Paper deep dive
From Democracies to Autocracies: How AI Systems Enable Authoritarianism by Design
Jeba Sania, Marta Ziosi, Fazl Barez
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 96%
Last extracted: 6/20/2026, 9:26:20 AM
Summary
This paper investigates how AI systems enable authoritarian practices across different political regimes, including both autocracies and democracies. By mapping the lifecycles of six specific AI systems (FlockSafety ALPR, LFR Vans, SlimmeCheck, Lavender, IJOP, and Sfera) across ten dimensions—from ideation to current state—the authors identify critical technical and operational features that facilitate authoritarianism. Key enabling features include the centralization of administrative data, regulatory gaps, weak user compliance, and the encoding of protected group traits. The study concludes that AI-enabled authoritarianism is a distributed phenomenon resulting from design and operational choices made by developers, administrators, and users, and can be achieved through both centralized and fragmented system architectures.
Entities (11)
Relation Signals (4)
FlockSafety Automated License Plate Recognition (ALPR) System → deployedin → United States
confidence 100% · We study these systems as deployed respectively in the United States, the United Kingdom, the Netherlands, the State of Israel, the People’s Republic of China, and the Russian Federation.
Integrated Joint Operations Platform (IJOP) → deployedin → China
confidence 100% · We focus on the following AI systems: ... Integrated Joint Operations Platform (IJOP)... We study these systems as deployed respectively in ... the People’s Republic of China...
AI_System → enables → Coercive Capacity
confidence 90% · The paper discusses how AI systems can exacerbate characteristics like Coercive Capacity, Accountability Erosion, etc.
Centralization of administrative data → enables → Authoritarianism
confidence 85% · We find that enabling features include the centralization and co-optation of administrative data for law enforcement and political punishment...
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:AI-enabled authoritarianism is not confined to autocracies. In this paper, we provide greater transparency by investigating and mapping the lifecycles of six AI systems deployed in different political regimes, ranging from the US to China. By drawing on an extensive range of sources (academic publications, investigative research reports, third-party evaluations, media interviews, government procurement notices), we conduct a systematic, qualitative comparison across systems to identify the critical technical and operational features that enable authoritarianism within their respective political contexts. We find that enabling features include the centralization and co-optation of administrative data for law enforcement and political punishment, regulatory gaps that fail to deter misuse, weak user compliance that nullifies human oversight mechanisms, and the encoding of protected group traits that identify members of vulnerable populations. We find that these features are present across systems deployed in autocratic and democratic regimes, albeit in varying configurations. We also find that both centralized and fragmented AI systems can contribute to authoritarianism by exploiting governance gaps: centralized systems directed by executive authorities, particularly within security and military institutions, are often not subjected to formal oversight mechanisms, while fragmented systems diffuse accountability between stakeholders, paving the way for entrenchment. These findings reveal that AI-enabled authoritarianism is distributed, resulting from design and operational choices made by developers, administrators, and users alike. We conclude with recommendations for developers and policymakers to mitigate these risks.
Tags
Links
- Source: https://arxiv.org/abs/2606.17286v1
- Canonical: https://arxiv.org/abs/2606.17286v1
Trouble viewing inline? Open PDF directly →
Full Text
91,057 characters extracted from source content.
Expand or collapse full text
From Democracies to Autocracies: How AI Systems Enable Authoritarianism by Design Jeba Sania Harvard Kennedy School Cambridge, MA, USA jebasania@hks.harvard.edu Marta Ziosi University of Oxford Oxford, UK marta.ziosi@sant.ox.ac.uk Fazl Barez University of Oxford Oxford, UK fazl@robots.ox.ac.uk Abstract AI-enabled authoritarianism is not confined to autocracies. In this paper, we provide greater transparency by investigating and map- ping the lifecycles of six AI systems deployed in different political regimes, ranging from the US to China. By drawing on an exten- sive range of sources (academic publications, investigative research reports, third-party evaluations, media interviews, government pro- curement notices), we conduct a systematic, qualitative comparison across systems to identify the critical technical and operational fea- tures that enable authoritarianism within their respective political contexts. We find that enabling features include the centralization and co-optation of administrative data for law enforcement and political punishment, regulatory gaps that fail to deter misuse, weak user compliance that nullifies human oversight mechanisms, and the encoding of protected group traits that identify members of vul- nerable populations. We find that these features are present across systems deployed in autocratic and democratic regimes, albeit in varying configurations. We also find that both centralized and frag- mented AI systems can contribute to authoritarianism by exploiting governance gaps: centralized systems directed by executive authori- ties, particularly within security and military institutions, are often not subjected to formal oversight mechanisms, while fragmented systems diffuse accountability between stakeholders, paving the way for entrenchment. These findings reveal that AI-enabled authoritarianism is dis- tributed—resulting from design and operational choices made by developers, administrators, and users alike. We conclude with rec- ommendations for developers and policymakers to mitigate these risks. CCS Concepts • Social and professional topics→Governmental regulations; Governmental surveillance;• Security and privacy→Social aspects of security and privacy. Keywords authoritarianism, system lifecycle, surveillance, safeguards 1 Introduction The use of technology by anti-democratic regimes to maintain control is well-documented. Classic examples include Nazi Ger- many’s use of IBM technologies to streamline the logistics of fa- cilitating genocide [17], and the Chinese government’s efforts to control and censor the flow of information on the internet within the country[129]. With the rise of the internet, the phrase "digital authoritarianism" was coined to describe the use of “digital infor- mation technology by authoritarian regimes to surveil, repress, and manipulate domestic and foreign populations”[44, 121, 126, 130]. Artificial intelligence, through its rapid development pace, in- creasing capabilities, and wide adoption and application, expands the scope and negative impact of these technologies. New reports document how AI has been misused to destabilize democracies[34, 125], interfere with elections[34,125,170], and manipulate at scale via misinformation in unforeseen ways globally [34,125,170]. Key risks of AI technologies include highly accurate mass surveil- lance [12], reduced costs of monitoring and repressing dissent [16,42,150], and increased state capacity to manipulate public opinion[56]. Despite this growing concern, systematic understanding of how these technologies are operated remains limited. Existing discus- sions primarily focus on system capabilities[12,54,170] or down- stream impacts[24,70,94,153], rather than how these AI sys- tems are developed, deployed, and operated to advance au- thoritarianism. This paper addresses this gap by shifting the focus from system capability to deployment by 1) investigating which fea- tures of AI systems (e.g model architecture, evaluation framework, launch plan) are key to enabling authoritarianism, and 2) moving beyond model-centric analysis by offering a systematic mapping of the lifecycle of the systems in question. In this paper, we dis- tinguish between authoritarianism as a strict regime classification and authoritarianism as a set of practices that can be facilitated by technology across different political regimes. We focus on the following AI systems: FlockSafety’s Automated License Plate Recognition (ALPR) System, Live Facial Recognition (LFR) Vans, SlimmeCheck, Lavender, Integrated Joint Operations Platform (IJOP), and Sfera. These systems were selected based on confirmation of the presence of AI, system type (e.g surveillance, predictive policing), political deployment context, and availability of public system documentation. We study these systems as de- ployed respectively in the United States, the United Kingdom, the Netherlands, the State of Israel, the People’s Republic of China, and the Russian Federation. Using a qualitative approach, we draw on investigative reporting, technical audits, system evaluations, and official government state- ments, among other sources. Through systematic cross-comparison of these systems across ten lifecycle stages, we identify the tech- nical and contextual features that may enable authoritarianism. We examine whether these features have regime-specific patterns. Our approach emphasizes a socio-technical lens by treating system design and deployment as the primary objects of study. We also recognize that such an analysis inevitably intersects with political science to contextualize how these technical features manifest as arXiv:2606.17286v1 [cs.CY] 15 Jun 2026 Preprint, 2026, OnlineJeba Sania, Marta Ziosi & Fazl Barez authoritarian control. We call for future work, including our own, to engage in deeper interdisciplinary collaboration with experts in the field to enrich the analysis and balance overly technical perspectives. As our main contribution, we provide a set of enabling factors through which system features advance the following character- istics of authoritarianism: expanded coercive capacity, erosion of accountability, symbolic safeguards, information control, antici- patory repression, and boundary control. We also find that while fragmented AI systems can contribute to authoritarianism like centralized systems, fragmented systems evade oversight mecha- nisms precisely due to their decentralized nature. Consequently, fragmented systems represent an underscrutinized mode of au- thoritarian risk. We then discuss the implications of these findings and provide takeaways for developers and policymakers. As this study relies on publicly available data of covert and controversial AI systems, there are inherent information gaps. 2 Literature Review 2.1 Developing A Framework for Understanding Authoritarianism 2.1.1 Defining Authoritarianism. Authoritarianism is commonly defined as a political system with limited political pluralism, com- petition, or accountable executive authority[91,134]. While this literature conceptualizes authoritarianism primarily as a regime type, this study adopts a practice-oriented perspective, focusing on authoritarian mechanisms and practices that may occur both within and beyond formally authoritarian regimes. Authoritarian rulers of- ten minimize constraints on their power while repressing or strate- gically containing meaningful political contestation [22,59,87]. The mechanisms that enable authoritarianism are highly contextual and vary across different regions and time periods [43,89,116,141,155]. Despite contextual variations, scholars have identified recurring features of authoritarianism. This section reviews existing litera- ture to set up a conceptual framework outlining six interrelated characteristics of authoritarian systems. 