The Case the Van Makes for Itself
Since June 2026, a single marked police van equipped with NEC's NeoFace live facial recognition system has cycled through public spaces in Perth and Fremantle, matching the faces of passersby in real time against a roughly 4,000-name watchlist of wanted people, reportable offenders, missing persons, and individuals subject to lawful exclusion orders. In its first week alone, the system scanned more than 130,000 faces, generated 33 alerts, and led to 18 arrests, with one confirmed false match, according to figures WA Police gave the ABC. Police say faces that don't match the watchlist are pixelated in real time and not retained.
That case deserves a fair hearing before it gets dismantled. Manually cross-referencing 130,000 faces a week against a wanted list is not something any police force could do at that scale without automation, and a tool that surfaces missing persons or reportable offenders in a crowd faster than a human ever could is a genuine public-safety capability, not a gimmick. Critics of live facial recognition should concede that point rather than pretend the technology has no legitimate use case.
No Regulator in the Room
What undermines WA Police's case is not the technology but how it was rolled out. The state's Office of the Information Commissioner (OIC WA) — the body created specifically to oversee government handling of personal information — says it was not invited to take part in formal consultation on the trial's design, and that when police later offered it a demonstration, it declined, judging that attending could look like an endorsement of a trial it was supposed to independently scrutinise. In its public statement, the OIC WA said it "welcomes the work WA Police has done to date" but flagged unresolved concerns about mass collection of personal information, collective privacy, scope creep, data quality, automated decision-making, and the adequacy of the privacy impact assessment (PIA) itself.
That PIA has drawn criticism beyond the regulator. Malcolm Crompton, a former federal privacy commissioner, described it as "feather-light" for a deployment of this scale. Reporting on the document found it denied the trial would "primarily or especially affect Aboriginal people" — a finding that let WA Police skip the Aboriginal Information Assessment ordinarily required for projects with disproportionate impact on Indigenous communities, despite Western Australia's high rate of Aboriginal incarceration and reporting that facial recognition systems generally perform worse on darker-skinned faces. Peter Collins, legal services director at the Aboriginal Legal Service of WA, called the consultation his organisation received — roughly 20 minutes' notice before launch — "an exercise in tokenism." WA Police disputes that deployment locations were chosen on demographic grounds, saying siting was based on "policing needs and policing objectives."
A Law That Wasn't Law Yet
The deeper problem is timing. Western Australia's Privacy and Responsible Information Sharing Act 2024 (PRIS Act) — the state's first-ever statute governing how government agencies handle personal information, including the 11 Information Privacy Principles that would bind WA Police's use of biometric data — received royal assent in December 2024, but its substantive privacy provisions did not commence until 1 July 2026, per the WA government's own account of the rollout timeline. The live facial recognition trial began the previous month. For several weeks, WA Police scanned six-figure numbers of faces under a regime where the state law meant to govern exactly this kind of mass biometric collection was not yet in force.
Nor did federal oversight fill the gap. The Office of the Australian Information Commissioner (OAIC) has published detailed guidance on facial recognition privacy risks — covering accuracy and bias, lawful basis for collection, transparency, and data security — but that guidance is explicitly scoped to "a physical commercial or retail setting," not state policing, which sits outside the Commonwealth Privacy Act 1988's reach entirely. Put together: for the trial's opening weeks, no privacy regulator in Australia, state or federal, had binding authority over a live biometric surveillance program scanning tens of thousands of members of the public a week.
Sequence the Guardrails, Don't Scrap the Tool
The fix here isn't a ban — it's sequencing. A tool that produced 18 arrests from three dozen alerts in a week, with a low reported false-match rate, has demonstrated enough value to justify continued, better-governed use. But "better-governed" has a specific, achievable meaning: don't launch a live biometric surveillance trial before the privacy statute meant to bind it has commenced; give the state's own privacy regulator a real seat at the design table, not a courtesy briefing; publish bias-testing results, including on First Nations subjects, rather than declining to confirm whether that testing happened at all; and require an independent evaluator with published success criteria before any trial converts into a permanent program. Other jurisdictions moving toward legislating live facial recognition, including the EU's AI Act, have converged on narrow, judicially authorised triggers for real-time biometric identification by police rather than an open-ended alert list. WA Police doesn't need to match that model exactly, but it needs one that exists before the van goes back on the road, not after the reporting is written.