Cities have always watched their streets. What has changed is the scale, the speed, and the intelligence of that watching. A nineteenth-century constable could remember a face. A mid-twentieth-century control room could cycle through a few dozen cameras. A contemporary operations center can ingest thousands of video streams, vehicle movements, environmental readings, and device signals at once. Artificial intelligence can sort those streams, match faces, reconstruct journeys, and assign risk scores. The result is a political question that no longer belongs only to science fiction.
Are smart cities making urban life safer and more efficient—or are they assembling the technological infrastructure of a total surveillance state?
The question is not whether cameras exist. They do. It is not whether data exist. They do. It is whether the combination of sensors, identity systems, commercial databases, and machine interpretation can, under certain legal and political conditions, produce something closer to continuous, individualized awareness of urban life than any previous generation of government possessed.
The 2026 science-fiction thriller Mercy, directed by Timur Bekmambetov and released in the United States on 23 January 2026, dramatizes one version of that future. Set in Los Angeles in 2029, the film imagines a Mercy Capital Court: an artificial-intelligence judge with access to a municipal cloud in which devices, cameras, social media, and location records are available for a ninety-minute trial. A defendant who fails to drive a calculated guilt probability below a set threshold is executed. Chris Pratt’s detective, once a champion of the system, must use the same apparatus to prove he did not murder his wife. Rebecca Ferguson appears as Judge Maddox, the composed face of the machine.
The film is entertainment, not a technical white paper. Several reviewers noted that it raises questions about privacy and then spends more energy on countdown-clock plotting than on institutions. That is a fair criticism of the movie as cinema. It does not make the premise useless. Mercy is valuable here as a thought experiment. It asks what happens when ubiquitous recording, data fusion, and automated judgment become a single system, and when speed is treated as a substitute for due process.
This article examines that question with as much care as the subject requires. It distinguishes technologies that already exist from those that are emerging, and both from the film’s fictional court. The gap between today’s smart city and the world of Mercy is still large. The building blocks are not imaginary. The decisive variables are not only chips and cameras. They are law, incentives, and who is allowed to say no.
What Is a Total Surveillance State?

A surveillance state is a political order in which public authorities can observe, identify, and reconstruct the activities of large populations as a matter of routine, not only as a targeted investigation of a named suspect. The word “total” is an ideal type. No state sees everything. Weather, darkness, encryption, informal cash economies, and simple human messiness still create gaps. The term is still useful. It describes a condition in which the default is visibility, and invisibility requires effort, luck, or privilege.
Ordinary security monitoring is narrower. A camera at a bank entrance, a police officer watching a crowd, a prison perimeter, or a warrant-backed wiretap are familiar forms of security. They are usually limited in place, time, or legal predicate. Mass surveillance is different. It collects information about people who are not individually suspected of a crime. The justification is statistical or preventive: we record everyone so that we can later find someone, or so that the possibility of being found will deter misconduct.
Government surveillance and corporate surveillance overlap but are not identical. Governments can compel testimony, seize property, imprison, and exclude people from a territory. Companies can profile, price, deny credit, fire, or lock a user out of a platform. When governments purchase commercial location data, when police query doorbell-camera networks, or when firms operate identity and camera systems under public contracts, the distinction blurs. A citizen may experience one continuous gaze even if the legal owners of the sensors are many.
Centralized surveillance funnels many sources into one authority or platform. A ministry, a police fusion center, or a municipal “city brain” becomes the place where queries are answered. Decentralized surveillance leaves data with many actors—transit agencies, retailers, phone companies, insurers, doorbell-camera firms, hospitals—until those datasets are later combined by contract, subpoena, breach, or informal sharing. Decentralization can protect liberty if the walls hold. It can also hide the true scope of watching, because no single agency has to admit that it holds the whole picture.
Mass surveillance watches everyone in a category or place: all passengers in a station, all cars on a ring road, all phones in a protest zone. Targeted surveillance focuses on a named person after some threshold of suspicion. Modern systems often begin as targeted tools and expand. A watchlist of fugitives becomes a gallery of “persons of interest.” A camera installed after a bombing remains after the investigation ends. A pandemic-tracing app outlives the pandemic.
Data aggregation changes the nature of the problem. A single GPS ping is almost meaningless. Combined with a workplace address, a credit-card record, a camera match, a social-media post, a transit tap, and a medical appointment, it can reconstruct a life. This is a long-standing insight of data-protection scholarship: information that is harmless in isolation becomes revealing in combination. The “mosaic theory” in privacy law makes the same point. The mosaic is not a metaphor. It is an engineering description of what fusion platforms do.
Interconnection multiplies power. A camera that only records is limited by human attention. A camera linked to facial recognition, a vehicle database, a digital identity, a payments rail, and a predictive model can do something closer to continuous identification. The risk is not any one sensor. It is the fusion layer—the software and legal authority that treat the city as a single searchable object.
Seemingly harmless data points become intimate when stacked. A coffee purchase is trivial. A coffee purchase every Tuesday near a clinic, followed by a bus ride to a lawyer’s office, followed by a deleted draft message, is no longer trivial. Smart-city architecture is exceptionally good at stacking.
What Is a Smart City?

