Executive Summary

  • BLUF: The strategic risk lies not in individual cameras, but in connecting sensors, facial recognition, police databases, communications networks and urban command platforms.
  • Serbia is the Western Balkan state with the clearest documented exposure; elsewhere, primary evidence establishes regulatory and cybersecurity vulnerabilities more conclusively than Chinese operational control.
  • Hardware installation, technical capability, operational activation and systematic use are distinct evidentiary thresholds.
  • By 2031, the most probable outcome is hybrid digital sovereignty: legacy Chinese-origin equipment combined with tighter European controls and persistent maintenance dependencies.
  • The most credible coercive mechanism is vendor lock-in, not an unproven continuous transfer of Balkan biometric data to China.
  • The EU AI Act will turn biometric surveillance into an accession-compliance issue.
  • The highest-risk configuration combines opaque procurement, interoperable identity databases, weak regulators, undocumented software functions and political instability.
  • Europe requires a regional audit of the complete surveillance stack, not merely an inventory of camera manufacturers.

Europe’s next sovereignty test may not begin at a border, port or energy terminal. It may begin inside a police control room. Across the Western Balkans, Chinese-origin cameras, communications equipment and urban-management platforms are entering institutional environments where data-protection enforcement, cybersecurity capacity and procurement transparency remain uneven. Serbia is the most advanced and documented case: Huawei publicly described a comprehensive Safe City project for Belgrade with potential national expansion, while European institutions continue to question the legal basis and proportionality of biometric surveillance. The decisive issue is no longer who manufactured the camera. It is who controls the software, cryptographic keys, identity databases, maintenance channels and ability to search the past. A surveillance system becomes geopolitical infrastructure when the state cannot independently audit it, govern it or replace its supplier.

The Serbian Laboratory

A Huawei corporate publication stated in January 2019 that Serbia’s Ministry of Interior wanted to develop a “leading Safe City” covering Belgrade and, eventually, the entire country, and that Huawei had proposed a comprehensive solution. The formulation matters: a comprehensive platform is not a collection of isolated cameras. It can encompass optical sensors, transmission networks, storage, command software, analytics, technical support and integration with police systems. Huawei Enterprise 01/2019 – Huawei – January 2019.

What became operational remains less transparent than what was proposed. In its report of 8 November 2023, the European Commission recorded that, after negative opinions from Serbia’s Commissioner for Information of Public Importance and Personal Data Protection concerning the Ministry’s street-surveillance impact assessment, the Ministry said it had suspended biometric-data processing until a legal basis was established. The Commission added that the necessity and proportionality of public-space video surveillance and facial-recognition processing still required assessment. Serbia 2023 Report – European Commission – November 2023.

The uncertainty did not disappear. On 30 October 2024, the Commission stated that a legal basis had still not been developed and that it had to be verified whether Serbia had processed personal data through facial-recognition software. Serbia Report 2024 – European Commission – October 2024. The 4 November 2025 assessment found Serbia’s personal-data framework only mostly aligned with the GDPR and Law Enforcement Directive, difficult to implement and insufficient in areas including penalties. It also noted that the broader harmonisation of sectoral legislation remained significantly delayed. Serbia Report 2025 – European Commission – November 2025.

These findings do not prove that China receives Serbian biometric data. They establish something institutionally serious in its own right: the capabilities, legal authority and actual use of a strategic public-security system have not been sufficiently transparent to permit an uncontested sovereignty assessment.

Beyond the Camera

The strategic asset is the stack. At street level, networked cameras capture video, faces, licence plates and movement. Embedded firmware determines how the device authenticates, stores information and communicates. Municipal fibre, police networks or mobile connections transport streams to a video-management system. Analytics servers can detect faces, extract biometric templates, recognise plates, follow persons between cameras and index archived footage. The political transformation occurs when this platform connects to reference databases containing identity photographs, police records, vehicle ownership or border movements.

This distinction separates observation from identification. A camera records an anonymous person. A biometric engine converts the face into a numerical template. A reference gallery assigns a probable identity. Cross-camera tracking reconstructs movement. Database fusion adds vehicles, associations and earlier encounters. The final command interface turns these correlations into police action.

The same architecture can support legitimate investigations into violent crime or missing persons. It can also reconstruct participation in a peaceful demonstration long after the event. Deleting raw video may provide little protection if templates, plate records, alerts or movement metadata survive in separate databases. Sovereignty therefore depends on data lineage: the state must know what was collected, which derived objects were created, where they were replicated, how long they remain searchable and which accounts accessed them.

The Protest Threshold

Facial recognition changes the balance between public order and political freedom because it can remove practical anonymity from assembly. The European Court of Human Rights addressed that boundary in Glukhin v. Russia, concerning the identification and arrest of a peaceful demonstrator through facial recognition. The Court characterised the measure as highly intrusive and required a particularly strong justification for its necessity in a democratic society. Case of Glukhin v. Russia – European Court of Human Rights – July 2023.

The Serbian political environment makes this question immediate. Mass protests began after the collapse of the Novi Sad railway-station canopy on 1 November 2024, which killed 16 people, and developed into a wider mobilisation demanding accountability, transparency and institutional reform. In 2025, UN experts reported allegations that peaceful student demonstrators faced intimidation, attacks and surveillance. These were allegations requiring investigation, not judicial findings concerning any specific Safe City platform. Serbia Must Halt Crackdown on Student Movement – Office of the UN High Commissioner for Human Rights – August 2025.

In 2026, the Parliamentary Assembly of the Council of Europe expressed concern over revelations involving the surveillance of Serbian journalists and activists and called for effective investigations and accountability. Progress of the Assembly’s Monitoring Procedure, Resolution 2635 – Parliamentary Assembly of the Council of Europe – June 2026.

No admissible primary evidence establishes that Huawei’s platform generated those alleged surveillance activities. That attribution must not be invented. The strategic connection is nevertheless unavoidable: an unsettled political environment is interacting with a technically powerful surveillance architecture whose precise functions and operational record remain incompletely verified.

The Hidden Control Layer

The most consequential access may not belong to the officer watching a control-room screen. It may reside in firmware-signing systems, diagnostic accounts, licence servers, virtual private networks, software-update channels or databases administered by an integrator. Surveillance platforms require continuous maintenance: vulnerability patches, certificate renewal, storage replacement, database optimisation, algorithm updates and emergency recovery. Each intervention may require privileges exceeding those of ordinary police operators.

A sovereign system should allow the national authority to approve every remote session, identify every technician, record every command, prevent unauthorised export and revoke access immediately. It should possess its own encryption keys, recovery material, configuration backups and ability to continue operating without the original supplier. If only the vendor can restore the platform, update essential components or convert proprietary archives, ownership becomes nominal.

Huawei’s audited 2025 reporting states that the group assessed cybersecurity and privacy risks across more than 4,000 suppliers and held more than 890 security and privacy certifications. Huawei 2025 Annual Report – Huawei – March 2026. These figures document substantial corporate security governance; they cannot certify the configuration of an individual Balkan police system. Corporate assurance and deployment-level verification are different evidentiary layers.

The appropriate test is vendor-neutral: can an independent authority inventory every component, identify every privileged account, inspect update paths, reproduce access logs and operate the system after supplier disconnection? If the answer is no, the state has a sovereignty deficit regardless of the manufacturer’s nationality.

Europe Changes the Rules

The regulatory environment has now shifted decisively. Regulation EU 2024/1689, published in the Official Journal on 12 July 2024, defines both real-time and post-event remote biometric identification. It treats real-time law-enforcement identification in publicly accessible spaces as particularly intrusive and confines it to narrow circumstances with specific safeguards and authorisation requirements. Artificial Intelligence Act – European Parliament and Council – July 2024.

Most of the AI Act became applicable on 2 August 2026, although parts had already applied from February and August 2025. On 24 July 2026, the EU also established specific classification codes for biometric AI systems, including remote biometric identification. This brings such systems more clearly into Europe’s regulatory and market-surveillance machinery. Commission Implementing Regulation on AI Classification Codes – European Commission – July 2026.

The convergence is not limited to artificial intelligence. On 13 February 2026, the NIS Cooperation Group—bringing together EU Member States, the European Commission and ENISA—adopted an ICT Supply Chain Security Toolbox. It recommends an all-hazards assessment of critical suppliers, multi-vendor strategies and measures to overcome dependence on high-risk providers. Toolbox to Improve ICT Supply Chain Security – European Commission – February 2026.

For EU candidates, surveillance systems are consequently becoming an accession issue. Formal amendments to national law will not be enough. Brussels will increasingly need proof of deployed functions, database connections, logging, human oversight, support arrangements and supplier substitutability.

The Balkan Vulnerability

Serbia is the clearest case, but the regional vulnerability is broader. The Commission’s 2025 reports found that Montenegro’s personal-data law remained unaligned with the EU acquis; North Macedonia continued to show low awareness of data protection and insufficient IT protection of personal information in state bodies; and Albania’s Total Information Management System retained security and data-protection vulnerabilities requiring urgent action.

These findings do not prove the presence of Chinese biometric platforms in those countries. They identify the institutional conditions under which any sophisticated foreign surveillance system could expand without adequate lifecycle control. Weak regulation increases the danger of function creep; fragmented cybersecurity obscures remote access; limited technical staffing shifts knowledge toward vendors and contractors; opaque procurement conceals the cost of exit.

The Western Balkans should therefore not be described as a single Chinese surveillance zone. It is a differentiated market of exposure. Serbia combines documented Safe City ambition with unresolved biometric governance. Other countries present varying levels of regulatory susceptibility, technical dependence and evidence gaps. Precision matters: exaggeration would allow governments and suppliers to dismiss valid concerns as geopolitical propaganda.

The Leverage Mechanism

Chinese geopolitical leverage does not require permanent remote access to Balkan police databases. It can arise from dependence itself. A supplier controlling firmware, proprietary interfaces, analytics licences, maintenance expertise or archive formats can become expensive and disruptive to replace. Governments anticipating those costs may delay exclusions, seek exemptions or soften regulatory choices even without an explicit threat from Beijing.

That condition is potential leverage, not proof of coercion. Actual geopolitical pressure would require a demonstrable connection between a political demand and a threatened or executed consequence involving support, finance, access, disclosure or system continuity. No qualifying primary evidence presently establishes such a case in the Western Balkans.

The more probable risk is structural lock-in. A low initial procurement price can generate long-term dependence through licence renewals, specialist support, incompatible formats and bundled upgrades. Replacing cameras may then require replacing servers, databases, management software and operator training simultaneously. The security system becomes a balance-sheet liability and a diplomatic constraint.

Europe’s answer should not be an indiscriminate removal campaign based solely on origin. It should impose measurable sovereignty: national control of cryptographic keys, complete software and hardware inventories, immutable regulator-owned logs, open interfaces, named maintenance accounts, independent biometric testing and contractually enforceable data portability.

The Five-Year Divide

Between 2026 and 2031, three trajectories are possible. The first is sovereign convergence: governments separate biometric galleries from camera networks, restrict cross-database queries, control all privileged access and demonstrate that systems can operate without their original supplier. The second—and most probable—is regulated hybridisation: legacy Chinese-origin equipment remains, live identification is restricted, retrospective capabilities survive and European controls improve unevenly. The third is political consolidation: biometric, vehicle and identity data become integrated during a period of domestic instability, creating an infrastructure capable of mapping dissent.

The decisive warning will not be another camera installation. It will be the convergence of four conditions: extensive biometric capability, integration with authoritative identity databases, weak independent auditing and elevated political stress. At that point, surveillance ceases to be merely a policing instrument and becomes a system of political power.

The cost of inaction is not simply lost privacy. It is the creation of a sovereign function that the state cannot fully explain, independently operate or economically replace. In the Western Balkans, Europe’s enlargement policy will be credible only if it can inspect the code behind the cameras as rigorously as it examines the laws written in parliament.


Navigational Index

  1. Architecture of the Transfer — Hardware, software, data, maintenance, system integration and supplier dependence.
  2. Sovereignty and Political Pressure — Biometrics, protest monitoring, policing, intelligence access and geopolitical leverage.
  3. Five-Year Outlook — Competing hypotheses, Bayesian indicators, Monte Carlo scenarios and early-warning thresholds.

Master Abstract

The expression “silent transfer” describes a strategically credible process, but it must be applied with strict evidentiary discipline. The verified primary sources do not establish that every Western Balkan government operates a Chinese facial-recognition system, that all installed Chinese cameras have biometric functions enabled, or that Beijing receives Balkan biometric data. They do establish a regional risk environment in which surveillance infrastructure, incomplete data-protection regimes, uneven regulatory capacity and increasingly integrated public-security systems can converge without sufficient public accountability. Serbia is the central case. The European Commission finds that its personal-data legislation remains only mostly aligned with the GDPR and Law Enforcement Directive, contains inadequate penalty provisions, is difficult to implement and has not been harmonised with numerous sectoral laws. It further records earlier negative opinions by the Serbian Commissioner for Information of Public Importance and Personal Data Protection regarding Ministry of Interior initiatives, while noting that Serbia adopted its new artificial-intelligence strategy in January 2025 without the legally required analysis of the preceding strategy. Serbia Report 2025 – European Commission – November 2025verified official document. These findings do not prove foreign access to Serbian surveillance data. They demonstrate an accountability gap between technological capability, governing legislation and independent verification. The appropriate unit of analysis is therefore the complete surveillance stack: optical sensors, embedded firmware, communications networks, command centres, storage systems, biometric engines, reference databases, operator interfaces, administrative privileges, software updates and maintenance contracts. Each layer creates a different dependency. Cameras can be replaced, but proprietary formats, application programming interfaces, trained models, database schemas, operator expertise and long-term service agreements generate cumulative exit costs. Digital sovereignty consequently requires more than storing data inside national territory. It requires demonstrable control over encryption keys, privileged accounts, update channels, data portability, audit logs, subcontractors, source-code inspection rights and the ability to operate and maintain the system without its original supplier.

The broader Western Balkan picture should be described as a corridor of differentiated vulnerability rather than as a uniform Chinese surveillance bloc. In Montenegro, the European Commission reports that personal-data legislation remains unaligned with the EU acquis and that essential legal and institutional shortcomings persist. Montenegro Report 2025 – European Commission – November 2025verified official document. In North Macedonia, the Commission identifies low awareness of data-protection obligations and insufficient information-technology safeguards for personal information across state administrative bodies. North Macedonia Report 2025 – European Commission – November 2025verified official document. In Albania, the Total Information Management System continues to suffer from security and data-protection vulnerabilities requiring urgent remediation. Albania Report 2025 – European Commission – November 2025verified official document. Bosnia and Herzegovina represents a different exposure pathway: institutional fragmentation. The Commission documented the absence of a comprehensive countrywide cybersecurity strategy, a national single point of contact and a coordinated network of computer-security incident-response teams, while explicitly urging implementation of the EU 5G Cybersecurity Toolbox through supplier-risk assessment and restrictions or exclusions concerning high-risk vendors. Bosnia and Herzegovina Report 2024 – European Commission – October 2024verified official document. These official findings do not prove that Chinese companies control those states’ security systems. They reveal conditions under which sophisticated platforms could be acquired, expanded or updated without consistent lifecycle controls. The European Commission has separately concluded, in the telecommunications context, that Huawei and ZTE represent materially higher risks than other 5G suppliers. Implementation of the 5G Cybersecurity Toolbox – European Commission – June 2023verified official communication. Automatically transferring that determination from 5G infrastructure to every urban-surveillance product would be analytically invalid. The underlying security principle is nevertheless transferable: supplier ownership, governing jurisdiction, update mechanisms, hidden dependencies, coercibility and the possibility of interference must be evaluated alongside price and technical performance.

The most consequential vulnerability is architectural convergence. A conventional closed-circuit television system records images for retrospective inspection; an integrated Safe City platform can transform those images into searchable identity events by combining facial templates, vehicle-registration data, mobile-device metadata, location history, police records and algorithmic alerts. Political power expands not only when facial recognition is continuously active, but when the state acquires the latent ability to activate it during protests, electoral crises, border emergencies or episodes of civil disorder. The critical distinction is between collection, identification, inference and intervention. Collection captures video; identification associates a person with a reference template; inference assigns behavioural meaning; intervention produces detention, questioning, movement restrictions or inclusion in an investigative file. A government may publicly describe the system as traffic management while retaining modules capable of identity resolution. Conversely, the mere presence of technically compatible cameras does not prove that those modules have been licensed, connected to an identity database or used. A forensic assessment must therefore obtain camera inventories, firmware versions, server configurations, module licences, network diagrams, data-protection impact assessments, database schemas, operator manuals, procurement annexes and access logs. The “shadow” dimension is contractual. Financing arrangements, warranty renewals, proprietary maintenance tools, cloud dashboards, remote-support accounts and dependence on foreign-trained integrators can produce leverage without any dramatic intelligence operation. The supplier may influence upgrade timing, security-patch availability, interoperability or replacement costs; the purchasing government may consequently avoid political decisions that threaten the commercial relationship. This is structural coercibility, not proof of executed coercion. Its measurement requires four variables: technical substitutability, time required to migrate, financial exit cost and availability of trusted domestic or European operators. Where all four are adverse, the platform becomes a strategic asset embedded inside sovereign policing capacity.

The legal collision will intensify between 2026 and 2031. The EU AI Act characterises real-time remote biometric identification in publicly accessible spaces as particularly intrusive because it may affect the private lives of large populations, create a perception of constant surveillance and indirectly discourage freedom of assembly. It restricts law-enforcement use to specified exceptional circumstances accompanied by necessity, proportionality and authorisation safeguards. Regulation (EU) 2024/1689 – European Parliament and Council – July 2024verified official text. Candidate countries will consequently face a widening compliance gap if they possess surveillance functions that cannot be inventoried, independently tested or reconciled with European rules. Formal statutory alignment will be insufficient. Operational compliance will require documented legal purposes, deletion schedules, watchlist-quality controls, immutable access records, human review, judicial authorisation where applicable, incident-reporting procedures and remedies for individuals who are falsely identified. The accession process could therefore turn surveillance infrastructure into stranded technology: equipment may remain physically functional while its most intrusive modules become legally unusable. This creates three possible government responses. The first is genuine convergence through audits, database separation and deactivation of prohibited functions. The second is cosmetic alignment, in which legislation changes while operational practices remain opaque. The third is geopolitical hedging, under which governments retain Chinese-origin systems as alternatives to EU-regulated platforms. The decisive variable will be verification. European institutions can evaluate legislation, but technical sovereignty demands inspection of deployed architecture. Without mandatory asset registers, procurement disclosure, independent penetration testing and verification of remote-administration pathways, neither accession negotiators nor domestic regulators can determine whether a system is compliant, dormant, partially active or capable of rapid reactivation.

