top of page

How Dictatorships Use AI to Expand Surveillance and Political Control

Aug 21
15 min read

Google News has surfaced a stark conflict: artificial intelligence is helping authoritarian governments identify, monitor, and silence perceived opponents at unprecedented speed.

The shift is not simply about installing more cameras or blocking more websites. Governments can now connect faces, movements, messages, relationships, and behavioral patterns across previously separate databases.

That integration changes the balance between rulers and the people challenging them. Traditional repression reacts to a protest, publication, or political organization. AI-assisted repression seeks to detect those activities earlier, rank their importance, and disrupt them before they spread.

China has built the most extensive version of this model. Russia, Iran, and other governments have adopted overlapping combinations of facial recognition, automated censorship, data fusion, and online influence operations.

These systems remain imperfect. They produce errors, inherit political bias, and still depend on human officials. Yet authoritarian governments do not need flawless predictions to gain an advantage.

They need enough information to raise the cost of organizing, speaking, traveling, or remaining anonymous. That chilling effect can strengthen a regime even when its algorithms frequently make mistakes.

The central contest is therefore not dictatorships against a single technology company. It is automated political control against accountable AI governance.

That conflict reaches beyond national borders. Surveillance components come from multinational supply chains, while governments exchange infrastructure, operational knowledge, and regulatory models.

What Google News Reveals About AI-Powered Repression

The important change is not a single deployment, but the conversion of disconnected control tools into an increasingly integrated political system.

Authoritarian governments have always collected information about critics. Secret police monitored meetings, intercepted communications, recruited informants, and built files on people considered politically dangerous.

Those methods were labor intensive. Officials had to decide whom to follow, which messages to read, and how to connect fragments of information stored across different offices.

AI reduces that administrative burden. Computer vision can search camera feeds, while natural language processing can classify messages and detect prohibited subjects.

Data fusion, which combines records from multiple sources, can connect a face with a phone number, vehicle, address, workplace, and social network. Predictive analytics can then rank people or events according to a government-defined risk score.

The result is a wider dragnet. Authorities can begin with entire populations rather than a short list of known suspects.

Freedom House documented this broader transformation in its study of digital repression. Its researchers examined developments across 70 countries representing 88 percent of global internet users.

The organization found that internet freedom declined for the thirteenth consecutive year during its 2023 reporting period. People faced legal consequences for online expression in 55 of the 70 countries studied.

Governments in at least 21 countries had also created legal rules that required or encouraged platforms to use machine learning against disfavored content. Such rules can make private platforms extensions of state censorship.

Generative AI adds another layer. It can produce articles, images, audio, comments, and fabricated identities faster than traditional propaganda teams.

Freedom House found that governments or political actors used generative tools in at least 16 countries to distort public debate during the reporting period. At least 47 governments deployed commentators to manipulate online discussions.

These activities differ from ordinary political messaging. A coordinated campaign can manufacture apparent agreement, overwhelm independent reporting, or make authentic evidence seem indistinguishable from fabricated material.

For a regime, confusion can be as useful as persuasion. Citizens who distrust every video, account, and document have greater difficulty organizing around a shared version of events.

This is why the Google News headline matters beyond its immediate publisher. It points to a structural change in how political control operates.

AI does not replace censorship, arrests, internet shutdowns, or intimidation. It helps governments decide where to apply those methods and how to conceal their scale.

The system also learns from enforcement. An arrest creates new device records, contacts, travel histories, and interrogation material that can feed later investigations.

That feedback loop turns each intervention into additional training data. It also makes repression harder to inspect because the decisive connection may occur inside an inaccessible government database.

The change creates a serious accountability gap. The person affected might never learn what data triggered attention, how an algorithm assessed it, or whether anyone verified the result.

Once a security agency labels that process secret, meaningful appeal becomes nearly impossible. The opacity is not merely a technical problem. It serves the political interests of the institution using the system.

The Authoritarian Advantage Is Scale, Not Perfect Accuracy

Dictatorships gain leverage from AI because they can tolerate errors that an accountable legal system should reject.

Public discussion often treats accuracy as the central measure of a surveillance system. That framing misses the political question.

