The Right to Protest in the Age of Artificial Intelligence: Predictive Policing, Facial Recognition, and Democratic Freedoms

The Right To Protest In The Age Of Artificial Intelligence: Predictive Policing, Facial Recognition, And Democratic Freedoms

Abstract

This article critically examines the constitutional implications of the growing deployment of Artificial Intelligence-driven surveillance technologies, particularly facial recognition technology and predictive policing, during public protests in India. Taking the 2026 Jantar Mantar student protests and the ensuing constitutional litigation as its point of departure, the article analyses the intersection of the right to peaceful assembly under Articles 19(1)(a) and 19(1)(b), the right to privacy under Article 21 as recognised in Justice K.S. Puttaswamy v. Union of India, and the existing regulatory vacuum governing biometric surveillance. It argues that indiscriminate AI-enabled monitoring transforms surveillance into a precondition for exercising democratic freedoms, thereby creating a chilling effect on political participation. Drawing upon Indian constitutional jurisprudence, comparative developments in the European Union, and contemporary debates on algorithmic governance, the article advocates for a comprehensive statutory framework that reconciles legitimate public order objectives with constitutional guarantees of privacy, dignity, and democratic dissent.


A Camera Is Watching, And It Knows Your Name

In July 2026, thousands of students converged at Jantar Mantar in New Delhi under the banner of the “Cockroach Janata Party” to demand accountability for the recurring paper leak incidents in NEET-UG exams. The protest achieved immediate political success: within days, the Union Education Minister resigned. It also left behind a more muted controversy, however. AI-powered facial recognition technology, drones, a mobile command and control vehicle, and even smart glasses that can scan humans using biometrics were reportedly being used to track the crowd in Delhi. Two Constitutional challenges that followed shortly were one filed by the student activist Aishe Ghosh in the Delhi High Court using the PIL mechanism and the other brought by Rajya Sabha MP A.A. Rahim directly before the Supreme Court under Article 32 as A.A. Rahim, M.P. vs. the Union of India.

The episode brings to the fore the question that Indian law has yet to answer clearly: can the same technology which can help solve crimes also, without a law, be used to identify and track freely everyone who steps out to protest? The right to assemble peaceably – one of the oldest freedoms of the Indian Constitution – may be reduced to a right that is exercised only in the presence of an unaccountable algorithm.

This is not a purely theoretical concern; as of mid-2026, it is the subject of live litigation.  It is at the crossroads of three distinct, but interconnected, legal issues: the right to protest, the right to privacy, and the absence of dedicated legislation governing facial recognition and predictive policing in India.

The Legal Architecture And Its Missing Pieces

The right to protest in India is not a standalone right, but it is derived from two provisions of the Constitution, Part III –  Article 19(1)(a) – Freedom of speech and expression and Article 19(1)(b) – Freedom to assemble peaceably and without arms. Both have reasonable restrictions under Article 19(2) and 19(3), respectively, on the basis of issues like public order and sovereignty and integrity of India. Whereas, in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, the nine-judge bench of the Supreme Court read into the right to life and personal liberty (Article 21) the right to privacy, which was restricted only in so far as it was necessary to serve a legitimate state purpose and was proportionate to that purpose.

Facial recognition technology (FRT) and predictive policing sit ill at ease on both sides of the fence. FRT transforms a person’s face, typically obtained without consent or knowledge, into a biometric template that can be compared to a database in real-time. Emergency call data, records of FIRs and geospatial inputs are fed into a predictive policing system developed by the Delhi Police in collaboration with the Indian Space Research Organisation since 2015 to generate maps of “hotspots” and, more recently, information on people or places for proactive surveillance. Others have taken a step further; Hyderabad has developed one of the world’s densest facial recognition networks connected to FIRs and the Automated Facial Recognition System (AFRS) of the National Crime Records Bureau, planned to be nationwide and would be linked with databases, such as the CCTNS. But — and that’s where the legal issue lies — there is no law in India that regulates police use of facial recognition or predictive policing.

The closest legislative instrument is the Digital Personal Data Protection Act, 2023 (enacted on 11 August 2023), whose operative provisions were substantially brought into force only with the notification of the DPDP Rules, 2025 on 13–14 November 2025. It introduces the concept of ‘data fiduciaries’ and requires them to fulfil duties of consent, purpose limitation and breach notification. However, Section 17(2) of the Act provides for broad exemptions for processing by Government agencies in the ‘interest of the sovereignty and integrity of India’, of security of the State and of public order — exemptions that on their face seem to include almost all police surveillance activities, whether connected to a protest or not. The Facial Recognition Technology (Regulation of Police Powers) Bill, 2023, which was to specify the procedures for using facial recognition technology, has not shown any movement since it was introduced in December 2023 and has languished in the Rajya Sabha.

