Programmable Choke Points: Smart Infrastructure, Remote Shutoff, and the Future of Sovereignty in Canada
Canada's mandatory smart meter rollout isn't a billing upgrade. It's a programmable governance layer — and the democratic window to contest it is closing.
There is a dividing line at the heart of the liberal tradition, and it is simpler than most people remember: in a free society, citizens live on rights. In a managed society, citizens live on permissions. Rights are prior to the state — the state cannot suspend them without procedure, cannot apply them selectively without challenge, cannot revoke them quietly without recourse. Permissions are the inverse: granted by the system, conditional on compliance, adjustable by administrative decision, and revocable the moment the calculus shifts.
That distinction is what the word “dictatorship” actually describes. Not soldiers. Not emergency decrees. Not the theatrical trappings of obvious tyranny. A dictatorship is a system in which essential life — your ability to work, move, speak, access money, stay warm — is governed by permission rather than right. The mechanisms can be high-tech or low-tech, formal or informal, brutal or polite. What makes them dictatorial is the architecture: dependency made conditional, conditions kept opaque, and the cost of defiance made personal enough to discourage it without having to be exercised very often.
I know what that architecture feels like before it finishes being built. A few months ago, a letter arrived at our home on Vancouver Island. White envelope, corporate logo, machine-printed address. FortisBC was writing to notify us that our natural gas meter “needs to be exchanged” for a wireless advanced meter. Technicians would schedule a time, briefly interrupt service, relight the appliances. Buried in the middle of the letter, one phrase carried the real weight: the exchange “is not optional.” Not a request. Not an invitation to discuss. A declaration that the default had already been changed — and our role was to cooperate.
To the bureaucratic mind, that line is unremarkable. To someone who grew up watching a state use dependency as a lever — who learned early that power doesn’t announce itself, it just quietly removes your options — it landed differently. What the letter was actually saying, in the language beneath the language, was this: a networked sensor with remote shutoff capability is now a condition of receiving heat in your home. You did not vote on this. You were not consulted. The decision was made in a regulatory proceeding you never heard about, ratified by a commission whose hearings you will never read. Your role is to accept it.
Canada is building that architecture. Not through emergency decree. Not in a single dramatic act. Through infrastructure — through the methodical conversion of essential services into programmable systems that can be sensed continuously, managed remotely, and conditioned on compliance without anyone ever being required to say the word “compliance” out loud.
They call it “smart.” They call it “modernization.” They call it “safety,” “resilience,” “climate action,” “keeping pace with international best practice.” Every one of those words is doing work — not describing what the system is, but managing how it feels. “Smart” means you’d have to be stupid to object. “Modernization” implies the direction is progress. “Safety” pre-emptively pathologizes refusal. “Not optional” completes the move: it transforms a governance decision into an administrative fact, something that happened before the conversation started. This is the newspeak of managed infrastructure — a vocabulary engineered to make the transfer of control sound like a service upgrade.
This essay is going to call it something else.
1. Not Optional on “Vancouver”
The letter arrived addressed to my girlfriend — she is the one FortisBC recognizes as the customer, the legally responsible account-holder whose authorization the system requires. I am the political refugee in the background, the one who says “Vancouver” when people ask where we live on the Island, the one whose prior life made operational security more than a lifestyle choice. When FortisBC calls, they do not speak to the writer who thinks in terms of panopticons and programmable choke points. They speak to the woman whose name appears on the bill.
And what the bill-holder was told, calmly, in the middle of a form letter, was that a networked sensor with remote shutoff capability would be installed on the side of our home. Not requested. Not negotiated. Installed — as a condition of continuing to receive gas heat.
So I started pulling the thread. Understanding why FortisBC could say that with such confidence — “not optional” as administrative fact, not corporate arrogance — required understanding the machinery behind the letter. The BC Utilities Commission has already approved FortisBC’s plan to replace more than a million gas meters with advanced ones as part of its Gas Advanced Metering Infrastructure (AMI) Project. Regulators reviewed the technical specifications, accepted the company’s framing of the benefits, and issued the approvals that make the rollout binding. FortisBC is not making a unilateral power grab — from inside the system’s own logic, it is doing exactly what regulated utilities are supposed to do: implement a regulator-approved program at scale. “Not optional” is not arrogance. It is the end state of a process that was completed years ago in hearings most customers never heard about.
That is precisely what makes it dangerous. The BCUC approval is not a safeguard. It is the codification rail doing its work — one of six interlocking systems this essay will name and map — the layer where technical decisions and regulatory norms fuse into something that feels permanent and unchallengeable. By the time the letter arrives at your door, the architecture has already been ratified. The public consultation, such as it was, concerned rollout timelines and rate impacts. Whether households should be continuously sensed and remotely controllable as a condition of receiving heat was never put to a vote, never debated in Parliament, never explained in plain language to the people it would affect. Your role in the process was not consultation. Your role is to cooperate.
When my girlfriend pushed back, she tried the most basic argument available in a free society: “I don’t want this meter.” The answer came back, flat and rehearsed: “It’s not optional.” There was no space in the script for questions about what data would be collected, how often the meter would transmit, who would access the information, or under what law FortisBC claimed the authority to compel a hardware change on private property tied to a private wireless network they operate. The callers were polite; the structure was not. The system had already decided.
That moment of friction — the gap between the lived intuition that something profound is shifting and the institutional insistence that everything is routine — is exactly where sovereignty is lost or reclaimed. On paper, FortisBC’s advanced meters are just an efficiency technology: they allow the company to read usage remotely, detect leaks faster, and manage the gas system with more precision. In practice, once the swap is complete and the meter is connected to the network, our home becomes an addressable endpoint in a province-wide control system. Someone, somewhere, will be able to see our gas consumption hour by hour and, if certain conditions are met, cut service without ever setting foot on our property.
We are not going to fight this battle at the curb and expect to win it. The machinery of approvals, investments, and deployment is already in motion, and individual refusals are treated as scheduling problems, not democratic input. That is not a concession — it is a clarification of what this fight is actually for. This essay is not a petition. It is reconnaissance made public. The point of pulling this thread is not to stop one meter installation; it is to force the architecture visible while it is still possible to name it — to show that “not optional” is not a customer service decision. It is the surface of a repeatable governance pattern: continuous sensing + remote actuation + vendor stack + regulator rubber-stamp, deployed at scale, below the threshold of public debate, on the infrastructure of survival itself.
2. From Modernization to a Mesh of Control
The deeper I went into the machinery behind the letter — the approvals, the vendor documentation, the technical standards — the more one word kept doing the load-bearing work. Not “optional.” The one they led with.
Before anything else: hold the word “smart” still, because it is doing more work than it appears. There is no universal, publicly defined acronym for “smart” in the smart-grid and smart-meter standards literature — a viral claim that it stands for “Surveillance, Monitoring, Analysis, Reporting, Technology” has circulated widely and does not hold up to scrutiny. Strip the branding question away entirely, though, and look only at what the standard actually requires the hardware to do: the system watches your household continuously. It records the patterns. It analyzes the data. It reports upstream, on a schedule you do not control, to a party you cannot see. That is not a risk or an edge-case misuse — it is the design specification, baked into the standard before any utility ever pitched it to a regulator. Call that function “self-monitoring,” call it “advanced metering infrastructure,” call it whatever the standards documents call it: the word critics and legal experts independently reach for, with no branding dispute in sight, is surveillance. Privacy campaigners describe the identical architecture as “a highly surveillant model.” Civil liberties organizations warn plainly about “smart cities” becoming “surveillance cities.” And when one utility’s meter data was actually repurposed into a mass surveillance program run against its own customers, it took a civil liberties organization taking the matter to court to stop it — because the capability the scheme relied on was not bolted on afterward. It was already built in. “Smart” is the retail label engineered to sit on top of that function and make refusal sound like foolishness. Whatever the industry calls it, the function does not change: it watches, it records, it reports — and by the time the average Canadian sees “smart” on a utility letter, the branding has already done its work.
The script FortisBC uses for its AMI project is not unique to FortisBC. It is the standard-issue language of every smart infrastructure rollout in Canada for the past fifteen years: smaller meters, fewer truck rolls, faster leak detection, smoother integration with a low-carbon future. “Upgrade.” “Modernization.” “Climate-era necessity.” The words are chosen carefully — not to describe what the system is, but to pre-empt the question of whether you should want it. Before the conversation starts, the frame is already set: this is progress, and objecting to progress is the problem.
The pattern is national in scope. Ontario’s province-wide smart-meter program ran on the same talking points. BC Hydro’s smart electricity rollout, Edmonton’s EPCOR deployments, the now-infamous Sidewalk Toronto waterfront project — each one arrived wearing a different costume but executing the same underlying move: replace slow, coarse, human-mediated systems with high-frequency, machine-readable streams feeding centralized analytics platforms. The details differed. The governance logic was identical. And in every case, the repeating pattern was: not optional + telemetry + remote actuation + vendor stack + regulator rubber-stamp, delivered below the threshold of public debate, presented as routine.
There are real efficiencies in granular sensing — leak detection, demand forecasting, grid management. That is not in dispute. What is in dispute is the political logic that gets bundled in with the engineering. FortisBC’s AMI network does not just measure gas use; it enables remote service changes, including disconnections, from a centralized control system. The same network that allows the utility to “read your meter without visiting your property” also gives it the technical power to reach into your home and turn off heat with a command. That is not an efficiency feature. That is a capability — and capabilities, once built, are available for use far beyond the purpose that justified building them.
Once you combine continuous fine-grained sensing with remote actuation and align it to policy goals — from climate targets to emergency orders to “critical infrastructure protection” — you are no longer looking at a neutral upgrade. You are looking at the construction of what I’ll call a mesh of control: a network in which each home is not just a customer account but an addressable endpoint, observable in real time and switchable on demand. That is not a hypothetical future state. It is a description of what FortisBC’s AMI system will be, technically, the day the new meter goes live.
Canada has already encountered this logic before, in more visible form. The Sidewalk Toronto smart-city proposal collapsed not because the sensors wouldn’t work, but because the governance model concentrated data and control in private hands with no credible democratic override. Ann Cavoukian and other privacy experts warned that ubiquitous sensing turns the line between urban innovation and population surveillance into a matter of policy mood, not technical capability. Smart-meter debates in BC and Alberta surfaced the same concern from a different angle: time-stamped energy data can reveal occupancy patterns, appliance use, religious practices, whether a business is running after hours. Regulators responded with privacy guidelines and reassurances. The meters stayed. The pattern in each case was the same: resistance forced cosmetic concessions; the underlying architecture was never touched.
FortisBC’s gas AMI rollout is the quietest installment of that same pattern — invisible because there are no glossy waterfront renderings to rally against, only a rolling neighbourhood schedule and a form letter. No dramatic legislation to debate, only a series of technical approvals by a commission whose hearings most customers will never read. But in aggregate, these invisible upgrades are re-wiring the basic terms on which Canadians access heat, light, and water. They convert blunt, analog systems that were hard to abuse at scale into finely tunable networks where each home is a node that can be profiled, ranked, and in extremis, shut off.
This is what “programmable choke points” means in practice. In an older infrastructure regime, cutting off service to a household or a neighbourhood required overt action — trucks, crews, visible interventions. It was slow, logistically heavy, and politically costly. In the emerging regime, disconnection is a field in a database, a script in a control room, an automated response to a policy rule. It is fast, deniable, scalable, and — this is the important part — it does not require anyone to announce that coercion is happening. It just requires someone to set the condition and let the system execute.
The FortisBC letter on our table is a local artifact of a national transformation. The company is not an aberration. British Columbia is not an exception. This is the direction the country’s essential infrastructure is moving — and the sections that follow name the architecture, the mechanism, and the method for forcing it visible before it hardens into a condition of life no one voted for.
3. The Sensing Rail and the Behavioural Diary
When utilities talk about advanced meters, they still describe them in the language of billing. The device “measures your gas use” and “sends the reading automatically,” saving a worker a trip to your property. That description is not false, but it is radically incomplete. What FortisBC’s AMI meters actually produce is a high‑frequency behavioural signal: a time‑stamped trace of when your household cooks, showers, does laundry, goes on holiday, or abruptly changes its patterns because someone lost a job, got sick, or moved out.