A smart city uses digital infrastructure to manage urban systems in near real time. The phrase is marketing as much as engineering. Vendors sell “intelligence.” Municipalities buy dashboards. Behind the language is a more ordinary fact: cities are trying to run complex physical systems with better information.
Typical components include:
Internet of Things sensors for traffic, parking, air quality, noise, waste, water pressure, and energy
CCTV networks, often upgraded with analytics software
Facial recognition in some jurisdictions
License-plate recognition on roads, car parks, and police cars
Adaptive traffic signals and connected public transport
Public Wi-Fi and smart streetlights that can host cameras and radios
Environmental and structural sensors on bridges, tunnels, and flood defenses
Digital identity systems and municipal applications
Smart buildings, lifts, and access control
Location tracking from phones, vehicles, ticketing, and payments
Cloud platforms, data lakes, and artificial intelligence
Predictive analytics and, in some cases, automated or semi-automated decisions
The architecture usually has four layers. First, devices at the edge: cameras, meters, gates, phones. Second, connectivity: fiber, cellular, and radio. Third, platforms that store and join data. Fourth, applications that display alerts, optimize signals, or recommend patrols. Artificial intelligence now sits in the third and fourth layers. It classifies video, forecasts demand, and, increasingly, proposes actions.
Governments adopt these tools for reasons that are not sinister. Congestion wastes time and fuel. Emergency services need faster routing. Utilities want to detect leaks before streets collapse. Transit agencies want to match buses with actual demand. Pollution sensors can inform public-health alerts. After a disaster, sensor networks can locate damage. A mayor who promises fewer traffic deaths and shorter ambulance times is not reciting a conspiracy.
Citizens often accept cameras if they believe the benefit is crime reduction or faster help. That acceptance is empirical, not only ideological. People who have been victims of violence, or who live with unreliable infrastructure, may value visibility more than anonymity. People who have been misidentified, over-policed, or politically targeted may value the opposite. A serious account has to hold both experiences at once.
The same architecture that optimizes traffic can, if poorly governed, become a map of who went where, with whom, and when. That dual use is not an accident of science fiction. It is a property of general-purpose data.
The Surveillance Technologies That Already Exist
Facial Recognition

Facial-recognition systems extract a mathematical template from a face and compare it with a gallery of known images—driver’s licenses, mugshots, visa photos, or other databases. Live or “real-time” systems scan crowds and attempt matches against a watchlist. Retrospective systems search recorded video after an incident. A third mode, sometimes called clustering or re-identification, tries to decide whether the same unknown person appears at several places and times.
Accuracy is not uniform. Independent testing over many years, including work associated with the U.S. National Institute of Standards and Technology, has shown that error rates can vary by demographics, lighting, camera angle, age, and image quality. Civil-liberties organizations, journalists, and courts have documented cases in which misidentification contributed to wrongful arrests. Some of those cases involved hours or days in custody; reporting in 2025 and 2026 continued to describe serious errors. Supporters argue that newer models, better cameras, and mandatory human review reduce those risks. The dispute is not whether the technology exists. It is how reliable it is under street conditions, who is in the gallery, whether the subject consented to being in the gallery, and whether a match should ever be enough to detain someone.
Deployments in 2025 and 2026 remain uneven. Some U.S. cities banned government use of face surveillance years ago. San Francisco’s 2019 ordinance was an early and influential example; other cities followed, while still others expanded police access. Several U.S. states now require warrants, forbid using a match as the sole basis for arrest, or restrict analysis of body-camera footage. There is still no comprehensive federal statute. The United Kingdom has moved toward more live facial recognition in high-crime and high-traffic areas, including plans discussed in August 2026 for busy commercial streets in London. Brazil has seen a rapid increase in municipal and police projects. India has integrated analytics into large city and transit camera networks. The European Union’s AI Act, with prohibitions on certain real-time remote biometric identification in publicly accessible spaces taking effect from February 2025, is the most comprehensive legal brake in a major market. The ban is not absolute. Narrow exceptions exist for searching for missing persons or trafficking victims, preventing an imminent terrorist threat, and identifying suspects in a limited list of serious crimes, and those exceptions must be written into national law with safeguards.
The public often imagines facial recognition as a magic name-tag. In practice it is a probability, a watchlist policy, and a workflow. If the watchlist is huge, false alarms multiply. If operators are under pressure, they may treat a possible match as a fact. If the gallery was built by scraping the internet, the legal and ethical problems multiply again. The AI Act’s prohibition on untargeted scraping to build facial databases is a direct response to that business model.
AI-Powered CCTV