2.1.2 Foundational Frameworks: Centralization and Control. Foun- dational works emphasize the centralization of power as a defining element of authoritarianism. Early theorists Friedrich and Brzezin- ski demonstrate that high degrees of power centralization occur across different spheres, including information channels and means of force [55]. Multiple scholars emphasize the state’s capacity to centralize means of coercion [36,55,140,165]. Scott’s analysis of state legibility in "Seeing Like a State" provides a foundational account of how states, more generally, have sought to centralize information as a precondition for administrative control[138]. As an example of an extreme form of coercion, Mbembe’s concept of necropolitics explores the state’s power to dictate who may live and who must die, which may entail terminating as well as ignor- ing, neglecting, or surveilling the lives of marginalized groups[96]. Across this literature, coercion is understood not only as violent repression but as a system of threats and intimidation to incentivize certain political outcomes. These works highlight the state’s ability to enforce compliance by monopolizing the use or threat of violence to achieve political goals, rather than democratic means. 2.1.3 The Role of Institutions: From Obstacles to Tools. Another mechanism authoritarian governments employ to centralize power is by undermining institutions, such as the electorate, judiciary, and the media[55]. Linz, in his seminal 1964 "An Authoritarian Regime: The Case of Spain," includes “ill-defined executive powers that routinely surpass democratic limits” as part of his three-part definition of authoritarianism[91]. Overreaching executive powers undermine other forms of institutional authority meant to serve as checks. Various scholars maintain an alternative view: rather than erod- ing institutions, authoritarian regimes strategically employ institu- tions to consolidate power[53,58,148]. Institutions are not obsta- cles, but rather tools to manage the key tension of appeasing ruling elites and repressing citizens[58,148]. According to this view, in- stitutions merely provide symbolic accountability. After synthesiz- ing decades of comparative authoritarianism literature, Frantz and Kendall-Taylor, in their "A Dictator’s Toolkit: Understanding How Co-optation, Repression, and Legitimization Help Autocrats Sur- vive," identify legitimation as a key authoritarian strategy to build positive public perception[53]. Collectively, the existing scholarship suggests that authoritarian rulers counter existing accountability mechanisms, either directly or indirectly. 2.1.4 Enduring Authoritarianism: Subtle Manipulation Over Overt Repression. Contemporary scholarship highlights subtler mech- anisms through which modern authoritarian regimes maintain power. Schedler describes a “menu of manipulation” where regimes structure law enforcement and political competition to preserve dominance while projecting a façade of legality[134,135]. Rather than relying on outright repression, authoritarians often manip- ulate information as a low-cost alternative[66]. Propaganda and censorship are tools to manage public opinion and maintain the appearance of democracy, thus preserving legitimacy in the inter- national arena[151]. At the same time, the literature underscores the role of pre- emptive modes of repression, such as harassment and threats to deter wider opposition [78,92]. Frantz and Kendall-Taylor note that anticipatory tactics, such as surveillance or intimidation, com- plement coercive approaches by shaping societal expectations of political punishment[53]. Foucault’s analysis of the panopticon pro- vides a useful lens for understanding how anticipatory punishment, surveillance-induced compliance, and chilling effects enforce the disciplinary power of institutions[52]. In summary, the longevity of authoritarianism depends on strategic combinations of subtler mechanisms with targeted, pre-emptive forms of repression. 2.1.5 A Persistent Feature: Insider/Outsider Boundaries. Another recurrent feature is the exclusion of minority populations. Linz highlights limited pluralism in his definition of authoritarianism, a condition that sets the stage for systemic social, political, and eco- nomic discriminatory boundaries[91]. Arendt’s foundational anal- ysis of Nazi Germany and Stalinist Russia examines how specific populations were excluded from state-granted legal protections, civic rights, and human rights, effectively denying what she terms the “right to have rights”[7]. While Arendt’s analysis applies to extreme cases, later work shows that exclusionary boundaries are common across authoritarian contexts[23,28,78]. Other scholars From Democracies to Autocracies: How AI Systems Enable Authoritarianism by DesignPreprint, 2026, Online provide nuance by conceding that exclusionary politics can para- doxically also put authoritarian regimes at risk of mass opposition [26]. However, strategies such as power-sharing with elites and balancing ruling coalitions mitigate these risks[14,148]. Postcolo- nial scholarship reveals that the specific mechanisms enforcing such boundaries have deep institutional histories, as evidenced by Breckenridge’s account of biometric governance in colonial India as a tool of racial classification[21] and Fanon’s analysis of colo- nial population division[46]. Collectively, these works illustrate how erosion of the "right to have rights" underpins exclusionary ’inside/outsider’ classification. 2.1.6 Synthesizing A Conceptual Framework of Authoritarianism. Drawing from the literature, the following conceptual framework synthesizes key characteristics of authoritarian governance. To- gether, these characteristics provide an analytical framework to contextualize the six AI-enabled authoritarian deployments in the following sections. • Coercive Capacity is defined as the extent to which force and other forms of compulsion are monopolized by executive powers. • Accountability Erosion is defined as the removal or weaken- ing of formal or informal oversight mechanisms. •Symbolic Safeguards are defined as accountability processes without genuine or meaningful enforcement that can be exploited or co-opted, and thus become largely symbolic. • Information Control is defined as the monopolization and manipulation of information channels, including invasive monitoring and surveillance practices. •Anticipatory Repression is defined as pre-emptive acts of co- ercion, intimidation, and harassment to maintain control. •Boundary Control is defined as drawing exclusionary social and political categories that violate the political participa- tion and human rights of specific populations, particularly minorities. It is important to caveat that these characteristics are not strictly confined to the authoritarian-democratic spectrum of governance, e.g., colonial administrative states as discussed previously[21,27, 138]. They are also not fully exhaustive, but they aim to capture salient characteristics that enable authoritarian outcomes. 2.2 AI Technologies as Enablers of Authoritarianism Authoritarians have historically resorted to technology to enforce their rule [55,83]. Often referred to as digital authoritarianism or techno-authoritarianism, this field studies how authoritarian- ism evolves as technological systems’ capabilities increase [94,97, 122,136]. While these terms have slight definitional variations, they describe the use of technology to enable authoritarian prac- tices, irrespective of formal regime classification. This reflects how AI systems can facilitate the adoption of authoritarian practices in multiple contexts. For the purposes of this study, we define AI systems, following the OECD, as machine-based systems that generate predictions, recommendations, or decisions influencing physical or virtual environments[1]. Such systems are of partic- ular interest due to specific features such as statistical learning, extensive data collection and analysis, and black-box algorithmic decision-making that resists explainability and thus evades effective oversight [12,120,143]. While AI systems do not originate authori- tarian practices, nor do they uniquely produce the characteristics of authoritarian governance as presented in Section 2.1.6, they can exacerbate such characteristics, extending reach, reducing cost, and obscuring accountability[16]. There are several key domains in which AI enables authoritarianism, including mass surveillance, predictive policing, and the manipulation or control of information systems [12]. 2.2.1 Mass Surveillance: Monitoring at Unprecedented Scale. Digi- tal surveillance systems expand state capacity to monitor citizens at an unprecedented scale by automating mass data collection and predictive identification via machine learning models. While state surveillance predates AI, AI systems introduce a dramatic reduction in the cost and labor required to sustain surveillance at scale[16]. This creates chilling effects and violates citizens’ fundamental right to privacy and free speech [102,154]. To support such endeavors, regimes invest in surveillance infrastructure such as advanced hard- ware, highly integrated datasets, and biometric models. Examples of mass surveillance AI systems include China’s Social Credit System, which aggregates and classifies large amounts of data for behavioral scoring[88]. 2.2.2 Predictive Policing: Pre-emptive Control over Opposition. Surveil- lance systems feed into predictive policing systems that enable anticipatory repression. Predictive analytics identify dissenters and preempt opposition before mobilization. In practice, ill-defined thresholds of suspicion include civilian protestors or even entire eth- nic or religious minorities perceived to be in opposition to the cur- rent regime [85].These technologies contribute to self-censorship, limited political engagement, and reduced pluralism [147]. Multiple police departments throughout the United States, in partnership with private sector companies have deployed predictive policing systems[128, 168]. 2.2.3 Information Manipulation: Controlling Narratives and Pub- lic Discourse. Information-manipulation technologies disseminate propaganda and suppress ideas critical to the ruling regime [29,66]. Limited transparent, free information biases public discourse, chal- lenging a society’s ability to align on shared facts and solve prob- lems [4,107]. Examples include AI-driven disinformation cam- paigns and content moderation algorithms that censor at scale [100]. Non-AI examples include control over digital infrastructure such as internet shutdowns, and bans on news and social media platforms[100]. 2.2.4 Global Proliferation. Authoritarian practices, such as the ex- pansion of surveillance infrastructure, are not strictly confined to historically authoritarian regimes. This is evidenced by the inter- national market for surveillance technologies [38,106,137,169]. Digital authoritarianism is spreading globally, even in liberal democ- racies such as the US and those in Western Europe [128]. The lack of oversight, enforceable accountability, and safeguards contributes to this rise, intentionally and unintentionally, domestically and internationally [97]. Preprint, 2026, OnlineJeba Sania, Marta Ziosi & Fazl Barez 3 Research Question Our driving research question is, “Which lifecycle features and con- textual factors act as key enablers to facilitate authoritarian practices and governance outcomes, and do these factors vary across regimes? ” We hypothesize that these factors will vary significantly between the liberal democratic, authoritarian, and hybrid regimes. 