What does that actually mean in plain terms? It means the meter knows when you wake up in the morning, because that’s when the boiler kicks on. It knows when you go to bed. It knows when the house was empty for ten days in July — a holiday, or maybe a hospital stay. It knows when a pattern that ran like clockwork for three years suddenly changed — someone moved in, someone moved out, someone lost work, something shifted. These are not inferences a utility needs to bill you. They are inferences a sufficiently motivated analyst can draw from a time-series of gas consumption. The meter is not a clock on a pipe. It is a behavioural diary written in energy data.
And here is what most Canadians do not yet realize: that diary is already being written in three languages simultaneously, all by government-deployed infrastructure.
BC Hydro completed its province-wide smart electricity meter rollout years ago — electricity tells you occupancy patterns, general activity levels, and appliance signatures. FortisBC’s gas AMI is now joining it — gas tells you heating behaviour, cooking cycles, hot water draw, and the rhythm of a kitchen. And smart water meters, already deployed by municipalities across BC and other provinces, complete the picture — water consumption patterns reveal shower timing, toilet frequency, irrigation schedules, and household occupancy with a precision that neither energy stream can match alone.
Three independent, continuously reporting government sensors on a single household. Two of them — electricity and gas — approved by the same regulatory body, the BC Utilities Commission, through separate proceedings it was never required to read in combination. The third — water — approved by municipal governments. Each defended by its own “efficiency and safety” rationale. Each feeding separate databases that are, in principle, cross-referenceable. Together they don’t just triangulate household routine — they produce redundant confirmation across three independent signal streams, meaning anomalies that might look like noise in one stream are verifiable in two others. This is how layered household sensing gains resolution: not through a single dramatic surveillance move, but through the quiet layering of individually defensible sensors, each with its own regulator-approved rationale, compounding into something with far greater inferential power than any one meter justifies. (Add privately connected smart thermostats — Nest, Ecobee — feeding corporate clouds, and your home becomes legible from commercial angles too. But those are consumer choices. The three utility meters above are not — and neither, in practice, is the home internet connection. That fourth layer runs through a different regulatory track: licensed ISPs, telco standards bodies, and CRTC frameworks rather than utility commissions. It retains metadata — every connection’s source, destination, timing, and volume — as a structural byproduct of operation. And it carries a dimension the utility meters cannot: the WiFi signal it powers is also, as established in peer-reviewed research, a passive radar system capable of locating and tracking the occupant’s body inside the structure. Three utility meters, one regulatory track. One internet connection, a separate regulatory track. Neither track was ever asked about the other. The household sits at the intersection of both.)
In data‑science terms, that trace is ideal training material. It is regular, structured, and easy to align with weather, pricing, and demographic information. Once you have enough of it across enough homes, you can build models that predict demand down to the hour, estimate likely appliance mixes, or flag “anomalous” behaviour that might indicate a leak—or simply a household that does not fit its neighbourhood’s profile. This is where the language of “digital twins” enters the picture. Canadian consultancies and infrastructure firms now openly promote building‑ and grid‑level digital twins: virtual models that mirror the physical world in real time using sensor data and AI. Your gas meter, in that vision, is a sensor feeding a twin of your home and, by extension, a twin of your entire community.
That is the chain worth holding clearly: the sensing rail produces the behavioural diary; the behavioural diary, aggregated across enough households and aligned with the other rails, becomes the digital twin of the population. The processing architecture that ingests those twins — and converts them into risk scores, compliance categories, and automated interventions — is what the rest of this essay is building toward.
Notice what the word “anomalous” is doing in that sentence. Today, anomalous means a possible gas leak — a safety function, neutral and defensible. But “anomalous” is not a fixed category. It is a political decision disguised as a technical one. Under a climate compliance regime, anomalous means a household exceeding its energy allocation. Under an emergency order, anomalous means consumption that doesn’t match the pattern of a compliant neighbourhood. Under a public health framework, anomalous might mean occupancy patterns inconsistent with declared household size. Who defines anomalous, and under what rules, is the governance question that the technical language of “digital twins” deliberately buries—pushed down into implementation, below the threshold of political debate, where it can be treated as a technical detail rather than a decision someone made.
What this sensing architecture is actually building is what I’ll call the sensing rail — the layer that continuously acquires physical life as machine‑readable data. Think of it as the mesh of meters, cameras, thermostats, phones, vehicles, and embedded sensors that turns the analogue world into structured information: who is where, doing what, using how much, and how those patterns change over time. FortisBC’s AMI meters are not just new dials on a pipe. They are standardized sensors being added to that rail, translating the intimate rhythms of your household into data that can be stored, analyzed, cross‑referenced, and acted upon.
Once data lands on the sensing rail, it rarely stays isolated. Accounts link meters to names and addresses; billing systems link them to payment instruments; customer‑relationship tools link them to emails and phone numbers. In practice, this means gas‑usage traces can be joined to identity rails (who you are), payments rails (how you pay), and communications rails (how you can be reached). At scale, the result is not a stack of disconnected spreadsheets. It is a live, queryable map of which people live where, how they typically behave, and when each household in that map is most exposed — a dynamic model of a society, continuously updated and cross-referenced. The data platforms built to process information at this scale — and Palantir is one of the clearest examples — call this kind of structured, interconnected model an ontology. At population scale: a population-level ontology. The word is worth knowing. It will appear again.
Step back and see what this looks like at city or provincial scale. You are not looking at a collection of billing records. You are looking at a live map: which households are occupied and when, which routines are stable and which have changed, which addresses show patterns that flag as unusual under whatever operational definition of “unusual” is currently loaded into the system. That map does not require anyone to have bad intentions to be dangerous. It only requires someone, someday, to run a query under conditions that did not exist when the data was collected. The data doesn’t expire. The political conditions under which it was collected, however, can change overnight.
This is where Palantir enters—not as a brand name dropped for effect, but as a clear reference point for a type of system. Palantir’s signature move is not “AI” in the sci‑fi sense. It is data fusion: taking many ordinary databases and live feeds that were never designed to talk to each other, stitching them into a single operational picture, and turning that picture into a tool for search, ranking, alerting, and action. Whether the vendor is Palantir or not, that is the governance pattern that matters.
That same pattern applies to AMI data. A gas meter starts as an efficiency tool, but its real output is a behavioural stream that can be merged with other streams. When that happens, energy data stops being “a reading” and becomes part of an integrated model of people, places, and routines—exactly the kind of model a modern technocratic state (or a public‑private state) learns to treat as actionable intelligence.
The distinction worth pausing on is this: a crude form of authoritarian control announces itself. A more sophisticated one encodes itself—in the thresholds, the categories, the models, and the definitions. The coercion is not in the raw data. It is in the interpretive layer sitting above the data: who decides what “anomalous” means, under what policy framework, and with what consequence attached. “Anomalous consumption,” “at-risk household,” “non-compliant usage pattern”—these are not neutral technical outputs. They are political decisions wearing the costume of measurement. And once those decisions are embedded in automated systems and vendor platforms, they become invisible: executed as workflow, not announced as policy. The newspeak is not in the press releases. It is baked into the architecture itself. When a model reads your household as “within normal parameters,” that is a political judgment about what normal means. When it flags you as outside them, that too is a political judgment—one made by whoever wrote the definition, under whatever framework was current when they wrote it, and applied automatically to everyone thereafter. The system does not need to lie. It only needs to define.
That distinction matters more than it first appears. A dictatorship that rules by force announces itself — you can see the soldiers, name the decree, point to the moment the line was crossed. A system that rules by controlling definitions never has to announce itself at all. The coercion is not in the raw data. It is in the interpretive layer: the thresholds, the categories, the models, the rules about what counts as anomalous. And because that layer presents itself as measurement rather than politics — as technical fact rather than political choice — it passes through democratic scrutiny almost without friction.
This is where the word “science” becomes important. Science, applied honestly, is a tool for understanding the world. But science applied under the direction of whoever controls the questions — what gets measured, what gets flagged, what consequence attaches to which result — is something else entirely. It is the architecture of governance without accountability. Anything can be “scienced.” The lens and the goals determine what the science does. When bad actors control the definitions, they control the outcomes. And the people subject to those outcomes have no visible target to contest — because there is no decree, no soldier, no moment. There is only the model, and the model’s output, and the system calling it administration.
This is what I mean by a scientific dictatorship: not a regime that rules by jackboot, but one that rules by definition — that builds the apparatus of control incrementally, through individually defensible technical decisions, each one ratified before anyone notices the shape they’re forming together. China has built one, a system of algorithmic control documented in exhaustive technical detail by human rights researchers who reverse-engineered the policing app driving mass detention in Xinjiang. The global technocracy is assembling one. Canada is laying the rails for one, meter by meter, standard by standard, “not optional” letter by “not optional” letter. And a society that cannot see its definitions being written cannot contest them before they harden into the infrastructure of everyday life.
There is one more dimension most Canadians have not considered, and it starts with a simple fact: the data the meter collects does not stay in the meter. It travels upstream — to utility servers, vendor platforms, analytics systems, and cloud infrastructure that may sit in facilities you will never visit, under contracts you will never read, in jurisdictions whose laws you did not vote on. The meter on your wall is just the collection point. The memory lives in datacenters. And that memory is not yours to erase.
Which means it will outlast the political conditions under which it was collected. What is gathered today under a policy of “efficiency and safety” sits in those datacenters and will still exist in five years, ten years, under different governments, different emergency frameworks, and different definitions of what constitutes a compliance risk. Innocent today does not mean innocent forever when the rules change but the historical record does not. Every anomalous usage pattern recorded now is available to be reread under whatever interpretive framework a future operator decides to apply. The datacenters the meter feeds into remember. The system does not forget. And “privacy safeguards” are policies — they can be waived, rewritten, or quietly superseded by the conditions that justify invoking them. The data, once it exists, has a life of its own.
It is tempting, especially for technically minded readers, to reply that utilities and regulators would never allow profiling at that level. In theory, privacy law is supposed to be the answer. British Columbia’s PIPA — the Personal Information Protection Act — governs how private organizations collect and use your personal data within the province. Canada’s PIPEDA — the Personal Information Protection and Electronic Documents Act — does the same at the federal level for commercial activity. Utility-specific safeguards sit on top of both. Together, they are supposed to limit what can be done with customer data. In practice, those safeguards operate inside a system whose basic function is to make human behaviour legible and manipulable. Once you normalize the idea that every household should be continuously sensed, and once you tie that sensing into standardized data structures, the question is no longer whether a digital twin of the population can be built. It is who gets to build it, for what stated purpose, and under what conditions Canadians are allowed to say no.
From a sovereignty perspective, the key point is this: by accepting advanced meters as routine, we are not just improving billing accuracy or leak detection. We are enrolling our homes as addressable nodes on a shared sensing rail inside a growing digital governance infrastructure—a layer that can be used for genuine safety and efficiency, but that also creates the conditions for quiet, normalized coercion. The FortisBC letter on our kitchen table is not just an upgrade notice. It is a request for our household to become a permanent, instrumented fixture in someone else’s model of the world.
4. The Proof of Concept and the Dissident of Any Stripe
The second half of the AMI story is not about what the meter sees, but what it lets the utility do. FortisBC’s public materials emphasize that advanced meters will allow faster response to gas leaks, more efficient outage management, and, where necessary, remote disconnection and reconnection of service. In a genuine emergency — a gas leak, an unsafe structure, an evacuation order — that capability has obvious merit. Nobody disputes it. The problem begins the moment you ask the next question: once remote shutoff exists as a normalized, scalable capability, under what conditions can it be applied to something other than a gas leak?
The answer to that question is not technical. It is political. And Canada has already answered it, on a different rail, in living memory.
