Facial recognition and law enforcement examines the deployment, capabilities, accuracy, and governance of facial recognition technology (FRT) within American policing — a technology that has become one of the most consequential and contested applications of artificial intelligence in the criminal justice system. Within Cyber Criminology, facial recognition occupies a distinctive position as a technology that promises significant investigative utility — enabling the identification of suspects from surveillance footage, the location of missing persons, and the verification of identities at scale — while simultaneously threatening civil liberties through mass surveillance capability, exhibiting documented racial and gender accuracy disparities, and operating within a governance framework that critics characterize as grossly inadequate to the technology’s power and risks. The National Institute of Standards and Technology’s Face Recognition Vendor Test (Grother, Ngan, & Hanaoka, 2019) and investigative reporting by the Georgetown Law Center on Privacy and Technology (Garvie, Bedoya, & Frankle, 2016) have established the empirical foundation for both the technology’s capability and its limitations. This article examines how facial recognition is used in law enforcement, its accuracy and equity profile, the legal and constitutional framework governing its deployment, the legislative responses it has generated, and the policy debates about its future within Criminology and criminal justice.
Introduction
Facial recognition technology uses machine learning algorithms to analyze the geometric features of human faces — the distance between eyes, the shape of the jawline, the contour of cheekbones — and compare them against databases of known faces to generate identification matches or verify claimed identities. The technology has improved dramatically over the past decade, driven by advances in deep learning and convolutional neural networks that have reduced error rates by orders of magnitude compared to earlier algorithmic approaches (Phillips, Yates, Hu, Hahn, Noyes, Jackson, Cavazos, Jeckeln, Rber, & O’Toole, 2018). Modern facial recognition systems can process images in milliseconds, operate on low-quality surveillance footage, and search databases containing hundreds of millions of photographs — capabilities that would have been science fiction a generation ago.
The deployment of FRT in American law enforcement has expanded rapidly and with minimal public deliberation. A 2016 Georgetown Law study found that approximately half of all American adults were enrolled in at least one law enforcement facial recognition database through driver’s license photos, mug shots, or passport photographs, and that at least one in four law enforcement agencies had access to facial recognition capabilities (Garvie et al., 2016). The GAO (2021) documented that twenty federal agencies reported using FRT between April 2018 and March 2020, with the FBI, Customs and Border Protection (CBP), and the Drug Enforcement Administration among the most active users. This expansion occurred largely without the legislative authorization, public notice, or impact assessment that the technology’s civil liberties implications would seem to demand — a governance failure that has prompted legislative action at multiple levels of government.
Technology and Capabilities
How Facial Recognition Works
Contemporary facial recognition systems operate through a pipeline of detection, alignment, feature extraction, and matching. Detection identifies the presence and location of faces within an image or video frame. Alignment normalizes the detected face for pose, illumination, and scale, compensating for the variation in angle, lighting, and distance that characterize real-world surveillance imagery. Feature extraction converts the aligned face into a mathematical representation — a “faceprint” or embedding — that captures the geometric and textural characteristics distinguishing one face from another. Matching compares the extracted faceprint against a database of known faceprints to identify the closest match or matches, generating a similarity score and a ranked list of candidate identities (Jain, Ross, & Prabhakar, 2004).
The accuracy of modern facial recognition systems varies significantly depending on the quality of the input image, the size of the comparison database, the demographic composition of both the probe and gallery images, and the specific algorithm employed. Under controlled conditions — frontal photographs with consistent lighting — the best-performing algorithms achieve accuracy rates exceeding 99 percent on benchmark datasets (Grother et al., 2019). Under the degraded conditions typical of real-world surveillance — angled faces, partial occlusion, variable lighting, low resolution, motion blur — accuracy declines substantially, and the rate of false positive matches increases. The gap between laboratory accuracy and operational accuracy is significant and frequently underappreciated by law enforcement users who may place excessive confidence in match results generated from suboptimal imagery.