4 Methodology To examine the deployment of authoritarian AI systems, we em- ployed a case study approach[60], mapping out the lifecycle of six systems applied in different political regimes across ten dimensions outlined in Section 4.1. To ensure consistency and comparability, each system was analyzed against these same dimensions and the conceptual framework established in Section 2. We then conducted a comparative analysis to identify patterns[99], while remaining sensitive to the varying political and operational contexts of each deployment. 4.1 Dimension Selection To provide a clear, structural understanding of systems’ deployment lifecycles, we selected dimensions adapted from conventional prod- uct development frameworks [127,167]. These dimensions capture critical technical and non-technical stages, and enable systematic 1 comparison across cases. The ten lifecycle dimensions are as follows: •Ideation: Which events or political drivers motivated its de- velopment, who defined the system’s goal, and which stake- holders participated and gave approval for its initial concep- tion? •Mandate and Legitimization: How is the system’s purpose justified, framed, and/or communicated to the public? This includes examining official announcements, media narra- tives, and public reception. •Procurement and Partnership: How are the system’s compo- nents, technologies, and talent to operate the system ac- quired? Which procurement processes, funding arrange- ments, and public-private partnerships were utilized? • Design and Development: Which stakeholders drove the tech- nical development process? This dimension also considers whether the system is an iteration of a previous system, and the technical stack used, including data sources, compute requirements, and model specifications. •Technical Integration: To what extent is the system integrated with other technical tools, especially existing government systems? •Testing: How was the system’s evaluation designed? How did the system perform, and which stakeholders conducted the evaluation? •Operational Rollout: How was the system launched, and was its rollout communicated? Which stakeholder is responsible for its ongoing maintenance, and what is the extent of public controversy surrounding its launch? 1 We use the term ’systematic’ here to denote a structured, consistent analytical ap- proach applied uniformly across all six cases. Specifically, we refer to the comparison of each case against the same ten lifecycle dimensions rather than a specific review protocol. •Oversight: What governance mechanisms are in place to monitor the system, such as audits, legal challenges, and third-party reviews? How independent are those mecha- nisms? • Safeguards: Are there technical and procedural protections built into the system itself, such as data retention limits and audit logs? This dimension also considers whether any safeguards were overridden. • Current State: How has the system evolved (or not) since its initial deployment as of the time of writing, and which stakeholders exert influence over the system’s direction? 4.2 System Selection The criteria for which these AI systems were chosen include: •Presence of Artificial Intelligence: Is there credible evidence that these systems employ machine learning or other ad- vanced statistical approaches? • System Classification: Can these systems be classified as surveillance, predictive policing, or information control sys- tems as defined by Barez et al.’s framework of AI-enabled authoritarian systems [12]? •Differing Political Contexts: Is there variation in the politi- cal regimes that these systems originate from and are de- ployed in? To assess this, we draw on well-respected non- profit democracy indexes 2 , including the V-Dem Institute’s Democracy Report and Freedom House’s Democracy In The World. •Deployment Data Availability: Is there sufficient public in- formation on these systems available and in the English language (the working language of the author) that verifies the presence of these systems and their lifecycles? The systems are presented in Table 1. Further information on how each system meets the criteria outlined above can be found in Appendix Table 2. Despite differences in scale, institutional purpose, and political context between the six systems, we treat them as analytically equivalent units of comparison on a specific and limited basis: AI systems whose development and deployment can be mapped across the ten lifecycle dimensions in Section 4.1. This framing allows for the comparison of diverse systems on the basis of high-level categories of design and deployment features and the evidence for them, rather than scale, purpose, or impact. 4.3 Case Study Methodology We drew on a wide range of sources to ensure the comprehen- siveness of our analysis. For each system, we conducted searches combining system names with terms related to lifecycle dimen- sions. We routinely followed citations in identified sources to locate additional material. While the availability of information varied across systems, we consulted the same categories of sources for each system to minimize information asymmetries in our comparative analysis. 2 We recognize that these classifications have certain normative assumptions and inher- ently reflect historical and political contexts. In this study, we use these classifications primarily to contextualize the political environments these systems are deployed in. From Democracies to Autocracies: How AI Systems Enable Authoritarianism by DesignPreprint, 2026, Online Table 1: Overview of selected AI systems. System NameDeployment Coun- try DomainPolitical Regime Classification System Description FlockSafetyAuto- mated License Plate Recognition (ALPR) United StatesPolicingLiberal Democracy[108], Free[61] Neighborhood and business-level li- cense plate recognition camera system developed by a private US company, FlockSafety[48]. Live Facial Recogni- tion (LFR) Vans United KingdomPolicing Electoral Democracy[108], Free[61] Real-time facial recognition vans used by 13 local UK police departments for suspect identification[111]. SlimmeCheck TheNetherlands, Amsterdam Administrative (Welfare Fraud) Liberal Democracy[108], Free[61] Welfare fraud detection system developed by the Amsterdam municipality govern- ment’s Work, Participation, and Income (WPI) department[65]. LavenderIsrael, Gaza StripMilitary Electoral Democracy[108], Free[61] Militant identification system developed by the Israeli Defense Force’s Unit 8200[3]. IntegratedJoint Operations Platform (IJOP) China,Xinjiang Province PolicingClosed Autocracy[108], Not Free[61] Aggregated policing system used to mon- itor and identify security threats in Xin- jiang, developed by the Xinjiang Public Security Bureau[158]. SferaRussia, MoscowTransportationElectoral Autocracy[108], Not Free[61] Biometric (facial recognition) payment system used in the Moscow Metro developed by Russian private-public partnerships[114]. These source categories include investigative research reports, human rights reports and investigations from well-known NGOs, first-hand accounts from impacted individuals of the public, gov- ernment employees, and system developers, public procurement notices, technical audits, independent system evaluations, informal statements by government officials via social media, news and me- dia coverage, official government communications, public lectures and publications by system developers, tribunal testimonies, official technical system diagrams, leaked screenshots of software inter- faces, and interviews with surveillance experts. Defunct links were cross-checked against the Internet Archive’s Wayback Machine. The diversity of sources enabled us to maximize the amount of credible information available on these systems. To maintain information fidelity, we excluded the following sources: opinion blogs, unverified social media posts, and materials that did not provide sufficient evidence to substantiate claims. The majority of sources were primarily examined over a one- month period from July to August 2025. Using the information gathered, we mapped each system against the ten lifecycle dimen- sions in Section 4.1, identifying technical and operational features based on whether they enabled the six authoritarian characteristics established in the Conceptual Framework in Section 2.1.6. As an initial attempt to examine AI-enabled authoritarianism across regime types, this study prioritizes identifying the authoritarian- enabling features before evaluating the countervailing features that might mitigate authoritarian outcomes. We treat the latter as an im- portant but distinct analytical question, which we leave for future work. 5 Results Across AI systems, we identify technical and contextual features that enable authoritarian practices. Rather than organizing findings by political regime, country, or AI system, we structure this section primarily around the authoritarian characteristics these features enable and the mechanisms by which they do so, in Section 5.1. See Appendix Table 3 for a visual mapping. In Section 5.2, we report other notable results, including the advantages of centralized and fragmented systems in enabling authoritarianism, as well as findings on the limited transparency of these systems. We find patterns across systems, regardless of the political regime in which these systems are deployed, suggesting regime classification does not fully account for the presence of enabling features. 5.1 System Features 5.1.1 Coercive Capacity. Coercive capacity is defined as the ex- tent to which force and other forms of compulsion (harassment, intimidation, etc) are monopolized by an executive power. We also consider the extent to which threats of force, force, and its deriva- tives are made viable. In Gaza, where the Lavender system has been used to identify and recommend military targets, coercive capacity is expanded by a combination of three factors: integration across military sys- tems, loose definitions of what constitutes a military target, and a 10% identification error margin[2,3]. Collectively, these factors lower the threshold for lethal force. Lavender uniquely enables fatal outcomes among other systems. Preprint, 2026, OnlineJeba Sania, Marta Ziosi & Fazl Barez Feature: Integration with Lethal Military Infrastructure, Insufficient Accuracy Rates Across the US, FlockSafety’s deployment of local ALPR cameras in over 6,000 cities, along with the integration of state and national databases such as the Federal Bureau of Investigation’s National Crime Information Center (NCIC) database, significantly expands surveillance infrastructure[49]. Such expansion enables greater levels of harassment and the implicit threat of it. Notably, many national law enforcement databases have been reported to be rou- tinely out of date or erroneous, increasing the risk of unwarranted harassment[68, 86, 104]. Feature: Widespread Data Integration, Integration with Outdated Databases Sfera, LFR Vans, and the IJOP system in particular, follow a similar model of centralizing surveillance inputs and wide inte- gration with other databases [57,158]. The Sfera system leverages data from non-law enforcement databases, including public ser- vices, local administration, and even passport databases [80,114]. It’s worth mentioning that Sfera’s facial recognition models are partially trained on a dataset extracted from a doxxing mobile appli- cation, explicitly connecting surveillance capabilities to harassment functions [139]. Feature: Widespread Data Integration, Co-optation of Administra- tive systems 5.1.2 Accountability Erosion. Accountability erosion is defined as the removal or weakening of formal or informal oversight mech- anisms. This dilution or denial of checks and balances is most relevant for the concentration of executive power. In the