7
In 2016, San Diego City Council voted to approve a $30 million investment in a new smart city street-lighting system that promised to not only reduce electricity consumption but also assist municipal officials in planning and managing street parking and new bike lanes using sophisticated digital sensors.
The deal, consummated the following year, involved the purchase of 4,200 of General Electric’s remote-controlled LED ‘nodes’ as the first phase in the replacement of 14,000 of San Diego’s 60,000 street lights, all of which used inefficient sodium bulbs.
The giant conglomerate, of course, had been in the lighting business for well over a century. In recent years, its ‘intelligent environment’ group began thinking about how street lighting, one of the most rudimentary forms of urban infrastructure, was an ‘under-utilized asset’ with vast potential. GE Current (now spun off) wanted to go further than just providing illumination by reinventing the street light altogether.
To that end, the company’s engineers designed CityIQ, which is essentially a weatherproof plastic box that sits at the top of a hydro pole next to the LED lamp fixture. This innocuous container houses all sorts of digital sensors, on-board computing power, and wifi connections to a city’s operations centre. As for the business model, GE Current told potential customers the CityIQ nodes could be financed using energy savings from the LED lights, so it’s essentially a wash for taxpayers. ‘It allows the city to do lots of things,’ said Jim Benson, a senior marketing executive for GE Current.
The devices come with air quality monitors, fish-eye lens cameras that can monitor bike or vehicle volumes on side streets, unsafe driving, and parking infractions. There’s even an audio device linked to a third-party software system called ‘ShotSpotter,’ which detects gunfire, estimates the location, and notifies 911. According to procurement reports cited in a San Diego Police Department document obtained by a local newspaper, the installation of the first 4,000 nodes would allow the city to transform the equipment ‘into a connected digital network to optimize parking and traffic, enhance public safety and track air quality.’ (Other manufacturers include features like parking-space occupancy detectors and automatic brightness adjustments.)
At the time the purchase was being considered, municipal officials had a lot to say in public about what these devices would do: reduce energy consumption and identify areas with lots of cyclists in order to expand the bike lane network. What they didn’t explain, however, is what they could do, especially in regards to public safety. As it turned out, these devices, perched inconspicuously at the tops of utility poles, were packed with surveillance technology – an unblinking eye, surveying the street below.
GE Current had sold its smart lighting systems in Portland, Atlanta, and San Diego; indeed, the market for these devices is growing rapidly. Benson insisted the sensors had been fitted out with a range of data privacy protections – the gunshot detector, for example, couldn’t make out voices. But, Benson admitted, not all customers wanted the video capabilities. ‘There’s a lot of sensitivity around this.’
That would be putting it mildly. Revelations about the use of the video cameras by police set off a raucous local fight, pitting former mayor Kevin Faulconer and the police chief against racialized communities and civil liberties activists. San Diego council scrambled to contain the fallout. ‘The city has been trying to cover up what they knew about the technology,’ charged Geneviéve Jones-Wright, a San Diego lawyer who speaks for TRUST SD Coalition, a coalition of groups that banded together to fight the use of cameras.
The San Diego street-lighting debacle illuminates two of the most contentious aspects of smart city technology: the potential for even more widespread surveillance and the related risk of so-called ‘function creep,’ particularly with complex digital systems purchased by local governments using public monies.
The world of the modern city is already intensely surveilled. CCTVs have become ubiquitous in public, commercial, office, and industrial spaces. China has layered facial recognition software onto its CCTV networks, creating the world’s most extensive public surveillance system. Using a range of technologies and biometric devices, employers can monitor workers’ emails, the amount of time they spend on external websites, their movements within an office, or the duration of their bathroom breaks.
Most of us consciously post all sorts of personal information to a range of social media sites – data that can become fodder for investigators, reporters, competitors, prospective employers, neighbours, criminals, and so on. Palantir, a surveillance software powerhouse created by Paypal founder Peter Thiel, has generated billions in revenues gathering, combining, and analyzing this kind of information for law enforcement, intelligence and immigration agencies, the military, and private investigators. It has been condemned by Amnesty International for failing to safeguard the human rights of people who are caught up in its surveillance web.
A great deal more digital watching takes place in the service of commerce. Websites set up cookies in your browser for digital ads. E-commerce sites track previous purchases and serve up suggestions for future ones. Google tracks and sells search information to advertisers. Social media sites use monetization strategies that rely on monitoring user behaviour and transforming those patterns into a saleable product. Smart phones and apps are designed to track an individual’s movement patterns, purchase habits, and other data that can be packaged up and marketed.
