Is Wi-Fi Sensing The Most Privacy Invasive Technology of the Year?
And Can You Even Withhold Consent for Normalized Ambient Surveillance?
At some point in the last decade, the modern home quietly stopped being a place and became a product. Not in the philosophical sense, in the practical sense. Your thermostat became a subscription. Your doorbell became a cloud service. Your lightbulbs started demanding firmware updates like tiny unionized employees.
And now your WiFi is trying to become a sensor.
Not a sensor you installed. A sensor you inherited, because you wanted wireless internet and the world decided that meant you must also want a home that can detect bodies.
This is WiFi sensing: the use of ordinary wireless signals to infer what is happening in a space. Presence. Movement. Patterns of activity. In some demonstrations and deployments, even breathing and pulse. No camera required, which is exactly why it is selling so well. Cameras have a public relations problem. Radio waves do not. Radio waves feel like weather. Something you live inside, not something that is done to you.
That is the trick, and it is the reason we are sleepwalking into the most intimate form of infrastructure surveillance we have ever normalized.
How we got here, one “helpful feature” at a time
Surveillance almost never arrives as a villain. It arrives as a convenience. It arrives like a polite person holding a door open, then quietly stepping into your house behind you.
The progression is familiar if you look at it honestly.
First we accepted connectivity everywhere. Then we accepted sensors everywhere. Then we accepted the fusion of the two, because the marketing told us it was safer, smarter, more efficient.
There were milestones.
We accepted always-on phones. We accepted smart speakers that sit in our kitchens, waiting patiently for the wake word like a well-trained informant. We accepted apps that want location access because the weather is apparently impossible to forecast without knowing which aisle of the grocery store we are standing in.
Then the smart home wave hit, and a new logic took over: if the home could sense us, it could serve us. Lights could turn on. Heating could adjust. Security could “help.”
That is the moment the idea of environmental inference became socially acceptable. Once you accept a house that detects presence, the only remaining debate is what technology is used to detect it, and whether the detection is “creepy.” WiFi sensing markets itself as the non creepy option because it is not a camera.
But “not a camera” is not the same thing as “not surveillance.” It is simply surveillance that does not look like surveillance.
The technical idea in plain language
WiFi is radio. Radio waves leave an antenna, bounce around your home, and arrive at another antenna after being shaped by the environment. Walls reflect them. Furniture scatters them. Human bodies absorb and reflect them in distinct ways.
If you measure how the wireless channel changes over time, you can infer movement. If you measure it carefully and combine it with increasingly capable models, you can infer more than movement.
That is the essence of WiFi sensing. It is not magic. It is physics, measurement, and pattern recognition.
This concept has been studied for years in academic and industry research. What changed recently is not feasibility. It’s standardization.
The moment it stops being research and becomes plumbing
IEEE 802.11 is the standards family behind WiFi. Inside that world, there is now a specific effort focused on wireless local area network sensing: IEEE 802.11bf. Remember that name.
This matters because once something becomes a standard, it becomes part of the default future. Standards are not just technical agreements. They are adoption engines. They make it easier for chipmakers, device makers, and network operators to build interoperable products at scale. They make it easier for “optional” to become “everywhere.”
The 802.11bf Project Authorization Request was approved in September 2020. Task Group bf exists to define how WiFi devices can use physical layer and medium access control features to obtain measurements useful for estimating features of objects in an area of interest. The leadership roster is a reminder that this is not fringe activity. It is mainstream industry and platform participation, including names tied to major companies. This is the center of the ecosystem, not the edges.
Once the sensing mechanisms are standardized, the path is predictable. Router platforms ship it. Firmware exposes it. Apps wrap it in a friendly interface. Somebody offers a premium tier that includes “insights,” “alerts,” or “wellness.”
Then it becomes normal to live inside a network that can model the bodies within it.
Why anyone would want this, and why that is not reassuring
There are legitimate use cases. That is what makes it dangerous, because legitimate use cases are the vehicle that gets a capability into the world.
Home security is the obvious pitch. Motion alerts without cameras. Peace of mind without the feeling of being filmed. That sounds great until you notice what it requires: a system that can detect and interpret movement through signal changes and that can log those events.
Elder care is the second pitch. Fall detection without wearables. Sleep monitoring without sensors stuck to the body. “Non intrusive” health monitoring is the phrase that gets repeated because it sounds humane. It can be, in narrow contexts, with strict safeguards.
Energy management is another pitch. If a building can estimate occupancy, it can tune heating and cooling. That sounds like sustainability until you realize it is also a way to build a minute by minute map of human presence and activity in a private space.
Retail and commercial property analytics are the quiet pitch. Not the public pitch, the boardroom pitch. Foot traffic measurement has existed for years using cameras, WiFi probe requests, Bluetooth beacons, and loyalty apps. WiFi sensing adds something richer: not just that a device passed by, but how bodies move within a space, how long they linger, and potentially how groups flow and cluster.