UK, police operators of LFR vans have wide discretionary power. Third-party auditors at the University of Essex note the freedom for operators to determine the proportionate use of the technology, suggesting limited constraints on improper usage[45, 57,163]. Additionally, inconsistent operating procedures between deployments can diffuse responsibility for negative impacts and enable potential misuse [45,57,163]. This is made possible by the lack of regulation of facial recognition technology in the UK, which instead relies on a patchwork of recommendations[62, 117]. Feature: Inconsistent Operating Procedures The extent of automa- tion within the Lavender system provides operators the option to defer decision-making to the system, which consequently limits opportunities for meaningful contestation [3, 5]. Feature: Over-reliance on Automated Decision-Making As the customers of FlockSafety’s ALPR system, businesses, HOAs, and private citizens own all locally collected surveillance data[50]. How- ever, these non-state users do not receive legal or ethical training and generally enjoy weaker oversight standards [39,145]. In a similar vein, informal data-sharing agreements between private citizens and law enforcement officials provide federal agencies with workarounds to avoid breaking state laws on ALPR data [40,79,101] and legal constraints in federal contracts [33, 35, 93]. Feature: Oversight Loopholes for Non-state Actors and Private Citizens/Organizations Russia’s 2022 law on biometric data stipulates that its restrictions on the handling, retention, and transfer of data do not apply to intelligence, national security, or other law enforcement activities, creating a significant accountability gap[63, 146]. Feature: Regulatory Gap and Exemption for Law Enforcement 5.1.3 Symbolic Safeguards. Symbolic safeguards are defined as existing accountability processes that lack genuine or meaningful enforcement, allowing for co-optation. Unlike accountability ero- sion, symbolic safeguards are maintained, but their presence serves to legitimize deployments rather than constrain. An official statement by the Israeli Defense Force justifies the us- age of Lavender, indicating that analysts review and verify whether targets meet the criteria stipulated by international law and internal directives[73]. However, investigative reports indicate that analysts intentionally bypassed such safeguards, spending only 20 seconds to verify whether identified targets were males in order to meet performance standards[3]. Feature: Lack of Compliance Mechanisms Similarly, law enforcement users with access to FlockSafety’s ALPR surveillance data are required to log their purpose of search- ing the database. However, investigations have shown that queries often use vague language, rendering audits of the usage of this system ineffective [93, 101]. Feature: Inconsistent Operating Procedures, Lack of Compliance Mechanisms 5.1.4 Information Control. Information control is defined as the monopolization and manipulation of information channels, includ- ing invasive monitoring and surveillance practices. Several of the examined systems consolidate large amounts of personal data. This is most evident through the IJOP system, deployed in Xin- jiang. Government officials centralize surveillance data on the Uyghur ethnic minority population through extensive biometric, medical, utility, location, and digital communications data collection across public and private spaces [118,119,123,158,159]. Informa- tion from non-law enforcement databases is also connected to the IJOP system, such as second-hand car databases [109]. Feature: Widespread Data Integration, Co-optation of Adminis- trative Systems While the IJOP system is justified on security grounds[160], the Sfera system was introduced as a moderniza- tion effort to streamline payments for riders on the Moscow metro [133,142]. However, reports show that as of 2022, 141 Moscow residents identified through Sfera were effectively detained for par- ticipation in protests [115]. The expansion of Sfera’s scope to target political dissenters exemplifies how executive powers manipulate information channels for political control. Feature: Co-optation of Administrative Systems 5.1.5 Anticipatory Repression. Anticipatory repression is a pre- emptive act of coercion, intimidation, and harassment without due process. Systems can enable anticipatory repression by identifying perceived political risks ahead of the fact. Many residents who have participated in past anti-government protests in Moscow reported being arrested by police ahead of large holidays [95,115]. These arrests occurred prior to any planned protest activity, illustrating that Sfera was used to prevent political mobilization. Feature: Co-optation of Administrative Systems Similarly, in Xinjiang, the IJOP system operationalizes anticipa- tory repression through the use of haphazard and arbitrary iden- tifiers of criminality, such as emotions [75,157]. Further arbitrary From Democracies to Autocracies: How AI Systems Enable Authoritarianism by DesignPreprint, 2026, Online measures include changes in facial expressions and skin pores [157]. Additionally, despite the advanced computer vision techniques used to collect inputs, the system’s downstream decision-making is com- paratively unsophisticated. Investigative reports reveal that simple rules-based logic is used to determine detentions rather than ML- based predictions [6,158]. This combination of advanced surveil- lance methods and lack of accurate decision logic enables mass detention. Feature: Predictive Behavioral Indicators, Arbitrary Indicators 5.1.6 Boundary Control. Boundary control is the creation of ex- clusionary social and political categories that disadvantage specific populations, particularly minority groups. The IJOP system explicitly targets ethnic Uyghurs for detention and re-education camps in Xinjiang. This is evidenced by multi- ple “Uyghur detection” algorithms connected to the surveillance cameras feeding into the system [25,69,76,131,144]. Additionally, officials can report the ethnic and religious practices of residents in IJOP, including donating to mosques or preaching without autho- rization [8, 158]. Feature: Explicit Group-Based Classification In Gaza, individuals are more likely to be identified by the Laven- der system as a military target according to imprecise and some- what arbitrary behaviors, including changing phones and addresses every few months, as is common during war [30,166]. The lack of tight definitions can result in indiscriminate violence against Gazans. Feature: Arbitrary Indicators During the testing and pre-pilot of SlimmeCheck, developers found that the algorithm was more likely to incorrectly flag ap- plications from non-Dutch citizens and those with non-Western nationalities [20]. Feature: Encoding of Protected Group Characteristics 5.2 Other Notable Patterns and Findings We refer to system centralization as the extent to which executive authorities meaningfully control or influence the AI system, as well as how connected the system is to multiple inputs and data sources. In line with this definition, the IJOP and Sfera systems are the most centralized, whereas Flock Safety’s ALPR system is the most fragmented, as it is operated by a private entity and exists as a collection of deployments. By concentrating decision-making authority, centralized systems are structurally well-suited to authoritarian applications. These sys- tems have distinct authoritarian advantages stemming from the reduced internal and legal checks. This includes fewer institutional stakeholders with power to veto or constrain the system. Conse- quently, such systems are susceptible to oversight capture, mitigat- ing the effectiveness of formal oversight mechanisms. For example, the Sfera system is exempt from any legal oversight for biomet- ric systems in Russia, while operators of the Lavender system did not verify the system’s outputs against the IDF’s own definitions of military targets under international humanitarian law [3]. In theory, centralization also facilitates an easier pathway to further integration with other government data repositories [77, 132]. However, fragmented systems also pose unique authoritarian- enabling risks. Using FlockSafety’s ALPR as a case study, we note that attempts to regulate the technology have proven challenging. The decentralized manner of the system and its network effects make it harder to be collectively dismantled in the absence of cen- tralized decision-making [145]. The ALPR network exhibits a lack of strong user coordination between deployments, resulting in a lack of clear responsible actors between FlockSafety, law enforce- ment users, and customers (neighborhoods, HOAs, and businesses). This is significant because Flock Safety lacks the ability to detect user-initiated abuse of the system [39,67]. Lastly, inconsistent user- led deployments can lead to inconsistent implementation of best privacy practices and safeguards. Across the ten lifecycle stages, several patterns emerge across systems, emphasizing a lack of clean distinction between system features and regime classifications. At the mandate and legitimiza- tion stage, all systems, except for SlimmeCheck and Sfera, were justified explicitly through public safety and law enforcement ra- tionales [32,48,65,142,149,160]. Importantly, the role of a pre- ceding security crisis was a salient factor for most of these sys- tems (IJOP, FlockSafety ALPR, Lavender )[13,74,84,166]. At the procurement and partnership stage, most systems were either pro- cured from private vendors or developed and fine-tuned through private-public partnerships[31,48,95,103,124,158]. SlimmeCheck and Lavender were instead developed in-house by government institutions[10,65,149,162]. At the operational rollout stage, all systems except for FlockSafety ALPR deployments and the Laven- der system are documented to be launched through a pilot approach [11,20,98,113,117,124]. However, pilot results have been disclosed for SlimmeCheck, LFR Vans, and Sfera, but not for the IJOP system [20,98,105]. Regarding the current stage of systems, only Slim- meCheck was formally dismantled by city officials after a series of bias audits[20,65]. Lavender is allegedly, but not confirmed, to be no longer in use in part due to international pressure [3,152]. In contrast, all other systems are actively expanding their user base and/or geographic reach[18, 19, 41, 47, 51, 69, 81, 110, 161, 164]. Lastly, notwithstanding our findings, there are notable informa- tion gaps regarding each system’s lifecycle across the ten dimen- sions. The most salient information gaps across systems, regardless of political regime, were related to the design and development and desting stages. With the exception of SlimmeCheck [65,90], there is limited or incomplete information regarding model spec- ifications, training data, and the technical stack each system is embedded in. With the exception of SlimmeCheck and the Live Facial Recognition (LFR) Vans, there is limited information regard- ing how these systems were evaluated. Notably, both systems were evaluated by third-party evaluators in collaboration with local gov- ernment officials [20,57,82]. For systems deployed in authoritarian regimes (IJOP, Sfera) and the Lavender system used by the Israeli military, there is a greater lack of information regarding oversight mechanisms and system safeguards. 