The Analysis of Competing Hypotheses requires five explanations to remain simultaneously active. H₁ is ordinary public-security modernisation: governments purchase affordable technology to improve policing, traffic control and emergency response, with geopolitics playing only a secondary role. H₂ is cumulative commercial dependency: fragmented purchasing decisions create proprietary lock-in without a coordinated Chinese state strategy. H₃ is deliberate adoption of a political-control model: governing elites value the capacity to identify demonstrators, reconstruct networks and deter mobilisation. H₄ is geopolitical leverage: maintenance, financing, integration or access dependencies create potential Chinese pressure over future foreign-policy choices. H₅ is European regulatory convergence: accession conditionality, cybersecurity controls and the AI Act progressively constrain or replace the highest-risk capabilities. An initial analytical prior assigns 30% to H₁, 27% to H₂, 20% to H₃, 13% to H₄ and 10% to H₅. These figures are structured judgements, not observed frequencies. Evidence of incomplete regulation raises H₂ and creates permissive conditions for H₃, but cannot independently establish H₄. Verified remote-access mechanisms, undisclosed foreign administrator accounts, systematic data exfiltration, politically conditioned maintenance or coordinated diplomatic pressure would be required to update H₄ sharply upward. Conversely, published inventories, independent code audits, separation of biometric databases and enforceable migration plans would update H₅ upward. The strongest discriminator between H₁ and H₃ is operational use during political mobilisation: retrospective use against specific serious crimes supports H₁ more strongly, whereas systematic identification of peaceful participants, network reconstruction and administrative retaliation would strongly favour H₃. Between H₂ and H₄, the discriminator is intentionality: dependency supports H₂; documented exploitation of that dependency supports H₄. This framework prevents the common analytical error of converting technological origin into proof of political control.

The five-year outlook is dominated by path dependence. During 2026–2027, governments are likely to inventory only part of their deployed architecture while the European Commission increases scrutiny of personal-data enforcement, high-risk artificial intelligence and ICT supply-chain security. During 2027–2028, the principal battleground will shift from camera procurement toward analytics, data fusion and interoperability: systems will become more consequential if connected to population registers, vehicle databases, border systems or mobile command platforms. During 2028–2029, replacement costs will become visible. Governments that failed to negotiate data portability, open interfaces and source-code escrow may discover that excluding a supplier requires simultaneous replacement of servers, storage, operator software and maintenance expertise. During 2029–2030, political instability could produce the first decisive operational test: whether systems designed for crime prevention are used to map protest participation or political networks. By 2030–2031, the region may divide into three groups: EU-convergent states with audited and functionally restricted systems; hybrid states retaining legacy equipment under partial safeguards; and sovereignty-deficit states in which authorities cannot independently verify, maintain or replace their surveillance architecture. The baseline estimate favours the hybrid group. Full Chinese operational dominance is less probable than continued technical dependency, while complete European replacement is constrained by costs, administrative capacity and installed-system inertia. The highest-impact adverse scenario combines political crisis, emergency legal powers, interoperable databases and a platform whose functions are neither publicly inventoried nor independently auditable. The principal mitigations are compulsory technical registries, disclosure of beneficial ownership and subcontractors, offline operation for sensitive databases, national control of encryption keys, multi-vendor interoperability, strict retention limits, independent biometric testing and automatic suspension of systems whose functions cannot be verified.

Balkan Surveillance Outlook · 2026–2031

Digital Sovereignty Stress Lab

● ANALYTICAL MODEL ONLINE

Scenario Drivers

Five-Year Risk State

68CONTROL RISK
74LOCK-IN RISK
49EU MITIGATION

Bayesian ACH Posterior

H₁ · Ordinary modernisation 30%
H₂ · Commercial dependency 27%
H₃ · Political-control adoption 20%
H₄ · Geopolitical leverage 13%
H₅ · EU regulatory convergence 10%
Simulated severe-control outcome
Simulated hybrid-regulation outcome
Simulated EU-aligned exit outcome
The displayed priors and risk scores are transparent analytical assumptions rather than reported government statistics. Each model run samples uncertainty around supplier dependency, safeguards, EU leverage and domestic political stress. “Severe control” denotes integrated biometric capability under weak oversight; “hybrid regulation” denotes retained infrastructure subject to partial restrictions; “EU-aligned exit” denotes effective auditing, functional separation or replacement of high-risk components.

Architecture of the Transfer: China’s Balkan Surveillance Stack

The transfer is a system, not a shipment

The transfer of Chinese-origin urban-surveillance capability into the Western Balkans must be analysed as the installation of a multilayer operational system rather than as the sale of cameras. The most important primary-source acknowledgement comes from Huawei itself: a 2019 corporate publication stated that the Serbian Ministry of Interior intended to develop a Safe City covering Belgrade and eventually the entire country, and that Huawei had proposed a “comprehensive solution” for those requirements. Huawei Enterprise 01/2019 – Huawei – January 2019verified corporate publication. That wording is architecturally significant. A comprehensive solution normally spans sensors, transmission networks, storage, computing, command software, integration services, technical support and operational training; it is fundamentally different from a procurement limited to standalone optical devices. The evidentiary record nevertheless requires strict boundaries: the corporate statement establishes the ambition and proposed solution, but it does not by itself establish which modules were ultimately delivered, how many devices became operational, whether facial-recognition licences were activated, which databases were connected or whether any foreign entity obtained access to Serbian data. The European Commission subsequently documented that, after negative opinions concerning the Ministry’s impact assessment for street video surveillance, the Ministry said it had suspended biometric-data processing until an adequate legal basis was created; the Commission also concluded that the proportionality and necessity of public-space surveillance and facial-recognition processing still required assessment. Serbia 2023 Report – European Commission – November 2023verified official document. The two primary sources therefore establish both capability ambition and regulatory friction, but not continuous biometric operation. This distinction governs the entire analysis: delivery, installation, configuration, activation, database connection, operator use and political employment represent seven separate evidentiary thresholds.

Evidentiary levelWhat must be demonstratedMinimum technical evidenceWhat cannot yet be inferred
E₁ — ProcurementHardware or services were contractedTender, contract, invoice, acceptance recordInstallation or functionality
E₂ — DeploymentDevices and servers were physically installedAsset register, serial numbers, geolocated inspectionNetwork connection
E₃ — IntegrationComponents exchange dataNetwork diagram, API logs, protocol capturesBiometric activation
E₄ — CapabilitySoftware can perform biometric or behavioural analysisLicence file, enabled module, model packageRoutine operational use
E₅ — ActivationCapability was technically enabledConfiguration export, service status, compute logsLawful or systematic use
E₆ — Operational useOperators queried or acted on outputsAudit logs, case records, watchlist queriesPolitical targeting
E₇ — Coercive useSystem supported repression or foreign pressureCorrelated orders, target files, access evidenceBroader conduct beyond evidence

Layered technical anatomy

The surveillance stack begins at the optical edge but derives its strategic value from the layers above it. A fixed or pan-tilt-zoom IP camera may contain a complementary metal-oxide-semiconductor image sensor, digital signal processor, system-on-chip, local memory, network interface, embedded operating system and cryptographic material. Higher-capability devices may execute edge analytics that detect faces, bodies, vehicles, licence plates, movement across virtual boundaries or crowd-density changes before transmitting metadata or selected images. This reduces bandwidth and shifts sensitive processing from the data centre into thousands of distributed endpoints, enlarging the attack surface and complicating forensic inspection. The transport layer may use municipal fibre, dedicated police networks, commercial mobile service, microwave links or combinations of these. Above it, a video-management system controls streams, user permissions, device health, recording schedules and evidence export, while a video-content-management or analytics layer transforms pixels into indexed objects. The integration layer then connects video events with police case systems, identity registers, vehicle records, border databases or emergency-dispatch applications. Chinese domestic standards demonstrate how mature this integration concept has become inside China: Shenzhen’s official technical specification for public-security video surveillance covers front-end device access, dedicated video networks, network-security architecture, interconnected sharing platforms and the integration of surveillance information resources. Technical Specification for Construction, Networking and Sharing of Public-Security Video Surveillance, DB4403/T 234—2022 – Shenzhen Municipal Government – May 2022verified Chinese government document. This Chinese standard does not prove that the same configuration was exported to Serbia. It provides an authoritative architectural reference showing that “video surveillance” in the Chinese technical ecosystem can mean a networked, shared and centrally governed information infrastructure, not isolated cameras. Huawei’s own 2018 description of a joint portrait-big-data solution combined its video cloud with third-party facial-recognition algorithms to organise urban governance around persons as data subjects. Huawei and Yitu Jointly Release Portrait Big-Data Solution – Huawei – March 2018verified corporate source. Again, this establishes design capability, not Balkan deployment.

Security Infrastructure Architecture

Multi-Layered Surveillance & Data Fusion Pipeline

Trigger Event: Public-Space Incident / Detection
L₁

Optical Edge

Camera Microphone Plate Sensor Environmental Sensor
L₂

Embedded Processing

Firmware Device Identity Edge Inference Local Storage
L₃

Transport Network

Police Fibre Municipal Network 4G / 5G Mobile Encrypted Tunnel
L₄

Platform Infrastructure

Video Management Stream Control Archive Storage Access Permissions
L₅

Analytics Engine

Face Detection Template Extraction Vector Matching Automated Alerting
L₆

Data Fusion Layer

Identity Register Police Files Vehicles Database Border Data
L₇

Operational Decision

Command Centre Field Dispatch Active Investigation Tactical Intervention
L₈

Lifecycle Control

System Updates Licences Management Maintenance Audit Logs Migration Rights

Hardware sovereignty and hidden component dependence

Hardware sovereignty cannot be established by counting visible camera housings or identifying their brand. A single labelled device may contain processors, memory, radio modules, cryptographic libraries, bootloaders and software components produced by several upstream suppliers, while the installation may depend on third-party switches, storage arrays, graphical-processing servers and synchronisation services. The critical question is whether the purchasing authority can establish an authoritative software and hardware bill of materials, validate component provenance, disable unnecessary interfaces, rotate credentials, verify firmware signatures and identify every external destination contacted by the device. NIST identifies seven core capabilities relevant to an IoT security baseline: device identification, device configuration, data protection, logical access to interfaces, software updating, cybersecurity-state awareness and device security. It also stresses that manufacturer-provided documentation and lifecycle support are non-technical capabilities essential to operational security. IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, NIST SP 800-213A – National Institute of Standards and Technology – November 2021verified United States government publication. Applied to a Balkan Safe City, these requirements mean that every camera should possess a unique inventory identity; configuration must be exportable and reviewable; stored and transmitted data must be cryptographically protected; remote interfaces must require strong authentication; updates must be signed, controlled and reversible; and the operator must receive usable security-state telemetry. A system fails the sovereignty test if the national operator cannot independently verify one or more of those properties. Dependence is particularly acute when the supplier alone holds firmware-signing authority, debugging utilities or recovery images. Even without malicious activity, the end of vendor support can convert thousands of functioning cameras into accumulating liabilities because newly discovered vulnerabilities remain unpatched. The danger is therefore not reducible to a hypothetical concealed backdoor. Ordinary lifecycle asymmetry—where the supplier knows the architecture, controls update material and retains specialist knowledge while the government possesses only operator-level access—can create durable strategic leverage.

Hardware control pointSovereignty requirementFailure signatureIntelligence significance
Device identityUnique serial, certificate and owner mappingDuplicate identities or undocumented devicesRogue endpoint can enter trusted network
Secure bootCryptographic verification of authorised firmwareUnsigned or unverifiable boot chainPersistent modification can survive reboot
Debug interfacesJTAG, UART and service ports disabled or controlledAccessible maintenance consolePhysical access may yield privileged control
Credential storageHardware-backed protected keysShared keys or exportable credentialsCompromise scales across many devices
Local storageEncryption and controlled deletionRecoverable video after decommissioningRetired devices remain intelligence assets
Firmware updateSigned, logged, staged and reversible processOpaque package or forced remote updateSupplier controls operational continuity
Component inventoryHardware and software bill of materialsUnknown chipset or library versionsVulnerabilities cannot be mapped reliably
Time integrityAuthenticated time source and drift monitoringManipulable timestampsEvidentiary chain and event correlation fail
Network interfacesAll radios and services inventoriedUndocumented Wi-Fi, Bluetooth or cellular pathHidden communications channel may exist

Software, algorithms and the separation between capture and identification

The central technical transformation occurs when software converts a video stream into a persistent, searchable representation of a person. Facial recognition commonly involves several operations: detecting a face within a frame; assessing image quality; aligning facial landmarks; extracting a numerical feature vector or template; comparing that template against a reference gallery; applying a similarity threshold; ranking candidates; and producing an alert for human review. Accuracy therefore depends not on a single advertised percentage but on camera angle, illumination, resolution, compression, occlusion, demographic distribution, gallery size, threshold selection and whether the task is one-to-one verification or one-to-many identification. The operational risk rises sharply when the platform supports retrospective search across large archives because authorities can reconstruct a person’s historical movement even if live alerts were disabled at collection time. Software licences create further opacity: the installed binary may contain modules for facial matching, person re-identification or vehicle analysis that remain dormant until activated by a licence key or configuration change. Consequently, an audit that observes no current biometric alerts cannot establish that the platform lacks biometric capability. It must inspect packages, containers, services, model files, accelerator use, scheduled jobs, API routes and licence entitlements. The EU AI Act defines remote biometric identification around identifying natural persons without their active involvement, typically at a distance through comparison with a reference database, and subjects high-risk biometric systems to extensive governance requirements. It also treats real-time law-enforcement use in public spaces as especially intrusive because of its effect on privacy and assembly. Regulation (EU) 2024/1689 – European Parliament and Council – July 2024verified official text. The decisive compliance boundary is thus not whether an authority calls the platform “Safe City,” “traffic management” or “video security”; it is what computational functions the deployed system performs, against which data, under whose authority and with which consequences.

Processing stageInputOutputTechnical audit artefactPrincipal abuse vector
Face detectionVideo frameFace bounding boxModel inventory, inference logInvisible mass collection
Quality assessmentDetected faceUsability scoreThreshold configurationSelective retention
Template extractionAligned face imageBiometric vectorModel hash, vector formatIrreversible biometric representation
Gallery enrolmentIdentity image and metadataReference recordEnrolment authority, provenanceUnlawful or politically constructed watchlist
One-to-many matchingProbe template and galleryCandidate rankingSimilarity scores, thresholdFalse-positive intervention
Person re-identificationBody appearance across camerasCross-camera trajectoryTracker configurationMovement reconstruction without identity
Behaviour analysisTracks and scene rulesAnomaly alertRule set, model versionNormal conduct classified as suspicious
Retrospective searchArchived imageryHistorical sightingsQuery audit trailPolitical network reconstruction
Alert adjudicationCandidate and operator reviewOperational decisionReviewer identity, rationaleAutomation bias
Evidence exportVideo, metadata and identityCase packageHashes, chain of custodyManipulation or unauthorised disclosure

Data architecture: the real strategic asset

Data, rather than the camera, is the durable strategic asset. A technically advanced surveillance environment may generate raw video, face crops, licence-plate strings, biometric templates, object attributes, movement trajectories, alert histories, operator notes, device-health data and access records. These objects have different sensitivity and retention requirements. Raw video may be deleted after a specified period, while derived metadata or biometric templates persist in separate databases, allowing the apparent deletion of footage to coexist with long-lived identity traces. Sovereignty therefore requires an end-to-end data-lineage model identifying where each object originates, every transformation applied to it, each storage location, each replication pathway and every actor authorised to retrieve it. The highest-risk transition occurs when the video platform becomes interoperable with authoritative identity sources. A facial-matching engine without a reference gallery can detect and cluster faces but cannot reliably assign civil identity; a connection to passport, national identity, border or police databases converts it into an identification system. Even a formally air-gapped environment may permit indirect movement through administrative exports, backup systems, maintenance laptops or removable media. Cloud functions add another dimension: telemetry, licence validation, threat-intelligence feeds or diagnostic uploads may transmit operational metadata even when video remains locally hosted. Chinese technical practice again illustrates the architectural model without proving Balkan replication. Shenzhen’s public-security video specification explicitly addresses dedicated video networks, shared platforms, front-end access and resource integration, demonstrating how data fusion is designed into modern Chinese public-security systems. Technical Specification for Construction, Networking and Sharing of Public-Security Video Surveillance, DB4403/T 234—2022 – Shenzhen Municipal Government – May 2022verified Chinese government document. An effective Balkan audit must therefore test packet flows, domain-name requests, certificate chains, backup destinations, database replication, API calls and privileged administrator activity over time. Contractual assertions that data “remain in country” are insufficient unless independent technical evidence proves that content, metadata, templates, diagnostics and credentials all remain under sovereign control.

