# Twenty-five years after 9/11: who now decides how much surveillance is too much?
**Date de l'événement :** 09/09/2026
* Publié le 09/09/2026

### Date
09/09/2026

## Chapô
**Cet article est aussi [disponible en Français](https://conference.sciencespo.fr/content/2026-09-09/vingt-cinq-ans-apres-le-11-septembre-qui-decide-aujourd-hui-du-seuil-de-surveillance-acceptable_XNACagFGAD7OUtfPw8pa).** 

**Twenty-five years after the attacks of September 11, 2001, democracies continue to grapple with the balance between security and liberty, even as a growing share of security-related decisions has shifted to private actors. Ivan Manokha, Professor of International Relations and Politics at Schiller International University in Paris, whose research focuses on surveillance, digital technologies, security practices and the political economy of data, and who also teaches at Sciences Po, revisits these issues to show how 9/11 represented less a rupture than one stage in a gradual transformation of surveillance practices. As banks, airlines, telecommunications operators and digital platforms are increasingly required to assess risks themselves and set certain thresholds of precaution, who is ultimately responsible for deciding how far security may encroach on individual freedoms?**

## Corps du texte
Twenty-five years after the attacks of 11 September 2001, the familiar question is whether democracies traded too much liberty for security. Ivan Manokha, Professor of International Relations and Politics at Schiller International University in Paris, argues that this framing misses a quieter transformation. The post-9/11 years did not only expand surveillance and preventive security; they also moved many security judgements into private entities such as banks, airlines, telecommunications companies and digital platforms. When public authorities set the risk environment but private organisations decide where to draw the line in individual cases, who is responsible for deciding how much precaution is too much?  

There is a familiar way of telling the story of the last twenty-five years. On 26 October 2001, six weeks after the attacks, the USA PATRIOT Act was signed into law. Britain adopted the Anti-terrorism, Crime and Security Act before the end of the same year. France, which had already developed a substantial anti-terrorism apparatus from the mid-1980s onwards, added further measures and, after the attacks of November 2015, lived under a state of emergency until November 2017. In June 2013, the documents disclosed by Edward Snowden revealed the scale of surveillance programmes operated by the National Security Agency and its Five Eyes partners. On this account, the central development after 2001 was an expansion of state power, and the anniversary invites us to ask whether democracies accepted too much surveillance in return for security.  

This account is accurate, but it remains incomplete. The post-2001 transformation was also institutional: security increasingly came to be produced through organisations whose primary function was not security, e.g., banking, transport, telecommunications or digital communication. Now, this did not begin on 11 September; indeed, anti-money-laundering rules already relied on banks, and European carrier-liability rules predated the attacks. What changed after 2001 was the centrality of this form of governing and, above all, this new kind of task private organisations were expected to perform. They were increasingly asked to identify risk, interpret uncertain signals and act before the feared event occurred.  

### Security moved into ordinary organisations  

Let us consider what happened in finance. Title III of the PATRIOT Act placed important obligations on financial institutions, including customer-identification requirements and new arrangements for information sharing. On 28 September 2001, the United Nations Security Council adopted Resolution 1373, requiring states to freeze terrorist assets and prevent funds from being made available to those involved in terrorist acts. A month later, on 29 and 30 October, the Financial Action Task Force met in Washington and extended its mandate to terrorist financing, adopting Eight Special Recommendations. These measures were addressed formally to states, but much of their practical operation depended upon banks, money-transfer businesses and other private actors identifying customers, monitoring transactions, reporting suspicions and blocking access to funds.  

The same architecture gradually emerged elsewhere: airlines collect passenger information that is transferred to public authorities for security screening under arrangements such as the EU-US Passenger Name Record system; the European data-retention regime adopted in 2006 required communications providers to retain traffic and location data so that competent authorities could obtain them in specified circumstances, although the EU Court of Justice later invalidated that directive in 2014. More recently, European rules on terrorist content online require platforms to delete material identified in a removal order within one hour and - in some circumstances - to adopt additional measures of their own. The state has not really disappeared: it makes laws, issues orders and retains coercive powers; yet the point at which a person is classified, reported, refused or removed increasingly lies inside a formally private organisation.  

Here we need to highlight an important conceptual distinction: a bank closing an account or an airline refusing boarding is not, in itself, an act of surveillance (surveillance concerns the collection and processing of information), while exclusion is an action taken on the basis of that information. But the post-2001 architecture increasingly connects the two: private organisations collect or retain data, classify a person or transaction as risky, and then decide whether access should continue. If we look only at who ‘watches’, we miss the equally important question of who is authorised, formally or informally, to act upon what the watching produces.  

