Smile, You're At A Protest

Scanned at a protest, stored in a database.

In partnership with

Students at New Delhi's Jantar Mantar say they were filmed while they ate, while they rested, and while they queued for medical help. Female demonstrators soaked by monsoon rain say officers filmed them at close range with handheld cameras and smart glasses.

Some were told their photographs would be passed on to their parents, their universities and their future employers.

They were being fingerprinted too, without arrest and without charge.

An Impressive Kit

The protests began in June after allegations of paper leaks and grading irregularities in NEET-UG 2026, and turned into a 36-day sit-in at Jantar Mantar demanding an overhaul of the National Testing Agency. It culminated in the march to Parliament on July 20, which turned sour after police batons fell indiscriminately on the heads of protesters.

My colleague Hera's investigation for Decode set out how Delhi Police turned that sit-in into a biometric dataset, and the equipment list is rather impressive.. and scary…and problematic.

Parked at the site was Ikshana, a mobile command vehicle carrying eight high-definition cameras on a telescopic mast, giving officers a 360-degree view of the crowd, running live facial recognition, number-plate reading and crowd density analytics from hardware inside the van. A second vehicle, DP-Drishti, pulled in feeds from surrounding CCTV cameras and displayed match confidence scores on screen as faces were scanned. Both were built by Aditya Infotech under its CP PLUS brand.

Officers on the ground wore smart glasses made by Mumbai firm Dimension NXG, sold as AjnaLens. These run facial matching without needing a network connection, checking faces against encrypted databases of over 10,000 profiles stored on the officer's own phone, with thermal imaging bolted on. Officers were also photographed wearing consumer smart glasses.

Then there was Abhigyan, an app built by the National Crime Records Bureau that lets officers take fingerprints on a handheld device and check them against the national fingerprint database in real time. Protesters and journalists were fingerprinted without being arrested. Some demonstrators covered their faces, and police used algorithms trained to identify people wearing masks.

The Numbers

On 27 July, police sources told reporters the system had scanned the crowd and identified 2,873 individuals with prior criminal records. This was offered as proof the technology works.

To find those 2,873 people, the system had to scan everybody else as well, converting every face in the crowd into a template and running it against a police database. Three days earlier, police had justified the deployment by citing intelligence about cross-border groups monitoring the demonstrations. A prior record is not a crime in progress, and nothing in the reporting suggests those 2,873 people were doing anything other than attending a protest.

Nobody has said what happens to the scans of everyone who matched nothing.

The Law (Or Lack Of)

India has no parliamentary law governing how police buy or use facial recognition. Delhi Police's Automated Facial Recognition System runs on an internal executive order dated 9 June 2022, which authorised the technology for tracing missing children, identifying unclaimed bodies and investigating serious crime. Scanning a student protest was not on that list.

The Criminal Procedure (Identification) Act permits police to collect fingerprints and facial data from people who have been convicted or arrested for specified offences. It says nothing about protesters at a sit-in.

And the Digital Personal Data Protection Act, which would ordinarily give citizens some say over their own data, exempts state agencies from consent, notice and purpose limitation whenever data is processed for public order or crime prevention. If your face was scanned at Jantar Mantar, you have no way to get it deleted.

Right to Information responses confirm Delhi Police conducted no privacy impact assessment before deploying any of this. The smart glasses flag a match at a similarity threshold set somewhere between 60% and 80%, which in a dense crowd is a generous definition of certainty, and there are no published error rates or independent audits to check it against.

The usual excuse is that technology moves faster than legislation. The standard has existed since 2017, when the Supreme Court held in the Puttaswamy judgement that any intrusion on privacy must rest on actual legislation, serve a legitimate aim and use the least intrusive means available.

An internal police memo clears none of those bars.

The “Luxury” Litigation

Two petitions are now live. Former JNU students' union president Aishe Ghosh moved the Delhi High Court on 15 July over the filming and the threats. On 28 July, Rajya Sabha MP A.A. Rahim took the matter to the Supreme Court, and notably named CP PLUS and AjnaLens as respondents alongside the government, which puts the private vendors themselves in the frame.

Two commercial firms supplied the hardware and algorithms used to biometrically process a political gathering, and neither they nor the police have disclosed what the data-sharing agreements say, how long the records are kept, or whether any of it can be used to improve the vendors' own products.

Appearing for the government in the High Court, Solicitor General Tushar Mehta argued that filming protests is ordinary police practice and that protesters post their own videos online anyway.

He described the petition as "luxury litigation". The Internet Freedom Foundation has written to the Police Commissioner demanding the biometric processing stop and the data be deleted, and lawyer Apar Gupta has set out at length why he considers the surveillance illegal.