Smart phones, in turn, leave trails of digital bread crumbs that can be aggregated across millions of users’ accounts and put to work driving navigation apps like Waze. Those apps and the companies behind them are interested in extracting huge amounts of data from the smart phones moving around a city at all times. Each device produces a signal plume, and these are aggregated by services like Google Maps to inform users about traffic delays, optimal routes, and all sorts of other embedded location information derived from Street-view 360 images, municipal databases, satellite photos, and so on. It is a highly useful form of mass surveillance.
As Harvard’s Shoshana Zuboff put it in her 2019 treatise, surveillance capitalism is ‘a new economic order that claims human experience as free raw material for hidden commercial practices of extraction, prediction, and sales.’ She characterized this ever-expanding sphere as not only a threat to human rights, but a ‘rogue mutation of capitalism’ that has produced unprecedented wealth, knowledge, and power. It is, she stated in a message that resonated with the critics of smart city ventures like Sidewalk Labs, ‘best understood as a coup from above.’
Concerns about smart city technologies, in fact, have zeroed in on the risk of creating heavily surveilled cities in the name of urban quality-of-life benefits, such as improved mobility, reduced emissions, or more efficient use of local services. ‘This futuristic wired urban world has a dark side,’ warned Robert Muggah, a principal at Ottawa-based SecDev Group, in a 2021 essay in Foreign Policy entitled ‘“Smart” Cities Are Surveilled Cities’ he wrote with Greg Walton. ‘Part of what supposedly makes cities smarter,’ they continued, ‘is the deployment and integration of surveillance technologies such as sensors and biometric data collection systems. Electronic, infrared, thermal, and lidar sensors form the basis of the smart grid, and they do everything from operating streetlights to optimizing parking and traffic flow to detecting crime’ (Muggah & Walton 2021).
The second but related source of controversy around San Diego’s smart lighting system was directly tied to the essential nature of digital devices, which is that they can do many things. In fact, the questions that fuelled the political fight over these devices had to do with intention: did the city set out to buy devices that could covertly assist the police in investigating street crime or was that capability essentially latent, something that was discovered once the devices were installed? Was it a case of ‘function creep’?
Initially, city officials insisted the video cameras embedded in the GE smart lighting nodes were never meant to be used as surveillance devices. They were even fitted out with software that obscures details like faces and licence plates. ‘It really started as an energy project,’ said the city’s deputy chief operating officer, Erik Caldwell.
At some point in 2018, however, San Diego police officials realized they could use the video footage, which is stored for five days, in crime scene investigations and began asking the city to release it. At the time, city council wasn’t informed about the SDPD’S interest in the tapes. ‘In our conversations with GE and council, we made it clear we didn’t want to use the system for law enforcement,’ Caldwell insisted. ‘That was not our intention.’ Still, he added, the city had ‘a legal and moral’ obligation to hand over video footage when the police asked for it.
Jones-Wright offered a far more skeptical account of the city’s conduct. She said officials and the mayor’s office made little effort to explain the system’s capabilities to constituents early on, and mostly played up the environmental benefits. ‘There was never even a public discussion,’ she said. ‘The city has been trying to cover up what they knew about the technology. No one had a chance to weigh in on this.’
As revelations about the police use of the nodes surfaced via documents obtained through access-to-information requests made by local investigative reporters, the SDPD responded by noting how the cameras had not only assisted with investigations but disproved assault charges that had been laid against a bystander in one incident.
SDPD officials themselves have subsequently confirmed how useful the footage is. ‘We had no idea what the quality of video would be, or what it would capture,’ Jeffrey Jordon, who leads special projects and legislative affairs for the San Diego Police Department, told Bloomberg CityLab. ‘The first time we saw it we were like, “Holy cow, that’s really good video.”’
It soon became obvious that the city was operating in a policy vacuum. There were unanswered questions about the ownership of the data and metadata generated by the nodes and whether the information could be mined or sold. There were no rules around how the police would access the video, and under what circumstances. Last, the city had done nothing in the way of community consultation around privacy issues. ‘They’re collecting data about how I move [around] in the city without acknowledging that we should have a say in that,’ said Jones-Wright.
In 2019, the SDPD issued a procedure document outlining the use of video from the smart street lights, but critics pointed out that such policies were designed by and for law enforcement. Jones-Wright and the TRUST SD coalition called for a complete moratorium on further deployment until San Diego council had produced a legally enforceable privacy policy with public oversight.
