When the similarity score between a probe face and a watchlist entry exceeds a pre-set confidence threshold, the system generates an alert visible to the operator in the van. Officers then physically review the alert image, observe the individual, and make their own independent judgment about whether to approach. WA Police Commissioner Col Blanch has repeatedly emphasized that an algorithmic alert alone cannot justify an arrest or the exercise of any police power.
Professor Dali Kaafar, Executive Director of Macquarie University's cybersecurity hub, told The Guardian that the police's comparison of this technology to standard CCTV is misleading. Live facial recognition does not merely observe, he said; it identifies — processing every face in view through a biometric pipeline regardless of whether that person is on any watchlist.
What NEC's Own Accuracy Data Reveals About the False-Alert Risk
WA Police reported two confirmed false alerts in the first week's 131,478 scans, alongside 19 arrests resulting from 33 total alerts. Officials have cited the overall scan-level figure as evidence of the system's precision. That framing requires unpacking.
The more operationally relevant measure is the false-alert rate among alerts generated — not among all faces processed. With 33 alerts and 2 confirmed false alerts, the system produced a false-alert rate of approximately 6 percent of all actionable alerts in its first week. That means officers were directed to engage an innocent person roughly once for every 15 or 16 valid alerts.
NEC's own published benchmark data adds a further layer of context. In 2023 testing by the UK's National Physical Laboratory, conducted for London's Metropolitan Police, NEC's NeoFace algorithm achieved a false match rate of 1-in-6,000. Applied to 131,478 scanned faces, that rate would predict approximately 22 false alerts. The trial produced far fewer — which suggests WA Police are operating the system at a more conservative confidence threshold than the NPL benchmark conditions, reducing the system's sensitivity and potentially causing the algorithm to miss some genuine suspects in exchange for fewer false positives. The specific threshold WA Police uses has not been publicly disclosed.
The NPL finding also came with a caveat: independent researchers have disputed the "no statistically significant race and gender bias" finding on grounds that at lower confidence thresholds, NeoFace shows uneven error rates based on skin darkness. The US National Institute of Standards and Technology has independently documented that facial recognition algorithms across the industry produce higher false-match rates for women, younger people, and individuals with darker skin tones. In a policing context, those accuracy gaps translate directly into a disproportionate risk of wrongful stops for minority groups.
Australia's First Automated-Decision Law Faces Its Earliest Test
The PRIS Act 2024 — Western Australia's Privacy and Responsible Information Sharing Act — received Royal Assent on December 6, 2024. Its primary Information Privacy Principles came into operation on July 1, 2026, nine days after the trial began.
Under those principles, WA Police must evaluate and demonstrate how they are managing risks of bias, harm, and discrimination in any automated system. The Act also requires a full Privacy Impact Assessment for projects deemed high-risk. A PIA was completed for the trial — WA Police published the document on their website in June 2026 — but whether it was subject to any independent review or public consultation before deployment remains unclear.
Electronic Frontiers Australia (EFA), the digital rights organization that condemned the trial as "an outrageous act of police overreach," publicly asked five questions WA Police have yet to fully answer: whether police consulted the OIC WA before launching the program, how express consent is being collected from members of the public, whether a human rights impact assessment was conducted, whether police can demonstrate the program is necessary and proportionate, and whether the PIA has been published for public scrutiny. EFA Chair John Pane was direct: "What we are talking about is a massive breach of human rights and privacy and one which could increase in scope and scale in the absence of strong laws to limit the use of biometric technologies in public and private spaces."
The OIC WA disputed the police's framing that brief biometric data processing avoids privacy law obligations. The regulator confirmed that even momentary capture still constitutes information collection under existing legal standards, and flagged biometric data's unique vulnerability: unlike a password or a credit card number, facial geometry cannot be changed if compromised.
Australia Has No Equivalent to the EU's Biometric Surveillance Rules
The contrast with European law is pointed. Under the EU AI Act, real-time remote biometric identification of individuals in public spaces is prohibited for law enforcement except under narrow, judicially authorized exemptions. No comparable national framework exists in Australia. The PRIS Act fills part of the gap for Western Australia's public sector, but it does not contain an outright prohibition or a judicial authorization requirement.
That absence matters because the UK experience — where police have used live facial recognition for nearly a decade — illustrates what happens when technology outpaces legal frameworks. In January 2026, London's Metropolitan Police faced a High Court challenge from a wrongly flagged youth worker and the director of privacy campaigning organization Big Brother Watch, who told the court the Met had deployed the technology 231 times in 2025, scanning approximately four million faces. Earlier UK deployments saw courts rule that the use of the technology violated human rights. South Wales Police's 2017-2018 trial was ruled in violation of human rights by the UK Court of Appeal in August 2020.
The pattern documented in the US is more alarming. More than a dozen people — almost all of them Black — have been wrongfully arrested due to police reliance on incorrect facial recognition results, with cases documented in at least ten states. In June 2026, the ACLU filed suit on behalf of Robert Dillon, a Florida man arrested on child-related charges after police relied on a grainy facial recognition match without any independent verification. The Detroit Police Department, per its own chief, operated a system that produced wrong results 96 percent of the time when used as the sole identification method before curtailing the practice.