Modern video analytics go beyond recording. Commercially available systems can detect people, vehicles, and objects; estimate crowd density; flag loitering or abandoned bags; read plates; notice someone going the wrong way down a corridor; and raise automated alerts. Research papers and vendor literature describe behavior analysis, fall detection, fight detection, and anomaly detection. These tools are already used in transport hubs, stadiums, retail, factories, and city command centers. Edge processing—running the model on or near the camera—has grown because it reduces bandwidth and latency.
What these systems do not do, reliably, is read minds or predict a unique future crime with certainty. They classify patterns in video. False alarms are common. Context is often missing. A person running may be late, exercising, or fleeing. A crowd may be a festival or a riot. A bag may be trash or a threat. The operational temptation is to treat the alert as knowledge rather than as a hypothesis.
The more cameras a city installs, the more it needs automation, because no staff can watch everything. Automation then creates a new staff problem: alert fatigue. Operators ignore the system, or they trust it too much. Neither failure is fictional.
Location Tracking
Smartphones continually interact with cellular towers, Wi-Fi access points, Bluetooth beacons, and satellite navigation. Apps request location for maps, ride-hailing, weather, and advertising. Operating-system permissions are imperfect protections when a user needs the app. Connected vehicles report position to manufacturers, insurers, and fleet managers. Transit cards and mobile tickets leave trails. Bluetooth contact-tracing during the COVID-19 years taught a generation that proximity can be measured even without GPS.
Even without a dedicated tracker, a dense city can reconstruct movement from multiple weak signals. A phone that never “shares location” may still generate cellular records. A car that is not a police target may still pass a dozen plate readers. A person who pays cash may still walk under cameras that can be searched later.
Law-enforcement use of historical location data, including so-called geofence requests that ask a company for all devices in an area at a time, has been litigated in the United States. Some states have imposed warrant requirements. The technical capability—reconstructing where a device has been—is mature. The legal capability depends on the country and, in federal systems, on the state.
License-Plate Recognition

Automated number-plate recognition cameras photograph plates and store time, location, and sometimes vehicle characteristics such as color or make. Networks operated by police or private companies can show where a car has traveled across a region. In several countries these systems are routine for tolling, parking, congestion charging, and stolen-vehicle alerts.
Privacy concerns focus on retention and sharing. A plate log is a travel diary. If it is kept for years and searchable by many agencies, it becomes a history of associations: who parked near whom, who visited a clinic, a church, a union hall, or a lover’s street. Private vendors have built large networks by selling cameras to neighborhoods and police departments. Public controversy has grown in parallel, including legislative scrutiny in some countries of how plate data are stored and who may query them.
Biometric Identification

Fingerprints, face, iris, voice, and, in some research and security settings, gait are used to bind a body to a record. Airports, phones, banking, welfare systems, and border kiosks already rely on biometrics. Gait recognition is attractive to some agencies because it can work at a distance or from behind, when a face is hidden.
The policy issue is not novelty. It is whether a biometric becomes a universal key that links otherwise separate databases. A fingerprint that unlocks a phone is a convenience. A fingerprint that is the same index used for welfare, voting, travel, and policing is an architecture. Once that architecture exists, the temptation to query it for new purposes is permanent.
Digital Identity

Digital identity systems connect a person to services: tax, healthcare, travel, payments, and transport. Estonia’s e-ID, India’s Aadhaar, and the European Union’s work on a digital identity wallet under the eIDAS framework illustrate different models.
Aadhaar, a twelve-digit number tied to biometric enrolment and used by well over a billion residents, has improved delivery of some public services and reduced certain forms of leakage. It has also raised long-standing concerns about exclusion when authentication fails, about data security, and about the risk that a single identifier becomes a bridge across previously separate records. India’s 2023 Digital Personal Data Protection Act and subsequent rules attempt to impose consent and purpose limits. A new Aadhaar app launched in January 2026 emphasized selective, consent-based sharing rather than photocopying an entire identity document. Critics argue that structural design still matters more than notices: if the same number sits inside bank, telecom, tax, and welfare files, those files can be aligned even without a dramatic central hack. In April 2026 the government dropped a proposal to mandate pre-installation of the Aadhaar app on smartphones after industry and privacy pushback.
A digital ID is not, by itself, a surveillance state. Linked to cameras, payments, and movement data without strong legal walls, it can become the index of one. The wallet model—prove one attribute, such as age, without revealing everything else—is an attempt to keep the benefits of digital identity without building that index. Whether governments and platforms accept minimal disclosure is a political test that is still underway.
The Rise of AI Surveillance

Traditional CCTV stored pictures for a human to review later. The tape was a record, not an analyst. AI changes the economics. Computer vision can watch thousands of feeds at once. Machine learning finds patterns that no analyst could search by hand. A query can become: show me the person in the green jacket who entered the station after 18:00 and later appeared near this car. That query is no longer science fiction. It is a product category.
Predictive analytics estimate where incidents are more likely. Social-network analysis maps associations from calls, co-location, or online graphs. Some vendors have marketed “emotion recognition,” offering to detect anger, fear, or deception from faces. Independent scientists have repeatedly warned that claims about reading inner states from facial muscle movements are weakly supported, culturally brittle, and easy to overfit. The EU AI Act treats emotion recognition in workplaces and schools as a prohibited practice, which is a legal judgment that the risk and the scientific weakness are both serious.
Predictive policing systems have been used in multiple countries to allocate patrols or score people for risk. Researchers and human-rights groups have argued that because historical crime data reflect past enforcement patterns, algorithms can reproduce those patterns—sending more officers to already over-policed neighborhoods and generating more data that confirm the original prediction. Feedback loops are not a metaphor. They are a data-generating process. Some departments have scaled back or abandoned particular tools after audits. Others continue to use them with claimed safeguards, such as removing race as an input. Removing the variable is not the same as removing the proxy. Address, prior stops, and social networks can carry the same information.
New investigative assistants based on large language models raise a different problem: sycophancy, the tendency of a system to tell the user what it thinks the user wants. If an officer asks a tool to summarize evidence, the summary may omit inconvenient facts. Transparency and independent evaluation are the minimum responses. They are not yet the norm.
The crucial shift is from collection to interpretation at scale. Storage is cheap. The new power is the ability to turn raw footage and logs into profiles, alerts, and scores without a human watching every minute. Mercy takes that shift to an extreme: interpretation becomes verdict, and the verdict is immediate.
The Data Fusion Problem

