Predictive Public Security in China: IJOP, Police Cloud, Skynet, Sharp Eyes, and the Expansion of Proactive Policing
Scope, methodology, and principal findings
This report examines how Chinese public-security institutions have moved from digitizing records and networking cameras toward systems intended to identify relationships, detect anomalies, generate warnings, and initiate police intervention before a conventional criminal case has been established. It covers developments through August 2, 2026, with particular attention to the Integrated Joint Operations Platform, or IJOP, in the Xinjiang Uyghur Autonomous Region; provincial and municipal “Police Cloud” systems; Golden Shield; Skynet; Sharp Eyes; public-security big-data platforms; and documented efforts in 2024–2026 to introduce large language models, generative-AI assistants, advanced video analytics, and proactive-warning functions.
The central finding is that China does not possess one monolithic surveillance platform called “Skynet,” “Police Cloud,” or “Golden Shield.” Instead, public evidence shows a layered and uneven ecosystem. National political and Ministry of Public Security directives establish policy priorities, networking requirements, data standards, security classifications, and preferred operational models. Provincial public-security departments construct data centers and “police clouds”; municipal and county bureaus procure applications, cameras, analytical modules, communications data, maintenance, and integration services; political-legal committees and social-governance bodies participate in Sharp Eyes and grid-management deployments; and state-owned and private vendors supply hardware, middleware, algorithms, systems integration, and training. Xinjiang’s IJOP was a region-specific operational system built within this broader institutional environment, not a national user interface through which every police officer in China conducts predictive policing. Official documents themselves sometimes budget separately for Golden Shield networking, Skynet cameras, Sharp Eyes networking, and smart-community systems, while other localities reuse or combine the labels “Skynet” and “Sharp Eyes.” citeturn3search0turn3search8turn3search12turn3search16
The strongest evidence supports five conclusions.
First, record retrieval, identity resolution, vehicle identification, entity linking, and rule-based alerting are more firmly documented than sophisticated probabilistic prediction. Police systems demonstrably combine household registration, identity, travel, lodging, vehicle, telecommunications, video, case, and police-observation data. Systems can search records, compare faces or license plates, draw relationship graphs, identify co-travel or co-residence patterns, and push alerts or work orders to officers. Public evidence is much weaker on whether most deployments accurately forecast an individual’s future criminal conduct or an event such as a protest. Chinese procurement and promotional documents frequently use terms such as “prediction,” “early warning,” “risk perception,” and “model,” but these may describe simple thresholds, watchlist matches, association rules, or keyword triggers rather than machine-learning forecasts validated against out-of-sample outcomes. citeturn2search17turn3search1turn13view0turn14view1
Second, the consequential step is often not an algorithmic score but the conversion of heterogeneous data into an actionable flag. In Xinjiang, Human Rights Watch’s reverse engineering of an IJOP mobile application found that the application collected detailed personal information, prompted officials to report specified conduct or circumstances, and assigned investigations in response to system-generated warnings. Ordinary and noncriminal conduct—including some forms of foreign contact, travel, communications use, religious practice, or deviations from administratively defined routines—could become grounds for questioning or further investigation. Human Rights Watch linked some flags to movement restrictions, house arrest, compulsory political education, or detention, although the app did not itself issue a judicial detention order. citeturn13view1turn23search2
Third, Xinjiang represents an unusually coercive combination of pervasive collection, ethnoreligious classification, checkpoints, home visits, and detention, rather than merely a technologically advanced version of routine policing. The Office of the UN High Commissioner for Human Rights found that available official and public documents indicated extensive surveillance of Uyghurs and other predominantly Muslim communities through cameras, facial recognition, checkpoints, device inspections, financial-history review, databases, and IJOP-generated bulletins and investigations. OHCHR concluded that the broader pattern of arbitrary and discriminatory detention could constitute international crimes, particularly crimes against humanity. citeturn12view1turn12view2turn22search6turn22search10
Fourth, outside Xinjiang, proactive policing has expanded but usually appears in more fragmented and function-specific forms. Municipal systems advertise the prevention of telecom fraud, identification of vulnerable potential victims, management of disputes, detection of unusual road or crowd conditions, monitoring of wanted persons and vehicles, investigation of organized crime, and warning about violent or “extreme” incidents. Some deployments also address petitions, collective incidents, “key persons,” political security, and “stability maintenance.” The balance between ordinary crime control and political-security objectives varies by locality, application, and institutional sponsor. citeturn0search10turn4search0turn4search7turn4search15
Fifth, 2024–2026 marked an identifiable shift toward large-model interfaces and AI-assisted workflow, but not proof that generative AI has replaced existing databases or alert rules. Police agencies reported deploying domestically hosted large models for call classification, document drafting, legal review, case-data extraction, relationship analysis, investigative suggestions, and natural-language access to police data. Video systems added abnormal-scene detection and automated patrol functions. These tools appear primarily as an additional interface and analytical layer over established data resources. Their existence is documented; their accuracy, training data, hallucination rates, operational reach, and influence over coercive decisions generally are not independently auditable. citeturn4search1turn4search3turn4search13turn4search14turn4search2
Source methodology and provenance. The evidentiary base has significant asymmetries. Official Chinese sources are strongest for institutional structure, terminology, policy objectives, standards, procurement scope, planned modules, and government justifications. They are generally weak on false positives, rights violations, failed projects, internal disagreement, and the precise consequences of flags. Procurement documents establish that an agency sought, contracted for, or specified a capability; they do not by themselves prove successful deployment, continuous operation, or accurate performance. Vendor white papers and award announcements are treated as evidence of product positioning or institutional interest, not as independent validation. For example, vendor descriptions of “object engines,” “tag engines,” unified search, or “intelligent warning” show intended architecture but not how accurately a particular police bureau used those functions. citeturn2search9turn2search12turn2search24
Human Rights Watch’s 2019 IJOP study is unusually important because the organization obtained a police application, commissioned the security firm Cure53 to reverse engineer it, compared technical findings with Chinese procurement records, and interviewed affected people. The analysis therefore goes beyond interpreting policy language, although it examined a particular application version and could not inspect every server-side rule, database, or subsequent update. Its identification of Xinjiang Lianhai Chuangzhi, a China Electronics Technology Group subsidiary, as the application’s developer was based on procurement records and technical evidence. citeturn13view1
The “China Cables” consist of leaked internal Xinjiang directives and IJOP bulletins received through an exile-mediated source chain and published by the International Consortium of Investigative Journalists. ICIJ subjected the documents to linguistic, formatting, contextual, and expert authentication, and consulted former officials and intelligence specialists. They remain an incomplete, selectively leaked collection rather than a full archive, and publication does not establish that every instruction was implemented identically in every locality. citeturn16search0turn16search3turn16search6turn16search15
The “Aksu List,” analyzed by Human Rights Watch, was a 2018 list concerning more than 2,000 people reportedly detained in Aksu and was supplied through Radio Free Asia. It is valuable because it connects IJOP-related reasons to named detention cases, but the present report does not reproduce names of nonpublic individuals. Its custody, geographic limitation, and lack of a complete companion database require caution. citeturn16search1turn16search7
The “Xinjiang Police Files” originated with an anonymous hacker claiming access to police computer systems and were authenticated in part by a multinational media consortium through document checks, geolocation, communication with affected families, and comparison with other records. The collection was curated and analyzed by Adrian Zenz and associated organizations whose advocacy positions and funding have been subjects of political dispute. Those circumstances do not by themselves invalidate the records, but they make independent corroboration and separation of primary files from interpretive claims essential. citeturn16search2turn16search11
The Urumqi Police Database documentation project is based on a breach containing hundreds of thousands of police reports from 2017–2019. Such material can reveal operational language and routine police interactions unavailable in public procurement notices, but a breach may be incomplete, manipulated, or stripped of database context. It also creates privacy and source-security risks. This report therefore uses aggregate findings and does not reproduce personal identifiers, addresses, phone numbers, or operational details that could endanger individuals. citeturn16search22
OHCHR’s Xinjiang assessment is neither a forensic audit of IJOP source code nor a criminal judgment. It synthesizes official laws and statements, public records, documentary studies, and interviews that the office considered credible. Its institutional independence and legal analysis make it highly probative, but its conclusions should be described in its own terms: the office found serious violations and stated that the extent of arbitrary and discriminatory detention “may constitute” international crimes. citeturn22search6turn22search10
Institutional and technical history
China’s contemporary public-security data environment developed in successive, overlapping phases rather than through a single master build. Early police informatization concentrated on communications networks, digitized population and case records, and cross-jurisdictional access. Camera networks then expanded through Safe City and locally branded Skynet projects. Police intelligence systems increasingly integrated administrative, commercial, internet, and sensor data. Sharp Eyes extended video networking and social-governance participation into counties, townships, villages, residential compounds, and grid-management structures. More recent “public-security big data” and “new policing operating model” initiatives have emphasized data fusion, analytical models, automated warnings, closed-loop tasking, and AI-assisted work.
Golden Shield as infrastructure, not a universal predictive engine. The Golden Shield Project, formally associated with the national public-security informatization program, was proposed by the Ministry of Public Security in 1998 to improve communications, coordinated operations, rapid response, and investigative efficiency. Contemporary descriptions characterized it as a police communications network and computer-information-system project. Ministry reporting on later completion of Golden Shield’s second phase stated that informatization had reached major areas of policing and created a horizontally and vertically connected system. These descriptions support treating Golden Shield as foundational infrastructure and databases, not as the name of every subsequent camera or prediction system. citeturn21search13turn21search22
Golden Shield is also frequently confused in foreign commentary with China’s internet filtering system, sometimes called the Great Firewall. The overlap lies in public-security and information-control institutions, network-security technology, and historical procurement—not in evidence that a single application simultaneously performs internet censorship, household-registration queries, facial recognition, and IJOP alerting. Later police clouds and video platforms may use networks and identity resources developed during Golden Shield, while remaining separate procurement, software, and governance projects.