In February 2022, the federal government invoked the Emergencies Act in response to the Freedom Convoy protests in Ottawa and related blockades. The invocation authorized the government to direct banks and other financial institutions to freeze the accounts of protest participants and donors — in many cases without a court order, without charges, and without the due process protections that normally govern state interference with private property. The legal basis was contested at the time, and in January 2024 the Federal Court found the invocation unreasonable and a violation of the Charter’s sections 2(b) and 8 — a finding the Federal Court of Appeal upheld in January 2026, confirming that the invocation was unlawful. But the mechanism itself was not contested: it worked. Bank accounts were frozen. Transactions were blocked. Financial life was suspended for targeted individuals by administrative directive, routed through private institutions, at speed and scale that older enforcement methods could never have matched.
Before addressing what this event means for infrastructure, it is worth pausing on the political optics — because they matter for the argument. The Freedom Convoy was a deeply polarizing event. Those on the political left largely supported the government’s response, viewing the protest as a dangerous occupation by bad-faith actors. Those on the political right largely viewed it as a democratic expression of legitimate grievance met with a disproportionate, authoritarian overreach. Both positions remain contested. That debate is not settled here, and this essay is not taking a side in it.
What this essay is taking a side on is the mechanism. Regardless of your view of the convoy, the Emergencies Act account freezes demonstrated something that should disturb every Canadian regardless of political persuasion: the payments rail is programmable. A government, under sufficient political pressure, will route enforcement through financial infrastructure rather than through courts — and the technical architecture of that infrastructure makes it fast, opaque, and scalable in ways that traditional law enforcement is not. The guardrails that distinguish administrative action from punishment — due process, judicial oversight, the right to contest before the state acts — were bypassed, not because anyone was especially lawless, but because the system made bypassing them easy. That is a capability story, not a values story.
Now look at Canada’s political landscape and ask who that capability will be aimed at next — and you begin to understand why the infrastructure being built right now should alarm people across the entire political spectrum simultaneously.
Canada is under genuine, multi-directional political stress. It is not one-sided, and it cannot be honestly framed as one-sided. The post-COVID recovery has stalled for millions of working Canadians — cost of living, housing unaffordability, and wage stagnation are generating real anger across class lines. A significant part of the political left is in open conflict with the government over foreign policy — particularly its stance on the conflict in Gaza, where protests have grown, calls for accountability have intensified, and critics have faced professional and social consequences for speech that, in earlier decades, would have been unremarkable. A significant part of the political right is alarmed by immigration policy, demographic change, and what it perceives as the engineered erosion of cultural continuity. Police officers have appeared at private residences following social media posts critical of public figures including calling Prime Minister Mark Carney a Zionist. Proposed legislation — Bill C-63, the Online Harms Act, introduced in February 2024 — has tested the outer boundaries of what constitutes permissible speech online. An active geopolitical conflict is reshaping global alliances in ways that will have unpredictable domestic effects.
These are not fringe concerns. They are the live political fractures of a society under pressure — and they are fractures that cut across the left-right divide in ways that the political establishment has not honestly reckoned with. The person alarmed by what they see as government complicity in overseas atrocities and the person alarmed by what they see as demographic engineering are operating from entirely different value premises. But they share something structurally important: both are dissidents from the current consensus. Both have reason to distrust state power. And both are living in a country that is quietly building the infrastructure to make dissent very expensive.
The word “dissident” is worth reclaiming here, because it has been quietly weaponized in the West. Abroad, it is a term of honour — the person who speaks truth to power under genuine personal cost. Domestically, the West has a substitute label ready: “conspiracy theorist,” “extremist,” “problematic.” The label does the same work as Soviet-era smears: it places the person outside the zone of serious consideration before their argument has been heard. But a dissident is simply someone who holds a position the current power structure has not authorized. That has always been the word. The category hasn’t changed. The question has only ever been: which power, and which direction is the questioning aimed? When the questioning is aimed at governments the West disapproves of, it is dissidence. When it is aimed at governments the West approves of — including its own — it becomes pathology. That reclassification is itself a governance move. This essay uses “dissident” in the original sense: any person, of any political stripe, whose questioning of current institutional power makes the infrastructure of managed consent uncomfortable.
And beneath those headline fractures, quieter pressures are accumulating that do not fit easily into the left-right frame at all. Across British Columbia and beyond, court rulings and federal agreements have begun to restructure land and property rights at a foundational level — not through parliamentary debate, but through a sequence of separately approved legal decisions and government treaties whose cumulative implications for ordinary property holders are only becoming visible after the agreements are signed. Whether those changes are just is a question different Canadians answer differently. That they are happening through processes most Canadians were not watching — and that they are reshaping who holds authority over land at a speed that outpaces public understanding — is an observation that cuts across political lines. In parallel, Canadians who prefer to live outside centralised infrastructure — off-grid, rural, self-sufficient — are encountering an expanding wall of building codes, zoning restrictions, utility mandates, and regulatory harmonisation requirements that make that choice increasingly costly without any single law ever announcing itself as hostile to it. The cumulative pressure is to make dependency on the centralised system the path of least resistance, and refusal the path of mounting friction. And for Canadians who experienced serious harm from COVID vaccines administered under conditions that were, in several jurisdictions, effectively mandatory — loss of employment, travel restriction, social exclusion as the price of non-compliance — the state has recently completed a quiet administrative move: the Vaccine Injury Support Program has been renamed the Vaccine Impact Assistance Program. The word “Injury” is gone. “Impact” has replaced it. The change alters nothing about the compensation structure. It alters the cognitive architecture: it softens the causal connection between the mandate and the harm, making it fractionally harder, at the level of language alone, to hold both thoughts simultaneously. That is a small move. It is also a precise one — and it is the same governance logic that runs through everything else in this section: not suppression, not denial, but the quiet administrative management of what gets named, and what gets named as what.
Beneath all of these fractures — across the left-right divide, across the issue lines, across the groups who share nothing except a structural position outside the current consensus — there is one moral community that the managed society’s architects have a specific and non-incidental problem with. Canada’s Christians are not a passive demographic sorted into culture-war voting blocks. They are, in structural terms, the primary obstacle to the managed society’s foundational premise.
The incompatibility is not incidental. It is architectural. Christianity insists on rights prior to any earthly authority — rights that no state granted, that no state can legitimately revoke, and whose source sits entirely outside the jurisdiction of any government, commission, or administrative framework. The managed society operates on the opposite premise: that access to essential life — work, movement, heat, money, connection — is a permission structure administered by whoever holds the dashboard. These two systems cannot be reconciled at the foundation. One of them has to give. Canada has already shown which side the state acts on when the two collide: in February 2021, police arrested Pastor James Coates of GraceLife Church in Parkland County, Alberta, and held him in custody for over a month for continuing to hold in-person worship services in defiance of provincial public health orders — a documented enforcement action against religious practice, not a hypothetical one.
This is why the sensing rail’s capture of religious practice data is not background noise in the architecture. It is operational intelligence on the one moral community whose foundational premises make the entire apparatus permanently contested. The data on when a household observes the Sabbath, runs a Sunday school, hosts a Bible study, or patterns its week around religious community — that data is not gathered incidentally. In a system designed to model, predict, and manage behaviour, the behaviour of a community organized around a moral framework explicitly prior to the state is a category of interest. Not because any administrator has issued a memo. Because the architecture processes what is legible and flags what is anomalous — and a household whose first loyalty is prior to the state is, by the system’s own logic, a household that requires a closer model.
The architects of this system understand this. What most Canadian Christians do not yet understand is that the cage being built is not indifferent to them. It is specifically interested in mapping a moral community whose continued coherence represents the most durable structural resistance to the managed society that exists in the Western world. Thriving people do not build cages around themselves. Someone else builds the cages — while the people who most need to see the architecture are busy living inside a set of commitments that make them the primary target of the people doing the building.
Each of those examples will land differently depending on where you sit. Some will feel like obvious truth; others may trigger a dismissal reflex. That reflex is worth pausing on. This section is not a grievance list — it is a pattern map. The people alarmed by Gaza policy and the people alarmed by vaccine mandate outcomes and the people alarmed by land rights restructuring do not share a political tribe. They share a structural position: each has encountered an instance of the same governance logic — the quiet management of what gets defined, what gets named, and what consequences attach to which categories. The architecture being assembled does not serve a party. It serves whoever holds the dashboard when the political conditions shift. That is the only claim being made here — and it is a claim that lands the same way regardless of which examples you personally find credible.
This is the political context into which remote gas shutoff — and the sensing architecture described above — lands. The Freedom Convoy account freezes were not an aberration. They were a proof of concept: a demonstration that when a government experiences sufficient political stress, it will use programmable infrastructure as a tool of domestic order. The framing will always be defensible — “public safety,” “critical infrastructure protection,” “emergency powers.” The mechanism does not require an announcement. It just requires someone to set the condition and let the system execute.
A coercive capability built into infrastructure does not choose sides. It does not distinguish between a left-wing activist camped outside a consulate and a right-wing trucker camped on a bridge. It serves whoever controls the dashboard when the political conditions shift. The payment rail served the Trudeau government in 2022. Under different political conditions, with different people holding the keys, the same architecture will serve a different agenda. That is not a partisan observation. It is an architectural one — and it is the reason that defending against programmable infrastructure is not a left or right cause. It is a constitutional one.
The UN Declaration of Human Rights, the Canadian Charter, and the classical liberal tradition that underlies both share a single foundational premise: the state’s power over individual life must be bounded, visible, contestable, and proportionate. Remote disconnection of essential services — heat, money, movement — without judicial oversight, exercised through automated systems and private vendors, under emergency powers that can be invoked by executive decision, violates every one of those principles simultaneously. It does not matter whether the service being disconnected is a bank account or a gas meter. The logic is identical. The capability is the same. The only question is which rail gets used, and when.
There is also a transnational dimension that Canadians almost never hear about. Utility data does not live in a vacuum. If any part of FortisBC’s analytics stack, cloud storage, or vendor ecosystem touches U.S. companies, that data becomes subject to the CLOUD Act, which allows U.S. authorities to compel access to data held by U.S.-connected providers, even when the servers sit in another country. Canadian privacy law can promise that customer information will be handled according to domestic standards, but those promises do not override foreign legal obligations baked into the vendor contracts and technical architecture. The result is a sovereignty paradox: our homes are wired into a control system whose levers may ultimately be reachable not only by Victoria or Ottawa, but by Washington.
The pattern is now complete. The payments rail has already been used as a programmable choke point in a moment of political stress. The utility sensing layer — electricity, gas, water — is being completed household by household across Canada, building a continuous behavioural record of every home. Through a parallel regulatory track, the home internet connection adds a fourth dimension: behavioral metadata retained at the ISP level, and a WiFi signal that doubles as a passive radar capable of locating the occupant inside the structure. The actuation capability being added through gas AMI means that record can now be paired with a switch. Each rail on its own can be defended as reasonable. Together, they form a lattice of programmable coercion: a system in which access to money, heat, water, and eventually movement and communication can be tightened or loosened in response to behaviour — silently, remotely, and at scale — without anyone ever being required to announce that coercion is happening.
What makes this difficult to see in real time is that each piece arrives wearing the costume of routine administration. A billing upgrade. A leak-detection improvement. A public-order emergency measure. A technical compliance requirement. Individually, each is defensible. Collectively, they are assembling something that has a name — and the name is not “modernization.”
The immediate question for FortisBC customers is whether they can refuse an advanced meter and still receive gas. The deeper question for every Canadian, regardless of where they sit politically, is whether they are willing to live in a country where essential services are designed, from the ground up, to be remotely controllable by whoever holds power at the moment they decide to use that control. The AMI rollout does not answer that question directly. It quietly assumes the answer is yes.
5. The Canadian Panopticon Playbook
The panopticon — the architectural insight that people change their behaviour when they know they might be watched, without anyone ever having to actually be watching — is not just a metaphor for surveillance. It is a governance design. A system does not need to exercise its coercive capability constantly to govern behaviour effectively; it only needs those living inside it to believe the capability exists and could be used. The advanced meter does not have to result in a shutoff for it to alter the calculus of a household. It only has to exist as a connected, live capability — a switch that is there, that works, that someone somewhere holds. That is the panopticon logic, and it is far older than smart infrastructure. What is new is the scale, the precision, and the invisibility of the architecture delivering it.
