Nverg:~$ _

BVG wants AI to detect danger on U-Bahn platforms. It hasn't written down what danger looks like. (like literally)

4 min read  1.2×

The track cameras make sense. As an active resident of Berlin, Charlottenburg specifically, I mostly ride the U2, which is about as calm as this network gets, and I've still had friends and family visiting the city for the first time run into moments over the last year or so where they felt unsafe from time to time. Forty-four intrusions flagged in two months, six unauthorized access alarms, in spaces the public doesn't belong in. [2] That's a contained use case with a measurable outcome. Someone on the tracks is wrong by definition. The camera doesn't have to make a judgment call. It just has to recognize a human in a space where no human should be.

The expansion is something different.

BVG announced it is extending AI camera coverage from 16 to 23 U-Bahn stations by the end of the year. [2] The new layer detects "potential dangers based on movement patterns" in public spaces. Our beloved "Kotti" a.k.a. Kottbusser Tor first, then Warschauer Straße. The cameras are moving from areas with a clear trespass threshold into platforms where everyone belongs, and where everyone now has to be assessed.

from non-public to public is not a small step

The threshold problem is the whole thing. A track intrusion system has a binary input: human presence in a restricted space. The new system takes something much harder and asks it to infer intent. What movement pattern is dangerous? At what threshold? Reviewed by whom, on what timeline, with what escalation path?

None of that is published. BVG has described the capability but not the criteria. That gap is where the errors happen.

Wrong platform, wrong hour. I understand what the cameras are trying to address. The concern is not the cameras. The concern is that "potential dangers based on movement patterns" is a capability description, not an operational one. Something underneath it defines what gets flagged. That something was written by someone, or derived from a training set, or set as a parameter. It is not public.

the vendor question

The contract went to Adesso SE, a large German IT consultancy. [2] Between 2022 and 2023, Adesso suffered a serious cyberattack. Attackers had substantial access to their internal systems for an extended period. The full scope was never publicly disclosed.

A prior breach is not a permanent disqualifier. Companies get breached. What matters afterward is the remediation: what was found, what was exposed, what was hardened, and whether the documentation to prove that exists. The question for BVG's procurement process is whether any of that was assessed and recorded before the contract was signed.

If you are building infrastructure that processes behavioral data on millions of transit users daily, your vendor's security posture is part of your own risk surface. That assessment belongs in a procurement record, not assumed away.

what the EU AI Act requires here

Behavioral pattern detection in publicly accessible spaces sits in contested territory under the Act. Article 5 restricts certain real-time biometric categorization systems in public spaces. [1] Annex III covers AI systems used as safety components in transportation infrastructure and attaches high-risk obligations to them: technical documentation, human oversight requirements, accuracy and robustness testing, registration in the EU database before deployment. [1]

BVG is already in talks with the Berlin data protection commissioner. [2] That conversation exists because someone recognized the legal question is open. What is not clear from public reporting is whether the system has been assessed against high-risk requirements, whether conformity documentation has been filed, or whether the Act's obligations are factored into the deployment timeline at all.

The Act's obligations are not advisory. If this system meets the Annex III threshold (behavioral detection in public transit infrastructure is a reasonable candidate), the documentation requirements apply before the cameras go live in public spaces, not after.

what this looks like from where I sit

Berlin's metro is not a polished place. That is part of what makes it the city it is. The people who make others feel unsafe are often the same people the city has failed to support in other ways. A camera does not change that. A camera with a clear, documented, externally reviewable definition of what it flags is at minimum honest about what it is doing.

The track intrusion system had that. Measurable scope, clear use case, two months of data showing it worked. The behavioral expansion has a headline and a starting station. The audit question is whether the definition, the vendor assessment, and the regulatory documentation are somewhere other than the press release.

references

  1. EU AI Act Annex III
  2. BVG Plans to Expand AI Surveillance Cameras — The Berliner
← back