6 Discussion Our findings extend existing scholarship on AI-enabled authori- tarianism in three ways. First, we find that authoritarian-enabling features are present across political contexts, including liberal demo- cratic ones. This suggests regime classification is insufficient for understanding authoritarian risks, and a practice-oriented approach Preprint, 2026, OnlineJeba Sania, Marta Ziosi & Fazl Barez is needed[59]. Secondly, through our analysis of FlockSafety’s frag- mented, privately operated ALPR system, we challenge the assump- tion that AI-enabled authoritarianism is strictly enacted by states in formally classified authoritarian regimes. Third, by shifting be- yond model development towards the full system lifecycle, we demonstrate how authoritarian outcomes emerge from design and deployment choices that capability-focused analyses overlook. Rather than classifying system outcomes as the product of regime type alone, our findings demonstrate that AI-enabled authoritarian- ism can also be enabled by design and deployment choices. Across political regimes, we uncover how specific features help enable key characteristics of authoritarianism, reframing anti-authoritarian AI governance as a wider socio-technical problem rather than a con- cern confined to non-democratic contexts. These features include widespread data integration, the co-optation of civil administra- tive systems, and weak or ineffective governance instruments. The role of regimes is not determinative, as we find systems enable authoritarian characteristics, such as the expansion of coercive ca- pacity and the erosion of accountability mechanisms, in both liberal democracies and autocracies. This is also evident in Section 5.2, as the lifecycle features of systems do not align into clear, regime- specific patterns. Instead, there is considerable variance regarding the configuration and combination of these features across regimes. Crucially, we note that whether systems enable authoritarian- ism is not restricted to a particular model, nor does it depend on highly capable models. In fact, both centralized and fragmented systems can enable authoritarianism due to their respective unique ability to evade oversight. Instead, authoritarian impacts emerge from user and developer choices embedded throughout the system lifecycle, from ideation and procurement to integration and roll- out. Therefore, such impacts are not inevitable. We thus encourage policymakers and technical developers to treat AI-enabled authori- tarianism as a current risk that requires mitigation, further studies, and targeted regulation, rather than an emerging risk contingent upon the direction of the capabilities of frontier models [15,37]. AI-enabled authoritarianism warrants present concern, as it can occur without the development of artificial general intelligence[71]. Future research should consider how embedded user and developer choices influence the systems’ capacity to enable authoritarianism as well, rather than narrowly focusing on technical capabilities and political deployment contexts. Consequently, mitigation efforts should focus not only on down- stream safeguards or user compliance post-deployment, but earlier lifecycle stages as well, in which systems are justified, procured, developed, and integrated with other systems. We recommend stake- holders consider interventions across the entire system lifecycle to minimize the risk that systems contribute to AI-enabled authoritar- ianism. Notwithstanding these findings, we acknowledge that the recommended interventions cannot entirely eliminate AI-enabled authoritarianism on their own. Rather they function to mitigate risk within the scope of the stakeholders’ influence. 6.1 Implications for Developers Our findings reveal that operational safeguards alone are insuf- ficient, as they rely on user compliance. The case study of the Lavender and FlockSafety’s ALPR system illustrates how users can neglect or easily bypass operational practices. This underscores the need for technical safeguards embedded directly into systems as an additional defense against user misuse. Developers should assume that government and public infras- tructure systems may be repurposed after deployment and should proactively design for resistance to misuse. As this will require developers to anticipate how features can be misused beyond their original intent, we re-emphasize the need for further studies on the specific feature-level mechanisms that enable authoritarianism. For example, boundary control risks can emerge when features that encode ethnicity, religion, nationality, or their proxies are intention- ally exploited for discriminatory 3 [72], rather than in the technical machine learning sense of model differentiation between classes purposes. Safeguards should be prioritized and subjected to the same level of rigor as any other part of the system’s specifications. 6.2 Implications for Policy Makers Transparency varies considerably between systems. For example, in- vestigations revealed details of the IJOP system’s technical stack in China, but the same level of detail is not available for Flock Safety’s ALPR system in the US. These differences in data availability are not merely methodological constraints but likely reflect meaning- ful variations in oversight, governance, and overall accountability. As a result, policymakers should consider mandating increased transparency from technical developers and administrators. One critical intervention point lies in the testing stage. Estab- lishing performance red lines before systems are piloted is crucial. Clear success criteria and evaluation data lower the barriers for decision-makers to roll back the deployment of systems and save face. For example, during the dismantling of SlimmeCheck, Ams- terdam city officials cited evaluation data that demonstrated the system performed worse than the existing analogue system[65]. Such documentation can serve as critical empirical justification. While developers build safeguards during system design, pol- icymakers can enforce accountability during other stages of the system’s lifecycle, especially once systems are deployed. These stages include: procurement, testing, operational rollout, oversight, and current stage. However, enforcing accountability will require real legislative authority, with clear standards for use, misuse, and consequences. For example, to limit high degrees of centralization and integration of administrative data, policymakers should enforce strict data-sharing regulations between agencies with explicit data retention limits. These will help close regulatory gaps, such as those of the UK’s live facial recognition policies. 6.3 Implications for Liberal Democracies Progression towards authoritarian outcomes via AI systems can occur within democratic institutions and is not limited to authori- tarian regimes. The erosion of democratic practices is not limited to overt repression or institutional breakdown. Instead, authoritarian- ism can be enabled incrementally, which can be facilitated through technology, as evidenced by our research. As liberal democracies are not immune to AI-enabled authoritarianism, we advocate for 3 We use "discriminatory" in the socio-political sense to refer to prejudicial distinctions that impair the recognitions, enjoyment, and exercise of rights between categories of people, particularly along lines of ethnicity, religion, nationality, and other protected characteristics From Democracies to Autocracies: How AI Systems Enable Authoritarianism by DesignPreprint, 2026, Online greater scrutiny of technological systems used by or in government and law enforcement officials, as the risk of AI-enabled authoritari- anism may be overlooked and minimized in these contexts. Next, many of the systems have been adopted and justified in the name of efficiency, modernization, and public safety, as demon- strated by the Sfera, Flock Safety’s ALPR, and LFR Van systems. This suggests that there is a delicate tradeoff between these goals and accountability, so liberal democracies must be vigilant in adopt- ing the necessary safeguards to prevent the scope creep of these AI systems. Lastly, our examination of FlockSafety’s ALPR system reveals that fragmented deployments can uniquely enable authoritarian- ism by diffusing responsibility for surveillance across stakeholders, weakening overall accountability. Liberal democracies, therefore, cannot ignore private-sector involvement and must regulate pri- vate entities that develop and deploy fragmented AI systems that exploit the nascent regulatory landscape. This finding enriches our analysis by demonstrating how AI-enabled authoritarian practices can occur outside authoritarian regimes and are not exclusively enacted by state actors. 6.4 Limitations Several limitations exist that should inform the interpretation of our results. First, due to the nature of this research, there are substan- tial information gaps that limit a comprehensive analysis. Despite extensive efforts to collect information on these controversial sys- tems, key technical and operational details are not fully available online for public viewing[9,20,112,158]. This is due to a combi- nation of factors, including outdated records, intentional efforts to limit transparency, and corporate secrecy that hides the internal technical workings of proprietary technologies. As we limit this research to only six case studies, these findings cannot be widely generalized across all contexts and AI deploy- ments. Additionally, we acknowledge limits in comparability as the six systems vary considerably in scale, purpose, technical de- sign, and context. Our findings should thus be strictly interpreted through the lens of the authoritarian-enabling features identified in high-level system analysis. We encourage readers to view our find- ings as an initial contribution to a nascent intersection of research, rather than a comprehensive and complete account of AI-enabled authoritarianism. As stated previously, many of the governance characteristics identified in our framework in Section 2.1 are not found exclu- sively in authoritarian regimes, nor do they manifest only along the democratic-authoritarian spectrum. For example, many of these characteristics intersect with mechanisms employed by colonial administrative structures, such as administrative data systems and population registries[21,27,46,138]. This suggests the democratic- authoritarian spectrum is likely just one analytical lens for under- standing AI-enabled governance harms, and a fuller account would require further engagement with non-Western and postcolonial scholarship. We invite researchers to enrich this analysis by consid- ering additional dimensions our approach does not fully capture, and that are underexplored in the existing literature. Future directions include expanding the number of systems in- vestigated, political contexts, and units of comparison, consider- ing features that enable democracy instead, and drawing on infor- mation available in other languages and platforms not examined. Additionally, in-depth studies of single-system deployments and their specific contexts can provide more granular accounts of en- abling factors. Lastly, as the relationship between technology and authoritarianism continues to evolve, we encourage researchers, particularly from the political and social sciences, to further ex- plore the specific mechanisms by which AI systems can abet or constrain anti-democratic practices, and how regime type impacts those mechanisms. 