Essay

What we

will not build.

Refusals are only meaningful when they are specific and costly. A general commitment to responsibility commits you to nothing. So: the four asks we get, stated as their advocates would state them.

One. Licence-plate recognition

The case for. A network of this size reading plates would recover stolen vehicles, resolve hit-and-runs where the victim has no other evidence, and support toll and enforcement systems that already exist by other means. Real harms, plausibly reduced.

Why not. A plate is a durable identifier attached to a person. A network that reads plates continuously across a country does not produce a list of stolen cars; it produces a movement history for everyone, and that history is then available to whoever can compel it or buy it. The record of what happens when such systems exist is not ambiguous.

The harms it would reduce are real. The infrastructure it would create is worse, and there is no configuration in which we hold that infrastructure and it is only ever used the way the brochure describes.

Two. Face recognition

The case for. Driver identification for fleets with pooled vehicles — knowing who was actually driving matters for coaching, for claims and for liability. Currently solved with fobs and logins that drivers share.

Why not. Once a face can be matched to a name, everything else follows: presence, absence, association, pattern of life. The fleet problem is real and there are ways to solve it that do not involve building a face-matching capability into a network that sees millions of people who never agreed to anything. We detect faces solely in order to destroy them.

Three. Person-level search

The case for. “Show me everything involving this vehicle” is the single most requested feature from investigators, insurers pursuing fraud rings, and occasionally from fleets pursuing a specific driver.

Why not. This is the capability all the others reduce to, and it is the one we have designed the platform to be unable to do. The record is indexed by condition, geography, object, behaviour and outcome. There is no person axis, so there is no query. This is also why we can tell a court, honestly, that we cannot produce a movement history under any order — a promise not to search is weaker than an architecture with nothing to search.

Four. Selling personal data

The case for. The market exists and it is large. Location and behavioural data command real prices and much of the industry participates.

Why not. Our commercial model does not need it. We sell measured knowledge of how the physical world behaves, which is an aggregate product. Adding personal data would raise revenue and destroy the thing that makes the aggregate product trustworthy, which is that nobody has to worry about what else we are doing with it.

Every one of these refusals costs us something. That is what makes them worth publishing.

The general rule underneath

Each refusal follows the same test, and it is the test we would apply to a capability we have not thought of yet.

  • Does it require identifying an individual? If yes, no.
  • Would it be dangerous in the hands of a future owner of this company with different values? If yes, no — because policy survives a change of ownership far less reliably than architecture does.
  • Would we be comfortable explaining it to the person it was used on? If not, no.

The second test is the one that does most of the work. We will not always run this company. What we build outlasts what we intend, and it is the only part of this a future executive cannot quietly revise.

Where governance has actually failed

This is not a hypothesis. Reporting through 2026 identified at least fifty police officers accused or charged with misusing licence-plate camera systems, forty-six of the cases involving one vendor’s equipment, across twelve states. Twenty-six of them involved surveilling wives, girlfriends, former partners, or women the officer wanted to meet. One chief of police queried an ex-partner’s plate somewhere between five and six hundred times in a year.

Access controls existed. Audit logs existed. A search-reason field existed. None of it prevented the stalking; it merely made the stalking countable afterwards. In one documented case the logged reason for a nationwide plate search read “had an abortion, search for female,” while the vendor and the sheriff’s office described it publicly as a welfare check for five months. The audit trail worked perfectly and was useless, because the party being audited wrote the record.

A state audit of four agencies found none had a compliant policy despite a statute requiring one, and none had conducted the required audits of user searches. One city police department ran nearly four million plate searches in a single year — a volume no review process can meaningfully examine. Set that against warranted interception in the same country: 1,735 wiretaps authorised nationally in a year, versus 3.9 million unwarranted plate searches in one city.

And the pattern predates the technology. An investigation a decade earlier found officers fired, suspended or resigned more than 325 times over three years for misusing confidential databases, motivated by romantic quarrels and voyeuristic curiosity. It is a property of holding a searchable database of people, not of any vendor.

What refusal looks like when it is tested

A messaging service received a federal grand jury subpoena demanding names, dates of birth, addresses, email addresses, financial information, employment history, correspondence records and activity logs. It produced two Unix timestamps — account creation, and last connection. No policy was invoked. No discretion was exercised. There was nothing there.

That is the whole argument in one exchange. A lawful, valid, compelled demand met an architecture with nothing to give.

A second example, from a company that publicly abandoned a capability it had already built and announced. Its stated reasoning was ours: scanning stored data would “create new threat vectors for data thieves to find and exploit,” and would “inject the potential for a slippery slope of unintended consequences — scanning for one type of content opens the door for bulk surveillance.” It has held for four years, including through litigation for having abandoned it.

The precedent that goes against us, and why we are raising it ourselves

The purest capability refusal in modern history is the 1972 convention banning biological weapons. It prohibited development, production and stockpiling. It was signed by a state that simultaneously ran a programme employing tens of thousands of people across dozens of facilities producing agents by the ton, undetected for two decades, and exposed only by a defection.

Refusal failed there completely. And the strongest counter-case runs the other way too: the 1987 ozone treaty governed production through quotas, trade controls and a compliance mechanism, achieved a ninety-nine per cent phase-out, and is the only UN treaty with universal ratification. Governance worked.

So the honest formulation is not “refusal beats governance.” It is narrower. Refusal without verification is a promise. The 1995 protocol banning blinding laser weapons has held for thirty years because the capability was specific, identifiable, and refused before anyone had sunk cost into it. The biological weapons convention failed because the capability was latent in ordinary biology and the treaty had no way to look. The operative variable is whether refusal is verifiable at the point of construction — which is exactly why we publish what the platform cannot do, and invite people to test it.

One more, because it complicates us usefully. Eight privacy regulators fined a facial recognition company roughly a hundred million euros between them. It has paid none of it, deleted nothing, and continues operating. Meanwhile a state biometric-privacy statute with a private right of action produced a permanent, nationwide, binding restriction on the same company. A use-regulating law outperformed eight capability-focused regulators — because it attached liability to possession rather than misuse, and created thousands of enforcers instead of one.

What would change our mind

A governance regime that demonstrably held a dangerous capability in check over a long period, in a commercial setting, without the capability being used for something nobody sanctioned. The ozone treaty is the closest thing, and it had a substitute product and an industry that profited from the transition. Surveillance has no substitute good. If someone shows us the counterexample that does, the argument weakens considerably.

What we are least sure about

Whether our own refusals are verifiable enough to count. We say there is no plate-recognition capability in the platform. A reader has to take that on trust today. Publishing a capability disclosure and inviting an independent party to test it is the beginning of an answer, not the answer — and until someone external has actually run that test, this essay is describing a standard we have set rather than one we have met.