Two connected learning models Explore the linear model at KillChains.com

Preserved research input · KW-RPT-024

Predictive Public Security in China: IJOP, Police Cloud, Skynet, Sharp Eyes, and the Expansion of Proactive Policing — Part 2

A comparative continuation examining proactive policing, person-risk flags, base-rate problems, circular data production, international comparisons, and governance boundaries.

Digest verified 90d111a22dbefafc7628b9a0d65991148ccc00e74468bc170595ff649956f776

Predictive Public Security in China: IJOP, Police Cloud, Skynet, Sharp Eyes, and the Expansion of Proactive Policing

Executive findings, scope, and evidentiary method

Central assessment

China’s predictive-public-security landscape is not one national artificial-intelligence platform. It is a layered and uneven institutional ecosystem: central political and Ministry of Public Security policy; national police networks and technical standards; provincial “Police Cloud” and public-security big-data platforms; municipal command, video, and warning projects; neighborhood-level governance and information collection; commercial cameras, analytics, cloud infrastructure, and system integration; and, in Xinjiang, region-specific systems built for an unusually coercive counterterrorism and “stability maintenance” campaign. These layers may exchange data or follow common standards without sharing one database, one model, one vendor, or one command structure. Evidence of interoperability is therefore not evidence of unification. citeturn0search23turn3view3turn5view1turn5view2turn17search4

The Integrated Joint Operations Platform, or IJOP, is the best-documented Chinese example of person-focused, proactive public-security analytics. Publicly available evidence indicates that it aggregated information from police records, checkpoints, identity documents, vehicles, communications-related sensors, household visits, utilities, and other sources; applied many relatively simple rule-based conditions; and generated investigative tasks or warnings concerning named people, relationships, locations, or behavior considered abnormal. The strongest technical evidence comes from Human Rights Watch’s reverse engineering of a 2017 police mobile application used with the platform. That evidence is unusually granular about fields, queries, and workflow, but it does not reveal the server-side code, all data sources, model weights, decision thresholds, or the platform’s current configuration. citeturn3view1turn16view0turn16view1turn16view2turn16view3

The available evidence does not support describing IJOP primarily as a sophisticated machine-learning crime-prediction model. The analyzed application exposed numerous conditional rules and structured forms, while the central analytics remained a black box. Its significance lies less in demonstrated predictive accuracy than in its institutional function: converting pervasive data collection into a continuous stream of suspicion, investigation, checkpoint interception, home visits, questioning, movement controls, and, in documented cases, referral into detention systems. In that respect, “predictive” describes anticipatory governance and prospective intervention, not necessarily a statistically validated forecast. citeturn16view0turn18search0turn18search1

Police Cloud systems elsewhere in China are better understood as provincial or municipal data-fusion and analytical infrastructures than as one standardized model. Procurement records reviewed by Human Rights Watch described systems designed to consolidate diverse personal and administrative records, reconstruct relationships, locate people, identify unusual conduct, and support warnings or police targeting. Yet a tender describes what an authority seeks to purchase, not what was ultimately delivered, used, or validated. Later maintenance and official publicity show that police-cloud and public-security big-data infrastructure continued after the initial mid-2010s buildout, but public evidence remains too fragmented to establish a uniform national feature set. citeturn3view3turn8search9turn9search5

Golden Shield, Skynet, and Sharp Eyes occupy different architectural roles. Golden Shield was a broad police-informatization program and network-and-database foundation, not merely a synonym for internet filtering and not itself one predictive model. “Skynet” generally denotes urban public-security video networks and associated command or recognition functions. “Sharp Eyes” extended video networking and community-level governance toward counties, townships, villages, residential compounds, and non-police camera owners, often with explicit requirements for sharing or interoperability with existing Skynet resources. The labels have varied across time and locality; newer projects are often marketed instead as public-security big-data intelligent platforms, integrated intelligence-command-operations systems, social-security prevention and control systems, or “proactive policing” mechanisms. citeturn2search4turn5view1turn2search2turn0search7turn0search11turn22search23

From 2024 through August 2, 2026, official and procurement sources document a shift toward large-language-model interfaces, locally deployed generative models, automated incident summarization, knowledge retrieval, entity linking, video anomaly detection, model-assisted case analysis, dispute-risk warnings, and integrated command. The evidence is strongest that these tools are being purchased, piloted, publicized, or used for workflow support. It is much weaker for claims that generative AI independently predicts crimes, protests, or violence with validated accuracy. Some systems clearly generate warnings; others merely retrieve records or draft reports. Treating every “AI police” announcement as predictive policing would collapse meaningful distinctions between search, identification, analysis, forecasting, and coercive decision-making. citeturn22search1turn22search3turn22search6turn22search14turn22search20turn22search23turn22search25

No credible public randomized trial, controlled quasi-experiment, or independently reproducible evaluation establishes that IJOP, Police Cloud, Skynet, or Sharp Eyes caused a specified reduction in terrorism or ordinary crime. Official accounts frequently cite arrests, recovered property, warnings, cases solved, or periods without attacks, but rarely publish denominators, false-positive rates, comparison groups, model specifications, or displacement effects. In Xinjiang, any before-and-after comparison is further confounded by mass police mobilization, checkpoints, restrictions on movement and communication, intensive neighborhood surveillance, detention, and changes in how authorities define and record “terrorism,” “extremism,” and public disorder. citeturn2search22turn9search15turn18search2turn18search4

The legal picture is similarly dual. China’s Personal Information Protection Law contains purpose limitation, necessity, data-quality obligations, special rules for sensitive information, safeguards for public-place image collection, impact-assessment duties, and a right to an explanation where a solely automated decision has a major effect. The 2025 regulations governing public-security video systems add planning, filing, signage, access-control, logging, retention, and use restrictions. Yet police and state bodies may process information to perform statutory duties without consent; notice and access may be restricted where disclosure would impede official functions; national-security, counterterrorism, state-secret, and public-security rationales remain broad; and public evidence of successful individual challenges to police risk profiles is extremely limited. Formal data-protection language therefore should not be equated with an EU-style independent supervisory and judicial-remedy environment. citeturn12view0turn12view1turn12view2turn23search0turn12view3turn12view4turn12view5

Internationally, the most serious issues are not the use of algorithms in the abstract but the combination of pervasive surveillance, discriminatory targeting, arbitrary deprivation of liberty, suppression of religion and expression, guilt by association, and absence of an effective opportunity to contest state-held information. The Office of the UN High Commissioner for Human Rights concluded in 2022 that serious violations had occurred in Xinjiang and that the scale of arbitrary and discriminatory detention could constitute international crimes, particularly crimes against humanity. China rejected the assessment, characterized its policies as lawful counterterrorism and vocational education, and argued that they had protected lives and development. citeturn18search2turn18search16turn15search0turn15search1turn15search11

Working definition

This report uses predictive public security to mean a computational or highly structured information system that does more than retrieve a known record and that produces a prospective judgment, alert, priority, or intervention recommendation concerning future crime, disorder, protest, violence, “instability,” or a person’s future relevance to those risks.

That definition includes both machine-learning models and rule-based systems where automated rules operationalize anticipatory suspicion. It excludes a camera that merely records footage, a database that returns an exact identity match, or an LLM that only reformats an officer’s report. Those technologies become part of predictive public security when their outputs feed prospective targeting—for example, when identity matches are combined with relationships, travel, or behavior to generate a warning that a person should be stopped.

Four analytically distinct outputs recur:

Output typeObject of inferenceTypical operational consequence
Record retrievalA known person, vehicle, address, phone, or caseOfficer receives existing records
Identification and linkageWhether observations concern the same entity, or whether entities are associatedWatchlist match, relationship graph, investigative lead
Place or incident warningWhere or what category of event may occurPatrol allocation, camera attention, event-security deployment
Person-risk or conduct flagWhether a named person may offend, protest, associate, travel, or otherwise warrant interventionCheckpoint stop, questioning, home visit, monitoring, restriction, investigation, or detention referral

The last two are the core predictive categories. IJOP predominantly falls into the person-risk and conduct-flag category, although it also handled place, vehicle, and checkpoint information. Much of Skynet is identification infrastructure; Sharp Eyes is primarily collection and networking infrastructure; Police Cloud can support all four functions depending on local implementation. The distinction matters because identification can be intrusive without predicting conduct, while person-risk systems add an inference about what someone may do or what their characteristics signify.

Source hierarchy and limitations

This report applies a source hierarchy rather than treating all records as equivalent.

Chinese laws, State Council regulations, national technical-standard records, procurement awards, and police or local-government pages provide strong evidence that an authority adopted a rule, announced a program, specified a desired capability, or awarded a contract. They are weaker evidence that every capability worked as described. A procurement specification may represent an aspiration; an award does not prove acceptance testing; and an official success story is not an independent effectiveness evaluation.

Vendor documents and patents are useful for reconstructing product architecture, intended markets, and available features. They cannot by themselves establish which modules a police agency activated, whether data were complete, or whether a model performed accurately in field conditions. Patent language is particularly prone to describing broad possible implementations.

