Facial recognition
Facial recognition does not identify anyone. It returns candidates, ranked by similarity, out of whatever database it was pointed at. What that database holds, and what an officer is permitted to do with a candidate, are the decisions that matter.
Updated
In one sentence
Software that measures a face in an image and searches for a match in a database of known faces. It can be run on live camera feeds or on recorded footage after the fact.
Matching one face, and searching for a face
There are two different jobs here and they are constantly confused.
The first is verification. The system compares one face against one claimed identity, which is what happens when a phone unlocks or a passport gate opens. The person is cooperating, the lighting is controlled, and the comparison is one to one.
The second is identification. The system takes one face and searches a database for whoever it resembles, returning a ranked list of candidates. Police use is almost always this second job, and it is much harder. Every additional face in the database is another chance to produce a convincing wrong answer, so error grows with the size of the collection being searched.
Accuracy figures quoted in public are often drawn from the first job and applied to the second.
The gallery is the policy question
The algorithm gets the attention. What decides whether a system is unremarkable or alarming is the database it searches, which is a choice somebody made rather than a property of the software.
A search against a repository of booking photographs is one thing. A search against a state driver-licence file sweeps in people who have never been arrested. A search against images scraped from the open internet sweeps in everyone who has ever been photographed at a party. The same software, pointed at three different galleries, produces three systems that raise very different questions.
When you read a local record about facial recognition, the question to ask is which database the system searches, not which vendor supplied it.
A match is a lead, not an identification
Law enforcement’s own guidance is clear that a candidate returned by the software is an investigative lead and needs independent corroboration before anyone is arrested. Departments generally say this in their policies too.
Robert Williams was arrested outside his home in Detroit in January 2020 after a false match, and held for about thirty hours. His lawyers describe it as the first publicly reported case of its kind. When the city settled in 2024 it agreed, among other things, that it would not arrest people on the basis of a face recognition result alone, or on a photo lineup assembled from one.
That rule already existed as guidance before the arrest. The settlement is what made it binding for one department. The safeguard everyone cites is a practice rather than a property of the technology, and practices are followed unevenly.
Live, and after the fact
Most police use is retrospective. An investigator has an image from a camera and wants a name.
Live matching, where a camera feed is compared continuously against a watchlist, is a different capability with different consequences, because it operates on everyone who walks past rather than on one image from one incident. Most laws written about facial recognition address the live case. Most actual use is the retrospective one.
How to recognise it
You cannot. Facial recognition is software running behind cameras that look like every other camera, and a system can be added to footage that was collected for some other purpose years earlier.
That is why the record is the only route. The tell is in procurement rather than hardware: a line item in a budget, a contract with an analytics tier, a policy posted on a department website, or a board agenda item. Those documents are what this site collects.
Why agencies say they need it
-
Agency statement
Law enforcement's own sector guidance describes the technology as a way to generate investigative leads from images an agency already holds, by having trained investigators search a surveillance image against an authorised repository of booking photographs. The same guidance frames the result as a lead rather than an identification. [2]
What the concerns are
-
Accuracy is not one number, and the differences fall unevenly
The reference study is the National Institute of Standards and Technology's 2019 evaluation of demographic effects, which ran 18.27 million images of 8.49 million people through 189 algorithms. It found that false positives, where the system wrongly matches two different people, varied across groups defined by sex, age and race far more than false negatives did, that this happened even with high-quality photographs, and that the size of the difference depended heavily on which algorithm was used. [1]
-
People have been arrested on the strength of a match
Detroit police arrested Robert Williams outside his home in January 2020 after a false face recognition match, in what his lawyers describe as the first publicly reported wrongful arrest of its kind. He was held for about thirty hours. The city settled in June 2024, paying $300,000 and agreeing to policy limits on how the technology may be used. [3] [8]
-
The rule that a match is only a lead is not self-enforcing
Sector guidance already described the output as a lead requiring corroboration before the Detroit arrest happened. The settlement had to impose it as binding policy anyway, barring arrests based solely on a face recognition result or on a photo lineup drawn from one, and requiring a review of cases from 2017 to 2023 in which the technology had been used. [3] [8]