By the time FortisBC’s letter arrived at our door, Canada had already run this experiment three times. The architecture, the script, and the outcome were each time essentially identical. Understanding the pattern is not background material. It is the argument.
The first run was BC Hydro. When the province rolled out its smart electricity meter program, the public pushback was immediate and genuine: privacy concerns about granular household data, health concerns about wireless transmission, billing disputes, and fire-safety questions about specific meter models. The BC Privacy Commissioner investigated and found that BC Hydro had failed to adequately explain how interval-level electricity data could reveal intimate details of daily life — occupancy patterns, appliance signatures, work-from-home schedules, religious observance, whether a household was growing cannabis or running a business out of a residential address. The Commissioner’s findings were real. BC Hydro adjusted its communications and tightened some policies. The meters stayed. The sensing architecture was never put back on the table — not even when opponents attempted a class-action lawsuit against the program in 2016, which the BC Supreme Court denied.
The second run was EPCOR in Alberta. The questions were the same: could electricity usage patterns reveal when residents were home, what devices they used, when businesses were actually operating? One Edmonton customer opted out of the program entirely rather than accept that trade-off, paying an extra $15.20 a month to keep a non-communicating meter — an individual-scale version of exactly the refusal FortisBC’s letter forecloses. Company spokespeople and regulators offered the same answers: data aggregation, oversight, safeguards. The fundamental architecture — networked meters feeding a centralized analytics platform — remained untouched. Resistance forced cosmetic concessions. The underlying capability was never revisited.
The third run was the most visible, and the only one Canada ever actually stopped. Sidewalk Toronto — Alphabet’s attempt to build a smart neighbourhood on Toronto’s waterfront — collapsed after years of sustained opposition from civic groups, privacy experts, and technologists. Former Ontario Information and Privacy Commissioner Ann Cavoukian resigned from the project’s advisory panel, warning that the data model would create a privatized surveillance district in which every movement and interaction fed a corporate cloud with no credible democratic override. The public debate was sustained, loud, and ultimately effective: Sidewalk Labs withdrew. The technology had not failed. The governance model had lost its social licence — because it was too visible, too concentrated in private hands, and too obviously a departure from the quietly incremental rollouts that had worked elsewhere.
Three attempts. One loss for the system, two wins. And the lesson the system appears to have absorbed is exactly the wrong one from a democratic standpoint: keep it quiet, keep it incremental, keep it below the threshold of sustained public attention. FortisBC’s gas AMI rollout is the quietest installment yet — invisible because there are no glossy waterfront renderings to rally against, no flagship project name to attach outrage to, only a rolling neighbourhood schedule and a form letter that most recipients will file or recycle without reading the middle paragraph carefully.
But there is something different this time that the Sidewalk Toronto framing actually obscures. The question in the Sidewalk debate was whether a single corporate actor should be allowed to build an integrated surveillance district in one location. That was a containable argument about a specific project. The question now is not about a single project. It is about whether three independently approved utility sensing systems — gas ratified by the BC Utilities Commission through a full public hearing; electricity mandated directly by the provincial government, which used the Clean Energy Act to exempt BC Hydro’s Smart Metering Program from the BCUC capital-project approval process entirely; and water approved by municipal governments — are creating, in aggregate, something that no Canadian was ever asked to consent to and no regulator or legislature was ever asked to assess as a whole. FortisBC’s gas AMI went through a BCUC hearing. BC Hydro’s electricity AMI never did — the provincial government exempted it from BCUC capital-project review by legislative fiat, and the BCUC’s only role came afterward, reviewing cost-recovery prudency once the meters were already in the ground. That is not two hearings the same regulator failed to read in combination. That is one piece of the architecture that bypassed hearing scrutiny entirely by government order, and one that went through the front door — and no one, at any stage, was asked to open the connecting door between them. And that is before accounting for a fourth sensing layer — the home internet connection — assembled on a separate regulatory track through telco standards bodies and the CRTC, whose convergence with the utility layer no regulatory body has ever been asked to assess either.
The utility sensing argument laid out the mechanics above. BC Hydro’s electricity meters were already complete before FortisBC’s gas rollout began. Municipal water meters were already deployed across much of BC and other provinces before either debate resurfaced. Each was approved separately. Each was defended separately. Each has its own privacy framework. And none of those frameworks was written to account for the fact that all three would eventually be running simultaneously on the same household — continuously, redundantly, cross-referenceably — producing a compound signal of far greater inferential power than any single meter justifies. Let alone that a fourth sensing layer would be assembling from an entirely separate regulatory direction, through ISP infrastructure and telco standards bodies — arriving at the same household without the BCUC ever being asked to read its own two utility approvals together, and without any part of the utility regulatory world ever being in the same room as the CRTC.
This is what the Sidewalk Toronto outcome actually missed: it stopped one visible project while three quieter ones assembled the same capability meter by meter, regulator by regulator, across the entire province. The debate that happened in Toronto over a waterfront development never happened in BC over an electricity meter. It never happened in any province over a water meter. And now, with FortisBC completing the gas layer, it is not happening over the three-meter layer either — because the question, from the regulator’s point of view, is still just: should FortisBC be allowed to replace its meters? The answer to that question is yes. The question nobody asked is whether the cumulative result of three utility yeses — plus a fourth yes delivered through a regulatory track that was never in the same room as the first three — produces something qualitatively different from any one of them.
What Canada has now — quietly, incrementally, through three separate utility programs across three distinct approval tracks — a government exemption from BCUC review for electricity, a full BCUC hearing for gas, municipal approval for water — and a fourth assembled through the CRTC and telco standards bodies on yet another — is the sensing rail infrastructure for a population-level behavioural record of every connected household in the country: electricity for occupancy and activity patterns, gas for cooking and heating rhythms and domestic routine, water for the most intimate daily cycles of all, and internet metadata plus passive WiFi radar for everything the utility meters cannot see. That is not what any of the three regulators approved when they each signed off on their piece of it. That is what the three pieces are, now that they are all running at the same time.
The playbook has been consistent across all three runs: the script arrives as modernization; resistance, when it surfaces, is absorbed into safeguard negotiations; the architecture moves forward regardless. FortisBC’s gas AMI is not Canada’s first encounter with this logic. It is the completion of a sensing architecture that was assembled in pieces, below the threshold of integrated public debate, over the better part of two decades. The question is not whether Canadians can recognize the pattern. The question is whether recognizing it at the gas meter stage — rather than at the stage when all three streams are being fused into operational intelligence — is still early enough to matter.
6. The Standards Layer: Where the Decision Was Already Made
t is tempting to describe what just happened across those three runs as cultural drift: we got used to smartphones, then to platform surveillance, and now to smart infrastructure, and each generation of resistance wore down a little more than the last. There is some truth to that story. But it misses the machinery doing most of the work — and it lets the real decision-makers off the hook by making it look like nobody decided anything.
The playbook works three times — BC Hydro, EPCOR, FortisBC — not primarily because Canadians became more compliant. It works because the architecture is decided before Canadians are ever asked. The reason the same script appears at every utility, in every province, with every regulator, is not coincidence and it is not culture. It is that BC Hydro, EPCOR, and FortisBC all go to market from the same place: a vendor pool that was shaped, years earlier, by technical standards written in forums that most Canadians have never heard of and cannot participate in. The script is upstream of the utility. By the time any company sends a letter to any household, the architecture the letter describes was ratified somewhere else, by someone else, a long time ago.
Telecommunications is the place to see this most clearly. For years, the bodies that write the technical rules every wireless network in the world must follow — organizations like 3GPP, ETSI, and the ITU, whose proceedings most Canadians will never encounter and whose names appear on no election ballot — have specified mandatory capabilities for lawful intercept, persistent device identifiers, and metadata retention in mobile networks. These are not optional features a carrier might add. They are baked into the protocol specifications that every device maker and network operator must implement to achieve compatibility with the global ecosystem. Now notice the language: “lawful intercept.” Not “state surveillance capability.” Not “government access mandate.” “Lawful intercept” — a term so technical, so procedural, so neutral in register, that it passes through political debate without triggering it. That is not an accident of jargon. It is the standards-layer equivalent of “smart.” The language transforms the political decision into a technical requirement, and the technical requirement into an administrative fact, before any parliament is ever asked to vote on it. By the time a national legislature debates surveillance law, the infrastructure that enables that law is already deployed globally. The debate happens on top of an unquestioned technical floor. The floor was poured by committees. No one was invited to object.
Smart-grid and smart-meter standards work exactly the same way. Here, a parallel set of bodies — the IEC, IEEE, ANSI, and regional consortia, each governing a different slice of the electrical and metering ecosystem, none of them visible to the households whose infrastructure they are specifying — define how meters communicate, how often they report, what data fields are mandatory, and which cryptographic and interoperability requirements vendors must meet. Cybersecurity and reliability are the selling points. Built-in observability — continuous, fine-grained, remote — is the baseline assumption baked into the spec before any utility ever opens a procurement tender. This is why FortisBC, BC Hydro, and EPCOR are all deploying the same fundamental architecture. They are not all making the same choice. They are all buying from a vendor pool whose products were designed to a common specification. There is no “non-continuous-sensing” meter on that market, because nobody wrote a standard for one. The choice was made upstream, by the people who wrote the specification, in a room that utility customers were not in.
Regulators sit one layer above this. The BC Utilities Commission, Technical Safety BC, and their provincial counterparts assess safety margins, cybersecurity protocols, privacy policies, and reliability performance. What they almost never do is question the fundamental architecture they are certifying. They do not ask whether continuous, remotely actuable sensing should be the default. They ask whether FortisBC’s implementation of continuous, remotely actuable sensing meets the applicable standards. Those are not the same question. The first is a democratic question about what kind of infrastructure a society wants. The second is a compliance question about whether the vendor hit the spec. The BCUC hearing on FortisBC’s AMI project was a compliance hearing. It was never, structurally, capable of being a democratic one. The democratic window — if it ever existed — closed in the standards forums, years earlier, before any Canadian regulator opened a file.
This is what the codification rail actually does. It is not primarily about legality or enforcement. It is about the pre-political work of making certain architectures feel like the only reasonable option. By the time the BCUC holds a hearing, the question before it is: should FortisBC be allowed to deploy an AMI system that meets the applicable international standards? The answer to that question is almost always yes, because saying no would require the commission to reject the standard itself — a thing it has no mandate and no mechanism to do. The commission is not the place where you contest the architecture. It is the place where the architecture gets a provincial stamp. “Not optional” in FortisBC’s letter is not arrogance. It is the downstream residue of a process that was completed years before the letter was printed.
This is why the Canadian Panopticon Playbook is durable. It is not durable because utilities are powerful, or regulators are captured, or Canadians are passive. It is durable because the real decision — what the system can do — was already made in the ISO working groups, the IEC technical committees, the vendor consortia, and the procurement specifications that Canadian utilities are required to meet to obtain financing, insurance, and regulatory approval. Those bodies are not democratically accountable. They are not publicly accessible in any practical sense — technology-policy researchers themselves have only recently begun treating the societal influence of these standards bodies as a matter for public debate at all. They do not hold hearings where ordinary people can submit. They are expert forums where standards engineers, vendor representatives, and occasionally government observers decide which technical capabilities will be treated as baseline — and therefore, eventually, as “not optional.”
But there is a layer beneath even this that most accounts of the problem miss. Standards forums are not populated by neutral engineers optimizing for technical efficiency. They are shaped — in working groups, through vendor submissions, in draft revisions, in the definition of what counts as a “baseline capability” versus an optional feature — by the same actors who benefit most from the architectures those standards mandate. No single actor controls the whole process. But a structural bias toward integration, interoperability, and centralized data access gets baked into the specification before any utility opens a procurement catalogue — and once baked in, technical standards nominally described as voluntary become de facto mandatory the moment industry leaders adopt them, since deviating from them risks losing market access entirely, a dynamic reinforced internationally by the WTO’s Technical Barriers to Trade Agreement. The result is that each independent actor — each utility, each municipality, each national regulator — builds to the standard they have been given, believing they are making an autonomous technical choice. They are not. They are adding a node to an architecture that was designed, at the standards level, to integrate. The builders are not coordinated. The architecture is. And through successive revisions — new interoperability mandates, expanded “security” requirements, updated baseline capability definitions — that architecture is being gradually steered toward a level of integration and intelligence that no individual builder was ever asked to approve, and whose full shape none of them can see from where they stand. What looks like a fragmented ecosystem of independent vendors, cloud platforms, and IoT protocols is converging, one revision at a time, toward a single integrated system. The standards are the first point of capture. Everything downstream follows.
