Resource guide

Facial Recognition: How It Works, Who’s Watching, Rights

A plain-English guide to facial recognition tech, its risks, real wrongful-arrest cases, and what laws and choices can protect you.

Last updated July 15, 2026 4192-word guide Editor Ban the Bots

Facial recognition technology is already watching you — at airports, retail stores, sports stadiums, and on city streets. This guide explains how facial recognition works, documents the racial bias built into these systems (at least 14 wrongful arrests in the US, all involving Black people), and covers your legal rights under state biometric privacy laws. It also addresses facial recognition ethics, the EU AI Act ban on real-time public surveillance, and which companies use facial recognition without telling you.

Facial recognition is a type of face recognition AI that turns your face into a “biometric” identifier (a measurable body feature) and tries to match it to photos or databases. The big ethical concern is that facial recognition technology can enable mass surveillance, make biased mistakes, and put people at risk—often without consent or notice.

What is facial recognition?

Facial recognition is software that analyzes an image of a face and compares it to other images to find a match (or a “possible match”). When people say “face recognition AI,” they usually mean machine-learning systems trained on huge numbers of face photos to recognize patterns and similarities.

In practice, facial recognition systems are used for things like unlocking phones, verifying identity, searching for a person in a photo database, or scanning crowds with live cameras. The market is large and growing: the global facial recognition market was worth $8 billion in 2025 and is projected to reach $13 billion by 2029.

It’s helpful to separate two common uses:

How does facial recognition work?

Most facial recognition technology follows the same basic pipeline: detect a face, measure it, and compare it. The exact math varies by vendor, but the steps are fairly consistent.

Step-by-step: what facial recognition systems actually do

  1. Face detection: The system locates a face in an image (or video frame).
  2. Normalization: It tries to standardize the face—angle, lighting, size—so comparisons are “fairer.”
  3. Feature encoding: It converts the face into a numeric representation (often called a faceprint or embedding). This is what gets stored and compared.
  4. Comparison and scoring: It compares your faceprint to stored faceprints and produces similarity scores.
  5. Decision: A system (or a human) sets a threshold: above it, it’s a “match”; below it, “no match.”

That last step is where a lot of real-world harm happens. If a threshold is set too low, the system produces more false positives (wrong matches). If it’s set too high, it misses matches. Neither outcome is harmless when police action, school discipline, or access to a job depends on it.

A quick comparison: phone unlock vs. police search

Not all facial recognition is equally risky. Here’s a plain-language comparison of common use cases and why the stakes are different.

Facial recognition issues: why it matters in daily life

People usually start caring about facial recognition ethics when they realize the tool isn’t just “a better security camera.” It’s a way to identify people at scale, often without their knowledge.

The most cited problems with facial recognition fall into a few buckets:

If you want a broader picture of how these harms show up in the real world, Ban the Bots tracks patterns and examples at /ai-incidents/.

Facial recognition bias and wrongful arrests (real cases)

Facial recognition bias isn’t a theoretical issue. It has been connected to real wrongful arrests in the United States.

As of 2026, at least 14 people in the US have been wrongfully arrested due to facial recognition false positives—and all publicly confirmed cases involve Black people. That’s a hard, human measure of what “false positive” can mean when a computer match is treated like a lead that “must be right.”

Robert Williams (Detroit, 2020)

In 2020, Robert Williams was wrongfully arrested after facial recognition matched his expired driver’s license photo to surveillance footage of a shoplifter. He was not near the store.

The case became a landmark not only because it was widely documented, but because of what happened later: it settled in June 2024 with policy changes at the Detroit Police Department. Importantly, this was reported as the first settlement in the US requiring police facial recognition policy reform.

Porcha Woodruff (Detroit, 2023)

In 2023, Porcha Woodruff was wrongfully arrested while eight months pregnant after facial recognition matched her to a carjacking suspect. A key detail underscores how blunt these systems can be when used carelessly: the actual perpetrator was not visibly pregnant.

