The Ethical Problems With Facial Recognition That Governments Are Ignoring
Wrongful arrests, undisclosed police searches, scraped photo databases and legal loopholes expose the governance failures behind facial recognition.
The most serious ethical problems with facial recognition are not technical glitches.
They are governance failures: wrongful arrests driven by false matches, police use that defendants are never told about, databases built from scraped photos without consent, and laws that regulate the headline use while leaving retrospective searches, private deployments and immigration enforcement largely untouched.
Trending Now!!:
Public argument tends to settle into two camps, one demanding a ban and the other defending the technology as a precision tool for catching dangerous offenders. Both positions skip the question that matters most to the people affected: what rules govern the system once it is running, and who answers when it is wrong.
The Accuracy Debate Is Real, and It Is Incomplete
The standard reference point is the 2019 demographic study from the US National Institute of Standards and Technology. It found empirical evidence of demographic differentials in the majority of contemporary face algorithms evaluated.
In one-to-many searches, the type police use to scan a database for a suspect, false positive rates were higher for African American women, a differential NIST flagged as consequential because it can lead to false accusations.
Algorithms developed in Asian countries showed no major false positive gap between Asian and Caucasian faces, which suggests the disparity is tied to training data and design choices rather than being an unavoidable property of the technology.
The counterargument deserves a fair hearing. The UK Home Office says an independent test by the National Physical Laboratory found no bias for ethnicity, age or gender at the settings police use. South Wales Police reports no false alerts since August 2019.
Both claims can be accurate at once. Error rates depend on the algorithm, the match threshold, the quality of the probe image and the size of the watchlist. A lab result at a strict threshold says little about a blurry doorbell frame run against millions of driver’s licence photos.
The common misconception is that a headline accuracy figure settles the matter. US Customs and Border Protection, for example, says its matching of departing travellers is accurate around 98 percent of the time. A 98 percent rate across millions of scans still produces a large absolute number of errors, and the cost of those errors is not distributed evenly.
The Human Safeguard That Keeps Failing
Governments routinely reassure the public that a person always makes the final decision. The wrongful arrest record undercuts that. The ACLU counts at least 14 wrongful arrests in the United States tied to erroneous facial recognition results, with Black people making up most of the known cases.
In several of them, police moved straight from the software’s output to a photo lineup shown to witnesses, a sequence that tainted identifications and led to the wrongful arrests of at least seven people.
The mechanism is automation bias. A witness shown a lineup built around the algorithm’s candidate, plus five filler photos, is being asked to confirm a suggestion, not to recall a face independently. The “human in the loop” is then a human who has been handed the answer.
Detroit offers the clearest institutional response. The city agreed to pay Robert Williams $300,000 after his wrongful arrest for shoplifting and committed to changes in how police use the software. Under the settlement, Detroit officers can no longer seek arrest warrants based only on a facial recognition lead combined with a photo lineup. The rule is narrow and sensible, and few other agencies have adopted anything comparable.
Informal use compounds the problem. In the case of Kimberlee Williams, an Oklahoma resident arrested on a Maryland warrant, the ACLU says a person on a police email list ran a suspect image through the software and returned her as a supposed match. Nothing in that chain resembles a controlled forensic process.
Evidence Defendants Never See
A defendant cannot challenge what the defendant does not know exists. A Washington Post investigation drew on records from police departments in 15 states covering more than 1,000 criminal investigations, and found that authorities routinely failed to tell defendants facial recognition had been used.
Reports often said suspects were identified through “investigative means” rather than naming the software. The Post reported that the Coral Springs Police Department in Florida instructs officers not to reveal facial recognition use in written reports.
Miami police ran 2,500 searches over four years that contributed to at least 186 arrests and more than 50 convictions, yet fewer than 7 percent of those defendants were informed of the technology’s use. The county’s state attorney said prosecutors had not been told in the vast majority of cases, and a disclosure rule followed.
Bans can also be sidestepped. In places where local restrictions exist, agencies have outsourced searches to other agencies that are not covered by them. A prohibition that can be bypassed with a phone call protects the department’s reputation more than it protects residents.
Databases Built Without Consent
The raw material of many systems is photographs people never agreed to provide. The Dutch Data Protection Authority fined Clearview AI €30.5 million for building an illegal database of more than 30 billion images, and the decision is final because Clearview did not object to it. Regulators in France, Italy and Greece had each fined the company €20 million earlier. The UK penalty of roughly £7.5 million was overturned on appeal.
