Russian-linked face recognition is suppressing Georgian protesters. The EU's silence on this speaks volumes about what the AI Act must still defend.
elcome to issue nine. This week the most chilling story in our inbox comes not from Brussels but from Tbilisi, where a Moscow-based company with FSB ties has helped build a face recognition enforcement system that is being used to silence Georgian demonstrators. Meanwhile, EFF is challenging Paraguay's secret use of facial recognition at the Inter-American Commission on Human Rights, and California is pushing ahead with a 3D-printer surveillance mandate that experts say is both dangerous and technically unworkable. The pattern is the same one we have been tracking all year: surveillance infrastructure goes up fast, accountability comes slowly or not at all.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We have added a vendor provenance checklist to the Flux compliance scan, covering FSB-linked and state-affiliated supplier flags following this week's Georgia investigation.
- Updated The Flux prohibited-practices explainer has been updated to reflect how real-time remote biometric identification bans apply when a tool is procured by a non-EU government but built on components from EU-based suppliers.
- ICYMI In case you missed last week: the AI Omnibus analysis from AlgorithmWatch and European civil society organisations is still the single best briefing document on what the proposed changes actually remove from the current AI Act text.
Russian FSB-linked surveillance software is tracking and silencing Georgian protesters using face recognition at scale

What happened, and why it matters beyond Georgia. AlgorithmWatch has published an investigation showing that the Georgian government procured a comprehensive face recognition enforcement system from a Moscow-based company with documented ties to the FSB, Russia's federal security service. Over two years, that system has been used to identify, track, and suppress civilian demonstrators. The findings are a direct, real-world demonstration of what the EU AI Act classifies as a prohibited practice: real-time remote biometric identification used for political surveillance.
The EU AI Act connection is not abstract. The Act bans real-time remote biometric surveillance in public spaces for law enforcement purposes, with narrow exceptions. Georgia is not an EU member state, so the Act does not apply directly. But the case shows exactly the harm the drafters had in mind, and it arrives at a moment when the AI Omnibus is proposing to water down enforcement mechanisms. If you are an operator procuring biometric or surveillance tools, this story is a live illustration of the risk category you are buying into.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓AlgorithmWatch's Georgia investigation puts pressure on EU institutions to clarify how export controls and the AI Act's prohibited-practices list apply to surveillance tools sold near EU borders.
- ✓EFF's Inter-American Commission complaint against Paraguay over secret face recognition use adds to a growing body of international human rights precedent that EU regulators are watching closely.
- ✓No new official EU Commission guidance published this week, keeping operators in a holding pattern as the Omnibus negotiations continue behind closed doors.
- ~Georgia's FSB-linked face recognition enforcement system exposed by AlgorithmWatch after two years of documented use against civilian protesters.


- 1AlgorithmWatch: Seen and Silencedinvestigation
The full Georgia investigation detailing two years of FSB-linked face recognition use against protesters.
Why we like it. The most concrete, documented example this year of the exact harm the AI Act's prohibited-practices list was designed to prevent.
- 2EFF: Face Recognition Complaints Hublegal tracker
EFF's running log of legal challenges and complaints against government face recognition deployments worldwide.
Why we like it. Gives EU operators a global map of where accountability actions are succeeding and what arguments are landing.
- 3AlgorithmWatch: Scored and Silenced (Kenya)worker rights

The harm was never hypothetical. It was always just somewhere else.
By John Ferguson
I have spent a lot of time this year explaining to operators why the AI Act's prohibited-practices list matters. The most common pushback is: who is actually going to do this? Who is genuinely going to run a face recognition dragnet on protesters? This week, AlgorithmWatch answered that question.
Georgia. Two years. An FSB-linked supplier. Demonstrators identified, tracked, and silenced. The harm was not hypothetical. It was just happening somewhere that was not generating headlines until now.
The Georgia case is not an argument for panic. It is an argument for taking vendor provenance seriously in a way that most procurement checklists do not yet do. Knowing whether your AI components were trained, maintained, or distributed by state-adjacent entities in authoritarian regimes is not paranoia. It is due diligence.
517 days until high-risk rules apply. The summer break is coming, and it is tempting to let compliance drift. Do not let the vendor provenance question be the thing you meant to check and never did.
John Ferguson · Founder, Agentic Fluxus

Short answer.Start with your vendor's ownership and supply chain. Ask them directly whether any components, models, or data services originate from sanctioned-country affiliates. Then check whether face recognition is switched on by default or opt-in. Under the AI Act, deploying real-time face recognition as a deployer makes you jointly responsible. Disable the feature until you have a clear answer and a written record.
Has the Georgia story changed how you think about vetting AI surveillance vendors?

Georgia's government ran an FSB-linked face recognition system on civilian protesters for two full years before an international investigation exposed it. The system was procured, deployed, and used without any public transparency process.
Paraguay has been operating a face recognition system while arbitrarily denying any public access to information about how it works or who it targets. EFF, TEDIC, and CEJIL have now taken the case to the Inter-American Commission on Human Rights.