All of these are plausible. None of them are worth the default creation of a new class of intimate telemetry.
Because the moment you create telemetry, you create incentives. And those incentives do not stop at “helpful.”
Why data brokers love the idea of a world that never stops measuring
Data brokers thrive on scale, linkage, and inference.
Scale: WiFi is everywhere. Turn WiFi into sensing and you have the broadest possible sensor network without installing new sensors.
Linkage: routers are managed through accounts. ISP gateways are tied to customer identities and addresses. Even if a system claims it does not identify individuals, the business systems around it are already doing identity work.
Inference: presence and motion patterns are not just events. They are signals about life. Sleep habits. Work routines. Whether someone is home alone. Whether a household is stable or chaotic. Whether someone is ill, elderly, or struggling. Whether an apartment is occupied beyond the lease terms. Whether a worker is at their desk.
Data brokers do not need perfect truth. They need probabilities that can be sold. They need categories that can be targeted. They need a new stream to enrich existing profiles.
If you want a real world reference point for what happens when sensitive data becomes commercially tradable, look at the location data ecosystem. In January 2024, the US Federal Trade Commission prohibited data broker X Mode and its successor Outlogic from selling sensitive location data after allegations that it sold precise location data tied to visits to sensitive places like clinics and shelters. That case is not about WiFi sensing. It is about the predictable life cycle of “useful data” in a market that rewards collection and resale.
WiFi sensing is the next rung up the ladder because it moves from “where you went” to “what happened around your body in space.”
Private attributes leak even when you think you only collected “motion”
A lot of the public debate about WiFi sensing gets stuck at the “it can tell someone is in the room” level. That is already invasive. It also understates the problem.
Once you start treating the wireless channel as a sensor, you do not only collect presence. You collect a body interacting with radio waves, and bodies have measurable signatures. Researchers have shown that it is possible to infer private attributes from WiFi sensing data, including gender with extremely high accuracy, and physical characteristics like height and weight with surprisingly small error margins. The important part is not the exact percentage in a lab. The important part is the direction of travel: “anonymous motion data” can still carry identity adjacent information.
That matters for two reasons.
First, it erodes the comforting claim that sensing data is harmless because it is not video. It is not video, but it is still a measurement of you.
Second, it gives data brokers and insurers the thing they really want: features. Not “a person moved,” but “this looks like the same person,” or “this looks like a certain kind of person,” or “this household’s pattern looks like a health or risk signal.” The surveillance economy runs on inference. WiFi sensing is inference fuel.
The civil liberties problem is not your home, it is everywhere else
In your home, you can at least pretend you have agency. You can choose equipment. You can turn off a feature. You can decide not to buy the newest thing.
In public spaces, consent collapses.
If WiFi sensing becomes mainstream, then any building with WiFi can become a building that detects bodies. Offices. Schools. Airports. Cafes. Waiting rooms. Libraries. Hospitals. Rental buildings. Shelters. Religious spaces. Transit hubs.
This is where it becomes a civil liberties issue rather than a gadget issue. Because in public and semi public spaces, you cannot realistically opt out. You can leave, but leaving is not a civil liberty. It is exile.
Even worse, WiFi sensing is easy to hide. Cameras trigger social friction and legal scrutiny. A router does not. It sits in a closet blinking politely while it does its other job.
And there is a darker edge: sensing can be passive. Research from Karlsruhe Institute of Technology was publicized in October 2025 warning about the ability to infer identity by passively recording WiFi communications in radio networks, without the target carrying a WiFi device. Whether or not every aspect of that research becomes widely deployed tomorrow, it highlights the trajectory: the radio environment itself is increasingly readable.
A society where the ambient radio layer becomes a continuous sensing layer is a society where anonymity becomes conditional.
When sensing turns into identity, the floor drops out
There is a second escalation that changes the stakes. It is the move from sensing to identification.
In the simplest commercial form, companies can already link sensing events to people through account level infrastructure. Your ISP gateway is tied to your name and address. Your app login ties alerts to a household. Even if the sensing model never “recognizes” you, the business systems around it already do.
But research has been pushing beyond linkage. Some recent work describes ways to use channel measurements as a kind of fingerprint, distinguishing individuals based on how their presence disrupts WiFi patterns. Other work has demonstrated surprisingly detailed person perception using WiFi signals, including body segmentation and pose estimation. You do not need perfect recognition for the civil liberties consequences to show up. You only need “good enough to separate and track.”
Now imagine this capability in a public space.
A mall does not need your face to follow you. It can estimate that you are the same person who passed the cosmetics aisle last week. An office does not need cameras to know which floors are active late and which teams are “under present.” A landlord does not need a key log to infer whether a unit is occupied “more than expected.” A transit hub does not need turnstiles to model crowd movement and identify unusual patterns.