No single technology matches the world of Mercy. Fusion does more of the work.
Imagine a city that already has the following, each of which exists in some form somewhere:
Street and transit CCTV with person and vehicle detection
Facial recognition against a limited watchlist
Smartphone location from apps and networks
License-plate readers
A digital identity used for benefits and travel
Payment and transit records
Social-media accounts that are public or obtainable by legal process
Building access logs and workplace badges
An AI platform that can query these sources together
A hypothetical reconstruction might look like this. A person leaves home: the phone leaves the night-time Wi-Fi, a camera near the door records a silhouette, a smart meter shows a change in load. They board a bus: a tap or an app. They enter an office district: a plate, a badge, or a face, if those systems are enabled. They meet someone: two devices in the same café, a camera, a payment split. They attend a demonstration: a phone in a geofenced area, cameras, posts, a purchase of a transit ticket at an unusual hour. They buy medicine: a payment. They visit a relative: a plate reader on a residential street.
None of these facts is extraordinary. Together they outline movements, relationships, habits, work patterns, shopping, health-adjacent behavior, and associations. A second pass can infer more: likely employer, likely partner, likely political interest, likely childcare routine. A third pass can compare this person with others who have similar patterns.
This is a realistic capability of fused systems. It is not a claim that every city runs such a complete stack, or that every government legally may. Technical possibility and institutional practice are different things. Many democracies still have legal silos, warrant requirements, and agencies that do not share well. Those frictions are sometimes called inefficiency. They are also a form of privacy.
The film’s municipal cloud is the fusion layer made total and then placed in charge of life-or-death judgment. The cloud is the character. The judge is its voice.
How Close Are We to Mercy?

Mercy is set only a few years after its release. That closeness is part of the film’s unease. The comparison below treats the movie as fiction and current systems as documented practice.
| Technology / capability | Depicted in Mercy | Exists today? | Current reality | Future potential |
|---|---|---|---|---|
| Ubiquitous cameras | Citywide, including doorbells and phones, in one cloud | Partially real | Dense CCTV in many cities; doorbell and body-worn cameras widespread; not universally pooled | Higher density and more contractual sharing |
| AI monitoring of video | Instant search across all feeds | Partially real | Analytics on selected networks; human review still common | Broader real-time search as compute cheapens |
| Facial recognition | Routine identification of anyone | Partially real | Used in airports, some policing, some cities; banned or restricted elsewhere; error and bias issues | More accurate models; political limits will decide scale |
| Predictive systems | Guilt probability updated in real time | Emerging | Risk scores and patrol prediction exist; not used as execution thresholds | More scoring in administration and security |
| Digital identity | Tied to the municipal cloud | Partially real | National IDs and wallets expanding; not always linked to live video | Tighter linkage if law allows |
| Automated law enforcement | AI judge, jury, and executioner in 90 minutes | Primarily fictional | Algorithmic support for investigation and some administrative decisions; capital or summary execution by AI is not a recognized legal system in democratic states | Automation of more decisions is plausible; this specific court is not |
| Behavioral prediction | Reconstructing events from all data | Emerging | Pattern-of-life analysis in intelligence and marketing; incomplete and error-prone | Richer models, still not mind-reading |
| Centralized databases | One municipal cloud of everything | Partially real | Fusion centers and city platforms exist; legal and technical silos remain | Greater integration |
| Real-time tracking | Near-total location awareness | Partially real | Phones and vehicles are highly trackable; legal access varies | More sensors, more warrants or more abuse |
| Autonomous security | Instant lethal enforcement | Primarily fictional | Drones, robots, and access control exist; lethal autonomy in city justice does not | Security robotics will grow; law is the constraint |
| Government control via tech | The system is the court | Emerging in some places | Service denial, watchlists, and administrative penalties exist; not a single AI sovereign | Depends on politics, not only chips |
Already real: dense cameras, ANPR, phone location, many biometrics, video analytics, city operations centers, commercial data brokerage.
Partially real: live facial recognition, data fusion, predictive scoring, digital ID linkage, automated alerts that trigger police action.
Emerging: city-scale digital twins, agentic systems that query many databases, more automated administrative decisions, more private-public camera sharing.
Primarily fictional: an AI that tries capital cases in ninety minutes, executes the defendant in the chair, treats a unified cloud of all private devices as the ordinary evidence file, and replaces appeal with a probability meter.
The film’s most science-fictional element is not the camera. It is the legal system. The second most fictional element is completeness. Real systems miss. They disagree. They go down. They are staffed by people who forget passwords and ignore alerts. Completeness is an aspiration of vendors and a fear of critics. It is not a present fact everywhere.
Avoiding exaggeration is not the same as being complacent. A system does not need to be total to be oppressive. It needs to be good enough, in the hands of an institution that is willing to use it broadly, against people who cannot effectively contest it.
The Most Important Difference: Technology vs. Governance

Identical tools produce different cities. A camera network under a warrant requirement, a retention limit, an independent auditor, and a free press is not the same as a camera network with no appeal and no deletion. A face-matching tool used only to find a missing child, with a short retention period and a public report, is not the same as a tool used to catalogue every person at every station.
What matters:
Constitutional and statutory rights that a court will actually enforce
Rules of evidence that can suppress unlawfully obtained material
Independent oversight and data-protection authorities with staff and teeth
Transparency reports that name the systems, the queries, and the error rates
Limits on retention and secondary use
Judicial authorization for sensitive searches
Meaningful consent and alternatives where the private sector is involved
Cybersecurity and access control so that a junior official cannot browse a life for amusement
Penalties that actually deter misuse
Democratic competition, so that excess can be voted against
A press and civil society that can obtain documents and survive retaliation
The European Union’s AI Act prohibits social scoring of the kind associated with ranking citizens for general worthiness, and it tightly restricts real-time remote biometric identification in public for law enforcement. GDPR already constrained purpose, minimization, and retention. Transparency rules for certain AI interactions and for some biometric and emotion-recognition systems took further effect in August 2026. Implementation will be uneven. Exceptions will be tested. The direction of travel is still a legal one: high-risk systems need duties; some practices are forbidden.
The United States remains a patchwork: city bans, state biometric and privacy laws, sectoral rules, and a still-unsettled Fourth Amendment jurisprudence for digital trails. That patchwork can protect people in one city and leave them exposed in the next. It can also allow agencies to shop for the most permissive partner.
China has built some of the world’s densest camera and analytics systems, while also issuing rules that try to bound public “credit” information, standardize repair of records, and reduce some of the more arbitrary local experiments. Researchers have repeatedly noted that the popular image of a single nationwide citizen score is not an accurate description of the national system as it has actually developed. That correction matters. It does not erase the reality of extensive police-technical capacity, identity-linked monitoring in sensitive regions, or the export of camera and analytics hardware.
These are not moral cartoons. They are different legal machines sitting on similar hardware. A serious comparison looks at courts, not only at camera counts.
Benefits of Smart-City Surveillance

A balanced account has to include uses that many residents want.
Cameras and analytics can help investigate shootings, locate abducted children, and identify stolen cars. After a bombing or a hit-and-run, retrospective video search can be the difference between a lead and a closed file. License-plate systems recover vehicles and enforce congestion charges that fund public transport. Traffic systems shorten emergency response. Hangzhou’s City Brain, often cited in technical and policy literature, has been associated with faster incident clearance and higher average speeds in pilot corridors; later versions have been described as coordinating a wider set of urban functions, from incident detection to some forms of automated operational response.
Environmental sensors warn of dangerous air and heat. Smart grids reduce waste and can isolate faults. Transit data can add buses where they are needed and reduce crowding that is itself a safety issue. Structural sensors can flag a bridge before it fails. After earthquakes or floods, connected infrastructure can show which pumps, roads, and hospitals are still working. During a missing-person search, a lawful, targeted query of cameras and phones can save a life.
People accept some watching when the benefit is visible and the alternative is fear or chaos. That bargain is the political engine of smart-city procurement. It is also the opening through which function creep enters. A camera justified by ambulances is still a camera. The ethical test is whether the city can keep the ambulance benefit without quietly acquiring a general dossier.
The Risks

The dangers are not speculative in kind, even when their worst forms remain incomplete.
Loss of privacy. Continuous recording erodes the assumption that moving through a city is anonymous. Anonymity in public was never absolute. It was practical. Practical anonymity is what makes political organizing, unpopular religion, medical visits, and ordinary eccentricity possible.
Function creep. A system bought for traffic is later used for protest monitoring, immigration enforcement, or tax compliance. Each new use is defended as a small, reasonable extension.
Mass profiling. Fusion creates categories of people: frequent this mosque, regular at this clinic, associate of this activist, typical of this neighborhood. Categories become inputs to scores.
False positives. A wrong face match or a bad location ping can cost someone a job, a visa, or days in custody. The person who is wrongly flagged bears the cost of the system’s convenience.
Algorithmic bias. Training data and camera placement can distribute errors unevenly. Darker skin, women’s faces, children, and people with disabilities have been associated, in multiple studies and audits, with higher error rates in some systems. Debate continues about how much recent models have improved. The duty to measure remains.
Discrimination. Even an accurate system can be used to police some communities more than others.
Abuse by authorities. Intimate video, location history, and association maps are tools of blackmail and political punishment if access is loose.
Corporate exploitation. Private camera, plate, and location networks monetize movement. A neighborhood that buys “security” may be selling a behavioral dataset.
Data breaches and identity theft. A fused identity graph is a high-value target. The more complete the city file, the more catastrophic the leak.
Chilling effects. Knowing that a protest will be archived changes who attends. The people who stay home are not recorded as a statistic of harm.
Suppression of protests. Identification after the fact can be as effective as a ban. Organizers know this. So do police.
Political misuse. Watchlists can track opponents more readily than they track the powerful.
Lack of transparency. If the model is proprietary and the query logs are secret, error cannot be audited.
Permanent digital records. Context dies. The file does not. A joke, a mistake, or a medical visit can outlive the reason it was innocent.
Incorrect automated decisions. A score that no official can explain is hard to contest. Automation plus opacity is a due-process problem even when the stakes are only a benefit payment or a school place.
Surveillance creep is the process by which a limited, popular system expands in purpose, in population covered, and in retention, usually one exception at a time. No single step looks like Mercy. The path is a staircase.
From Surveillance to Social Control

