
Surveillance society 2026 — utopia or dystopia, which are we closer to?
Contents
Surveillance society 2026 — utopia or dystopia, which are we closer to?
The future shaped by AI and facial recognition forks in two directions. On one side is a utopia that protects privacy while maximizing social benefit; on the other, a dystopia in which everyday life is reduced wholesale to data. Looking evenly at the three axes of technology, regulation, and national models as of 2026, the conclusion is clear: neither is inevitable, and everything depends on how governance is designed.
Why this topic now
In February 2025, the EU AI Act's prohibited-practices provisions took effect, banning in principle real-time facial recognition in public places for law enforcement purposes. In August 2026, more substantial rules are due to apply, including police use of facial recognition, limits on employment AI, and biometric identification requirements. In the same period, officially documented wrongful arrests in the US caused by facial recognition misidentification rose to more than nine, and China issued new standardization guidelines for its social credit system in March 2025.
Korea is no exception. Incheon Airport's Smart Pass expanded in 2025 to all 158 boarding gates in Terminals 1 and 2, and the number of CCTV cameras nationwide reached about 19.6 million as of the end of 2022. With the AI Basic Act coming into force, it is the moment for a full public debate on how far facial and biometric data may be used.
This article lays out with equal weight the two possible futures mixed into the single term 'surveillance society', utopia and dystopia, and organizes the data and cases that support each.
Key data and current state
- Global facial recognition market size (2026): About USD 9–10 billion (estimates by major firms including Precedence Research, Mordor Intelligence, and MarketsandMarkets, as of January 2026 / wide variance between firms)
- Long-term outlook: A market of more than USD 20 billion by 2031 and more than USD 36 billion by 2035 is possible (Precedence Research, Mordor Intelligence, 2026)
- Share by application: Security and surveillance is the largest at 38.4% (Coherent Market Insights, 2025)
- Korea's CCTV infrastructure: About 19.6 million nationwide, about 1.61 million in the public sector (Personal Information Protection Commission, as of end-2022)
- Wrongful facial recognition arrests in the US: More than 9 officially documented, more than 12 by the ACLU's count (Federation of American Scientists, March 2026 / ACLU, April 2026)
- Phased entry into force of the EU AI Act: Prohibited practices in force from February 2025, substantive rules such as police facial recognition from August 2026, obligations for AI embedded in products from August 2027 (European Commission, 2026)
? Interpretation: The market is growing fast and the infrastructure is already in place. The variable is not the technology but who may use it, how far, and under what procedures . The answer to this question separates utopia from dystopia.
In-depth analysis
The utopian scenario — three pillars holding up the possibility
First, privacy-enhancing AI technologies (PETs) have entered the practical stage. Federated learning exchanges only model updates without gathering raw data in one place, enabling collaboration across data silos in healthcare, finance, and IoT. Differential privacy limits the possibility of identifying individuals by adding mathematically defined noise to data, a proven technique that Apple and Google already apply to OS and keyboard learning. Homomorphic encryption and secure multi-party computation (SMPC) are also beginning to be adopted in collaborative research by medical regulators (Frontiers in Drug Safety and Regulation, 2025).
The meaning of this technology stack is simple: the premise that 'AI gets stronger only by collecting more data' is no longer absolute.
Second, the EU AI Act has begun to serve as the global regulatory baseline. Just as the GDPR became the de facto global standard for data protection, the AI Act is likely to follow the same path. Building databases by indiscriminately scraping facial images from the internet and CCTV, emotion recognition in workplaces and educational institutions, and biometric categorization that infers protected characteristics are already illegal in the EU market.
Third, there are areas that deliver clear benefits to citizens. Incheon Airport's Smart Pass, introduced in July 2023, expanded in 2025 to all 158 boarding gates and operates across 11 airlines (Kyunghyang Shinmun, September 2025). In healthcare, diagnostic models based on multi-institution federated learning have entered practical use in radiology and rare diseases. In areas that even the EU AI Act recognizes as exceptions, such as searching for missing persons or responding to imminent terrorist threats, biometric identification creates clear social value.
Analysis: The core of the utopian scenario is not 'a society without surveillance' but 'a society that has reached social agreement on where surveillance is and is not permitted'. The decisive change is that technology can now enforce that agreement technically.
