Two reports landed within days of each other this week, and read together they describe something bigger than either one alone: the construction of a permanent, automated, always-on aerial and tower-based surveillance layer over large parts of the United States.
Neither is secret. Both are funded through ordinary appropriations and approved through ordinary regulatory channels. That’s the notable part.
The towers: 830 → 2,300
A Government Accountability Office report reveals that the Department of Homeland Security plans to nearly triple the number of surveillance towers along US borders — from 830 today to 2,300 by 2034.
The expansion carries roughly $1 billion in funding, sourced from the tax and spending law signed in 2025.
The Integrated Surveillance Tower (IST) program covers three technology families:
- Autonomous surveillance towers — AI-driven systems combining radar, thermal infrared, and optical sensors to detect and track targets at long range with no human operator required for detection
- Integrated fixed towers — optimized for surveilling foot traffic and vehicles
- Remote video surveillance systems — the older, human-monitored camera installations
And these towers are not the whole apparatus. The border surveillance stack also includes drones, tethered aerostats, surveillance vehicles, buried ground sensors, camouflaged game cameras, and license plate readers.
Six out of six
The GAO assessment includes a finding that deserves to be quoted rather than paraphrased: Customs and Border Protection failed to address six out of six main privacy protections for surveillance towers, aerostats, and ground sensors.
Six out of six. Not a partial score, not a mixed record — a complete miss on every baseline privacy requirement evaluated, for a system being expanded nearly threefold.
The standards in question are not exotic. They are the ordinary machinery of federal privacy compliance: privacy impact assessments completed before deployment, systems of records notices published, retention schedules defined, access controls documented, data-sharing agreements governed, and oversight mechanisms established. These are the minimum procedural commitments the government makes to itself about surveillance technology.
Who actually lives under them
The standard mental image of “border surveillance” is empty desert. That image is wrong in a way that matters.
The federal government treats a zone extending 100 air miles inward from any external boundary — including coastlines — as the border region for certain enforcement purposes. That zone contains roughly two-thirds of the US population and includes most of the country’s largest cities.
The towers themselves cluster nearer the physical border, but “nearer the border” still means densely populated communities: El Paso, San Diego, Brownsville, Laredo, Nogales, Detroit, Buffalo. Hundreds of thousands of American citizens live and work within sensor range.
As the EFF put it, these systems operate “indiscriminately trained on towns, school playgrounds, backyards, and vehicles.” An autonomous tower with thermal and optical sensors that can track targets over long distances does not distinguish between a border crossing and a family barbecue. It records both, and the retention policy governing which one gets kept is — per GAO — among the things CBP hasn’t adequately addressed.
The drones: 1,000+ agencies cleared to fly
The second development is happening in ordinary American towns, and moving faster.
Drone-as-first-responder (DFR) programs dispatch an autonomous drone to a 911 call, often arriving well before a patrol car. The drone launches from an automated docking station on a municipal rooftop, flies the route itself, and streams video back to a dispatcher — with a single operator supervising several aircraft at once.
By February 2026, over 1,000 public safety agencies held the FAA Part 91 waivers required to automate drone operations. And the growth curve is the story: after the FAA streamlined its approval process in April 2025, it issued more waivers in ten months than in the previous seven years combined — the first DFR program having launched back in 2018.
That is a regulatory bottleneck opening, and a market rushing through it.
Who’s selling
Flock Safety and Axon dominate. Axon describes its DFR platform as one of the company’s fastest-growing sectors. Flock — already operator of one of the largest automatic license plate reader networks in the country — has converted drones into flying ALPRs.
That convergence is the point worth flagging. Flock’s value proposition was never the individual camera; it was the network — a searchable, cross-jurisdictional index of vehicle movements. Putting that capability on an aircraft removes the constraint that made fixed ALPRs tolerable to some: cameras had to be somewhere in particular, mounted on a pole, at a known intersection. A drone-mounted reader goes where it’s sent.
Drone footage then integrates with ALPR databases and the rest of the surveillance stack. The data doesn’t sit in an isolated silo; it joins.
What they’re actually used for
Agencies justify DFR programs with high-risk scenarios: active shooters, armed suspects, missing persons, fires. The deployment data tells a different story.
Analysis of Chula Vista, California — the longest-running and most-studied DFR program in the country — found that most deployments involved low-risk calls for service related to unhoused people, mental health concerns, and loud music.
That is a familiar trajectory. A capability is procured for the extreme case, then absorbed into routine operations because it is available and cheap to use. The marginal cost of launching a drone that’s already sitting on a dock, charged, on an automated flight path is close to zero — and technologies with near-zero marginal cost of use get used constantly.
The specific privacy problem with drones
Drones see what patrol officers structurally cannot. An officer walking a beat sees the street. A drone at altitude sees backyards, rooftops, patios, and through upper-story windows — spaces where the expectation of privacy is at its highest and where physical barriers like fences and hedges exist precisely to establish it.
A fence is a legally meaningful privacy assertion. Aerial surveillance renders it decorative.
The San Francisco Police Department’s drone footage leak demonstrated the concrete risk: the ease with which routine flights capture footage of people who were never the subject of any call, and the ease with which that footage subsequently escapes.
Why these two stories belong together
Border towers and municipal drones are administered by different agencies, funded by different mechanisms, and justified by different threats. They share four properties:
- Autonomy. Detection and tracking happen without a human deciding to look. The human enters after the machine has flagged something.
- Persistence. These are not deployments in response to events. They are always on.
- Integration. Tower feeds, drone footage, ALPR hits, and ground sensor data flow into shared systems and become jointly searchable.
- Procedural deficit. The GAO found CBP missing six of six privacy protections; most DFR programs launched with no advance public notice at all.
The combination — automatic, permanent, networked, ungoverned — describes infrastructure, not tactics. Infrastructure gets built once and stays for decades.
What can actually be done
Individual countermeasures are limited against this category. The leverage is procedural and local.
- CCOPS ordinances. California’s AB 481 model requires law enforcement to publish a use policy, obtain governing-body approval before acquiring surveillance technology, and file annual reports. Community Control Over Police Surveillance ordinances exist in dozens of cities and work on the same principle: the decision point is procurement, not deployment. Once a system is bought and operating, reversing it is enormously harder.
- Show up to the vote. DFR programs are approved in city council meetings, usually as consent-agenda line items with minimal discussion. That meeting is the entire window for public input.
- Demand the annual reports. Where reporting requirements exist, request the data. Chula Vista’s deployment statistics only exist as a public argument because someone insisted on the numbers.
- Support the FOIA work. EFF’s Atlas of Surveillance and similar projects map who has what. You cannot organize against a system you can’t see.
The pattern
There is a version of the surveillance debate that focuses on secret programs and undisclosed capabilities. That debate matters. But the larger buildout of 2026 isn’t secret at all.
The towers are in a GAO report. The funding is in a public appropriation. The FAA waivers are a matter of record. The vendors publish case studies and win awards. Everything about this expansion is documented, approved, and available to anyone who goes looking.
It proceeds anyway, because documentation is not the same as consent, and because the procedural safeguards that were supposed to convert one into the other — the privacy impact assessments, the retention schedules, the oversight mechanisms — turn out to be optional in practice. Six out of six.
The window to influence infrastructure is before it’s poured. On this one, the pour is scheduled through 2034.
Sources:
- An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion — EFF
- Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country — EFF
- GAO-26-107501: U.S. Customs and Border Protection — Resources Deployed and Challenges Faced
- Customs & Border Protection Fails Baseline Privacy Requirements for Surveillance Technology — EFF