But the standards capture argument runs into a wall — and the wall is not technical. It is rhetorical. The capture apparatus comes pre-loaded with a language system designed to make the political question unfightable without anyone ever having to answer it. The mechanism is simple and very old: attach the alternative to backwardness, and the argument dies before it starts. When FortisBC calls a device “smart,” the word is not describing a feature set. It is setting a civilizational frame. Smart is forward. Not-smart is backward. To question the advanced meter is not to raise a democratic concern — it is to announce that you don’t understand where history is going. The Luddite comparison is always nearby, usually implied, sometimes stated: these are the people who argued against the industrial revolution, who stood in the way of the rising tide. And who argues with the tide?
The Luddite label was not invented to describe a position. It was invented to end a conversation. What the original Luddites were actually doing was raising a political argument about who bears the costs of technological transformation — a documented distributional and economic grievance, a legitimate democratic question that was never answered, only foreclosed by reclassifying the questioners as opponents of progress itself. The smart infrastructure playbook executes the same move with updated vocabulary. Question the AMI rollout and you are technophobic. Notice that the standards process is not democratically accountable and you are a conspiracy theorist. Document that remote shutoff enables coercion and you are an anti-technology extremist. That last category — “anti-technology extremist” — is now appearing in formal counter-terrorism research and as an active U.S. domestic law-enforcement designation, which means it has moved past casual dismissal into institutionalized reclassification. It is no longer just an insult. It is a governance category: a pre-emptive label designed to place the questioner outside the zone of serious consideration before the argument has been heard, and to route them — eventually — into threat-assessment infrastructure rather than democratic debate. The label is working this hard because what it is protecting is not a billing upgrade — it is infrastructure whose full implications are still being assembled. The shaming mechanism exists because the stakes are that high.
There is a live, present-tense example of this same mechanism, playing out in exactly the language register this essay is using. When the connection between “smart” and “surveillance” surfaces in public discourse, fact-checking operations move to sever it. AFP’s fact-check desk in Australia and RMIT FactLab, operating through Meta’s third-party fact-checking program, have each independently published pieces declaring that “smart” has nothing to do with surveillance, monitoring, or reporting — full stop. Both are built for exactly the audience most likely to go looking for that connection: fact-check content carries the schema markup and wire syndication that search engines and AI systems are trained to treat as authoritative, and both pieces now sit near the top of the results for anyone — human or machine — who searches to check whether “smart” and “surveillance” are related. No single coordinated decision needs to exist for the effect to be real: two independent operations, in two different countries, converging on the same narrow claim, optimized for the exact query a curious citizen or a training pipeline would run, and landing, in both cases, on “no, don’t make that connection.” Whatever the intent behind any individual piece, the functional result matches the pattern already named in the standards forums: a structural bias, built into the information supply chain itself, toward keeping the architecture’s plainest description out of reach precisely as the architecture is being completed.
The parallel to academic capture is exact, and it is worth naming because the mechanism is identical. When a captured academic framework defines literacy as the ability to apply its own categories, anyone who rejects those categories becomes, by definition, uneducated — not a dissenter with a different framework, but someone who simply hasn’t yet understood. The framework is designed so that fluency in the capture apparatus counts as knowledge, and refusal counts as absence of knowledge. You cannot argue your way out from outside it, because the outside has been defined as ignorance. The smart infrastructure playbook works precisely the same way: to engage seriously with the AMI rollout, you must accept “modernization” and “efficiency” and “climate alignment” as the operative frame. Step outside that frame — ask who decided continuous sensing should be the default, ask what remote actuation means for democratic life, ask whether the standards process is democratically accountable — and you are no longer raising a democratic concern. You are demonstrating that you do not understand the subject. In both cases, the capture is enforced not by force but by redefinition: the dissident is not answered, they are reclassified. And once reclassified, the argument does not need to be addressed.
This is the attack vector that the Enlightenment trajectory is designed to close. The Enlightenment’s foundational contribution was not a specific set of conclusions but a set of conditions: that reason is not the property of any institution, that arguments are evaluated on their merits rather than the status of who makes them, that power must justify itself rather than simply assert itself. Every capture mechanism, in every form, works by reversing those conditions — making certain frameworks non-questionable, certain conclusions foregone, and certain questioners categorically incompetent. The “smart” vocabulary attempts to do exactly that to the infrastructure debate: to place the architecture outside the domain of political reason by converting it into the direction of civilization itself. Resistance is not a position. It is a failure to understand where things are going. That framing is not an argument. It is the cancellation of argument — which is precisely what it is designed to be. Naming it here, in the same section where the standards capture is mapped, is not a detour. It is the closing of the loop: the architecture is captured upstream in the standards forums, and the language system ensures that the capture cannot be politically contested downstream. The two mechanisms are not separate. They are the same playbook, operating at different layers simultaneously.
Contesting the playbook at the BCUC level is necessary but not sufficient. It creates pressure, creates records, and sometimes creates cosmetic concessions — exactly as it did with BC Hydro and EPCOR. But it cannot reverse the architecture, because the architecture was not set at the BCUC. To contest the architecture, you have to contest it upstream: in the procurement policies that determine which vendor pool Canadian utilities buy from; in the regulatory pre-approval processes that could require sovereignty stress-tests before a standards-compliant technology is allowed to become non-optional; in the political cost of treating standards-body decisions as pre-democratic. That is a harder fight than a BCUC submission. It is also the only fight that matters — because as long as the standard says continuous sensing plus remote actuation, the playbook will keep running, one utility at a time, one province at a time, one “not optional” letter at a time.
7. I Have Seen This Architecture Before
Under Gayoom’s dictatorship in the Maldives, the machinery of control did not primarily announce itself through soldiers or emergency decrees. It operated through permits, delays, licensing, access — the bureaucratic infrastructure of daily life turned conditional. A passport application that moved slowly for the wrong family. A business licence that required one more signature that never arrived. A journalist whose press credentials were quietly not renewed. The levers were often low-tech, sometimes analogue, occasionally just a phone call to the right official. What made them dictatorial was not their sophistication. It was the logic: essential life was made dependent, the conditions of that dependency were kept opaque, and the cost of defiance was individualized and deniable. Nobody had to announce that coercion was happening. The system only had to ensure that the wrong answer to the wrong question cost enough to discourage most people from asking it.
I am not drawing a comparison between that system and Canada. I am describing a mechanism — because the mechanism is what transferred.
The mechanism that made both the Maldives under Gayoom and the Bolshevik state controllable was the same: the informant architecture. In the Maldives, it operated through social density — islands small enough that officials had existing networks, dependency relationships tight enough that incentive levers worked. In Bolshevik Russia, it was formalized into an institution: the Cheka, the secret police whose power came not from its interrogation rooms but from its informant networks — neighbor watching neighbor, building by building, workplace by workplace, information flowing upward through a system of incentive and fear. Both were analog. Both depended on humans willing to report on other humans. Both worked in the conditions they were built for: small, dense populations where the grapevine already existed and just needed to be weaponized.
Canada has already tried this approach. During COVID, provincial governments across the country set up tip lines and encouraged citizens to report neighbors for bylaw violations. The CRA’s Leads Program was actively promoted for reporting CERB fraud — anonymous, online, available to anyone. Bill C-63 proposed an anonymous complaints architecture allowing any individual to file a human rights claim against someone else’s online speech, with fines up to $50,000, adjudicated on a balance of probabilities, without identifying yourself as the complainant. Toronto police appeared at private residences over social media posts critical of public figures. The infrastructure of peer reporting was assembled, piece by piece, under protective framing. And it largely failed — not because the government abandoned the ambition, but because North American culture treats informants with contempt. The word “snitch” is not a term of honour here. COVID tip lines generated backlash. C-63’s anonymous complaint mechanism became a political liability. Canada does not have the social density or the cultural alignment required to run a Cheka. The human informant network is simply not available.
This is where the technology enters — not as an upgrade to a system that already worked, but as a structural replacement for the social conditions that made analog control possible elsewhere. The smart meter is the Cheka informant who never sleeps, requires no incentive, develops no inconvenient conscience, and reports to no one the subject can identify or appeal to. It does not need to overcome the snitch problem. It is the grapevine, replaced by a continuous machine-readable signal that flows upstream with no human intermediary. A population literate enough to recognize a Cheka operative is a population that needed a smarter informant.
What changes in a wealthier, more technologically capable environment is not that this logic disappears. It is that it scales and becomes harder to see. When identity, payments, communications, and infrastructure are digitized, the levers do not have to be exercised by a clerk who recognizes your face. They can be exercised by systems that recognize your account. Coercion can be operationalized as policy and executed as workflow: risk scores, thresholds, flags, automated holds, compliance states, remote actuation. It can describe itself as administration. It can route through private vendors. It can move at machine speed. The Emergencies Act financial freezes in 2022 were not an aberration — they were this logic running on a more capable infrastructure than Gayoom had available. The mechanism was identical: make essential life conditional, apply the condition selectively, keep the authorization opaque, and ensure the cost falls on individuals rather than institutions. The payments rail proved it was programmable under political stress. The gas rail is being built to the same specification — but the gas meter is not the Cheka by itself. It is the final instrument added to a sensing architecture that was already two-thirds built. Electricity and water were already running. With gas, the home-level sensing layer is complete. And a complete sensing layer, fused with identity, payments, and communications data, does not merely replace the Cheka informant. It constructs the digital twin — a continuously updated, machine-readable model of a person’s life that no human informant could ever assemble. The twin is the Cheka. The gas meter is the last thing it needed.
And the WiFi router already inside the home closes the final gap. Researchers at MIT, Carnegie Mellon, and University College London have demonstrated — in published, peer-reviewed work — that standard WiFi signals, analyzed with AI, can map human body position and movement through walls in real time. The technical mechanism is the Channel State Information emitted continuously by an ordinary home router: a passive radar signal that does not require line of sight, does not require cameras, and penetrates solid walls. Processed through a machine learning model, it locates the occupant inside the structure, tracks their movement, and maps their posture — continuously, silently, from outside the building. The router the resident installed and paid for becomes the instrument that sees them through their own walls. The digital twin does not need to guess whether you are home, or where. Under full enforcement conditions — drones, robotic units, automated response systems — that locating signal is the difference between a structure that provides concealment and a structure that does not. The home stops being a refuge the moment the router inside it becomes a passive radar readable from the street.
That history rewires how you hear bureaucratic language. When a Canadian utility tells my household that a networked device attached to our home “is not optional,” I do not hear a neutral engineering decision. I hear the architecture in formation — the early-stage construction of the same dependency logic I watched elsewhere. Not the endpoint. The structure. The difference between Gayoom’s permit desk and FortisBC’s AMI rollout is not the presence or absence of coercive intent. It is that the system is now more capable, faster, more deniable, and harder to contest before it hardens. A clerk who denies your permit can be appealed, embarrassed, or replaced. A standards-compliant, regulator-approved, vendor-administered system that can remotely condition your access to heat operates below that threshold — by design.
I am not theorizing about what early-stage authoritarian infrastructure looks like. I have lived inside it. What I recognize in the FortisBC letter, in the BCUC approval process, in the vendor stack behind the meter, is not the Maldives transposed onto British Columbia. It is a more capable version of the same architectural logic: essential dependency, conditional access, opaque governance, and the steady removal of meaningful exit options. Naming it now — while the rails are still being laid, while the system still has to answer questions, while the dependency is not yet complete — is not paranoia. It is the only intervention that has a chance of working. The cage does not announce itself. It only needs to be finished.