The outcome is a remarkable lack of regulation: cities across India implement biometric surveillance of public gatherings based on the police’s inherent powers, and municipal or state-level administrative regulations, and there is no Parliamentary order to determine who can deploy it, on what grounds or for what purpose, for how long these data can be kept, or how a citizen whose data has been flagged might seek correction or deletion.

The Central Debate: Surveillance As A Precondition, Not A Consequence Of Protest

The doctrinal problem is that restriction under Articles 19(2)–(3) presupposes some triggering conduct, which is typically an unlawful assembly, threat of imminent breach of public order, or some specific and articulable threat. Facial recognition in a protest turns this around. It does not limit conduct once it is surpassed; it triggers the collection of identifying biometric data about each participant without discrimination, as a precondition for the exercise of the right. Whether or not it happens that the protester does something illegal, he or she is scanned and catalogued.

This is then a live and pending issue of proportionality in the Puttaswamy paradigm, later developed in the Aadhaar case, K.S. Puttaswamy v. Union of India (2019) 1 SCC 1. Is mass, suspicionless surveillance of a peaceful assembly a proportionate restriction on the right to protest, or is it a prior restraint, fancy-clad as a security measure? Another issue is the “chilling effect“— well documented across the world’s largest democracies— in which citizens, especially students, journalists and people from marginalised communities, choose not to attend protests because they are aware they can be identified and that they will be prevented from doing so. A right that requires an individual to be permanently logged in a police database is, in essence, if not in name, a reduced right.

What The Courts Have Actually Said

Indian courts have taken individual pieces of this puzzle so far, without yet connecting them up to create a unified framework for AI-supported protest policing.

In Amit Sahni v. Commissioner of Police, (2020) 10 SCC 439, arising from the anti-CAA sit-in at Shaheen Bagh, the Supreme Court has said that the right to protest is valuable and a constitutional protection, but it can’t be exercised in a way that keeps public space away from others forever and that the right to protest must be balanced with the right to traffic. The decision is important not because it has any particular implications for surveillance, but because it reaffirms that, while robust, the right to protest is not without limits and can be subject to judicial restrictions, the opposite of which could be true with regard to the FRT.

Puttaswamy (2017) continues to be the basis. It is in the very framework of the proportionality test (legality, necessity, and proportionality stricto sensu) that the Delhi High Court and Supreme Court will now have to apply facial recognition at Jantar Mantar. Notably, no executive order or statute authorises FRT deployment at protests with the specificity Puttaswamy would seem to require — the Delhi Police order for Jantar Mantar, for example, stated only that FRT be used to identify known criminals or suspected individuals.

On the issue of internet shutdowns, Anuradha Bhasin v. Union of India, (2020) 3 SCC 637 is instructive only by narrow analogy — it concerned denial of internet access, not surveillance. What transfers is the Court’s requirement that restrictions on Part III freedoms satisfy the “least intrusive means” test and that orders imposing them be published and periodically reviewed, not left to unaccountable discretion. The Delhi Police order authorising FRT at Jantar Mantar, framed only in general terms, reflects exactly this opacity. The same question follows: could police have met their public-order objective through narrower, targeted means, rather than indiscriminate capture of an entire assembly?

Older privacy jurisprudence is relevant here. As early as 1963, the Supreme Court held in Kharak Singh v. State of U.P., AIR 1963 SC 1295, that unauthorised surveillance of a citizen’s movements — there, domiciliary night visits — violated ‘ordered liberty’ under Article 21, a concern Kharak Singh’s reasoning anticipates in the biometric context, even though the majority in that case did not go so far as to recognise a freestanding right to privacy — a step taken only decades later, and expressly, in Puttaswamy (2017)

In essence, the judiciary is being asked to do what Parliament has not: Provide clarity and establish strict parameters around when, how, and on whose authority AIs can be used to monitor public gatherings. The similarities are already being pointed out with justice k.s. puttaswamy (retd.) v. union of india, (2017) 10 scc 1, and a detailed judgment in this case may establish a precedent for algorithmic governance in India, not only in protests, but in predictive policing, biometric databases, and automated decision-making, in general.

While The Lawsuit Has Some Success, It Does Not Resolve All Structural Issues.