Observation becomes control when it is tied to consequences: a denied permit, a frozen payment, a blocked turnstile, a higher insurance price, a visit from police as a “precaution,” a visa refused, a job offer withdrawn.
Some mechanisms already exist in limited form. No-fly lists. Benefit-eligibility algorithms. Credit scoring. Automated fare enforcement. Workplace access systems. Customs risk targeting. Personalized government messaging is common. Predictive intervention—visiting someone because a model says they are high risk—has been tried and criticized, including in programs that scored people for likely involvement in violence.
Digital reputation systems that rate general civic virtue and then automatically restrict travel, schooling, or consumption for the poorly rated are closer to the popular myth of China’s social credit system than to that system’s documented national design. The more accurate picture is a cluster of tools: court-defaulter blacklists with real travel consequences, corporate compliance ratings, local experiments, and formidable police databases. Exaggeration helps no one. Understatement does not either. Administrative scoring plus dense identification is a real pathway to control, even without a cinematic Mercy chair.
The film’s execution device is a moral amplifier. It forces the audience to feel the cost of error. Real systems often hide the cost in quieter exclusions: you simply cannot board, cannot work, cannot enter, cannot appeal in time.
The Psychological Effect

Jeremy Bentham’s panopticon and Michel Foucault’s reading of it remain useful. If you believe you may be watched, you often behave as if you are. The effect does not require an executioner. It requires uncertainty.
People avoid jokes in public. They skip demonstrations. They hesitate to visit a clinic. They stop meeting a controversial friend. They keep their heads down on public transport. They fear that an algorithm will misread a gesture, a hoodie, or a running step. Parents warn children that anything they do may be recorded. That advice is already common. It is a cultural adaptation to cameras, not a prophecy.
Self-censorship is difficult to measure and easy to dismiss, which is why it is dangerous. Surveys can understate it. Officials can say that only the guilty should worry. That slogan misunderstands both error and politics. Innocent people worry about being misread. Citizens in a democracy sometimes need to do lawful things that the current majority dislikes.
A city can become less free while remaining formally legal. The streets are calm. The feeds are clean. The population has learned the new manners of being observed.
China, the United States, Europe, the Middle East, and Other Regions

China. Large-scale CCTV, increasingly searchable by AI, is a documented feature of urban governance, along with platforms for traffic and public security. Hangzhou’s City Brain is a prominent operations system. Reporting and technical accounts describe later upgrades, including more automated coordination and the integration of newer models for search and management. Social credit, as of 2025 and 2026 official drafting and commentary, is better understood as a family of financial, judicial, and compliance tools than as one omniscient citizen score. Drafting toward a more formal social-credit law, catalogues of public credit information, and credit-repair measures all point to an effort to regularize rather than to theatricalized omniscience. In Xinjiang and other sensitive contexts, reporting by researchers, journalists, and governments has described far more intrusive, identity-linked monitoring. Export of Chinese camera and analytics vendors has spread hardware widely. A serious reader should hold two thoughts: the sci-fi score is overstated, and the police-technical stack is not.
United States. Camera density is high in many metropolitan areas. Private networks—doorbell cameras, retail analytics, neighborhood plate readers—are especially important. Police often reach those networks through partnerships rather than through a single municipal cloud. Federal law on facial recognition remains thin. States and cities diverge, from bans to active use. Immigration enforcement has at times expanded biometric tools available to local partners. Constitutional litigation over location data, reverse warrants, and prolonged tracking is a live constraint that many other countries lack. The constraint is incomplete. It is still real.
Europe. GDPR and the AI Act create the strictest large-market rules against social scoring and against most real-time public facial recognition for police. Member states still run extensive CCTV and debate how wide the exceptions should be. Italy and other states have tried to write national rules that sit inside the Act’s exceptions; the Commission has already signaled that the ban is the default. Implementation, delayed in some high-risk respects, will be a decade-long legal argument. Europe is not camera-free. It is trying to make certain uses expensive, exceptional, and reviewable.
Middle East. Gulf states have invested heavily in smart-city brands, command centers, biometric borders, and new-city projects. Ambition is high. Independent oversight is generally weaker than in the European Union. Projects such as NEOM advertise comprehensive sensing and AI management of resources. What is built, who is enrolled, and how dissenters are treated will matter more than brochures. Other states in the region mix older security services with newer cameras and lawful-intercept systems. One should not flatten the region into a single model.
India and others. Aadhaar plus expanding city CCTV and facial-recognition pilots create a powerful stack if legal walls fail. Delhi’s integrated command system and AI-enabled cameras have grown in phases, with public debate about databases and accuracy. Brazil’s expansion of police facial recognition has been driven by crime fear as much as by industrial policy. The United Kingdom has treated live facial recognition as a crime-fighting tool while civil-liberty groups argue that the evidence of necessity and the problem of bias have not been adequately met. Singapore’s Smart Nation program is often ranked highly for services and also runs substantial sensing, under a political model that prioritizes order, competence, and efficiency.
No region is simply good or bad. The variables are law, transparency, who can say no, whether a mistake is reversible, and whether the press can report the mistake.
Real-World Smart Cities