Reverse engineering is stronger for the actual functions visible in a particular software version. Human Rights Watch analyzed IJOP mobile application version 2.1.2.7762, reportedly released in November 2017, with assistance from the cybersecurity firm Cure53. The researchers did not possess authorized credentials or the server-side platform and therefore could not determine all central analytics or confirm every field’s use. The findings should be treated as a technically grounded snapshot of a specific client application, not a complete audit of IJOP over time. citeturn3view1turn16view0

The China Cables consisted of leaked internal documents, including operational directives and four 2017 IJOP bulletins. The International Consortium of Investigative Journalists coordinated review with journalists and specialists and compared the records with other evidence. Their value lies in the operational detail and consistency with separate procurement and technical findings; their limitations include incomplete coverage, unknown selection effects, and the inability of outside researchers to reconstruct the source’s entire chain of custody. The Chinese government denied the reporting and characterized the documents and conclusions as fabrication. citeturn18search0turn15search11

The Aksu List was a leaked list covering more than 2,000 detainees from one prefecture. Human Rights Watch concluded that IJOP apparently flagged the people, after which officials evaluated them and sent many for “political education.” It is direct evidence about one locality and period, not a statistically representative sample of Xinjiang or proof that every detention originated in an automated alert. citeturn18search1

The Xinjiang Police Files are a separate leaked collection reportedly extracted from local police systems. Journalists and researchers checked internal consistency and portions of the data against publicly available records and other sources. Because the collection came through an anonymous hacking source and has been curated by researchers with publicly stated advocacy positions, individual claims should be corroborated where possible. The files are most useful for confirming the bureaucratic scale and coercive context surrounding Xinjiang policing; they are not a substitute for direct inspection of IJOP’s current code. citeturn18search3turn18search9

OHCHR’s assessment carries special weight because it evaluated Chinese laws and official documents alongside interviews and other evidence, but it was not an unrestricted forensic inspection of police servers, detention sites, or classified files. Its conclusions concern the broader human-rights situation, not the accuracy of a particular predictive model. citeturn18search2turn18search5turn18search16

Institutional and technical evolution

From police informatization to anticipatory governance

The roots of present systems lie in police informatization rather than in contemporary generative AI. Golden Shield was developed as a broad Ministry of Public Security effort to connect police networks, computerize records, and improve information exchange across territorial and functional boundaries. Official histories emphasize databases, communications, case support, and police efficiency. Academic reconstruction describes the program as an operational data hub spanning local, municipal, provincial, and national security institutions, while also documenting fragmentation, duplicate construction, incompatible systems, and “information walls.” It is therefore inaccurate both to reduce Golden Shield to the Great Firewall and to imagine it as a seamlessly integrated national supercomputer. citeturn2search4turn2search14turn2search22turn5view0turn5view1

During the 2000s and 2010s, city video projects expanded under labels including Safe Cities and Skynet. The central technical problem was not simply installing cameras but connecting devices, standardizing streams, storing images, linking them to maps and command centers, and enabling police to search or retrieve footage. As facial recognition, license-plate recognition, video structuring, and cross-camera tracking matured, video networks became sensors for higher-level analytical platforms. Official publicity sometimes describes Skynet as capable of intelligent warning and prediction, but local implementation differs markedly in camera quality, coverage, analytics, staffing, and system integration. citeturn2search2turn9search2turn17search4turn17search5

The 2015 multi-agency opinions on public-security video surveillance were an important policy bridge from recording to analytics. The opinions called for wider networking and sharing, national and provincial processing capacity, and the use of data mining, facial and license-plate recognition, tracking, rapid search, and intelligent warning. This was a policy direction, not a single procurement order. It gave local governments a central mandate under which heterogeneous projects could be funded and linked. citeturn0search23

Sharp Eyes, promoted especially in counties and rural areas, broadened the institutional base of surveillance. Official local plans describe the interconnection of police-built cameras, government resources, residential and commercial video, township and village governance centers, grid-management personnel, and sometimes household or community viewing. Its name conveyed the political idea that public participation could make cameras ubiquitous. In practice, “mass participation” could mean volunteers or local personnel watching feeds, reporting anomalies, or using neighborhood platforms; it did not necessarily mean every citizen had equal access or control. citeturn0search7turn0search11turn5view2turn5view3

Police Cloud emerged as a parallel data-fusion concept. Ministry of Public Security information-sharing policy and local tenders envisaged provincial clouds consolidating police and non-police records and supporting a national information environment. Human Rights Watch’s study of tenders from Shandong, Jiangsu, and Tianjin found specifications reaching beyond criminal records into medical information, retail memberships, delivery records, movement, relationships, and “abnormal” behavior. These documents show a policy ambition to make heterogeneous social data searchable and actionable. They do not establish that every province obtained the same sources or deployed identical scoring methods. citeturn3view3

By the late 2010s and early 2020s, official terminology increasingly emphasized “public-security big-data intelligent platforms,” integrated intelligence-command-operations mechanisms, and “new police operating models.” The architecture shifted from separate camera, records, and command projects toward modular stacks: data lakes or warehouses; identity and entity-resolution services; knowledge graphs; rule engines; model libraries; visual dashboards; mobile police clients; command-and-dispatch systems; and audit or access-control layers. The same locality might retain older Golden Shield, Skynet, or Police Cloud components while procuring a newly branded analytical layer. citeturn0search1turn9search5turn22search1turn22search23

Relationship map

The relationship among the principal labels is best represented as a layered map rather than an organizational chart:

LayerPrincipal institutionsTypical technologiesRelationship to prediction
National political and policy directionCCP central bodies, State Council, Ministry of Public Security, National Development and Reform Commission, central political-legal institutionsPlans, funding priorities, interoperability mandates, national regulationsDefines “proactive prevention,” stability, counterterrorism, and data-sharing objectives
National police infrastructureMinistry of Public Security and subordinate research, standards, and network institutionsGolden Shield networks, shared databases, identity and case systems, national standardsProvides records and connectivity; not one predictive model
Provincial police data infrastructureProvincial public-security departmentsPolice Cloud, provincial big-data platforms, model libraries, command systemsEntity linkage, cross-jurisdiction search, warning, local model deployment
Municipal and county applicationsCity and county public-security bureaus, local governments, political-legal committeesSkynet, integrated command platforms, dispute warnings, video patrol, local LLMsPlace, incident, person, or relationship alerts depending on project
Community and governance collectionTownship, street, village, residential, grid-management, and comprehensive-governance bodiesSharp Eyes terminals, visitor systems, household surveys, dispute reportsSupplies observations and enables preventive intervention
Xinjiang-specific security architectureXinjiang regional and local public-security organs, political-legal authorities, Xinjiang Production and Construction CorpsIJOP, checkpoints, home-visit applications, biometric collection, regional data centersIntensive person-focused flags linked to coercive counterterrorism and stability operations
Commercial supply chainState-owned integrators, telecom carriers, camera vendors, cloud firms, software developers, chip and server suppliersCameras, storage, servers, analytics, maps, middleware, AI modelsCapabilities depend on contracted configuration and agency use

This map explains why the same video stream may participate in several programs without those programs being identical. A camera may be installed through a Skynet or Sharp Eyes contract; transmit using a national protocol; have its structured image metadata stored in a GA/T 1400-compliant database; be queried through a Police Cloud; and contribute to a locally written warning model. The national government creates interoperability conditions, but procurement, configuration, data quality, and operational rules remain distributed. citeturn17search0turn17search2turn17search4turn17search5

IJOP fits into this architecture as a Xinjiang-focused operational fusion platform. Public evidence indicates connections to checkpoints, video, local databases, mobile police work, and regional information collection. It does not establish that every provincial Police Cloud outside Xinjiang sent data into IJOP or that IJOP was the national backend for Skynet or Sharp Eyes. Human Rights Watch expressly noted uncertainty about the platform’s connections beyond Xinjiang. citeturn16view0

Standards and procurement timeline

China’s standardization program is crucial because standards can create practical integration without centralized ownership. GB/T 28181 specifies transmission, exchange, and control requirements for networked public-security video; its 2016 edition was succeeded by GB/T 28181-2022. GB 35114-2017 addresses security for networked public-security video. The GA/T 1400 family, issued under Ministry of Public Security supervision in 2017, covers police video-image information application systems, including platforms, databases, and interface protocols. Drafts and implementation documents also reference GA/T 1399 for video-image analysis and the GA/T 1788 series for security requirements. citeturn17search0turn17search2turn17search5turn17search6turn17search8

The drafting organizations listed for GA/T 1400 included Ministry of Public Security bodies, research institutions, and major Chinese video companies such as Hikvision, Dahua, and Uniview. This illustrates a recurring public-private governance pattern: police authorities establish operational needs and supervise standards while vendors contribute technical expertise and build compatible products. Participation in standardization is evidence of sectoral influence, not proof that a company supplied a particular coercive deployment. citeturn17search0turn17search2

A concise timeline is as follows:

PeriodDevelopmentEvidentiary significance
Early 2000s–2010sGolden Shield networks and police databases expandFoundation for cross-unit police information exchange; persistent fragmentation documented
2000s–mid-2010sUrban Skynet and Safe City video deploymentsLarge-scale video collection and command integration
2014–2015Central social-security prevention and video-networking policiesShift toward coordinated prevention, sharing, and intelligent warning
2015–2017Police Cloud tenders and provincial-data initiativesExpansion from police records to heterogeneous social and administrative data
2016–2018Intensive Xinjiang checkpoint, biometric, home-visit, and IJOP deploymentPerson-focused operational fusion in a coercive counterterrorism campaign
2017GA/T 1400 series and GB 35114; IJOP app version analyzed by HRWInteroperability, image databases, interface and security requirements become more formalized
2018–2020Sharp Eyes expansion and integrated social-governance projectsExtension to county, rural, community, and privately owned video resources
2021–2023PIPL, Data Security Law, newer video-security standards, big-data platform consolidationFormal data-governance duties coexist with continuing police expansion
2024–2026Local large models, DeepSeek deployments, video anomaly detection, model libraries, integrated risk-warning platformsGenerative and analytical layers are added to existing data and command systems
April 2025National public-security video-system regulations take effectFirst broad national administrative regulation focused specifically on public-security video-system planning, operation, access, and use
January 2026Amended Cybersecurity Law takes effectAdds express national support for AI development alongside AI safety and risk-governance language

The procurement record from 2024–2026 shows modular modernization rather than one nationally synchronized replacement. A 2025 Dafeng District award described an integrated intelligence-command-operations platform combining AI, large models, data mining, data aggregation, warning models, research tools, information handling, and command dispatch. A separate Yancheng project included a major-risk monitoring system. Such documents are strong evidence of intended capabilities and contracting but do not disclose validation datasets or operational false-positive rates. citeturn22search1turn22search24

