For most of its existence, WiFi has been treated as plumbing: invisible infrastructure that moves data between a router and a device, and nothing more. That assumption no longer holds. A growing body of research, now backed by an official industry standard, shows that the radio signals carrying your internet connection can also be read as a sensor, capable of detecting where people are, how they are moving, and in some cases what they are typing, without a camera anywhere in the room.
The basic mechanism
WiFi signals do not travel in a straight, undisturbed line. They bounce off walls, furniture and bodies before reaching a receiver, and each reflection subtly changes the signal’s shape. This distortion, known as Channel State Information (CSI), was traditionally discarded as noise. Researchers have spent the past decade proving that CSI can instead be decoded to reveal what caused the distortion in the first place, since a person moving through a room alters the propagation of nearby WiFi signals in patterns a receiver can be trained to recognise. Internet Pros
The results have been demonstrated repeatedly in laboratory conditions. Researchers at Carnegie Mellon University used three inexpensive WiFi routers and three receivers to map the three-dimensional shape and movement of people in a room, without cameras or LiDAR, by tracking how signals reflected off moving bodies. Earlier work at University College London demonstrated a system called Wi-Vi, which used interference-cancelling techniques to detect and track the direction and angle of moving people behind hollow walls, wooden doors and concrete walls up to eight inches thick, distinguishing as many as three individuals at once. Later research pushed the same principle further, using WiFi passive radar to pick up not just walking but finer movements such as typing or breathing through concrete walls. Ddrcarxiv
A standard built for sensing
What changes the picture in 2026 is that this capability is no longer confined to research labs. The IEEE, the body that governs the WiFi standard, finalised an amendment called 802.11bf in 2025, designed specifically to formalise sensing as a network feature rather than a side effect. The task group was formed to enhance WiFi’s ability to support applications such as user presence detection, environment monitoring in smart buildings, and remote wellness monitoring. Under the new standard, two compatible devices can coordinate to send and read signals cooperatively, turning the space between them into a de facto radar system. NIST
Chipmakers have moved quickly. Qualcomm is building sensing directly into WiFi 7 chipsets, while Huawei’s AirSensing platform is already operating in enterprise buildings. Independent estimates suggest the underlying detection is already accurate at scale: one large-scale deployment spanning more than ten million WiFi routers reportedly achieved over 92 percent accuracy in motion detection while keeping the additional data overhead below 0.3 percent. In practice, this means an ordinary domestic or office router could soon detect occupancy, falls, gestures and breathing patterns as a built-in feature, requiring no new hardware. Purplehuetechnosoftarxiv
Two different threats, one blind spot
It is worth separating two distinct forms of WiFi surveillance, because they carry different risks and different defences.
The first, older method relies on probe requests. Phones with WiFi enabled periodically broadcast a search for known networks, and each broadcast carries the device’s MAC address, a unique hardware identifier. Retailers and venue operators have used this for years to measure footfall, with the BRC-Sensormatic Footfall Monitor alone drawing on 1.5 million footfall-measurement devices and recording more than 40 billion shopper visits annually across UK retail. The most notorious UK example remains the Renew London recycling bins, which in 2013 were found to be fitted with devices that recorded the unique MAC address of any nearby phone with WiFi switched on, prompting the City of London Corporation to order the practice halted after Big Brother Watch raised concerns. On a single day, the bins reportedly identified more than 106,000 people by their MAC addresses. Purple + 3
That particular risk has since been partly defused by manufacturers rather than regulators. Apple introduced MAC address randomisation in iOS 8, and Android followed from version 6, meaning a single phone can present a different, randomised address as often as twenty times during a forty-minute shopping visit. This breaks the crude version of MAC tracking, and modern footfall analytics now apply statistical correction to compensate, running at roughly plus or minus three to seven percent accuracy against camera-based counts. retaildive
But randomisation does nothing to stop the second, newer method: cooperative or passive CSI sensing. That form of detection does not need to identify a specific device at all; it only needs a WiFi signal passing through a space with a body in it. This is precisely why researchers describe the regulatory position as unresolved. Most existing privacy regulation was written with visual surveillance technologies such as cameras in mind, while RF-based sensing derives information from wireless signal behaviour rather than direct visual capture, placing it in a regulatory grey area. In the UK, the Information Commissioner’s Office guidance on WiFi still centres on the older MAC-based model, recommending that operators carry out a privacy impact assessment, define the purpose of data collection clearly, notify individuals through signage, and anonymise MAC addresses where possible. Nothing in that guidance was written with CSI-based, device-free sensing in mind. DIAMATIXBird & Bird
The standard-setters knew, and disagreed
Perhaps the most striking detail to emerge from the 802.11bf process is that the privacy question was raised inside the standards committee itself and left unresolved. Documentation from the working group’s deliberations shows that a proposal to define sensing privacy within the standard did not survive; the accompanying resolution record effectively acknowledged that the group could not agree on how to characterise the privacy problem at all, and the relevant amendments were withdrawn. The distinction that matters here is between cooperative sensing, which requires two devices to coordinate openly and could in principle be detected and regulated, and passive extraction, where a device simply listens to ambient signal reflections without announcing itself. The first is visible. The second, currently, is not.
What can actually be done about it
Academic countermeasures exist but remain firmly in the research stage. Techniques such as RF-Protect and IRShield attempt to obfuscate the CSI signal to defeat unwanted tracking, in some cases by manipulating the beamforming data that WiFi devices exchange, though these approaches generally require additional equipment such as signal repeaters, or come at a measurable cost to network performance. None of this is available as a consumer product today. ScienceDirect
The stakes go beyond simple presence detection. Separate research into the same beamforming feedback data that WiFi devices already exchange has demonstrated that it can be used to infer keystrokes and PIN codes, with plaintext beamforming feedback in WiFi standards from 802.11ac onward found to make keystroke and password inference significantly more accurate. arxiv
For now, the practical reality is that the connectivity layer running through most British homes, offices and shops is quietly acquiring a second function that was never advertised on the box, and that no current regulator has fully caught up with. The technology did not arrive as a single dramatic launch. It arrived as a standard, a chipset update, and a line in a product spec sheet, which is usually how the most consequential infrastructure changes.