Singapore. The Smart Nation agenda digitizes services, transport, and urban planning. Virtual Singapore is a well-known city-scale digital twin used for simulation of buildings, terrain, and infrastructure. Sensors support traffic, estate management, and security. The bargain is competence and convenience under strong state capacity. Residents get services that work. They also live in a polity where the state is unusually able to join data if it chooses.
Hangzhou. City Brain is frequently cited for AI traffic management: cameras and other data feed signal control and incident detection, with reported gains in speed and emergency response in official and academic accounts. The same architecture can support identification and search. Data governance and public trust remain live issues in the literature. The lesson is dual use in a single platform.
Barcelona. Superblocks and IoT lighting, noise, and air-quality sensors are often presented as a citizen-centric model. The city has also experimented with treating data as a public commons rather than a vendor asset. The emphasis is livability more than total identification. It is a reminder that “smart” can mean reclaiming streets, not only recognizing faces.
Songdo, South Korea. A purpose-built district with extensive sensors, pneumatic waste, and a control center. It shows that wiring a city from scratch is possible—and that technology does not automatically produce a vibrant or trusted public realm. Population and social life lagged the infrastructure story for years.
Sidewalk Toronto. Alphabet’s waterfront proposal collapsed in significant part over data governance: who would own the city’s sensor trails, and whether a corporate platform should sit under urban life. It is a reminder that public opposition can stop a project while the same components continue elsewhere under different branding.
Command-center cities. Delhi’s expanding AI camera network, Rio’s integrated centers, London’s mix of CCTV and live facial-recognition trials, and New Orleans’ contested private-public camera arrangements show how “safe city” branding becomes a procurement category. Controversies typically concern watchlist composition, accuracy, notice, private control of public watching, and mission creep.
In each case the pattern is the same: a problem such as congestion, crime, or energy; a sensor; a platform; a controller; and an argument about limits. The argument is the part that cannot be outsourced to a vendor.
Could AI Eventually Create a “Digital Twin” of a Person?

A city digital twin is a living model of streets, pipes, and buildings. Singapore’s project is a leading example of the urban kind. A personal or behavioral twin would be a model of an individual’s likely movements, purchases, contacts, and responses.
Marketing systems already approximate this. Recommendation engines guess what you will watch or buy. Intelligence agencies have long built “patterns of life” from communications and travel. Insurers price risk from behavior. Smart-city platforms could do it with more sensors and a more continuous clock.
That is prediction from traces, not telepathy. People remain unpredictable. Models fail on rare events, private motives, shared devices, cash, and those who live partly off-grid. A twin can be confident and wrong. The danger is that institutions will treat the twin as more real than the person, especially when the person cannot see the model.
The ethical line is whether such a model is used to serve the person, to sell to them, or to pre-empt them. A twin that warns you about a flood is a service. A twin that decides you are about to become a problem is a political instrument.
The Cybersecurity Dimension

A connected city is an attack surface. Cameras have been breached in large numbers. The 2021 intrusion into Verkada’s cloud, in which attackers accessed a vast set of enterprise and institutional cameras, remains a standard warning. Older and poorly maintained cameras are routinely conscripted into botnets. Traffic systems have been disrupted; researchers have shown for years that poorly secured signals and sensors can be manipulated. The Polish city of Olsztyn’s 2023 incident, in which an attack on integrated traffic and ticketing systems produced jams and forced a crude disconnection of servers, illustrated that integration is both a benefit and a failure mode. Ransomware has hit municipalities around the world. Compromised cameras can be turned from shields into intelligence tools for an adversary.
If identity systems, water, power, rail, and emergency radio share networks or vendors, a failure cascades. Default passwords on street hardware are not a theoretical issue; they have been exploited in embarrassing and instructional ways, including tampering with pedestrian-crossing audio. A smart city that is not a cybersecure city is a brittle city.
Centralization makes operations elegant and outages existential. Mercy assumes the municipal cloud is available to the defendant. A real attacker would assume the municipal cloud is available to them.
What Could Stop a Surveillance State?