The dystopian scenario — warnings that have come true
First, facial recognition misidentification is leading to actual detentions. As of March 2026, there are at least nine officially documented wrongful arrests from facial recognition in the US (Federation of American Scientists). Robert Williams of Detroit was arrested in front of his children, wife, and neighbors and held for 30 hours, and Porcha Woodruff, eight months pregnant, was detained for 11 hours on carjacking charges even though the suspect in the footage was not pregnant. A grandmother in Tennessee was arrested on North Dakota bank fraud charges while caring for four children and jailed for about six months.
According to an investigation the Washington Post published in January 2025, 15 police departments in 12 states ignored their own guidelines and made arrests based on facial recognition results alone, with many cases confirmed in which contradictory evidence such as alibis or DNA was disregarded. By NIST's evaluations, facial recognition systems show significantly higher misidentification rates for Black people, women, teenagers, and the elderly.
Second, integrated data infrastructure is taking root as an authoritarian model. Western media portrayals of China's social credit system as a 'single citizen score' have been judged inaccurate in numerous recent (2025) analyses (Newsweek, November 2025 / Asia Society). In reality it is closer to a patchwork of administrative databases and industry-specific blacklists. But the real danger lies elsewhere.
New guidelines issued on March 31, 2025 by the Central Committee of the Chinese Communist Party and the State Council formalized inter-ministry data sharing that flags tax, labor, environmental, and customs violations on a single dashboard, and explicitly included foreign-invested enterprises (China-Briefing, May 2025). Concerns have been raised that such standardized, integrated data infrastructure could become a package exportable to other authoritarian states (Eurasia Review, May 2025).
Third, the 'chilling effect' constrains the actual exercise of rights. The EU AI Act guidelines and recommendations themselves warn explicitly that remote biometric identification systems in public places create risks to rights and freedoms by their mere existence (Future of Privacy Forum, April 2026). When citizens perceive that they 'may be under surveillance anywhere', self-censorship arises in the exercise of public freedoms such as expression and assembly.
Regulation is not perfect either. Even the EU AI Act bans real-time remote biometric identification, but retrospective facial recognition is merely classified as a high-risk system, not banned (State of Surveillance, March 2026). Recording a protest and then, days later, matching every face against a database is legal if it passes judicial approval.
Analysis: The essence of the dystopia is not a technical defect but a governance failure. Operations that use technology with known flaws without verification procedures, regulations whose exceptions erode the main rule, and policies that lay infrastructure before any public debate all point in the same direction.
The fork between the two scenarios
The same facial recognition technology ends up on one side as the convenience of shorter airport transit, and on the other as the 11-hour detention of a pregnant woman. What makes the difference is not the technical specification but the following four things.
First, whether clear red lines exist. The EU has written into law absolutely prohibited areas such as indiscriminate scraping, workplace emotion recognition, and real-time public biometric identification. In the US, legislation varies by state and only 15 states have partial legislation (Stateline, February 2025).
Second, the binding force of after-the-fact verification procedures. What is decisive is whether the procedural requirement that no arrest may be made on a facial recognition result alone is enforced, and whether judicial approval is more than a formality.
Third, citizens' right to know and right to refuse. Whether notice of camera operation in public places, stated retention periods, and citizens' ability to exercise control over their own data are guaranteed. In Korea's case, the share of public CCTV footage retained for 30 days or less is 86.7%, relatively short (Personal Information Protection Commission).
Fourth, whether PETs are mandated. Whether federated learning, which exchanges only models instead of collecting data, and differential privacy, which adds noise, are adopted as mandatory standards will be a key variable in future regulation.
Implications for Korea
Korea sits midway between the two scenarios. In terms of infrastructure alone, its CCTV density per capita is among the highest in the world, and the pace of biometric authentication adoption, including Incheon Airport's Smart Pass, is fast. At the same time, the Personal Information Protection Commission has independent authority, and Korea received a GDPR adequacy decision (2021), so a data governance infrastructure aligned with EU standards is already in place.
The problem is that two tendencies can collide. First, a pattern is repeatedly observed in which infrastructure is laid before public debate under the 'safety' frame. When a violent crime occurs, local governments rapidly adopt AI-based intelligent selective monitoring systems (Boan News, 2023). Second, whether the subordinate decrees and notices of the AI Basic Act, in force since 2025, will draw clear red lines on real-time biometric identification and emotion recognition has not yet been decided.