Marieke de Goede has described this development through the idea of a ‘chain of security’, in which companies that do not regard themselves as security organisations, nevertheless, make security judgements on the basis of ordinary commercial data. The word ‘judgement’ is the key here: a bank is not simply asked to freeze an account after a court has established that its owner financed terrorism; it is also asked to decide whether a customer, transfer or relationship presents a risk before such a determination exists. The same is true, in different ways, when an airline evaluates documents, a platform decides whether content falls within a prohibited category, or an employer interprets a screening result. Security moves into ordinary organisational routines because prevention requires somebody to decide under uncertainty.  

### Private actors are asked to judge risk in advance  

This is where Michel Foucault’s vocabulary remains helpful. Foucault argued that power does not operate only by commanding or prohibiting; it can also structure the field in which others make their own decisions, especially with respect to obedience, conformity and self-descipline. Applied here, what is important  is not that the state withdraws and private firms become sovereign; it is that public authorities can shape conduct of the latter by altering the risks organisations believe they face.  
A banking authority, for example, need not tell a bank to terminate a particular customer; it can publish an assessment, place a jurisdiction on a list, announce an enforcement priority or impose a large penalty in another case. The bank then asks a different question from the one a court would ask: not simply whether this customer is presently prohibited, but whether continuing the relationship could later be described as evidence of inadequate controls. Because the consequences of under-reacting can be severe, while the regulatory consequences of declining marginal business or an individual account holder are usually much smaller, precaution tends to move in the direction of ‘over-compliance’.  

A good illustration of this is what is called ‘financial de-risking’. What this term describes is the termination or restriction of relationships with customers or categories of customers in order to avoid - rather than manage - risk. It has several causes, such as profitability, prudential requirements and reputational concerns, and it would be inaccurate to attribute every account closure to anti-terrorism policy. Yet enforcement risk is an important part of the structure. For example, in 2013, Barclays announced that it would close many accounts held by money-transfer businesses, including firms serving Somalia, after tightening the criteria under which it was prepared to provide banking services to the sector. What is significant here is that no public authority had ordered a blanket withdrawal from Somali remittance businesses; the bank was responding to its own assessment of potential future legal, regulatory and reputational risks of remaining in the market. This episode is quite revealing because the Financial Action Task Force itself later actually felt the need to clarify what its standards meant, to minimize such effects. In October 2014, it stated explicitly that its risk-based approach required case-by-case management of risk, not the wholesale termination of entire categories of customers. In other words, the international body whose standards helped structure the compliance environment found itself explaining that private actors were doing more than the standards required. However, while do necessarily want over-compliance and may even try to it, in this environment private actors feel that caution is rewarded more reliably than restraint. Indeed, a compliance officer who approves a relationship creates a judgement that may later potentially prove seriously damaging if something goes wrong, while a decision to refuse the relationship may impose a very serious cost on the customer, but it ordinarily creates much less regulatory exposure and damage for the institution. The two possible errors are, therefore, not priced equally: precaution is generated by the position in which the organisation is placed, not necessarily by an instruction to be excessively cautious.  

Didier Bigo’s work on the transnational field of security professionals helps to place this development in a wider context. Security is produced not only through prominent sovereign decisions but also through mundane practices of classification, sorting and risk management. What the decades after 2001 added was an increasingly dense interface between that security field and the private economy. The people making consequential security judgements now include compliance officers, risk managers, data analysts and content-moderation teams who may, as a matter of fact, never describe themselves as security professionals.  

### The model spread beyond counterterrorism  

It would be tempting to say that 11 September created this model and that it subsequently spread elsewhere, but the story is more complex than that. Carrier liability in European migration control, for example, predates the attacks: airlines and other carriers were already required to check whether travellers possessed the documents needed for entry and could be penalised for transporting inadequately documented passengers. The significance of 9/11 lies elsewhere: it helped make such separate or occasional anticipatory judgement by private intermediaries a normal way of organising security, and the model that spread to issues far beyond counterterrorism.  

Thus, financial sanctions provide a good example. After Russia’s invasion of Ukraine in February 2022, firms routinely withdrew from transactions and relationships that were not themselves prohibited, because sanctions rules were complex, ownership structures were difficult to establish and the cost of an incorrect permissive decision could be very high. Export controls on sensitive technologies similarly rely upon manufacturers, distributors, banks and logistics providers to investigate counterparties and end uses before transactions occur. The legal rule may be public, but its effective perimeter of enforcement is often drawn inside private compliance systems.  