The databases against which law enforcement facial recognition searches are conducted vary in composition and governance. The FBI’s Next Generation Identification (NGI) system contains over 640 million photographs including mug shots, visa application photos, and driver’s license photos from cooperating states. State and local databases typically contain mug shot photographs and may include driver’s license photos depending on state law and policy. Clearview AI, a private company, has assembled a database of over 30 billion facial images scraped from publicly accessible websites including social media platforms — a database that Clearview markets to law enforcement agencies despite legal challenges and platform terms-of-service violations (Hill, 2020; Mac, Haskins, & McDonald, 2021).
Operational Use Cases
Law enforcement deploys facial recognition across multiple operational contexts with varying levels of investigative urgency, civil liberties sensitivity, and governance oversight. Retrospective identification — comparing an image of an unknown suspect against a facial recognition database to generate investigative leads — represents the most common and least controversial use case. An investigating officer submits a photograph extracted from surveillance footage, and the facial recognition system returns a ranked list of potential matches that the officer uses as a starting point for further investigation — confirming or disconfirming the match through additional evidence rather than treating the algorithmic output as conclusive identification.
Real-time surveillance — the continuous scanning of live camera feeds against databases of wanted persons or persons of interest — represents the most invasive and controversial use case. Real-time FRT creates the capability for mass identification in public spaces: every person passing through a surveillance zone can have their face captured, analyzed, and compared against a watchlist without their knowledge or consent. While real-time surveillance has been deployed in limited contexts in the United States — airports, border crossings, high-security events — its expansion to general-purpose public surveillance has been resisted through legislative action and institutional policy in multiple jurisdictions (Selinger & Hartzog, 2019).
Identity verification — confirming that an individual is who they claim to be rather than identifying an unknown individual — represents a lower-risk application that is widely deployed in airport security (CBP’s Traveler Verification Service), mobile device authentication, and access control systems. The one-to-one comparison involved in verification is technically simpler and more accurate than the one-to-many comparison involved in identification, and the privacy implications are less severe because the comparison is conducted against a single enrolled image rather than an entire database (Jain et al., 2004).
Accuracy and Demographic Disparities
The NIST Findings
The most authoritative assessment of facial recognition accuracy across demographic groups is the NIST Face Recognition Vendor Test, which has evaluated commercial and academic facial recognition algorithms against standardized image datasets since 2006. The 2019 FRVT report on demographic effects (Grother et al., 2019) — evaluating 189 algorithms from 99 developers — produced findings that have become foundational to the policy debate. The study found that the majority of algorithms exhibited elevated false positive rates for African American and Asian faces relative to Caucasian faces, with disparities ranging from a factor of 10 to a factor of 100 depending on the algorithm. False positive disparities were particularly pronounced for African American women, who exhibited the highest error rates across demographic intersections. False negative rates (failure to identify a face that is in the database) showed smaller but still significant demographic variation.
The magnitude of these disparities varies substantially across algorithms and developers. Some algorithms — particularly those developed by companies with diverse training data and specific attention to demographic performance — exhibited minimal disparities, while others showed dramatic differences. The finding that demographic performance disparities are not inherent to the technology but vary by implementation suggested that the disparities are addressable through improved training data and algorithmic design, while also establishing that many currently deployed systems exhibit accuracy gaps that create disproportionate risks for specific populations (Raji & Buolamwini, 2019).
Buolamwini and Gebru’s (2018) Gender Shades study, which preceded and helped motivate the NIST evaluation, documented that commercial gender classification systems from Microsoft, IBM, and Face++ exhibited error rates of up to 34.7 percent for darker-skinned women compared to 0.8 percent for lighter-skinned men. The study’s findings, and the subsequent improvement in system performance following public attention, demonstrated both the severity of the disparity problem and the capacity of the industry to address it when held accountable — a dynamic that supports the case for mandatory accuracy standards and auditing requirements as governance mechanisms.
Wrongful Arrest Cases
The real-world consequences of facial recognition accuracy disparities have been illustrated by documented cases of wrongful arrest resulting from FRT misidentification. Robert Williams was arrested by Detroit police in January 2020 after a facial recognition match between a surveillance camera image from a shoplifting incident and his driver’s license photograph; the match was incorrect, and Williams was detained for thirty hours before being released (Hill, 2020). Michael Oliver and Nijeer Parks experienced similar wrongful arrests based on FRT misidentification in separate incidents, each resulting in detention, criminal charges, and the financial and emotional costs of defending against erroneous prosecution.