Official police reports show related deployments. Guizhou’s “Gui Police Intelligent Brain,” initiated in late 2024 and extended province-wide by the end of 2025, was described as supporting command, case handling, analysis, investigation, grassroots management, and public services. Shijiazhuang reported an “AI + big data” platform with risk-sensing and warning functions. Shanghai stated that it had built more than 7,400 data models and used them for advance assessment and front-end risk resolution. These figures indicate scale and institutional commitment; they do not reveal how many models were materially distinct, how often they were used, or how accurately they predicted harmful events. citeturn22search3turn22search6turn22search23

Systems, data flows, and the turn toward generative AI

Golden Shield, Skynet, and Sharp Eyes

Golden Shield should be treated as enabling infrastructure. Its major functions included networking police units, building and connecting databases, supporting identity and case queries, and improving communication. Some components may have supported internet-control functions, but the public-security significance was broader: police informatization across administrative levels. Later predictive or warning systems rely on precisely this kind of standardized identity and records backbone. citeturn2search4turn2search14turn5view1

Skynet’s core unit is generally the urban video sensor and network: a camera, stream, map location, recording system, and command-center interface. Analytics can add face matching, license-plate recognition, person or vehicle tracking, crowd or anomaly detection, and event alarms. These are distinct tasks. Face matching answers “is this observed face sufficiently similar to a stored template?” A predictive warning asks “does this observation or pattern imply a future event or intervention need?” Skynet becomes predictive only where recognition or structured video outputs feed such prospective rules.

Sharp Eyes broadens collection and access. Local plans commonly seek “full-domain coverage,” network sharing, continuous availability, and whole-process control; they connect government cameras with social or privately installed resources and embed video in comprehensive-governance centers. Its contribution to predictive public security is therefore primarily sensor expansion, organizational participation, and access to neighborhood context. In some localities, the same governance staff who contribute dispute, visitor, household, or grid-management observations may also respond to system warnings. citeturn0search7turn0search11turn5view2turn5view3

The 2025 State Council video regulations partially constrain this infrastructure. They require governments to plan systems rationally and avoid duplicate construction; restrict installation to places where public security requires it; prohibit cameras in private spaces such as hotel rooms, dormitory rooms, changing rooms, toilets, and bathrooms; require compliance with national standards and visible notices; and require filing of system information with local public-security authorities. citeturn3view5turn12view3

Operators must establish cybersecurity, data security, access-control, authorization, and operational logging measures. Video information generally must be retained for at least 30 days and should be deleted when the retention period has expired and the processing purpose has been achieved, unless another lawful basis requires preservation. State organs may retrieve information when performing statutory duties, but collection and retrieval are formally limited to necessary scope. Unauthorized access, alteration, disclosure, and dissemination are prohibited. citeturn12view4turn12view5

These rules improve the formal governance baseline, particularly for installation, logging, and misuse. They do not establish an independent authorization requirement before police use face recognition, relationship analysis, or risk models. Nor do they mandate publication of algorithmic thresholds, false-match rates, watchlist criteria, or aggregate statistics on how often video-generated alerts lead to questioning or detention.

Police Cloud and public-security big-data platforms

Police Cloud is a more direct bridge from data storage to prediction. The tenders studied by Human Rights Watch envisaged combining records that had previously been held by separate agencies or companies. Examples included police records, identity and residence data, movement, medical history, delivery information, commercial memberships, and relationships. Analytical functions sought to reveal where people were, whom they were with, and what activities might appear unusual. One cited example was a local resident staying at a local hotel, a fact that could be innocuous but become an investigative signal in a system designed to detect anomalies. citeturn3view3

The term “cloud” may refer to shared computing and storage, a consolidated data platform, a set of virtualized police applications, or a branded analytical environment. It should not be assumed to mean public commercial cloud hosting. Provincial and municipal systems may operate on police networks, government clouds, telecom infrastructure, or dedicated data centers. Maintenance procurements, such as a 2024 Kunming police-cloud software-maintenance project, show persistence of the infrastructure but reveal little about current analytical rules. citeturn8search9

Commercial descriptions illustrate possible functions. Public-security big-data vendors advertise person-centered profiles, knowledge graphs, relationship discovery, labels, dynamic-control mechanisms, and cross-source search. These materials are evidence that such capabilities are marketed to police and sometimes claimed as deployments; they are not independently verified descriptions of a particular agency’s operational database. citeturn9search1

The key analytical transition is from a record-centered to an entity-centered architecture. In a record-centered system, an officer searches separate files. In an entity-centered system, software attempts to resolve records into a person, vehicle, phone, address, organization, event, or relationship and then displays a composite profile. Entity resolution can improve investigation where records concern the same suspect. It also magnifies error: a mistaken identity link can propagate across all connected records, and an inferred association can become indistinguishable from a verified relationship on a dashboard.

Data-flow architecture

A generalized data flow supported by public records can be represented as follows:

Collection layer: identity registration; household and residence systems; police incident and case records; checkpoints; traffic and vehicle records; CCTV; facial or license-plate recognition; visitor systems; grid-management reports; officer observations; mobile police applications; and, in some documented projects, selected administrative, commercial, delivery, medical, utility, or communications-related information.

Transport and standardization layer: police networks, government networks, video-network protocols, security gateways, structured image metadata, message queues, extract-transform-load tools, and standardized identity fields.

Storage and identity layer: local databases, provincial Police Clouds, public-security big-data platforms, video-image databases, data centers, biometric repositories, and indexes linking persons, phones, vehicles, addresses, organizations, and events.

Analytical layer: exact search; fuzzy matching; facial or plate matching; entity resolution; relationship graphs; temporal and geographic analysis; rule engines; statistical models; model libraries; semantic search; LLM-based summarization; and video-event detection.

Decision-support layer: “full profile” pages, lists, scores or categories, map overlays, warnings, investigative tasks, recommended response guides, and command dashboards.

Operational layer: patrol deployment, checkpoint interception, phone or in-person inquiry, home visit, dispute mediation, enhanced monitoring, investigative opening, administrative measure, restriction, or detention referral.

Feedback layer: officer disposition, interview result, new label, updated relationship, additional home-visit observations, and enforcement outcomes are returned to the platform.

This is a composite architecture, not evidence that every system contains every layer. The most consequential point is the feedback loop. Once a person is flagged, police attention produces additional records; those records may strengthen the appearance of risk even where the original trigger was weak. Systems that count police contacts, interviews, or prior alerts as risk signals can convert surveillance intensity into apparent confirmation.

Documented data categories

The following categories should be included only at the stated level of confidence:

Data categoryDocumented contextConfidence and limitation
Identity, national ID, household registration, residence, addressCore police databases; IJOP queries; Police CloudHigh. Repeated across technical and official sources. citeturn3view3turn16view0
Police incidents, cases, prior investigations, officer observationsPolice big-data platforms and IJOP workflowsHigh. Fundamental police inputs; exact retention and weighting often undisclosed. citeturn16view0turn22search3
Vehicle and license-plate informationIJOP, checkpoints, Skynet and video standardsHigh. Vehicle color, plates, trajectories, and identity mismatches are documented. citeturn16view0turn17search5
CCTV and facial-recognition dataSkynet, Sharp Eyes, IJOP-related infrastructure, video platformsHigh. Widespread collection is documented; specific algorithm performance usually is not. citeturn0search23turn16view0turn17search5
Phone identifiers, network-device observations, Wi-Fi-related sensorsIJOP technical analysis and Xinjiang reportingHigh for Xinjiang historical deployment; uncertain nationwide. citeturn16view0
Travel, checkpoints, hotel and movement informationIJOP and Police Cloud tendersHigh. Precise integration and current retention vary. citeturn3view3turn16view0
Household visits and neighborhood observationsIJOP mobile workflow and Xinjiang campaignHigh for Xinjiang. Not evidence of identical nationwide collection. citeturn16view0
Social relationships and associationsIJOP and Police CloudHigh. May combine verified, declared, co-occurrence, household, and inferred links. citeturn3view3turn16view0
Electricity or utility informationIJOP alerts concerning unusual electricity useHigh for the analyzed application; unclear current scale. citeturn16view1
Medical or health informationPolice Cloud tenders; later Xinjiang infrastructure studiesModerate to high for specified projects. Public evidence does not establish universal police access. citeturn3view3turn22search0
Delivery and retail-membership informationPolice Cloud tender analysisModerate to high for documented procurements. Delivery by vendors and operational use remain less certain. citeturn3view3
Religious and political activity or classificationIJOP fields and Xinjiang targeting documentationHigh for Xinjiang historical use. Categories are politically constructed and may encompass lawful conduct. citeturn16view0turn18search1
Biometrics, including facial images and DNA-related collectionXinjiang biometric campaign and video systemsHigh that collection occurred; system-level linkage varies. citeturn10search4turn16view0
Gait recognitionMarketed and technically possible in ChinaInsufficient for a general claim of IJOP or national Police Cloud use. It should not be treated as an established universal input.
Financial activitySome public-security and counterterrorism systems may lawfully seek financial intelligenceProject-specific evidence required. Public materials reviewed here do not justify asserting universal Police Cloud access to complete bank-account data.
Genetic, health, and other sensitive data in 2024–2026 regional data centersRecent supply-chain and infrastructure researchModerate. Based on procurement and infrastructure analysis rather than direct platform access. citeturn22search0turn22search2

Generative AI and proactive-warning expansion

Generative AI is being layered onto this architecture in three principal ways.