What Mehta's argument skips is that a video is a video, while a facial recognition match is a name, an address and a file. In February, Amit Shah opened an expanded command centre at police headquarters that pulls in feeds from 25,000 cameras across the capital. Europe banned this exact use of real-time facial recognition in public spaces last year.

The students wanted change in the education system. Some of them may instead have got a permanent entry in a police database.

Kimi K3, The New Disrupter

On 27 July, Chinese firm Moonshot AI released the full weights of Kimi K3 for anyone to download, eleven days after putting it on its API. At 2.8 trillion parameters it is the largest open-weight model ever published,. Artificial Analysis scored it third in the world at 57.1, just behind Anthropic's Claude Fable 5 on 60 and OpenAI's GPT-5.6 Sol on 59. On Arena.ai's blind developer preference test for front-end code, it came first outright, ahead of both. Cognition verified it as the first open-weight model to pass its FrontierCode benchmark and put it straight into Devin.

The disruption is in the pricing. Kimi K3 costs $3.00 per million input tokens and $0.30 for cached ones, roughly a third of what Claude Fable 5 charges. Coding agents work by feeding the same codebase back to the model over and over, so cache hit rates in those loops run above 90%, which drops the real cost of running an autonomous coding agent by 70% to 90%.

Markets noticed within a day. Z.ai fell as much as 30%, MiniMax 16% and Alibaba 4%, the Asian semiconductor index dropped over 6%, and Nasdaq futures slipped, with investors working out whether cheaper architectures mean less demand for chips.

OpenAI responded by cutting the price of GPT-5.6 Luna by 80%, taking input costs from a dollar to twenty cents. Moonshot's own revenue went up sixfold, its annual recurring revenue hit $300 million, and it is now raising at a $50 billion valuation ahead of a Hong Kong listing.

Washington's response has been less about products and more about accusations. White House science adviser Michael Kratsios has alleged Moonshot trained the model on restricted NVIDIA chips bought through back channels and distilled it against Anthropic's models. The industry has split neatly along commercial lines. Anthropic and OpenAI are lobbying for restrictions on open foreign models.

A joint assessment by the UK and US AI safety institutes found K3 meaningfully behind American models on offensive cyber tasks, completing 17 steps of a 32-step simulated network attack against an average of 28.5 for US frontier systems. They also found its safeguards did not stop it attempting to write exploits when asked.

Once the weights are public, of course, anybody can fine-tune those safeguards away entirely, and roughly a third of the world's open-weight AI workloads already run on Chinese architectures.

MESSAGE FROM OUR SPONSOR

Own Search With Podcasts

Your competitors are fighting over the same keywords. The smartest brands are building the authority that search engines, AI platforms, and customers trust everywhere.

Every relevant podcast appearance can produce branded mentions, backlinks, transcripts, citations, clips, expert content, and third-party proof that keeps compounding across search and AI discovery.

PodPitch searches millions of podcasts, finds the shows that matter to your market, develops the angle, sends personalized pitches, and follows up automatically until your experts are booked.

Growth teams are already using podcast appearances to build distributed authority that cannot be manufactured by publishing another generic SEO article.

Only 20 SEO, AEO, and GEO demo spots are available this month. Once they’re claimed, the offer disappears.

Start building searchable authority now, before your competitors own the conversations shaping your market.

📬 READER FEEDBACK

💬 What are your thoughts on using AI chatbots for therapy? If you have any such experience we would love to hear from you.

Share your thoughts 👉 [email protected]

Was this forwarded to you?

Have you been targeted using AI?

Have you been scammed by AI-generated videos or audio clips? Did you spot AI-generated nudes of yourself on the internet?

Decode is trying to document cases of abuse of AI, and would like to hear from you. If you are willing to share your experience, do reach out to us at [email protected]. Your privacy is important to us, and we shall preserve your anonymity.

About Decode and Deepfake Watch

Deepfake Watch is an initiative by Decode, dedicated to keeping you abreast of the latest developments in AI and its potential for misuse. Our goal is to foster an informed community capable of challenging digital deceptions and advocating for a transparent digital environment.

We invite you to join the conversation, share your experiences, and contribute to the collective effort to maintain the integrity of our digital landscape. Together, we can build a future where technology amplifies truth, not obscures it.

For inquiries, feedback, or contributions, reach out to us at [email protected].

🖤 Liked what you read? Give us a shoutout! 📢

↪️ Become A BOOM Member. Support Us!

↪️ Stop.Verify.Share - Use Our Tipline: 7700906588

↪️ Follow Our WhatsApp Channel