After a year of bitter fighting, San Diego council in July 2020 cut off funding for the street lights and in mid-November 2020 approved an ordinance calling for stricter controls and better governance, including the establishment of a privacy advisory board that reports to council.
‘Let us never underestimate the power of concerned community members coming together and making change,’ Jones-Wright said after the ordinance passed. ‘The work started because our government and public officials failed us.’
A growing number of cities are buying or considering smart lighting systems, and some, like Oakland, have opted to disable video to head off concerns about civil liberties. Erik Caldwell, for his part, pointed to the broader issue of unintended consequences. ‘It’s a kind of lesson for cities thinking about smart city technology.’
When municipalities buy buses, playground equipment, or traffic signals, it’s generally obvious how these assets will be used, which is to say, as intended. By contrast, data-generating digital technologies like laptops are packed with features: they can do many things, not all of which are known ahead of time. The smart phone is a perfect example. Did Apple’s Steve Jobs envision that someday Bluetooth-enabled electric toothbrushes would have digital features that deliver brushing-effectiveness metrics to an app on a smart phone? Probably not. Yet he certainly did recognize that the iPhone could serve as a platform from which third-party apps would operate.
The iPhone represents one link in a long chain of innovation that includes predecessor devices like the Blackberry and the pager, as well as iPods and, before those, MP3 players, cellphones, and radio transmitters. Innovation is an intrinsically iterative process, and doubly so when it involves technology.12 An invention is launched into the world, and people begin to find various ways of using it, some envisioned and others discovered through experimentation, imagination, or accident. In the meantime, the inventors or their successors develop iterations of the original, incorporating new features that respond to evolving uses and also finding ways of improving efficiency or reducing cost. All of these intertwined processes – involving myriad end users, as well as engineers, designers, and marketers – generate feedback loops, which yield improvements, inspire competing products, and seed new industries and inventions.
Was the discovery that GE’S smart lighting node could be used for police investigations an innovation or something else? Critics of smart city technology have argued that the San Diego smart lighting story, and others like it, represent examples of ‘function creep’ (a.k.a. ‘mission creep’), not innovation.
In a 2021 paper in Law, Innovation and Technology journal, Bert-Jaap Koops formally defined ‘function creep’ ‘as an imperceptibly transformative and therewith contestable change in a data-processing system’s proper activity.’ Koops, a professor of regulation and technology at Tilburg Institute for Law, Technology, and Society in the Netherlands, explained that the term can be applied when some kind of system shifts subtly, but not necessarily organically, with a non-trivial alteration to the original function (e.g., from an energy-reducing street light system with a few additional features to an investigative tool). What’s more, he distinguishes function creep from conventional innovation processes, as well as ‘transformative’ changes – such as the evolution of phones from analogue land lines to digital cellulars.
As he points out, the functions of data-processing systems frequently expand, and it is neither possible nor indeed desirable to regulate that process. For example, Excel spreadsheets were originally designed as accounting software, but they are now used for almost countless non-financial purposes.
Digital systems, however, are vulnerable to function creep, and the examples of this phenomenon, both in the smart city world and elsewhere, have piled up with the exponential growth in both big data and computing power.
In July 2019, for example, the Washington Post revealed that agents with the FBI and Immigration and Customs Enforcement (ICE) were using facial recognition software to scan digital databases of state-level driver’s licence records, which always include photos. The goal: identify illegal immigrants and suspects in criminal cases.
Freedom-of-information requests made by the Georgetown Law Center on Privacy and Technology produced thousands of documents showing how the databases had been transformed into an ‘unprecedented surveillance infrastructure.’ Law enforcement officials, moreover, were accessing the images without obtaining consent from the licencees. The Post also found that neither the U.S. Congress nor state legislatures authorized such uses of state driver’s licence images. The episode revealed how those databases, originally intended for one specific purpose, had been covertly used for something different and nefarious.
As the San Diego street light fight illustrated, function creep poses a particular concern with technology that collects large amounts of data in public spaces. ‘These technologies can have different features turned on,’ says Gilad Rosner, the IoT Privacy researcher. He advocates for the use of the ‘precautionary principle’ in the deployment of new technology.