Camera-network expansion. Urban “Safe City” and “Skynet” projects built and linked public-space cameras, traffic checkpoints, license-plate systems, video command centers, and storage. “Skynet” is more a recurring programmatic label than a single nationally uniform product. Local police reporting describes city video networks supporting retrospective investigation, live public-order monitoring, wanted-person or vehicle searches, and event security. Some local systems integrate camera feeds with identity readers, vehicle checkpoints, electronic patrol tools, and augmented-reality command maps. citeturn3search6turn3search14turn21search4turn21search8
A decisive policy document was the 2015 National Development and Reform Commission–led opinion on strengthening public-security video monitoring, networking, and application. It called for interconnected video resources and national and provincial video-image analysis centers, and specifically identified face comparison, license-plate recognition, intelligent warning, trajectory analysis, rapid retrieval, data mining, and linkage with social-governance video systems. The directive set an architectural and policy direction but left implementation to numerous agencies and local projects. citeturn3search1
Sharp Eyes. Sharp Eyes, formally associated with public-security video monitoring construction, networking, and application, added an explicit social-governance and mass-participation dimension. Official descriptions place county, township, and village comprehensive-governance centers at its organizational core, with grid management and video networking intended to extend prevention into rural and neighborhood settings. In some early implementations, residents could view selected village cameras through television set-top boxes or mobile applications and report suspicious circumstances. citeturn21search1turn21search3turn21search18turn21search23
Sharp Eyes is consequently neither simply another name for facial recognition nor merely a rural camera purchase. Its institutional logic links cameras to political-legal committees, comprehensive-governance centers, community cadres, grid workers, police, and public participation. A Zhejiang policy document described it as a public-security project oriented toward county, township, village, and grid-level governance. Nevertheless, local naming is inconsistent: some budgets describe “Skynet/Sharp Eyes” as phases of one video program, while other agencies distinguish Skynet, Sharp Eyes, social video, and smart-community resources. citeturn3search12turn3search16turn3search24
Police intelligence and Police Cloud. Beginning before the widespread use of the term “Police Cloud,” Chinese public-security agencies developed “great intelligence” platforms intended to combine internal police databases with external government and commercial records. The Police Cloud concept generally denotes provincial or municipal computing, storage, data-governance, sharing, and analytical environments rather than a single national application. Human Rights Watch’s review of procurement records from Shandong, Jiangsu, and Tianjin found projects designed to aggregate police and non-police data, reconstruct people’s movements and relationships, detect unusual behavior, and produce warnings. HRW also cited a 2015 Ministry of Public Security information-sharing regulation that instructed provincial authorities to construct police clouds as a foundation for wider information exchange. citeturn13view0
A Chinese state information-center article provides a representative conceptual architecture. It describes importing data from internal police systems, other government departments, “social” or commercial sources, the internet, and multimedia sensors; standardizing the information; organizing it into background, dynamic, relationship, and characteristic-information libraries; and exposing it through resource, service, and application layers. This is an architectural ideal rather than proof that every locality has complete access to every category, but it closely matches procurement language found across provinces. citeturn2search17
The Ministry of Public Security has supported this development through national standards and catalogues. Ministry reporting stated that it had established technical standards covering a new-generation police network, police cloud, big-data processing, data security, a ministry-level big-data platform, and a standardized comprehensive police platform and data-resource catalogue. The national standards registry includes requirements for public-security big-data governance and resource catalogues, while the GA/T 1400 family specifies general, platform, database, and interface requirements for police video-image information application systems. citeturn0search0turn2search3turn21search2turn21search5
These standards facilitate interoperability; they do not establish that all data are stored in one national database. Standardized interfaces can permit federated queries, scheduled replication, cross-regional exchange, or the transfer of selected records without abolishing local ownership, classification, data-quality differences, or access controls. China’s public-security architecture is therefore better understood as a hierarchical and partially federated ecosystem with national direction and growing interoperability, rather than either a completely centralized super-database or a collection of isolated local systems.
Xinjiang’s IJOP. IJOP emerged amid the intensified “Strike Hard” counterterrorism campaign and regional securitization from 2014 onward, particularly after Chen Quanguo became Xinjiang Party secretary in 2016. It was designed to aggregate information from checkpoints, police databases, officials’ observations, and other sources; identify persons or circumstances deemed suspicious; and direct grassroots personnel to investigate. Procurement and application evidence links the system to Xinjiang Lianhai Chuangzhi, a subsidiary of the state-owned China Electronics Technology Group Corporation. citeturn13view1turn23search2
IJOP drew on techniques seen elsewhere—identity databases, video, device identifiers, relationship analysis, and mobile police tasking—but was embedded in Xinjiang’s region-specific counterterrorism, religious-governance, and detention apparatus. It therefore should not be treated as merely Xinjiang’s brand name for Police Cloud, although it likely depended on regional data centers and police networks that performed analogous infrastructure functions.
Big-data-driven policing after 2018. Ministry policy increasingly framed data as a basic policing resource and sought to combine specialized police units, institutional mechanisms, and big data. The formula “professional capabilities + operating mechanisms + big data” became a national model associated with integrated intelligence, command, operations, and supervision. Provincial authorities then constructed local versions with varying platforms, data access, vendor relationships, and priorities. citeturn0search9turn0search16
From 2023 onward, this model was paired with a three-year technology-driven policing action plan and growing emphasis on “new-quality public-security combat capability.” By 2026, Ministry-affiliated reporting claimed that AI models had been embedded in risk warning, crime investigation, public-order prevention, and public services. Such statements establish national encouragement and numerous deployments, but the term “embedded” may encompass pilot assistants, specialized classifiers, natural-language interfaces, or limited demonstration projects. citeturn4search2
The principal policy and standards milestones can be summarized as follows:
| Period | Documented development | Evidentiary significance |
|---|---|---|
| 1998–2006 | Golden Shield proposed and national police-network components constructed and accepted. citeturn21search13turn21search22 | Foundation for cross-jurisdictional police communications, digitized records, and later applications; not itself proof of predictive analytics. |
| Late 2000s–mid-2010s | Municipal Safe City and Skynet video networks expand. citeturn3search6turn21search14 | Establishes local camera, storage, command, and investigative infrastructure. |
| 2015 | National video-networking opinion calls for analysis centers, facial and plate comparison, intelligent warning, trajectory analysis, and social-video integration. citeturn3search1 | Clear national policy basis for interconnected and analytically enriched video. |
| 2015 onward | Ministry information-sharing policy and provincial tenders support Police Cloud construction. citeturn13view0 | Supports provincial data aggregation and cross-system querying; implementation remains locally varied. |
| 2016–2017 | Sharp Eyes becomes a national social-governance and video-networking priority; IJOP expands in Xinjiang. citeturn21search3turn21search18turn13view1 | Rural/community video and grid governance expand while Xinjiang develops a particularly coercive integrated-warning system. |
| 2017–2023 | GA/T 1399 and GA/T 1400 series establish video-analysis and video-information application requirements, followed by testing, security, and retrieval standards. citeturn21search2turn21search5 | Interoperability and modular procurement become easier, although compliance and implementation cannot be inferred from issuance alone. |
| 2018–2021 | MPS advances the public-security big-data strategy, new police clouds, catalogues, governance, and data-security standards. citeturn0search0turn0search16 | Big data becomes a national operational model rather than an isolated technology project. |
| 2024 | “Professional + mechanisms + big data,” proactive prevention, predictive dispute models, and integrated large-model pilots receive prominent official attention. citeturn0search2turn0search9turn0search12 | Indicates movement from search and retrospective investigation toward automated tasking and prevention. |
| 2025 | Local bureaus report DeepSeek-based platforms, large-model call handling, risk-analysis models, video patrol, and AI agents. citeturn4search0turn4search1turn4search13 | Strong evidence of experimentation and workflow integration; limited evidence of independently validated prediction. |
| 2026 | National reporting describes AI across warning, investigation, prevention, and service; local procurements add open-source intelligence, technical forensics, analytics, and automated investigative support. citeturn4search2turn13view2 | Suggests institutionalization of AI-assisted policing, while operational coverage and accuracy remain opaque. |
System relationships, vendors, and data-flow architecture
The relationship among these systems is best represented as layers that may be connected in particular jurisdictions but remain institutionally and technically separable.
Central political and legal priorities
│
├── State Council / central political-legal policy
├── Ministry of Public Security strategy, networks, catalogues and GA/T standards
└── National data-sharing, cybersecurity and counterterrorism rules
│
▼
Provincial public-security departments
├── Police cloud / big-data center
├── provincial population, case, intelligence and video resources
├── cross-city data exchange and model services
└── provincial command and intelligence mechanisms
│
┌──────────┴──────────┐
▼ ▼
Municipal/county police Political-legal and social-governance bodies
│ │
├── police stations ├── Sharp Eyes
├── investigation ├── grid management
├── 110 command ├── community governance centers
├── Skynet/video └── community reporting and tasking
└── local models
│
▼
Front-end collection and intervention
├── cameras, checkpoints, plate readers and access control
├── officer mobile terminals and field observations
├── administrative and commercial data feeds
├── alerts, investigative leads and work orders
└── questioning, visits, checks, restrictions or case action
In Xinjiang, IJOP occupied an application and operational-workflow position spanning the provincial or regional big-data layer and grassroots intervention. It collected or received information, applied rules or labels, generated investigation tasks, and required officers or cadres to report results. The available evidence does not show that IJOP was the sole repository for all Xinjiang data, nor that every camera sent raw video directly into a single IJOP server. It is more plausible—and consistent with Chinese systems architecture—that IJOP queried or consumed outputs from multiple databases and subsystems, including identity, checkpoint, device, and video resources. This is an inference from the app’s functions, procurement architecture, and China’s wider layered model rather than a complete published network diagram. citeturn13view1turn2search17
Golden Shield versus Police Cloud. Golden Shield supplied earlier national and local police-network and information-system foundations. Police Cloud represents a later computing and data-integration model that can host or connect population, case, travel, video, and analytical services. A locality may budget for upgrading its Golden Shield network while separately procuring police-cloud storage or applications. The terms therefore denote different generations or layers, not mutually exclusive systems. citeturn3search8turn21search22
Skynet versus Sharp Eyes. Skynet commonly refers to police-oriented urban video surveillance and command networks, although local scope varies. Sharp Eyes emphasizes broader networking, rural and community coverage, social-governance centers, grid management, and sometimes citizen viewing or reporting. A 2024 Guizhou public-security report separately identified Sharp Eyes, Skynet, and “social video” as three resource pools being fused, which is strong evidence against treating them as inherently identical. At the same time, procurement titles such as “Skynet phase six—Sharp Eyes” show that local governments may merge the brands or use one as an expansion phase of another. citeturn3search2turn3search12turn3search16
Video platforms versus public-security big data. Cameras and video platforms generate images, metadata, feature vectors, plate reads, trajectories, and event alerts. Big-data platforms can combine those outputs with identity, case, lodging, vehicle, telephone, or administrative records. Standards in the GA/T 1399 and 1400 families create common interfaces and database structures for video-image analysis and application systems. They make integration more feasible, but neither the standards nor the term “Skynet” demonstrates automatic access to every police or commercial database. citeturn21search2turn21search5
Vendor roles. The supply chain is divided among prime contractors, systems integrators, network and storage vendors, camera manufacturers, algorithm suppliers, telecommunications-data providers, and specialized software companies. One vendor may provide cloud infrastructure without controlling the police rules applied to the data; another may supply cameras and facial-recognition software; a third may integrate databases; and a local research institute may build a model on top of all three.
