
A 50-year-old grandmother spent 108 days in jail over a facial recognition match. She was 1,200 miles from the crime.
The Angela Lipps case (Fargo, charges dismissed Christmas Eve 2025) isn't a story about a bad algorithm. The top NIST FRVT systems hit 99%+ accuracy. The failure is a math problem most enterprises never run before going live.
Here's the math. A store with 8,000 daily visitors and a 200-person watchlist means 97.5% of every scan is against someone who isn't enrolled. That's open-set screening. But most commercial systems are tuned for closed-set matching — "is this the phone's owner?" — not "is this stranger one of 200 faces?" Even a 0.1% false positive rate then throws roughly 8 wrong alerts per store per day. Across 500 locations, 4,000 false flags daily.
And those flags aren't random. NIST FRVT demographic testing shows within-group false positive rates varying by up to 7,203x — and the FTC found Rite Aid's stores in plurality-Black and Asian neighborhoods generated far more false alerts than others. A match score with no calibrated confidence bound is not evidence. It only looks like one.
This is why BIPA settlements hit $136.6M in 2025 and the FTC now orders model disgorgement: deleting not just the data, but every algorithm trained on it.
If you've deployed facial recognition, or you're evaluating vendors, "how accurate is it?" was never the real question. Accurate for whom, in which deployment, on whose enrollment database?
Save this before your next vendor review — and send it to whoever signed off on the last one. Which question does your current FR contract actually answer: accuracy, or accuracy for whom?
#BiometricCompliance #FacialRecognition #AIGovernance #BIPA #RetailLossPrevention