A facial recognition model can wrongly match a protester, journalist, or passerby. A language model can mistake sarcasm for dissent. A risk system can treat an innocent association as evidence of disloyalty.

In a rights-respecting system, those failures should trigger disclosure, review, correction, and compensation. Courts, regulators, journalists, and elected officials can challenge the agency responsible.

An authoritarian system faces fewer constraints. Its leaders can accept large numbers of false positives when intimidation itself supports the regime.

A person wrongly questioned still learns that participation carries risk. Their family and colleagues receive the same message. Others may withdraw before authorities ever contact them.

This produces a chilling effect, meaning people change lawful behavior because they expect surveillance or punishment. The government does not need to prosecute everyone.

It needs citizens to believe that anonymity is disappearing.

AI strengthens that belief by making surveillance appear comprehensive. Networked cameras suggest that authorities can reconstruct movement across a city, even if coverage contains gaps.

Automated monitoring creates a similar impression online. Users cannot know whether a deleted phrase triggered an algorithm, a human moderator, or a government directive.

That uncertainty encourages self-censorship. It also shifts enforcement costs from the government to the population, since people begin policing their own behavior.

Carnegie’s surveillance index illustrated how widely the underlying technology had already spread by 2019.

The study identified active AI surveillance use in at least 75 of 176 countries. It found smart-city or safe-city platforms in 56 countries, facial recognition in 64, and smart policing in 52.

Those figures do not prove abuse. Carnegie explicitly noted that legitimate and unlawful deployments could not be separated through the index alone.

That distinction is essential. Democratic governments also use facial recognition, predictive systems, and video analytics for policing, border management, and public safety.

The political environment determines whether legal safeguards constrain those capabilities. Independent courts, free media, procurement transparency, and effective appeals can reduce misuse.

Closed systems lack those protections. Security agencies can define political criticism as extremism, public disorder, separatism, or false information.

Once that classification enters a watchlist, AI can automate its consequences. A person might face additional searches, blocked travel, account restrictions, employment pressure, or repeated police contact.

The computer does not create the political category. It makes the category easier to apply across millions of records.

This explains why claims about neutral algorithms are inadequate. A technically accurate model can still support an abusive policy.

If the government orders a system to identify peaceful protesters, improving accuracy does not solve the human-rights problem. It makes the violation more efficient.

The same concern applies to automated censorship. A classifier might correctly recognize every reference to a prohibited event, minority, or opposition figure.

From an engineering perspective, the model performs well. From a political perspective, it narrows the public’s ability to speak and obtain information.

AI therefore offers authoritarian governments three connected advantages: scale, speed, and plausible distance.

Scale expands the number of people monitored. Speed shortens the period between expression and enforcement. Plausible distance lets officials attribute decisions to platforms, vendors, or automated processes.

None requires artificial general intelligence. Existing computer vision, database matching, recommendation systems, and language models already provide the necessary components.

China Is Building an AI Control Stack

China’s model combines commercial innovation, legal mandates, and state procurement into a reusable infrastructure for political control.

China remains the most developed case because its system extends across online content, physical surveillance, policing, courts, and prisons.

The Australian Strategic Policy Institute examined this integration in its 2025 report on China’s AI systems.

The researchers analyzed procurement records, corporate filings, job listings, and model behavior. They also tested Chinese large language models with a dataset of 200 politically sensitive images.

Their findings describe a control stack rather than one surveillance product. Different systems classify information, identify people, generate alerts, assist officials, and enforce content rules.

Chinese large language models do not only filter text. ASPI found censorship mechanisms that also affected politically sensitive images.

That matters because multimodal models process several formats, including text, pictures, audio, and video. A censorship system can therefore follow the same political rule across different media.

This capacity makes evasion harder. Users have historically relied on images, homophones, screenshots, or coded language when direct text was blocked.

A model trained to interpret multiple formats can identify more of those substitutions. Human reviewers still provide cultural and political judgment, but automation increases their reach.

ASPI reviewed more than 100 listings for online censorship jobs. The continued demand for reviewers shows that China’s system has not removed people from the loop.

Instead, human workers interpret evolving political boundaries and feed those judgments into automated processes. The machine supplies scale, while people update the definition of unacceptable speech.