7 Conclusion This study offers one of the few systematic, cross-regime compar- isons of the technical and operational features of AI systems that enable authoritarianism.As such, this study extends the current lit- erature by demonstrating that enabling features do not map neatly to regime type, challenging assumptions about how authoritarian- enabling systems are deployed, and widening the scope of analysis beyond model development to include deployment. Our research, based on the mapping of these systems across ten lifecycle stages, re- veals that six characteristics of authoritarianism (coercive capacity, accountability erosion, symbolic safeguards, information control, anticipatory repression, and boundary control) can be furthered through recurring patterns of design and deployment choices, re- gardless of political regime. We identify these features as a) overreliance on automation, b) mass data integration and centralization, c) co-optation and inte- gration of administrative and military infrastructures, d) oversight and regulatory gaps, e) weak user compliance, and f) harms to protected groups. Importantly, these features are not necessarily tied to highly accurate or advanced AI systems. We examine the implications and provide suggestions for developers, policy mak- ers, and liberal democracies. We conclude by reemphasizing that AI-enabled authoritarianism should be understood as an ongoing risk that requires mitigation, attention, and governance across the full system lifecycle. 8 Generative AI Usage Statement During the preparation of this work, the authors used Grammarly to assist with grammar and spell checking. ChatGPT was used to format tables, and check for inconsistent usage of key terms. Grammarly, ChatGPT, and Claude were used to suggest changes in sentence-level fluency. No generative AI was used to develop the core ideas or structure of the paper. 9 Acknowledgements The research was supported by the authors’ affiliation with the Oxford Martin AI Governance Initiative, funded by the Berkeley Existential Risk Initiative. We thank Keir Reid, Dr. Isaac Friend, Igor Krawczuk, Rose Hadshar, Uma Kalkar, Shariqah Hossain, Garrett Sanborn, Emma Pan and Tappy Lung for their feedback in shaping this work. We thank Professor Darren Byler from Simon Fraser University and Conor Healy from Internet Protocol Video Market Preprint, 2026, OnlineJeba Sania, Marta Ziosi & Fazl Barez (IPVM) for their time, and invaluable expertise on surveillance systems in the US and China. References [1]2024. https://w.oecd.org/content/dam/oecd/en/publications/reports/2024/ 03/explanatory-memorandum-on-the-updated-oecd-definition-of-an-ai- system_3c815e51/623da898-en.pdf [2]Yuval Abraham. 2024. How Israel Used AI to Form Kill Lists and Bomb Pales- tinians in Their Homes. https://w.democracynow.org/2024/4/5/israel_ai [3]Yuval Abraham. 2024. “Lavender”: the AI Machine Directing Israel’s Bombing Spree in Gaza. +972 Magazine (Apr 2024). https://w.972mag.com/lavender- ai-israeli-army-gaza/ [4]Oluwatomisin Ajayi. 2025. AI-Powered Disinformation and Narrative Warfare: A Global Security Threat. (Jan 2025). doi:10.2139/ssrn.5184687 [5]Saar Alon-Barkat and Madalina Busuioc. 2023. Human-AI interactions in public sector decision-making: “Automation bias” and “selective adherence” to algo- rithmic advice. Journal of Public Administration Research and Theory 33, 1 (Feb 2023), 153–169. doi:10.1093/jopart/muac007 [6]Arelemorgen. 2018.With hearts set on “Visiting, Benefiting, and Gathering” and offering words of comfort, warmth and care are felt. https://web.archive.org/web/20190706170558/http://w.zgtks.gov.cn/ shishixinwen/zwdt/2018-02-05/55504.html [7]Hannah Arendt. 1968. The origins of totalitarianism. Harcourt Brace Jovanovich, San Diego. 290–302 pages. [8]ASPI. 2018. How mass surveillance works in Xinjiang | The Xinjiang Data Project. https://xjdp.aspi.org.au/explainers/how-mass-surveillance-works-in- xinjiang/ [9] NEC Australia. 2014. NeoFace® Watch. https://w.naffco.com/downloads/ pdf/neoface-watch-brochure.pdf [10] Yaniv Avital. 2023. IDF: We used AI to thwart Hamas cell leaders.https: //w.geektime.co.il/idf-fights-hamas-with-ai-and-data-science/ [11]Chris Baraniuk. 2017. Police to use facial recognition at Champions League final. BBC News (Apr 2017). https://w.bbc.com/news/technology-39735637 [12]Fazl Barez, Isaac Friend, Keir Reid, Igor Krawczuk, Vincent Wang, Jakob Mökan- der, Philip Torr, Julia Morse, and Robert Trager. 2025. Toward Resisting AI- Enabled Authoritarianism. (2025). https://aigi.ox.ac.uk/publications/toward- resisting-ai-enabled-authoritarianism/ [13]BBC. 2014. Attack on Chinese market kills 31. BBC News (May 2014). https: //w.bbc.com/news/world-asia-china-27502652 [14]Janina Beiser-McGrath and Nils W. Metternich. 2020. Ethnic Coalitions and the Logic of Political Survival in Authoritarian Regimes. Comparative Political Studies 54, 1 (Jun 2020), 001041402092065. doi:10.1177/0010414020920656 [15]Yoshua Bengio. 2023.AI and Catastrophic Risk.https://w. journalofdemocracy.org/articles/ai-and-catastrophic-risk/ [16]Martin Beraja, Andrew Kao, David Y Yang, and Noam Yuchtman. 2023. AI- TOCRACY. The Quarterly Journal of Economics 138, 3 (Mar 2023). doi:10.1093/ qje/qjad012 [17]Edwin Black. 2001. IBM and the Holocaust : the strategic alliance between Nazi Germany and America’s most powerful corporation. Dialog Press, Washington, D.C. [18]Masha Borak. 2024. Leaked documents reveal details on Russia’s upcom- ing surveillance system. https://w.biometricupdate.com/202404/leaked- documents-reveal-details-on-russias-upcoming-surveillance-system [19] Masha Borek. 2023.Moscow Metro biometric payment system hits 320,000 users amid surveillance fears | Biometric Update.https: //w.biometricupdate.com/202305/moscow-metro-biometric-payment- system-hits-320000-users-amid-surveillance-fears [20]Justin-Casimir Braun, Gabriel Geiger, Eileen Guo, Eva Constantaras, and Amanda Silverman. 2025. How we investigated Amsterdam’s attempt to build a “fair” fraud detection model. https://w.lighthousereports.com/methodology/ amsterdam-fairness/ [21]Keith Breckenridge. 2016. Biometric state: The global politics of identification and surveillance in South Africa, 1850 to the present. Cambridge University Press. [22]Nathan J Brown, Steven D Schaaf, Samer Anabtawi, and Julian G Waller. 2024. Autocrats Can’t Always Get What They Want. University of Michigan Press. 3 pages. [23] Jason Brownlee. 2007. Authoritarianism in an age of democratization. Cambridge University Press, Cambridge. [24]Justin B Bullock, Samuel Hammond, and Seb Krier. 2025. AGI, Governments, and Free Societies. https://arxiv.org/abs/2503.05710 [25] Darren Byler. 2020. “Because There Were Cameras, I Didn’t Ask Any Questions”. https://w.chinafile.com/extensive-surveillance-china [26]Lars-Erik Cederman, Andreas Wimmer, and Brian Min. 2010. Why Do Ethnic Groups Rebel? New Data and Analysis. World Politics 62, 1 (Dec 2010), 87–119. [27]Partha Chatterjee. 1993. The nation and its fragments: Colonial and Postcolonial Histories. Princeton University Press. [28]Nic Cheeseman. 2015. Democracy in Africa : success, failures, and the struggle for political reform. Cambridge Univ. Press, Cambridge. 155–180 pages. [29]Jidong Chen and Yiqing Xu. 2015. Information Manipulation and Reform in Authoritarian Regimes. Political Science Research and Methods 5, 1 (Jun 2015), 163–178. doi:10.1017/psrm.2015.21 [30]Andy Clarno. 2024. Israel’s Lavender Kill List: A Joint Imperial Production. Spectre Journal 5, 10 (Nov 2024). doi:10.63478/ls2n6v2d [31]Devin Coldewey. 2016. NTechlab aims new FindFace.Pro facial recognition ser- vice at businesses | TechCrunch. https://techcrunch.com/2016/10/18/ntechlab- aims-new-findface-pro-facial-recognition-service-at-businesses/ [32]Rob Corp. 2025. BBC Verify Live: How UK police use live facial recognition and videos show typhoon hitting Taiwan. BBC News (2025). https://w.bbc.com/ news/live/cdxyqd0k07vt [33]Joseph Cox and Jason Koebler. 2025.A Texas Cop Searched Li- cense Plate Cameras Nationwide for a Woman Who Got an Abortion. https://w.404media.co/a-texas-cop-searched-license-plate-cameras- nationwide-for-a-woman-who-got-an-abortion/ [34] Raluca Csernatoni. 2024. Can Democracy Survive the Disruptive Power of AI? Technical Report. Carnegie Endowment. [35]Tim Cushing. 2024.California HOAs Are Buying Up Flock Li- cense Plate Readers; Giving Cops Open Access To Them.https: //w.techdirt.com/2024/04/03/california-hoas-are-buying-up-flock- license-plate-readers-giving-cops-open-access-to-them/ [36]Christian Davenport. 2007. State Repression and Political Order. Annual Review of Political Science 10, 1 (Jun 2007), 1–23. doi:10.1146/annurev.polisci.10.101405. 143216 [37]Tom Davidson, Lukas Finnveden, and Rose Hadshar. 2025. AI-Enabled Coups: How a Small Group Could Use AI to Seize Power. https://w.forethought.org/ research/ai-enabled-coups-how-a-small-group-could-use-ai-to-seize-power [38] Harry Davies and Yuval Abraham. 2025. “A million calls an hour”: Israel relying on Microsoft cloud for expansive surveillance of Palestinians. the Guardian (Aug 2025).https://w.theguardian.com/world/2025/aug/06/microsoft-israeli- military-palestinian-phone-calls-cloud [39]Sam Dean. 2019. Flock Safety makes license plate cameras that track every car in a neighborhood. https://w.latimes.com/business/story/2019-09-12/flock- safety-license-plate-readers-los-angeles [40] Mount Prospect Police Department. 2023. Police Department Response to Flock License Plate Reader Investigation | News | Village of Mount Prospect, IL. https://w.mountprospect.org/Home/Components/News/News/10311/1042 [41]Garrison Douglas. 2025. Gov. Kemp: Georgia-based Flock Safety Opens New 97,000-Square-Foot Manufacturing Facility.https://gov.georgia.gov/press- releases/2025-04-02/gov-kemp-georgia-based-flock-safety-opens-new- 97000-square-foot [42] Jennifer Earl, Thomas V. Maher, and Jennifer Pan. 2022. The digital repression of social movements, protest, and activism: A synthetic review. Science Advances 8, 10 (Mar 2022), 1–15. doi:10.1126/sciadv.abl8198 [43]Grzegorz Ekiert. 2023. Democracy and Authoritarianism in the 21st Century: a Sketch. Harvard Kennedy School.https://ash.harvard.edu/wp-content/ uploads/2023/12/democracy_and_authoritarianism_in_the_21st_century- _a_sketch.pdf [44] Fredrik Erixon and Hosuk Lee-Makiyama. 2011. Digital authoritarianism: Hu- man rights, geopolitics and commerce. Handle.net (2011). doi:10419/174715 [45]Essex. 2019. Metropolitan police live facial recognition trial concerns | University of Essex.https://w.essex.ac.uk/news/2019/07/03/met-police-live-facial- recognition-trial-concerns [46] Frantz Fanon and Jean-Paul Sartre. 1963. The Wretched of the Earth. Grove Press. [47]FlockSafety. 2025. Accelerating Innovation: Flock Secures 275 Million to Ad- vance Crime-Solving Technology. https://w.flocksafety.com/blog/flock- safety-secures-major-funding [48]FlockSafety. 2025. LPR Cameras. https://w.flocksafety.com/products/license- plate-readers [49]FlockSafety. 2025. National LPR Network.https://w.flocksafety.com/ products/national-lpr-network [50]FlockSafety. 2025. Privacy and Ethics. https://w.flocksafety.com/privacy- ethics [51]FlockSafety. 2026. Flock Safety Opens New Boston Office, Plans to Bring 150 Jobs to the City. https://w.flocksafety.com/blog/flock-safety-opens-new- boston-office-plans-to-bring-150-jobs-to-the-city [52] Michel Foucault. 1977. Discipline and punish: The birth of the prison. Penguin Books. [53]Erica Frantz and Andrea Kendall-Taylor. 2014. A Dictator’s Toolkit: Under- standing How Co-optation Affects Repression in Autocracies. Journal of Peace Research 51, 3 (Mar 2014), 332–346. doi:10.1177/0022343313519808 [54]Erica Frantz, Andrea Kendall-Taylor, and Joseph Wright. 2020. Digital Re- pression in Autocracies Users Working Paper SERIES 2020:27 THE VARIETIES OF DEMOCRACY INSTITUTE. https://v-dem.net/media/publications/digital- repression17mar.pdf From Democracies to Autocracies: How AI Systems Enable Authoritarianism by DesignPreprint, 2026, Online [55]Carl J Friedrich and Zbigniew Brzezinski. 1965. Totalitarian dictatorship and autocracy. Harvard University Press, Cambridge, Mass. 3–27 pages. [56]Allie Funk, Adrian Shahbaz, and Kian Vesteinsson. 2023. The Repressive Power of Artificial Intelligence. [57]Pete Fussey and Daragh Murray. 