Digital platforms constitute another example of the same development. Some removals follow direct legal orders, while others result from platform own precautionary rules. These situations obviously should not be collapsed into one another, but public concern is often translated into internal standards, automated thresholds and categories that operate at a scale no authority could administer case by case. Once encoded in a private system, the public signal that helped produce the rule can become difficult to see, which in turns raises important questions about accountability and transparency when it comes to customers and users who may be impacted by such opaque decisions.  
We may, therefore, say that the post-2001 transformation concerns a form of reasoning: it is preventive rather than retrospective, because it acts on what might happen; it relies heavily on categories and large-scale sorting, because large organisations cannot investigate every person individually; it shifts much of the cost of interpretation and screening to private intermediaries. In addition, it often leaves the operative threshold - the point at which a customer becomes too risky, a transaction too uncertain or a piece of content too dangerous - to be set by those organisations themselves.  

### Democratic control became fragmented  

A democratic polity has clear mechanisms about how to debate a decree or a statute. For example, after the attacks of November 2015, France declared the state of emergency (which was later repeatedly extended), but this decision was publicly contested and eventually ended on 1 November 2017. The same applies to the law on internal security and counterterrorism adopted on 30 October, which placed several preventive measures into ordinary law. Whether one regards that decision as necessary, excessive or as an unacceptable normalisation of emergency powers is of secondary importance – what matters is that the institutional object is visible: there is a text, a parliamentary history, a public authority responsible for it and courts capable of reviewing its provisions.  

In contrast, the arrangement described above with private actors adopting their own interpretations and enforcement decisions is much more difficult to debate or revisit: a regulator may issue a general warning, but a bank may translate it into a specific risk policy that was not intended by the regulator; a software provider may build a different policy into a screening system and start applying it while this was not implied in the regulator’s general warning. Thus, if criticized, the regulator may rightfully say that it never ordered the account to be closed, while the bank can correctly say that it made a commercial decision. Neither statement is necessarily evasive; the problem is that the consequence exists only because the two forms of action interact.  

Now, it would also be inaccurate to say that there are no remedies at all. Indeed, customers can sometimes complain to banks or ombudsmen, users can appeal platform decisions, and some regulatory regimes provide rights of challenge. The difficulty is resides elsewhere - the increasing fragmentation of decision-makers and enforcement measures. A private appeal may examine whether the company followed its rules without asking whether the public signal that shaped them was too broad, while a court reviewing the public authority may find that the authority never made the individual decision complained of. There may be several forums and still be no single forum in which the whole chain is visible.  

In the light of the above, we may suggest that this is one of the more important – and more difficult – issues for democracies to deal with twenty-five years after 9/11. The liberty-versus-security question remains, of course, indispensable, but it presupposes that we know where the security decision is being made. Increasingly, the answer is that part of it is made by public authorities and part inside private infrastructures of compliance, data processing and risk management. In other words, the threshold has not simply been lowered - it has been distributed.  

Some immediate reforms and actions might be suggested: public authorities may begin to measure and publish the downstream effects of their warnings, lists and enforcement priorities; regulators can correct predictable over-compliance when it becomes visible rather than merely insisting that firms should be more proportionate. Where security law permits it, organisations can give meaningful reasons for important exclusions and provide review by some entity able to reconsider the underlying risk judgement. To repeat, none of this requires pretending that security can be organised without precaution, or that banks and platforms should ignore genuine risks. What it requires is making the exercise of precaution more visible where it acquires the effects of public power.  

To conclude, one of the lessons of the last twenty-five years, then, is not simply that democracies chose security over liberty after 11 September 2001. It is that they increasingly organised security in ways that allow consequential choices to be made outside the institutions in which democratic societies are accustomed to debating, challenging and overruling them. The problem today is not only that the line moved; it is that we can no longer point to one specific institution and ask it to move the line back.

### Thématique
`#Démocratie` `#Numérique` 

**Licence :** `#CC-BY-ND (Attribution, Pas de modification)` 

**Langue :** `#Anglais` 



---
### Navigation pour IA
- [Index de tous les contenus](https://conference.sciencespo.fr/llms.txt)
- [Plan du site (Sitemap)](https://conference.sciencespo.fr/sitemap.xml)
- [Retour à l'accueil](https://conference.sciencespo.fr/)