Similar concerns came up when Sidewalk Labs was promoting its Quayside smart city project in Toronto. At one 2018 session of a digital strategy advisory panel established by Waterfront Toronto, the agency that invited Sidewalk to bid on the project, U of T privacy expert Andrew Clement warned that the proposed surveillance infrastructure in the company’s plans, combined with the sheer volume of data-sharing envisioned by Sidewalk Labs, posed clear privacy risks. ‘Function creep is a concern that may develop over time,’ he said (‘Minutes’ 2018).
Other privacy law scholars offered even more ominous warnings. Noting the risk of what she described as ‘surveillance creep,’ Ellen P. Goodman, the information policy scholar at Rutgers Law School, pointed out that Google, Sidewalk’s parent, had demonstrated a willingness to slip surveillance features into products like Nest, its front-door security system. Unbeknownst to consumers, the device came with an onboard microphone, as Google later admitted.
With Sidewalk’s plan, ‘a vendor-led project planning for a thick weave of special-purpose sensors may deploy that surveillance capability in new ways, without authorization,’ Goodman wrote in a thirty-eight-page affidavit filed as part of a 2019 Canadian Civil Liberties Association lawsuit against Waterfront Toronto. ‘This tendency for devices to expand their capabilities in the future is common in smart-city technologies’ (‘Affidavit of Ellen P. Goodman’ 2020).
In San Diego, as in Toronto with Sidewalk Labs, grassroots politics spelled the end of a smart city venture gone wrong. The smart street light controversy tapped into broader political undercurrents – about class, police power, and a mayor perceived to be indifferent to race issues. After reports that the videos on the smart nodes had been used by police to monitor the protests over the George Floyd murder in Minneapolis, the city scrambled to contain the fallout.
‘Mayor Kevin Faulconer’s decision to turn off the city’s Smart Streetlight surveillance devices until an oversight plan has been crafted and adopted makes sense,’ the San Diego Union-Tribune opined in an editorial that characterized the origins of the program as ‘bizarre’ but acknowledged the potential value of ‘tech tools’ in solving crime. ‘A city policy that clearly lays out how, when, where and if data gathered by Smart Streetlights can be used is critical’ (San Diego Union-Tribune Editorial Board 2020).
In Toronto, public response to Sidewalk’s plans was less explicitly reactive, in the sense that the backlash – from civil liberties activists, tech-skeptics, and some city officials – coalesced well before the company was able to build anything. What’s more, the public and media scrutiny of Sidewalk’s far-reaching proposal set in motion – at least temporarily – a broad-ranging discussion about the governance of smart city systems and the potential for function creep, as well as concerns about privacy and the monetization of data gathered from people moving through urban spaces. Those fears seemed to be confirmed when Sidewalk’s privacy advisor, Ann Cavoukian, a former Ontario information and privacy commissioner, quit because she felt Sidewalk’s Quayside plan lacked adequate safeguards.
Waterfront Toronto established an oversight committee to advise on digital policy matters as they pertained to a smart city project like Quayside. The city in turn set up a smart city policy consultation process. In the media, academic journals, and university classrooms, Sidewalk’s highly publicized pitch set in motion a remarkable outpouring of debate about the regulation and oversight of a family of technologies whose true capabilities were not especially well understood.
Beyond the blunt-force instrument that is politics, the question hanging over both San Diego and Toronto’s fraught experiences with smart city development is whether there are or could be more proactive approaches, either to regulation or to the design of these technologies themselves.
As tech critics in both cities pointed out, existing privacy laws, at least in Canada and the United States, weren’t equal to the task of regulating such devices. In 2019, for example, Ontario’s Information and Privacy Commissioner Brian Beamish cautioned Waterfront Toronto that Sidewalk’s plans, which envisioned brand-new governance structures and dubious legal definitions of the data it gathered within the Quayside development, didn’t conform to Ontario privacy rules. More generally, Beamish stated, ‘The provincial government must modernize our laws to ensure that privacy protective, transparent, accountable and ethical data practices are at the forefront of all smart city projects’ (Information and Privacy Commissioner of Ontario 2019).
Yet legislative action, while crucial, is only part of the picture. Some municipalities have sought to adopt a more intentional approach to procuring smart city systems specifically to head off the types of PR disasters that befell San Diego.
Barbara Swartzentruber, executive director of Guelph’s smart city office, observes that the difficulty for cities is that these technologies have become intensely polarizing: ‘Either you’re for innovation and risk, or you’re a Luddite.’ Guelph’s solution has been to set up processes designed to anticipate problems instead of reacting to crises as they’re happening. ‘It has to be an eyes-wide-open conversation,’ she says, adding that Guelph officials constantly get overtures from smart city tech firms promoting the latest solutions.
