Researchers at Karlsruhe Institute of Technology recently used ordinary Wi-Fi routers to identify individual people walking through a room using a new system called BFId. In a study of 197 participants, it identified people with accuracy running up to 99.5%, across different walking styles and viewing angles.
There’s no camera, no mobile app, and no specialized equipment. The person being tracked does not need to be carrying a phone, and the system does not even need the network’s password.
It works on beamforming feedback information, kind of like the sonar a bat emits. Your Wi-Fi 5 router at home has the same feature, sending radio signal back and forth with connected devices to steer the signal to the right place. That feedback is broadcast unencrypted, so any adapter in monitor mode within range can capture it passively. This is very common in household connected devices.
Opting into WiFi Sensing Detection
I’ve worked on personalization strategy projects for major retailers and airlines, and the proximity programs of the major brands would often fail at the same place when they tried to apply homepage tactics to screens in physical space: it was difficult to trigger. Beacons needed someone to have a mobile app open. Geofencing needed the customer to grant permission on a device. Kiosks needed attention and someone to walk up and tap the screen. Every one of them needed a customer to commit to the interaction before the experience could start, and most customers just walked by.
This passive Wi-Fi sensing tactic asks for nothing. You don’t even need a phone, and you could be recognized by your body shape, gait analysis (the way you walk), or the contours of your face. Comcast already ships the mild version, counting bodies through Xfinity gateways.
Comcast turned Xfinity gateways into motion sensors with WiFi Motion. Customers opt in when renting the hardware, with terms allowing Comcast to log movement data, share it under subpoena, and use it commercially. Today it counts bodies. The research is about naming them. That is a smaller gap than it sounds.
That gap is where the problem starts, because everything we built to handle it assumes a customer who is looking at something.
For twenty-five years, personalization has run on an exchange of information. The customer does something and gets something back. They create an account. They accept the cookie banner. They join the loyalty program. They turn on location for the store finder.
Every consent mechanism we have built assumes that exchange, because every one of them needs a surface to appear on. The cookie banner, the preference center, the privacy policy, the just-in-time permission prompt, the unsubscribe link. These are interface elements. They work because there is a moment when the customer is looking at something we control.
The consent screen was never really a legal artifact, it was an interface. If WiFi can track you without a device, the interface just disappeared.
The person walks past a router. That is the entire interaction. You cannot ask permission from someone who never interacts with anything. If there’s no screen, there’s nowhere to put disclosure, and no action to condition it on.
It was already decided, quietly
This is not exactly a surprise to the industry. In 2023, during a formal review, a participant proposed protecting sensing transmissions the way the 11az standard protects its ranging frames. Encrypt the waveform so a bystander with an antenna cannot read bodies out of the air. Committee members disagreed about whether the threat was genuine. The proponent withdrew the comment. The standard was published in September 2025 without the protection.
That was the moment. Not a product decision or a policy fight, but a comment resolution inside a working group most people have never heard of. Privacy could have been built in before anything was shipped. That’s a common pattern with ambient technology. The decision that matters gets made years early, in a room without customers.
The value exchange argument does not survive contact
One defense is that customers will accept anything if the value is good enough (e.g., accepting cookies for personalized offers). The numbers are less forgiving. Qualtrics surveyed more than 20,000 consumers across 14 countries. 64% prefer personalized experiences, but only 39% trust organizations to use their personal information responsibly. Only 41% believe the benefits justify the privacy cost. Most importantly, 86% of people say they would share more if organizations were transparent about how their data gets used.
What do you even do?
The data center backlash is instructive here. Opposition now polls above 70% in states that agree on almost nothing else, and the industry keeps responding by fact-checking water usage. Correcting the number does not repair a consent failure. A privacy FAQ is the same move.
WiFi sensing as a different category from data collection, with a different review path. Data collection has a consent surface. Sensing does not. If a use case only works because the customer never learns about it, that is the finding, not an obstacle to route around.
Build the disclosure before the capability. If nobody can tell you where the disclosure lives, you do not have a program. You have an exposure with a roadmap date.
Would you put a sign on the door? If a sign would kill the value, you already know what you are building. The best experiences of the next decade will be the ones that still ask. Not because asking is polite, but because it is the only version that survives contact with the people it is about.

Leave a Reply