CETC is particularly important to IJOP. Human Rights Watch linked the IJOP application to Xinjiang Lianhai Chuangzhi, described in procurement material as a CETC subsidiary. CETC, a centrally controlled state-owned defense-electronics conglomerate, had publicly promoted integrated anti-terrorism data systems. That evidence supports a direct vendor relationship for the analyzed IJOP application, but it does not establish that CETC alone supplied every IJOP data source, camera, checkpoint device, or later software version. citeturn13view1
Hikvision and Dahua are major Chinese video-surveillance manufacturers whose products have been used in public-security and Xinjiang projects, but the existence of their cameras at a site should not be equated automatically with control of IJOP’s analytical rules. Camera manufacturers can supply front-end devices, storage, video-management software, facial comparison, and integration services while a separate contractor operates the overarching data platform. U.S. regulatory actions subsequently placed certain Hikvision and Dahua public-safety and national-security equipment on the Federal Communications Commission’s Covered List, reflecting U.S. national-security determinations rather than an adjudication of every product’s use in China. citeturn23search1turn23search6turn23search10
Chinese cloud and network vendors market police-cloud infrastructure with unified resource pools, object or tag engines, search services, and integrated command support. H3C and QingCloud materials illustrate the commercial architecture, but vendor diagrams should be read as proposed solutions, not proof that a named bureau has all advertised capabilities. Likewise, analytics vendors advertise intelligence-lead management and knowledge graphs without publishing error rates, customer configurations, or evidence that their outputs directly determine coercive action. citeturn2search9turn2search12turn2search24
Documented data categories. The following table includes a category only where public evidence supports its collection or use in at least one relevant system. It does not mean that every system or locality holds every category.
| Data category | Documented evidence and likely role | Limits |
|---|---|---|
| Identity and household registration | National ID, name, sex, date of birth, hukou, address, household and family links support record retrieval and identity resolution. IJOP collected identity-linked personal information; police clouds draw on population databases. citeturn13view0turn13view1 | Coverage is broad, but public evidence does not establish identical fields or live synchronization everywhere. |
| Residency and lodging | Hotel registrations, temporary residence, co-residence, and changes of address can be queried or analyzed for movement and associations. citeturn13view0 | Procurement aspirations may exceed actual completeness; informal lodging may not appear. |
| Travel and checkpoints | Air and rail travel, border or passport information, checkpoint passages, and foreign travel were used in Police Cloud and IJOP-related assessment. citeturn13view0turn12view1turn12view2 | Evidence is strongest for ticketed travel and Xinjiang checkpoints, not continuous universal location tracking. |
| Communications identifiers and metadata | Phone numbers, device identifiers, communications relationships, internet or application-related information, and mobile-device checks feature in IJOP and police big-data systems. citeturn13view1turn12view1 | Public evidence does not establish that IJOP itself possessed the content of all calls or messages. Metadata, device inspection, and platform-derived records must be distinguished from full interception. |
| Financial activity | OHCHR identified scrutiny of financial history in Xinjiang; later police systems analyze funds in fraud and criminal investigations. citeturn12view1turn14view2turn4search14 | Evidence supports targeted or system-accessible financial analysis, not a single real-time ledger of every transaction available to every officer. |
| Purchases, deliveries, and commercial activity | Police Cloud tenders reviewed by HRW described supermarket, delivery, and other commercial records linked to identity. citeturn13view0 | Tendered access does not prove complete nationwide coverage or reliable identity matching. |
| Utilities | Xinjiang research found that abnormal electricity use and related household circumstances could be treated as suspicious indicators. citeturn13view1 | The evidence concerns specified IJOP-related rules, not routine utility scoring throughout China. |
| Health and medical information | Police Cloud procurement analysis identified medical records among external data sources. citeturn13view0 | Actual fields, legal basis, frequency of access, and geographic coverage remain unclear. |
| Religious practice and material | IJOP-related collection and investigations encompassed religious practice, religious knowledge, possession or use of religious material, and contacts deemed religiously suspicious. OHCHR identified automated or database-assisted flagging of religious material. citeturn13view1turn12view1 | This is strongly documented in Xinjiang; evidence for equivalent systematic religious classification elsewhere is much weaker. |
| Social and family relationships | Family, household, telephone contacts, co-travel, co-residence, visits, and association networks are used for link analysis. citeturn13view0turn13view1turn4search14 | A graph edge may reflect innocuous contact; public systems rarely reveal weighting or evidentiary thresholds. |
| Biometrics | Facial images, fingerprints and, under specified counterterrorism authority, iris and biological samples may be collected. Facial comparison is standard in video platforms. citeturn3search1turn5search2 | Availability and legal authority vary by data type; claims of universal gait, iris, DNA, or voice coverage should not be assumed. |
| Vehicles | Registration, ownership, plate reads, vehicle characteristics, checkpoint passages, and trajectories support identification and tracking. citeturn3search1turn21search4turn21search24 | A plate match identifies a vehicle, not necessarily its driver; cloned or obscured plates create errors. |
| CCTV and extracted features | Public, traffic, community, and some socially owned cameras provide live or stored video; systems may extract faces, bodies, plates, trajectories, or abnormal events. citeturn3search1turn3search17turn21search27 | Camera existence does not prove facial recognition is enabled, accurate, continuously operating, or connected to a particular database. |
| Police and cadre observations | Officers and local officials enter interview results, household conditions, perceived suspicious behavior, and task dispositions into mobile or police platforms. citeturn13view1 | These records can encode subjective judgments and may become self-reinforcing if later models treat prior police attention as an objective risk signal. |
| Case, complaint, and emergency-call data | Criminal and administrative cases, 110 calls, reports, prior police contacts, and investigative materials are core police data resources; large models increasingly classify and summarize them. citeturn4search1turn4search13turn14view1 | A report or call is not proof of wrongdoing; duplicate, unverified, or malicious complaints may persist. |
A generalized data flow. At the collection layer, data arrive from police registration and case systems, other state agencies, commercial or platform partners, cameras and sensors, telecommunications-related services, and officers’ mobile terminals. An integration layer cleans records, converts formats, resolves identities, deduplicates entities, and associates people, devices, vehicles, locations, and events. Analytical services then execute searches, watchlist comparisons, feature extraction, graph analysis, anomaly rules, statistical models, or increasingly natural-language queries. Results appear as hits, labels, risk categories, alerts, reports, or task orders. Officers verify, question, visit, monitor, investigate, restrict, or open a case, and their dispositions return to the system as new data. citeturn2search17turn14view1turn13view1
This last feedback loop is analytically important. When prior police attention becomes an input for future risk detection, the system may generate circular evidence: a neighborhood, family, religious community, or petitioner appears “high risk” because it has been repeatedly policed; that classification produces more stops and reports; those reports then validate the original classification. European fundamental-rights research describes comparable feedback-loop risks in algorithmic policing, and the structure of IJOP creates the same possibility even when the initial rule is not machine learned. citeturn18search3turn13view1
The IJOP case study: functions, flags, and consequences
IJOP provides the clearest documented example of proactive public-security data processing in China because multiple source types converge: a reverse-engineered police application, procurement records, internal bulletins, a detention list, survivor testimony, leaked police files, and OHCHR analysis. No single source provides a complete system image, but their areas of agreement permit firmer conclusions than are possible for most provincial police clouds.
Technical and organizational role. Human Rights Watch identified three principal functions in the mobile application it examined: collecting detailed information about individuals; requiring officials to report activities or circumstances prescribed as suspicious; and receiving system instructions to investigate people flagged by the platform. The application linked entries to identity records and enabled officials to complete investigative tasks in the field. It therefore functioned not just as a search tool but as a human–machine workflow connecting data analysis to grassroots policing. citeturn13view1
The application’s client-side code could reveal fields, workflow, categories, and communications with the platform, but not every server-side model or data source. Consequently, it is possible to establish that the system generated specified categories of warnings and investigation tasks without knowing the full weighting, whether particular warnings were generated by fixed rules or statistical models, or how rules changed after the analyzed version.
Internal IJOP bulletins published in the China Cables further indicate that the platform was used to identify large groups of persons for investigation based on data matching and specified behavioral or relationship criteria. The bulletins describe operational follow-up rather than a fully autonomous detention decision. Their significance is that they connect platform output to bureaucratic directives and reporting requirements, although they cover selected periods and may not represent every regional workflow. citeturn16search3turn16search6
What constituted suspiciousness. IJOP-related criteria documented by Human Rights Watch included some conduct with a plausible connection to security investigations, such as possession of material authorities considered extremist. But the system also treated many lawful or ambiguous circumstances as suspicious: certain foreign contacts or travel, use of communications tools, failure to use a phone normally, unusual electricity consumption, entering through a building’s back door, relationships to already monitored people, or religious conduct that authorities classified as excessive or unauthorized. citeturn13view1turn23search2
The significance is not that every listed behavior automatically led to detention. Rather, the rules lowered the threshold for state intervention by converting ordinary variation into an investigative obligation. A person could be questioned not because police possessed individualized evidence of a planned offense but because the person matched a category created for administrative counterterrorism and stability control.