Even if the judges were able to win on those pending cases, it would not solve all the problems that there are because the problems here are as much structural as doctrinal.

First, the law-enforcement exception in the DPDP Act is performing a tremendous, largely unchallenged function. With security and public order as an exception to most of the requirements of this Act, police use of facial recognition is, for all intents, practically outside the very Act that was to be the main data protection mechanism in India. Unless Parliament limits it, this exemption will coexist with any judicial rule the courts establish about protest surveillance.

Second, there is a unique and under-discussed issue with predictive policing systems such as CMAPS: algorithmic feedback loops. However, scholars studying CMAPS have noted that the system’s predictions are based on the history of policing, meaning that places and communities that were already over-policed do provide the system with more “hits,” and that leads to further policing in those communities — and the perpetuation of discrimination without anyone making an explicit choice to discriminate. It’s more difficult for courts to deal with on a case-by-case basis because the discrimination is not concrete, but is based on a number of officers’ statistical discrimination.

Thirdly, it is instructive to compare India’s position. As of February 2025, facial recognition in real-time by law enforcement in public areas is generally prohibited by law in the European Union, with exceptions that are narrow and exhaustively defined: (i) the targeted search for victims of abduction, trafficking, or sexual exploitation, and for missing persons; (ii) the prevention of a specific, substantial and imminent threat to life or physical safety, including a terrorist attack; and (iii) the identification of a suspect in a serious offence carrying a custodial sentence of at least four years. The law for live biometric identification in Sweden, which was passed in 2026, also requires independent oversight and prosecutorial authorisation. India doesn’t have one in its class. For now, not only is it a hole that will be filled at some point in the future, it is a hole that the legality of a particular FRT deployment depends upon ad hoc administrative decision-making, and more recently on litigation outcomes.

Why This Cannot Wait

This is not a hypothetical or future discussion; this is reality. At the moment, there are two constitutional challenges pending in Indian courts on this exact issue, and their verdicts will have a bearing on surveillance laws beyond protests, impacting predictive policing, biometric ID systems, and administrative decisions based on AI in general. The DPDP Rules 2025 have recently been brought into effect and are in transition until 13 May 2027, so the compliance picture for data fiduciaries – such as arguably the police – remains to be worked out. The deployment, meanwhile, continues to grow, with the Union Home Minister kick-starting a deployment phase to Delhi’s surveillance network, including facial recognition, in February 2026 – though the constitutionality of its use at protests is still under consideration.

A democracy values both public order and freedom of dissent, and the risks of failing to strike the right balance are no abstract. If the citizen decides that coming to a protest requires being biometrically captured, cross-referenced and Possibly retained indefinitely in a police database, with the attendant risk of triggering further police action, he or she may just decide not to come to a protest — and the chilling effect of that leaves no fingerprints, no FIR and, often, no evidence to be reviewed by a court after the event.

Closing Remarks: A Right Worth Defending, Deliberately

The right to protest, though nowhere named as such in the constitutional text — and as discussed above, judicially derived from Articles 19(1)(a) and 19(1)(b) — has nonetheless been treated by the Court as a right, not because it is comfortable for the powerful but because it is necessary to a good democracy, where the weak find a voice without having to wait for elections. AI has not introduced a new constitutional right to privacy or a new constitutional risk of privacy; it has merely given an old privacy risk, unaccountable surveillance, a new face, one that is cheaper, faster and more complete than ever before.

The impending case provides the courts in India a real chance to strike a balance that Parliament for now has failed to do: to hold the line between legitimate security measures and the subtler creep of the right to dissent anonymously among a mob of people. It is yet unclear whether that line will be struck by the judiciary, following the Puttaswamy reasoning, or by a dedicated statute in the future, as other democracies have already adopted, which would regulate facial recognition and predictive policing. There is no doubt that the question must be answered now. When citizens next enter a public space to carry a placard, the law must already have determined who they are: a citizen of the democratic community or simply a point in a database.

So, should facial recognition ever be allowed in a peaceful protest, even if authorised by a judge, or does the capture of biometric data make it impossible to dissent in the first place?


Author

  • Ayush Soni

    Piyush Soni is a law student at Symbiosis Law School, Nagpur, with academic interests in ADR, technology law, artificial intelligence governance, cyber law, and anti-trust law. His research focuses on the intersection of emerging technologies and fundamental rights, particularly issues relating to privacy, digital governance, and democratic accountability.

    View all posts

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *