A 50-year-old grandmother spent 108 days in jail because a facial recognition match put her at a crime scene 1,200 miles from where she actually was.
The system wasn't broken. It did exactly what it was built to do — return the best match for a face. The failure was treating that match score as evidence instead of a lead that still needs checking.
That's the pattern in nearly every facial recognition failure we audit. The algorithm is rarely the problem. The procurement, the data, and the missing governance are.
Here's the math most enterprises never run. A store with 8,000 daily visitors and a 200-person watchlist screens 97.5% of faces against people who aren't enrolled. The system is tuned for closed-set matching — is this person in the database? — but deployed for open-set screening, where the crowd dwarfs the list. Even a 0.1% false-positive rate means 8 wrong alerts per store per day. Across 500 locations: 4,000 false accusations a day.
Those errors don't fall evenly. NIST's own benchmarks show within-group false-positive rates varying by up to 7,203x across demographics. When Rite Aid deployed facial recognition, the FTC found its stores in plurality-Black and Asian communities generated far more false alerts — and handed down a five-year ban plus deletion of every model trained on that data.
If you run facial recognition in retail or finance: who on your team can actually read a NIST FRVT report and tell you your real exposure?
#AIGovernance #BiometricCompliance
Published on Facebook · June 18, 2026
On social media
See this post on its original platform
In our archive