What research says about demographic performance

A National Academies of Sciences report (2024) found facial recognition accuracy varies significantly across demographic groups and is least accurate on darker-skinned faces and women. When accuracy drops for certain groups, it increases the risk of wrongful targeting—especially in high-stakes uses like law enforcement identification and watchlists.

Who’s watching: police, stores, and facial recognition apps

When people ask “Who’s watching?” they usually mean three overlapping worlds: law enforcement, public-space camera networks, and private companies (including retailers and apps).

Police and public cameras (including live facial recognition)

Live facial recognition uses cameras in public places to scan faces in real time and compare them to watchlists. One concrete example of the scale: London’s Metropolitan Police scanned approximately 1 million faces in 2025 using live facial recognition cameras.

In the UK, even senior officials have acknowledged the governance gap. The UK Home Secretary said in July 2025 the UK needs “a proper, clear governance framework” for facial recognition—and that such a framework does not yet exist. That matters because “rules later” is exactly how surveillance tools become normalized before the public can meaningfully consent or object.

Stores and “does Walmart use facial recognition?”

A very common search is: does Walmart use facial recognition? Here’s the careful, evergreen answer: big retailers use a mix of security tools—cameras, analytics, and sometimes biometric tools—but whether facial recognition is used can vary by location, vendor, and time, and it’s often not publicly transparent. The bigger issue for shoppers is this: you may not be told what biometric surveillance is in use, and you typically can’t negotiate the terms just to buy groceries.

If you’re concerned about retail surveillance, a practical step is to look for posted notices at entrances and read store privacy policies. Another is to push your city or state for clear rules (see the legal section below) so the burden isn’t on individual shoppers to investigate.

Facial recognition app risks

A facial recognition app can range from harmless (sorting your own photo library) to risky (building a searchable database of strangers’ faces). The ethical red flags are consistent: unclear consent, unclear retention, unclear sharing, and unclear security.

Even when an app feels optional, its outputs can affect people who never agreed—because if your friend uploads a photo, your face can be processed too.

Whether facial recognition is legal depends heavily on where you live and who is using it. One of the biggest realities right now is uneven protection: strong rules in some places, almost none in others.

United States: no federal law (as of 2026), patchwork local bans

As of 2026, the United States has no federal facial recognition law. Instead, protections come from a mix of local bans and state biometric privacy laws.

This patchwork matters for everyday rights. In a city with a police-use ban, you have a different baseline expectation than in a city where police can run face searches with minimal transparency.

For readers thinking “I didn’t vote on this,” you’re not imagining it: many deployments happened through procurement decisions, not public referendums. If you want to get involved in the policy side, Ban the Bots maintains practical steps at /fighting-back/.

European Union: the EU AI Act draws a bright line

The EU AI Act, fully applicable from August 2, 2026, takes a much firmer stance on certain uses. It prohibits real-time facial recognition in public spaces by law enforcement, with narrow exceptions. It also classifies mass facial recognition databases as “unacceptable risk” AI.

If you want a readable walkthrough of what the EU law does (and doesn’t) do, see /explainers/eu-ai-act.

Why bans focus on police use

Some people ask: why ban facial recognition instead of “improving accuracy”? Because accuracy doesn’t solve the core civil liberties problem of constant identification in public. And even “pretty accurate” systems can be dangerous when used as a shortcut to suspicion.

Is facial recognition safe? Biometric privacy concerns

“Safe” depends on what you mean: safe from hacking, safe from misuse, safe from discrimination, or safe for democracy. Facial recognition software can fail on all four.

Key biometric data privacy risks (and why they’re different)

Facial recognition ethics: the human questions behind the tech

Facial recognition ethics isn’t just about whether an algorithm is “biased.” It’s also about power: who gets to identify whom, under what rules, and with what accountability when it goes wrong.