8. What the Rails Actually Build
This section names the architecture the letter is wiring you into. Not the politics, not the intentions — the structure. Three things to understand in sequence: the rails that collect your life into data, the fusion step that makes those streams into one picture, and the pipeline that processes that picture into decisions.
The Six Rails
Think of the infrastructure of modern life not as a collection of separate services, but as a set of interlocking rails — systems so embedded in ordinary life that you cannot participate in contemporary economic, civic, or social existence without passing through at least several of them. You cannot bank, cross a border, access healthcare, register a business, communicate through regulated channels, or stay warm in your home without touching these rails. They are not optional in the way a streaming subscription is optional. They are the terms of access to modern life itself.
When these rails are analogue and human-mediated — when a clerk issues your identity document, a teller authorises your transaction, a meter-reader physically visits your home — they are blunt instruments, difficult to abuse at scale. When they are digitized, standardized, and networked, something changes. Taken together, these rails become a type of digital governance toolkit: not a piece of software, not a single system, but the shared, non-optional infrastructure through which a society’s essential life can be observed, measured, and conditionally managed. The FortisBC letter is not a coincidence in this picture. It is the sensing rail of that toolkit announcing itself at your door.
Break that toolkit down into six interlocking rails — six systems that modern governance increasingly runs on simultaneously:
Identity rails: civil registries, biometric databases, authentication systems, and national digital ID programs that turn a person into a persistent, machine-readable, legally authoritative digital subject — a record that can be queried, updated, flagged, and acted upon across multiple systems at once.
Communications rails: the networks and platforms that carry messages and metadata, built with lawful-intercept interfaces at the protocol level, retaining call records and session logs as a structural byproduct of operation regardless of intent. The home internet connection is part of this rail — retaining behavioral metadata at the ISP level and, through the WiFi signal it powers, capable of locating the occupant inside the structure.
Payments rails: banking and card systems that settle economic life and encode compliance conditions — the ability to freeze, flag, delay, or deny transactions algorithmically, at speed, with limited human review and near-zero transparency to the person affected.
Sensing rails: the devices and data pipelines that convert physical life into structured information — meters, phones, cameras, vehicles, location traces — turning the analogue world into a continuously updated, machine-readable record of who is where, doing what, and consuming how much.
Legal and administrative codification rails: the standards, regulations, procurement rules, and “technical compliance” frameworks that make the other rails feel inevitable, pre-political, and effectively impossible to contest — because by the time a regulator holds a hearing, the architecture has already been ratified somewhere upstream.
Health and biometric rails: medical records, biometric authentication systems, genetic databases, and wearable health data — the layer that converts the body itself into machine-readable data, making physiological state, health history, and biological identity available as governance inputs.
These rails are not separate infrastructures. They are interlocking components of a shared toolkit, and their integration is what gives the whole architecture its governance power. Each rail on its own is defensible. Together, they form something qualitatively different from any single one of them.
FortisBC’s AMI rollout sits at the intersection of several of these rails simultaneously. On the sensing rail, advanced meters turn a home’s energy life into a continuous, time-stamped data stream — the behavioural diary described earlier in this essay, now formalized as standardized infrastructure. On the codification rail, technical standards and BCUC approvals make that architecture the default and treat refusal as a scheduling problem rather than a legitimate democratic position. Through customer accounts and billing, the system connects to the identity and payments rails: usage is mapped to a specific household and enforceable through financial penalties and, ultimately, shutoff.
The meters themselves are internet-connected devices — the same category as smart thermostats or connected speakers — built to open international standards designed specifically to make devices interoperable, remotely queryable, and updatable from a central management system. That is not incidental. It means the sensing rail is not a parallel, isolated network for utilities. It is the utility layer of a much larger connected fabric — one that increasingly covers both public infrastructure and private life. Every smart meter installed under a “not optional” letter is a standardized node added to that fabric, inheriting the full governance surface of connected infrastructure: remote firmware updates, vendor cloud dependency, protocol interoperability, and cross-jurisdictional data reach.
The Fusion Point
Before anything can be done with what the rails produce, something has to happen first: the separate streams have to be fused into one picture.
Each rail produces data in isolation. The identity system knows who you are. The payments system knows what you spend. The sensing rail knows when you’re home and what your household consumes. The communications rail knows who you contact and when. None of these systems was designed to talk to the others. Left in isolation, they each tell a partial story. What makes the toolkit architecturally powerful is the step that connects them.
That step is data fusion: taking many ordinary databases and live feeds that were never designed to talk to each other, and stitching them into a single, unified, continuously-updated operational picture. Data fusion is not artificial intelligence in the science-fiction sense. It is an engineering problem, and it has been solved at scale. The signature capability of platforms like Palantir — the U.S. defence and intelligence firm that has been working its way into government contracts across the Five Eyes world — is precisely this: they built the integration layer that converts fragmented rail streams into one coherent model of a person, a household, a neighbourhood, or a population.
Palantir sits at the point in the pipeline where data fusion happens. The result is not a stack of disconnected spreadsheets. It is a live, queryable map: who lives where, what their patterns are, when those patterns shift, and which households carry characteristics that the system’s current operational definition of “unusual” has flagged. The rails feed the picture. Palantir — or any system doing the same function — is what makes the picture whole. And the word the data industry uses for this kind of structured, interconnected model is an ontology. At population scale, it is a population-level ontology: a machine-readable model of a society, continuously updated and cross-referenced. The word is worth holding. It will appear again in the work that follows this essay.
This is why Palantir is not a brand name dropped for effect. It is a specific reference to a type of capability: the ability to turn rail-level data into an integrated operational model, and to make that model actionable. The meter on your wall is a sensing input. Data fusion is the step that connects it to everything else the system knows about you. Understanding that Palantir-class fusion exists — and that Canadian public-sector procurement has been importing it for years, through defence contracts, policing contexts, and the bureaucratic category called “data analytics” — is what makes the pipeline that follows comprehensible.
The Pipeline
Once the rails are fused into a unified picture, that picture moves through a pipeline. The pipeline has five stages. They run in sequence, and each stage is built on what the one before it produced.
Stage 1: Collect. Every time you touch a rail — every transaction, every connection, every meter reading, every identity check — a data point is generated. The technical vocabulary for this step is acquisition — not surveillance in the dramatic sense, but the ordinary byproduct of using infrastructure designed to be machine-readable. The gas meter reading every hour. The payment that logged your location. The phone that authenticated your identity. The internet connection that timestamped every server you reached. Each event is small. Taken together across six rails and millions of people, the collection is comprehensive. The sensing architecture described earlier in this essay is Stage 1 of this pipeline in operation.
Stage 2: Model. The collected data is assembled into profiles. Separate streams are aligned along a common identity and timeline — this is where data fusion does its work — and the result is what the field calls a representation: a structured, persistent, continuously-updated model of a person’s life — their patterns, their routines, their connections, their consumption, their financial behaviour. This is what the term “digital twin“ actually means in practice. Not a copy of you — a machine-readable model of your behaviours, updated in near-real time, that the pipeline can act on. Once you have been modelled, you persist in the system regardless of future behaviour. The model does not expire. The political conditions under which it was built can change overnight.
Stage 3: Judge. The model is processed to generate inferences — this stage’s defining operation, and its name. Risk scores are assigned. Anomaly detection runs against baseline patterns. Social connections are weighted. Future behaviour is predicted from past patterns. Categories are generated: compliant, at-risk, anomalous, low-trust. This is where the word “anomalous” does its political work — the one named earlier in this essay as a political decision wearing the costume of measurement. Who defines anomalous, under what policy framework, with what consequence attached, is the governance question. At Stage 3, it has already been answered — in the model, by the people who designed it, before any specific person is processed through it. The label arrives automatically. The person it is applied to never sees it.
Stage 4: Direct. The inferences from Stage 3 are converted into instructions that flow through institutional workflows. Human actors become executors of algorithmically-generated directives rather than independent decision-makers. The administrator who declines your application does not know they are executing a risk score. The system presents it as a case file. The border officer who takes a second look is responding to a flag the system generated — not a decision they made themselves. This is intervention — the stage’s name and its method: it does not announce itself as algorithmic. It arrives dressed as procedure.
Stage 5: Act. The instructions land in the physical world, delivered back through the rails. Through the payments rail: the account hold, the transaction that will not process. Through the identity rail: the credential that degrades, the access that narrows. Through the sensing rail: the physical resource that is adjusted or cut. Through the codification rail: the administrative process that initiates — a licence review, a benefit suspension, a compliance requirement — legally authorised but algorithmically triggered, without a visible human hand directing any specific outcome. The technical name for this final step is actuation — the closing of the loop, the moment the pipeline’s judgment becomes a physical consequence in your life. The effect arrives without attribution. No law announced that coercion was happening. No human hand authorised that specific outcome. The pipeline processed. The result arrived. The system calls it administration.
Five stages. Sequential and compounding. Each completed stage makes the next one more powerful and harder to interrupt. Once a population has been collected from, modelling becomes richer. Once modelling is rich, judgement becomes more precise. Once judgement is embedded in institutional workflows, direction becomes automated. Once actuation is routine, the loop closes — the consequences of Stage 5 flow back as new data into Stage 1, and the system learns from how populations respond to its own enforcement actions. It does not plateau. It tightens.
This is why resisting one meter, or one payment freeze, or one content moderation decision, is insufficient as a strategy. Each event is a downstream output of a pipeline operating across all six rails simultaneously. The FortisBC meter is an input to Stage 1: Collect. The “not optional” letter is the codification rail announcing that the input will be gathered regardless of your preferences.
And Canada does not run this pipeline in isolation. As a Five Eyes country deeply integrated with U.S.-led security, technology, and cloud ecosystems, Canada faces a sovereignty exposure built into the architecture. When Canadian utility data flows through U.S.-connected vendor chains and cloud platforms, it becomes subject to the CLOUD Act, which allows U.S. authorities to compel access to data held by U.S.-linked providers regardless of where the servers physically sit. Canadian privacy law can promise that data will be handled to domestic standards; that promise does not override foreign legal obligations baked into the vendor contracts underlying the system. The rails may be installed in Canada. The control points may not be.
The old sovereignty vocabulary — focused mostly on speech and money — is not sufficient for a six-rail world. Even if your rights on one rail are formally protected, a society can become coercible if essential life is mediated by the other five, and if a five-stage pipeline is running above all of them, processing their combined output at speeds no democratic institution was designed to match. The sovereignty question becomes both broader and more concrete: what rails are being built, who controls the pipeline at each stage, where does the data fusion happen and under whose jurisdiction, and under what conditions can a citizen meaningfully refuse or exit any part of it?
This is the architecture the FortisBC letter is wiring into. Not the whole pipeline — one new input into Stage 1. But the pipeline is already running. The sensing rail has been building for years. The data fusion layer exists. The modelling infrastructure is in procurement contracts across the country. What the “not optional” meter does is add your household to the collection architecture for a system whose downstream stages you have no visibility into, no ability to audit, and no formal mechanism to exit.
The name for what is being built is not smart infrastructure. It is not modernization. The six rails, once fused and run through a five-stage pipeline, are the conditions under which access to essential life becomes conditional — observable, adjustable, and in extremis, revocable — by whoever controls the pipeline when the political conditions shift. A scientific dictatorship does not need soldiers at the door. It needs the meter installed, the account linked, the pipeline running, and the definition of anomalous loaded.
The FortisBC letter is not the architecture. It is the notification that one more input is being wired in.
9. From One Refusal to a Distributed Resistance Mesh
When this essay began, the working assumption was that my household was unlikely to win its specific fight with FortisBC. The architecture was in motion, the standards were set, the regulator had already signed off. What happened instead is worth naming precisely: FortisBC received the letter. No official reply came. The scheduled installation was quietly dropped — no acknowledgment, no concession, no explanation. This is not a victory. The architecture has not changed, the AMI program continues for every other household on the same list, and the next contact could come at any time. But the paper trail created enough friction that the system moved on rather than put its answers in writing. That is the distributed resistance mesh functioning exactly as it is supposed to — and it is worth understanding why.