This is how tracking becomes ambient. No opt in. No obvious sensor. No easy way to refuse. Just the radio environment quietly turning into a database of bodies.
What the immediate future looks like, with names and dates
This is not theoretical. Pieces are already in market.
Comcast’s Xfinity has promoted WiFi Motion as a feature that detects movement using signal disruptions between a gateway and other stationary devices, managed in the Xfinity app.
In Canada, Rogers provides guidance for using WiFi based motion sensing inside the Rogers Xfinity app, explicitly positioning it as not professionally monitored but still a motion detection capability delivered through the network infrastructure.
In the United Kingdom, Vodafone announced a “Who’s Home” feature tied to its Ultra Hub 7 router in December 2025, framed as alerts when loved ones arrive home, managed through the Vodafone app.
Quick clarification: not all “who is home” features are WiFi sensing
Some products infer presence because a person’s phone connects to the home network. That is tracking by association.
WiFi sensing is different. It infers motion and presence from changes in radio propagation, even when you are not actively using a device. This is the shift that matters, because it turns connectivity infrastructure into a sensor layer.
Keeping the distinction clear helps, because the end result can look similar to consumers, while the privacy consequences are not the same.
These examples matter because they show how the idea is being normalized. It is being framed as family convenience and safety. It is being embedded in ISP relationships. It is being delivered through the same gateway device you rent or receive as part of service.
Now add adoption forecasts. ABI Research projects that WiFi sensing compatible customer premises equipment in North America will grow rapidly between 2024 and 2030, reaching 112 million installed units by 2030. That is not a hobbyist market. That is mass infrastructure.
And add the standardization timeline. Academic and industry publications describe the 802.11bf effort as a multi year process, with the foundational authorization in September 2020. NIST has published technical work on the standard’s role in enabling widespread adoption.
This is why the right question is not “will it arrive.” The right question is “how fast will it become default, and what safeguards will exist before that happens.”
Canada vs Europe vs the United States: how regulators are likely to respond
This is where the story gets interesting, because regulatory culture shapes what companies dare to do.
Canada: cautious principles, uneven enforcement, Quebec as the gravity well
Canada’s federal private sector privacy law, PIPEDA, is built around meaningful consent, purpose limitation, and proportionality. The Office of the Privacy Commissioner of Canada has published guidance warning that lengthy legalistic policies can make control illusory and emphasizes the need for meaningful consent.
In a world of WiFi sensing, “meaningful consent” becomes the stress test. It is one thing to ask consent for an email address. It is another thing to ask consent for ambient motion inference that can reveal patterns of life. If the feature is bundled into ISP apps and buried in settings, that is where complaints should land.
The complication is that federal reform has been slow. Bill C 27 was positioned as a major modernization step, and the OPC has called it an important step while suggesting improvements. But the practical impact today is that Canada remains a mix of principles and enforcement limits.
Quebec changes the picture. Law 25 has already raised the bar in Canada, with staged implementation and significant obligations. The data portability right came into force in September 2024. The Commission d’accès à l’information is a serious regulator with a mandate to enforce.
That means Canadian companies often end up designing to Quebec’s stricter expectations because it is harder to maintain separate systems. In practice, Quebec can pull the national market toward more European style accountability, even if the rest of Canada is still waiting for federal modernization.
So Canada’s likely posture is mixed. Expect stronger scrutiny and governance pressure in Quebec. Expect more uneven outcomes elsewhere unless the OPC takes an aggressive stance or federal reform lands with real enforcement teeth.
Europe: stricter law, clearer concepts, less patience for “we did not mean it”
Europe is better positioned to treat WiFi sensing as what it is: tracking and inference.
Under GDPR, if sensing data relates to an identifiable person, it is personal data. If it reveals health related patterns, it may drift toward special category data, which triggers stricter conditions. Even if vendors try to claim anonymization, household accounts and device identifiers make identifiability arguments tricky.
The ePrivacy Directive adds another layer by focusing on confidentiality of communications and restrictions on interception and access to information in terminal equipment. The European Data Protection Board has also issued guidance on tracking techniques covered by the ePrivacy Directive, emphasizing that new and emerging tracking methods can seriously harm privacy and require legal clarity.
In plain language: Europe already has conceptual tools to regulate “we are tracking you without cookies.” WiFi sensing fits neatly into the category of tracking that is not obviously visible to the user. That is the kind of thing European regulators love to make expensive.
Add the EU AI Act, which entered into force on 1 August 2024. Many sensing systems rely on AI models to classify activity and infer states. If those inferences are used in sensitive settings like employment monitoring, access control, or other high impact contexts, the compliance obligations rise.
So Europe’s likely posture is skeptical and structured. Expect demands for explicit transparency, clear lawful basis, strict minimization, short retention, and limits on public space deployments where consent is not meaningful. Expect enforcement that can hurt, because GDPR penalties exist.