Data Processing & Verification Protocol

Dual-Path Data Architecture & Shadow Verification

Raw Data Path (Camera Frame Processing)

Full-Res Stream Video Archive Evidence Export
Face Crop Quality Filter Temporary Cache
Plate Crop OCR Engine Vehicle-Event Database
Object Metadata Analytics Index Retrospective Search

Identity Path (Biometric Matching Engine)

Reference Image Template Generator Biometric Gallery
Probe Template Similarity Engine Candidate List Human Review Police Action

Shadow Paths Requiring Verification

Diagnostics Support Server
Licence Data Vendor Endpoint
Backups Secondary Data Centre
Logs Security Platform
Updates Supplier-Controlled Repository
Technician Privileged Remote Session

Maintenance, remote support and privileged access

Maintenance is the least visible and potentially most decisive layer because it determines who can preserve, modify, recover or disable the system after formal delivery. Surveillance platforms require firmware patches, operating-system maintenance, database optimisation, certificate renewal, storage replacement, vulnerability remediation, model updates and operator support. These activities often involve accounts more powerful than those assigned to ordinary police operators. A remote-support channel may be legitimate and operationally necessary, but it becomes a sovereignty problem when activation does not require national approval, sessions are not recorded, technician identities are not attributable, commands are not logged or data can be extracted through diagnostic bundles. The correct audit question is not merely “Does the vendor have remote access?” but “What complete set of technical and procedural conditions would allow any supplier, integrator, subcontractor or former employee to obtain privileged access?” This includes dormant accounts, shared passwords, emergency credentials, virtual private network profiles, remote-management agents, hardware management controllers, cloud consoles and update infrastructure. NIST’s IoT guidance emphasises authentication before remote connection, protection of logical interfaces, secure software updating, access to cybersecurity-state information and lifecycle documentation. IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, NIST SP 800-213A – National Institute of Standards and Technology – November 2021verified United States government publication. The EU’s 2026 ICT Supply Chain Security Toolbox extends the analysis beyond individual vulnerabilities by recommending assessment frameworks for critical suppliers, multi-vendor strategies and measures to overcome high-risk dependencies. ICT Supply Chain Security: EU Adopts a Toolbox to Mitigate Risks – European Commission – February 2026verified official publication. These principles imply that a maintenance contract is part of the security perimeter. Procurement authorities must specify sovereign session approval, just-in-time credentials, multi-factor authentication, complete command recording, data-export prohibition, named personnel, subcontractor disclosure and rapid credential revocation.

Maintenance vectorLegitimate purposeExploitable dependencyRequired sovereign control
Firmware updatePatch vulnerabilities and improve stabilitySupplier controls executable codeSigned packages, staging, reproducible hashes, rollback
Licence renewalContinue analytics functionsCapability can be remotely reducedOffline licence option and transition period
Remote diagnosticsResolve faults quicklyPrivileged access to system and metadataNational approval, recording and command logging
Model updateImprove detection or matchingModel behaviour changes without transparent reviewVersioned testing and independent validation
Certificate renewalMaintain trusted communicationsExpiry can halt serviceNational certificate authority or escrow process
Database tuningPreserve performanceAdministrator can access identity and query dataSegregated duties and monitored sessions
Storage replacementMaintain archive capacityRetired media contain recoverable dataCertified sanitisation or physical destruction
Incident responseRecover after compromiseSupplier controls forensic narrativeIndependent evidence preservation
TrainingMaintain operator competenceKnowledge remains vendor-specificTrain-the-trainer and national documentation
End-of-life supportSustain legacy deploymentSecurity patches ceaseContractual notice, migration assistance, source escrow

System integration and the multiplication of political power

System integration produces a nonlinear increase in capability because each additional database changes what can be inferred from the same image. A camera network connected only to a local recorder can document an event; connected to a vehicle register, it can identify owners; connected to civil identity records, it can identify faces; connected to telecommunications or border data, it can reconstruct associations and movement; connected to command-and-control software, it can trigger immediate intervention. The architecture therefore has to be assessed as a graph of trust relationships rather than as a list of assets. Every API creates a pathway through which privileges, errors and compromise can propagate. A police investigator authorised to query one database may gain indirect access to another through a federated platform. A compromised analytics server may become a bridge between a less-protected municipal network and a sensitive national register. A unified dashboard may conceal these trust transitions from the operator, creating the appearance of a single application while executing queries across several agencies. The danger grows when identity resolution is probabilistic: the dashboard may present an algorithmic candidate with an authoritative appearance even though the underlying match is uncertain. Integration consequently requires purpose-bound access controls, field-level restrictions, query justification, immutable audit trails and independent review of cross-agency use. The Serbian case remains particularly important because Huawei’s corporate publication described an ambition extending beyond Belgrade toward national coverage, while the European Commission recorded unresolved questions concerning proportionality, necessity and legal basis for public-space facial recognition. Huawei Enterprise 01/2019 – Huawei – January 2019verified corporate publication. Serbia 2023 Report – European Commission – November 2023verified official document. Neither source establishes that a national integrated biometric network became operational. Together, however, they identify the exact strategic problem: ambitious system scope preceded a settled and independently validated governance framework.

Integration nodeData contributionCapability createdPolitical-risk escalation
National identity registerAuthoritative face and civil identityNamed facial identificationAnonymous presence becomes attributable
Passport databaseHigh-quality identity photographsExpanded reference galleryResidents and travellers become searchable
Vehicle registerPlate-to-owner relationshipAutomated mobility mappingMeetings and travel can be reconstructed
Border systemEntry and exit eventsCross-border movement historyDiaspora and opposition travel become visible
Police case databaseInvestigative status and associationsRisk-labelled identificationSuspicion propagates into public-space monitoring
Emergency dispatchLive operational responseImmediate interventionAlgorithmic alerts affect physical liberty
Municipal sensorsLocation, parking and access eventsUrban behaviour profileAdministrative data become intelligence data
Telecommunications metadataDevice relationships and locationSocial-network reconstructionAssociation becomes a targetable attribute
Event-permit recordsOrganisers, locations and timesProtest-specific monitoringLawful assembly becomes pre-indexed
Private CCTV feedsCommercial and residential coverageNear-continuous spatial visibilityState reach expands without public procurement

Supplier dependence and the lock-in equation

Supplier dependence accumulates across technical, financial, legal and human-capital dimensions. Technical lock-in arises from proprietary protocols, database schemas, video codecs, analytics APIs, device-management systems, model formats and licence mechanisms. Financial lock-in emerges when replacing one layer forces simultaneous replacement of others, converting a seemingly inexpensive procurement into a high-cost migration programme. Legal lock-in can arise from restrictive intellectual-property clauses, non-portable configurations or weak contractual rights to documentation. Human-capital lock-in occurs when police technicians learn only the vendor interface and lack the engineering knowledge needed to operate the underlying infrastructure independently. The most consequential dependency is rarely a single monopoly component; it is the interaction among all four. Huawei’s audited 2025 reporting states that cybersecurity and privacy protection remain foundational corporate priorities and that the company works with customers, partners and suppliers to strengthen security capabilities. Huawei 2025 Annual Report – Huawei – March 2026verified audited corporate report. That statement is relevant evidence of the vendor’s declared governance position, but it cannot substitute for system-specific verification inside a Balkan police deployment. Corporate assurance, architectural transparency and operational audit are separate layers of evidence. A sovereign government must be able to test whether its specific configuration complies with national requirements regardless of the supplier’s general policies. The EU’s horizontal supply-chain approach is therefore strategically more useful than an exclusively country-of-origin test: assess criticality, substitutability, supplier characteristics, dependencies, incident exposure and mitigation capacity, then use multi-vendor architecture to prevent any single supplier from controlling operational continuity. ICT Supply Chain Security: EU Adopts a Toolbox to Mitigate Risks – European Commission – February 2026verified official publication. The correct objective is not symbolic “de-Chinesification,” but measurable sovereign control over every critical function.

Dependence dimensionLow-risk conditionMedium-risk conditionHigh-risk conditionExit test
Device managementOpen standard and national consoleExportable proprietary consoleSupplier-only administrationCan another platform enrol every device?
Video archiveStandard export with metadataExport possible with conversionProprietary archive inaccessible externallyCan evidence migrate without losing hashes?
AnalyticsReplaceable model interfaceLimited third-party compatibilityVendor-exclusive engine and accelerator stackCan an independently tested model be substituted?
Identity galleryOpen documented schemaPartial exportEncrypted or undocumented proprietary databaseCan all templates be lawfully re-enrolled?
LicencingPerpetual offline operationPeriodic local renewalContinuous vendor-controlled validationDoes system survive supplier disconnection?
FirmwareSigned and independently stagedSupplier package with local approvalForced or opaque remote deliveryCan updates be rejected and rolled back?
SupportMultiple certified integratorsSingle domestic integratorForeign supplier-exclusive expertiseCan national staff restore service alone?
DocumentationComplete and currentPartial or delayedUnavailable or vendor-confidentialCan an independent team rebuild configuration?
ContractPortability and escrow rightsNegotiated transition assistanceNo migration obligationIs exit enforceable within a fixed timetable?
FinancingTransparent budget purchaseConcessional supplier creditDebt tied to continued vendor ecosystemCan financing be separated from operations?

Bayesian competing hypotheses and collection priorities

The architecture supports five competing hypotheses that must be updated through discriminating evidence rather than rhetoric. H₁ proposes that the system is principally an ordinary crime-control modernisation programme and that Chinese-origin technology was selected for cost, integration capacity and rapid delivery. H₂ proposes that the principal consequence is unplanned commercial lock-in, produced by cumulative technical choices rather than geopolitical direction. H₃ proposes that domestic political authorities intentionally value latent capabilities for protest identification, opposition mapping or social deterrence. H₄ proposes that Chinese state or corporate actors can exploit maintenance, financing, access or replacement dependencies as geopolitical leverage. H₅ proposes that EU accession conditionality, the AI Act and supply-chain policy will progressively constrain, separate or replace the most sensitive capabilities. An architecture-based prior for 2026 assigns H₁ 26%, H₂ 31%, H₃ 20%, H₄ 11% and H₅ 12%. The higher prior for H₂ reflects the well-established mechanics of proprietary system integration; it does not imply intentional misconduct. Huawei’s documented proposal for comprehensive national-scale coverage raises the relevance of H₂, while the Serbian regulator’s earlier objections and the absence of an established legal basis increase the permissive conditions for H₃. Neither observation proves H₄. That hypothesis requires discriminators such as undocumented foreign administrator accounts, supplier-controlled extraction paths, politically conditioned support, financing covenants tied to diplomatic conduct or verified intervention by Chinese authorities. Evidence that would favour H₅ includes complete public inventories, independent firmware testing, system-specific impact assessments, database separation, strong regulator access and funded migration programmes. Russian-language official sources were checked for corroboration of a Russia–China–Balkan surveillance integration nexus, but no qualifying primary evidence was identified that would support such a claim; no Russian link is therefore introduced as evidentiary filler. This negative finding is analytically meaningful because it prevents the unsupported fusion of separate Russian and Chinese influence ecosystems into a single operational architecture.

HypothesisPrior 2026Evidence increasing probabilityEvidence decreasing probabilityPriority collection requirement
H₁ — Ordinary modernisation26%Crime-specific use, narrow access, transparent metricsProtest-oriented queries, hidden modulesCase-to-query sampling and use-policy audit
H₂ — Commercial lock-in31%Proprietary formats, single integrator, supplier-only recoveryOpen APIs, tested migration, multiple maintainersContract annexes and technical portability test
H₃ — Domestic political control20%Protest watchlists, retrospective participant searchJudicially limited serious-crime useQuery logs during demonstrations and elections
H₄ — Foreign geopolitical leverage11%External privileged access, conditional support or financeNational keys, offline licensing, audited sessionsRemote-access logs and financing documentation
H₅ — EU convergence12%AI Act mapping, audits, separation and replacement fundingCosmetic legislation without technical inspectionAccession benchmarks tied to deployed systems

Monte Carlo risk model and five-year outlook

The five-year model treats risk as the interaction of six variables: supplier concentration C, privileged-access opacity A, database integration D, domestic political stress P, regulator effectiveness R and EU conditionality E. Each variable is scored from 0 to 100, with higher C, A, D and P increasing the probability of sovereignty loss, while higher R and E reduce it. The model does not treat these factors as independent because that would understate systemic risk. Supplier concentration and access opacity are positively correlated: a single-vendor environment often concentrates maintenance knowledge and credentials. Database integration and political stress are also correlated in the adverse tail because emergency conditions increase pressure to connect systems or relax controls. Regulator effectiveness and EU conditionality are positively correlated but imperfectly so, since formal accession progress does not guarantee operational enforcement. A 100,000-path conceptual Monte Carlo specification using triangular distributions and moderate correlation produces three scenario classes rather than a false point forecast: S₁, EU-aligned controlled migration; S₂, hybrid persistence with partial restrictions; and S₃, integrated high-dependence surveillance. The baseline analytical distribution for 2031 assigns approximately 24% to S₁, 53% to S₂ and 23% to S₃. These values are structured risk estimates derived from disclosed assumptions, not official statistics. S₂ dominates because complete replacement is financially and technically demanding, while unrestricted expansion will face increasing legal and accession pressure. S₃ becomes the modal adverse outcome if privileged-access opacity remains above 70, database integration exceeds 75 and regulator effectiveness remains below 40 during a sustained political crisis. S₁ becomes more probable if candidate governments establish asset registers by 2027, require national control of keys and credentials by 2028, complete independent biometric testing by 2029 and demonstrate successful vendor-independent recovery by 2030. The graph at the end visualises the annual risk trajectories generated by this structured model.

Model variable2026 baseline2031 controlled path2031 hybrid path2031 adverse path
C — Supplier concentration72386186
A — Privileged-access opacity67244988
D — Database integration5548 with controls6991
P — Political stress58425782
R — Regulator effectiveness43795631
E — EU conditionality67917649
Composite sovereignty-loss risk64285689

The operational sequence from 2026 through 2031 is likely to move through five distinct stages. In 2026–2027, the principal uncertainty will concern inventory: governments and external assessors may know visible manufacturers but lack a complete register of firmware, licences, server modules, support accounts and connected databases. In 2027–2028, procurement pressure will shift from camera expansion toward analytics, storage consolidation and data fusion, because existing video becomes substantially more valuable when searchable across time and agencies. In 2028–2029, AI Act alignment and wider EU supply-chain controls will force candidate countries to classify biometric systems, document legal purposes and confront whether dormant functions must be removed rather than merely disabled. In 2029–2030, migration economics will become decisive as governments discover whether configurations, archives, identity galleries and device certificates can move to alternative platforms without simultaneous replacement of the entire stack. In 2030–2031, the first credible sovereignty verdict will depend on operational tests: whether national teams can disconnect the supplier, rotate all privileged credentials, restore the platform from trusted backups, update components independently, reproduce audit histories and continue essential service. A platform that passes legal review but fails this technical exercise remains dependent. A system that passes technical migration but retains uncontrolled cross-agency data use remains politically dangerous. The decisive policy is therefore functional decomposition: separate capture from identification, identification from the reference gallery, analytics from police decision-making, and maintenance from unrestricted data access. This architecture reduces the blast radius of compromise and permits individual components to be replaced. It also creates observable control points for accession monitoring, making it harder for intrusive functions to remain hidden behind a generic Safe City label.

Technical audit and OSINT exploitation framework

A rigorous OSINT and technical investigation must combine documentary, geospatial, network, procurement and software evidence while preserving the distinction between indication and proof. Documentary collection should target tender specifications, acceptance certificates, maintenance schedules, data-protection impact assessments, subcontractor lists, training materials and amendments that expand system scope after the original award. Geospatial work should identify cameras, network cabinets, command centres, fibre routes and likely aggregation points, but external imagery cannot determine enabled software functions. Network analysis should occur only under lawful authority and should map device destinations, certificate issuers, update servers, domain-name queries and remote-support windows. Software examination should hash firmware and platform components, enumerate services, identify embedded libraries, inspect licence files and compare installed modules with procurement descriptions. Operational forensics should analyse query logs around protests, elections, major public events and serious-crime investigations, using strict access controls to avoid creating a second privacy violation. Financial analysis should map initial purchase cost, concessional credit, recurring licences, foreign-currency exposure, maintenance escalation and the replacement-cost cliff. The “shadow liquidity” dimension is not limited to secret financing; it includes underpriced initial hardware compensated by long-term service revenue, bundled training, supplier credit and upgrades purchased outside the original tender. Cyber-norm analysis must distinguish espionage allegations from enforceable controls: any supplier should be assessed through identical requirements for access logging, update transparency, vulnerability disclosure and portability. The correct red-team test assumes neither innocence nor guilt. It asks what a malicious vendor technician, compromised domestic administrator, politically directed operator, foreign intelligence service or criminal intruder could do with the same architecture, and which evidence would reveal the action. This multi-actor approach prevents country-of-origin analysis from obscuring domestic abuse and ordinary cybersecurity failure.

Audit workstreamCollection targetVerification methodHigh-risk finding
Procurement OSINTTenders, annexes, amendments, subcontractorsCross-document entity and date reconciliationSensitive modules absent from public scope
Physical inventoryCameras, servers, switches, command sitesSerial reconciliation and geospatial inspectionUndocumented or duplicate devices
Firmware analysisImages, hashes, libraries, signing chainStatic analysis and trusted-boot validationUnsigned code or hidden service
Network forensicsDestinations, ports, certificates, DNSFlow monitoring and packet inspectionUnauthorised external connection
Identity governanceGallery source, enrolment, deletionRecord sampling and legal-authority checkUnlawful or politically curated watchlist
Access reviewAccounts, roles, sessions, emergency accessPrivilege graph and session replayForeign or shared administrator account
Algorithm validationThresholds, error rates, demographic performanceIndependent controlled testingUnacceptable false-positive disparity
Use auditQueries, alerts, police actionsLog-to-case correlationSearch unrelated to authorised investigation
Financial mappingCredit, renewals, maintenance and exit costContract cash-flow reconstructionReplacement economically prohibitive
Resilience testBackup, restore, credential rotation, failoverSupplier-disconnection exerciseEssential service cannot continue independently

The minimum sovereign-security programme should therefore contain twelve enforceable controls: a complete asset and software-component register; secure device identity; national ownership of cryptographic keys; segmented networks; disabled unnecessary interfaces; signed and locally approved updates; immutable access and query logging; named and time-limited maintenance accounts; independent algorithm testing; purpose-limited database connections; contractual portability and source escrow where technically justified; and an annually exercised supplier-exit plan. Compliance must be demonstrated through evidence rather than self-certification. The exit exercise is the most revealing control because it simultaneously tests documentation, credentials, backups, staff competence, licences, interoperability and political willingness. Governments should be required to operate the system for a defined period with all supplier remote connections disabled, then restore a representative subsystem using nationally controlled material. Failure should trigger a time-bound remediation plan and restrictions on further integration. European financial assistance could reduce the political attraction of opaque bundled procurement by funding open interfaces, migration tooling, regulator laboratories and regional testing capacity. The objective is not necessarily to remove every Chinese-origin device; indiscriminate replacement could waste public funds while leaving equally weak governance around the successor system. The objective is to ensure that no supplier can unilaterally update, disable, inspect, extract from or render irreplaceable a sovereign public-security platform. By 2031, digital sovereignty should be measured through four practical questions: Can the state identify every critical component? Can it prove who accessed every sensitive function? Can it replace any supplier without losing essential capability or evidence? Can an independent authority verify that biometric use complies with law? If any answer remains negative, the system is not sovereign regardless of where its servers are located.