These cases share several characteristics that illuminate the operational risks of facial recognition deployment. In each case, the facial recognition match was treated as significantly more probative than department policy prescribed — investigators used the algorithmic output as a basis for arrest rather than as a starting point for additional investigation. In each case, the defendant was Black, consistent with the demographic accuracy disparities documented by NIST and Buolamwini. And in each case, the lack of transparency about the role of facial recognition in the investigation initially concealed the technology’s involvement from defense attorneys and the court, raising due process concerns about the disclosure of investigative methods that affect defendants’ ability to challenge the evidence against them (Garvie, 2019).
Legal and Constitutional Framework
Constitutional Analysis
The constitutional analysis of facial recognition implicates both the Fourth Amendment (protection against unreasonable searches) and the First Amendment (protection of anonymous association and expression). Fourth Amendment analysis depends on whether facial recognition surveillance constitutes a “search” under the Katz reasonable expectation of privacy framework and its post-Carpenter evolution. The traditional view — that individuals have no reasonable expectation of privacy in their physical appearance when visible in public — would exclude most facial recognition applications from Fourth Amendment protection. However, the Carpenter Court’s recognition that technologies enabling pervasive, automated tracking of individuals create privacy interests that momentary observation does not suggests that systematic facial recognition surveillance may cross the Fourth Amendment threshold (Gray & Citron, 2013).
First Amendment concerns focus on the chilling effect that facial recognition surveillance may have on constitutionally protected activity. The knowledge or suspicion that one’s face is being scanned and identified at a protest, religious gathering, or political meeting may deter participation in activities that the First Amendment protects. The ACLU and other civil liberties organizations have argued that facial recognition surveillance in public spaces is inherently incompatible with anonymous assembly and expression, regardless of how the collected data is used, because the surveillance infrastructure itself creates a chilling effect that constrains the exercise of constitutional rights (Stanley, 2019).
The Fourteenth Amendment’s Equal Protection Clause provides an additional constitutional basis for challenging facial recognition deployment that produces racially disparate outcomes. However, equal protection claims face the Washington v. Davis (1976) requirement of proving discriminatory intent rather than merely demonstrating discriminatory impact — a standard that is difficult to satisfy when the alleged discrimination results from algorithmic processing of neutral inputs rather than deliberate targeting. The disparate impact framework available under some civil rights statutes (Title VI of the Civil Rights Act, applied to recipients of federal financial assistance) may provide an alternative legal theory for challenging racially disparate FRT deployment, though this theory has not been tested in litigation to date.
Legislative Responses
Legislative responses to facial recognition have occurred primarily at the municipal and state level, producing a patchwork of regulations that vary widely in scope and stringency. Municipal bans on government use of facial recognition have been enacted in San Francisco (2019), Boston (2020), Portland, Oregon (2020, covering both government and private use in public accommodations), and several other cities. These bans reflect a legislative judgment that the technology’s risks — particularly its accuracy disparities and mass surveillance potential — outweigh its investigative benefits under current conditions.
State-level legislation has taken multiple approaches. Illinois’s Biometric Information Privacy Act (BIPA), enacted in 2008 before the current wave of facial recognition deployment, requires informed consent before the collection of biometric identifiers and has been the basis for significant litigation against both private companies and law enforcement agencies. Washington state’s biometric privacy statute includes a law enforcement carve-out that permits FRT use in certain circumstances. Virginia enacted legislation requiring legislative approval before state and local agencies deploy facial recognition, establishing a democratic authorization requirement that most other states do not impose (Selinger & Hartzog, 2019).
Federal legislation specifically addressing facial recognition has been proposed but not enacted. The Facial Recognition and Biometric Technology Moratorium Act, introduced in multiple Congressional sessions, would impose a federal moratorium on the use of facial recognition by federal agencies and condition federal funding to state and local agencies on their adoption of similar moratoriums. The Facial Recognition Technology Warrant Act would require federal agencies to obtain court orders before using FRT for ongoing surveillance. Neither proposal has advanced to enactment, leaving the federal governance of facial recognition to agency-level policies that vary in specificity and enforcement across the federal government.