First, it serves as an interface to police knowledge. Officers can ask natural-language questions, retrieve rules or records, generate response guides, summarize case material, and draft documents. Suzhou police reported using a large model in emergency dispatch, including production of personalized handling guidance. Zhangjiakou publicized a police “agent” introduced in 2025. These functions may affect decisions, but they are not inherently predictive. citeturn6search0turn22search14

Second, large models assist investigative synthesis. They can extract entities, link case records, review documents, identify inconsistencies, and generate analytical narratives. Guizhou’s platform was described as operating across analysis, case handling, command, and investigation. Commercial police products similarly advertise case analysis and clue discovery. The audit concern is that fluent generated explanations can obscure whether the underlying evidence was verified, inferred, or hallucinated. citeturn22search3turn9search7

Third, large models are coupled to warning engines. Dafeng’s procurement explicitly combined large models with warning models and social-risk command. Lianyungang reported using AI analysis of family and neighborhood disputes to detect escalation risk and trigger mediation. Nanchong described a locally built dispute-risk model combining police, community, and grid information. Shanghai described thousands of models used for advance risk assessment. These are closer to predictive public security because they support intervention before a reported event has matured into a conventional criminal case. citeturn22search1turn22search20turn22search23turn22search25

Video analytics are also moving toward continuous anomaly detection. Shenzhen police publicity described round-the-clock video patrol and early intervention in fights or intoxication-related incidents. The operational significance depends on whether the model detects an observable current event, such as a person falling, or predicts an unobserved future one. The former is automated detection; the latter is forecasting. Procurement and publicity often blur that line. citeturn6search11turn6search15

As of August 2, 2026, the most defensible conclusion is that generative AI has become an interface and analytical layer within multiple public-security organizations, while structured warning models continue to drive many prospective alerts. Public evidence does not show that police have replaced rule engines and conventional statistical models with autonomous general-purpose LLM crime prediction. Nor does it establish that the numerous local systems share a national foundation model, even where domestic models such as DeepSeek are locally deployed.

Xinjiang and the IJOP case study

Authority, developers, deployment, and purpose

IJOP operated under Xinjiang’s public-security and political-legal apparatus during the intensified “Strike Hard Campaign against Violent Terrorism.” Public procurement and technical research link the platform to Xinjiang Lianhai Cangzhi, a subsidiary connected to China Electronics Technology Group Corporation, and to Hebei Far East Communication System Engineering, another CETC-related entity involved in developing the analyzed mobile application. CETC is a large state-owned defense-electronics and information-technology conglomerate, making IJOP an example of state-owned industrial capacity supporting regional police operations rather than an ordinary commercial software purchase. citeturn3view1turn16view0

The analyzed Android application was published in November 2017, during the height of Xinjiang’s intensive surveillance and detention campaign. IJOP’s broader construction began earlier through regional command, checkpoint, video, and data-fusion projects. Public evidence does not establish one clean launch date because the platform appears to have been assembled and expanded through multiple procurements and operational phases.

Its official security context was counterterrorism, anti-extremism, social control, and stability maintenance, not simply burglary, robbery, or conventional urban crime forecasting. That distinction is fundamental. In Xinjiang, authorities defined numerous forms of lawful or ambiguous religious, communicative, travel, and social conduct as possible indicators of extremism or political unreliability. The platform therefore operationalized a policy ontology in which noncriminal behavior could become a security signal. citeturn16view0turn18search1turn18search2

Technical functions

Human Rights Watch identified three broad application functions: collecting data, reporting information, and receiving or completing investigative missions. Officers could search by name, national identity number, address, household utility account, and other identifiers. Access to fuller person profiles apparently required authorization, indicating role-based controls at least at the application level. citeturn16view0

The application supported person, vehicle, location, and relationship inquiries. Fields included identifying information, physical attributes, vehicles, phones, addresses, political or religious classifications, relationships, and movement-related records. It also incorporated or interacted with information generated at checkpoints, gas stations, visitor systems, delivery controls, police contacts, and household visits. Facial comparison functionality appeared in the client. citeturn16view0

Data entered by officers were not merely passive archival records. The interface structured observations into standardized categories that could be reused by the platform. This is a form of administrative feature engineering: policy categories are embedded into forms, officers translate complex lives into categorical fields, and later analytics treat those fields as machine-readable facts. The accuracy of the system therefore depends not only on software but on how officers interpreted categories and whether residents could correct errors.

The analyzed workflow included alerts for mismatches or patterns such as a person’s identity, phone, or vehicle not aligning as expected; unusual electricity consumption; loss of normal digital or geographic traces; associations with targeted persons; gas-station activity; or crossing a virtual boundary. Many of these appear to have been deterministic rules rather than trained probabilistic models. Human Rights Watch found no basis to conclude that every alert was produced by sophisticated machine learning and described the server-side analytics as unknown. citeturn16view0turn16view1turn16view3

The platform could send warnings to checkpoints, enabling personnel to stop or inspect a targeted person or vehicle. This converts a database inference into a physical intervention. It also gives the system a distributed enforcement capability: the officer at the checkpoint may know only that a warning exists, not the origin, reliability, or legal significance of the underlying data. citeturn16view0

What IJOP predicted

IJOP’s outputs do not fit one narrow predictive-policing category.

It retrieved known records when officers searched a person, vehicle, phone, or address.

It identified or linked entities through facial comparison, identity attributes, co-occurrence, household relations, phone and vehicle links, and other associations.

It flagged current or recent conduct where data differed from an expected pattern—for example, a mismatch, sudden absence of data, or unusual utility use.

It assessed prospective person risk by selecting named people for investigation based on combinations of classification, associations, movement, communication, or behavior.

It supported place-based interception through checkpoints and virtual fences.

It did not primarily predict an unknown future offender in the sense of estimating that an unidentified person would commit a conventional crime in a forecast grid. Its characteristic output was a named-person or known-entity warning. The target could be someone with no substantiated connection to a specific planned offense.

This distinction separates IJOP from European near-repeat burglary systems such as PRECOBS, which forecast elevated incident risk in small geographic areas after a triggering burglary. A place forecast can still produce discriminatory patrol patterns, but IJOP’s person-centered architecture creates a more immediate pathway from association or categorization to individualized coercion.

Data inputs and confidence

The following IJOP inputs are strongly documented in the analyzed application or corroborating records: national identity and residence information; physical description; household and family relationships; vehicle and license information; phone-related identifiers; addresses; checkpoint and travel traces; video and facial imagery; police observations; home-visit records; and classifications concerning religion, politics, or perceived reliability. citeturn16view0turn16view2

Electricity use is documented through an “unusual electricity” warning function. The existence of the alert does not disclose the statistical baseline, whether household size or seasonal factors were considered, or how often it was wrong. A low-information anomaly can become dangerous when institutional practice treats it as a reason to investigate rather than as a weak signal requiring independent corroboration. citeturn16view1

Communications-related collection included Wi-Fi sensing and phone or device information in the wider Xinjiang architecture. Public evidence should not be stretched into a claim that IJOP contained the content of every communication. Metadata, device identifiers, network observations, and application classifications can be highly revealing without complete content interception. citeturn16view0

Health, finance, and other administrative data should be attributed carefully. Later infrastructure investigations indicate broad digitization and data-center processing in Xinjiang, while Police Cloud tenders elsewhere sought medical and commercial records. That does not prove that every such record was ingested into every IJOP deployment. The sound conclusion is that IJOP existed within an environment of extensive cross-sector data collection, with the exact central schema publicly unknown. citeturn3view3turn22search0turn22search2

Outputs and police response

IJOP outputs included alerts, person lists, investigative missions, profile information, checkpoint warnings, and prompts to determine whether further investigation was needed. Police response could include checking identity, questioning, searching a phone, verifying residence, conducting a home visit, increasing monitoring, or recording a disposition. In the wider campaign, adverse findings or classifications could contribute to movement restrictions, administrative controls, detention, prosecution, or referral to political-education facilities. Not every alert necessarily produced detention, and public evidence does not provide a complete alert-to-outcome rate. citeturn16view0turn18search0turn18search1

The Aksu List provides the clearest documented link between automated or platform-mediated flagging and detention decisions. Human Rights Watch reported that the list covered more than 2,000 detainees whom IJOP apparently flagged before officials evaluated and sent many to political education. The presence of an official review does not eliminate algorithmic influence: the system framed who was examined, presented selected data, and made nonintervention an affirmative bureaucratic choice. citeturn18search1

The China Cables likewise described IJOP bulletins and operational instructions concerning large numbers of people identified through the system. The records indicate that authorities sought rapid checking and disposition of flagged cases. Because the documents are incomplete, they cannot establish the total number of alerts, the share cleared, or the degree to which local officials exercised meaningful discretion. citeturn18search0

Guilt by association

Relationship analysis was central to IJOP’s risk logic. A person could attract attention because of family, household, communication, travel, or other ties to someone already categorized as suspicious. In a conventional criminal investigation, association may be one lead among many and must be connected to evidence of an offense. In IJOP’s documented setting, association could itself become an indicator of unreliability or extremism.

This creates network propagation. Suppose A is incorrectly classified. A’s family members, contacts, co-travelers, or co-residents may then become higher-priority nodes. Police contacts generated by that priority produce additional records, which can be treated as confirmation. The original classification acquires apparent support through consequences it caused.

The problem is aggravated by compulsory social proximity. Family relationship, shared housing, shared devices, work, religious community, and ordinary travel can generate graph edges without indicating common criminal intent. A system that fails to distinguish the reason, direction, duration, and evidentiary quality of an association turns social life into a risk surface.

Rule-based suspicion and the “AI” label

IJOP demonstrates why “algorithmic” is broader than machine learning. A rule such as “generate an alert when utility usage deviates from an expected pattern” is algorithmic even if no neural network is involved. It can be audited in principle by inspecting the rule, threshold, exceptions, and outcomes. Yet rule-based systems are not necessarily more legitimate. A transparent rule can encode a discriminatory or irrational policy.