Architecture of the Transfer
Figure 1: Five-Year Sovereignty-Risk Projection
Analytical scenario scores, 0–100. Values are modeled estimates, not observed government statistics.

Sovereignty and Political Pressure: Biometrics, Protest Monitoring, Policing, Intelligence Access and Geopolitical Leverage

Sovereignty as control over the decision chain

Digital sovereignty in an urban-surveillance environment is not established merely because cameras and servers are physically located inside national borders. It exists only when domestic institutions retain exclusive, independently verifiable control over five linked authorities: the authority to collect data, transform images into biometric identifiers, decide which persons enter reference databases, authorise searches and determine the consequences of algorithmic results. A government may own the physical infrastructure while remaining dependent on a foreign supplier for software updates, licence activation, model configuration or specialist maintenance. Conversely, a foreign-manufactured system can theoretically operate under strong sovereign control if the purchasing state controls encryption keys, administrator accounts, update approval, data flows, source documentation and supplier replacement. The Serbian case contains both a documented capability ambition and unresolved legal constraints. Huawei stated that Serbia’s Ministry of Interior wanted a Safe City covering Belgrade and eventually the country, and that Huawei proposed a comprehensive solution. Huawei Enterprise 01/2019 – Huawei – January 2019verified corporate publication. The European Commission later reported that the Serbian Ministry had placed biometric-personal-data processing on hold after negative opinions concerning its street-surveillance impact assessment, pending an adequate legal basis. It further concluded that the proportionality and necessity of public-space surveillance and facial-recognition processing still required assessment. Serbia 2023 Report – European Commission – November 2023verified official document. In 2024, the Commission stated that it still had to be verified whether Serbia had processed personal data using facial-recognition software. Serbia Report 2024 – European Commission – October 2024verified official document. These findings do not establish systematic biometric surveillance. They establish an unresolved sovereignty question: whether governmental, regulatory and judicial institutions can determine with certainty which functions exist, which are active, who uses them and whether their use remains within law.

Sovereignty domainSovereign-control requirementDeficit indicatorPolitical consequence
Collection authorityCameras operate for defined legal purposesUnbounded or repurposed collectionPopulation-wide visibility
Biometric transformationTemplate generation separately authorisedFace templates produced by defaultIdentity data created without scrutiny
Gallery governanceEntries have documented provenance and expiryPolitical, administrative or unclear watchlistsOpposition actors become targetable
Query authorityEach search requires attributable justificationShared accounts or bulk searchesCollective monitoring becomes difficult to detect
Algorithm controlThresholds and models independently validatedVendor-selected settingsSupplier influences error and alert rates
Operational responseHuman review precedes coercive actionAutomatic dispatch or administrative actionSoftware affects physical liberty
Audit authorityIndependent regulator can inspect all layersClassified or supplier-restricted accessExecutive branch becomes self-policing
Exit authorityGovernment can replace the supplierProprietary formats and exclusive maintenanceForeign-origin dependency becomes durable

From presence to identity: the biometric escalation ladder

Biometric surveillance changes the political meaning of public space because it converts transient presence into an identity-linked and potentially permanent state record. The escalation begins with ordinary video capture but develops through a series of technically distinct functions. Face detection locates a face without necessarily identifying it. Template extraction converts facial characteristics into a mathematical representation. One-to-many matching compares that representation against a reference gallery. Person re-identification follows an individual across different cameras using clothing, body shape, gait or other appearance features even when civil identity remains unknown. Retrospective search reconstructs earlier sightings after authorities obtain a target image. Relationship analytics infer co-presence, repeated association and movement patterns. Each stage increases state knowledge, but each also requires separate testing and legal justification. The EU AI Act defines remote biometric identification as identifying natural persons without their active involvement, usually at a distance through comparison with reference data. It treats real-time law-enforcement use in publicly accessible spaces as especially intrusive because it can affect large parts of the population, create a sense of constant surveillance and discourage the exercise of assembly and other fundamental rights. Regulation (EU) 2024/1689 – European Parliament and Council – July 2024verified official text. The European Court of Human Rights has similarly emphasised the exceptionally intrusive character of facial recognition used to locate and arrest a person connected to a peaceful demonstration. Its updated data-protection case-law guide states that the highest level of justification is required for such interference to qualify as necessary in a democratic society. Guide on Article 8 of the European Convention on Human Rights: Data Protection – European Court of Human Rights – February 2026verified official guide. The core sovereignty issue is consequently not accuracy alone. Even a highly accurate system can be politically illegitimate if the gallery, legal purpose or query process is unlawful; an inaccurate system adds discriminatory and coercive error to that legitimacy failure.

State Control Escalation

Biometric Political-Power Escalation

V₁

Video Capture

State observes a public-space event but may not know the identities of individual participants.
V₂

Identity Attachment

Biometric templates link recorded public physical presence directly to legal individual identity files.
V₃

Cross-Database Fusion

Identified individuals are cross-referenced with intelligence files, travel records, and tax registries.
V₄

Automated Real-Time Alerting

Live camera networks automatically generate tactical alerts when watchlist individuals enter public zones.
V₅

Predictive Behavior Modeling

Algorithms track movement patterns over time to predict gatherings, dissent, or association networks.
V₆

Coercive Social Control

Automated administrative interventions, movement restrictions, or targeted enforcement prior to physical actions.

Sovereignty and Political Pressure: Biometrics, Protest Monitoring, Policing, Intelligence Access and Geopolitical Leverage

From observation to political power

A surveillance platform becomes politically consequential when it changes the cost, speed and scale of identifying people who participate in collective action. Conventional policing requires officers to observe a demonstration, record suspected offences, identify specific individuals and assemble evidence. A networked biometric platform can compress this sequence by detecting faces or bodies, comparing captured representations with reference databases, correlating sightings across cameras and producing candidate identities before or after an event. The transformation is not merely quantitative. It allows the state to shift from investigating conduct to reconstructing presence, association and movement. A person need not commit an offence to become analytically visible: attendance at a protest, repeated proximity to organisers or movement between politically significant locations may create a persistent data trail. The Serbian context makes this distinction operationally important. The European Commission reported that the Ministry of Interior had suspended processing of biometric personal data after negative opinions concerning its street-surveillance impact assessment and that the proportionality and necessity of public-space video surveillance and facial-recognition processing still required evaluation. Serbia 2023 Report – European Commission – November 2023verified official document. In 2024, the Commission stated that it still had to be verified whether Serbia had processed personal data using facial-recognition software and noted the incompatibility of certain uses with the developing EU artificial-intelligence framework. Serbia Report 2024 – European Commission – October 2024verified official document. These official formulations do not prove systematic biometric monitoring of protesters. They establish an unresolved verification problem at precisely the moment when Serbia experienced sustained mobilisation, making technical auditability a question of democratic sovereignty rather than routine data administration.

Political-surveillance stageTechnological functionMinimum inputOperational outputDemocratic-risk threshold
ObservationLive or recorded videoPublic-space imageVisual recordLow if limited, lawful and time-bound
DetectionFace, body or vehicle extractionVideo frameStructured objectRises when collection is indiscriminate
IdentificationBiometric or plate matchingReference galleryCandidate identityHigh without strict necessity and review
AssociationCo-location and repeated proximityMulti-camera eventsRelationship graphHigh when presence substitutes for conduct
ReconstructionCross-camera trackingTime-stamped sightingsMovement historyHigh when applied retrospectively to assemblies
ClassificationRisk or behavioural scoringIdentity plus contextual dataPriority or suspicion labelVery high when criteria are secret
InterventionDispatch, questioning or detentionAlert or analyst judgementState coercive actionCritical if automated output drives action
PersistenceLong-term storage and reuseTemplates, metadata and case recordsDurable political dossierCritical without deletion and remedies

Serbia’s protest environment and the evidentiary boundary

The political-pressure assessment must integrate Serbia’s protest cycle without converting allegations into established technical findings. The student-led mobilisation that followed the November 2024 Novi Sad railway-station canopy collapse expanded into demands for accountability, transparency and institutional responsibility. The United Nations High Commissioner for Human Rights described more than six months of student-led protests during his May 2025 visit and emphasised the importance of dialogue, civic space and protection of rights. Serbia: Türk Touched by Resilience of People He Met, and Their Desire and Determination for a Better Future – Office of the UN High Commissioner for Human Rights – May 2025verified United Nations statement. In August 2025, UN experts stated that peaceful demonstrators had reportedly faced intimidation, physical attacks and surveillance; the word “reportedly” is essential because the statement communicated received allegations rather than a completed forensic adjudication. Serbia Must Halt Crackdown on Student Movement, Uphold Human Rights and Academic Freedom – Office of the UN High Commissioner for Human Rights – August 2025verified United Nations publication. The Parliamentary Assembly of the Council of Europe later expressed concern about mass protests, disproportionate violence, harassment and revelations concerning surveillance of Serbian journalists and activists, urging effective investigations and accountability. Progress of the Assembly’s Monitoring Procedure, Resolution 2635 – Parliamentary Assembly of the Council of Europe – June 2026verified official resolution. None of these sources attributes the alleged surveillance to Huawei cameras, proves facial-recognition use at demonstrations or establishes Chinese intelligence access. They do, however, show a politically sensitive target environment in which the unresolved status of biometric capabilities becomes materially more dangerous. The appropriate conclusion is therefore conditional: if an unaudited biometric platform is connected to police identity repositories during mass mobilisation, the opportunity for coercive use is high even before such use is proven.

Biometric mechanics of protest identification

The technical chain for identifying demonstrators contains several distinct operations, each generating evidence that an independent inquiry should be able to recover. Cameras first capture frames whose evidential value depends on resolution, focal length, angle, illumination, motion blur and compression. A detection model locates faces; a quality model rejects unusable images; an embedding model converts the remaining face into a numerical template; and a similarity engine compares that template with one or more galleries. The output is not a factual identity but a ranked candidate accompanied by a similarity score. The operator or downstream workflow then applies a threshold and decides whether to accept, reject or escalate the match. In a protest environment, performance may deteriorate because of crowd density, banners, masks, head movement, oblique angles and rapidly changing light. Yet the political danger does not disappear when individual identification is unreliable. Person re-identification can connect appearances across cameras using clothing, body characteristics and movement patterns without initially knowing a civil identity; vehicle recognition can associate arrival and departure with ownership records; and retrospective search can identify an individual after authorities obtain a better reference image. The European Court of Human Rights’ judgment in Glukhin v. Russia is the most directly relevant official precedent. The Court examined the use of facial recognition to locate and arrest a person connected to a peaceful solo demonstration and emphasised the particularly intrusive nature of the technology and the high justification required for its use. Case of Glukhin v. Russia – European Court of Human Rights – July 2023verified official judgment. The Court’s updated data-protection case-law guide reiterates that live facial recognition in public CCTV systems requires the highest level of justification where it connects peaceful demonstration to identification and arrest. Guide on Article 8 of the European Convention on Human Rights: Data Protection – European Court of Human Rights – February 2026verified official guide.

Biometric Surveillance Architecture

Protest-Identification Pipeline

Multi-Modal Identification Paths

Camera Capture Face Detection Quality Filtering Biometric Template Reference-Gallery Search Ranked Candidate Identities
Camera Capture Body Tracking Cross-Camera Re-Identification
Vehicle Capture Plate Recognition Owner Data
Event Records Time & Location Correlation Identity Dossier Analyst Review Police Query Intervention

Critical Control Points & Safeguards

Legal Gallery Legality
Algorithmic Threshold Validity
Oversight Human Review
Purpose Query Purpose
Data Retention Period
Compliance Audit Integrity
Access Cross-Agency Access
Judicial Judicial Remedy
Biometric parameterTechnical meaningProtest-specific distortionRequired control
Detection rateProportion of visible faces detectedMasks, banners and crowd occlusionPublish controlled test conditions
False-match rateIncorrect gallery candidates acceptedLarge galleries multiply candidate opportunitiesSet use-specific thresholds
False non-match rateCorrect identity not returnedAngle, blur and low lightPrevent repeated threshold relaxation
Gallery sizeNumber of enrolled identitiesBroad civil databases increase surveillance reachPurpose-limited enrolment
Gallery provenanceSource and legality of reference imagesProtest photos may be unlawfully harvestedDocument lawful authority
Template retentionDuration biometric vectors are storedEnables future retrospective searchesAutomatic deletion and verification
Re-identification spanTime and distance over which tracking persistsReconstructs attendance and social proximityStrict spatial and temporal limits
Human adjudicationReview before operational actionAutomation bias favours machine candidateDual review and recorded rationale
Query loggingRecord of who searched whom and whyReveals political targeting patternsImmutable independent audit
Downstream propagationTransfer of alert into other systemsSuspicion persists after false matchCorrection and deletion workflow

Protest monitoring beyond facial recognition

A mature urban-control platform does not require definitive facial identification to exert political pressure. Crowd analytics can estimate density, direction, dispersal and convergence; virtual tripwires can detect entry into defined zones; object detection can identify banners, vehicles or protective equipment; licence-plate recognition can map transport used by participants; and temporal correlation can reconstruct repeated presence around universities, party offices, newsrooms or civil-society organisations. Audio sensors may add sound-event detection, while telecommunications or online datasets—if lawfully or unlawfully combined—can connect physical presence with social relationships. The most politically powerful output is therefore often not “Person X has been recognised” but “these devices, vehicles and visual tracks repeatedly co-occurred at these politically significant events.” This creates an association graph that can guide questioning, tax inspection, employment pressure, administrative scrutiny or intensified physical monitoring. The UN’s April 2025 communication concerning Serbia raised allegations relating to interference with human-rights defenders’ financial privacy, spyware use against journalists and activists, criminalisation and smear campaigns. Joint Communication to Serbia, AL SRB 3/2025 – United Nations Special Procedures – April 2025verified official communication. This communication does not establish a connection between spyware and Chinese Safe City infrastructure. Its analytical importance lies in demonstrating that political surveillance may be multi-modal: mobile-device compromise, financial-data access, street cameras, human sources and administrative databases can reinforce one another even when operated through separate systems. Consequently, an investigation that examines only facial-recognition logs risks missing the broader targeting architecture. The audit scope must include watchlist creation, plate searches, device identifiers, retrospective video export, map queries, cross-agency data requests, operator-created tags and correlations between digital alerts and subsequent state action. The absence of a facial match does not demonstrate the absence of technologically enabled political monitoring.

Surveillance modalityIdentity required initially?Political intelligence producedKey forensic artefact
Crowd-density analysisNoSize, direction and concentrationZone definitions and event alerts
Person re-identificationNoCross-camera movement patternTracker identifiers and route history
Facial recognitionYes, through gallery matchNamed individual presenceProbe, candidate list and threshold
Licence-plate recognitionIndirectlyVehicle and owner movementPlate query and registry lookup
Mobile-device exploitationYes or later attributionCommunications, files and locationDevice forensic image and server indicators
Financial-data accessYesFunding, donors and organisational

Sovereignty and Political Pressure: Biometrics, Protest Monitoring, Policing, Intelligence Access and Geopolitical Leverage

From observation to coercive capacity

The political significance of a Safe City platform begins when observation becomes attribution. Conventional video surveillance records a scene; biometric surveillance converts an unknown person into a persistent digital subject who can be located across space, searched retrospectively and associated with other people or events. The transformation follows a technical chain: face detection isolates an image; template extraction converts facial geometry into a numerical representation; one-to-many matching compares that representation with a reference gallery; identity resolution links the candidate to an authoritative record; and operational integration connects the result to police action. Each stage increases state power, but each also introduces a separate legal and evidentiary threshold. A camera capable of detecting faces does not prove the existence of a national biometric gallery; an installed matching engine does not prove that it is active; a match does not prove that an operator acted upon it; and operational use does not prove political targeting. In Serbia, this distinction is particularly important. The European Commission reported in 2023 that, following negative opinions on the Ministry of Interior’s impact assessment for street video surveillance, the Ministry stated that biometric-data processing had been suspended until a legal basis was developed. The Commission further concluded that the necessity and proportionality of public-space video surveillance and facial-recognition processing still required assessment. Serbia 2023 Report – European Commission – November 2023verified official document. In 2024, the Commission stated that it still had to be verified whether Serbia had processed personal data using facial-recognition software, while noting the relevance of the EU prohibition framework. Serbia Report 2024 – European Commission – October 2024verified official document. The official record therefore demonstrates unresolved verification, regulatory controversy and latent capability; it does not establish continuous facial recognition or Chinese access to Serbian biometric data.

