
- Angela Lipps spent 108 days in jail. She was 1,200 miles from the crime. A facial recognition match put her there — and nobody checked whether that number was reliable before treating it as evidence. 🧵
- The Fargo police chief apologized March 27, 2026. Charges were dismissed Christmas Eve 2025. This is what happens when a match score is treated as proof: the system produced a number, and no step in the workflow asked whether it was trustworthy.
- The failures are almost never bad algorithms. Top NIST FRVT systems hit 99%+ accuracy on a 12M-image gallery. The failures are bad procurement, contaminated enrollment data, and reviewers trained to trust the score — the math the enterprise never ran.
- The math: a store with 8,000 daily visitors and a 200-person watchlist runs 97.5% of scans against people who aren't enrolled. Closed-set algorithms pick a "best match" for every face. At a 0.1% false positive rate, that's 8 wrong alerts per store, per day.
- Across 500 locations: 4,000 false alerts a day. They don't fall evenly. NIST FRVT testing shows false positive rates varying by up to 7,203x across demographic groups. The errors concentrate on the people least able to absorb them.
- The FTC found Rite Aid's stores in plurality-Black and Asian neighborhoods threw more false alerts than stores in plurality-White ones. The penalty: a 5-year ban AND deletion of every model trained on that data. That's model disgorgement.
- Disgorgement is the part procurement misses. You don't just stop — you destroy the algorithms built on improperly collected data. Years of investment, gone. Experts expect the FTC to reach for it far more often.
- The bill keeps climbing: $136.6M in BIPA settlements in 2025 alone. A $1.375B Texas CUBI settlement with Google. EU AI Act penalties up to 35M euros or 7% of global turnover. Vendors disclaim accuracy — you inherit the liability.
- The audit almost nobody runs: read NIST FRVT data for YOUR vendor and demographics. Prune the enrollment DB driving false positives. Demand calibrated confidence bounds — vendors ship raw match scores with no error bars, which is how a number becomes "evidence."
- If you run facial recognition in retail or KYC: do you actually know your vendor's false positive rate on the demographics walking through your doors — or just the headline 99% accuracy? #BiometricCompliance
- We built an independent biometric compliance audit for exactly this gap — FRVT interpretation, enrollment hygiene, multi-jurisdiction mapping, HITL validation: https://veriprajna.com/solutions/biometric-facial-recognition-compliance