The challenge for municipalities is to not get taken in by a sales pitch and end up locking in to a complex contract that effectively gives the supplier all sorts of advantages, such as unanticipated data ownership rights. At the same time, municipal managers like Swart-zentruder want to find ways of taking advantage of new technologies that potentially improve services.
In Guelph’s case, transportation officials wanted to figure out how they could use digital cameras affixed to city vehicles to capture images and locations of potholes, cracks, and other signs of wear on the 581 kilometres of roadway within city limits. These images would assist the city in prioritizing 311 calls and making capital plans.
Guelph officials realized early on that they would have to use technology that blurs identifying details, like licence plates or faces, to ensure privacy. The municipality also asked Guelph Lab, a small civic accelerator run jointly by the city and the University of Guelph, to research the proposal. Sam Laban, the Lab’s facilitator, served up some important insights: U.S. research, he found, has shown that municipal works departments that rely on digital feedback to drive maintenance decisions don’t treat all neighbourhoods equally. The law of unintended consequences seemed to be a factor.
Some studies showed, for example, that predominantly Black communities log plenty of requests for service but tend to be underserved. Meanwhile, neighbourhoods with many newcomers generate fewer complaints and may get even less attention. ‘Equity isn’t implicit in these technologies,’ Laban says. As they scoped out the project, city officials knew they’d have to look at equity issues when vetting potential vendors in order to avoid investing in technology that serves to amplify, rather than reduce, underlying social problems. As Swartzentruber says, ‘We have to go a bit faster and the tech people have to go a bit slower, and we’ll meet in the middle.’
Other jurisdictions have engineered protections against function creep directly into their technology systems. Estonia is one of the best-known examples of widespread adoption of e-government technologies that don’t fall prey to these kinds of headaches. In 2001, the tiny Baltic state (1.3 million residents) began building what came to be known as X-Road, a national software network that knit together the information systems and databases of dozens of public agencies, state banks, and utilities.
Residents can access the entire network – from tax filings to medical records – with a single password. Changes input by citizens or public servants are automatically updated in the appropriate databases. But security and access safeguards prevent data breaches and unauthorized or unspecified uses, such as police surveillance of drivers’ licences. ‘Critically,’ observed public sector IT analysts David Eaves and Ben McGuire in Policy Options in 2019, ‘there is a mechanism for citizens to see who has accessed their data to ensure no one is doing so without proper authority.’
Some places have turned to technological solutions to fix the headaches created by some forms of smart city tech. One example is Numina, a Brooklyn-based start-up that makes ‘computer vision sensors’ that look like tall-boy beer cans strapped to utility poles. The devices can map pedestrian activity without capturing human images – an approach Numina describes as ‘intelligence without surveillance.’
The firm, which has partnered with Sidewalk Labs, says it runs the data through its analytics software to provide cities with insights about how residents are using public space – for example, recreational facilities like soccer fields in public parks or bike paths.
Numina’s technology is an example of ‘edge computing.’ The term is used to describe highly decentralized computer networks where the heavy computational lifting takes place at the edges rather than in a mainframe processor. In the case of Numina, the beer can–shaped sensors have enough onboard computing power to be able to take a measure of the activity on a given sports field, for example, and they’re also set up to obscure details that might identify individuals. All the readings are fed into a central system so Numina’s clients, such as the managers of municipal parks, can get a bigger picture of what’s going on – as with charts that track the changing volume of bikes on a bike path during the course of a week. The company says its technology is intended to help municipalities plan and operate these amenities based on actual traffic counts that can be generated without compromising any individual’s privacy.
This approach, known as ‘security by obscurity,’ might head off the kind of controversy that engulfed San Diego’s smart lighting project. Yet issues of privacy, surveillance, and the financialization of data collected intentionally or incidentally from people moving through public spaces are ultimately not technical questions to be solved with better technology. Nor are they simply legal questions.
The promise of so much smart city technology rests on its claim to take a close measure of urban spaces and systems, and then use those readings – in whatever form they may be – as a means of tackling urban problems. But as quantum physicists postulated well over a century ago, the act of observation is neither neutral nor passive. Rather, observation itself can alter that which is being observed, as those innocuous plastic nodes perched at the top of San Diego light standards proved.
12. It is also possible to innovate processes, such as the production of a magazine or the approval of a building permit.