Capability stageTechnical functionPolitical effectMinimum evidence neededConfidence if evidence is absent
C₁ — ObservationRecords public-space imageryDocuments presence without identityCamera inventory and recording policyPresence of surveillance only
C₂ — DetectionIsolates faces, bodies or vehiclesConverts crowds into machine-readable objectsModel package and inference logTechnical possibility
C₃ — IdentificationMatches a biometric template to a galleryConverts anonymity into named presenceGallery schema, threshold and match logsUnproven activation
C₄ — TrackingLinks sightings across cameras and timeReconstructs movementRe-identification configuration and trajectory recordsUnproven persistence
C₅ — AssociationCorrelates co-presence and repeated encountersMaps social and political networksGraph-query logs and analytic rulesUnproven network analysis
C₆ — InterventionSends alert to police or intelligence operatorsConverts prediction into state actionDispatch, case and adjudication recordsUnproven operational consequence
C₇ — CoercionUses outputs against lawful political activityProduces deterrence, questioning or retaliationTarget files, orders and correlated actionsAllegation requiring corroboration

Protest monitoring as a distinct surveillance mission

Protest monitoring differs technically and legally from ordinary crime investigation because the state begins with a politically salient event rather than a previously identified suspect. A demonstration provides time, place, route and participant density, making it unusually compatible with automated collection. Authorities can establish virtual perimeters around assembly points, extract face crops as participants enter, compare them with identity databases, track movement between transport hubs and protest sites, and retrospectively query archival footage after the event. Even when the platform does not identify every person, person re-identification can link the same individual across multiple cameras by combining clothing, body geometry, gait and temporal proximity. Association analysis can then infer organisers, recurrent participants, logistical coordinators or individuals who move between otherwise separate groups. The political effect is not limited to arrest. Knowledge or suspicion that participation can be reconstructed may create a chilling effect, especially for public employees, students, journalists or individuals dependent on state licences and benefits. The Serbian environment makes this risk operationally relevant. The UN High Commissioner for Human Rights stated in May 2025 that Serbia had experienced more than six months of mainly student-led protests demanding transparency and accountability. Serbia: Türk Touched by Resilience of People He Met, and Their Desire and Determination for Accountability and Justice – Office of the UN High Commissioner for Human Rights – May 2025verified official statement. In August 2025, UN experts reported allegations that peaceful demonstrators had faced intimidation, physical attacks and surveillance. Serbia Must Halt Crackdown on Student Movement, Uphold Human Rights and Academic Freedom – Office of the UN High Commissioner for Human Rights – August 2025verified official statement. These are official records of reported conduct, not judicial findings that Huawei equipment performed the surveillance. Attribution to a specific platform requires logs, configuration evidence or operational testimony that official sources presently do not provide.

Public Order Surveillance

Protest-Surveillance Escalation Path

Public Demonstration

Event Trigger
Initial public gathering or demonstration monitored by municipal surveillance infrastructure and deployed tactical units.

Fixed CCTV & Mobile Police Video

Multi-Source Feeds
Real-time optical collection combining fixed municipal camera infrastructure, body-worn cameras, and mobile police units.

Face & Body Extraction

Biometric Isolation
Automated computer vision algorithms isolate individual facial bounding boxes, body features, and gait characteristics from raw video frames.

No Identity Link

Anonymized
Extracted features do not match watchlist records or reference galleries.
Outcome: Aggregate Crowd Statistics

Identity Link Established

Identified
Biometric vectors return a positive candidate match in state database registers.
Outcome: Named Participant File

Cross-Camera Correlation

Spatial-Temporal Fusion
Algorithmic tracking correlates movement vectors across transit, public, and private camera networks by synthesizing multi-source data streams.
Transport Cameras
Named Participant
Historical Movement

Co-Presence Network Graphing

Social Link Analysis
Graph analytics map relational proximity, group structures, and repeated spatial co-locations between identified individuals across time.

Serious-Crime Inquiry

Lawful Track
Evidence processing strictly bounded by criminal procedure for formal offense investigation.
Outcome: Judicially Reviewable Investigative Action

Political Profiling

Coercive Track
Extralegal tracking utilized to target activist networks, dissenters, and political opposition.
Outcome: Deterrence, Pressure, Questioning, Retaliation

The biometric watchlist as the decisive control point

The watchlist or reference gallery is the decisive control point because it determines whom the platform can identify and for what purpose. A facial-recognition system does not search “the population” in the abstract; it compares probe templates against one or more galleries constructed from identity documents, police photographs, border records, missing-person files, judicial warrants, intelligence nominations or event-specific collections. A narrowly defined gallery containing persons sought for serious offences has a materially different political character from a population-scale identity gallery or a list assembled from protest images. Governance therefore requires four forms of traceability: the legal authority for enrolment, provenance of each reference image, duration of inclusion and the identity of the official who approved it. Without those controls, an authority can quietly convert administrative identity infrastructure into an intelligence resource. False-positive risk also increases with gallery size. Even when pairwise matching performance remains constant, a larger gallery creates more opportunities for a non-matching person to obtain a high similarity score. Operational safeguards must therefore include calibrated thresholds, candidate ranking, image-quality rejection, trained human adjudication and a prohibition against treating a machine match as sufficient grounds for coercive action. The EU AI Act imposes a particularly restrictive framework around real-time remote biometric identification in publicly accessible spaces for law enforcement, including necessity, proportionality and authorisation conditions for defined exceptions. It also recognises the technology’s capacity to generate constant-surveillance effects and deter the exercise of assembly rights. Regulation (EU) 2024/1689 – European Parliament and Council – July 2024verified official text. Serbia’s accession trajectory consequently creates an operational challenge, not merely a legislative one: authorities must be able to demonstrate which galleries exist, which systems can access them, whether dormant modules can be activated, how searches are logged and whether past biometric processing occurred. A statutory prohibition without technical inspection cannot establish compliance.

Watchlist typeLegitimate purposePolitical-abuse potentialRequired controlsCritical audit question
Judicial fugitive listLocate persons subject to valid warrantLow to mediumCurrent warrant, expiry and reviewWas every enrolment linked to an enforceable order?
Missing and vulnerable personsProtection and rescueMediumPurpose restriction and rapid deletionWere images reused for unrelated policing?
Serious-crime intelligenceIdentify high-risk suspectsMedium to highEvidentiary threshold and independent reviewWas intelligence nomination independently validated?
Border-security galleryVerify travellers and detect document fraudHighLegal separation from domestic policingCan urban cameras query border identities?
Population identity registerAdministrative identificationVery highTechnical isolation and exceptional accessHas the register become a general police gallery?
Event-specific listProtect a named event or locationVery highNarrow duration, threat evidence and deletionWas the event designation used to monitor dissent?
Protest-derived galleryReidentify demonstratorsExtremePresumptive prohibition absent serious-crime basisWere participants enrolled solely because they assembled?
Journalist or activist listIntelligence targetingExtremeStrict judicial basis and remedyDo query logs contain professional or civic categories?

From policing to intelligence access

The transition from policing to intelligence occurs when surveillance data are used not simply to investigate a defined offence but to discover relationships, intentions or future behaviour. A police video archive contains observations; an intelligence platform links those observations to identities, co-presence, recurring locations, vehicles, communications metadata and institutional affiliations. The analytical products may include association graphs, movement patterns, frequent-location profiles and ranked subjects of interest. This change can occur without visible alterations to street hardware because the critical modifications are server-side: a new API, reference gallery, graph database, search index or authorisation role can transform the mission of an existing camera network. Formal ownership is therefore an unreliable guide. A system administered by the police may provide query access to intelligence personnel; an intelligence-derived watchlist may be ingested into a police platform; or a municipal traffic system may export events to a national command centre. Sovereignty requires an access-control graph mapping each agency, role, service account and database privilege. It also requires immutable records of the initiating user, stated purpose, search parameters, returned candidates, subsequent access and operational outcome. The Parliamentary Assembly of the Council of Europe expressed concern in its 2026 periodic-review resolution about reported surveillance of Serbian journalists and activists and called for the practice to end and for effective investigations and accountability. The Progress of the Assembly’s Monitoring Procedure, Resolution 2635 – Parliamentary Assembly of the Council of Europe – June 2026verified official resolution. A related monitoring report recorded that the Assembly’s committee had examined revelations concerning surveillance of journalists and activists during 2025. The Progress of the Assembly’s Monitoring Procedure, Document 16316 – Parliamentary Assembly of the Council of Europe – June 2026verified official report. These institutional findings heighten the probability of a broader surveillance-governance problem, but they do not independently identify Chinese hardware, Safe City software or foreign access as the mechanism.

Access tierTypical actorPermissible functionEscalation riskRequired evidence trail
A₁ — Device operatorMunicipal or police technicianCamera health and positioningLowConfiguration changes and technician identity
A₂ — Video operatorCommand-centre staffLive view and incident replayMediumViewed feeds, timestamps and declared incident
A₃ — InvestigatorPolice case officerSearch and evidence exportHighCase number, legal basis and exported material
A₄ — Biometric analystSpecialist matching unitGallery search and adjudicationVery highProbe image, gallery, score and reviewer decision
A₅ — Intelligence analystSecurity or intelligence serviceAssociation and pattern analysisExtremeMission authority, selector and dissemination record
A₆ — System administratorMinistry, integrator or supplierFull platform controlExtremeRecorded session and command-level audit
A₇ — Emergency accountDesignated recovery actorBypass or restorationExtremeDual approval, time limit and post-use review
A₈ — External supportVendor or subcontractorDiagnostics and maintenanceExtremeNamed person, national escort and export prevention

The jurisprudential threshold: identification of protesters

The European Court of Human Rights provides the strongest primary legal benchmark for assessing biometric identification of demonstrators. In Glukhin v. Russia, the Court examined the use of facial-recognition technology to identify and locate a person associated with a peaceful solo demonstration. The Court emphasised the highly intrusive nature of facial recognition linked to public-space cameras and required a high level of justification for such interference to be considered necessary in a democratic society. Case of Glukhin v. Russia – European Court of Human Rights – July 2023verified official judgment. The Court’s updated data-protection case-law guide reiterates that live facial recognition used through CCTV to locate and arrest an individual connected with peaceful protest demands the highest level of justification. Guide on Article 8 of the European Convention on Human Rights: Data Protection – European Court of Human Rights – February 2026verified official guide. For Western Balkan governments subject to the European Convention, the implication is direct: technical capability cannot create its own lawful purpose. A police authority must demonstrate foreseeability of the legal basis, necessity, proportionality, safeguards against arbitrary use and effective remedies. Protest-related searches present an especially high burden because the same act—appearing in a public place—may represent constitutionally protected assembly rather than criminal conduct. Retrospective identification can be as politically consequential as live recognition: the absence of immediate intervention does not remove the chilling effect if participants can be identified days later. The relevant audit period must therefore extend beyond the protest itself and include later image searches, gallery enrolments, cross-camera queries and dissemination to employers, universities or administrative agencies. A compliant platform should technically prevent general-purpose protest searches unless a narrowly defined legal condition is recorded. It should reject queries lacking a valid case identifier, preserve the initiating selector and alert the independent supervisory authority when protected civic activity intersects with biometric processing.

Domestic abuse, supplier access and foreign leverage are separate hypotheses

Analytical integrity requires separating three propositions often collapsed into a single narrative. The first proposition is that domestic authorities may use surveillance technology against political opponents, journalists or protesters. The second is that the supplier or its personnel possess technical access enabling them to view, modify or extract information. The third is that the supplier or the Chinese state exploits that access or dependency to influence Balkan foreign policy. Evidence for the first does not prove the second; evidence for the second does not prove the third. Domestic political abuse can occur through a completely sovereign European platform. Conversely, a foreign technician may possess legitimate supervised maintenance access without viewing operational data. Geopolitical leverage requires an additional mechanism: threatened suspension of support, conditional financing, privileged intelligence access, coercive requests, vulnerability exploitation or credible ability to disrupt essential services. The public primary-source record examined here does not prove that China receives Serbian biometric data or has used Safe City infrastructure to compel a Serbian political decision. Huawei’s audited reporting states that the company assessed cybersecurity and privacy risks across more than 4,000 suppliers and held more than 890 security and privacy certifications as of its 2025 reporting. Huawei 2025 Annual Report – Huawei – March 2026verified audited corporate report. Those metrics document the company’s declared security-governance scale but do not establish the configuration or access controls of a particular Balkan police system. Equally, geopolitical concern cannot be dismissed solely through corporate-level assurance. The decisive evidence must be deployment-specific: administrator lists, remote-access routes, encryption-key ownership, update authority, incident records, data-export telemetry, support contracts and financing covenants. The correct intelligence judgement is therefore conditional: domestic political-use risk is substantiated as a governance concern; supplier-enabled access remains technically plausible but deployment-specific; executed Chinese geopolitical coercion remains unproven in the verified record.

PropositionCurrent judgementEvidence presently availableEvidence still requiredAnalytic confidence
Domestic authorities possess extensive surveillance capabilitySupportedSafe City ambition, public-space surveillance policy, regulatory reviewComplete deployed-function inventoryHigh
Facial-recognition processing occurred systematicallyUnresolvedCommission demanded verification and legal clarificationMatch logs, licence status and audit recordsLow
Serbian activists and journalists faced surveillanceOfficially reported as a concernUN and Council of Europe recordsCase-level attribution and technical mechanismMedium
Huawei retained privileged operational accessNot establishedComprehensive-solution and maintenance plausibilityAccount, VPN, session and contract evidenceLow
Serbian biometric data were transferred to ChinaNot establishedNo qualifying primary proof identifiedNetwork, export, cloud and forensic evidenceVery low
China used surveillance dependency for political coercionNot establishedGeneral dependency mechanism onlyConditional support, request or retaliation evidenceVery low
EU accession can constrain the systemStrongly supportedAI Act, Commission monitoring and accession leverageTechnical enforcement and funded implementationHigh

Chinese cyber norms and the asymmetry of cross-border assurance

Chinese domestic regulation is analytically relevant because it demonstrates that Beijing recognises facial data as sensitive and treats cross-border access as a legally significant event. China’s 2025 facial-recognition security rules require necessity, defined purposes and security safeguards; official explanations specify encryption, security auditing, access control, authorisation management, intrusion detection and defensive measures. They also require public-space facial-recognition installations to be necessary for public security and accompanied by visible notices. Measures for the Security Management of Facial Recognition Technology Applications – Cyberspace Administration of China and Ministry of Public Security – March 2025verified Chinese government text. Questions and Answers on the Measures for the Security Management of Facial Recognition Technology Applications – Cyberspace Administration of China – March 2025verified official explanation. China’s Data Security Law defines data processing broadly to include collection, storage, use, processing, transmission, provision and disclosure, and embeds data security within national sovereignty and security policy. Data Security Law of the People’s Republic of China – National Bureau of Statistics of China – March 2025 republication of the 2021 lawverified Chinese government text. These provisions do not prove that Chinese law

Architecture of the Transfer
Figure 1: Five-Year Sovereignty-Risk Projection
Analytical scenario scores, 0–100. Values are modeled estimates, not observed government statistics.

Sovereignty and Political Pressure: Biometrics, Protest Monitoring, Policing, Intelligence Access and Geopolitical Leverage

Sovereignty begins with control over purposes, not ownership of equipment

Digital sovereignty in an urban-surveillance environment is not established merely because cameras, servers and biometric databases are physically located inside national territory or formally owned by a ministry. It exists only when the state can independently determine and enforce the purposes for which information is collected, the persons who may access it, the algorithms applied to it, the duration of retention, the databases against which it is compared, the conditions under which it produces police action and the circumstances in which every function can be suspended or removed. This definition separates territorial control from functional control. A Balkan government may own the equipment but remain dependent on a foreign supplier for firmware, licences, maintenance credentials or model updates; conversely, it may possess technically autonomous infrastructure yet use it domestically without lawful necessity, independent supervision or effective remedies. The first condition is a foreign-dependence risk; the second is a democratic-governance risk. They can coexist, but evidence of one does not prove the other. The Serbian case illustrates the distinction. Huawei stated in 2019 that the Serbian Ministry of Interior wanted a Safe City covering Belgrade and eventually the entire country and that Huawei proposed a comprehensive solution. Huawei Enterprise 01/2019 – Huawei – January 2019verified corporate publication. The European Commission subsequently recorded that the Ministry suspended biometric-data processing after negative opinions concerning its street-surveillance impact assessment and that the proportionality and necessity of public-space surveillance and facial-recognition processing still required evaluation. Serbia 2023 Report – European Commission – November 2023verified official document. These sources demonstrate strategic ambition and regulatory conflict. They do not, standing alone, prove systematic protest identification, Chinese access to Serbian data or geopolitical coercion by Beijing.

Sovereignty dimensionGoverning questionSovereign conditionSovereignty-deficit condition
TerritorialWhere are data and compute resources located?All critical locations documentedUnknown replicas, backups or support endpoints
CryptographicWho controls keys and certificates?National authority can rotate and revoke themSupplier retains exclusive signing or recovery power
FunctionalWho enables or disables analytics?Nationally controlled, logged configurationSupplier licence or remote command controls function
InformationalWho can retrieve raw and derived data?Complete attribution and purpose limitationShared, foreign or unlogged privileged access
AlgorithmicWho validates models and thresholds?Independent testing and version approvalOpaque model changes or supplier-defined thresholds
LegalWhich law authorises each use?Specific purpose, necessity and proportionalityGeneric policing mandate or retrospective justification
InstitutionalWho investigates misuse?Independent regulator with technical accessSupervisory body lacks access, staff or enforcement power
OperationalCan the state continue without the supplier?Tested independent recovery and maintenanceDisconnection causes critical service failure
PoliticalCan surveillance be directed against lawful dissent?Judicially constrained and auditable useExecutive discretion with weak remedies
ExitCan components and data be migrated?Enforceable portability and funded transitionProprietary formats make replacement prohibitive

Biometrics converts public presence into persistent identity

Biometric surveillance changes the political meaning of public space because it converts visible presence into machine-searchable identity. Conventional video permits an investigator to review a scene; facial recognition can associate a person with a reference record, retrieve earlier appearances and generate a longitudinal movement history. The technical chain generally comprises face detection, landmark alignment, feature extraction, conversion into a biometric template, comparison with a reference gallery, similarity scoring, threshold application and operator adjudication. Each stage can create error or abuse. A false detection may crop the wrong face; low-quality imagery may generate an unstable template; a large gallery increases the absolute number of false candidates; an aggressively low threshold raises recall but also false positives; and an operator may defer to the apparent objectivity of the ranking. The political effect does not require perfect accuracy. A system that occasionally identifies demonstrators correctly, or merely creates a credible perception that it can, can impose a chilling effect on assembly, association and anonymous participation. The European Court of Human Rights established in Glukhin v. Russia that using facial recognition to identify and locate a peaceful protest participant constituted a highly intrusive interference requiring a correspondingly high level of justification. Case of Glukhin v. Russia – European Court of Human Rights – July 2023verified official judgment. The Court’s updated data-protection guide emphasises the especially intrusive character of live facial recognition in public CCTV environments and the high justification threshold required under the European Convention. Guide on Article 8 of the European Convention on Human Rights: Data Protection – European Court of Human Rights – February 2026verified official guide. Although the judgment concerns Russia rather than Serbia, its legal reasoning is directly relevant to all Council of Europe systems assessing biometric identification of peaceful demonstrators.