Machine learning adds separate risks: opaque feature interactions, distribution shift, proxy discrimination, and difficulty explaining a score. But in a coercive environment, a simple rule applied to a vast population may have greater impact than a technically advanced model used narrowly. The audit question should be “what inference triggers what intervention under what evidentiary standard?” rather than “does the product use AI?”

Current status as of August 2, 2026

No reliable public record establishes that IJOP has been formally discontinued, dismantled, or replaced. Equally, no outsider has publicly audited the current server-side platform, model library, mobile client, data connections, or operating rules. Claims that the precise 2017 application remains unchanged would be speculative.

The most defensible status statement is therefore:

IJOP’s historically documented operation is high-confidence; the persistence of an extensive Xinjiang surveillance and data-processing infrastructure is high-confidence; the current branding, codebase, organizational placement, and alert rules of IJOP itself are not publicly verifiable.

Recent research documents continuing data-center investment and surveillance-related processing in the region, including systems that use domestic and foreign-origin components. This evidence supports continuity of the underlying capacity but does not prove that every facility feeds the IJOP instance analyzed in 2017. citeturn22search0turn22search2

The decline in public tenders mentioning “IJOP” may reflect secrecy, procurement-cycle completion, modular replacement, changed branding, or operational consolidation. It cannot alone establish termination. In China generally, older program names often recede while their functions are incorporated into new platforms described as big-data intelligence, integrated command, proactive policing, or social-risk prevention.

Effectiveness, error, bias, and documented consequences

Absence of credible causal evaluation

A scientifically adequate evaluation would specify the intervention, target outcome, unit of analysis, baseline period, comparison group, model version, operational response, and potential displacement. It would distinguish model performance—such as precision, recall, false-positive rate, calibration, and lead time—from program impact, such as whether police action prevented harm without disproportionate rights costs.

Public evaluations of the major Chinese systems rarely meet this standard. Official reports tend to present activity counts: cameras installed, records aggregated, models built, warnings issued, clues discovered, arrests made, or cases solved. Those measures can show utilization but not causation. A system could issue many warnings because its threshold is low; recover property in cases that would have been solved through ordinary investigation; or shift conduct into less monitored areas.

Vendor case studies pose similar problems. A claim that video analytics generated clues or assisted arrests does not disclose how many alerts were wrong, how many officers reviewed them, whether comparison methods performed as well, or whether the cited cases were selected because they succeeded. The lack of denominators prevents calculation of positive predictive value. citeturn9search15turn9search19

For Xinjiang, official claims that counterterrorism policies prevented attacks cannot isolate IJOP’s contribution. The period included extraordinary police deployment, checkpoints, communications control, restrictions on travel and religious practice, neighborhood monitoring, and mass detention. A reduction in publicly recorded incidents under such conditions is not an estimate of the platform’s causal effect, much less proof that individual flags were accurate. citeturn15search0turn15search1turn18search2

Base-rate and false-positive problems

Predicting rare serious violence is mathematically difficult. Even a model with apparently high sensitivity and specificity can produce far more false positives than true positives when the underlying event is rare. This is the base-rate problem.

Assume, illustratively, that one person in 10,000 would commit the narrowly defined event within the forecast period. A model with 90 percent sensitivity and a one-percent false-positive rate would identify most true cases, but it would also flag roughly 100 innocent people for every true case. The exact figures for Chinese systems are unknown; the example shows why accuracy percentages without prevalence and positive predictive value are misleading.

Authorities can attempt to avoid this problem by defining the target more broadly—“instability,” “abnormality,” “extremist tendency,” “dispute escalation,” or “risk person.” That may increase the number of events labeled as correct, but at the cost of conceptual validity. A model can appear successful because almost any police encounter, home visit, argument, religious activity, or travel irregularity is counted as confirmation.

Labels and ground truth

Supervised machine learning requires labels. In public security, labels may derive from arrests, police suspicion, administrative designations, watchlists, prior warnings, detention, or convictions. These are not interchangeable.

An arrest label reflects police behavior as well as underlying conduct. A detention label may be especially invalid where detention is arbitrary or politically motivated. Training a model to reproduce such labels does not discover objective dangerousness; it automates a prior institutional judgment.

IJOP’s structured categories present an analogous problem even where machine learning was not used. The “ground truth” was created by policy: certain religious practices, foreign contacts, travel patterns, use of communication tools, or social ties were treated as suspicious. The system could be internally consistent while being normatively and legally defective.

Circular data production

Predictive systems produce some of the data used to validate them.

A flag prompts a home visit. The home visit becomes a police record. The person’s profile now contains an additional police contact. That contact may increase a future risk category. More monitoring detects more deviations. The system then appears to confirm its initial concern.

Place-based systems have a parallel patrol-feedback loop. More patrol in a selected area produces more recorded minor offenses and stops, which raise the area’s apparent crime rate and justify further patrol. Person-based systems are more direct because repeated scrutiny attaches to an individual and their network.

To audit circularity, agencies would need to distinguish exogenous events—reports or evidence arising independently of the model—from model-induced observations, such as police contacts caused by a prior alert. Publicly available Chinese evaluations do not make that distinction.

Ethnic, religious, and political targeting

In Xinjiang, bias was not merely an unintended statistical artifact. The broader campaign explicitly concentrated surveillance and intervention on Uyghurs and other predominantly Muslim groups, and platform categories incorporated religious, political, ethnic, and relational information. OHCHR found that deprivation of liberty and other restrictions were imposed in a discriminatory context. citeturn18search2turn18search16

This matters for audit terminology. “Bias” can imply an accidental deviation from a neutral objective. Where an institution deliberately treats ethnic or religious identity and associated cultural conduct as security-relevant, the issue is discriminatory policy implemented through technology. Improving facial-recognition parity would not cure a system whose target definition is itself discriminatory.

Outside Xinjiang, political-security and stability-maintenance objectives can similarly shape labels concerning petitioners, protesters, activists, religious communities, labor disputes, or individuals involved in recurring local conflicts. Evidence varies greatly by locality, and it would be improper to assume that every municipal crime platform performs political classification. Yet procurement phrases such as social-risk prevention, key-person management, and stability warning require close examination of the actual target categories.

Facial and video error

Video analytics introduce several error sources: poor lighting, pose, occlusion, camera angle, compression, low resolution, demographic performance disparities, outdated templates, plate obstruction, similar clothing, and cross-camera tracking mistakes. A face-match score is not identity proof. In a dense system, even a small false-match rate can create many alerts.

Chinese standards improve interoperability and may set image-quality or security requirements, but interoperability does not establish biometric accuracy. Local authorities should publish algorithm versions, threshold settings, demographic testing, camera conditions, false-match rates, and human-review outcomes. Public sources generally do not provide that information. citeturn17search2turn17search5

The Personal Information Protection Law categorizes biometrics, religious belief, health, financial accounts, and location tracking as sensitive personal information. It requires a specific purpose, sufficient necessity, and protective measures. These principles create a formal basis for demanding stricter control, but public evidence does not show routine disclosure of police facial-recognition accuracy or individualized notice after a match. citeturn12view1turn23search0

Large-model failure modes

Generative AI adds risks not present in conventional rule engines.

A large model may hallucinate a relationship, misstate a record, merge similarly named people, omit exculpatory facts, or present a probabilistic inference as a confident narrative. Retrieval-augmented generation can reduce but not eliminate these problems; if the retrieved database contains errors, the model may restate them persuasively.

Prompt injection and contaminated documents may manipulate a system that reads externally supplied text. Sensitive police data can leak through logs, training pipelines, debugging interfaces, or poorly separated user permissions. Model updates can change outputs without an obvious rule revision.

Large models can also create explanation laundering. A system may generate a coherent paragraph explaining why a person is high-risk even though the underlying model is opaque or the source fields are weak. The narrative gives human reviewers a sense of reasoned judgment while concealing uncertainty.

Current public evidence supports actual use of large models for police knowledge, report drafting, analysis, and some warning workflows. It does not establish that local public-security organizations have solved these audit problems. Official usage counts demonstrate adoption, not reliability. citeturn22search3turn22search14

Chilling effects and social consequences

Mass observation changes behavior even without a formal risk score. People may avoid religious practice, travel, gatherings, political discussion, contact with relatives abroad, sensitive medical services, or lawful association because those activities create records or could be misinterpreted.

In Xinjiang, the chilling effect was reinforced by checkpoints, home visits, communications controls, and the possibility of detention. Surveillance therefore operated not only as an investigative tool but as a means of behavioral discipline. The inability to know which act generated suspicion can intensify self-censorship: virtually any deviation may appear risky. citeturn16view0turn18search2turn18search4

Elsewhere, dispute-warning and proactive-governance systems may have less severe consequences and can sometimes direct social services or mediation before violence occurs. The rights assessment should turn on the actual response. A warning that offers voluntary support is different from one that triggers coercive monitoring. Nonetheless, apparently benevolent interventions can become compulsory where the person cannot decline contact or correct the underlying record.

Transparency and contestability

Chinese procurement notices may disclose more technical architecture than police-facing transparency regimes disclose to affected individuals. Researchers can sometimes reconstruct a project’s modules, budget, or vendor, while a person stopped because of an alert may receive no meaningful explanation.

PIPL gives individuals rights concerning access, copying, correction, deletion, and explanation, and it permits litigation where processors reject rights requests. It also states that a person affected by a solely automated decision with major consequences may request an explanation and refuse a decision made solely through automation. citeturn12view1turn12view2turn23search0

Several qualifications limit practical force in policing. State organs process personal information to fulfill statutory duties; notice may be withheld in legally specified circumstances or where it would impede those duties; national-security and state-secret rules can restrict disclosure; and an agency can characterize the system as decision support rather than the sole decision-maker. If an officer formally approves the outcome, the Article 24 right to refuse a solely automated decision may not apply even where the alert effectively determined who was targeted.