The Aksu List provides an important consequence-level cross-check. Human Rights Watch’s analysis found detention reasons involving religious practice, contact with foreign countries, possession or use of certain applications, relationships with other flagged persons, and prior travel. Because the list concerned one prefecture and was obtained through an intermediary, it cannot yield a reliable regional detention rate. It nevertheless demonstrates that at least some data-driven or IJOP-associated reasons were recorded in detention administration. citeturn16search1turn16search7
OHCHR independently found that surveillance in Xinjiang encompassed facial-recognition cameras, checkpoints, access to personal electronic devices, financial histories, and police databases, and that IJOP bulletins and the associated application could automatically identify conduct or connections for police follow-up. The office reported that such follow-up could result in referral to a vocational education and training center or another form of detention. citeturn12view1
Identity, ethnicity, and religion. IJOP did not operate in a socially neutral environment. It was deployed during a campaign directed overwhelmingly at Uyghurs, Kazakhs, and other predominantly Muslim Turkic communities. Household registration, language, family ties, travel, religious practice, and foreign connections could act as explicit fields or proxies for group membership. Checkpoints and neighborhood policing subjected members of these communities to much more intensive scrutiny than Han residents. OHCHR found that the surveillance and restrictions were discriminatory in purpose or effect and linked them to broader restrictions on religion, movement, privacy, and family life. citeturn12view0turn12view1turn12view2
The system’s logic created guilt by association at several levels. Family members of detainees or persons abroad could attract scrutiny. Telephone or social contact with a monitored person could produce a relationship edge. Co-travel, co-residence, religious participation, or membership in a household could be treated as risk-relevant even when there was no evidence that the associated person knew of, supported, or participated in an offense. citeturn13view1turn16search1
In conventional criminal investigation, association evidence can be relevant when combined with individualized facts concerning planning, intent, capability, or participation. In IJOP’s documented use, association could instead initiate a broad administrative investigation whose subject might not know the underlying allegation or be able to rebut the data. The difference is not simply technological; it concerns the evidentiary threshold and the consequences attached to administrative suspicion.
Rule-based alerting versus risk scoring. Public commentary sometimes describes IJOP as assigning every person a predictive “score.” The available evidence more securely establishes categorical labels, watchlists, behavior rules, relationship flags, and investigation tasks. Some Chinese police systems and vendors do advertise scores or composite risk indexes, but neither the reverse-engineered application nor the public IJOP documents disclose a stable, universal numerical score comparable to a commercial credit score. Describing IJOP as a system of algorithmic and rule-based classification is therefore more accurate than asserting that every Xinjiang resident received a single quantified risk rating. citeturn13view1turn16search6
“Algorithmic” here includes deterministic rules and database matching, not only machine learning. A rule such as “flag individuals with specified foreign contacts and another listed attribute” can produce automated, large-scale, rights-affecting decisions even if no neural network is involved. The opacity and discriminatory impact can be comparable to those of a statistical classifier.
From alert to intervention. Documented consequences existed on a continuum. A flag could trigger record checks, an officer’s visit, an interview, device inspection, community-cadre monitoring, a requirement to report regularly, movement restrictions, denial of travel, home confinement, or referral for detention. The platform was not the formal legal authority for each measure; police, Party-state committees, prosecutors, detention administrators, and camp authorities made or implemented decisions. Yet IJOP materially shaped who entered that chain and what information officials collected. citeturn13view1turn12view1turn12view2
This distinction matters when assigning responsibility. An algorithmic flag is not equivalent to a judgment, but a system designed to generate compulsory investigation orders can be causally significant even when a human signs the final form. “Human in the loop” is not a meaningful safeguard if the human reviewer lacks time, independence, contrary evidence, or authority to reject the system’s premise.
False positives and unreviewable records. No authoritative public audit discloses IJOP’s false-positive rate. Indeed, the concept is difficult to define because many alert categories were administrative judgments—such as whether religious practice was “abnormal”—rather than predictions testable against an objectively defined future crime. A person might be “correctly” identified as having traveled abroad while being wrongly treated as a terrorism risk. Technical matching accuracy and substantive legitimacy are separate questions.
Data-quality errors could arise from mistaken identity, reused telephone numbers, transliteration of Uyghur names, stale addresses, family-record errors, imperfect face matches, inaccurate officer observations, or incorrect assumptions about household and device ownership. Relationship analysis magnifies such errors because an incorrect identity link can propagate through a network. Public evidence offers no indication that subjects received systematic notice of the data, access to source records, an explanation of the rule, or a practical procedure for correction before consequences occurred. citeturn13view1turn12view1
Circular data production. IJOP depended heavily on information entered by police and cadres. A system-generated task produced a visit; the visit produced a report; the report became another data point; and the accumulated record could justify continued attention. This is a reasoned inference from the documented workflow. It means the platform could manufacture the empirical appearance of risk by repeatedly measuring the consequences of its own earlier classifications. citeturn13view1
Chilling effects. Affected people could rationally respond by avoiding overseas relatives, religious gatherings, messaging applications, unapproved travel, private political discussion, or other lawful conduct that might generate a flag. Such effects do not require every person to be continuously monitored; the credible possibility of observation and the opacity of thresholds can produce self-censorship. OHCHR’s findings on checkpoints, device scrutiny, religious restrictions, and discriminatory monitoring support the conclusion that surveillance was part of a wider environment constraining privacy, movement, religion, expression, and association. citeturn12view0turn12view1turn12view2
What IJOP has not been shown to do. Public evidence does not demonstrate that IJOP could reliably predict a particular terrorist attack before planning began, infer intent from video alone, continuously intercept every communication, or autonomously order imprisonment. Nor is there sufficient evidence to establish the current operational status, name, or architecture of every IJOP component in 2026. Xinjiang’s security institutions may have renamed, replaced, distributed, or integrated functions into newer platforms. The absence of recent public references could reflect secrecy, institutional migration, or reduced use; it should not be treated as proof of either continued operation in its original form or complete discontinuation.
Deployment elsewhere and the turn toward proactive AI
Outside Xinjiang, public-security big-data and video systems operate across a much broader spectrum of policing. They support ordinary criminal investigation, emergency response, traffic management, missing-person searches, anti-fraud work, crowd and event management, community policing, and administrative enforcement. They also support political-security and stability-maintenance tasks, including monitoring petitioners, collective disputes, sensitive anniversaries, online opinion, and people categorized as “key persons.” The systems’ names and modules vary, making functional comparison more useful than brand comparison.
Retrieval and identification. The most mature functions are searches across population, case, vehicle, lodging, and travel data; plate and face comparison; retrospective video retrieval; and the identification of links among people, telephone numbers, addresses, accounts, vehicles, and events. Police video standards and local deployments support human, vehicle, license-plate, and trajectory searches. Official reports describe these capabilities as routine tools for solving theft, robbery, violent crime, and hit-and-run cases. citeturn3search1turn3search18turn21search27
These functions can be highly consequential without being predictive. A face comparison may identify a person already sought by police; a plate reader may locate a stolen vehicle; a relationship graph may reveal that suspects share an account or address. Such uses resemble data-driven investigation in many countries and should be distinguished from preventive intervention based on lawful behavior.
Proactive warnings. Provincial and municipal agencies increasingly describe moving from “passive response” to “proactive prevention,” “source governance,” or “early discovery, early warning, and early disposal.” Jiangsu reporting, for example, emphasizes risk perception and preventive handling; Shanghai police reported thousands of data models intended to detect risks in advance; and Sichuan described broad scenario modeling in 2026. citeturn0search10turn4search7turn0search17
The underlying models can range from straightforward rules to machine learning. A fraud model might identify an elderly person who has just withdrawn an unusually large sum of cash and prompt police to warn the person. A domestic-dispute model might combine repeated emergency calls, prior violence, protective-order records, and local officer assessments. A public-order model might detect an unusual crowd or vehicle flow. A political-security system might flag an activist’s travel, contacts, or online activity. The shared technical vocabulary does not make these applications normatively equivalent.
An official 2024 Ministry report described a grassroots-prevention model that claimed 77 percent accuracy in identifying potential disputes or security risks and reported complete handling of generated tasks. These figures are agency-reported and lack an independent evaluation protocol, denominator, definition of a correct prediction, or analysis of people incorrectly flagged. “Complete handling” means a task was disposed of administratively, not that the warning was substantively accurate. citeturn0search2
Changzhou’s 2024 “super-fusion” platform illustrates the convergence of data integration, models, and field tasking. The city described combining perceptual, police, and geographic data; incorporating a large model; having models generate basic-work tasks; requiring police verification; and feeding results back through a command platform connected to location, video, and drone resources. The published task counts demonstrate claimed scale but are not an audit of accuracy, necessity, or rights impact. citeturn0search12
Detailed procurement evidence. A 2025 Shijiazhuang procurement specification for an investigative center is particularly revealing because it describes required modules rather than only high-level slogans. It cites Ministry directives calling for integrated investigation centers and for early warning, early response, and early enforcement. The specification seeks data fusion, compound labeling, collaborative modeling, automated or recommended case analysis, standardized analytical reports, and closed-loop work orders. Modules include mobile-internet data services, online-crime warnings, funds analysis, video investigation, telephone-related capture tools, and anti-fraud applications; a subsequent phase planned open-source intelligence, broader analytics, technical forensics, organized-crime applications, and application reverse engineering. citeturn14view0turn14view1turn14view2turn13view2
Because this is a procurement requirement, it establishes institutional intent and the desired architecture. It does not establish that all modules passed acceptance tests, achieved advertised performance, or were used in every investigation. It also illustrates why references to “AI policing” must be disaggregated: some modules are data subscriptions, some are forensic tools, some produce network graphs, some automate reports, and some may apply predictive models.