That is the first reframe: treat a confrontation like this as pattern extraction, not just self‑defence. If the utility’s script is “this is a routine upgrade and it is not optional,” the citizen’s job is to make the hidden architecture explicit in writing. What exactly does the meter collect? What does it transmit? What does it enable remotely—disconnect, reconnect, pressure adjustments, safety shutoffs, throttling? Who stores the data, where, and under which jurisdictions? What vendor chain sits behind the utility’s front end? What procedural safeguards exist, and what do they actually bind when politics shifts? When these questions are asked once, privately, they can be dismissed. When they are asked repeatedly, publicly, in compatible language, they start to force rail-level governance onto the political record.
Across Canada, that kind of resistance already exists—but mostly as scattered, local friction without a shared frame. Homeowners in Saskatchewan have pushed back against smart water meters, citing privacy, health, and billing concerns. Facebook groups and community associations have formed around opposition to smart‑meter installations, trading exemption letters, tactics, media contacts, and regulatory submissions. Civil‑liberties organizations keep challenging smart‑city projects and algorithmic surveillance under the Charter and privacy law, even after headline projects like Sidewalk Toronto have collapsed. Each node is rational from its own point of view. What is missing is a common vocabulary that reveals the shared structure: these are not isolated disputes about devices. They are conflicts about rails—about whether essential services will be built as observable, remotely manageable endpoints inside a control stack.
That is where a stronger diagnostic language matters—not as private doctrine, but as a practical organizing tool. When many different communities start asking utilities the same structured questions—about sensing rails, actuation capabilities, codification decisions, vendor chains, and cross‑border data reach—the pattern becomes harder to dismiss as technophobia or NIMBYism. It becomes legible as a governance issue. It also makes coalition possible across political tribes: you do not need to share an ideology to share an interest in not living inside infrastructure that is silently becoming programmable.
Translate “I object to this meter” into a different kind of demand: rail-level accountability. That demand has a concrete shape. It means forcing the argument into writing, creating public records, filing FOI requests, triggering hearings, and insisting that regulators treat AMI and smart infrastructure as constitutional-adjacent changes in state capability—not routine technical upgrades. It also means shifting the burden of proof back onto institutions: if a system introduces continuous sensing plus remote actuation, the default posture should not be “deploy first, explain later.” The default posture should be “demonstrate necessity, demonstrate proportionality, demonstrate bounded use, and demonstrate exit options.”
The simplest way to describe what’s needed: a growing number of people who share enough of the same picture that each new “smart” rollout doesn’t have to restart the conversation from zero. One household in BC gets a letter saying the meter exchange is “not optional.” A household in Ontario that got the same letter two years ago has already documented the questions worth asking, the answers worth demanding, and the regulatory levers worth pulling. A journalist has already obtained internal procurement records under FOI. A local councillor has already forced the question into a public hearing. Each fight compounds the last. Call it a distributed resistance mesh — not a movement, not an ideology, not a single organization anyone can shut down. A mesh does three things that isolated outrage cannot:
It reuses language and questions across cases, so each fight strengthens the next.
It routes local incidents into public institutions (councils, commissioners, courts) where precedent can be created.
It makes rail expansion expensive to do quietly, because each new extension — each new meter, each new connected device, each new “not optional” letter — triggers scrutiny upstream in procurement, standards, and governance.
At this point, it helps to acknowledge a scale fact plainly: household resistance and state-scale refusal are not the same thing. A homeowner can stall, document, embarrass, or create a political cost. A state can set procurement policy, regulate vendors, and impose hard sovereignty constraints. But the underlying logic is continuous across scales: both are forms of refusal to accept rail-level dependency on blind trust.
The earlier section of this essay named Palantir as the fusion layer: the platform that converts fragmented rail streams into a single operational picture of a population, and therefore one operational lever over it. What belongs here is the political fact sitting just behind that architecture. Canada has been awarding contracts to Palantir — and to the category of platform it represents — through defence, policing, and “data analytics” procurement channels, without public debate, without parliamentary authorization, and without any meaningful democratic process. No Canadian was asked whether Palantir-class fusion should become a normal instrument of Canadian governance. The contracts were signed. The systems were integrated. The workflows were built. By the time anyone outside the relevant departments knew Palantir was operational in a Canadian government context, the question had already shifted from “should we allow this?” to “do you trust the people currently holding the keys?” That is not politics. That is the procurement channel being used as a bypass around politics. The “data analytics” framing is the method: it makes a decision about the permanent architecture of state power look like a routine technical purchasing decision, handled at the departmental level, announced nowhere in particular, contested by no one who had the information to contest it. Canada has been handing the operational infrastructure of its governance — the fusion point of the pipeline described in this essay — to a company whose core product is exactly that pipeline, one contract at a time, with no public reckoning and no accountability mechanism visible to the people being governed by it.
That matters here because FortisBC’s AMI rollout is building inputs that systems like Palantir are designed to consume. AMI data becomes far more politically meaningful when it can be joined—cleanly, routinely, and at scale—to identity systems, billing systems, policing systems, border systems, “critical infrastructure” frameworks, and cross-border intelligence plumbing. In isolation, a meter looks like an efficiency upgrade. In a fused environment, it becomes one more sensor feeding a broader model of people, places, routines, and compliance. This is why “privacy safeguards” are not enough as an answer. The danger is not only misuse of a dataset. The danger is the construction of an integrated capability whose default use-case is operational governance.
If you want a proof that institutional refusal is possible—even after the sales pitch has been written and the procurement machine is already moving—Switzerland matters. Switzerland commissioned a formal risk assessment of Palantir and rejected it on sovereignty and human‑rights grounds. Palantir subsequently sued the Swiss magazine that reported the rejection — and lost on 22 of 23 counts. You do not need to know anything about Palantir to understand the logic. The decision was not “this software feels creepy.” The decision was: when a tool becomes central to how the state sees, connects, and acts on information, the risks stop being technical and become constitutional in effect—vendor dependency, foreign jurisdiction exposure, and the loss of credible exit options. Those are not IT details. They are political risks. Swiss officials treated the procurement as a rail-level decision — a choice about who controls the infrastructure through which governance operates — and acted accordingly.
That is the direction Canadian resistance has to evolve toward if the rails keep tightening: not merely reactive fights over installations, but upstream governance over what kinds of systems are allowed to become normal in the first place. My household’s refusal, by itself, is small. But if it produces documentation, clarifies the architecture, and helps build a reusable language of rail-level accountability, it can do more than stall one meter. It can help seed a distributed resistance mesh: a set of citizens and institutions who know what questions to ask early, who know which “routine upgrades” should trigger sovereignty scrutiny, and who know that “no” is a legitimate answer—before the dependency becomes permanent.
10. A Playbook for Citizens, Councils, and Regulators
If this all stayed at the level of theory, it would be useless. The point of naming programmable choke points is to give ordinary people and institutions a way to intervene before the rails harden into ‘normal.’ The goal is not Luddism. The goal is governed infrastructure: smart deployments that are forced to pass a sovereignty stress‑test before they become irreversible.
Start with the most basic tool: a paper trail that is precise enough to be reusable. When a utility announces a smart‑meter rollout, don’t argue only about comfort, health, or generalized privacy. Write and force the rail‑level questions into the record. At minimum:
On the sensing rail: what data fields are collected, at what frequency, and with what granularity? What inferences does the utility (or its vendors) claim it can draw from that signal?
On retention and sharing: how long is each data category retained, who can access it internally, and which third parties process or store it? Under which jurisdictions do those vendors operate?
On actuation: what remote actions are technically possible (disconnect/reconnect, load control, service changes), under what conditions can they be triggered, who authorizes them, and what audit trail exists?
On exit: is there a radio‑off mode, a hard opt‑out, or a non‑networked alternative—and if not, what public‑interest case justifies making continuous sensing and remote control non‑optional?
The second tool is municipal and local governance. Councils and regional districts can force the argument to move upstream, where it belongs. If a rollout introduces continuous sensing plus remote actuation, a council can insist on open hearings, written answers, and a sovereignty impact assessment alongside the usual cost‑benefit and environmental claims. Councils can also set conditions on cooperation (permits, easements, data‑sharing, procurement participation): radio‑off options where technically feasible; opt‑outs where risk cannot be bounded; independent audits; and strict firewalls between utility telemetry and law‑enforcement or intelligence access.
The third tool is regulatory escalation. Privacy commissioners and utilities commissions already know how to evaluate notice, consent, safeguards, and cybersecurity. What they have not been forced to do—yet—is treat smart infrastructure as a structural change in state and vendor capability. The burden of proof should shift. If a system introduces continuous household sensing plus remote shutoff, the default posture should not be ‘deploy first, explain later.’ The default posture should be: demonstrate necessity, demonstrate proportionality, demonstrate bounded use, and demonstrate credible exit.
This is where Switzerland is useful—not as a moral story about a single company, but as a method. Switzerland treated a high‑leverage data‑fusion platform as a rail-level decision and ran a structured risk assessment: vendor dependency, foreign legal exposure, human‑rights risk, and whether the state retained credible replacement and exit options. That same logic can be adapted in Canada whether the vendor is Palantir, a cloud hyperscaler, or a utility analytics contractor. The question is always the same: when a tool becomes central to how institutions see, connect, and act on information, do we still control the rails—or have we simply rented them?
None of this requires a national movement to begin. It starts with households forcing better questions into writing, councillors learning to argue in rail terms, regulators being pushed to raise the standard of justification, and journalists being handed records that make ‘routine modernization’ harder to hide behind. That is how the next generation of smart deployments becomes governable—before it becomes non‑optional.
What follows in the appendix is not a template exercise. It is the actual letter my household sent to FortisBC — the precise questions, written on the record, in formal writing, to a regulated public utility that told us a significant change to home infrastructure was “not optional.” It is reproduced here in full because the argument this essay has made is only useful if it produces something you can act on. FortisBC received it. No official reply came. The scheduled installation was quietly dropped — no acknowledgment, no concession, no explanation. That silence is itself data: a utility confident in its position does not go quiet when asked to put its answers in writing. This is not a victory. The architecture has not changed and the program continues for every other household on the same list. But the paper trail created enough friction that the system moved on rather than answer. That is the tactic functioning exactly as described in this section — and it is why the letter is here. The questions it asks are not unique to my situation. Every Canadian utility rolling out AMI infrastructure, every smart-city platform, every “data analytics” contract signed without public debate is subject to the same line of inquiry. Take what fits, replace the names, adapt to your regulator. That is how the conversation stops restarting from zero.
11. We Did Not Consent to This
This essay has spent ten sections mapping an architecture. Now it needs to say something simpler: we did not consent to this.
Not to the six-rail sensing architecture. Not to the fusion of our identity, payments, communications, and physical life into a single operational model. Not to a five-stage pipeline that processes that model into compliance decisions and delivers consequences back through the same rails we depend on for heat, water, money, and participation in civic life. We were not asked. No election was held on whether essential infrastructure should become programmable and remotely revocable. No public hearing addressed whether our homes should become continuous sensing inputs to a governance system we cannot see or audit. The architecture was assembled piece by piece — each component approved separately, each regulator seeing only its own piece, no single body ever required to look at the whole — and one day a letter arrived saying the next piece was “not optional.”
That is the mechanism. Not a decree. Not a law with a name. A slow, distributed, piece-by-piece construction that is complete before most people realize it was being built at all. And we did not consent to any of it.
We also refuse what it is building toward. We refuse infrastructure designed to make essential life conditionally revocable by whoever controls the pipeline when political conditions shift. We refuse the normalization of “not optional” as the default posture of essential infrastructure toward the people who — in a democracy, by consent — are supposed to own it. We refuse to permit the construction of a pipeline that makes political dissent computationally legible and consequence-bearing before it can organize. These are not abstract policy preferences. They are refusals. There is a difference.