Published facial-recognition litigation has largely concerned commercial or civil settings, such as compulsory facial identification by private operators. Supreme People’s Court rules provide meaningful protections in those contexts but do not amount to a developed body of judgments requiring disclosure of police risk models. citeturn13search0turn13search1turn13search8

The diminishing completeness of publicly accessible Chinese court-decision databases further complicates assessment. Researchers cannot assume that all relevant administrative or data-protection cases are published. Absence of reported litigation is therefore not proof that no disputes occurred, but it is evidence that public accountability cannot be evaluated comprehensively. citeturn13search27

Domestic law, international law, and official justification

Personal-information law

The Personal Information Protection Law, effective in 2021, applies to state organs as well as private processors. Its general principles require legality, legitimacy, necessity, defined purposes, processing limited to the minimum scope needed, openness, data quality, and responsibility for security. citeturn12view0turn23search0

State organs do not ordinarily rely on individual consent when processing is necessary to perform statutory duties. They must act within legal authority, procedures, and necessary scope. Information generally must be stored domestically where a state organ processes it, subject to statutory procedures for cross-border transfer. These provisions authorize necessary public administration while formally rejecting unlimited collection. citeturn12view1

Article 24 regulates automated decision-making. It requires transparency, fairness, and impartiality and prohibits unreasonable differential treatment in transaction conditions. Where an automated decision has a major impact on an individual, the person can request an explanation and refuse a decision made solely through automation. In police settings, two questions are unresolved in public jurisprudence: what counts as a “decision” rather than an investigative lead, and how much human involvement prevents a decision from being “solely” automated. citeturn23search0turn23search12

Article 26 requires that image-collection and personal-identification devices installed in public places be necessary for public security, comply with state rules, and carry prominent notices. The resulting images and identity information generally may be used only for public security absent separate consent. This is purpose limitation, but “public security” is broad and may encompass crime, public order, counterterrorism, emergency response, and stability-related functions. citeturn23search0

Sensitive personal information includes biometrics, religious belief, specially designated identity, medical and health information, financial accounts, and specific location information. Processing requires a specific purpose, necessity, and stricter safeguards. A person-focused police platform combining several of these categories presents cumulative risk beyond each field in isolation. citeturn12view1

Processors must conduct personal-information protection impact assessments for sensitive information, automated decision-making, entrustment or sharing with other processors, cross-border transfers, and other activities with a major impact on personal rights. Records of assessments and processing should be retained. Public-security agencies should therefore be able, at least internally, to document necessity, proportionality, data sources, security measures, and individual impacts. Public evidence that such assessments are routinely disclosed or independently reviewed is scarce. citeturn12view2

Individuals possess correction, deletion, access, copying, and explanation rights, subject to exceptions. Procuratorates, consumer organizations, and authorized bodies may bring public-interest actions for large-scale infringements. Published enforcement has concentrated heavily on commercial misuse, apps, face recognition, and data security rather than on individualized police prediction. citeturn12view2turn13search2turn13search6turn13search10

Video-system regulation

The 2025 State Council regulations are the clearest specialized national rules for public-security video systems. They assign the Ministry of Public Security nationwide guidance and supervision, with local public-security organs responsible for local oversight. Governments are directed to coordinate planning and avoid redundant construction. citeturn3view5

The regulations establish location restrictions, signage, filing, standards compliance, internal controls, security protections, access logging, use limitations, and penalties for unlawful operation or disclosure. They also allow public authorities to retrieve video for statutory duties. This creates a governance framework for cameras and their data, but it does not comprehensively regulate all downstream analytics. A risk score generated after video metadata are merged with residence, relationships, and police observations may raise issues not resolved by camera-placement rules. citeturn12view3turn12view4turn12view5

The rules’ effectiveness will depend on implementation: whether filing databases are complete; whether local police inspect systems they also use; whether private and residential cameras are brought into compliance; whether deletion rules are enforced; and whether individuals can discover misuse. As of August 2, 2026, insufficient public evidence exists for a national implementation audit.

Data Security and Cybersecurity Laws

The Data Security Law regulates the collection, storage, use, processing, transmission, provision, and disclosure of data and links data governance to national sovereignty, security, public interests, and individual and organizational rights. It establishes classified and graded protection and special treatment of important and core data. For police platforms, its principal force is institutional security, control, localization, and national-interest governance rather than an individualized right against predictive classification. citeturn23search1

The Cybersecurity Law and associated multi-level protection regime govern network security, critical systems, incident response, and operator duties. Amendments adopted in October 2025 and effective January 1, 2026 added express support for AI research, infrastructure, ethics, risk monitoring, and safety governance. This reflects China’s dual policy: accelerate AI deployment while strengthening state-directed control over its security risks. It does not create a comprehensive substantive prohibition on police person-risk prediction comparable to Article 5 of the EU AI Act. citeturn11search2turn11search6turn11search18

Counterterrorism and public-security authority

China’s Counterterrorism Law gives public-security and state-security authorities substantial powers to collect intelligence, investigate suspected terrorist activity, require assistance from service providers, and use technical investigative measures subject to domestic authorization rules. It also provides confidentiality obligations for personal and commercial information learned during counterterrorism work. citeturn23search2turn23search6

The central legal problem is definition and application. OHCHR found that China’s counterterrorism and anti-extremism framework used vague and broad concepts that could encompass lawful religious and personal conduct. When such categories become machine-readable indicators, defects in the substantive law and policy flow directly into the technical system. An algorithm cannot supply legal precision that the governing category lacks. citeturn18search2

Local implementation measures can extend preventive monitoring into communities. For example, provincial provisions may direct authorities and grassroots bodies to identify and assist persons considered prone to extremism, hatred, or retaliatory violence. Such programs can support mediation and welfare, but broad labels and mandatory information collection also create pathways for preventive policing without evidence of a completed offense. citeturn23search10turn23search14

Ordinary criminal investigation versus stability maintenance

Ordinary criminal investigation begins with a legally defined offense or concrete suspicion and seeks evidence relevant to culpability. Stability maintenance is broader. It aims to identify and neutralize social, political, administrative, or collective-action risks before they become incidents. Its objects may include disputes, petitions, protests, public opinion, religious organization, labor conflict, mass gatherings, or persons considered likely to create disruption.

The two domains overlap. A threat of violence arising from a dispute may be both a criminal and stability concern. But the evidentiary and rights implications differ when the target is lawful collective action or political expression. An integrated platform may not visibly separate the models, data-retention rules, and legal authorities for each purpose.

Auditors should therefore require every warning model to identify a legally defined target outcome. “Risk,” “abnormality,” and “instability” are not adequate labels. The agency should state whether it predicts reported crime, physical violence, a public-order offense, a missing person, self-harm, protest participation, petitioning, or an administrative concern. Each target requires different authority, data, validation, and safeguards.

International human-rights obligations

China is a party to the Convention against Torture and the International Convention on the Elimination of All Forms of Racial Discrimination. It has signed but not ratified the International Covenant on Civil and Political Rights. Treaty bodies and UN mechanisms have scrutinized Xinjiang under binding nondiscrimination and anti-torture obligations as well as broader international human-rights standards. citeturn23search3turn23search7turn14search5turn14search12

Predictive public-security systems implicate privacy because they collect, combine, infer, and retain information about identity, movement, relationships, belief, communication, and behavior. International human-rights analysis asks whether interference is provided by sufficiently accessible and foreseeable law, pursues a legitimate aim, is necessary and proportionate, and contains safeguards against abuse.

They implicate liberty and due process where an alert contributes to detention, movement restriction, or coercive questioning. A weak inference cannot lawfully substitute for individualized grounds. Human review is meaningful only where the reviewer can inspect the evidence, reject the alert, document reasons, and operate free from institutional pressure to confirm the system.

They implicate equality and nondiscrimination where ethnicity, religion, language, nationality, geography, family association, or proxies produce differential surveillance or intervention. Discrimination can arise from express categories, skewed data, selective deployment, or the use of a formally neutral signal that closely tracks a protected group without adequate justification.

They implicate freedoms of religion, expression, association, assembly, and movement where lawful conduct becomes a security feature or where pervasive observation chills participation. In Xinjiang, these rights did not operate as isolated concerns; the surveillance architecture linked them to detention and coercive assimilation.

OHCHR’s 2022 assessment found serious violations and concluded that the extent of arbitrary and discriminatory detention may constitute international crimes, particularly crimes against humanity. The assessment urged release of arbitrarily detained persons, review of the legal framework, investigation of abuses, clarification of detainees’ whereabouts, and stronger safeguards. citeturn18search2turn18search16

Official justifications and responses

Chinese government white papers present Xinjiang policy as a response to serious terrorist violence and religious extremism. They argue that preventive counterterrorism, vocational education, poverty reduction, legal education, and employment assistance addressed root causes, protected the rights to life and development, and restored security. Official accounts deny that the measures target ethnicity or religion as such and state that religious freedom and lawful activities are protected. citeturn15search0turn15search1turn15search4

The government rejected the OHCHR assessment and major investigative reports, describing them as politically motivated, based on disinformation, or products of anti-China forces. It has emphasized the absence of terrorist attacks over extended periods and argued that Western critics apply double standards to Chinese counterterrorism. citeturn15search11turn15search17turn11search3

Several parts of the official position address legitimate state interests. Governments have a duty to protect people from terrorism and serious violence; information sharing can prevent fragmented investigation; and early mediation may prevent disputes from escalating. The unresolved issue is not whether prevention is permissible but whether the means are lawful, evidence-based, necessary, proportionate, nondiscriminatory, and contestable.

Official effectiveness claims should not be accepted or rejected solely because of their source. They should be tested against transparent definitions, incident data, independent access, and rights outcomes. At present, such testing is largely impossible for IJOP.

Vendors, infrastructure, and foreign supply chains

Domestic developers and integrators

The Chinese surveillance market includes state-owned electronics groups, telecom carriers, public-security research institutes, cloud and software companies, major camera manufacturers, mapping providers, local system integrators, and specialized data-analysis firms. A single municipal project may involve one prime contractor and numerous subcontractors supplying servers, storage, cameras, network security, databases, models, and maintenance.