-
The best-known biometric privacy law does not apply to police
Illinois's Biometric Information Privacy Act is the statute most often cited in this area. It requires notice and written consent before biometric identifiers are collected and lets people sue over violations, but it regulates private entities and expressly excludes state and local government agencies and the courts. It does not bind a police department. [7]
-
Schools are a different situation, and at least one state has said so
Students are minors, attendance is compulsory and consent is not meaningful. In September 2023 New York's Education Department prohibited schools in the state from buying or using facial recognition, following a state report that found little evidence it prevents violent incidents and concluded the risks may outweigh the benefits. Other biometric technologies remain permitted there under conditions. [4]
What the law requires
| State | Law | What it requires |
|---|---|---|
| California | AB 1215 (2019), expired | Prohibited agencies from applying facial recognition and other biometric surveillance to officer-worn camera footage. It never covered other cameras. The prohibition expired on 1 January 2023, and SB 1038, which would have made it permanent, did not become law. [5] [6] |
| Illinois | Biometric Information Privacy Act (740 ILCS 14) | Requires notice and written consent before a private entity collects biometric identifiers, and gives people a private right of action. State and local government agencies and the courts are excluded, so it does not govern police use. [7] |
| New York | Education Department determination (2023) | Schools in New York State may not purchase or use facial recognition technology. Other biometric identifying technology may be used at local discretion, subject to consideration of privacy, civil rights, effectiveness and parental input. [4] |
Only the states we have researched appear here. A state's absence from this table means we have not checked it yet, not that it has no law.
Where we have found it
4 counties documented so far. Each new county is added here as its research publishes.
- Butte County, CA 2 systems
- Approved Facial recognition [Butte County Sheriff]
- Approved Campus cameras with facial recognition [Chico Unified]
- Placer County, CA 1 system
- Approved Facial recognition [Roseville Police]
- Tuolumne County, CA 1 system
- Reported Facial recognition cameras [Sonora Union High School District]
- Washington County, OR 1 system
- Retired Facial recognition [Washington Co. Sheriff (OR)]
This list covers the counties we have researched, which is not the same as everywhere this technology operates. Counties we have not published say nothing either way.
Questions
- Does my police department use facial recognition?
- There is no way to tell by looking, because facial recognition is software running behind cameras that look like any others. The record is the only route: the agency's policy, its contracts, and a public records request. Where we have researched a county, what we found is on this page. [2]
- Is facial recognition accurate?
- It depends on the task, the image and the algorithm. Matching one face against one claimed identity is easier than searching one face against a database of millions, where errors accumulate with the size of the database. Testing 189 algorithms in 2019, the National Institute of Standards and Technology found that false positive rates differed across demographic groups far more than false negative rates, that this held even for high-quality photographs, and that the scale of the difference varied greatly between algorithms. [1]
- Has anyone been wrongfully arrested because of facial recognition?
- Yes. Detroit police arrested Robert Williams in January 2020 on the basis of a false match and held him for about thirty hours. The city settled his lawsuit in June 2024 for $300,000 and agreed to restrict how the technology is used. Other cases have been reported; each should be checked against its own court record. [3] [8]
- Is facial recognition banned in California?
- No. California prohibited biometric surveillance on officer-worn camera footage from 2020, a restriction that covered only those cameras and expired on 1 January 2023. A bill to make it permanent did not pass. There is no general state prohibition on police use in force. [5] [6]
- Can my child's school use facial recognition?
- It depends on the state. New York prohibited it in schools in 2023 after a state review found little evidence it prevents violent incidents. We could not find an equivalent California rule for schools. [4]
What you can do
Civic action
Purchases and policies for this technology are decided at public meetings any resident can attend and speak at. Start with your county's record.
Go to the Butte County hub →Personal protection
Practical steps to shrink your personal data trail. Our guides publish at launch; until then, EFF's Surveillance Self-Defense is the best starting point.
Surveillance Self-Defense ↗Sources
- 1.
- 2. IJIS Institute and International Association of Chiefs of Police, "Law Enforcement Facial Recognition Use Case Catalog" · Primary document · · accessed · archived copy
- 3. American Civil Liberties Union, Williams v. City of Detroit case page · News · accessed · archived copy
- 4.
- 5. California AB 1215 (2019), Body Camera Accountability Act · Law · · accessed · archived copy
- 6.
- 7. Illinois Biometric Information Privacy Act, 740 ILCS 14 · Law · accessed · archived copy
- 8.