That is the opposite of reassuring, because here are the stats for those processes as a whole (just ‘requests for user information’, not broken down by data type or Google product). Currently at 84% accepance rate i.e. the ‘process’ is a formality lol: https://transparencyreport.google.com/user-data/overview?hl=...
This is not some newfangled shiny thing. If you hold records that are important to a court case you can be forced to give them up by court order. This is true regardless of who "you" happens to be. If police "have access" to a Waymo, it's only because they also "have access" to your phone, your medical records, your car rental history, etc., etc.
The linguistic ambiguity is always where the creepy extrajudicial shit seeps in.
See also: ‘We do not provide any government agency with direct access to our servers’ RE: Snowden/PRISM
Because they also comply with warrants and court orders, and it's easier to say "valid legal request" than that. Probably the vast majority of data requests are subpoenas.
I suppose that a FISA court could try to get footage from Waymo, but it would be difficult to do so because FISA requires a reasonable suspicion that the target is outside the United States. The (terrible) decision to allow dragnet surveillance with PRISM was allowed because the government claimed that it would be targeted mostly at people outside the borders of the US.
Needless to say, data from a Waymo operating entirely inside the United States is not covered by this. Secret courts are a bad idea in general IMO, but according to the rules this should not be allowed.
That process is fine, the best we have.
The problem is having roving surveillance vehicles driving around everywhere. I see a couple of them every day on my walk in a mostly residential area.
The addition of facial recognition is trivial if not already implemented. Can be done after the fact. The tradeoff is catching an occasional criminal while enabling all sorts of abuse from the powers that be.