2019. Independent Report on the Lon- don Metropolitan Police Service’s Trial of Live Facial Recognition Technol- ogy. https://repository.essex.ac.uk/24946/1/London-Met-Police-Trial-of-Facial- Recognition-Tech-Report-2.pdf [58] Jennifer Gandhi. 2008. Political institutions under dictatorship. Cambridge University Press, Cambridge. 73–106 pages. [59]Marlies Glasius. 2018. What Authoritarianism Is . . . and Is not: a Practice Perspective. International Affairs 94, 3 (May 2018), 515–533. doi:10.1093/ia/iiy060 [60]Roger Gomm, Martyn Hammersley, and Peter Foster. 2009. Case Study Method. SAGE Publications Ltd, 1 Oliver’s Yard,55 City Road,London England,EC1Y 1SP, United Kingdom. doi:10.4135/9780857024367 [61]Yana Gorokhovskaia and Cathryn Grothe. 2025. Freedom in the World 2025: The Uphill Battle to Safeguard Rights. [62] GOV.UK. 2013. Amended Surveillance Camera Code of Practice (accessible ver- sion). https://w.gov.uk/government/publications/update-to-surveillance- camera-code/amended-surveillance-camera-code-of-practice-accessible- version [63] Andrei Grigoryev. 2024. “Significant” Risks As Facial Recognition In Russia’s Subways Goes Regional. https://w.rferl.org/a/facial-recognition-security- civil-rights-subways/33109725.html [64]Patrick Grother, Mei Ngan, and Kayee Hanaoka. 2026. Face Recognition Technol- ogy Evaluation (FRTE) Part 2: Identification. [65]Eileen Guo, Gabriel Geiger, and Justin-Casimir Braun. 2025.In- side Amsterdam’s high-stakes experiment to create fair welfare AI. https://w.technologyreview.com/2025/06/11/1118233/amsterdam-fair- welfare-ai-discriminatory-algorithms-failure/ [66]Sergei Guriev and Daniel Treisman. 2020. A theory of informational autocracy. Journal of Public Economics 186, 104158 (Jun 2020), 104158. doi:10.1016/j.jpubeco. 2020.104158 [67]Sarah Hamid and Rindala Alajaji. 2025.Flock Safety’s Feature Up- dates Cannot Make Automated License Plate Readers Safe.https: //w.eff.org/deeplinks/2025/06/flock-safetys-feature-updates-cannot- make-automated-license-plate-readers-safe [68]Patrick Hand. 1982. Probable Cause Based on Inaccurate Computer Information: Taking Judicial Notice of NCIC Operating Policies and Procedures. FLASH - Fordham Law Archive of Scholarship and History (Fordham University) 10, 3 (Jan 1982), 497. [69]Conor Healy. 2024. Shanghai Launches New “Uyghur Ethnicity” Detection. https: //ipvm.com/reports/filtering-for-uyghurs [70] Dan Hendrycks, Thomas Authors, and Mantas Mazeika. 2023. An Overview of Catastrophic AI Risks. https://arxiv.org/pdf/2306.12001 [71] Dan Hendrycks, Dawn Song, Christian Szegedy, Honglak Lee, Yarin Gal, Erik Brynjolfsson, Sharon Li, Andy Zou, Lionel Levine, Bo Han, Jie Fu, Ziwei Liu, Jinwoo Shin, Kimin Lee, Mantas Mazeika, Long Phan, George Ingebretsen, Adam Khoja, Cihang Xie, and Olawale Salaudeen. 2025. A Definition of AGI. https://arxiv.org/abs/2510.18212 [72] Human Rights Committee. 1989.General Comment No. 18: Non- discrimination. https://w.refworld.org/legal/general/hrc/1989/6268 UN Doc. HRI/GEN/1/Rev.9 (Vol. I), p. 191. [73] IDF. 2024.Israel Defence Forces’ response to claims about use of “Lavender” AI database in Gaza.The Guardian (Apr 2024). https://w.theguardian.com/world/2024/apr/03/israel-defence-forces- response-to-claims-about-use-of-lavender-ai-database-in-gaza [74]Amnesty International. 2012. Urumqi Riots three years on - crackdown on Uighurs grows bolder. https://w.amnesty.org/en/latest/press-release/2012/ 07/urumqi-riots-three-years-crackdown-uighurs-grows-bolder/ [75]IPVM. 2021. IPVM Full Testimony at Uyghur Tribunal, September 12, 2021. https://w.youtube.com/watch?v=SJQmeskvhvw [76]Leo Kelion. 2021. Huawei patent mentions use of Uighur-spotting tech. https: //w.bbc.com/news/technology-55634388 [77]Philipp Kernstock, Constantin Harms, Andreas Hein, and Helmut Krcmar. 2025. Establishing and governing data ecosystems at the crossroads of centralization and decentralization. Electronic Markets 35, 1 (Jul 2025). doi:10.1007/s12525- 025-00810-x [78] Gary King, Jennifer Pan, and Margaret Roberts. 2013. How Censorship in China Allows Government Criticism but Silences Collective Expression. American Polit- ical Science Review 107, 02 (May 2013), 326–343. doi:10.1017/s0003055413000014 [79]Jason Koebler. 2025. Emails Reveal the Casual Surveillance Alliance Between ICE and Local Police.https://w.404media.co/emails-reveal-the-casual- surveillance-alliance-between-ice-and-local-police/ [80]Kommersant. 2021. Moscow authorities have assured that the personal data of mos.ru users will not be shared with the police. https://w.kommersant.ru/ doc/5030021 [81]Nikita Korolev and Alexey Zhabin. 2024. Biometrics is spreading across the regions. https://w.kommersant.ru/doc/6444994 [82]National Physical Laboratory. 2020. Metropolitan Police Service Live Facial Recognition Trials. https://w.met.police.uk/syssiteassets/media/downloads/ central/services/accessing-information/facial-recognition/met-evaluation- report.pdf [83] Marie Lamensch. 2021. Authoritarianism Has Been Reinvented for the Dig- ital Age.https://w.cigionline.org/articles/authoritarianism-has-been- reinvented-for-the-digital-age/ [84]Garett Langley. 2025. Flock Safety CEO addresses mass surveillance, access concerns. https://w.youtube.com/watch?v=aMfO7D-f7U0 [85]Tim Lau. 2020. Predictive Policing Explained. https://w.brennancenter.org/ our-work/research-reports/predictive-policing-explained [86]Kenneth C. Laudon. 1986. Data quality and due process in large interorganiza- tional record systems. Commun. ACM 29, 1 (Jan 1986), 4–11. doi:10.1145/5465. 5466 [87]Steven Levitsky and Lucan Way. 2002. Elections without Democracy: the Rise of Competitive Authoritarianism. Journal of Democracy 13, 2 (2002), 51–65. [88]Fan Liang, Vishnupriya Das, Nadiya Kostyuk, and Muzammil M. Hussain. 2018. Constructing a Data-Driven Society: China’s Social Credit System as a State Surveillance Infrastructure. Policy and Internet 10, 4 (Aug 2018), 415–453. doi:10. 1002/poi3.183 [89]Alexander Libman and Anastassia V. Obydenkova. 2018. Understanding Au- thoritarian Regionalism. Journal of Democracy 29, 4 (2018), 151–165. doi:10. 1353/jod.2018.0070 [90] Lighthouse-Reports. 2025. City of Amsterdam GitHub Repo for Model Training and Scoring.https://github.com/Lighthouse-Reports/amsterdam_fairness/ tree/main/wpi_uitkeringsfraude/Repo%20wpi-onderzoekswaardigheid- aanvraag%20-%20based%20on%20dev%20branch%20commit%20069435abe [91] Juan J Linz. 1964. An Authoritarian Regime : Spain. Tidnings Och Tryckeri Aktiebolag, Abo (Finlandia). 255 pages. [92] Peter Lorentzen. 2014. China’s Strategic Censorship. American Journal of Political Science 58, 2 (Oct 2014), 402–414. doi:10.1111/ajps.12065 [93]Dave Maass and Rindala Alajaji. 2025.How Cops Are Using Flock Safety’s ALPR Network to Surveil Protesters and Activists.https: //w.eff.org/deeplinks/2025/11/how-cops-are-using-flock-safetys-alpr- network-surveil-protesters-and-activists [94]Federico Mantellassi. 2023. GCSP Publication | Digital Authoritarianism: How Digital Technologies Can Empower Authoritarianism and Weaken Democ- racy. https://w.gcsp.ch/publications/digital-authoritarianism-how-digital- technologies-can-empower-authoritarianism-and [95]Lena Masri. 2023. Facial recognition is helping Putin curb dissent with the aid of U.S. tech. https://w.reuters.com/investigates/special-report/ukraine-crisis- russia-detentions/ [96]Achille Mbembe and Steve Corcoran. 2019. Necropolitics. Duke University Press. [97]Oier Mentxaka, Natalia Díaz-Rodríguez, Mark Coeckelbergh, Marcos López, Emilia Gómez, David Fernández Llorca, Enrique Herrera-Viedma, and Francisco Herrera. 2025. Aligning Trustworthy AI with Democracy: A Dual Taxonomy of Opportunities and Risks. arXiv (Cornell University) (May 2025). doi:10.48550/ arxiv.2505.13565 [98]Moscow Metro. 2022.Moscow Metro ticketing: your face here. https://w.itsinternational.com/feature/moscow-metro-ticketing-your- face-here#:~:text=What%20did%20you%20learn%20from,and%20speeding% 20up%20the%20service [99] Melinda Mills and B Rihoux. 2008. Comparative Analysis. SAGE Publications, Inc. https://doi.org/10.4135/9781412963909.n54 [100]Marika Miner, Natalia Natsika, and Staffan Lindberg. 2024. Internet Shutdowns Shutting Down Democracy. https://v-dem.net/media/publications/PB_40.pdf [101]Johnson Mohamed. 2025. California police are illegally sharing license plate data with ICE and Border Patrol. https://calmatters.org/economy/technology/ 2025/06/california-police-sharing-license-plate-reader-data/ [102]Bryce Neary. 2022. Tech and A ech and Authoritarianism: How the People’s Republic of China is Using Data to Control Hong Kong and Why The U.S. is Vulnerable. Seattle Journal of Technology, Environmental and Innovation Law 12, 1 (2022). [103]NEC. 2017. NEC provides facial recognition system to South Wales Police in the UK. https://uk.nec.com/en_GB/press/201707/global_20170711_01.html [104] Madeline Neighly and Maurice Emsellem. 2013. WANTED: Accurate FBI Back- ground Checks for Employment. https://w.nelp.org/app/uploads/2015/03/ Report-Wanted-Accurate-FBI-Background-Checks-Employment.pdf [105]BBC News. 2018. 2,000 wrongly matched with possible criminals at Champions League. BBC News (May 2018). https://w.bbc.com/news/uk-wales-south- west-wales-44007872 [106]Vincent Ni. 2021.Documents link Huawei to Uyghur surveil- lance projects, report claims.the Guardian (Dec 2021).https: //w.theguardian.com/technology/2021/dec/15/documents-link-huawei- uyghur-surveillance-projects-report-claims Preprint, 2026, OnlineJeba Sania, Marta Ziosi & Fazl Barez [107]Michelle Nie. 2024. Artificial Intelligence: The Biggest Threat to Democracy Today? Proceedings of the AAAI Symposium Series 3, 1 (May 2024), 376–379. doi:10.1609/aaaiss.v3i1.31239 [108] Marina Nord, David Altman, Fabio Angiolillo, Tiago Fernandes, Ana Good God, and Staffan Lindberg. 2024. Democracy Report 2025: 25 Years of Autocratization – Democracy Trumped? [109] Department of Commerce of Xinjiang Uygur Autonomous Region. 2019. Multi- ple measures to promote the healthy and orderly development of the automotive industry. https://web.archive.org/web/20201113184427/https://scyxs.mofcom. gov.cn/article/qclt/df jy/201909/20190902896439.shtml [110]Home Office. 2025. Live Facial Recognition technology to catch high-harm offenders.https://w.gov.uk/government/news/live-facial-recognition- technology-to-catch-high-harm-offenders [111]Home Office. 2025.Police use of facial recognition: factsheet. https://w.gov.uk/government/publications/police-use-of-facial- recognition/police-use-of-facial-recognition-factsheet [112]ACLU Oregan. 2025. Know Your Tech: Flock - ACLU of Oregon. https://w. aclu-or.org/know-your-tech-flock/ [113]Shai Oster. 2016. China Tries Its Hand at Pre-Crime. https://w.bloomberg. com/news/articles/2016-03-03/china-tries-its-hand-at-pre-crime [114]OVD-Info. 2022. How the Russian state uses cameras against protesters. https: //reports.ovd.info/en/how-russian-state-uses-cameras-against-protesters#1 [115]OVD-Info. 2022. Repressions in Russia in 2022. https://ovd.info/en/repressions- russia-2022#1 [116]Catherine Owen. 2022. Varieties of authoritarianism, and How They Might Be Studied. https://theloop.ecpr.eu/varieties-of-authoritarian-regime-and-how- they-might-be-studied/ [117] Greg Oxley, Allwell Uwazuruike, Maria Lalic, Harriet Samuel, and William Downs. 2024. Police use of live facial recognition technology. https://researchbriefings.files.parliament.uk/documents/CDP-2024-0144/CDP- 2024-0144.pdf [118] Lacin Idil Oztig. 2023. Big data-mediated repression: a novel form of preemptive repression in China’s Xinjiang region. Contemporary Politics 29, 5 (Apr 2023), 1–22. doi:10.1080/13569775.2023.2203568 [119] Lacin Idil Oztig and Abdurresit Celil Karluk. 2025. China’s High-Tech Repression Against Uyghurs: Novel Theoretical Insights. Springer Nature Switzerland, Cham. doi:10.1007/978-3-031-82287-2 [120] Javier Pastor-Galindo, Pantaleone Nespoli, and José A Ruipérez-Valiente. 