IJOP’s documented developer chain is unusually important. Xinjiang Lianhai Cangzhi and Hebei Far East Communication System Engineering were linked to CETC, tying the platform to a state-owned group with defense, electronics, and public-security capabilities. Human Rights Watch found third-party code in the analyzed application, including mapping components. It also identified Face++-related code but reported that the relevant component appeared inoperative and that Megvii denied a relationship to the project. The responsible conclusion is therefore not that Megvii supplied IJOP facial recognition, but that unused or nonfunctional code associated with a commercial library was present in the analyzed package. citeturn3view1turn16view0

Hikvision, Dahua, and Uniview have major roles in China’s camera and video-analytics ecosystem and participated in police video standards development. Their products can provide facial and plate recognition, structured video metadata, tracking, and alarms. A vendor’s nationwide market presence does not prove participation in every named platform, and standards participation does not establish responsibility for an agency’s later use. citeturn17search0turn17search2turn9search13turn9search19

Telecom and system-integration companies are equally significant because they connect components. The 2025 Dafeng award went to a Jiangsu Mobile system-integration entity for an integrated platform combining data, large models, warnings, analysis, and command. The operational system is therefore not reducible to the model developer; network design, access permissions, data ingestion, and agency configuration shape its impact. citeturn22search1

Supply-chain functions

A predictive-public-security stack depends on several supply-chain tiers:

Sensors: fixed and mobile cameras, microphones where lawful and procured, access-control devices, checkpoint equipment, plate readers, Wi-Fi and device-sensing equipment, and biometric collection hardware.

Edge computing: chips and embedded processors that perform compression, face detection, object detection, or event classification near the camera.

Network: switches, routers, telecom links, encryption, security gateways, and protocol-conversion equipment.

Data-center hardware: servers, central processing units, graphics processors, accelerators, storage arrays, backup power, cooling, and high-capacity networking.

Software: operating systems, databases, middleware, identity resolution, video management, map services, knowledge graphs, rule engines, model-training frameworks, LLMs, and command interfaces.

Services: installation, data cleaning, labeling, model tuning, maintenance, cybersecurity, and officer training.

Human-rights due diligence that focuses only on cameras misses the server, storage, software, and service layers that transform observations into action.

Foreign-origin technology

Foreign technology has historically entered Chinese surveillance and public-security supply chains through direct sales, Chinese distributors, original-equipment manufacturing, servers containing foreign chips, research collaboration, and globally available software tools. The presence of a foreign-origin component does not establish that its manufacturer knew the final deployment or controlled police use; responsibility depends on knowledge, leverage, contractual restrictions, due diligence, and response after credible risk information.

Thermo Fisher announced in 2019 that it would stop selling human-identification technology in Xinjiang and in 2024 expanded restrictions concerning Tibet, following scrutiny of DNA collection. Earlier procurement research identified planned acquisition of foreign DNA-analysis equipment by Xinjiang-related authorities. These cases demonstrate both the potential role of specialized foreign components and the difficulty of tracking downstream use through distributors and integrators. citeturn10search1turn10search28

Investigative reporting has found foreign processors, servers, storage, and enterprise technology in Chinese surveillance-related institutions. A 2026 C4ADS report based on procurement and corporate records concluded that data-center facilities in the Uyghur region continued to specify or use Western-origin components, including technology associated with major American hardware and chip firms. The report’s case studies are strong evidence about the named contracts and facilities; they should not be generalized into a claim that every foreign company supplied IJOP directly. citeturn10search11turn22search0turn22search2

The C4ADS report also identifies an export-control gap: many ordinary server processors, graphics components, cameras, and storage products useful for surveillance fall below thresholds designed for frontier AI training. A system does not need the most advanced accelerator to perform face matching, entity linkage, rule-based warnings, or run a smaller local model. citeturn22search0turn22search2

Conversely, reports of Chinese entities obtaining export-controlled AI chips through servers or intermediaries should not automatically be attributed to public-security deployments. Evidence that a restricted chip reached a Chinese buyer is not evidence that it operated IJOP, Skynet, or a Police Cloud. End-user, end-use, serial-number, and facility-level corroboration are necessary. citeturn10search2

Corporate human-rights due diligence

The UN Guiding Principles on Business and Human Rights provide the relevant baseline. Companies should identify actual and potential adverse impacts connected to their products and business relationships; integrate findings; use leverage; track responses; and communicate how risks are addressed. Severe impacts require heightened due diligence even where a product is dual-use.

For surveillance suppliers, useful controls include end-use screening; examination of public-security and ethnic-region deployments; contractual bans on discriminatory targeting; reseller traceability; technical limits on prohibited uses where feasible; audit rights; escalation when agencies refuse information; and withdrawal where the company cannot prevent or mitigate severe abuse.

Due diligence should not assume that a product described as “smart city,” “school management,” “public safety,” or “data center” is benign. The 2026 C4ADS study illustrates how ordinary infrastructure can support real-time movement and behavior monitoring in sensitive institutions. At the same time, researchers should avoid attributing responsibility from a component logo alone: procurement date, model, distributor, integrator, end user, and operational function must be established. citeturn22search0turn22search2

Comparative assessment, confidence-rated findings, and unresolved questions

Comparison with United States watchlisting

The closest U.S. comparison is not ordinary predictive policing but the federal terrorism-watchlisting system administered by the FBI’s screening center, renamed the Threat Screening Center in March 2025. The Terrorist Screening Dataset consolidates identity records concerning people nominated by authorized government agencies under intelligence-related criteria. The FBI states that a person may not be listed solely because of race, ethnicity, religion, protected beliefs, or guesses and hunches. citeturn21search0turn21search4turn21search7

The U.S. system and IJOP share several structural risks: identity resolution at scale, nomination or classification based partly on intelligence unavailable to the individual, distribution of alerts to frontline screeners, consequences arising at borders or during encounters, mistaken identity, association-based inference, and difficulty obtaining the underlying reasons for an alert.

They differ in stated scope and legal structure. The U.S. watchlist is formally centered on known or suspected terrorism identities and nomination criteria; IJOP’s documented Xinjiang indicators extended deeply into ordinary religious, social, travel, and communications behavior under broad anti-extremism and stability concepts. U.S. watchlisting is not a general model for predicting ordinary crime, although encounters can generate additional intelligence.

The United States has oversight by inspectors general, courts, Congress, GAO, privacy offices, and administrative redress through DHS TRIP, albeit with significant secrecy and continuing due-process criticism. A 2025 GAO review examined nomination and redress procedures and noted the importance of accuracy and review, especially for U.S. persons. The existence of oversight does not guarantee an effective remedy, but it provides public institutional documentation largely absent for IJOP. citeturn21search1turn21search5turn21search26

The most instructive common lesson is that an officer’s formal participation does not eliminate automated or database-driven harm. A frontline official may simply receive a “match” or handling instruction. Effective human review requires access to sufficient underlying evidence, authority to decline the system recommendation, time to investigate identity ambiguity, and accountability for errors.

Comparison with European predictive policing

European predictive-policing systems commonly distinguish place-based forecasts from person-based risk assessments. A system such as PRECOBS uses near-repeat theory to identify small areas with elevated burglary risk after a triggering incident. Its output is a place and time window, not a prediction that a named person will offend. Place-based prediction can still reproduce reporting and patrol biases but usually does not directly classify an individual.

The EU AI Act establishes a sharper boundary for person-based criminal-risk systems. Article 5 prohibits placing on the market, putting into service, or using AI to assess or predict a natural person’s risk of committing a criminal offense where the assessment is based solely on profiling or on personality traits and characteristics. It preserves AI used to support a human assessment of a person’s involvement in criminal activity where that assessment is already based on objective and verifiable facts directly linked to criminal activity. citeturn21search6turn21search23

Systems not prohibited may still be classified as high-risk under the Act’s law-enforcement provisions and remain subject to data protection under the Law Enforcement Directive, fundamental-rights rules, national police law, judicial review, and the European Convention on Human Rights. Thus, Europe does not create a simple place-based-safe/person-based-banned dichotomy. A person system grounded in concrete crime-linked evidence may be permissible but high-risk; a place model may become person-focused through downstream watchlists or targeted stops.

IJOP’s documented functions would raise profound Article 5 concerns if deployed within the EU and if they satisfied the Act’s definition of an AI system. Person-risk alerts based only on profiles, associations, religious or political classifications, utility patterns, or personality-like characteristics would be close to the prohibited core. Adding a nominal human reviewer would not necessarily cure the system if no objective and verifiable crime-linked facts existed before AI support.

China has no directly equivalent statutory prohibition. PIPL’s solely automated-decision provision is a procedural individual right rather than a substantive ban on predicting criminality from profiling. An agency may also argue that a platform merely supplies leads or supports an officer. This makes purpose, function, and causal influence more important than labels.

Can agencies avoid scrutiny through labels?

Terms such as “intelligence analysis,” “decision support,” “social governance,” “risk prevention,” “model-enabled research,” and “proactive policing” describe institutional framing, not necessarily technical function.

A system should be treated as predictive where it:

  1. infers an unobserved or future risk;
  2. identifies a place, person, group, relationship, or event category for priority;
  3. causes or materially influences prospective police attention; and
  4. operates before sufficient evidence exists for an ordinary case-based intervention.

Calling an output a “clue” does not change its effect where it determines who is stopped. Calling a score “decision support” does not create meaningful human control where reviewers rarely disagree, cannot inspect inputs, or are evaluated on whether they clear alerts quickly.

Conversely, not every analytical tool should be classified as predictive. Searching a known plate, translating a witness statement, summarizing an existing case file, or detecting an assault visibly underway are different functions. Overinclusive terminology obscures where the most consequential inference occurs.