Chinese regulations also create commercial demand. Major technology companies have developed compliance platforms that smaller businesses can use to screen content.

This arrangement distributes enforcement across the digital economy. A new service does not need to build an entire censorship operation from scratch.

It can purchase or integrate a system shaped by existing state requirements. Compliance becomes an ordinary infrastructure expense rather than an exceptional intervention.

The criminal-justice system presents higher stakes. ASPI found that China was deploying AI across policing, prosecution, courts, and prisons.

Tools reportedly assist with documents, evidence processing, sentencing recommendations, and institutional management. Each use raises different questions about transparency and appeal.

An automated recommendation can appear objective even when its training data reflects selective policing. Past arrests and convictions do not form a neutral record in a politically directed system.

If officials targeted a community heavily in the past, an algorithm trained on that history can reproduce the pattern. It can then present repetition as statistical evidence.

Minority-language systems deepen this concern. ASPI found government-backed work involving Uyghur, Tibetan, Mongolian, and Korean language processing.

Commercial developers have limited incentives to create expensive models for relatively small language groups. The state can supply funding when surveillance and information control justify the investment.

Such models can monitor speech that previously required scarce human specialists. They can also extend analysis across text, audio, and video.

The control stack therefore closes several gaps at once. It broadens language coverage, joins online and offline identities, and brings automated recommendations deeper into government decisions.

China’s system is not fully centralized or uniformly capable. Agencies have different budgets, vendors provide uneven products, and local officials still make consequential choices.

That unevenness should not create false reassurance. Political systems do not need technical consistency to impose fear or punish selected groups.

Google News readers should also avoid reducing this story to a uniquely Chinese development. China offers the clearest large-scale model, but components and operational practices travel.

Some travel as commercial exports. Others spread through training relationships, conferences, standards bodies, policing exchanges, or imitation.

That makes the Chinese case both a domestic human-rights issue and a preview of capabilities available elsewhere.

Global Technology Supply Chains Keep the System Running

Authoritarian surveillance is not produced inside sealed national systems; it depends on international hardware, software, expertise, and financing.

A camera network requires sensors, storage, processors, communications equipment, databases, and analytical software. Each layer can involve companies operating across several jurisdictions.

That complexity creates opportunities for denial. A chipmaker can say it sells general-purpose hardware. A software company can argue that a local partner controlled deployment.

A distributor can claim it never met the final government customer. Authorities can place procurement behind contractors or public-safety projects with benign names.

Yet the assembled system can still support political monitoring.

An Associated Press investigation examined how foreign technology contributed to China’s digital police state.

The investigation drew on tens of thousands of leaked emails and databases, confidential records, procurement documents, and interviews with more than 100 people.

AP reported that technology connected to American, European, and Asian companies appeared in Chinese policing and surveillance infrastructure.

The examples covered database software, cloud systems, storage, mapping products, chips, cameras, biometric tools, and analytical applications.

Several companies told AP that old relationships had ended, that they followed export controls, or that alleged misuse occurred outside their knowledge and control.

Those responses illustrate the enforcement problem. A component can remain useful for years after sale, while software can be copied, modified, or integrated by another company.

Export rules often focus on named entities, destinations, or products. Surveillance systems evolve faster than those lists and frequently incorporate common commercial technology.

Supply-chain responsibility cannot therefore end with a narrow sanctions check. Vendors need to examine intended users, local partners, deployment settings, and foreseeable secondary uses.

They also need contractual controls, technical restrictions, audits, and credible exit procedures. None offers a complete solution, especially when a government conceals its operations.

The history of Western involvement complicates claims that authoritarian AI follows one national model. Carnegie found technology from American firms in 32 countries within its 2019 index.

Chinese companies were major suppliers, but businesses based in France, Germany, Israel, Japan, and the United States also contributed to global proliferation.

This is not evidence that every vendor intended repression. It shows why a simple democracy-versus-dictatorship supply map fails.

Commercial incentives can connect firms from open societies to agencies operating without open oversight. Investors and executives may see public-security contracts before they see political risk.

The same infrastructure can also shift purpose. A city may purchase cameras for traffic management, then connect them to facial recognition after protests begin.