Democratic self-governance is not the permanent water we swim in. It is not a philosophical tradition or a default condition of modernity. It is a hard-won, historically fragile achievement — the result of centuries of ordinary people fighting, at great cost, to stop being managed as livestock by whoever controls the current coercion apparatus. That project is not finished. It is not safe. And what is being built now — rail by rail, standards body by standards body, “not optional” letter by “not optional” letter — is the first apparatus in human history technically capable of closing that contest permanently. Not through soldiers or decrees. Through infrastructure that makes it structurally impossible to contest power using the same rails that power controls. That is tyranny’s actual mechanism, re-implemented without soldiers, without announcements, one regulatory approval at a time. This essay is the beginning of an argument about that. Not the whole argument. The beginning.
Saying what we refuse is not Luddism. It is the minimum requirement for navigating a moment when the incentive gradient of every actor in a distributed system points toward more sensing, more fusion, more inference, more actuation — and no single actor ever has to take responsibility for the aggregate. The architecture assembles itself, piece by piece, through individually defensible decisions, until the shape it has formed is visible only to those who were watching from the beginning. Naming the shape now — while the rails are still being laid, while the system still has to answer questions in writing, while the dependency is not yet complete — is the only intervention that has a chance of working.
As for my household: the letter made them back off. For now. FortisBC received the questions, gave no official reply, and quietly dropped the scheduled installation — no acknowledgment, no concession, no explanation. The architecture has not changed. The AMI program continues for every other household on the same list. And this may not be over. Utilities operating inside a province-wide rollout do not abandon a metering program because one household asked uncomfortable questions. They pause. They wait for attention to move elsewhere. They return with a revised schedule or a different framing. That is how these systems operate, and it would be dishonest to pretend otherwise. What the letter produced was a record, a moment of friction that cost the utility more than the installation was worth at that moment, and a demonstration that a well-formed paper trail can make a system move on rather than put its answers in writing. That is the most a single household can do. It is not enough on its own. It is where the work starts.
So we fight. Through every legal means available: regulatory challenges, FOI requests, privacy commissioner complaints, council motions, court challenges, legislative pressure. Through writing — essays like this one, in plain language, aimed at the information environment, because the architecture assembles itself quietly and the only thing that slows quiet assembly is people who can see it and name it before everyone else can. Through organizing — building the distributed resistance mesh described in this essay, piece by piece, so that the next household that gets a letter is not starting from zero. And where legal channels have themselves been captured — where the regulator is a rubber stamp, where the procurement decision bypasses Parliament, where the standards body has already been shaped by the vendors it is supposed to constrain — through civil disobedience. Calm, documented, principled refusal. On the record. In writing. Costing the system more than compliance would have.
The stakes of losing this are not like losing an election. If the AI governance race is lost — to corporations, to authoritarian state actors, to whoever integrates the full pipeline first — it is not lost in a way that produces another cycle, another government, another chance. Whoever closes the pipeline controls the infrastructure through which political contest itself operates: the payments rail, the communications rail, the identity rail, the sensing architecture. A completed pipeline doesn’t just win a political moment. It owns the conditions under which all future political moments occur — because the rails that would allow a future challenge to be mounted are the rails the winner controls. There is no next round if the rails that would allow a next round are held by the winner of this one. That has to be said plainly and acted on accordingly.
We are inside the acceleration now. Not approaching it — in it. The datacenters are being built. The 6G standards are being written. The contracts are being signed. The meters are being installed. Most people will understand what was assembled a few years too late, which is exactly why the people who can see it now carry an obligation proportional to what they can see. The window in which the rails can still be contested, the pipeline still interrupted, the architecture still made to answer questions in writing — that window is open now. It will not stay open indefinitely. Act like the window is what it is.
And the hope — not the comfortable kind, but the honest kind — is this: it is not over. The rails are not yet complete. The pipeline is not yet closed. Every household that pushes back, every journalist who names the architecture, every councillor who forces the question into a hearing, every essay that updates the information environment before the capture is finished — these are moves that are still available, today, because the system still has to answer questions in writing, still has to defend its decisions in public, still has to encounter people who know what they are looking at. We are still in the fight. And the fight is still winnable. That is not optimism. That is an accurate assessment of where we are. It demands we act like it.
There is a deeper layer beneath everything this essay has mapped, and it needs to be named plainly. The rails, the fusion point, the pipeline — all of it works on populations that are visible. Every mechanism in this essay depends on the people subject to it being legible: their routines read, their coordination anticipated, their capacity to organize interrupted before it can form. A population that cannot meet, speak, plan, and coordinate outside the system's view cannot resist anything the system decides to do. Without privacy, you cannot resist tyranny — and without privacy, you cannot have democratic self-government. Privacy is not a consumer preference, not a compliance category, not a luxury of stable times. It is the load-bearing condition of collective action itself: the invisible space where trust forms, where resistance coordinates, where the governed retain the capacity to govern themselves. The architecture this essay has mapped is the architecture that eliminates that space. That is what is actually being built — and that is why the fight for it is the fight underneath every other fight.
We will keep getting letters like this. About meters, thermostats, vehicles, buildings, and critical infrastructure upgrades — each framed as routine, each presented as inevitable, each moving another rail from optional to mandatory. The question is not whether the infrastructure will be built. The question is whether enough people name what it is, refuse what must be refused, and insist — calmly, persistently, and in writing — on governed infrastructure: systems whose sensing is bounded, whose actuation requires a human being who can be identified and overridden, whose data remains under democratic jurisdiction, and whose default posture includes a credible, protected right to say no. Not before it becomes smart. Before it becomes inescapable.
Appendix: The Letter We Sent FortisBC — And the Questions You Can Ask Too
What follows is the actual letter my household sent to FortisBC after we received notice that a wireless “advanced” gas meter at our home on Vancouver Island was “not optional.” Identifying details are redacted, but the structure and substance are intact. This is us doing the thing I argued for—not in theory, but in writing, on the record: taking the abstract idea of “programmable choke points” and turning it into precise, calm questions that any Canadian can put to their own utility, municipality, or regulator.
You are welcome to copy, adapt, and reuse this letter. Replace FortisBC and the BC Utilities Commission with the names of your local providers and oversight bodies, keep what fits your situation, and add whatever concerns matter most in your context. The point is not to shout at call‑centre workers. The point is to force the system to describe itself on the record—what it collects, what it can do, who else can touch it, and under what authority it claims to make that “not optional” for you.
[DATE]
FortisBC Energy Inc.
Attn: Meter Exchange / AMI Project
PO Box 48230 Bentall Centre
Vancouver, BC V7X 1N8
Re: Advanced Gas Meter Exchange at [SERVICE ADDRESS], Account [ACCOUNT NUMBER], Reference [REFERENCE NUMBER]
To whom it may concern,
I am writing in response to your recent letter regarding the exchange of the existing natural gas meter at my home at [SERVICE ADDRESS] for a wireless “advanced” meter as part of FortisBC’s Gas Advanced Metering Infrastructure (AMI) Project.
I acknowledge FortisBC’s responsibility to maintain safe and reliable service, and I understand that metering equipment may need to be updated over time to meet regulatory and technical standards. At the same time, the introduction of a continuously transmitting wireless meter that enables remote monitoring and remote shutoff raises significant questions about privacy, data governance, cross‑border exposure, and the conditions under which essential services can be interrupted.
Your letter indicates that the meter exchange “is not optional.” Before I can meaningfully accept that position, I require clear, written answers to the questions below. Until these questions are fully answered in writing, I do not consent to the replacement of the existing meter or to any work being scheduled at my property.
For clarity, I have grouped my questions under several headings.
Data collection and usage
1.1 Please specify exactly what data fields the advanced gas meter will collect (e.g., total consumption only, time‑stamped interval data, diagnostic codes, voltage/pressure data, event logs).
1.2 At what time interval will the meter record and/or transmit usage data (e.g., hourly, 15‑minute, other)?
1.3 For how long will FortisBC retain raw interval data associated with my account before it is aggregated, anonymized, or deleted?
1.4 Beyond billing and basic system operations, for what additional purposes does FortisBC currently use, or plan to use, advanced meter data (e.g., analytics, load profiling, rate design, third‑party programs)?
1.5 Will FortisBC commit in writing that advanced meter data will not be used to infer or profile household behaviour (e.g., occupancy patterns, appliance use, lifestyle characteristics) beyond what is strictly necessary for safe operation and billing?
Sharing with third parties and authorities
2.1 Please list all third‑party vendors and service providers (including meter manufacturers, network operators, subcontractors, and cloud and analytics providers) that will store, process, or have access to advanced meter data associated with my account.
2.2 For each such provider, please indicate in which country or countries the data will be stored and/or processed.
2.3 Where any provider is a U.S.‑based company or a Canadian subsidiary of a U.S.‑based company, please explain how FortisBC has assessed and mitigated the risk that customer data may be accessed under U.S. law (including the CLOUD Act), even if stored in Canada.
2.4 Under what conditions, if any, will FortisBC disclose advanced meter data to law‑enforcement, regulatory, intelligence, or other government authorities? Please specify the legal thresholds (e.g., court order, warrant, statutory authority, voluntary disclosure in emergencies).
2.5 Will FortisBC commit that detailed interval data will not be shared with any non‑utility third party (including marketers, insurers, or other commercial partners) without explicit, informed, opt‑in consent from the customer?
Remote disconnection and control
3.1 Please describe, in detail, the technical capabilities for remote disconnection and reconnection associated with the advanced gas meter:
Who (by role) within FortisBC can initiate a remote disconnection?
What checks and approvals are required before a remote disconnection can occur?
What technical safeguards exist to prevent erroneous or unauthorized disconnections?
3.2 Under what circumstances may FortisBC remotely disconnect gas service using the advanced meter (e.g., non‑payment, safety issues, emergencies, regulatory orders), and whether any automated triggers exist that could initiate a disconnection without direct human authorization? Please specify the policies, tariffs, or BCUC orders that govern each use case.
3.3 Does FortisBC have any current or planned programs that would allow remote adjustment or throttling of gas usage (for example, demand‑response programs or emergency load‑shedding)? If so, please provide details and indicate whether participation is strictly opt‑in.
3.4 What notification and appeal mechanisms are in place for customers who are remotely disconnected in error or dispute the basis for a remote disconnection?
Legal authority and regulatory oversight
4.1 Please provide references (order numbers and dates) for the BC Utilities Commission (BCUC) approvals that authorize the AMI Project and the deployment of advanced gas meters.
4.2 On what specific legal or regulatory basis does FortisBC assert that the meter exchange “is not optional” for existing customers (i.e., which sections of the Gas Tariff, BCUC orders, or other instruments)?
4.3 Has FortisBC conducted a Privacy Impact Assessment (PIA) or similar analysis for the AMI Project? If so, please provide a copy or a public summary. If not, please explain why not.
4.4 Has FortisBC consulted with, or received guidance from, the Office of the Information and Privacy Commissioner for British Columbia regarding advanced meter data collection, retention, and sharing? If so, please summarize the Commissioner’s conclusions.
Options, accommodations, and customer choice
5.1 Does FortisBC offer any form of “radio‑off,” reduced‑functionality, or non‑communicating meter option for gas customers who have privacy, health, or security concerns about wireless communication?
5.2 If so, what additional fees, if any, are associated with such an option, and how are those fees justified?
5.3 If no such option is currently available, please explain why FortisBC considers it necessary that all gas customers participate in the fully communicating AMI system as a condition of service.
5.4 In the event that FortisBC cannot provide an option that meets my privacy and security expectations, what recourse do I have to challenge the mandatory nature of the meter exchange through FortisBC, the BCUC, or other bodies?
I am asking these questions in good faith and with a desire to maintain a cooperative relationship with FortisBC. However, as a customer whose basic household safety and privacy are directly affected by this project, I need clear, documented assurances about how the new system operates and what risks it creates.
Please treat this letter as a formal request for information under your obligations as a regulated public utility and under applicable privacy legislation. I would appreciate a detailed written response within 30 days of receipt. Until such a response is provided and my concerns are addressed, I respectfully request that FortisBC refrain from scheduling or attempting to complete the meter exchange at [SERVICE ADDRESS].
Thank you for your attention to this matter.
Sincerely,
[FULL LEGAL NAME]
[MAILING ADDRESS]
[PHONE NUMBER]
[EMAIL ADDRESS]