Confidence-rated findings

FindingConfidenceBasis
China’s surveillance systems do not constitute one technically unified national platformHighOfficial standards and policies coexist with documented local fragmentation, separate procurements, vendors, and architectures. citeturn5view1turn5view2turn17search4
Golden Shield is broad police information infrastructure, not one predictive modelHighOfficial and academic descriptions consistently emphasize networks, databases, and informatization. citeturn2search4turn5view1
Skynet is principally urban video-surveillance and command infrastructureHighOfficial descriptions and technical documents; analytics vary by locality. citeturn2search2turn17search5
Sharp Eyes extends video networking and community-level governance, often interconnecting government and social camerasHighMultiple local government plans and independent analysis. citeturn0search7turn0search11turn5view2
Police Cloud projects sought to aggregate unusually broad personal and administrative data and perform relationship and anomaly analysisHigh for documented tenders; moderate for nationwide operational uniformityTender analysis across several jurisdictions; limited deployment verification. citeturn3view3
IJOP supported person searches, relationship analysis, data collection, alerts, and investigative missionsHigh for the 2017 client versionReverse engineering corroborated by procurement and leaked operational records. citeturn3view1turn16view0turn18search0
Many IJOP indicators were rule-based rather than demonstrably sophisticated machine learningHighReverse-engineering evidence; server-side analytics remain unknown. citeturn16view0
IJOP flags contributed in documented cases to investigation and detention referralHigh for specific leaked records; unknown population-wide rateAksu List and China Cables. citeturn18search0turn18search1
IJOP’s current 2026 code, name, and operating scope are publicly verifiedLowNo direct contemporary technical audit or official discontinuation notice located
Xinjiang’s broader surveillance and data-processing infrastructure persistsHighRecent procurement and data-center research. citeturn22search0turn22search2
Chinese police agencies added LLMs and generative-AI tools during 2024–2026HighNumerous official deployments and awards. citeturn22search1turn22search3turn22search14
LLMs are autonomously and accurately predicting future crime nationwideLowMarketing and official claims lack model-level, causal, and error-rate evidence
Major systems have independently demonstrated crime- or terrorism-reduction effectivenessLowNo transparent controlled evaluation located
PIPL and the 2025 video regulations create real formal duties concerning necessity, sensitive data, logging, and rightsHigh as a matter of textPrimary legislation and regulation. citeturn23search0turn12view3turn12view4turn12view5
Affected people have a consistently effective remedy against police risk classificationsLowSparse public police-specific jurisprudence, broad official-function exceptions, and limited transparency
Foreign-origin components remain present in some Xinjiang surveillance-related infrastructureHigh for named procurements; lower for direct IJOP attributionProcurement and supply-chain investigations. citeturn22search0turn22search2

What remains unknowable from public evidence

The principal unknowns are not peripheral; they are the facts needed for a full algorithmic audit.

The current IJOP source code, server architecture, model inventory, alert thresholds, suppression rules, authorization structure, and integration with post-2020 platforms are not public.

No complete data dictionary shows every category held about a person, the provenance of each field, retention period, confidence level, or whether inferred facts are distinguished visually from verified records.

The number of people subjected to each kind of alert, the number cleared, the number questioned, and the number detained because of a platform-mediated process are unknown.

False-positive, false-negative, calibration, demographic-performance, and identity-matching statistics are unavailable for the principal systems.

The role of human discretion cannot be quantified. It is unknown how often officers reject warnings, whether rejections affect performance evaluations, whether a reviewer sees the underlying evidence, and whether confirmation pressure varies by campaign.

The extent of nationwide linkage among Police Clouds, video systems, national databases, and politically sensitive person lists cannot be established from public tenders. Technical interoperability permits sharing but does not prove routine transfer.

The full vendor and subcontractor chains remain incomplete. Prime awards may not disclose software libraries, labeling contractors, cloud providers, server distributors, or downstream maintenance firms.

The extent to which 2024–2026 large models receive person-level police data, generate risk classifications, or merely provide knowledge and drafting support is often unspecified. Public demonstrations may not reflect production permissions.

The practical operation of PIPL access, correction, explanation, and impact-assessment rights against police systems cannot be evaluated from published cases. Internal audits may exist without public disclosure.

Audit and compliance framework

A meaningful audit should begin with legality and institutional purpose, not model accuracy.

Purpose and authority. The agency should identify the exact statutory purpose, target harm, responsible controller, operational owner, and permissible response. “Public security,” “stability,” and “risk” should be decomposed into legally defined events.

System classification. Each module should be classified as record retrieval, identification, entity linkage, current-event detection, place forecasting, person-risk assessment, or generative decision support. Hybrid systems should not be assigned one benign label.

Data inventory. Every input should have a source, collection authority, timestamp, retention rule, accuracy status, sensitivity classification, and correction channel. Inferred attributes should be separated from observed facts.

Relationship evidence. Graph edges should state whether they represent kinship, declared contact, shared address, co-occurrence, communication, transaction, officer inference, or algorithmic similarity. Association alone should not be treated as criminal involvement.

Model documentation. Agencies should disclose model type, version, training and test periods, target label, features, exclusions, threshold, calibration, geographic validity, and known limitations. Rule-based systems require equally detailed rule and threshold registers.

Outcome validation. Evaluation should use independent outcome data and distinguish model-induced police observations from events arising independently. Precision, recall, false-positive rate, positive predictive value, lead time, subgroup performance, and operational burden should be reported.

Causal effectiveness. Where crime reduction is claimed, the design should include credible controls, pre-registration where possible, displacement analysis, changes in reporting, simultaneous interventions, and confidence intervals.

Human review. Reviewers must have access to underlying evidence, authority to reject the output, sufficient time, training in uncertainty, and a duty to document reasons. Rubber-stamp approval should be treated as automation.

Generative-AI controls. LLM output should link every material factual assertion to retrieved records; unverifiable generated content should be blocked from coercive decisions; prompts and outputs should be logged; sensitive data should be isolated; model changes should trigger revalidation; and adversarial testing should cover hallucination, identity confusion, prompt injection, and exculpatory omissions.

Necessity and proportionality. Agencies should compare the system with less intrusive alternatives and prohibit collection whose expected value does not justify rights costs. Sensitive data should require heightened authorization.

Equality testing. Testing must cover ethnicity, religion, language, sex, age, disability, nationality, residence status, and geographic proxies where lawful and methodologically possible. Where the target policy itself discriminates, technical parity testing is insufficient.

Operational limits. A weak alert should not independently justify detention, search, movement restriction, or adverse classification. Escalation should require objective, independently verified evidence proportionate to the measure.

Notice and challenge. People should receive notice when disclosure no longer jeopardizes a legitimate investigation, along with access to material facts, correction procedures, and independent review. Watchlist and risk-profile errors require expedited remedies because they recur across encounters.

Logging and traceability. Systems should log queries, data changes, model versions, alert generation, reviewer action, downstream sharing, and final disposition. Logs should be protected from alteration and available to independent auditors.

Procurement controls. Contracts should require acceptance testing, documentation, security updates, subcontractor disclosure, data-portability protections, audit access, performance warranties, bias testing, and termination rights.

Public accountability. Authorities should publish program purposes, vendors, broad data categories, aggregate alert and outcome statistics, error findings, retention rules, and audit summaries. Security-sensitive details can be withheld without concealing the existence and impact of the program.

Independent oversight. The institution operating the platform should not be its sole auditor. Effective governance requires an external body with technical expertise, access to source code and data, authority to compel remediation, and a channel for individual complaints.

Final assessment

China’s public-security transformation is best understood as the convergence of pervasive sensing, standardized networks, entity-centered data fusion, preventive governance, and expanding analytical automation. Golden Shield supplied foundational police informatization. Skynet and Sharp Eyes expanded video and organizational reach. Police Clouds and big-data platforms made heterogeneous records searchable and relational. IJOP demonstrated how such infrastructure could become an operational system of individualized suspicion in a setting where political, religious, and ethnic classifications were embedded into preventive security.

The 2024–2026 generative-AI wave does not erase that history. Large models are being attached to established databases, command systems, model libraries, and video platforms. Their immediate contribution is often convenience—querying, summarizing, drafting, and extracting—but convenience can increase the scale and speed at which existing risk categories are applied. The greatest danger is not necessarily an autonomous “pre-crime” oracle. It is a high-throughput institution in which uncertain inferences are converted into persuasive narratives, distributed instantly to frontline personnel, and insulated from challenge.

The strongest findings concern architecture and institutional function, not predictive validity. China has constructed extensive capacity to retrieve, identify, link, flag, and intervene. Public evidence is inadequate to show that its major systems accurately predict rare harmful events or reduce crime causally. In Xinjiang, available evidence instead shows that technological systems helped administer a broader campaign of discriminatory surveillance and arbitrary coercion, whose consequences cannot be evaluated as an ordinary public-safety optimization problem. citeturn18search1turn18search2turn18search16

Domestic law now contains more substantial privacy, security, necessity, and automated-decision language than existed when IJOP’s best-documented version was deployed. The 2025 video regulations and PIPL are not meaningless. They create standards against which collection, retention, access, and automation can be assessed. But their practical value for predictive policing depends on narrow legal purposes, independent supervision, disclosure sufficient for challenge, and remedies capable of overriding public-security institutions. Public evidence through August 2, 2026 does not demonstrate those conditions consistently.

Comparative analysis therefore should avoid two errors. China’s systems should not be treated as technologically unique or incomprehensible: U.S. watchlisting and European predictive policing exhibit recognizable problems of identity error, association, feedback, secrecy, and preventive intervention. But formal similarity should not flatten differences in scale, legal definitions, discriminatory policy, oversight, and consequences. IJOP’s documented connection to Xinjiang’s coercive campaign makes it more than a controversial algorithm. It is a case study in how data architecture can turn a state’s political conception of danger into routine, distributed police action.