Large language models and generative AI. From 2024 onward, police agencies began publicly associating large language models with public-security work. The principal documented functions are natural-language interaction with police knowledge bases, extraction of entities and keywords from case material, summarization, document generation, call classification, legal and procedural guidance, search, relationship analysis, and suggested investigative steps.
Guizhou’s “Guijing Brain” was described as a large-model platform serving intelligence command, case handling, grassroots prevention, investigation, and public services. Zhangjiakou’s “Officer Zhang” reportedly contained hundreds of AI-agent modules for asking questions, processing matters, investigating, and searching. Yueyang public-security reporting described a privately deployed DeepSeek model extracting keywords, inferring behavior patterns, drawing relationship and fund-flow structures, grading calls, suggesting response plans, and reviewing legal documents. citeturn4search3turn4search13turn4search14
Suzhou’s 110 emergency-call model pushed individualized handling guidance to call takers or dispatch personnel. Such an application could improve consistency and help inexperienced staff retrieve procedures. It could also misclassify ambiguous speech, dialect, mental-health crises, domestic violence, or politically sensitive complaints. The available official report does not disclose training data, error rates, whether personnel can reject recommendations, or whether model outputs are retained as risk indicators. citeturn4search1
A 2025 Hunan police technology-award list included projects described as a DeepSeek public-security platform, a social-risk analysis and warning model, a model for preventing “individual extreme” incidents, and intelligent video patrol. Award listings verify that agencies or affiliated developers presented such projects and that authorities valued them; they do not show production scale or successful prediction. citeturn4search0
Advanced video analytics. Video systems increasingly advertise detection of fights, falls, crowding, abandoned objects, smoke, traffic incidents, perimeter intrusion, and other “abnormal scenes.” Shenzhen’s 2025 rule-of-law report described intelligent video patrol and road-abnormality warning, together with drones and robotic equipment. Older Wuhan reporting had already described automatic roadway alerts, identity and vehicle filtering, and real-time people-and-vehicle monitoring. citeturn4search10turn21search4
Some abnormal-event detection can be objectively evaluated, but context remains difficult. A running crowd may reflect panic, exercise, celebration, or violence; a person lying down may be injured or resting; a gathering may be a permitted event, a labor dispute, or a queue. Low-prevalence events generate a basic false-positive problem: even a classifier with high nominal accuracy may produce many false alerts when the event sought is rare. No systematic Chinese public evaluation has been located that reports sensitivity, specificity, demographic performance, and downstream police outcomes for major public-security video-warning systems.
Anti-fraud and protective applications. Not every proactive intervention is punitive. Yancheng police reported using a model to identify possible fraud victims through large cash withdrawals and intervene before money was transferred. Similar systems correlate calls, transfers, accounts, device or platform data, and known scam patterns. These uses can prevent substantial harm, but they still involve financial-data access and may lead to questioning or temporary transaction restrictions. citeturn4search15
The rights analysis should therefore examine purpose, data minimization, accuracy, notice, retention, and remedy rather than presume that all prediction is inherently abusive. A narrowly tailored fraud warning based on a recent high-risk transaction differs substantially from labeling an ethnic or religious group suspicious. Nevertheless, technically beneficial systems can normalize infrastructure later repurposed for political monitoring.
Dispute and violence prevention. Chinese police increasingly seek to identify domestic, neighborhood, labor, debt, and mental-health disputes before escalation. This objective responds to genuine public-safety concerns, including attacks by individuals with unresolved grievances. Yet the administrative category “individual extreme incident” can combine violence prevention with broad monitoring of petitioners, people with mental-health conditions, debtors, laid-off workers, or politically aggrieved persons. Award descriptions and official narratives rarely disclose which attributes are used or whether social disadvantage itself becomes a risk proxy. citeturn4search0turn0search10
Political-security and stability maintenance. Chinese public-security responsibilities include not only ordinary crime but also political security, counter-subversion, counter-separatism, counterterrorism, management of mass incidents, and maintenance of social stability. Data systems can therefore treat protest organization, petitions, foreign ties, online mobilization, or politically sensitive associations as warning targets even when the anticipated conduct would be protected expression or assembly under international standards.
Police Cloud procurements reviewed by Human Rights Watch envisioned identifying activists, petitioners, and people associated with protests or “mass incidents,” alongside conventional criminal suspects. This does not prove that every provincial police cloud uses an identical political watchlist, but it shows that political and stability objectives were part of the architecture from an early stage. citeturn13view0
Comparison with Xinjiang. The technical components outside Xinjiang—identity resolution, camera analytics, mobile tasking, link analysis, watchlists, and alerts—can resemble IJOP. The key differences are degree, target definition, coercive environment, and consequences. Xinjiang combined those techniques with dense checkpoints, compulsory household visits, ethnoreligious classification, device inspections, collective family consequences, pervasive movement restrictions, and a large detention and political-education apparatus. OHCHR found this combination discriminatory and potentially connected to international crimes. citeturn12view1turn12view2turn22search6
Outside Xinjiang, most publicly described models concern a narrower event, case type, or operational problem and usually culminate in an officer check, warning, or investigation rather than automatic referral to mass detention. This is a relative distinction, not a conclusion that systems elsewhere are rights-respecting. Petitioners, dissidents, religious communities, labor organizers, and other politically sensitive groups can still face intensive monitoring and administrative coercion.
Generative AI as an accelerator rather than a new data source. Large models do not inherently create reliable knowledge. They make it easier to query, summarize, connect, and narrate existing police data. This can reduce search costs and expose useful relationships; it can also turn uncertain, stale, or prejudicial records into fluent but misleading investigative narratives. If an LLM describes a person as “high risk” based on previous police contacts, the natural-language output may obscure the fact that the underlying contacts involved no conviction or were themselves generated by earlier surveillance.
Official sources sometimes describe an officer verifying an AI-generated result. Verification is preferable to automatic action, but its adequacy depends on access to source data, uncertainty indicators, documentation of contrary evidence, and incentives to disagree. In hierarchical police organizations, an officer may treat a machine-generated task as an instruction rather than a hypothesis.
Consequences, error mechanisms, and the distinction between crime control and political security
The effects of proactive public-security systems cannot be evaluated solely by asking whether an algorithm “works.” A system can accurately identify a religious practice, association, protest plan, or foreign contact while violating rights because the state’s objective is illegitimate or disproportionate. Conversely, a lawful objective such as preventing violence can be undermined by inaccurate, discriminatory, or unreviewable data.
False positives. Technical false positives arise when a system incorrectly matches a face, plate, device, account, or identity; incorrectly classifies a scene; or forecasts an event that does not occur. Administrative false positives arise when accurate data are interpreted as evidence of risk without a sound basis—for example, treating ordinary religious practice or contact with a relative abroad as a terrorism indicator. IJOP illustrates both possibilities. citeturn13view1turn12view1
China’s official reporting rarely publishes confusion matrices, base rates, demographic error distributions, or long-term outcome studies. Claimed “accuracy” may be measured against officer confirmation, but officer confirmation can itself be influenced by the alert. A model trained on historical enforcement data may reproduce the police organization’s past selection choices rather than an independent measure of crime or danger.
Guilt by association. Relationship graphs are central to police big data. They can reveal genuine conspiratorial links, shared financial infrastructure, or coordinated criminal conduct. But the same tools can represent family relationships, phone contacts, co-location, common religious attendance, shared employment, or a single transaction as suspicious edges. Without transparent thresholds and contextual review, people become risk-relevant because of what others did or because authorities previously labeled an associate. citeturn13view0turn13view1turn4search14
In Xinjiang, family and foreign-contact analysis took place in an environment where ethnicity and religion were already securitized. Outside Xinjiang, similar risks arise for protest movements, labor networks, petition groups, criminalized informal economies, and residents of heavily policed neighborhoods.
Circularity and selection bias. Police data reflect where officers look, whom they stop, what conduct is criminalized, and which communities report or are reported. A model trained on arrests will often learn the pattern of arrests, not the total distribution of offending. Increased patrol in a flagged area produces more observed infractions, which can be interpreted as confirmation that the area deserved increased patrol. European Union fundamental-rights analysis has specifically warned of this feedback-loop problem, and studies of European predictive-policing systems have reported mixed or contradictory evidence of effectiveness. citeturn18search1turn18search3
The same issue applies to person-based Chinese systems. A person categorized as “key” receives more visits and checks. Those contacts create more reports. More reports increase the person’s apparent abnormality. The system can become internally consistent without becoming externally accurate.
Opaque thresholds. Public procurement notices often identify data sources and desired functions but omit alert thresholds, feature weights, model versions, training sets, override rules, and deletion policies. State secrecy and police-work confidentiality make it difficult for courts, lawyers, researchers, or affected people to reconstruct why a flag occurred. Commercial secrecy adds another layer where vendors retain proprietary models.
Opacity also complicates institutional accountability. A police bureau can attribute a flag to a vendor model, while the vendor says that police selected the rules and data. A provincial platform can say that a municipality entered the record, while the municipality says it came from a national database. Without auditable provenance, responsibility disperses across the data chain.
Inability to contest records. Chinese personal-information law recognizes rights to know, restrict, correct, and delete personal information in many circumstances, but state-organ processing for statutory duties is subject to special provisions and exceptions. In sensitive public-security contexts, individuals may not know that a record exists, which agency holds it, or whether it was a watchlist hit, model output, police observation, or third-party data feed. Notice can be withheld where it would impede performance of statutory duties, and national-security or criminal-investigation secrecy can restrict disclosure. citeturn6search0turn6search8
Formal administrative reconsideration, litigation, complaint, and procuratorial-supervision mechanisms exist, but meaningful review requires an identifiable decision and accessible evidence. A home visit, repeated checkpoint delay, informal travel restriction, warning, or invisible watchlist status may be difficult to challenge. Xinjiang’s mass political and coercive environment made independent legal contestation particularly implausible.
