Australians are being scanned by artificial intelligence at a scale that is only now becoming visible, and privacy advocates say the law has been left standing still. A facial recognition trial has captured the faces of more than 130,000 people in a single week, according to a report by 7News, prompting a fresh round of warnings that the technology is spreading faster than the rules meant to govern it.
The number is the sort of figure that tends to focus attention. In seven days, a single deployment gathered biometric data from a crowd larger than the population of Darwin, and most of those people would have had no idea it was happening. That, in essence, is the concern at the heart of the debate. Facial recognition does not require you to hand over a card, tap a phone or sign a form. It works passively, at a distance, on anyone who happens to walk past a camera, and it converts a human face into a mathematical template that can be stored, matched and shared.
How the technology moved from novelty to normal
Facial recognition has crept into Australian life over several years without much in the way of public debate. It sits inside airport SmartGates, it has been trialled in stadiums and shopping centres, and it underpins age-assurance experiments now being run as part of the social media age restrictions. What has changed recently is the quality and cheapness of the underlying AI. Systems that once struggled with poor lighting or side-on faces are now accurate enough to run continuously, in real time, across busy public spaces.
The commercial pull is obvious. Retailers see facial recognition as a tool against theft and aggression toward staff. Venues see it as a way to speed up entry and spot banned patrons. Governments see it as a means of verifying identity and enforcing rules at scale. Each individual use can be argued on its merits. The worry, for many experts, is the aggregate: a patchwork of separate systems that together amount to something close to routine tracking of the population, assembled without anyone ever deciding that Australia should go down that road.
Why the experts are alarmed
The core criticism is not that facial recognition can never be useful, but that Australia lacks a dedicated legal framework for biometric surveillance. The country’s main privacy protection remains the Privacy Act 1988, a piece of legislation older than the modern internet. It was written for a world of filing cabinets and mailing lists, not for AI that can identify a face in a crowd. Reforms to the Act have been promised for years and only partially delivered, and biometric data, while classified as sensitive information, is not subject to the kind of specific, upfront controls that civil liberties groups have been calling for.
Critics point to a familiar pattern. Consent is often reduced to a small sign at an entrance that few people read and none can meaningfully refuse without turning around and leaving. There is limited transparency about who runs a given system, how long the data is kept, whether it is matched against watchlists and who those watchlists belong to. And there is the risk of error. Facial recognition has a documented history of performing less accurately on some groups than others, which raises the prospect of people being wrongly flagged, followed or refused service because an algorithm made a mistake they cannot see or contest.
This is not a hypothetical debate in Australia. In late 2024 the Office of the Australian Information Commissioner found that Bunnings had breached privacy law by capturing the faces of hundreds of thousands of customers through in-store facial recognition without adequate consent, a determination the hardware giant has contested. That case made clear that regulators are prepared to act, but it also showed how far the technology had already spread before the law caught up.
The other side of the argument
Supporters of facial recognition make a case that deserves to be heard on its own terms. Retail workers face genuine and rising rates of abuse and violence, and businesses argue they have a duty of care to protect staff that ordinary security measures no longer meet. Law enforcement bodies point to real investigations solved and missing people found through facial matching. Proponents of the age-assurance trials argue that some form of automated verification is now unavoidable if the country is serious about keeping young children off adult platforms.
The industry position tends to be that the answer is better governance, not prohibition: clear rules on retention, independent auditing, accuracy standards and meaningful notice, rather than a blanket ban that would push the technology into less accountable hands. On that narrow point, at least, both camps often agree. The disagreement is about how much surveillance a democratic society should accept as the price of convenience and safety, and who gets to decide.
What it means for Australia
Australia sits at an awkward juncture. It is trying, through the new federal office of AI and a string of policy reviews, to present itself as a country that will adopt artificial intelligence responsibly and build trust as it scales. A facial recognition landscape that expands quietly, one trial at a time, cuts directly against that ambition. Trust is hard to build and easy to lose, and few technologies test public trust as sharply as being watched without knowing it.
There is also a sovereignty dimension. Much of the software and cloud infrastructure behind these systems is supplied by overseas vendors, which means Australians’ biometric templates can end up processed or stored under arrangements that are difficult for regulators to inspect. For a country that has spent the past year debating sovereign AI capability and where its data lives, the idea of the most intimate identifier of all, the human face, flowing through opaque commercial pipelines is uncomfortable.
What happens next
The immediate question is whether the long-promised Privacy Act reforms will finally include specific, enforceable rules for biometric surveillance, rather than leaving the issue to case-by-case regulatory action after the fact. Expect renewed pressure on the Attorney-General’s Department and the information commissioner to move from principles to hard obligations covering consent, retention, accuracy testing and public transparency about where these systems operate.
For now, the 130,000 figure serves as a marker of how quickly the ground has shifted. The technology is here, it is working, and it is scaling. Whether Australia decides to shape that trajectory or simply watch it unfold, as the cameras watch everyone else, is the choice that this trial has forced back into the open.
Sources: 7News.



















