Biometric modeTechnical operationSurveillance reachPrimary political riskEssential control
One-to-one verificationCompares person with claimed identitySpecific transactionCompelled biometric authenticationAlternative non-biometric method
One-to-many identificationSearches probe against reference galleryEveryone captured may be queriedAnonymous presence becomes attributableNarrow gallery and judicially defined purpose
Live identificationProcesses streams with minimal delayContinuous public-space populationImmediate intervention against assemblyExceptional authorisation and strict geofencing
Retrospective identificationSearches stored video after an eventHistorical reconstructionLater identification of protest participantsCase-specific warrant and query logging
Person re-identificationTracks appearance across camerasCross-camera movement without a namePersistent tracking before identity is knownShort retention and constrained cross-camera search
Attribute classificationEstimates appearance or behaviourPopulation sortingDiscriminatory profilingBan sensitive-attribute inference
Relationship inferenceCorrelates co-presence and repeated contactSocial-network reconstructionAssociation treated as suspicionEvidentiary threshold and independent review
Emotion or intention inferenceAttempts to infer internal stateHighly speculative population assessmentProtest behaviour pathologised as threatProhibition or non-operational research separation
Watchlist alertingCompares observations with target listContinuous target detectionSecret list with weak challenge rightsProvenance, expiry and appeal mechanism
Template retentionStores derived biometric vectorPotentially indefinite future reuseFunction creep after raw video deletionPurpose-specific deletion and cryptographic erasure

Protest monitoring is a sequence of escalating functions

Protest monitoring should not be treated as a binary question of whether police “used facial recognition.” Authorities can exercise political pressure through a graduated chain beginning before any demonstration and continuing long after it. Before an event, intelligence units may combine permit information, publicly available organising material, prior police files and location data to identify organisers or forecast attendance. During the event, cameras may estimate crowd density, detect banners, follow vehicles, track individuals between camera zones or record interactions around entrances and transport hubs. After the event, retrospective analytics can identify participants, reconstruct movement, infer associations and connect individuals to administrative, employment or criminal-investigation records. The coercive result can arise without arrest: questioning, repeated identity checks, warnings to employers or universities, selective tax scrutiny, travel friction, reputational leaks and inclusion in security databases may collectively deter participation. In Serbia, the UN Special Rapporteur on education and other mandate holders reported allegations of intimidation, surveillance and pressure affecting student-led mobilisation. These remain allegations requiring investigation, not judicial findings. Serbia Must Halt Crackdown on Student Movement, Uphold Human Rights and Academic Freedom – Office of the UN High Commissioner for Human Rights – August 2025verified official statement. The Parliamentary Assembly of the Council of Europe later expressed concern about revelations involving surveillance of Serbian journalists and activists and urged effective investigations and accountability. Progress of the Assembly’s Monitoring Procedure, Resolution 2635 – Parliamentary Assembly of the Council of Europe – June 2026verified official resolution. Neither source attributes those alleged practices specifically to Huawei’s Safe City platform. A disciplined assessment must therefore maintain separate confidence levels for the existence of political pressure, the technical mechanism used and the role of any foreign-origin system.

State Control Architecture

Political-Surveillance Escalation Chain

Stage P₁

Pre-Event Intelligence

Permit Data Organiser Files Online-Event Records Anticipated Attendance
Stage P₂

Spatial Collection

Street Cameras Transport Cameras Mobile Police Video Private CCTV Feeds
Stage P₃

Machine Enrichment

Face Detection Person Re-Identification Plate Recognition Co-Presence Mapping
Stage P₄

Identity Resolution

Probe Image Biometric Gallery Candidate Score Operator Confirmation
Stage P₅

Network Reconstruction

Shared Location Repeated Contact Vehicle Linkage Organisational Association
Stage P₆

Administrative Fusion

Police File University Record Employer Information Border & Travel Events
Stage P₇

Intervention & Coercion

Warning Questioning Detention Investigation Reputational / Economic Pressure
Stage P₈

Deterrence Feedback Loop

Public Awareness of Surveillance Perceived Identification Certainty Reduced Democratic Participation

Policing value and democratic risk must be measured separately

Urban-surveillance systems can provide legitimate policing value, including locating missing persons, reconstructing serious offences, managing traffic incidents, protecting critical sites and improving emergency response. That value cannot be assumed from vendor claims or arrest totals; it must be measured through attributable outcomes, counterfactual comparison and error costs. A platform that generates thousands of alerts but contributes little unique evidence may create administrative burden while normalising mass collection. Conversely, a tightly governed retrospective search used for a narrowly defined violent offence may produce significant value with a smaller intrusion than continuous live identification. The analytical framework should therefore separate effectiveness E from rights intrusion I and political-abuse potential P. A use case is not justified merely because E exceeds zero; it must satisfy legality, necessity and proportionality, and less intrusive alternatives must be insufficient. The EU AI Act’s treatment of real-time remote biometric identification for law enforcement reflects precisely this structure. It limits such use in publicly accessible spaces to narrowly framed circumstances and requires safeguards including authorisation and consideration of the consequences for rights and freedoms. Regulation (EU) 2024/1689 – European Parliament and Council – July 2024verified official text. Serbia’s 2024 Commission assessment stated that it still had to be verified whether personal data had been processed with facial-recognition software and connected that issue to emerging EU prohibitions and safeguards. Serbia Report 2024 – European Commission – October 2024verified official document. The evidentiary phrase “has to be verified” is strategically important: uncertainty concerning use is itself a governance weakness when the state possesses infrastructure capable of intrusive processing.

Police use casePotential public valueIntrusion levelMisuse pathwayMinimum evidentiary threshold
Missing vulnerable personImmediate protection of lifeMedium–highGallery retained after incidentDocumented urgency and automatic expiry
Imminent terrorism threatPrevention of mass casualty eventVery highThreat definition expanded politicallySpecific intelligence and judicial authorisation
Serious violent offenceIdentification of suspectHighBroad retrospective search of bystandersDefined offence and temporal-spatial boundary
Routine property crimeInvestigative efficiencyMedium–highNormalisation of population-wide searchDemonstrated necessity beyond ordinary methods
Traffic enforcementRoad safety and evidenceMediumPlate data converted into movement profilesStrict purpose separation and short retention
Crowd safetyDensity and emergency managementLow if anonymousAnonymous analytics converted into identificationTechnical prohibition on identity linkage
Protest violenceIdentification of specific offenderHighEntire assembly treated as suspect populationIndividualised evidentiary basis
Peaceful protest attendanceMinimal legitimate valueExtreme political impactNetwork mapping and deterrencePresumptive prohibition
Border identity checkIdentity and document integrityMediumCross-purpose domestic trackingClear border mandate and database separation
Intelligence watchlistingNational-security detectionExtremeSecret criteria and weak challenge rightsIndependent authorisation, review and expiry

Intelligence access is a graph of permissions, not a single backdoor

The question of intelligence access must be framed more precisely than the politically charged question of whether “China can see the cameras.” Access can occur through several distinct mechanisms: direct remote administrator access; supplier diagnostics; software-update infrastructure; cloud dashboards; licence-validation traffic; domestic-system integrators; compromised credentials; supply-chain vulnerabilities; lawful government requests in the supplier’s home jurisdiction; covert intelligence operations; or data voluntarily exported by the purchasing government. These mechanisms have different probabilities, evidence signatures and attribution requirements. A remote-support account does not prove that data were extracted; an external network connection does not prove Chinese government control; Chinese national law does not prove that every overseas deployment is technically accessible from China; and a vendor’s general cybersecurity assurance does not prove the absence of system-specific vulnerabilities. Huawei’s audited 2025 reporting states that the company assessed cyber and privacy risks among more than 4,000 suppliers and held more than 890 security and privacy certifications. Huawei 2025 Annual Report – Huawei – March 2026verified audited corporate report. These are relevant corporate-governance indicators but cannot replace deployment-level examination of Serbian or Balkan access logs, firmware, administrative accounts and data routes. China’s Data Security Law regulates data processing and contains provisions concerning official data requests and the handling of foreign judicial or law-enforcement demands for data stored in China. Data Security Law of the People’s Republic of China – National Bureau of Statistics of China – March 2025 publication of enacted lawverified Chinese government text. Its relevance must be bounded: it establishes a Chinese legal environment for data and official authority, but it does not establish that Balkan police data are stored in China or accessible to a Chinese supplier.

Access pathwayActorRequired preconditionObservable artefactAttribution confidence if found
Local operator queryPolice or intelligence officerValid or abused domestic credentialsQuery and case logsHigh for domestic action
Local privileged administrationMinistry or integrator engineerAdministrator roleConfiguration and session logsHigh if identities are individualised
Supplier remote supportVendor technicianVPN, agent or support gatewaySession source, commands, ticket recordHigh for access; extraction still separate
Cloud managementSupplier or customer cloud administratorActive cloud tenancyAPI calls, cloud audit recordsHigh if logs are complete
Update-channel compromiseSupplier, attacker or intelligence serviceTrusted update mechanismPackage hash, signing chain, changed binaryMedium until actor is independently attributed
Shared credentialsUnknown insiders or former staffNon-individual administrator accountConcurrent or anomalous loginsLow attribution, high control failure
Domestic intelligence fusionNational security serviceLegal or informal database accessCross-system query patternHigh if authorisation records exist
Supplier-home-state legal requestForeign authorityData or control reachable in jurisdictionLegal demand and disclosure recordHigh only with documentary evidence
Covert exfiltrationForeign intelligence or criminal actorVulnerability or implanted capabilityUnauthorised traffic and forensic artefactsVariable; technical origin is not state attribution
Government-to-government sharingBalkan and foreign authoritiesFormal or informal cooperationTransfer record and recipient logsHigh when documented

The access-control model must assume multiple adversaries

A credible security model cannot treat the Chinese supplier as the only potential adversary. The same architecture may be exploited by a domestic ruling party, corrupt police official, organised-crime network, commercial intelligence actor, foreign service, hostile cyber group or contractor seeking financial leverage. Each actor prefers different access. Domestic political actors may use legitimate credentials and lawful-looking queries, leaving no malware. Criminal groups may seek live locations, evidence deletion or identity records. Foreign intelligence services may target remote-management infrastructure, maintenance laptops or software-update chains. A supplier does not need to cooperate for its products to become the attack surface through which another actor enters. This multi-adversary model changes mitigation priorities: excluding a particular vendor cannot compensate for shared administrator accounts, weak logging or unconstrained police queries. At the same time, robust domestic access controls do not eliminate supplier-dependence risk if firmware, recovery keys or licences remain externally controlled. The correct design applies zero trust principles to both local and foreign actors: every account must be individually identified; every privileged session explicitly authorised; every query attached to a lawful case purpose; every data export recorded; every software update verified; and every sensitive action subject to separation of duties. The access graph should be continuously reconstructed from identity providers, VPN concentrators, application logs, database audit records, endpoint telemetry and physical-access systems. Unexplained privileges must be treated as incidents, not administrative anomalies. The investigation must also search for negative-space evidence: periods in which logging was disabled, clock synchronisation failed, accounts were created and removed quickly, or support activity occurred without a ticket. The most serious sovereignty failure is not necessarily a discovered foreign connection. It may be the inability to determine retrospectively whether such a connection existed because the system was never designed to produce trustworthy evidence.

Threat actorPrimary objectivePreferred accessLikely observable behaviourMost effective control
Domestic political executiveMonitor opposition and protestLawful-looking operator queriesSearches around demonstrations or organisersIndependent query audit and judicial approval
Police insiderPersonal, criminal or political misuseExisting credentialsOff-case queries and selective exportsIndividual attribution and behavioural analytics
Domestic integratorPreserve commercial controlAdministrator and maintenance accountsUndocumented configuration changesSegregated access and source-session recording
Foreign supplier technicianMaintenance or potential intelligence accessRemote privileged sessionDiagnostic collection and system commandsJust-in-time nationally approved access
Foreign intelligence serviceStrategic collection or disruptionSupply chain, vulnerability or credentialsCovert persistence and staged extractionNetwork segmentation and independent forensics
Organised crimeTrack targets and neutralise evidenceBribed insider or stolen accountVictim-specific searches and deletion attemptsDual control and tamper-evident logs
Cybercriminal groupExtortion or data saleInternet-exposed serviceBulk encryption, export or credential attacksIsolation, patching and resilient backup
Political proxy or contractorPlausibly deniable targetingTemporary or shared accountsShort-lived burst around sensitive eventProhibition of shared accounts and rapid review
Data brokerCommercial exploitationExported archives or metadataRepeated bulk extractsExport controls and watermarking
Future successor governmentRetrospective political targetingHistorical archive and templatesSearches of past assemblies and networksEnforced deletion and purpose-bound cryptography

Geopolitical leverage operates through dependence before coercion

Geopolitical leverage does not require a confirmed stream of biometric data flowing to Beijing. It can emerge from asymmetric dependence: one party controls a resource, capability or timetable that the other cannot replace without substantial cost. In a surveillance system, that resource may be security patches, firmware-signing authority, analytics licences, specialist engineering, storage formats, device certificates, technical documentation, credit arrangements or compatibility with other infrastructure. The leverage remains latent until a political dispute makes continuity valuable. A government that believes exclusion of the supplier would impair policing, require large capital expenditure or reveal earlier procurement failures may moderate its diplomatic behaviour even if the supplier never issues an explicit threat. This is anticipatory compliance, a form of structural influence that is difficult to observe because it operates through expected cost rather than documented coercion. However, dependence alone cannot be described as Chinese geopolitical pressure. H₂, commercial lock-in, must remain analytically distinct from H₄, deliberate exploitation of dependence. Evidence for H₄ would require an identifiable linkage between a political demand and a threatened or executed change in support, finance, access, disclosure or operational capability. Without that linkage, the strongest defensible conclusion is that the architecture creates potential leverage. The European Commission’s 2026 ICT Supply Chain Security Toolbox recommends supplier assessment, multi-vendor strategies and measures to overcome high-risk dependencies precisely because supply-chain concentration can produce strategic exposure before any malicious act occurs. ICT Supply Chain Security: EU Adopts a Toolbox to Mitigate Risks – European Commission – February 2026verified official publication. For the Balkans, the accession process creates a competing leverage structure: China may benefit from installed-system dependence, while the EU controls regulatory alignment, market access and accession incentives.

Strategic Dependency & Control

Geopolitical Leverage Mechanism

Technical Concentration

Vendor Lock-In
Creation of deep technological dependencies through proprietary standards, restricted maintenance access, and isolated data architectures.
Proprietary Firmware Exclusive Licences Supplier-Only Maintenance Non-Portability Undocumented Integration

High Replacement Cost & Migration Delay

Switching Friction
Extremely prohibitive financial costs and multi-year implementation timelines required to rip-and-replace core technical infrastructure.

Government Expectation of Operational Disruption

Policy Anticipation
State decision-makers anticipate severe service outages or security gaps during replacement, shaping executive risk tolerance.
Avoids Supplier Exclusion Delays EU-Alignment Measures Seeks Exemptions / Transitions Preserves Political Relationship

Potential Structural Influence

Leverage Realization
The external power or vendor achieves implicit policy leverage over state regulatory, security, and diplomatic decisions.
Evidence Threshold for Actual Coercion
Political Demand + Supplier / State Action + Operational / Financial Consequence

China’s domestic biometric rules create a revealing normative contrast

Chinese official sources demonstrate that Beijing itself recognises facial information as highly sensitive and requires security, necessity and purpose controls in domestic non-exempt applications. China’s facial-recognition management measures, effective from June 2025, require that public-space facial-recognition installations be necessary for public security, that collection areas be reasonably determined, that prominent notices be displayed and that systems employ encryption, security auditing, access control, authorisation management and intrusion detection. Measures for the Security Management of Facial Recognition Technology Applications – Ministry of Justice of the People’s Republic of China – March 2025verified Chinese government text. The Cyberspace Administration’s official explanation additionally emphasises legality, necessity, minimisation and separate consent where consent forms the legal basis. Expert Interpretation: Regulating Facial Recognition Applications and Protecting Facial Information – Cyberspace Administration of China – March 2025verified Chinese government publication. These provisions should not be misread as demonstrating that China and the EU apply equivalent limits to public-security surveillance; their institutional structures, exemptions, judicial environments and enforcement systems differ. Their analytical value lies elsewhere: they establish that security auditing, access control, necessity and visible notice are not alien or technically impractical requirements for Chinese-origin technology. Balkan purchasers should therefore be able to demand at least equivalent technical documentation and protection from Chinese suppliers. A supplier cannot credibly argue that logging, encryption or access governance are incompatible with its product ecosystem when Chinese domestic rules explicitly require such safeguards. The geopolitical inquiry should also test whether exported configurations offer less transparency or weaker privacy-by-design than domestic Chinese deployments. Such a divergence would not prove malign intent, but it would reveal regulatory arbitrage in which governance weakness in recipient states becomes a competitive advantage.