Chilling effects and behavioral normalization. Surveillance changes behavior even without formal sanctions. People may avoid lawful assembly, sensitive searches, religious participation, foreign communication, or contact with monitored individuals. The effect is strongest where rules are vague and consequences severe. In Xinjiang, the combination of device inspection, home visits, checkpoints, and detention made the deterrent effect direct. Elsewhere, the same dynamic can affect petitioning, protest, online political discussion, and community organizing. citeturn12view1turn12view2
Ordinary criminal investigation. Legitimate investigative uses include locating a wanted violent suspect, tracing a stolen vehicle, identifying a kidnapping victim, linking accounts used in fraud, reconstructing a crime scene, and alerting police to an imminent threat supported by objective facts. Chinese authorities cite these functions as evidence that video and big-data systems improve public safety, and local reports provide numerous case anecdotes. citeturn3search14turn3search18turn21search8
Case anecdotes cannot establish net effectiveness because authorities publish successes rather than failed matches or displaced crime. Yet it would be inaccurate to depict all infrastructure as exclusively political. The same camera, identity database, or graph tool can be used for both legitimate investigation and rights-abusive monitoring.
Stability maintenance. “Stability maintenance” is broader than crime prevention. It encompasses anticipation and management of disputes, petitions, collective incidents, online mobilization, politically sensitive persons, and events that might challenge Party-state authority or disrupt administrative order. Some activities in this category may involve genuine violence; others involve peaceful dissent or complaints.
The practical dividing line is the predicate for intervention. A system that flags a person because of objective evidence of an imminent violent act is performing a recognizably public-safety function. A system that flags the person because of peaceful petitioning, religious identity, family ties, foreign contact, or association with critics is pursuing political control even if officials describe the purpose as stability.
Political classification. Chinese systems may not always contain an explicit field called “political reliability.” Political classification can be produced through combinations of administrative categories: petitioner status, prior protest, religious affiliation, foreign relationship, online speech, membership in an organization, or previous “stability” handling. Large models may make such classification less visible by generating a narrative risk assessment from underlying labels.
From prediction to preemption. Proactive policing changes the temporal logic of intervention. Traditional investigation asks who committed an offense based on evidence of an event. Proactive systems ask who or what deserves attention because an offense, dispute, protest, or instability event might occur. The earlier the intervention, the less concrete the evidence is likely to be and the greater the importance of necessity, proportionality, independent authorization, and review.
In China’s current architecture, many alerts result first in low-level administrative action: a phone call, visit, warning, mediation session, checkpoint inspection, or enhanced patrol. Such actions may appear modest individually but become coercive when frequent, discriminatory, recorded indefinitely, or linked to employment, travel, education, housing, or detention.
Chinese law, international law, and government justifications
Domestic statutory framework. Chinese public-security surveillance operates under a combination of the People’s Police Law, Criminal Procedure Law, Counterterrorism Law, Cybersecurity Law, Data Security Law, Personal Information Protection Law, sectoral regulations, Ministry rules, and local implementing measures. These instruments provide both authorization and nominal constraints. The central legal problem is that broad substantive mandates coexist with limited transparency and review of data-driven selection.
The People’s Police Law authorizes public-security organs to maintain public order, prevent and investigate crime, and perform other statutory duties. Article 9 permits on-the-spot questioning and inspection when officers suspect a person of illegal or criminal conduct and specifies conditions for continued questioning. In principle, this requires a factual suspicion rather than unrestricted identity checks. In practice, automated alerts can become the asserted factual basis, while the affected person may never learn the underlying rule. citeturn6search6
The Criminal Procedure Law governs criminal investigations and permits technical investigative measures for specified serious crimes subject to approval and time limits. Information obtained through such measures can be used as evidence under prescribed conditions. These safeguards are more concrete where police have opened a criminal case; they fit less clearly with pre-case mass data aggregation, broad watchlist screening, or administrative stability work. citeturn6search3turn6search7
The Counterterrorism Law grants extensive authority for intelligence collection, investigation, screening, monitoring, and early warning. It permits questioning, inspection, summons, and, for terrorism suspects, collection of facial images, fingerprints, iris information, and biological samples. The law also requires confidentiality concerning personal privacy and commercial secrets. citeturn5search2turn5search10
These powers are not legally unlimited, but key concepts—terrorism, extremism, suspicious circumstances, and necessary preventive measures—have been applied broadly in Xinjiang. OHCHR concluded that the legal and policy framework was vague and overbroad and enabled discriminatory restrictions and arbitrary detention. citeturn12view0turn22search10
The Cybersecurity Law imposes security and data-handling obligations on network operators and supports state access for national-security and criminal-investigation purposes. Its privacy provisions require lawful, proper, and necessary collection by network operators, while its security architecture also facilitates government supervision and mandatory assistance. The law was revised in 2025, but the basic dual structure—data protection alongside strong state-security authority—remained. citeturn5search3turn5search7
The Data Security Law defines data processing broadly and establishes classification, risk control, state data-security coordination, and special treatment for government data. Its organizing principle includes national security and social and economic development. It does not provide a detailed public procedure for contesting a police risk label. citeturn5search1turn5search15
The Personal Information Protection Law is the most important general privacy statute. Articles 34 and 35 apply specific requirements to state organs: processing must be undertaken within statutory authority and procedures and must not exceed the scope and limits necessary to perform legal duties; state organs generally must provide notice, subject to exceptions where notice would impede those duties. citeturn6search0turn6search8
On paper, the necessity clause is significant. Bulk collection of medical, commercial, religious, communications, or relationship data should require a defensible connection to a statutory purpose. Sensitive personal information, automated decision-making, retention, and security obligations also create potential constraints. In practice, however, broad police and counterterrorism mandates, secrecy, weak public standing to challenge invisible processing, and the absence of an independent data-protection authority comparable to many European regulators substantially reduce the law’s ex ante restraining effect.
China’s courts have developed privacy and consent principles in private-sector disputes, including Supreme People’s Court guidance limiting unjustified processing. Such decisions demonstrate that privacy is not absent from Chinese law. They do not establish equivalent judicial scrutiny of classified public-security databases or political watchlists. citeturn5search20
Legality of automated flags. Chinese law does not supply a single publicly accessible statute stating when a police model may classify a person as a stability or terrorism risk, which data may be combined, how long a label may persist, or what explanation is owed. Agencies rely on general statutory duties, internal Ministry rules, technical standards, and administrative procedures. Technical standards regulate interoperability and security more readily than substantive fairness.
A legally adequate framework would need to distinguish at least four stages: data acquisition, analytical processing, generation of an alert, and coercive intervention. Lawful access to a hotel record does not automatically justify combining it indefinitely with religion, health, family, and communication data. A lawful analytical lead does not automatically justify detention. Public documents rarely make those boundaries transparent.
International privacy law. Article 12 of the Universal Declaration of Human Rights protects against arbitrary interference with privacy, family, home, and correspondence. Article 17 of the International Covenant on Civil and Political Rights provides a treaty formulation of the same protection. China signed the ICCPR but has not ratified it; as a signatory it is expected not to defeat the treaty’s object and purpose, while not being bound in the same way as a state party. China is party to the Convention against Torture and the Convention on the Elimination of Racial Discrimination, among other treaties. citeturn22search0turn22search8
OHCHR’s digital-privacy work states that public surveillance must be lawful, necessary, and proportionate and supported by effective safeguards. The fact that technology can collect or link data does not establish necessity. Mass or indiscriminate surveillance creates particular risks for privacy, expression, association, religion, and participation. citeturn22search1turn22search9
A measure is not non-arbitrary merely because domestic legislation authorizes it. International human-rights analysis examines clarity, legitimate purpose, necessity, proportionality, discrimination, independent oversight, retention, security, and remedy. Monitoring an identified suspect based on individualized evidence differs from persistent collection concerning an entire ethnic or religious population.
Non-discrimination and religious freedom. Ethnicity, religion, language, nationality, and family origin are protected characteristics under international norms and relevant treaty obligations. A system that explicitly or effectively subjects Uyghurs and other Muslim minorities to more intensive surveillance must satisfy a particularly demanding justification. OHCHR found that Xinjiang’s counterterrorism system was discriminatory and that ordinary Islamic practices and foreign connections were treated as indicators of extremism or risk. citeturn12view0turn12view1turn22search6
Even when ethnicity is not an explicit model field, proxies can reproduce the same classification: place of residence, language, name, mosque attendance, family links, travel destination, dietary practice, or communications network. Removing a protected-characteristic column does not eliminate discrimination if the operational target remains the group.
Arbitrary detention and due process. An algorithmic flag cannot itself make detention lawful. International standards require a legal basis, individualized reasons, prompt notice, ability to challenge detention before an independent tribunal, and protection against torture or ill-treatment. OHCHR found credible evidence of large-scale arbitrary detention and concluded that its discriminatory extent might constitute crimes against humanity. citeturn22search6turn22search10
Where IJOP-related flags contributed to referral to vocational centers or other detention without ordinary criminal process, the rights concern was not merely data privacy. The data system became part of a chain affecting liberty, family unity, movement, religion, and physical and psychological integrity.
Freedom of expression, association, assembly, and movement. Predicting a violent offense and forecasting a protest are not legally equivalent. Peaceful assembly, criticism, religious communication, and contact with foreign relatives are protected activities, subject only to lawful and proportionate restrictions. Stability systems that seek to prevent mobilization regardless of violence risk converting the exercise of rights into evidence of dangerousness.