User reviews of Incheon Airport's Smart Pass reveal both sides at once. On one side, 'the hands-free liberation of not having to keep pulling out your passport and phone' draws praise; on the other, civic unease that 'sensitive facial biometric data is kept for as long as five years' is expressed in everyday language. Korea's balance point will be built on this texture of daily life.
Outlook and variables to watch
- Positive variables: The full application of the EU AI Act in August 2026 could accelerate the formation of a global standard. As a country with an EU adequacy decision, Korea has a policy incentive to adopt aligned regulation.
- Risk variables: The spread of 'areas even the EU AI Act failed to stop' (such as retrospective facial recognition) through regulatory circumvention and expanded exceptions. Export of China-style integrated data infrastructure to authoritarian states.
- Checkpoints: What incidents and rulings emerge when the EU AI Act fully applies in August 2026, how biometric data guidelines are arranged in the subordinate rules of Korea's AI Basic Act, and whether US state facial recognition legislation expands beyond 15 states are the key indicators for the next one to two years.
Conclusion
Three things the reader should take from this article.
First, the surveillance society debate of 2026 is not about 'whether to surveil' but about 'what kind of surveillance, under what procedures, controlled by whom'. If this question itself disappears, we tilt toward dystopia.
Second, the utopian scenario is technically possible. PETs and the EU AI Act model show that 'reconciling data use and protection' is not an abstract slogan but at the practical stage. It will not, however, materialize automatically.
Third, Korea's position is not yet decided. The infrastructure is in place and the legal system is aligned, but the inertia of the 'safety' frame and the lack of public debate are variables. 2026–2027 will be the turning point for drawing Korea's balance point.
--
? Facial recognition market size and outlook
- Precedence Research, Facial Recognition Market (2026.01) — https://www.precedenceresearch.com/facial-recognition-market
- Mordor Intelligence, Facial Recognition Market Size, Trends, Growth & Share Analysis 2026-2031 (2026.01) — https://www.mordorintelligence.com/industry-reports/facial-recognition-market
- MarketsandMarkets, Facial Recognition Market Report 2026-2031 — https://www.marketsandmarkets.com/Market-Reports/facial-recognition-market-995.html
- Fortune Business Insights, Facial Recognition Market Size, Share | Growth Report [2034] — https://www.fortunebusinessinsights.com/industry-reports/facial-recognition-market-101061
- Coherent Market Insights, Facial Recognition Market Size and Trends Forecast – 2026 — https://www.coherentmarketinsights.com/industry-reports/facial-recognition-market
- Statista, Facial Recognition - Worldwide — https://www.statista.com/outlook/tmo/artificial-intelligence/computer-vision/facial-recognition/worldwide
Market size estimates vary widely by firm, in the range of USD 7–10 billion (2026). That is why the text cites a range.
? EU AI Act and regulation
- European Commission, AI Act — https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- artificialintelligenceact.eu, Article 5: Prohibited AI Practices — https://artificialintelligenceact.eu/article/5/
- Future of Privacy Forum, Red Lines under the EU AI Act: Restricting Real-time Remote Biometric Identification Systems (2026.04) — https://fpf.org/blog/red-lines-under-the-eu-ai-act-restricting-real-time-remote-biometric-identification-systems-for-law-enforcement-purposes/
- State of Surveillance, The EU AI Act Takes Full Effect in August. Here's What It Actually Bans (2026.03) — https://stateofsurveillance.org/news/eu-ai-act-august-2026-biometric-surveillance-explainer/
- Quinn Emanuel, Initial Prohibitions Under EU AI Act Take Effect (2025.07) — https://www.quinnemanuel.com/the-firm/publications/initial-prohibitions-under-eu-ai-act-take-effect/
?? Facial recognition misidentification and wrongful arrests
- ACLU, More than a Dozen Wrongful Arrests Due to Police Reliance on Facial Recognition Technology (2026.04) — https://www.aclu.org/news/privacy-technology/more-than-a-dozen-wrongful-arrests-due-to-police-reliance-on-facial-recognition-technology
- Federation of American Scientists, Face Recognition Performance, Bias, and the Limits of Technical Fixes (updated 2026.03) — https://fas.org/publication/face-recognition-bias/
- Washington Post, Arrested by AI: Police ignore standards after facial recognition matches (2025.01) — https://www.washingtonpost.com/business/interactive/2025/police-artificial-intelligence-facial-recognition/