United States: fast market, patchwork law, enforcement after the damage
The United States tends to regulate privacy the way it regulates potholes: after the car breaks an axle, somebody files a complaint, and then you get a warning sign.
There is no comprehensive federal privacy law. The FTC is the main federal enforcer using consumer protection authority. That makes it capable of important actions, like the X Mode and Outlogic case, but it is still reactive and case based.
States are filling gaps. California’s privacy framework explicitly defines “sensitive personal information” and includes precise geolocation, with rights to limit certain uses. That offers leverage if WiFi sensing data becomes clearly categorized as sensitive, or if it produces inferences that relate to health, location, or intimate life patterns.
But the US market remains structurally friendly to collection and monetization, especially when a technology can claim it is not a camera and not a biometric scanner. That semantic gap is where companies sprint.
So America’s likely posture is uneven. Expect rapid deployment through ISPs and consumer products. Expect privacy fights to happen through investigative journalism, local activism, and selective enforcement rather than consistent national rules.
How bad can it get, and how soon
It can get very bad very quickly, mostly because the path is not “sensing exists.” The path is “sensing becomes normal.”
Once a capability becomes standard and common, it will be used beyond its initial purpose. That is not cynicism, it is history.
Short term, you see household features that provide motion alerts and occupancy awareness.
Medium term, you see commercial deployments for space analytics and workforce monitoring dressed up as efficiency and safety.
Long term, you see a society where the radio environment is a continuous measurement layer, with weak consent, weak transparency, and strong incentives to retain and share data.
The most dangerous part is not a single feature. It is the idea that a building can measure bodies by default, with no visible sensor and no meaningful opt out.
That is how surveillance states become boring.
How to fight back without scaring people into giving up
You asked for awareness without alienation. That means telling the truth without sneering at the audience. People adopted smart homes for understandable reasons. They wanted convenience. They wanted safety. They wanted to care for family members. None of that makes them foolish.
The goal is to make the tradeoffs legible and to demand guardrails.
Here are practical actions that work in the real world.
- Ask your ISP a direct question
Ask whether your gateway supports WiFi motion or sensing features. Ask whether it logs motion events. Ask how long it keeps them. Ask whether data is shared with affiliates or third parties. Do this in writing. - Turn features off, then document the experience
If your ISP or router platform offers WiFi motion features, disable them. Screenshot the settings screens. Note how hard it is to find. That documentation becomes useful for regulators and journalists. - File complaints where they matter
In Canada, file a complaint with the Office of the Privacy Commissioner if you believe meaningful consent is not being obtained or if disclosures are inadequate under PIPEDA. In Quebec, use the Commission d’accès à l’information for Law 25 issues. In Europe, file with your national Data Protection Authority. In the US, file with the FTC and your state attorney general, and if you are in California, use the mechanisms supported by the California Privacy Protection Agency regime. - Push for a simple regulatory principle
Treat WiFi sensing data as sensitive by default. Not “sometimes.” Not “if combined.” By default. It is behavioral and potentially health adjacent telemetry about people in physical space. - Demand hard defaults
Default off. Local processing. No retention unless strictly necessary. No sharing. Clear on device indicators when sensing is enabled. A physical toggle is not too much to ask when the system is effectively an environmental sensor. - Draw a bright line for public spaces
Advocate for bans or strict permit regimes for WiFi sensing in public and semi public spaces like transit, schools, shelters, and government buildings, unless there is a clearly justified purpose, strong oversight, and meaningful public notice. “Because we can” is not a public interest justification. - Aim at the standard setters, not just the vendors
Standards bodies respond to sustained pressure from civil society and regulators. If 802.11bf becomes the foundation, privacy requirements should not be treated as optional add ons. They should be built into expectations around transparency and control.
If you want the most honest summary, it is this: the best privacy protection is not a better privacy policy. It is refusing to build systems that create intimate data streams in the first place.
WiFi does not need to become a body sensor. It is being steered in that direction because there is money in inference and because the world is full of data brokers salivating at the thought of extending behavioural change and individual influence into our bathrooms.
That is not paranoia. That is the current business model, as of September 2025. The question is, what are we going to do about it?
For more interesting takes on Wi-Fi sensing, look these up (with your favourite, privacy-enhancing search engine):
- “An investigation of the private attribute leakage in WiFi sensing” (ScienceDirect, 2024).
- “Wi-Fi signals could be used to uniquely identify individuals (WhoFi)” (TechRadar, 2025).
- “Person in WiFi: Fine grained Person Perception using WiFi” (arXiv, 2019).
- Karlsruhe Institute of Technology press release on passive radio network surveillance (October 2025)
- “A Survey on Secure WiFi Sensing Technology: Attacks and Defenses” (Sensors, MDPI, 2025).