Practical safeguards are known. The obstacle is rarely imagination. It is will.
Privacy by design and data minimization should be procurement requirements, not slogans. If a traffic model needs counts, it does not need identities. Encryption and on-device processing can keep raw faces from becoming a central gallery. Decentralized storage and purpose-specific databases make fishing expeditions harder. Role-based access, logging, and unexpected-use alerts make browsing a neighbor’s night a detectable offense. Short retention by default forces the state to choose what is worth keeping.
Independent audits should include accuracy by demographic group, false-alert rates, and mission creep. Algorithmic transparency does not require publishing every weight. It does require explaining the data sources, the target variable, and the human fallback. High-stakes actions should need a human who can be cross-examined. Biometric and location searches should need a judicial warrant except in genuine emergencies that are later reviewed. Cities should publish what they bought, what they query, and how often they were wrong.
Statutes need remedies: exclusion of evidence, damages, and career consequences. Citizens should participate before a new sensor network is switched on, not after the contract is signed. Purpose limitation should be literal. Traffic data stays traffic data unless a new, debated law says otherwise.
Technology can blur faces by default, process video at the edge, and delete raw footage after events are extracted. Those choices are design choices, not destiny. A city can buy a camera that forgets. Vendors will sell a camera that remembers if the request for proposal asks for memory.
A Possible Future Scenario

These are scenarios for 2040, not forecasts. They are tools for thinking about combinations, not a calendar.
Scenario A — The Privacy-Protected Smart City
Daily life is convenient. Buses arrive when needed. Outages are rare. Flood and heat warnings are timely. Cameras exist at intersections, tunnels, and stations, but live identification is rare, logged, and legally bounded. Video used for traffic is stripped of identity where possible. Digital identity is selective disclosure: you prove you are old enough or licensed without handing over a life history. Courts still require warrants for retrospective tracking. Companies that sell urban software face audits and cannot quietly resell movement graphs. People protest without expecting a permanent dossier. Journalists can obtain error rates. A wrong match is a scandal, not a shrug. Security is good enough. Freedom is ordinary. The city is smart in the way a well-run hospital is smart: information serves a defined duty.
Scenario B — The Surveillance-Heavy Smart City
After a decade of crime scares, migration politics, and successful efficiency campaigns, fusion is normal. Most journeys are reconstructable if an official asks. Facial recognition is used for “serious crime,” defined more broadly each year. Insurance, employers, landlords, and platforms buy movement and association data. Municipal apps are hard to avoid. Few people are formally punished for speech, but many decline to attend rallies. Young people assume that anything done outdoors is on file. The city is safe, smooth, and slightly exhausting. Residents praise the buses and joke, uneasily, about the cameras. The joke is a form of consent.
Scenario C — The Total Surveillance State
Almost every public space is identifiable in real time. Digital identity is required for transit, work, clinics, and many buildings. Scores affect access to travel, credit, and public services. Automated restrictions replace some hearings. Opposition is not only illegal; it is logistically difficult. Organizing requires devices that leave trails. Daily life is orderly. Individual freedom is residual. Errors are difficult to correct because the system is the record of what happened. This is the neighborhood of Mercy, even if the execution chair is replaced by quieter forms of exclusion: you simply cannot move, work, or be believed.
Which scenario appears depends less on camera resolution than on who can say no, how expensive it is to join databases, and whether fear remains the master justification.
Key Question: Are We Heading Toward Mercy?

Some building blocks of a surveillance society already exist: cameras, biometrics, phones, clouds, commercial data markets, and models that interpret them. A true total-surveillance state needs more.
It needs connectivity that leaves few dark spaces. It needs institutions willing to pool data across agencies and companies. It needs legal permission or legal collapse. It needs political incentives—fear of crime, fear of disorder, fear of the outsider—that make the public accept the bargain. It needs weak courts or captured oversight. It needs a culture in which being watched feels like being protected.
Technology plus data plus AI plus connectivity plus institutional power plus legal framework plus political incentives: that is the real formula. Remove any term and the outcome changes. Excellent cameras in a jurisdiction with warrants, retention limits, and a combative press are not Mercy. Mediocre cameras in a jurisdiction with no appeal and a politicized police can be worse than the film in human terms, even if they are less cinematic.
We are closer to the film’s infrastructure than to its court. That should not comfort anyone who cares about reversible decisions and unwatched rooms. It should also restrain panic. Cities can choose Scenario A. Many of the tools that make Scenario C possible are the same tools that make a bus run on time and an ambulance find a stroke patient.
The film’s ninety-minute clock is a dramatist’s device. Real erosion is slower. It looks like a procurement, then a pilot, then a crisis exception, then a permanent program, then a new data-sharing memorandum. By the time the chair appears, if it ever does, the cloud is already there.

The decisive issue is not whether cities become smart. They will. Sensors are useful. Traffic engineering is not tyranny. Finding a missing child is not tyranny. The decisive issues are who controls the city’s intelligence, what is collected, how long it is kept, who may combine it, whether the subject can see and contest it, and what rights remain when the model is wrong.
Mercy is a fable about a cloud that judges. Real cities are assembling clouds that manage. The distance between manage and judge is a legal and moral distance. It can be crossed slowly, by creep, without anyone filming an execution. It can also be defended, statute by statute, audit by audit, warrant by warrant.
A smart city is a concentration of knowledge about people in motion. Knowledge is power only if someone is allowed to use it without limit. The task of a free society is not to smash the sensors. It is to keep knowledge in its proper office: limited, reviewable, and subordinate to rights that do not depend on a probability score.
The real question may not be whether technology can watch us, but whether society will decide that it should—and, if it should in some places and for some purposes, how we will still remain unwatched enough to be free.
![]() | ![]() | ![]() |
![]() | ![]() | ![]() |