A border database can become a domestic watchlist. A content-safety classifier can enforce political taboos. A fraud-detection platform can expose dissident financial networks.

This repurposing problem weakens assurances based only on the original sales description. Governance must follow the technology throughout its useful life.

Companies also need to consider maintenance. Updates, cloud services, replacement components, and technical support can keep an abusive system operational.

Stopping new sales will not immediately disable deployed equipment. Governments can stockpile hardware, use intermediaries, or develop local replacements.

The global market consequently gives dictatorships resilience. They can mix technologies from different suppliers and replace restricted components over time.

That resilience creates pressure for coordinated rules. One country’s strict export controls have limited effect when equivalent products remain available elsewhere.

Shared standards must also define prohibited uses, not merely prohibited customers. A government can move a project between ministries, local agencies, or affiliated contractors.

Google News coverage can expose individual deals, but public attention rarely follows the full chain. Procurement records, corporate disclosures, and technical research must fill that gap.

The decisive question is not whether a component was marketed as AI. It is whether the completed system expands a government’s ability to identify, classify, or punish lawful activity.

The Real Tradeoff Is Security Without Accountability

The hardest policy problem is separating legitimate public safety from systems that make political power difficult to challenge.

Governments present facial recognition, data analytics, and automated monitoring as tools for finding criminals, preventing attacks, or locating missing people.

Those purposes are not inherently illegitimate. The same technology can deliver different outcomes under different laws and institutions.

A tightly limited search for a known suspect differs from continuous identification across every public camera. Both might use similar software.

The distinction lies in necessity, proportionality, retention, access, and oversight. It also depends on whether affected people can discover and challenge misuse.

Authoritarian governments erase those distinctions. Broad national-security laws can make peaceful opposition equivalent to criminal danger.

They can define the entire population as a potential source of instability. Mass collection then becomes the default rather than an exceptional measure.

The Office of the United Nations High Commissioner for Human Rights has warned that remote biometric surveillance can affect privacy, expression, movement, and peaceful assembly.

Its guidance supports strict limits on systems that scan crowds or protests. It also opposes individualized crime prediction and biometric categorization based on protected characteristics.

Those positions reflect a basic problem. A camera scanning everyone at a demonstration does not only observe suspected wrongdoing.

It records lawful participation and can identify networks of organizers, journalists, lawyers, bystanders, and supporters. That knowledge changes whether people feel safe attending the next event.

The risk increases when several systems connect. Facial recognition identifies a person, phone data maps contacts, and language analysis classifies their communications.

An official may then treat the combined output as stronger than any individual record. However, linking uncertain inferences does not automatically create reliable evidence.

Errors can compound. A weak facial match can connect the wrong person to an address, while a mistranslated message supplies a false motive.

Opaque vendors and classified agencies make those failures difficult to detect. The affected person may only see the final restriction or accusation.

The United Nations has therefore emphasized transparency, independent supervision, and human-rights assessments before deployment.

Those protections are weakest precisely where the political risk is highest. An authoritarian legislature will not reliably constrain the security services preserving the ruling order.

Technical safeguards alone cannot repair that institutional failure. Human review helps only when the reviewer has authority, independence, and incentives to reject the machine’s output.

An official who expects punishment for missing a threat will accept more false alerts. Automation can intensify that bias by giving the alert a numerical score.

Systems also shape behavior inside government. Once an agency purchases expensive infrastructure, managers face pressure to demonstrate results.

More watchlists, alerts, and interventions can appear to justify the investment. Low activity might instead be interpreted as poor system performance.

This incentive encourages mission creep. A platform introduced for terrorism can expand to ordinary crime, protests, immigration, political speech, or workplace monitoring.

Russia’s experience with facial recognition shows how public-safety infrastructure can reach political gatherings. Human Rights Watch reported that Russian officials acknowledged using facial recognition for mass surveillance at a Moscow protest.

Iran demonstrates another pathway. Authorities combined internet restrictions, platform blocking, camera networks, and digital monitoring during periods of mass opposition.

Freedom House recorded Iran’s major decline in internet freedom following protests triggered by Jina Mahsa Amini’s death in custody in September 2022.