Policy Debates and Future Directions
Reform Versus Prohibition
The central policy debate over facial recognition in law enforcement divides those who advocate for regulated use — permitting FRT under conditions of accuracy standards, auditing, transparency, and use restrictions — from those who advocate for prohibition, arguing that the technology’s inherent risks are too severe to be adequately mitigated through regulation. The reform position, articulated by organizations including the Brookings Institution and some law enforcement professional associations, argues that FRT provides genuine investigative value for solving serious crimes and locating missing persons, and that accuracy improvements, demographic performance standards, and use-case restrictions can address the technology’s equity and privacy concerns without forgoing its benefits (Castro & McLaughlin, 2019).
The prohibition position, advocated by the ACLU, the Electronic Frontier Foundation, and numerous academic scholars, argues that facial recognition in law enforcement is fundamentally incompatible with civil liberties and racial equity. The argument rests on several premises: that the technology’s mass surveillance capability is inherently threatening to democratic freedom regardless of how it is regulated; that accuracy disparities cannot be fully eliminated for all demographic groups under all operational conditions; that regulation assumes a level of institutional compliance and oversight capacity that the history of law enforcement surveillance does not support; and that the technology creates an infrastructure of control whose existence poses risks that transcend any specific use case (Stark, 2019; Browne, 2015). The prohibition position reflects a precautionary principle — the judgment that the potential for irreversible harm warrants restraint even if the probability of that harm is uncertain.
Accuracy Standards and Governance Frameworks
If facial recognition use by law enforcement continues — as it almost certainly will in some form, given the technology’s investigative utility and the limited geographic scope of existing bans — the development of governance frameworks becomes critical. The elements of effective governance include mandatory accuracy standards (minimum thresholds for demographic performance that algorithms must meet before deployment), use-case restrictions (prohibiting real-time surveillance while permitting retrospective identification under defined conditions), transparency requirements (disclosure of FRT use in investigations and prosecutions), human review mandates (requiring trained human confirmation of matches before investigative action), and auditing protocols (regular independent assessment of accuracy, equity, and policy compliance).
The NIST FRVT provides a technical foundation for accuracy standards, but translating laboratory test results into operational standards requires attention to the gap between controlled testing conditions and real-world deployment environments. An algorithm that achieves acceptable demographic equity on standardized test images may exhibit larger disparities when applied to the degraded imagery typical of surveillance cameras. Governance frameworks must account for this operational reality by requiring testing under realistic conditions and establishing accuracy floors that apply to operational rather than laboratory performance (Raji, Gebru, Mitchell, Buolamwini, Lee, & Denton, 2020).
The development of facial recognition governance also requires engagement with the communities most affected by the technology’s deployment and its errors — predominantly communities of color, which bear the disproportionate risk of misidentification and which have historically been subject to over-surveillance by law enforcement. Meaningful community engagement in governance decisions about facial recognition deployment, use restrictions, and accountability mechanisms represents a democratic imperative that the technology’s rapid expansion has largely bypassed.
Conclusion
Facial recognition and law enforcement exist in a state of tension between the technology’s genuine investigative utility and its significant risks to civil liberties, racial equity, and democratic governance. The documented accuracy disparities across demographic groups — with Black individuals, women, and particularly Black women facing substantially elevated misidentification risks — create conditions under which FRT deployment produces discriminatory outcomes that are inconsistent with the constitutional commitment to equal protection. The legislative landscape reflects this tension: municipal bans, state-level regulations, and proposed federal legislation represent diverse institutional judgments about how to balance investigative value against civil liberties risk.
The resolution of the facial recognition debate will depend on the interplay between technical improvement (reducing accuracy disparities to acceptable levels), governance development (establishing standards, transparency, and accountability mechanisms), and political judgment (determining what level of surveillance capability is consistent with democratic values). The technology will continue to improve, the governance frameworks will continue to develop, and the debate will continue to evolve — but the fundamental question of whether mass biometric identification in public spaces is compatible with a free society will remain at the center of one of the most consequential policy discussions at the intersection of technology and criminal justice.