Business and supply-chain responsibility. Under the UN Guiding Principles on Business and Human Rights, technology companies should conduct human-rights due diligence, avoid causing or contributing to abuse, and seek to prevent or mitigate harms directly linked to their products or services. This responsibility extends beyond formal compliance with export laws and applies to hardware, software, integration, updates, cloud services, and business relationships. citeturn22search3turn22search7turn22search11
Government justifications. Chinese authorities present these systems as responses to terrorism, violent crime, fraud, public-order threats, and demand for more efficient services. Official Xinjiang white papers describe vocational education and preventive counterterrorism as lawful measures intended to eliminate the conditions producing extremism, rehabilitate persons influenced by extremist ideology, and protect life, health, development, and social stability. Authorities state that counterterrorism is not linked to a particular ethnicity or religion and that human rights and religious freedom are protected. citeturn19search1turn19search21turn19search24
A 2024 Chinese white paper on the legal system and practice of counterterrorism likewise emphasized rule according to law, protection of human rights, safeguards for personal freedom and dignity, and balancing security with rights. citeturn19search19
Chinese officials reject allegations of mass arbitrary detention and ethnoreligious persecution, describe vocational centers as educational institutions, point to the decline in reported terrorist violence, and accuse Western governments of politicization and double standards. Xinjiang representatives have asserted that participants could communicate, take leave, and return home, and that the measures improved safety and prosperity. citeturn19search2turn19search4turn19search8
These official claims deserve inclusion for both legal and analytical reasons. Xinjiang experienced real episodes of terrorism and lethal violence, and states have a duty to protect residents. The dispute concerns whether the measures were individualized, necessary, proportionate, nondiscriminatory, and reviewable. The documented treatment of lawful religious behavior, foreign ties, communications use, and family association as risk indicators—and the scale and arbitrariness found by OHCHR—undermine the claim that the system was confined to persons reasonably suspected of violence. citeturn12view1turn22search6
Outside Xinjiang, authorities justify proactive models as a way to resolve disputes before violence, protect fraud victims, allocate patrols, improve emergency response, and reduce bureaucratic burden. Those are legitimate public goals. Nevertheless, official performance claims should be tested against false-positive rates, rights impacts, displacement, data minimization, and whether “risk disposal” means assistance, mediation, surveillance, or coercion.
Supply chains and comparison with U.S. and European systems
Foreign technology and components. China’s public-security infrastructure developed through a mixture of indigenous systems, imported enterprise technology, joint ventures, local integration, and later localization. An Associated Press investigation based on procurement records, confidential company and government documents, leaked communications, and more than 100 interviews reported that U.S. and other foreign technology was incorporated into earlier Chinese police and surveillance infrastructure. It identified IBM-related analytical technology, Intel and Nvidia processors, Oracle and Microsoft software, VMware virtualization, and Dell, HP, Cisco, and Seagate hardware in various systems. citeturn15view0
The AP investigation’s provenance is stronger than an ordinary news summary because it drew on tens of thousands of records and extensive interviews. Some of its most sensitive findings, however, depend on confidential documents that the public cannot independently reproduce. Companies disputed or qualified aspects of the reporting, said products were general-purpose, emphasized compliance programs, or stated that they had ended relevant relationships. Those responses should be treated as part of the evidentiary record. citeturn15view0
AP reported that IBM worked with the Chinese integrator Huadi on Golden Shield-era analytical capabilities and that software later marketed by a Chinese company bore similarities to IBM’s i2 link-analysis tools. It further reported an alleged connection between copied or derived link-analysis technology and systems associated with IJOP. IBM stated that it had ended relevant relationships by 2014 and was unaware of use by Xinjiang police. Because the technical lineage is contested and proprietary code has not been fully compared in public, the defensible conclusion is that Western analytical concepts and enterprise tools contributed to China’s early police-data ecosystem—not that a current foreign company directly operates IJOP. citeturn15view0
General-purpose processors, storage, databases, and networking equipment are dual-use. A server can host hospital records or a political watchlist; a graphics processor can train medical imaging or facial recognition. Supply-chain responsibility therefore depends on customer due diligence, product capability, customization, red flags, contractual controls, update and service relationships, and the vendor’s leverage after learning of abuse.
U.S. export restrictions and sanctions after 2019 reduced some direct flows to named Chinese surveillance and Xinjiang entities, while Chinese firms accelerated domestic substitution and alternative sourcing. The FCC placed specified Hikvision, Dahua, and Hytera equipment used for public-safety, government-security, critical-infrastructure, or national-security purposes on its Covered List and prohibited new equipment authorizations within the defined scope. These are U.S. regulatory measures based on national-security determinations, not a comprehensive human-rights certification regime. citeturn23search1turn23search6turn23search10
Restrictions can impede access to advanced chips or components but do not automatically disable installed systems. Existing inventory, indirect distribution, domestic chips, open-source software, Chinese cloud infrastructure, and local algorithm development can sustain deployments. By 2025–2026, official police reporting emphasized domestically deployed DeepSeek-derived models, reflecting both technological capability and a preference for data localization and controllability. citeturn4search0turn4search14
Comparison with U.S. watchlisting. The closest U.S. comparison is not city-level predictive policing alone but the terrorist-watchlist and No Fly List system: multiple agencies nominate individuals, identity data are consolidated, watchlist records are disseminated for screening, and matches can produce questioning, enhanced screening, or travel denial. A 2026 Government Accountability Office report states that inclusion generally requires reasonable suspicion based on articulable intelligence and a totality-of-circumstances assessment, followed by multi-stage review. citeturn24search7
Similarities with Chinese systems include data integration, secret criteria, identity matching, association-based intelligence, preventive logic, false-match risk, and consequences imposed before a criminal conviction. Both systems face the problem that revealing sources and methods may conflict with providing meaningful notice.
Important differences concern scope, institutional checks, and protected conduct. The U.S. watchlist is formally tied to terrorism criteria and a reasonable-suspicion standard, whereas documented IJOP criteria included a much broader range of ordinary religious, communications, travel, and family behavior. The United States has judicial review, constitutional due-process litigation, congressional oversight, inspectors general, GAO review, media investigation, and an administrative redress process, although each has been criticized as incomplete. citeturn24search1turn24search4
In FBI v. Fikre, the U.S. Supreme Court held unanimously in 2024 that the government did not moot a former listee’s challenge merely by removing him from the No Fly List and promising not to relist him on currently available information. The Court emphasized that the government had not disclosed what conduct caused the original listing or ruled out repetition. The case did not decide the ultimate merits of every watchlisting procedure, but it demonstrates the availability of adversarial judicial review that has no clear counterpart for an IJOP flag. citeturn24search0turn24search3
The comparison should not romanticize the U.S. system. Watchlisted people may receive limited explanations, encounter classified evidence, experience religious or national-origin bias, and face lengthy litigation. The point is institutional: U.S. listing can be challenged publicly and has generated binding judicial doctrine, whereas Chinese public evidence reveals no comparable route through which an ordinary person can obtain and contest the basis for a public-security big-data label.
Comparison with European predictive policing. European police have used place-based forecasting, person-based risk tools, crime mapping, automated link analysis, and algorithmic assessments. Durham Constabulary’s HART system, for example, classified suspects into risk categories to inform decisions about prosecution or diversion into a rehabilitation program. Dutch place-based systems have sought to identify locations at elevated risk of crime, although academic assessments report mixed and sometimes contradictory results. citeturn18search1turn18search22
Europe shares many technical risks found in China: historical enforcement bias, feedback loops, opaque vendor systems, data-quality problems, demographic discrimination, overreliance by officers, and difficulty measuring crimes that did not occur. The European Union Agency for Fundamental Rights has warned that systems must be tested before and during use and that biased data can reproduce discriminatory policing. citeturn18search3
The legal environment differs markedly. In 2023, Germany’s Federal Constitutional Court held that laws authorizing automated police data analysis in Hesse and Hamburg lacked sufficiently specific thresholds and safeguards and were unconstitutional in their existing form. The decision demonstrates judicial insistence that the intensity of automated analysis be matched by a concrete danger or sufficiently weighty suspicion and clear statutory limits. citeturn18search0turn18search28
The EU Artificial Intelligence Act prohibits AI systems used to assess or predict an individual’s risk of committing a criminal offense solely on profiling or personality traits, while allowing systems that support human assessment based on objective and verifiable facts directly linked to criminal activity. It also prohibits specified social scoring, untargeted scraping of internet or CCTV facial images to build facial-recognition databases, sensitive biometric categorization, and most real-time remote biometric identification by law enforcement in public spaces subject to defined exceptions. The prohibited-practice rules took effect in February 2025, and the broader enforcement framework reached a major implementation stage on August 2, 2026. citeturn20search0turn20search1turn20search4turn20search7turn20search14
The AI Act does not ban every form of predictive policing. Location-based forecasts, evidence-supported investigative analytics, and some law-enforcement AI remain permissible or classified as high risk, subject to requirements concerning data governance, documentation, accuracy, human oversight, registration, and fundamental-rights assessment. National-security uses may also fall outside parts of the regulation. European safeguards are therefore significant but incomplete.
Key comparative differences. China, the United States, and Europe all use digital identity, integrated databases, watchlists, cameras, link analysis, and preventive intervention. None is immune to secrecy, bias, false positives, or mission creep. The strongest distinctions are:
| Dimension | China | United States | European Union and member states |
|---|---|---|---|
| Institutional architecture | National policy and standards with provincial and municipal implementation; Party political-legal leadership and public-security hierarchy. | Federal, state, and local systems with separate legal authorities; intelligence and law-enforcement information sharing. | National police systems constrained by EU law, national constitutions, data-protection law, and courts. |
| Political-security scope | Explicitly includes Party-state political security, stability maintenance, separatism, religious governance, petitions, and mass incidents. citeturn0search9turn13view0 | Counterterrorism and public safety; political surveillance is legally constrained but has historical and continuing controversy. | Public safety and national security; political surveillance is constrained by rights law but exemptions and controversies remain. |
| Public explanation | Procurement and propaganda reveal capabilities, but operational rules and adverse decisions are rarely disclosed. | Criteria and records are partly classified, but litigation, GAO review, inspectors general, and congressional oversight produce some disclosure. citeturn24search7 | Data-protection impact assessments, court challenges, legislative debate, and regulatory obligations provide more formal transparency, though police exemptions remain. |
| Contestability | Weak where a person does not know of a label or the action is informal; no demonstrated independent review of IJOP-type classification. | Administrative redress and judicial review exist but may be slow and secrecy-limited. citeturn24search0 | Courts and data-protection authorities can review systems; automated-analysis laws have been invalidated. citeturn18search0 |
| Treatment of person-based prediction | Broad risk and “key person” systems are promoted; no comprehensive public prohibition based solely on profiling. | Constitutional and statutory standards vary; watchlisting requires stated thresholds, but local predictive tools are fragmented. | AI Act prohibits individual criminal-risk prediction based solely on profiling or traits and imposes high-risk controls. citeturn20search1turn20search7 |
| Xinjiang-equivalent ethnoreligious campaign | Xinjiang combined integrated surveillance with discriminatory mass detention and religious control. citeturn22search6 | Serious discriminatory watchlisting and surveillance concerns exist, but no directly equivalent contemporary mass regional internment system. | Discriminatory policing and migration surveillance remain concerns, but courts and EU rules impose materially stronger formal limits. |
The relevant lesson is not that one jurisdiction uses technology while another does not. It is that the rights impact depends on the purpose of classification, quality of evidence, scope of collection, institutional independence, available explanation, and consequences of a flag.