Control domainChinese 2025 facial-recognition measureEU AI Act directionBalkan audit implication
NecessityPublic-space installation must be necessary for public securityLaw-enforcement biometric use limited by necessity and specified groundsGeneric “security” justification is insufficient
NoticeProminent signage required in public spacesTransparency and information duties vary by usePhysical and digital notice should be verified
Data minimisationMinimum necessary processing emphasisedData governance and purpose limitation requiredCollecting every available attribute should be prohibited
SecurityEncryption, access control and intrusion defence requiredHigh-risk systems require technical and governance controlsSupplier must expose security configuration for audit
AuditabilitySecurity auditing requiredLogging and traceability central to high-risk complianceImmutable logs must cover queries and administration
ConsentSeparate consent where consent is the legal basisPolice use cannot be legitimised by fictional public-space consentLegal basis must be explicit and non-circular
AlternativesNon-facial methods preferred where equivalentLess intrusive means inform necessity analysisFacial recognition cannot be default convenience
Public securityCreates an important exception contextNarrow exceptions and authorisation conditionsScope of “public security” must be independently constrained
System registrationFiling obligations apply at specified processing scaleRegistration duties apply to high-risk systemsCandidate states need authoritative system inventories
Data exportSeparate Chinese data-export rules may applyEU transfers require legal safeguardsBalkan systems must document every foreign-access route

Political-pressure indicators must be event-linked

The strongest OSINT method for determining whether surveillance supports political pressure is event-linked temporal analysis. Investigators should construct a timeline around protests, elections, strikes, environmental campaigns and opposition events, then compare system activity with normal baselines. Relevant indicators include sudden creation of watchlists, increased biometric-gallery enrolment, expanded camera retention, deployment of mobile command units, spikes in retrospective queries, new cross-agency API calls, emergency maintenance, temporary administrator accounts or exports concentrated around protest locations. Each indicator is ambiguous alone. Increased video retention may support a legitimate investigation into violence; a new watchlist may concern a specific security threat; maintenance may coincide accidentally with an event. Confidence rises when multiple independent indicators converge and when the resulting police or administrative actions disproportionately affect peaceful participants. Investigators must also control for alternative explanations through an Analysis of Competing Hypotheses. H₁ holds that activity reflects ordinary event security; H₂ that authorities collect broadly because of institutional habit rather than political direction; H₃ that surveillance is intentionally used to identify and deter lawful dissent; H₄ that a supplier or foreign actor exploits the event to obtain intelligence; H₅ that public allegations overstate technical capability and rely on the visibility of Chinese hardware rather than operational evidence. The Parliamentary Assembly’s 2026 resolution expressing concern about surveillance of Serbian journalists and activists increases the prior probability of H₃ at the ecosystem level, but does not resolve the mechanism or supplier. Progress of the Assembly’s Monitoring Procedure, Resolution 2635 – Parliamentary Assembly of the Council of Europe – June 2026verified official resolution. System logs, case files and access records remain the decisive evidence.

IndicatorBaseline expectationPolitically sensitive deviationAlternative explanationConfidence multiplier
Watchlist sizeStable, case-driven enrolmentRapid expansion before protestSerious-threat intelligence2 if targets are peaceful organisers
Query volumeProportional to ordinary casesLarge spike around assemblyViolence investigation2 if queries precede violence
Retention periodFixed published scheduleTemporary extension for event areasEvidence preservation1.5 if no documented case basis
Camera configurationStable fields of viewReorientation toward meeting pointsCrowd-safety planning2 if identity analytics also activated
Cross-agency requestsCase-specific exchangeBulk requests for student or activist dataEmergency coordination3 if unrelated administrative datasets are used
Remote supportScheduled maintenanceUnplanned session during political eventGenuine system fault2 if commands touch analytics or exports
Gallery enrolmentAuthorised wanted personsSocial-media or event photographs addedMissing-person search4 with documentary proof
Operator accountsStable named personnelTemporary or shared accounts createdStaffing surge2 if logs later disappear
Police interventionIndividualised reasonable suspicionQuestioning based on attendance or associationPublic-order management4 if biometric output is cited
Public deterrenceNormal political participationParticipants report credible identification fearGeneral political climate1.5 unless technical mechanism is confirmed

Bayesian update and five-year pressure scenarios

The revised Bayesian model should distinguish domestic political exploitation from foreign geopolitical leverage. For the period beginning in 2026, the proposed priors are H₁, predominantly legitimate policing, 24%; H₂, bureaucratic overcollection and commercial dependence without coordinated repression, 28%; H₃, deliberate domestic political monitoring, 25%; H₄, exploitable foreign geopolitical leverage, 13%; and H₅, effective EU-driven constraint, 10%. These are analytical judgements rather than empirical frequencies. The official concerns about surveillance of Serbian journalists and activists increase H₃ relative to a technology-only baseline. The lack of verified evidence tying those concerns specifically to a Chinese Safe City platform limits the update. Huawei’s documented comprehensive proposal and the difficulty of verifying actual biometric processing increase H₂ because opacity and integration produce lock-in even without abuse. H₄ remains lower because potential access and dependence are not evidence of executed foreign coercion. H₅ begins low but rises across the five-year horizon as AI Act alignment, accession benchmarks and ICT supply-chain policy become operational. In a Monte Carlo model with 100,000 conceptual paths, the principal variables are biometric integration B, protest pressure P, domestic oversight O, foreign-access opacity F, supplier substitutability S and EU conditionality E. The adverse scenario—high domestic political monitoring combined with unresolved foreign dependence—becomes most likely when B and P exceed 70, O remains below 40, F exceeds 65 and S remains below 35. The stabilised hybrid scenario remains the baseline because governments can restrict live identification while preserving retrospective capabilities and legacy infrastructure. A rights-protective transition requires not merely new legislation, but verified deletion of unlawful galleries, judicial control of queries, independent inspection of source and destination logs, and demonstrated supplier substitutability.

Hypothesis2026 prior2031 central estimateMain upward indicatorMain downward indicator
H₁ — Predominantly legitimate policing24%17%Narrow case use and measurable public-safety outcomesProtest-linked bulk queries
H₂ — Bureaucratic overcollection and lock-in28%29%Persistent opacity and proprietary integrationSuccessful independent migration
H₃ — Domestic political monitoring25%22%Event-linked identification and administrative retaliationJudicial control and transparent query audits
H₄ — Foreign geopolitical leverage13%12%Political conditionality tied to support or accessNational keys, audited sessions and multi-vendor operation
H₅ — EU-driven constraint10%20%Accession benchmarks tied to deployed technical functionsFormal legal alignment without system inspection

Outlook 2026–2031: the decisive contest will concern latent capability

Between 2026 and 2031, the central sovereignty contest will move from visible camera acquisition to control over latent software functions and cross-database access. During 2026–2027, political debate is likely to focus on whether facial recognition is formally active; this framing is too narrow because retrospective search, person re-identification, plate correlation and network analysis can create substantial political intelligence without continuous live matching. During 2027–2028, governments will face pressure to inventory high-risk AI systems and establish data-protection impact assessments, but authorities may define systems by declared purpose rather than actual capability. During 2028–2029, the decisive issue will become database separation: whether police video platforms can query identity, border, vehicle and telecommunications records through unified interfaces. During 2029–2030, political crises or election disputes may provide the operational test of whether safeguards survive executive pressure. During 2030–2031, EU accession progress should increasingly depend on technical demonstrations rather than statutory promises: candidate governments should prove that prohibited functions are removed, remote access is controlled, watchlists have lawful provenance and independent regulators can inspect complete logs. The most likely outcome is a hybrid surveillance regime: live biometric identification restricted or publicly denied, retrospective and metadata-based capabilities retained, Chinese-origin components preserved where replacement is costly, and European controls applied unevenly. The worst outcome is not necessarily Chinese remote command of Balkan police systems. It is a layered sovereignty deficit in which domestic authorities can use intrusive analytics without effective oversight, cannot independently verify foreign access and cannot replace the supplier without unacceptable disruption. The mitigation architecture must therefore address rights, cybersecurity and geopolitics simultaneously. Any policy that treats only one dimension will leave the other two available for exploitation.

YearPrincipal contestTechnical indicatorPolitical indicatorDecision threshold
2026Inventory and legal classificationComplete module, model and database registerRegulator receives unrestricted inspection accessUnknown function count approaches zero
2027Watchlist governanceProvenance and expiry attached to every identityJudicial or independent authorisation becomes mandatoryNo orphan or politically sourced entries
2028Database separationPurpose-bound API gateways and query limitsCross-agency requests independently reviewedBulk identity access becomes impossible
2029Supplier-access controlNational keys and recorded just-in-time sessionsForeign support cannot bypass domestic approvalEvery privileged action attributable
2030Crisis resilienceSafeguards remain active during protest or emergencyNo exceptional mass identification without lawful thresholdEmergency powers automatically expire
2031Sovereignty and exitVendor-independent restore and migration testPublic report certifies compliance and residual riskSystem can operate without supplier dependency

Required strategic controls

The necessary control regime should be designed around the principle that an intrusive capability must be technically impossible to use outside authorised conditions, rather than merely prohibited by policy. Capture networks should be separated from biometric galleries; live identification should require cryptographic activation tokens issued for a defined location and time; retrospective searches should require a case identifier and independent approval; watchlist entries should carry source, legal basis, confidence, reviewer and expiry metadata; and query results should be watermarked to the operator. Privileged support sessions should be nationally initiated, recorded and automatically terminated, while supplier personnel should never have standing access to raw video or identity databases. Logs must be replicated into a regulator-controlled environment so that the operator cannot erase evidence of misuse. Public-space analytics that support crowd safety should run in an irreversible anonymous mode whenever identity is unnecessary. Data retention should be enforced through cryptographic key destruction rather than discretionary operator deletion. Procurement contracts should require algorithm documentation, threshold transparency, test datasets appropriate to Balkan populations, vulnerability disclosure, software-component inventories, portability and assisted exit. Political safeguards must include notification after surveillance where operationally possible, accessible remedies for false identification, meaningful sanctions for off-purpose searches and protection for technical whistleblowers. The European Commission should condition digital-security assistance on measurable controls rather than equipment acquisition. Domestic parliaments should receive aggregate statistics on biometric searches, rejected alerts, false positives, protest-related requests, emergency authorisations and supplier support sessions. These controls will not eliminate political pressure, but they can convert covert discretion into observable events and raise the cost of abuse. Sovereignty becomes credible when neither the government, the supplier nor a foreign service can exercise hidden unilateral control.

Sovereignty and Political Pressure
Figure 1: Balkan Surveillance Pressure Outlook, 2026–2031
Structured analytical scores from 0 to 100. Projections are disclosed scenario estimates, not official observed statistics.

Five-Year Outlook: Competing Hypotheses, Bayesian Indicators, Monte Carlo Scenarios and Early-Warning Thresholds

Forecasting object, baseline and confidence discipline

The five-year forecast covers August 2026–July 2031 and estimates how Chinese-origin surveillance infrastructure in the Western Balkans may evolve across five interacting dimensions: technical expansion, domestic political use, foreign-access exposure, supplier dependence and European regulatory constraint. The model does not estimate whether “China controls Balkan surveillance,” because that proposition collapses several distinguishable outcomes into a single politically charged claim. It instead forecasts observable states: whether biometric functions become active; whether video platforms connect to authoritative identity databases; whether police queries concentrate around protests or political targets; whether suppliers or integrators retain privileged access; whether governments can migrate away from proprietary platforms; and whether EU accession pressure produces technically verifiable restrictions. The evidentiary baseline is asymmetric. Huawei publicly described a comprehensive Safe City solution proposed for Serbia’s Ministry of Interior, with an intended scope beginning in Belgrade and potentially extending nationally. Huawei Enterprise 01/2019 – Huawei – January 2019verified corporate publication. The European Commission later recorded that biometric processing had been put on hold pending an adequate legal basis and that the necessity and proportionality of public-space facial recognition remained to be assessed. Serbia 2023 Report – European Commission – November 2023verified official document. The 2025 Commission assessment further identified incomplete alignment and implementation weaknesses in Serbian data protection. Serbia Report 2025 – European Commission – November 2025verified official document. This evidence establishes capability ambition, regulatory uncertainty and institutional weakness, but not continuous biometric operation, Chinese extraction of police data or executed geopolitical coercion. All probability estimates below are consequently structured analytical judgements, not measurements reported by governments.

Forecast dimensionObserved baseline, August 2026Critical uncertainty2031 forecast question
Hardware footprintChinese-origin Safe City ambition documented in SerbiaComplete deployed inventory unavailable in admissible primary evidenceDoes deployment expand, stabilise or undergo replacement?
Biometric capabilityFacial-recognition processing subject to unresolved legal and verification questionsDormant, licensed, enabled and operational functions are not equivalentWhich functions remain technically available and legally usable?
Database integrationPotential value depends on identity and police-system connectionsExact interfaces and query permissions are not publicly verifiedAre galleries and cross-agency APIs segmented or consolidated?
Domestic political useOfficial international bodies raised surveillance concerns involving journalists and activistsSpecific technical mechanism remains unresolvedDo protest-linked queries become demonstrable and systematic?
Foreign accessSupplier dependence creates potential access pathwaysNo qualifying evidence proves routine Chinese access to Balkan biometric dataAre all support and update pathways nationally controlled?
Supplier dependenceComprehensive platforms create migration and lifecycle dependenciesExit cost, licence structure and documentation remain uncertainCan states operate and migrate without original suppliers?
EU conditionalityAI, cybersecurity and accession requirements are strengtheningImplementation may remain formal rather than technicalDoes accession produce audited operational compliance?
Regional diffusionOther Western Balkan states show differing regulatory and cybersecurity weaknessesChinese platform penetration is not uniformly documentedDoes the Serbian model diffuse or remain an exceptional concentration?

Analysis of Competing Hypotheses

The forecast retains six competing hypotheses because a five-hypothesis structure would inadequately separate domestic political exploitation from foreign leverage and genuine European convergence. H₁, bounded public-safety modernisation, holds that governments retain surveillance systems primarily for serious-crime investigation, traffic management and emergency response while intrusive functions remain legally restricted. H₂, commercial and technical lock-in, holds that cumulative procurement, proprietary interfaces and maintenance dependence become the principal strategic consequence even without political misuse or foreign direction. H₃, domestic political-control adaptation, holds that national authorities progressively exploit retrospective facial recognition, person re-identification, plate correlation and cross-database queries to map protests, journalists, activists or opposition networks. H₄, Chinese geopolitical leverage, holds that supplier dependence, support, financing or privileged access is deliberately used to influence diplomatic or regulatory decisions. H₅, EU-constrained hybridisation, holds that candidate governments retain legacy hardware while separating databases, restricting live identification and adding European controls without completing wholesale replacement. H₆, accelerated sovereign migration, holds that systems are technically decomposed or replaced through open standards, national key ownership, multi-vendor operation and independent audit. Initial priors are H₁ 16%, H₂ 24%, H₃ 20%, H₄ 9%, H₅ 25% and H₆ 6%. H₅ receives the largest prior because hybrid outcomes reconcile installed-system inertia with strengthening European constraints. H₂ remains high because lock-in follows from platform economics without requiring deliberate coercion. H₄ remains comparatively low because no admissible primary evidence presently establishes that China has used surveillance-system dependence to coerce a Western Balkan government. The EU’s ICT Supply Chain Security Toolbox explicitly recommends critical-supplier assessment, multi-vendor strategies and mitigation of high-risk dependencies, strengthening the plausibility of H₅ and H₆ over the forecast horizon. Toolbox to Improve ICT Supply Chain Security – European Commission – February 2026verified official publication.

HypothesisDescription2026 priorStrongest confirming indicatorStrongest disconfirming indicator
H₁Bounded public-safety modernisation16%Case-specific use, narrow galleries, measurable serious-crime outcomesProtest-linked bulk queries or persistent tracking
H₂Commercial and technical lock-in24%Proprietary archive, supplier-only recovery, recurring licence controlIndependently completed migration and multi-vendor maintenance
H₃Domestic political-control adaptation20%Event-linked identification followed by police or administrative pressureImmutable audits showing no political-purpose queries
H₄Chinese geopolitical leverage9%Political demand linked to support, finance, access or disclosure consequenceNationally controlled keys, offline licences and audited support
H₅EU-constrained hybridisation25%Legacy equipment retained but functions segmented and independently auditedUnrestricted integration or complete sovereign replacement
H₆Accelerated sovereign migration6%Open interfaces, national recovery and supplier-independent operationUnfunded plans, proprietary dependencies and delayed procurement

Bayesian update framework

Bayesian updating converts new evidence into probability changes through likelihood ratios rather than intuitive narrative escalation. For each indicator Iₙ and hypothesis Hₖ, the posterior odds equal the prior odds multiplied by the likelihood ratio associated with observing Iₙ if Hₖ is true relative to observing it if Hₖ is false. The model uses five evidentiary strength bands: LR 1.0–1.3 for weakly diagnostic evidence, 1.3–2.0 for limited evidence, 2.0–4.0 for moderately diagnostic evidence, 4.0–8.0 for strong evidence and above 8.0 only for highly specific, independently corroborated evidence. Negative evidence uses reciprocal ratios. The framework prevents a common OSINT error: repeatedly counting correlated reports as independent confirmation. For example, several official statements citing the same underlying allegation of activist surveillance constitute one evidentiary family, not several independent updates. Similarly, the discovery of Huawei cameras, Huawei servers and Huawei maintenance contracts may all derive from a single procurement decision and must be discounted for dependency. Evidence quality receives four modifiers: source authority Q, directness D, technical specificity T and independence N. A direct regulator audit containing system logs scores more highly than a general political statement; a corporate statement proves what the company claims or offers, but not necessarily what a customer deployed; a government denial has evidentiary value regarding official position but limited value concerning concealed activity unless supported by audit. The European Court of Human Rights’ determination that public-space facial recognition used to locate a protest participant requires exceptionally strong justification establishes a legal discriminator but does not provide evidence about Balkan deployment. Case of Glukhin v. Russia – European Court of Human Rights – July 2023verified official judgment. Forecast updates must therefore classify each observation as architectural, operational, political, legal or attributional before assigning likelihood.

