
AI in Public Safety & Surveillance
The Decision: How to Buy, Govern, and Keep Public Trust in Public-Safety AI
For the chiefs and councils who actually sign the contract, three questions decide everything: what to buy, how to govern it, and how to keep the public's consent. This closing guide walks the procurement fork — AI-native cameras vs. software that upgrades the cameras you already own — and the total cost of ownership behind the sticker price; the governance playbook from INTERPOL/UNICRI and NIST (NIST-tested systems, warrants for persistent tracking, retention caps, relentless audit, public reporting); and the hard lesson from two dozen towns that ripped out cameras they never asked their residents about. The throughline: legitimacy and stewardship aren't constraints on effectiveness — they're what make it last. Going cheap, or going quiet, is a dereliction of duty.
By Tom Hanks· June 2026· 8 min read
Somewhere this month, a police chief and a city council are sitting through a very good demo. The map lights up. A stolen car is found in the time it takes to pour coffee. A missing grandmother is located before lunch. The salesperson is competent and sincere, the technology is real, and the price on the slide looks manageable. At the end, someone asks the only question that feels natural: is this the best product?
It's the wrong first question, and I say that as someone who builds these systems for a living. It feels like the responsible thing to ask — of course you want the best tool. But sit with what the demo can't show you. If the decision were really about picking the best product, why do so many towns that bought a top-rated system vote to rip it out eighteen months later?¹ Why does the number on the slide turn out to be a fraction of what the program actually costs? And why do two departments buy the identical technology and end up in opposite places — one trusted, one in a recall fight? The answer is that the decision was never a product comparison. It's three harder questions, and they have to be asked in order: what to buy, how to govern it, and how to keep the public's consent. Get the third one wrong and the first two won't survive the term.
Let's take them in the order that actually matters.
Question one: what to buy — and what it really costs
The first fork is more fundamental than which brand. It's whether to buy AI-native cameras — new hardware sold as a subscription, where the vendor owns the equipment and pulls it off your poles if you stop paying — or software that upgrades the cameras you already own, the model where a platform aggregates your existing municipal and consenting private feeds into one searchable system.² The first is faster to deploy and turnkey; the second leans on infrastructure you've already bought and keeps you from renting your own streets. Neither is wrong. But they are different bets about ownership, and the brochure rarely frames it that way.
Then there's the number on the slide, which is the part I'd most want a council to slow down on. The sticker is not the price. Independent reporting and city budgets put these camera subscriptions in the range of roughly $2,500 to $3,000 per camera, per year — recurring, not once³ — so the real figure is that annual number multiplied across every camera and out across the life of the program. One cluster of Ohio departments was found to have spent nearly $2 million on these systems.³ And the recurring fee buys a relationship with a catch: reporting has documented that customers who stop paying can lose practical access to their own footage, because the data lives on the vendor's platform, not yours.⁴ The sticker price is the down payment on a mortgage, not the cost of the house — and the house comes with a landlord who keeps the keys.

Question two: how to govern it — the playbook already exists
The good news on governance is that you don't have to invent it. The work has been done; most agencies just don't pick it up.
INTERPOL and the UN's interregional crime institute jointly published a Toolkit for Responsible AI Innovation in Law Enforcement — a readiness assessment, a set of principles, and a risk questionnaire built specifically for police agencies.⁵ The U.S. National Institute of Standards and Technology offers the AI Risk Management Framework, organized around four plain verbs — govern, map, measure, manage — that a non-engineer can actually follow.⁶ For anything involving facial recognition, NIST also runs the independent accuracy testing that lets you make a contract contingent on measured performance rather than a vendor's adjective — "show me your results in the NIST evaluation" is a sentence every procurement officer should learn to say.⁷ And the policy floor for face recognition has been written down for years by the Bureau of Justice Assistance and the police chiefs' own association: a match is an investigative lead, never a positive identification and never probable cause on its own — to be corroborated, logged, and paired with training and retention limits.⁸ A companion essay in this series walks through why that single rule, honored or ignored, separates the recovered child from the wrongfully arrested man.
The throughline of every one of these frameworks is the same: write down who may use the system, for what, for how long, and with what record — before the cameras go live, not after the first scandal.
Question three: how to keep consent — the question that decides the other two
Here is the question that the demo never raises and that turns out to govern everything: did you ask the people being watched?
The evidence that this is decisive is no longer theoretical. Across 2025 and into 2026, a striking number of communities moved to cancel or reject camera contracts they'd already signed — the EFF counts nearly two dozen jurisdictions since early 2025; NPR puts it at least thirty.¹ The most instructive case is Cambridge, Massachusetts, which terminated its contract after discovering the vendor had installed cameras the city says it never authorized — a "material breach of trust," in the city's words.¹ The pattern underneath the list is consistent: programs imposed on a community rather than agreed with one tend to collapse when the community finds out, often taking the public's goodwill down with them. (In fairness, the trend isn't universal — some cities reviewed the same technology and chose to keep it.¹ The point isn't that everyone is revolting; it's that consent is what determines which way it breaks.)