2024. Large-Language-Model-Powered Agent-Based Framework for Misinformation and Disinformation Research: Opportunities and Open Challenges. IEEE security and privacy 22, 3 (May 2024), 24–36. doi:10.1109/msec.2024.3380511 [121]James S. Pearson. 2024. Defining digital authoritarianism. Philosophy and; Technology 37, 2 (Jun 2024). doi:10.1007/s13347-024-00754-8 [122] Alcides Eduardo dos Reis Peron, David Almstadter Mattar de Magalhães, and Gabriel Fernandes Caetano. 2025. Beyond digital repression: techno- authoritarianism in radical right governments. Cogent Social Sciences 11, 1 (Jul 2025). doi:10.1080/23311886.2025.2528457 [123]Dahlia Peterson. 2021. How China harnesses data fusion to make sense of surveillance data. https://w.brookings.edu/articles/how-china-harnesses- data-fusion-to-make-sense-of-surveillance-data/ [124] South Wales Police. 2017. Automated Facial Recognition Solution - Contracts Finder. https://w.contractsfinder.service.gov.uk/Notice/6281c974-6fd5-4632- ab1b-9f9ef3510b2e [125] Alla Polishchuk. 2024. AI Poses Risks to Both Authoritarian and Democratic Politics | Wilson Center. https://w.wilsoncenter.org/blog-post/ai-poses- risks-both-authoritarian-and-democratic-politics [126]Alina Polyakova and Chris Meserole. 2019. Exporting digital authoritari- anism: The Russian and Chinese models.https://w.brookings.edu/wp- content/uploads/2019/08/FP_20190827_digital_authoritarianism_polyakova_ meserole.pdf [127]Alicia Raeburn. 2024. Product Development Process: 6 Stages (With Examples). https://asana.com/resources/product-development-process [128]Rashida Richardson, Jason Schultz, and Kate Crawford. 2019. Dirty Data, Bad Predictions: How Civil Rights Violations Impact Police Data, Predictive Policing Systems, and Justice. https://papers.ssrn.com/sol3/papers.cfm?abstract_id= 3333423. [129]Margaret E Roberts. 2018. CENSORED : distraction and diversion inside china’s great firewall. Princeton University Pres, S.L. [130] Tony Roberts and Marjoke Oosterom. 2024. Digital authoritarianism: a system- atic literature review. Information Technology for Development 31, 4 (Nov 2024), 1–25. doi:10.1080/02681102.2024.2425352 [131]Charles Rollet. 2019. Hikvision Markets Uyghur Ethnicity Analytics, Now Covers Up. https://ipvm.com/reports/hikvision-uyghur [132]Maria A Rujano, Jan-Willem Boiten, Christian Ohmann, Steve Canham, Sergio Contrino, Romain David, Jonathan Ewbank, Claudia Filippone, Claire Connellan, Ilse Custers, Rick van Nuland, Michaela Th Mayrhofer, Petr Holub, Eva García Ál- varez, Emmanuel Bacry, Nigel Hughes, Mallory A Freeberg, Birgit Schaffhauser, Harald Wagener, and Alex Sánchez-Pla. 2024. Sharing sensitive data in life sciences: an overview of centralized and federated approaches. Briefings in Bioinformatics 25, 4 (May 2024). doi:10.1093/bib/bbae262 [133] Pjotr Sauer. 2021. Privacy fears as Moscow metro rolls out facial recognition pay system. https://w.theguardian.com/world/2021/oct/15/privacy-fears- moscow-metro-rolls-out-facial-recognition-pay-system [134] Andreas Schedler. 2002. Elections without Democracy: The Menu of Manipula- tion. Journal of Democracy 13, 2 (2002), 36–50. [135] Andreas Schedler. 2015. Electoral Authoritarianism. John Wiley and Sons, Inc. doi:10.1002/9781118900772.etrds0098 [136]Oliver Schlumberger, Mirjam Edel, Ahmed Maati, and Koray Saglam. 2023. How Authoritarianism Transforms: A Framework for the Study of Digital Dictator- ship. Government and Opposition 59, 3 (Jul 2023), 1–23. doi:10.1017/gov.2023.20 [137]Jon Schuppe. 2019.Amazon is developing high-tech surveillance tools for an eager customer: America’s police.NBC News (Aug 2019). https://w.nbcnews.com/tech/security/amazon-developing-high-tech- surveillance-tools-eager-customer-america-s-n1038426 [138] James C. Scott. 1998. Seeing like a state how certain schemes to improve the human condition have failed. Yale University Press. [139]Andrea Signorelli. 2024. How Russia Built Its Digital Gulag. https://conflicts. digital/p/how-russia-built-its-digital-gulag [140] Dan Slater. 2010. Ordering power : contentious politics and authoritarian leviathans in Southeast Asia. Cambridge University Press, Cambridge ; New York. [141]Dan Slater. 2018. Violent Origins of Authoritarian Variation: Rebellion Type and Regime Type in Cold War Southeast Asia. Government and Opposition 55, 1 (May 2018), 1–20. doi:10.1017/gov.2018.4 [142]Sergey Sobyanin. 2026.Securly - Geolocation sharing.https://x.com/ MosSobyanin/status/1448738116571906051 [143]Marta Sofia, Maria Anastasiadou, and Vitor Santos. 2024. Framework for the application of explainable artificial intelligence techniques in the service of democracy. Transforming Government People Process and Policy 18, 4 (Jul 2024). doi:10.1108/tg-02-2024-0030 [144]IPVM Editorial Staff. 2021. Patenting Uyghur Tracking - Huawei, Megvii, More. https://ipvm.com/reports/patents-uyghur [145] Jay Stanley. 2022. Fast-Growing Company Flock is Building a New AI-Driven Mass- Surveillance System. https://w.aclu.org/wp-content/uploads/publications/ flock_1.pdf [146]Victor Startsev. 2022. Russians’ biometric data will be merged into a state database without their knowledge. What are the risks? Novosibirsk City Site (2022). https://ngs.ru/text/world/2022/08/08/71550350/ [147] Litska Strikwerda. 2020. Predictive policing: The risks associated with risk assessment. The Police Journal: Theory, Practice and Principles 94, 3 (Aug 2020), 0032258X2094774. doi:10.1177/0032258x20947749 [148] Milan W Svolik. 2012. The Politics of Authoritarian Rule. Cambridge University Press, New York. 3,85–119 pages. [149] TAUVOD. 2023. AI in Defense - Digital Transformation and AI in the Intelligence Domain (AI Week TLV). https://w.youtube.com/watch?v=CJvOoX7dK1M [150]Matthew Tokson. 2025. The Authoritarian Risks of AI Surveillance. https: //w.lawfaremedia.org/article/the-authoritarian-risks-of-ai-surveillance? [151]Daniel Treisman and Sergei Guriev. 2023. Spin Dictators. Princeton University Press. [152]UN. 2024. UN / GAZA GUTERRES | UNifeed. https://media.un.org/unifeed/en/ asset/d319/d3193884 [153] Hamid Akin Unver. 2018. Artificial Intelligence, Authoritarianism and the Future of Political Systems. https://papers.ssrn.com/sol3/papers.cfm?abstract_ id=3331635 [154]Dimitrios Vagianos and Glykeria Stavrou. 2023. Surveillance Infrastructure and Artificial Intelligence Challenging Democracy and Human Rights in China. The Cyprus Journal of Sciences 20 (2023). [155]Yamil Ricardo Velez and Howard Lavine. 2017. Racial Diversity and the Dy- namics of Authoritarianism. The Journal of Politics 79, 2 (Apr 2017), 519–533. doi:10.1086/688078 [156] VisionLabs. 2026. VisionLabs. https://visionlabs.ai/about-us [157]Jane Wakefield. 2021. AI emotion-detection software tested on Uyghurs. BBC News (May 2021). https://w.bbc.com/news/technology-57101248 [158]Maya Wang. 2019.China’s Algorithms of Repression.https: //w.hrw.org/report/2019/05/01/chinas-algorithms-repression/reverse- engineering-xinjiang-police-mass [159] Maya Wang. 2019. Interview: China’s “Big Brother” App. https://w.hrw. org/news/2019/05/01/interview-chinas-big-brother-app [160]Human Rights Watch. 2018. China: Big Data Fuels Crackdown in Minority Re- gion. https://w.hrw.org/news/2018/02/27/china-big-data-fuels-crackdown- minority-region [161]Human Rights Watch. 2020. China: Big Data Program Targets Xinjiang’s Mus- lims. https://w.hrw.org/news/2020/12/09/china-big-data-program-targets- xinjiangs-muslims [162]Human Rights Watch. 2024. Questions and Answers: Israeli Military’s Use of Digital Tools in Gaza. https://w.hrw.org/news/2024/09/10/questions-and- From Democracies to Autocracies: How AI Systems Enable Authoritarianism by DesignPreprint, 2026, Online answers-israeli-militarys-use-digital-tools-gaza#_What_are_some [163]Kate Whannel. 2025. Government expands police use of live facial recognition vans. British Broadcasting Company (Aug 2025). https://w.bbc.com/news/ articles/cj4wy21dwkwo [164]Marcus White. 2025. Police facial recognition vans in Hampshire and Isle of Wight. BBC News (Dec 2025). https://w.bbc.com/news/articles/ce91ddjy14ko [165]Ronald Wintrobe. 1998. The political economy of dictatorship. Cambridge Univ. Press, Cambridge. 20–40 pages. [166] Brigadier General Y.S. 2021. The human machine team : how to create syn- ergy between human and artificial intelligence that will revolutionize our world. Ebookpro Publishing. 26–57 pages. [167]Jiaona Zhang and Anand Subramani. [n. d.]. Reforge. https://w.reforge. com/blog/product-development-process [168]Marta Ziosi and Dasha Pruss. 2024. Evidence of What, for Whom? The Socially Contested Role of Algorithmic Bias in a Predictive Policing Tool. The 2024 ACM Conference on Fairness, Accountability, and Transparency (Jun 2024). doi:10.1145/ 3630106.3658991 [169]Shoshana Zuboff. 2019. The age of surveillance capitalism. Profile Books, London. [170]H. Akin Ünver. 2024.Artificial intelligence (AI) and human rights: Using AI as a weapon of repression and its impact on human rights. https://w.europarl.europa.eu/RegData/etudes/IDAN/2024/754450/EXPO_ IDA%282024%29754450_EN.pdf A Appendix Preprint, 2026, OnlineJeba Sania, Marta Ziosi & Fazl Barez Table 2: System Mapping Against Inclusion Criteria System NamePresence of Artificial IntelligenceSystem ClassificationPolitical Regime Classification FlockSafetyAuto- mated License Plate Recognition (ALPR) While the AI/ML model is not known, the system is deduced to have computer vision capabilities based on its use case. SurveillanceLiberal Democracy[108], Free[61] Live Facial Recogni- tion (LFR) Vans The system is confirmed to be AI/ML-based, as verified by vendor and third-party testing[64]. As of 2013, the system relied on a modified Generalized Learning Vector Quantization (GLVQ) algorithm[9]. SurveillanceElectoral Democracy[108], Free[61] SlimmeCheckThe system is confirmed to be AI/ML-based, according to developers and third-party testers. It relies on an ex- plainable boosting machine algorithm[20]. Predictive PolicingLiberal Democracy[108], Free[61] LavenderThe system is confirmed to be AI/ML-based, as indicated by its developer. The system leverages positive unlabeled learning[149, 162]. Predictive PolicingElectoral Democracy[108], Free[61] IntegratedJoint Operations Platform (IJOP) The surveillance apparatus part of the system is con- firmed to be AI/ML-based on its various developers[144]. Surveillance,Predictive Policing Closed Autocracy[108], Not Free[61] SferaThe system is confirmed to be AI/ML-based on its developers[31, 64, 156]. Surveillance,Predictive Policing Electoral Autocracy[108], Not Free[61] Table 3: Mapping of Authoritarian Characteristics to Enabling Features and Deployed Systems. Authoritarian CharacteristicEnabling FeatureSystem Coercive Capacity Integration with Lethal Military InfrastructureLavender Insufficient Accuracy RatesLavender Widespread Data IntegrationALPR System; IJOP; LFR Vans; Sfera Integration with Outdated DatabasesALPR System Co-optation of Administrative SystemsIJOP; LFR Vans; Sfera Accountability Erosion Inconsistent Operating ProceduresLFR Vans Overreliance on Automated Decision-MakingLavender Oversight Loopholes for Non-state Actors and Private Citi- zens/Organizations ALPR System Regulatory Gap and Exemption for Law EnforcementSfera Symbolic Safeguards Lack of Compliance MechanismsALPR System; Lavender Inconsistent Operating ProceduresALPR System Information Control Widespread Data IntegrationIJOP Co-optation of Administrative SystemsIJOP; Sfera Anticipatory Repression Co-optation of Administrative SystemsSfera Predictive Behavioural IndicatorsIJOP Arbitrary IndicatorsIJOP Boundary Control Explicit Group-Based ClassificationIJOP Arbitrary IndicatorsLavender Biased Training DataSlimmeCheck Encoding of Protected Group CharacteristicsSlimmeCheck