Indicator codeObservable indicatorPrimary hypothesis favouredIllustrative LRRequired corroboration
I₁Public, complete system inventory with model and licence dataH₅ or H₆2.5Regulator verifies deployed assets against inventory
I₂Hidden biometric module discovered on active serverH₃ or H₂3.5Hash, configuration, service and usage evidence
I₃Protest-period surge in identity queries preceding violenceH₃5.0Immutable logs, case-purpose fields and target sample
I₄Supplier remote session without national ticketH₂; potentially H₄3.0VPN, session and command records
I₅Verified foreign extraction of biometric or police dataH₄8.0Network forensics plus actor attribution
I₆Support threatened following a political disagreementH₄7.0Documentary linkage between demand and consequence
I₇Successful supplier-disconnection exerciseH₆5.0Independent restore, operation and credential rotation
I₈AI Act mapping limited to written policyH₅ weakly1.3Technical audit absent
I₉Database interfaces restricted by purpose-bound gatewayH₅ or H₆3.0API policies, logs and penetration testing
I₁₀Facial gallery includes peaceful activists or journalistsH₃8.0Gallery export, provenance and identity verification
I₁₁New supplier-exclusive national expansion contractH₂4.0Contract, scope, interfaces and maintenance annexes
I₁₂Competitive multi-vendor replacement funded and executedH₆6.0Acceptance testing and demonstrated interoperability

Indicator dependency and deception controls

Indicators cannot be treated as independent Bernoulli observations because surveillance programmes generate clustered evidence. A new national command centre may simultaneously produce procurement documents, training announcements, additional cameras and increased network traffic; counting each as a separate confirmation of expansion would inflate the posterior. The model therefore groups indicators into six dependency clusters: procurement C₁, architecture C₂, operations C₃, political outcomes C₄, foreign access C₅ and regulation C₆. Evidence within the same cluster receives a diminishing multiplier: the first high-quality observation retains full weight, the second contributes 60%, the third 35%, and further observations contribute 20% unless they are technically independent. Deception and denial require parallel treatment. Authorities may relabel facial recognition as “advanced video analytics,” describe retrospective identification as ordinary archive search or declare a function inactive while retaining executable services and valid licences. Suppliers may provide accurate general assurances that customer data remain locally controlled while a domestic integrator retains unlogged remote access. Critics may commit the reverse error by equating every Chinese camera with active facial recognition or every network connection with Chinese intelligence access. The collection plan must therefore privilege hard discriminators: software manifests, licence entitlements, running services, model files, accelerator utilisation, database query logs, remote-session records, update signatures, packet destinations and case outcomes. China’s 2025 facial-recognition rules require encryption, access control, authorisation management, security auditing and intrusion protection, demonstrating that these controls are technically recognised within the Chinese regulatory environment. Measures for the Security Management of Facial Recognition Technology Applications – Ministry of Justice of the People’s Republic of China – March 2025verified Chinese government text. Their existence does not prove equivalent safeguards in exported systems; it strengthens the argument that Balkan purchasers should demand them contractually and verify them technically.

Monte Carlo model architecture

The Monte Carlo model simulates 100,000 five-year paths using twelve variables scored from 0 to 100. Six variables increase sovereignty risk: supplier concentration C, privileged-access opacity A, biometric capability B, database integration D, domestic political stress P and regulatory non-compliance N. Six reduce it: regulator capability R, judicial control J, audit completeness U, supplier substitutability S, EU conditionality E and civil-society detection capacity V. Baseline 2026 values are C 72, A 67, B 61, D 55, P 58, N 59, R 43, J 41, U 32, S 29, E 67 and V 61. These are explicit analytical inputs derived from the architecture and governance assessment, not official country statistics. Each path draws annual changes from bounded triangular distributions because reliable empirical distributions do not exist. Correlations are included: C and A correlate positively at 0.55; B and D at 0.65; P and political-use probability at 0.70; R and U at 0.60; E and N correlate negatively at −0.50; S and C at −0.55. Three shocks are randomly introduced: a political-crisis shock, a major cybersecurity incident and an accession-acceleration shock. Crisis probability begins at 18% annually, cybersecurity shock at 12%, and accession acceleration at 15%; these are scenario assumptions, not measured frequencies. A crisis increases P and raises the probability that latent functions become operational. A cyber incident can either increase dependence, if only the supplier can restore service, or accelerate diversification, if it exposes unacceptable access risk. Accession acceleration raises E, R and U but only produces sustained improvement where budgets and technical staff are available. The model classifies terminal states according to operational characteristics rather than political labels.

VariableMeaning2026 inputPrincipal data needed for recalibrationRisk direction
CSupplier concentration72Asset and contract market shareHigher increases risk
APrivileged-access opacity67Named accounts, VPN and session recordsHigher increases risk
BAvailable biometric capability61Module, model, licence and service inventoryHigher increases latent capability
DCross-database integration55API map and query permissionsHigher increases surveillance reach
PDomestic political stress58Protest, election and emergency indicatorsHigher raises misuse probability
NLegal and operational non-compliance59Independent compliance auditHigher increases rights and accession risk
RRegulator technical capability43Staff, budget, laboratory and access authorityHigher reduces risk
JJudicial authorisation strength41Warrant rules and case samplingHigher reduces political discretion
UAudit completeness32Log coverage and retention integrityHigher reduces opacity
SSupplier substitutability29Migration exercise and alternative maintainersHigher reduces leverage
EEU conditionality strength67Accession benchmarks and funding conditionsHigher favours H₅ and H₆
VIndependent detection capacity61Regulator, parliament and civil-society accessHigher increases exposure of misuse

Terminal scenarios and probability distribution

The simulation resolves into five terminal scenarios. S₁, sovereign European convergence, combines strong audits, national key ownership, supplier-independent recovery, purpose-bound database interfaces and enforceable biometric restrictions. S₂, regulated hybrid persistence, retains Chinese-origin cameras or servers but separates the most sensitive databases, restricts live identification and subjects maintenance to stronger controls. S₃, opaque commercial lock-in, preserves the platform primarily because replacement costs, proprietary formats and specialist dependence make migration unattractive; political use remains possible but is not systematically demonstrated. S₄, domestic control escalation, combines expanding biometric and metadata capabilities with protest-linked or opposition-linked use by national authorities. S₅, foreign leverage or access event, requires either verified foreign extraction, politically conditioned support or another direct mechanism connecting external influence to system dependence. Under the central parameterisation, the 2031 probabilities are S₁ 17%, S₂ 39%, S₃ 24%, S₄ 16% and S₅ 4%. The low value assigned to S₅ reflects the demanding evidentiary definition and absence of verified current proof, not an assertion that foreign access is impossible. S₂ is modal because it best reconciles installed-system inertia with the EU’s strengthening legal framework. The AI Act creates strict conditions for remote biometric identification and high-risk systems, while the Cyber Resilience Act establishes lifecycle cybersecurity obligations for products with digital elements. Regulation (EU) 2024/1689 – European Parliament and Council – July 2024verified official text. Regulation (EU) 2024/2847 – European Parliament and Council – November 2024verified official text. Candidate-country convergence will not be automatic, but these rules increase the legal and procurement cost of retaining unverifiable functions.

Scenario2031 probabilityDefining technical statePolitical conditionConfidence
S₁ — Sovereign European convergence17%Multi-vendor, national keys, complete audit, successful migrationStrong regulator and accession executionMedium–low
S₂ — Regulated hybrid persistence39%Legacy hardware retained, sensitive functions restrictedPartial EU alignment and uneven enforcementMedium
S₃ — Opaque commercial lock-in24%Proprietary platform and supplier-dependent maintenancePolitical use unproven or episodicMedium
S₄ — Domestic control escalation16%Integrated biometric and cross-database analyticsProtest or opposition monitoring becomes systematicMedium–low
S₅ — Foreign leverage or access event4%Verified external access or politically conditioned dependencyDirect foreign influence demonstratedLow probability, high impact

Sensitivity, tail risk and scenario transitions

Sensitivity analysis indicates that privileged-access opacity A, supplier substitutability S, audit completeness U and database integration D exert greater influence on terminal outcomes than the raw number of cameras. Reducing A from 67 to 35 while increasing U from 32 to 70 lowers the combined S₄–S₅ probability more sharply than replacing half the visible camera estate without changing platform access. Increasing S from 29 to 65 materially reduces S₃ and weakens the potential leverage mechanism underlying S₅. Conversely, increasing D above 80 while B remains above 70 produces nonlinear growth in S₄ because identity, vehicle, border and police records become mutually reinforcing. The principal tail risk is a compound event: acute political crisis, emergency legal measures, activation of previously dormant biometric modules, temporary expansion of watchlists, increased retention and emergency supplier support. Each action can be described individually as temporary or security-driven; together they can establish a durable surveillance regime before ordinary safeguards return. Another tail risk is a destructive cyber incident in which restoration depends exclusively on the supplier. Such an incident could strengthen H₂ by demonstrating operational dependence or strengthen H₆ if governments respond with funded diversification. The result depends on political framing and available financing. Huawei’s audited reporting describes extensive cybersecurity and privacy governance, including assessment of risks across more than 4,000 suppliers and more than 890 security and privacy certifications. Huawei 2025 Annual Report – Huawei – March 2026verified audited corporate report. These figures support evaluation of corporate security capacity, but they do not determine the state of a specific Balkan deployment. Deployment-level logs, configurations and contracts remain necessary for updating A, U and S.

Stress testParameter shockMost affected scenarioDirectional probability effect
Full regulator accessU rises to 75; R rises to 70S₁ and S₂Strong increase
National cryptographic controlA falls to 30S₄ and S₅Strong decrease
Supplier-exclusive expansionC rises to 90; S falls to 15S₃Strong increase
Protest crisisP rises to 85 for two yearsS₄Strong increase if B and D are high
Verified foreign sessionA rises to 90; H₄ LR above 5S₅Sharp increase, still requiring attribution
Successful migration exerciseS rises to 75; C falls to 45S₁Strong increase
Cosmetic legal alignmentE rises but U and R remain unchangedS₂ or S₃Little sovereignty improvement
Integrated identity gatewayD rises to 85S₄Nonlinear increase
Major cyber incidentA and operational dependence exposedS₃ or S₁Direction depends on response
EU-funded replacementS and U rise; N fallsS₁Moderate-to-strong increase

Early-warning architecture

Early warning must rely on measurable thresholds that trigger collection, audit or policy intervention before the system reaches an irreversible state. The framework uses four levels. Green indicates controlled exposure; amber indicates accumulating vulnerability; red indicates probable loss of sovereign control or serious abuse risk; black indicates an event requiring immediate suspension, forensic preservation and independent investigation. Thresholds should be tested monthly for technical indicators and around every major protest, election or emergency for political-use indicators. A single red indicator may arise from error, but two red indicators from independent clusters should trigger a formal audit. One black indicator is sufficient for escalation. Technical warning should precede public attribution: unexplained encrypted traffic to an external endpoint is a black operational event until investigated, but it is not automatically evidence of Chinese state access. Similarly, a protest-period biometric-query surge is red for domestic misuse, but H₃ should not be confirmed until target purpose and resulting action are verified. The warning system must be protected from the operator it monitors. Logs should be replicated to an independent authority; configuration changes should be cryptographically signed; watchlist additions should require dual approval; and emergency exceptions should expire automatically. The EU’s ICT Supply Chain Security Toolbox provides a horizontal, all-hazards approach to supplier and dependency risk, reinforcing the need to monitor critical suppliers, multi-vendor resilience and high-risk dependence. ICT Supply Chain Security: EU Adopts a Toolbox to Mitigate Risks – European Commission – February 2026verified official publication.

Warning indicatorGreenAmberRedBlack
Uninventoried devices or modulesBelow 2%2–5%Above 5%Unknown critical server or biometric engine
Privileged accounts without named owner01 temporary exceptionMore than 1 or over 24 hoursActive unknown foreign or shared administrator
Unrecorded support sessions0Ticket discrepancySession without complete recordingCommands or extraction outside authorised scope
External network destinationsAllow-listed onlyNew destination under reviewUnauthorised persistent destinationConfirmed sensitive-data transfer
Biometric watchlist growthCase-linked and stableAbove 10% quarterlyAbove 25% or event-linkedPeaceful activists or journalists enrolled
Protest-period query volumeNormal baseline1.5 times baseline3 times baselineBulk identity search without individual suspicion
Database integrationPurpose-bound interfacesNew interface pending auditBulk cross-agency accessIdentity, telecom and protest data fused without authority
Log integrityComplete and replicatedShort collection gapGap over 30 minutes in critical systemDeliberate deletion or tampering
Supplier substitutabilityTested annuallyTest delayedRecovery failsSupplier disconnection halts essential operation
Firmware updatesSigned and locally stagedDocumentation incompleteUnreviewed updateSignature failure or undeclared functionality
Retention complianceAutomatic deletion provenLimited exceptionsRepeated extensionSecret or indefinite political-event retention
Regulator accessImmediate and completeDelayed under 7 daysMaterial information withheldAccess refused or records destroyed

Country and regional differentiation

The forecast should not mechanically transfer Serbia’s risk profile to every Western Balkan state. Serbia receives the highest architectural attention because the Huawei Safe City ambition and biometric-law controversy are documented in admissible primary sources. Montenegro, North Macedonia, Albania, Bosnia and Herzegovina and Kosovo possess different combinations of cybersecurity maturity, data-protection alignment, institutional capacity and foreign-supplier exposure. The European Commission reported that Montenegro’s personal-data framework remained unaligned with the EU acquis; North Macedonia continued to show low awareness and insufficient information-technology protection of personal data; Albania’s Total Information Management System retained security and data-protection vulnerabilities; and Bosnia and Herzegovina lacked elements of a unified cybersecurity framework while being urged to implement supplier-risk controls. These conditions represent vulnerability multipliers, not proof of Chinese biometric deployment. Montenegro Report 2025 – European Commission – November 2025verified official document. North Macedonia Report 2025 – European Commission – November 2025verified official document. Albania Report 2025 – European Commission – November 2025verified official document. Regional forecasting should therefore use a two-stage model: first establish actual vendor and system presence through inventories and contracts; then apply governance-risk multipliers. A state with weak data protection but no integrated biometric platform has high susceptibility but lower present capability. A state with advanced infrastructure and strong audit may possess high capability but lower misuse probability. Conflating susceptibility with deployment produces false regional maps and weakens warning accuracy.

Regional tierDefining conditionForecast treatmentRequired collection
Tier A — Documented comprehensive ambitionPrimary evidence of integrated Safe City proposal or deploymentFull Bayesian and Monte Carlo modelContracts, architecture, licences, logs and use cases
Tier B — Documented Chinese componentsVerified devices or network elements but uncertain platform integrationArchitecture-first risk assessmentAsset register, firmware and network map
Tier C — Governance vulnerabilityWeak data protection or cybersecurity, supplier presence unverifiedSusceptibility model onlyProcurement search and technical inventory
Tier D — Controlled deploymentStrong safeguards and limited purposeResidual-risk monitoringIndependent annual audit
Tier E — UnknownInsufficient admissible primary evidenceNo substantive attributionPriority collection without speculative scoring

Decision points and collection plan

The five-year model requires formal decision points rather than passive annual reassessment. By the end of 2026, candidate governments should publish or confidentially provide independent regulators with complete surveillance-system inventories, including modules, licences, firmware, databases, remote-access mechanisms and maintenance parties. By mid-2027, every biometric gallery should have documented provenance, legal basis, expiry and challenge procedures, while all privileged accounts should be named and multi-factor authenticated. By 2028, cross-agency data interfaces should operate through purpose-bound gateways with immutable query logs, and prohibited or unjustified functions should be physically removed rather than merely disabled. By 2029, each state should conduct a supplier-disconnection exercise covering licence continuity, credential rotation, backup restoration and vendor-independent operation. By 2030, EU accession reporting should include technical evidence concerning high-risk AI, not only legislative alignment. By 2031, governments should demonstrate migration of a representative subsystem to an alternative supplier without losing evidentiary integrity, functionality or access control. Failure at each decision point updates H₂ or H₃ upward depending on whether the failure concerns technical dependence or political use. Refusal to disclose support pathways updates A, while a failed recovery exercise lowers S. A public law that appears compliant but is not reflected in system configuration increases the probability of S₂ or S₃ rather than S₁. Conversely, a technically verified audit, successful exit exercise and absence of protest-linked misuse across several high-stress events would raise H₆ substantially. Forecasting must remain iterative: every update should publish the changed indicator, likelihood ratio, dependency adjustment, posterior probability and remaining collection gap. This audit trail prevents political actors from selectively presenting favourable model outputs while concealing assumptions.

DeadlineMandatory milestoneVerification artefactFailure consequence
December 2026Complete asset, software and access inventoryRegulator-signed reconciliation reportA and U risk scores deteriorate
June 2027Watchlist and privileged-account governanceGallery provenance and identity-access registerH₃ rises if political entries appear
December 2027Independent algorithm and threshold validationTest protocol, error distribution and version hashesBiometric use restricted pending compliance
June 2028Purpose-bound database gatewaysAPI map, rules and immutable query logsD classified red
December 2028National control of keys and certificatesRotation and revocation exerciseA classified red
June 2029Supplier-disconnection testRecorded independent operationS classified red if service fails
December 2029Protest-event use auditQuery-to-case correlationH₃ updated using event evidence
June 2030AI Act operational alignmentSystem-level conformity and rights assessmentAccession conditionality triggered
December 2030Multi-vendor interoperability testAlternative component successfully integratedH₂ declines if successful
July 2031Sovereign migration demonstrationEnd-to-end data and service migrationFinal scenario classification

Strategic forecast judgement

The most probable 2031 outcome is neither a complete Chinese surveillance sphere nor a clean European replacement. It is a regulated but incomplete hybrid in which Chinese-origin hardware and platform components remain operational, live biometric identification is formally restricted, retrospective and metadata capabilities persist, access controls improve unevenly and supplier dependence declines more slowly than legal alignment advances. The central forecast assigns 39% to this outcome. Commercial lock-in without clearly demonstrated systematic political use remains the second-largest scenario at 24%. A sovereign European transition reaches 17%, while domestic political-control escalation receives 16% and a verified foreign leverage or access event 4%. Confidence in the ranking is medium; confidence in the exact percentages is low-to-medium because contract, configuration and query-log data remain incomplete. The two indicators with the greatest power to alter the forecast are a verified protest-target watchlist and a successful supplier-disconnection exercise. The first would move H₃ sharply upward; the second would move H₆ upward while reducing H₂ and H₄. The most important warning is therefore not the installation of another camera. It is the convergence of four conditions: biometric capability above 70, database integration above 75, audit completeness below 40 and political stress above 70. When those thresholds coexist, surveillance changes from a collection system into a political-control infrastructure. The most important protective convergence is equally clear: national cryptographic control, regulator-owned logs, purpose-bound database interfaces and tested supplier substitutability. If all four are implemented, the residual risk becomes governable regardless of equipment origin. If they are absent, replacing the Chinese supplier alone may merely transfer the same sovereignty deficit to another vendor.

Five-Year Outlook · August 2026–July 2031
Figure 1: Monte Carlo Terminal-Scenario Distribution
Central model: 100,000 conceptual paths. Percentages are analytical scenario estimates derived from disclosed assumptions, not official statistics.

Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization – Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.