WA Police have emphasized that their program includes safeguards absent from many US and early UK deployments: the van is clearly marked, public signage announces each deployment, faces not triggering alerts are pixelated and immediately deleted from the operator's screen, and officers must conduct independent verification before any arrest.
Is This Really "Not Mass Surveillance"?
Commissioner Blanch has consistently maintained the program is not mass surveillance — pointing to the bounded watchlist, the marked vehicle, the immediate deletion of non-alert data, and the manual verification requirement. That framing has support in how the term is conventionally used.
But critics argue it misses the operative question. The OIC WA's concern about "collective privacy harms" reflects a legal concept distinct from individual privacy — the idea that even if no single person suffers a direct, traceable injury, the act of subjecting an entire population passing through a public space to biometric identification creates a harm distributed across that population. Whether people know the van is there — or can read the signage — does not resolve the question of meaningful consent, because there is no alternative: a person who simply wants to walk down the street cannot opt out of having their face biometrically processed.
The 2026 Australian Community Attitudes to Privacy Survey, cited by the OIC WA, found that 45 percent of Australians now consider facial recognition their greatest privacy risk, up from 27 percent in 2023. Comfort with police use of biometric technology has fallen to 57 percent. These figures reflect a public that is increasingly skeptical of the framing — even as governments move toward normalization.
What Happens Next
WA Police have stated that the five-month pilot carries no commitment to a permanent rollout, covert deployment, or integration with the state's broader CCTV network. Results from each deployment will be published. The OIC WA says it is actively monitoring the trial and requesting information from police to assess PRIS Act compliance, and that its observations will directly inform the development of broader biometric policy in Western Australia.
Two further deployments are scheduled this week: Joondalup on July 23 and Perth again on July 24. Each requires authorization from an officer at superintendent rank or above before proceeding.
Whether the trial ends there or expands into a permanent fixture may depend less on its operational results than on the precedent it sets. As the OIC WA has made plain, the PRIS Act is actively watching — and what the regulator learns from this trial will shape the rules that govern what comes next. Australia's legal framework for biometric surveillance is being written in real time, and the van on the streets of Perth is writing the first chapter.
Frequently Asked Questions
Is Australia's live facial recognition program legal?
The trial is operating under existing law, and WA Police completed a Privacy Impact Assessment before deploying. Western Australia's Privacy and Responsible Information Sharing Act 2024 — whose primary obligations took effect on July 1, 2026 — requires police to evaluate and demonstrate how they are managing risks of bias, harm, and discrimination in any automated system. The OIC WA has confirmed it is monitoring the trial for PRIS Act compliance. Whether specific aspects of the deployment satisfy the Act's requirements is still being assessed. No national framework equivalent to the EU AI Act — which prohibits real-time biometric identification in public spaces except under narrow judicial authorization — exists in Australia.
How accurate is police facial recognition technology — and who is most at risk of a false match?
NEC's NeoFace algorithm, confirmed as the system used in WA's trial, was ranked the world's most accurate in 1:N identification by the US National Institute of Standards and Technology in April 2025, with an authentication error rate of 0.07 percent against a database of 12 million people. In the WA trial's first week, 33 alerts were generated from 131,478 scans, with 2 confirmed false alerts. Across the industry, however, NIST has documented that facial recognition algorithms consistently produce higher false-match rates for women, younger people, and individuals with darker skin tones. An independent dispute of NEC's own bias findings has also been noted: at lower confidence thresholds, NeoFace shows uneven error rates based on skin darkness. The WA Police's specific operating threshold has not been made public.
What does Australia's new PRIS Act actually require of police running this trial?
The Privacy and Responsible Information Sharing Act 2024 — Australia's first law to directly govern automated decision-making in Western Australia's public sector — requires WA Police to evaluate and demonstrate how they manage risks of bias, harm, and discrimination in any automated system. High-risk projects require a full Privacy Impact Assessment, which WA Police completed and published before the trial launched. The Act also places specific obligations around the use of biometric data — classified as sensitive personal information — including restrictions on its collection without consent. The regulator, the OIC WA, has the power to investigate complaints and to monitor compliance. What the OIC WA learns from this trial will directly inform the development of biometric policy across the state. Details are available through the OIC WA's privacy guidance.
Can I avoid having my face scanned if I walk past the WA Police van?
No. Any person who passes within the camera's field of view will have their face detected, a biometric template created, and that template compared against the watchlist — regardless of whether they have any reason to be on it. WA Police state that faces not generating an alert are pixelated on the operator's screen and that the associated biometric data is deleted automatically and immediately. Marked vehicles, signs, and online notices are used to indicate when the system is active. But experts and the OIC WA have noted that the presence of a sign is not the same as meaningful consent: there is no practical mechanism for a member of the public to decline to have their biometric data processed by the system, as the regulator has confirmed.
Related Articles