References
- Browne, S. (2015). Dark matters: On the surveillance of blackness. Duke University Press.
- Buolamwini, J., & Gebru, T. (2018). Gender shades: Intersectional accuracy disparities in commercial gender classification. Proceedings of Machine Learning Research, 81, 77–91.
- Castro, D., & McLaughlin, M. (2019). A policymaker’s guide to facial recognition. Information Technology and Innovation Foundation.
- Garvie, C. (2019). Garbage in, garbage out: Face recognition on flawed data. Georgetown Law Center on Privacy and Technology.
- Garvie, C., Bedoya, A. M., & Frankle, J. (2016). The perpetual line-up: Unregulated police face recognition in America. Georgetown Law Center on Privacy and Technology. https://www.perpetuallineup.org/
- Gray, D., & Citron, D. K. (2013). The right to quantitative privacy. Minnesota Law Review, 98(1), 62–144.
- Grother, P., Ngan, M., & Hanaoka, K. (2019). Face Recognition Vendor Test (FRVT) Part 3: Demographic effects. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8280
- Hill, K. (2020, January 18). The secretive company that might end privacy as we know it. New York Times. https://www.nytimes.com/2020/01/18/technology/clearview-privacy-facial-recognition.html
- Hill, K. (2020, June 24). Wrongfully accused by an algorithm. New York Times.
- Jain, A. K., Ross, A., & Prabhakar, S. (2004). An introduction to biometric recognition. IEEE Transactions on Circuits and Systems for Video Technology, 14(1), 4–20. https://doi.org/10.1109/TCSVT.2003.818349
- Mac, R., Haskins, C., & McDonald, L. (2021). Clearview AI has new tools to identify you in photos. BuzzFeed News.
- National Institute of Standards and Technology. (2022). Face Recognition Vendor Test ongoing. https://pages.nist.gov/frvt/html/frvt11.html
- Phillips, P. J., Yates, A. N., Hu, Y., Hahn, C. A., Noyes, E., Jackson, K., Cavazos, J. G., Jeckeln, G., Rber, R., & O’Toole, A. J. (2018). Face recognition accuracy of forensic examiners, superrecognizers, and face recognition algorithms. Proceedings of the National Academy of Sciences, 115(24), 6171–6176. https://doi.org/10.1073/pnas.1721355115
- Raji, I. D., & Buolamwini, J. (2019). Actionable auditing: Investigating the impact of publicly naming biased performance results of commercial AI systems. Proceedings of the 2019 AAAI/ACM Conference on AI, Ethics, and Society (pp. 429–435). https://doi.org/10.1145/3306618.3314244
- Raji, I. D., Gebru, T., Mitchell, M., Buolamwini, J., Lee, J., & Denton, E. (2020). Saving face: Investigating the ethical concerns of facial recognition auditing. Proceedings of the 2020 AAAI/ACM Conference on AI, Ethics, and Society (pp. 145–151). https://doi.org/10.1145/3375627.3375820
- Selinger, E., & Hartzog, W. (2019). The inconsentability of facial surveillance. Loyola Law Review, 66(1), 101–122.
- Stanley, J. (2019). The dawn of robot surveillance: AI, video analytics, and privacy. American Civil Liberties Union.
- Stark, L. (2019). Facial recognition is the plutonium of AI. XRDS: Crossroads, 25(3), 50–55. https://doi.org/10.1145/3313129
- U.S. Government Accountability Office. (2021). Facial recognition technology: Federal law enforcement agencies should better assess privacy and other risks. GAO-21-518.
- Washington v. Davis, 426 U.S. 229 (1976).
- Yar, M., & Steinmetz, K. F. (2019). Cybercrime and society (3rd ed.). SAGE Publications.
Related Articles
- Algorithmic Bias in Criminal Justice
- Digital Surveillance and Crime Control
- Privacy, Civil Liberties, and Digital Crime Control
- Big Data and Criminal Justice
- Digital Evidence in American Courts