These cases show why focusing on model accuracy is insufficient. The main uncertainty concerns who defines the target and what happens after identification.

A system can perform exactly as designed while violating rights. The design goal itself may be political control.

Democratic governments should not assume that their own institutions eliminate this danger. Carnegie found AI surveillance across liberal democracies as well as autocracies.

Open societies possess stronger correction mechanisms, but those mechanisms require access to information. Secret procurement and broad security exemptions can weaken them.

The appropriate dividing line is therefore accountable use, not national branding. Governments should publish legal authority, permitted purposes, retention periods, error testing, vendor identities, and audit results.

They should also provide effective remedies. A right that cannot be exercised because the system remains secret offers little practical protection.

What the Next Phase of Digital Control Looks Like

The next contest will center on predictive targeting, generative propaganda, and whether governments can constrain the companies supplying both.

The first signal to watch is the movement from identification toward prediction.

Traditional facial recognition asks whether an observed face matches a stored image. Predictive systems make a more ambitious claim about what a person might do.

They can analyze travel, purchases, contacts, language, and location patterns to generate a risk assessment. Governments may call the result an investigative lead rather than a final decision.

That label does not remove its influence. Officers allocate attention based on those leads, while increased surveillance produces more records that appear to validate the original score.

The loop can turn political assumptions into statistical patterns. Communities watched most heavily will generate the most alerts.

Watch for procurement documents mentioning public-opinion analysis, social stability, early warning, risk portraits, or preemptive governance. Those phrases often reveal the desired function more clearly than an AI label.

Independent audits should test whether predictions identify actual conduct or merely reproduce official suspicion. Without access to data and outcomes, accuracy claims remain unverified.

The second signal is automated persuasion.

Generative models make it cheaper to operate many convincing accounts, tailor messages to different groups, and respond quickly during a political crisis.

A government no longer needs every propaganda worker to draft original posts. Models can produce variations, translations, comments, and synthetic media at scale.

Detection will remain difficult because generated content does not always contain a stable technical signature. Operators can also mix human and machine work.

The goal may be less ambitious than changing everyone’s mind. Flooding a discussion can exhaust moderators, distract journalists, and bury authentic testimony.

Synthetic media can also support the “liar’s dividend.” Officials can dismiss genuine recordings as fabricated because convincing fakes exist.

Watch how platforms report coordinated influence operations. Useful disclosures should explain account creation, amplification, targeting, payment, and links to state institutions.

Simple counts of removed posts will reveal little about reach or effect. Researchers need access to preserved datasets before platforms delete the evidence.

The third signal is whether export controls and corporate due diligence move from promises to enforceable practice.

Governments have imposed restrictions on selected surveillance companies and advanced components. Those measures create friction but leave broad commercial pathways open.

Future rules should address brokers, resellers, cloud support, software updates, and technical services. They must also cover repurposing after an apparently legitimate sale.

Company reporting offers an early test. Vendors should identify high-risk government contracts, describe their review process, and disclose when they suspend service.

Investors can ask whether revenue depends on customers that block audits or conceal end users. Employees can examine whether internal escalation channels have authority to stop deployment.

Civil society groups will need resources to investigate procurement and test deployed systems. Authoritarian governments deliberately restrict the evidence required for accountability.

Journalists and researchers also face personal risk when mapping these networks. Protection for whistleblowers and secure access to records will shape what becomes publicly knowable.

These three signals reinforce one another. Predictive surveillance generates targets, generative propaganda shapes the narrative, and global suppliers provide the infrastructure.

A regime that controls all three can act earlier, obscure what it did, and challenge the credibility of anyone documenting the result.

The counterweight must also operate as a system. Regulation, technical testing, investigative reporting, corporate accountability, and legal remedies cannot work in isolation.

Google News can bring the issue into public view, but attention is only the first step. Readers should ask what evidence lies behind each claim and which institution can impose consequences.

The question is no longer whether dictatorships will use AI. Documented deployments show that they already do.

The urgent question is whether companies and democratic governments will establish limits before integrated control systems become ordinary public infrastructure.

Follow procurement records, biometric laws, platform influence reports, and vendor disclosures over the coming months. Those signals will show whether accountability is catching up or falling further behind.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page