This is the second installment of Where We Stand: Position, Proximity, and Power in AI Safety.
The first piece in this series focused on the user, the person sitting in front of the screen. As users, we can decide what to ask, what to share, how carefully to check the answer, and how much authority to give the system. Those choices do not eliminate risk, but they give us some agency.
The second position is different. You become the subject when an AI system is not working for you but is being used to observe, classify, predict, rank, or create knowledge about you. Someone else chooses the system and controls how it is used. You may never see the interface or even know that the system exists.
That difference becomes especially clear with Flock cameras.
Flock Safety operates a large network of automated license plate readers. Police departments and other organizations use the cameras to capture license plates, vehicle characteristics, time, and location. These systems can serve legitimate public purposes. Departments use them to investigate crimes, locate stolen vehicles, and search for missing people. An Associated Press overview of Flock captures both their usefulness and the concerns surrounding their rapid expansion.
But the police department is the user. The person driving past the camera is the subject. Flock often refers to its customers as “communities.” But in this context, the customer is usually a police department or another organization operating the cameras. The people whose movements are being recorded are part of the community too, yet they do not control the system or the data it creates.
That distinction matters. Saying that a community controls its data suggests a degree of shared public agency that may not exist. In practice, control sits with the institution that purchased the system, while many of the people represented in the data had no role in choosing it or establishing its limits.
That person did not choose the system. They may not know where the cameras are, how long the information is retained, who can search it, what other information it can be combined with, or where it may travel next. They may have done nothing wrong and may never be investigated, but a record about their movements has still been created.
This is not mainly a story about whether a camera can read a license plate correctly. It is a story about what happens after that observation becomes data.
The power is in the join
I see the power of linked data every day in my work. A single dataset usually gives you one narrow view of a person or a program. When you connect datasets, you can begin to see patterns that were previously invisible.
That can produce real public value.
Rhode Island, for example, connected information from developmental screenings, early intervention, health programs, early childhood care, and education. Linking those records allowed the state to ask whether children who failed developmental screenings were referred, evaluated, and connected to services. It could also examine whether children who were missed later required special education.
None of the individual datasets could answer those questions alone. The insight came from the join. The goal was not simply to collect more information. It was to understand where children were falling through the cracks and improve how public systems served them. The federal government’s report on integrating early childhood data also describes safeguards including parental notice, opportunities to opt out, controlled access, and formal data-sharing agreements.
The same principle applies to surveillance data.
One observation of a license plate at a particular time and place may not reveal very much. A series of observations can begin to show a routine. Combine those observations with vehicle registration, home addresses, police records, commercial information, or other location data, and the system may be able to infer where someone lives, works, worships, receives medical care, or spends time with other people. The Electronic Frontier Foundation’s overview of automated license plate readers explains how aggregated location records can reveal far more than an isolated photograph.
The join is not inherently good or bad. The Rhode Island example shows how linked data can help institutions identify gaps and improve services. The Flock example shows how the same capability can create knowledge about people who have little visibility into the process.
The difference lies in purpose, safeguards, and agency.
What we know and what we cannot see
Concerns about Flock often become entangled with Palantir because there is a real financial connection between the companies, although it is important to describe that connection accurately.
Peter Thiel co-founded Palantir and remains its chairman. He is also a partner at Founders Fund, which has invested in Flock and participated in its 2025 funding round. Palantir builds software designed to integrate and analyze information from many different sources. Its own materials describe Foundry as a platform for connecting data across systems.
That connection is worth noticing because it illustrates the growing ecosystem around government and surveillance data. It is not, however, evidence that Flock is sending data directly to Palantir.
Flock says that it does not work with Palantir, that Palantir has no access to its customer data, and that Flock data is not shared with Palantir. I have not found public evidence of a direct Flock-to-Palantir feed.
The problem is not that we should assume a secret connection. The problem is that an ordinary person has no practical way to see every search, export, integration, derived record, or downstream use involving data about them and must trust that Flock and Palantir are operating in the interest of the common good. Evidence may eventually surface through contracts, audit logs, public-records requests, litigation, investigations, or required disclosures. But those are not routine, subject-facing forms of accountability.
We already know that data can move beyond the context in which people assume it is being collected. The Associated Press reported that Border Patrol previously had access to data from at least 1,600 Flock readers across 22 states. Some local agencies also reportedly conducted searches on behalf of federal authorities.