Confidence-rated findings and what remains unknowable
The following ratings distinguish what is securely established from what is plausible or uncertain.
| Finding | Confidence | Basis and qualification |
|---|---|---|
| China’s public-security surveillance ecosystem is layered and not one unified national platform. | High | Separate official budgets, policies, standards, and local descriptions distinguish Golden Shield networks, police clouds, Skynet, Sharp Eyes, social video, and specialized platforms, even where they are connected. citeturn3search0turn3search2turn3search8 |
| National MPS policy and standards significantly shape provincial and municipal systems. | High | Ministry directives, technical standards, data catalogues, video-interface standards, and national policing models are publicly documented. citeturn0search0turn0search9turn21search2 |
| Provincial and municipal police clouds aggregate internal police and external government, commercial, internet, and sensor data. | High for intended architecture; moderate for completeness in any locality | Procurement research and Chinese architecture documents converge, but no public source shows that every desired feed is complete or continuously available. citeturn13view0turn2search17 |
| Police systems routinely retrieve records, identify people and vehicles, and link entities. | High | Supported by standards, procurement, official case descriptions, and vendor architecture. citeturn3search1turn21search2turn14view1 |
| Automated alerts and tasking are operational in multiple jurisdictions. | High | IJOP reverse engineering, internal bulletins, municipal platforms, and procurement specifications document alerts and closed-loop work orders. citeturn13view1turn16search6turn0search12turn14view1 |
| Most “prediction” is a mixture of watchlist matching, fixed rules, anomaly detection, statistical modeling, and human judgment rather than autonomous AI forecasting. | High as an ecosystem-level characterization | Technical descriptions reveal heterogeneous methods; public evidence rarely supports the stronger marketing implication of accurate individual future-behavior prediction. |
| IJOP collected identity-linked data, flagged prescribed behaviors or relationships, and directed officers to investigate. | High | Reverse-engineered application, procurement records, internal bulletins, and OHCHR assessment converge. citeturn13view1turn16search6turn12view1 |
| IJOP-related flags contributed in some cases to questioning, restrictions, political education, or detention. | High | Supported by HRW application analysis, Aksu detention records, interviews, and OHCHR findings. citeturn13view1turn16search1turn12view1 |
| IJOP assigned a single numerical risk score to every Xinjiang resident. | Low / not established | Evidence supports categories, labels, rules, and alerts; no complete public documentation shows a universal individual score. |
| Xinjiang’s system was ethnically and religiously discriminatory. | High | Multiple independent documentary sources and OHCHR analysis identify disproportionate and targeted surveillance of Uyghurs and other Muslim minorities. citeturn12view1turn22search6 |
| Xinjiang’s IJOP architecture was replicated unchanged throughout China. | Low | Components and operational ideas have analogues elsewhere, but no evidence shows nationwide replication of the same application, data rules, or detention pipeline. |
| Camera networks are increasingly integrated with public-security big-data platforms. | High | National policy, technical standards, and local reporting expressly call for video–data fusion. citeturn3search1turn21search27 |
| Every Chinese public camera performs live facial recognition. | Low / false as a generalization | Camera type, connectivity, processing capacity, licensing, image quality, and local configuration differ. |
| Large language models were being used by multiple police agencies by 2025–2026. | High for pilots and reported deployments | Numerous official reports identify locally deployed large models and AI agents. citeturn4search1turn4search3turn4search13turn4search14 |
| Generative AI independently decides whom Chinese police detain. | Low / not established | Public sources describe assistants, analysis, recommendations, and tasking, not autonomous legally final detention decisions. |
| Large-model outputs materially influence some police workflows. | Moderate to high | Official reports describe integration into call handling, case analysis, command, and investigative recommendations, but independent observation is limited. |
| Proactive-warning systems produce significant false positives. | Moderate to high as a structural inference; low for a precise rate | Rare-event detection, broad indicators, subjective labels, and the one published agency accuracy claim make error likely, but no reliable aggregate rate is public. citeturn0search2turn13view1 |
| Foreign technology materially contributed to earlier Chinese police-data infrastructure. | High in general; moderate for contested product lineage into IJOP | Procurement, company records, and AP investigation support broad contribution; specific code-lineage allegations are not fully independently auditable. citeturn15view0 |
| Post-2019 controls ended Chinese access to all foreign components. | Low / contradicted by supply-chain realities | Installed equipment, indirect sales, alternative sourcing, domestic substitution, and general-purpose components continue to complicate controls. |
| Chinese domestic law contains privacy and necessity constraints applicable to state organs. | High | PIPL expressly requires statutory authority, procedures, and necessity limits for state organs. citeturn6search0turn6search8 |
| Those constraints provide an effective, independent remedy against secret police risk labels. | Low to moderate | Formal legal rights exist, but secrecy, broad security authority, lack of notice, and limited independent review undermine practical contestability. |
| Xinjiang’s broader detention and surveillance campaign may constitute crimes against humanity. | High as an accurately stated OHCHR legal assessment; not a judicial conviction | OHCHR reached this conclusion after its assessment; no international court has issued a final judgment concerning the campaign. citeturn22search6turn22search10 |
Several core questions remain unknowable from current public evidence.
The current status of IJOP. There is no authoritative public technical documentation showing whether the original platform remains operational under the same name, has been upgraded, split into services, absorbed into a broader regional big-data platform, or partly retired. Public silence is not evidence of discontinuation.
The server-side decision logic. The reverse-engineered mobile application exposed fields and workflows, but not a complete inventory of server rules, model weights, confidence thresholds, watchlists, feature engineering, retraining schedules, or version history.
The national graph of data access. Public standards and procurements establish interoperability and sharing, but they do not show which officer can access which fields across provinces, whether queries are real-time or replicated, how approvals work, or where sensitive data physically reside.
The completeness and quality of external feeds. Procurement documents may list banking, health, utilities, delivery, telecommunications, or internet data without showing whether access was obtained, how often data refresh, or how identity mismatches are resolved.
The actual prevalence of gait, voice, iris, and emotion recognition. Chinese vendors and research institutes market these capabilities, and some legal or technical documents permit particular biometric collection. Public evidence does not support treating them as universally deployed or continuously operational across Chinese public-security cameras.
False-positive and false-negative rates. Almost no systems publish externally auditable metrics based on representative data. Agency success figures omit base rates, definitions, abandoned alerts, demographic differences, and downstream harms.
Human override. Official descriptions frequently state that police verify model outputs. It remains unknown how often officers reject alerts, whether disagreement is recorded, whether performance incentives encourage compliance, and whether subjects can provide exculpatory information.
Retention and correction. Public evidence does not reveal how long many risk labels, association edges, dismissed alerts, mistaken face matches, or field observations remain searchable; whether corrections propagate across replicated databases; or whether deletion requests are feasible in classified police systems.
The role of generative-AI hallucination. Police large-model deployments publicize efficiency but generally do not disclose hallucination testing, retrieval-grounding design, prompt logs, adversarial evaluation, model-update procedures, or incidents in which fabricated or misattributed information affected an investigation.
The boundary between pilot and production. Award lists and publicity articles can make demonstrations appear institutionally mature. Without acceptance reports, usage logs, budget renewals, or independent field observation, it is often impossible to determine whether a model serves an entire city, one unit, a test environment, or a limited number of cases.
The number of affected people. Camera totals, alert counts, model-task counts, and detention estimates are frequently repeated without consistent definitions. No defensible public method can calculate how many people nationwide are currently subject to algorithmic police monitoring, how many alerts lead to visits, or how many coercive actions depend materially on automated processing.
The allocation of responsibility among vendors and police. Contracts may specify technical deliverables but omit who designed substantive risk rules, selected training data, approved protected-characteristic proxies, or decided retention and intervention thresholds. Responsibility is often distributed among the customer, systems integrator, subcontractors, platform vendors, and local police analysts.
The most defensible overall judgment is therefore narrower than either official technological triumphalism or descriptions of an omniscient machine state. China has constructed a powerful, increasingly interoperable public-security data ecosystem capable of retrieving records, identifying people and vehicles, mapping relationships, generating automated warnings, and directing police work at scale. The ecosystem is fragmented, locally variable, and dependent on human institutions, but fragmentation does not necessarily protect rights: standardized interfaces and hierarchical policy can connect separate systems while obscuring accountability.
In Xinjiang, these capabilities were integrated into an exceptionally coercive campaign in which ethnicity, religion, foreign contact, ordinary behavior, and association became bases for investigation and, in documented cases, restrictions or detention. Elsewhere, similar technical components serve a mixture of legitimate crime control, administrative management, protective intervention, stability maintenance, and political security. The 2024–2026 adoption of large models and advanced video analytics has made these systems easier to query and more proactive, but public evidence does not demonstrate reliable machine prediction of future criminality.
The decisive governance question is not whether Chinese police use “AI.” It is whether a person can be selected for state intervention without individualized evidence; whether the underlying data and inference are accurate, necessary, and nondiscriminatory; whether an independent institution can inspect the process; and whether the person can learn of, contest, and correct the record before an opaque flag becomes a continuing source of surveillance or coercion.