- Stateline, Facial recognition in policing is getting state-by-state guardrails (2025.02) — https://stateline.org/2025/02/04/facial-recognition-in-policing-is-getting-state-by-state-guardrails/
- ACLU, Williams v. City of Detroit — https://www.aclu.org/cases/williams-v-city-of-detroit-face-recognition-false-arrest
?? China's social credit system
- Newsweek, How China is changing its social credit system (2025.11) — https://www.newsweek.com/how-china-changing-its-social-credit-system-11079499
- China-Briefing, China's Social Credit System Raises Stakes for Dishonest Businesses (2025.05) — https://www.china-briefing.com/news/china-social-credit-system-dishonest-consequences-2025/
- Remote People, China Social Credit System Explained – How It Works [2026] — https://remotepeople.com/blog/china-social-credit-system-explained/
?? Korean infrastructure and policy
- Personal Information Protection Commission, Guide to the Installation and Operation of Fixed Video Information Processing Devices (combined public and private edition) (2024.12)
- Korean National Indicator System, Public institution CCTV installation and operation data — https://www.index.go.kr/unity/potal/main/EachDtlPageDetail.do?idx_cd=2855
- Boan News, A close look at the CCTV installation and operation changes in the Personal Information Protection Act amendment — https://m.boannews.com/html/detail.html?idx=119608
- Kyunghyang Shinmun, Facial recognition 'Smart Pass' expanded to all Incheon Airport boarding gates (2025.09) — https://www.khan.co.kr/article/202509232004015
- Nongmin Shinmun, Pass through without passport or boarding pass… Incheon Airport's 'Smart Pass' fully expanded (2025) — https://www.nongmin.com/article/20250902500425
- Incheon International Airport Corporation, Smart Pass guide — https://www.airport.kr/ap_ko/889/subview.do
? Privacy-enhancing AI technologies (PETs)
- arXiv, Federated Learning: A Survey on Privacy-Preserving Collaborative Intelligence (2025.06) — https://arxiv.org/html/2504.17703v3
- Frontiers in Drug Safety and Regulation, Federated learning: a privacy-preserving approach to data-centric regulatory cooperation (2025.04) — https://www.frontiersin.org/journals/drug-safety-and-regulation/articles/10.3389/fdsfr.2025.1579922/full
This series is the four-part 'Surveillance Society: Utopia/Dystopia'.
Part 1: Surveillance society 2026 — utopia or dystopia, which are we closer to?
Part 2: China's social credit system 2026 — why the real threat is 'integrated data infrastructure', not a single score
Part 3: Korea's digital trust society — from Incheon Airport's Smart Pass to the AI Basic Act
Part 4: The EU AI Act in August 2026, what really changes — the boundary between real-time and retrospective facial recognition
Contents
Related posts

The EU AI Act in August 2026, what really changes — the real-time/retrospective facial recognition boundary and the shock of the 'Digital Omnibus'
August 2, 2026 has been billed for more than a year as the EU AI Act's most important date. But in November 2025 the European Commission unveiled its 'Digital Omnibus' package proposing to delay high-risk AI obligations by up to 16 months, and on May 7, 2026 the European Parliament and Council reached a provisional agreement. The result is more than a schedule change. The ban on real-time facial recognition survived, but retrospective facial recognition and workplace and education AI obligations are pushed beyond December 2027. Here is how the 'world's first AI regulation' wobbled, and what remained intact.

AI and the future of human relationships and mental health
A clinical trial found an AI chatbot cut depressive symptoms nearly in half, while a study found that the more people rely on AI friends, the lonelier they get, and both landed at the same time. Whether AI becomes a treatment for the mind or a substitute for relationships that deepens isolation: we are at that fork now.

The AI data center power problem — 'electricity hog' or engine of the green transition? (2026 Utopia vs. Dystopia ⑥)
The GPU drought is over, and the contest is now decided by power. In 2026, the approval rate for data center grid connections in Korea's capital region fell to 1.9%, and in the US a $130 billion project was canceled 'for lack of power'. Is AI devouring the climate, or bringing the energy transition forward? This installment examines both faces with data.

Google I/O 2026 recap — the Gemini 3.5 era and Google's 'agent full-stack' blueprint
Google I/O 2026, held on May 19 (local time) at the Shoreline Amphitheatre in Mountain View, came down to one message: 'from assistant to agent'. From Gemini 3.5 Flash, Spark, and Antigravity 2.0 to Android XR glasses and the overhaul of Search, here is a one-stop summary of the message Google delivered as a full-stack AI company.