This does not prove that every department is misusing its system. It does show why “our police department owns the data” is not a complete answer. Access can expand through sharing arrangements, regional networks, exports, integrations, and requests from other agencies.
Public safety requires public trust
Flock cameras are generally purchased in the name of a public good: safer communities, faster investigations, recovered vehicles, missing people found, and serious crimes solved. Those benefits matter. It would be too easy to dismiss them or pretend that communities do not have real safety problems they want public institutions to address.
But the public good cannot be defined only as the institution’s ability to collect more information or solve cases more efficiently. It also includes civil liberties, equal treatment, freedom of movement and association, and confidence that public power is being used within limits.
Trust is part of that public good.
Public trust does not mean asking people to take an agency’s assurances on faith. It comes from being able to form reasonable expectations about what an institution will do, seeing evidence that the rules are being followed, and having somewhere to go when they are not. The NIST AI Risk Management Framework treats transparency and accountability as foundations of trustworthy systems, including for people who may not even realize they are interacting with one.
This matters because the relationship between a public agency and a resident is not the same as the relationship between a company and a customer. A resident cannot simply choose another police department. In many cases, they cannot avoid the system, decline its terms, or remove themselves from its dataset.
That means a procurement decision can also be a public policy decision. Buying the technology determines what the government will be capable of knowing, whom it can monitor, which other institutions can gain access, and how long those capabilities may persist. If those decisions happen primarily between a vendor and a police department, the people who will become the subjects are left out of deciding what the public good requires.
A system can produce useful results and still damage trust if people believe its reach is hidden, unlimited, or impossible to challenge. Once that trust is lost, publishing another reassurance may not repair it. Institutions have to show that boundaries exist before a controversy exposes how weak they were.
The agency gap
The central problem is not simply data collection. It is the distance between the power of the system and the agency of the person described by it.
The NIST Privacy Framework offers two useful ideas for thinking about this. The first is predictability, or whether people can form reasonable expectations about how their data will be used. The second is manageability, or whether they have any ability to alter, delete, limit, or selectively disclose that information.
A person driving past a Flock camera may have neither. They cannot reasonably predict every future use of the record, and they cannot meaningfully manage it. They may also lack notice, access, an opportunity to correct an error, or a way to challenge a harmful use.
For public systems, those protections cannot depend entirely on individual action. Most people do not have the time or expertise to file records requests, investigate vendor contracts, and interpret data-sharing agreements. The responsibility has to sit with the institutions choosing and governing the technology.
Residents, journalists, elected officials, oversight boards, and public employees can still push for specific answers:
What public problem is this system meant to solve, and how will success be measured?
What information is collected, and how long is it retained?
Who can search the system, and what reason must they provide?
Which agencies, vendors, and other organizations can receive the data?
Can the information be linked with other datasets? If so, which ones and for what purposes?
Are all searches, exports, and sharing requests logged and independently audited?
What happens when someone misuses the system?
Can a person learn whether inaccurate data affected an investigation or decision and have it corrected?
Will the agency publish aggregate statistics about searches, matches, sharing, violations, and outcomes?
Those questions only matter if the answers become enforceable rules. That can mean retention limits, written search standards, restrictions on data sharing, public reporting, independent audits, contract provisions, penalties for misuse, and expiration dates requiring a system to be reconsidered rather than renewed automatically.
The goal is not to prevent government from using useful technology. It is to make sure that usefulness is judged alongside the rights of the people who supply the data simply by moving through public space.
When someone else is the user
Flock cameras are one example of what it means to be the subject of an AI or data system. The same position appears when software analyzes an employee’s productivity, predicts a family’s risk, ranks a student, flags a benefits application, estimates a patient’s future behavior, or uses online activity to infer something a person never directly disclosed.
In each case, the institution is the user. The person being described is the subject.
The safety question is therefore larger than whether the system works as designed. We also have to ask who can see what it is doing, who receives the benefit, who carries the risk, and whether the people affected have any meaningful voice in setting the rules.
A join creates new knowledge, and new knowledge creates power. When that power is exercised by a public institution, public trust cannot be treated as an obstacle to efficiency. It is one of the outcomes the system should be designed to protect.
The power is in the join. Safety depends on whether that join serves a publicly defined good and whether it is visible, limited, auditable, and open to challenge.
Anthralytic, I helps organizations use data and AI to solve real problems without losing sight of the people represented in the data. Through consulting and practical digital tools, I help teams build systems that are useful, responsible, and worthy of public trust.

