Who watches the AI watching your street?
Yusaku Fujii, a professor at Gunma University in Japan, has designed audits and penalties to stop operators from misusing AI that analyzes street camera footage. His system adds an independent record-keeper and unannounced spot checks to the AI’s outputs.

Fujii’s test setting is what he calls a Fully Monitored Public Space (FMPS): streets where cameras are dense enough to follow people and vehicles continuously. It can be built with existing network cameras and encrypted storage. For residents of such a street, the open question is where the AI’s conclusions go afterward and who checks.
The Recorder reads labels, not footage
Fujii’s answer is the Verifiable Record of AI Output, or VRAIO. Each municipality runs its own AI systems behind an outbound firewall managed by an independent third party called the Recorder. Before any output leaves, the operator declares which cameras, what time range and what purpose. The Recorder checks that declaration against the legal Rules and writes its decision to a tamper-resistant ledger. It holds no decryption keys and has no access to the content.
That leaves a gap. The Recorder can check that a declaration fits the Rules, but it has no way to tell whether the declaration is true. Take his example: an operator says it needs footage to find a missing child, then uses it for something else entirely. The Recorder waves it through, because the label looks fine. Only an unannounced audit catches the lie, by setting the recorded declaration next to what was actually released. The ledger then points to the request and the operator behind it, who can face administrative penalties, criminal liability and public disclosure of the violation.
Deterrence depends on how often audits happen and how heavy the penalties are. “I do not think there is one minimum audit frequency or sanction level for every case,” he told Help Net Security. “The combination should be strong enough to remove the incentive for misuse.”
He described the test in terms of incentives. “In simple terms, the expected cost of being caught and sanctioned should be greater than the expected benefit of misuse. The appropriate levels should be adjusted based on actual experience.”
Bypassing the firewall leaves no record, so catching it depends on conventional security. The Recorder could be captured by the operators it oversees. And VRAIO does not judge whether the Rules are fair: if a city adopts discriminatory Rules, the system may enforce them faithfully.
He named no existing institution for the Recorder’s job. “I imagine the Independent Recorder could be operated by a judicial institution, or by an independent body between the administrative and judicial systems,” Fujii said. “The important point is that it must be independent from the organization operating FMPS and should be overseen by multiple parties.”
Approval can hide avoidance
Even if the records hold, a second question remains: do people accept being tracked? Fujii counts acceptance only when three things are true. People say they accept it, their reason is no harm experienced or a benefit received, and they show no change in routes, information seeking, expression or participation in assemblies. Someone who says yes because there is no way to avoid the cameras is resigned.
An earlier experiment of his comes close to the mildest version of this. It put 11 cameras on streetlight poles, with notice sent to all 2,218 households in the area. Residents gave positive opinions, but the experiment did not measure whether their behavior changed. Positive opinions are exactly what his own criteria treat as insufficient.
To measure behavior, Fujii said, “I would use anonymous surveys of citizens.” He expects little avoidance. “I do not expect FMPS to cause much avoidance if information use is properly controlled, but this should be tested.” He also wants the opposite effect counted. “We should also measure the opposite effect: whether people feel safer and use public spaces more freely. This may be especially important for children and other vulnerable people.”
His plan has three stages. The first covers locating a missing child and consent-based child safeguarding. The second uses AI in streetlights to flag crimes or accidents. The third has a central AI learn behavior patterns from past crimes and flag pedestrians who resemble them. He calls that last stage a stress test and wants it tried first in vignette studies and simulations. Stopping criteria set in advance include a substantial rise in chilling effects, unacceptable false detections and a marked rise in complaints or withdrawals. The stages change several factors at once, so a comparison shows where acceptance stops holding, not which factor broke it.
Fujii has not yet discussed the proposal with regulators or municipalities. “I believe this institutional design should be developed and tested through a small-scale demonstration project,” he said.