There's a mature body of research behind this, and it's worth naming the principle: procedural justice. When people believe an institution acquired its authority fairly and uses it transparently, they extend it legitimacy — they cooperate, comply, and tolerate even intrusive tools, because they trust the motives behind them.⁹ The mechanism for earning that up front already exists too: "community control" ordinances, adopted in more than two dozen jurisdictions, simply require a public hearing and a council vote — with the capabilities, costs, and use policy disclosed — before a surveillance system is acquired.¹⁰ Asking first is not a delay tactic. It's the cheapest insurance a program can buy against being torn out later.
This is why I'd put consent first even though it comes last in the sequence: it's the load-bearing wall. The best product, perfectly governed, still fails if the public learns about it by accident.
The decision, made well
I'll disclose my seat, since this is my field: I work in AI for public safety, and these are my own views. You might expect someone in my position to tell you these questions are friction that slows good technology down. I think the opposite is true, and the whole arc of this work has convinced me of it. The tool can do real, documented good — recovered children, located missing people. The harms are just as real — wrongful arrests, purpose drift, surveillance no one agreed to. What separates the two columns is almost never the hardware. It's whether someone asked the three questions in the right order: bought the right thing for its true cost, governed it with a playbook that already exists, and earned consent before switching it on.
Legitimacy and stewardship are not constraints on effectiveness. They are what make effectiveness last — the difference between a tool a community keeps for a decade and one it rips off the poles in a year. I could be wrong about which vendor or which framework wins; those will change. I don't think I'm wrong that the order is the thing. So if you're the one holding the pen at the end of the demo, don't start with "is this the best product?" Start with "what will this cost us in full, how will we govern it, and have we asked the people we serve?" Answer those, in that order, and you won't just buy a system. You'll build something your town is still proud of after the salesperson has gone home.
References & Sources
Superscript numbers in the text correspond to the numbered sources below. The cost figure is an original graphic by the author, built from independently reported pricing; the underlying per-camera price is a range drawn from city budgets and journalism, and program totals vary by deployment. Several items post-date mid-2025.
-
NPR, "Why some cities are ditching their Flock license plate readers" (Feb 2026) — "at least 30 localities" deactivated or canceled since early 2025; some cities (e.g., San Diego, Oakland) chose to keep theirs. EFF, "Local Communities Are Winning Against ALPR Surveillance: 2025 in Review" (Dec 27, 2025) — "nearly two dozen jurisdictions." On Cambridge, MA terminating after unauthorized camera installation ("material breach of trust"). npr.org · eff.org
-
The two procurement models: AI-native subscription hardware (vendor-owned, removed on non-payment), per NPR (above); versus platforms that aggregate existing/third-party camera feeds (e.g., Axon Fusus). axon.com (vendor) · police1.com
-
Independent/government pricing: Windsor, CT official LPR FAQ (
$3,000/camera/year including installation and maintenance); City of Cleveland contract ($2,500/reader); WOSU/NPR, "Central Ohio police departments have spent nearly $2 million on Flock cameras" (Apr 28, 2026). (Vendor cooperative-purchasing price lists corroborate the $2,500–$3,000 range.) windsorct.gov · wosu.org -
Vendor lock-in / data access tied to an active subscription: Footnote4a, "You Will Own Nothing: How Flock Safety Keeps Cities From Their Own Surveillance Data"; EFF, "'Free' Surveillance Tech Still Comes at a High and Dangerous Cost" (Feb 2026). (Advocacy/journalistic framing.) footnote4a.org · eff.org
-
INTERPOL and UNICRI, "Toolkit for Responsible AI Innovation in Law Enforcement" (launched 2023; revised Feb 2024) — readiness assessment, principles, and risk questionnaire for law-enforcement agencies. unicri.org · interpol.int
-
NIST, "Artificial Intelligence Risk Management Framework (AI RMF 1.0)" (Jan 2023) — Govern, Map, Measure, Manage. nist.gov
-
NIST Face Recognition Vendor Test / Face Recognition Technology Evaluation (FRVT/FRTE) — independent third-party accuracy and demographic testing usable as a procurement benchmark. nist.gov
-
Bureau of Justice Assistance, "Face Recognition Policy Development Template" (results are investigative leads only — not positive identification, not probable cause; corroboration, logging, training, retention). bja.ojp.gov
-
Tom R. Tyler et al., "Procedural Justice, Legitimacy, and Effective Law Enforcement" — perceived legitimacy drives voluntary cooperation and tolerance of police authority; Tyler, "Legitimacy-based policing," Criminology & Public Policy (2025). law.yale.edu
-
ACLU, "Community Control Over Police Surveillance" (CCOPS) — public hearing and governing-body approval, with capabilities/cost/use-policy disclosed, before acquiring surveillance technology; adopted in two dozen-plus jurisdictions. aclu.org