The more instructive detail is what happened next. As of mid-2025, Clearview had not paid the Dutch fine, and a further €5.1 million in penalties was accruing. The company is US-based and has no physical presence in the EU, which raises doubts about whether regulators can collect. The Dutch authority has said it is exploring personal liability for the company’s directors.
This matters commercially as well as ethically. The Dutch regulator’s chairman, Aleid Wolfsen, warned that organisations using Clearview’s services are acting illegally and may face fines of their own. Any agency or business weighing facial recognition software procurement inherits the legal exposure of the vendor’s data sourcing. Due diligence on where a vendor’s training and reference images came from is now a compliance question, not a technical footnote.
Laws That Regulate the Wrong Thing
The EU AI Act is the most ambitious attempt at regulation, and its limits are widely misunderstood. It prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, with exceptions for targeted searches for victims, specific imminent threats and suspects of serious crimes, each requiring prior judicial authorisation.
The common belief that all biometric identification is banned is wrong. Retrospective identification by police is classed as high-risk rather than prohibited, and real-time use by non-police actors falls outside the ban. Because the second case describes most of what happens after a crime has occurred, the prohibition covers a narrower slice of real-world use than its reputation suggests. Legal commentators have also warned that the exceptions are vague and could lead to inconsistent and expanding deployment across member states.
The UK shows a different failure, a patchwork. The government funded 10 live facial recognition vans for seven police forces, with Home Secretary Yvette Cooper describing the use as targeted. Separately, the Home Office reportedly allowed police to run scans against passport and immigration databases without notifying Parliament or the public.
The Home Office itself acknowledged in its consultation brief that a member of the public would need to read multiple statutes and layers of guidance to understand the legal basis for police live facial recognition on the high street. That consultation on a new legal framework closed on 12 February 2026.
One commentator noted that the reforms address only law enforcement, leaving retailers using the same technology in public places under a separate regime. The UK data protection regulator has stated that the technology does not operate in a “legal vacuum.”
The United States has the thinnest framework of the three. No federal law governs police use of facial recognition. More than 20 cities and jurisdictions have banned police use, producing a map where a person’s protections depend on postcode.
Immigration Enforcement and the End of Opt-Out
The least examined frontier is identity checking in the field. Reporting by 404 Media, based on an internal Department of Homeland Security document, says ICE does not allow people to decline a scan by its Mobile Fortify app and stores the resulting photos for 15 years, including those of US citizens.
The app reportedly draws on databases holding more than 200 million images. An ICE statement indicated that the app’s results would be prioritised over a birth certificate. A further DHS document describes plans to give potentially more than a thousand local law enforcement agencies a version of the app. A coalition led by the Electronic Privacy Information Center has asked DHS to suspend its use.
The ethical issue is the inversion of the burden of proof. A false match in a criminal case can be contested in court eventually. A false match on a street corner, in a system where the machine outranks documentary proof of citizenship, leaves the person to disprove the software while already detained.
A Five-Part Test for Any Deployment
Policymakers and procurement teams can evaluate a facial recognition programme against five questions, drawn from the failures above.
Disclosure
Is every defendant told, in writing, that facial recognition contributed to an identification, along with the software, the threshold and the probe image? Miami’s experience shows that voluntary practice does not deliver this.
Corroboration
Does policy forbid arrest or warrant requests resting on a match plus an identification procedure built around that match? Detroit’s settlement rule is the working model.
Auditability
Are searches logged, attributable to a named officer and open to independent review? An email-list search with no record fails this test immediately.
Provenance and retention
Can the vendor document the lawful origin of its reference images, and is retention limited by purpose? Fifteen years of storage for people never suspected of anything fails the second half.
Redress
Is there a defined route for a person to learn they were scanned, correct an error and obtain compensation? Few systems offer one.
What the Strongest Defenders Get Right
The case for the technology is not frivolous. A Home Office survey found two in three people support police use of facial recognition, even though many voiced concern about misuse and false identification.
UK forces report using live deployments to arrest suspects in rape, domestic abuse, knife crime and robbery cases, and to catch sex offenders breaching their conditions. Locating missing people and serious offenders is a legitimate aim, and the EU’s own exceptions acknowledge it.
The realistic policy question, then, is not ban versus permit. Systems that can find a violent fugitive can also misidentify a shopper, log a protester or scan a citizen who cannot refuse. The measure of a government’s seriousness is whether it writes the constraints into binding law, publishes the error data and gives the wrongly identified a way to be heard, rather than leaving them to depend on the restraint of whichever agency happens to hold the camera.
What People Ask