Ask these ethics questions whenever you see facial recognition proposed:

Anti facial recognition mask, glasses, and makeup: what they can (and can’t) do

Searches for “anti facial recognition mask,” “anti facial recognition glasses,” and “anti facial recognition makeup” are really searches for control: people want a way to move through public life without being turned into a trackable ID.

Here’s the reality in plain terms:

The more reliable fix is policy: limits on deployment, limits on retention, and bans on high-risk uses—especially real-time public surveillance.

What you can do: rights, pressure points, and safer choices

You shouldn’t need to be a privacy expert to protect yourself from biometric surveillance. Here are practical steps that match the world as it is: patchwork laws, limited transparency, and real harms.

1) Find out whether your city has a ban (and use it)

In the US, at least 16 cities have banned police use of facial recognition, including San Francisco, Boston, and Portland. Milwaukee banned police facial recognition in February 2026 after public outcry.

If you live in a city with a ban, you can:

2) If you’re wrongfully arrested, treat it like an emergency civil-rights issue

If facial recognition contributes to an arrest, time matters. The research context here is clear: at least 14 wrongful arrests have been publicly confirmed, and all involved Black people.

Ban the Bots’ practical guidance: contact the ACLU if you are wrongfully arrested. Also preserve evidence: booking paperwork, any mention of “facial recognition,” body-cam disclosures, and timeline proof of where you were.

3) Push for clear rules (not vague “responsible use” promises)

Because the US lacks a federal law as of 2026, public pressure often matters at the city and state level. Support facial recognition legislation using the action steps at /fighting-back/.

If you’re evaluating proposed policies, look for hard requirements like:

4) Watch the bigger AI ecosystem (surveillance grows with infrastructure)

Facial recognition doesn’t exist alone; it rides on data centers, cameras, databases, and contracts. To understand the physical footprint behind AI systems, explore Ban the Bots’ data center map and the explainer on infrastructure impacts at /explainers/data-center-impact.

5) Track incidents and patterns so it’s not “your word vs. the system”

When harms stay isolated, institutions can frame them as rare mistakes. Tracking helps show patterns. You can follow documented examples at /ai-incidents/ and broader public response at /ai-backlash/.

Comparison: policy fixes vs. personal workarounds

Facial recognition and government surveillance laws (Section 702)

Facial recognition rarely works alone. It is one tool inside a much larger government surveillance toolkit. A key law behind that toolkit is Section 702 of the Foreign Intelligence Surveillance Act.

Section 702 lets US agencies collect foreign communications without a warrant. Americans' messages often get swept up too. Congress reauthorized it in April 2024 through the RISAA law.

Section 702 covers communications, not faces directly. But agencies combine many databases. Facial recognition, license plate data, and intercepted messages can all point at the same person.

That is why privacy groups treat these systems as one problem. To see how vehicle tracking fits in, read our guide to automated license plate readers. For identity systems, see digital ID, and for ways to push back, visit fighting back.

FAQ

Is facial recognition banned in the US?

No nationwide ban exists. As of 2026 the US has no federal facial recognition law, but at least 16 cities have banned police use of facial recognition, including San Francisco, Boston, and Portland, and Milwaukee banned it in February 2026.

Does facial recognition work the same for everyone?

No. A National Academies of Sciences (2024) report found accuracy varies significantly across demographic groups and is least accurate on darker-skinned faces and women, which increases the risk of wrongful targeting.

Why do wrongful arrests happen if it’s “just a lead”?

Because “just a lead” can become the center of an investigation. The Robert Williams and Porcha Woodruff cases in Detroit show how a match can override common-sense checks—like location evidence or obvious physical differences.

What does the EU AI Act do about facial recognition?

The EU AI Act, fully applicable from August 2, 2026, prohibits real-time facial recognition in public spaces by law enforcement with narrow exceptions, and treats mass facial recognition databases as “unacceptable risk” AI.

What should I do if I think my city is using facial recognition on the street?

Start by checking whether your city has a ban on police use and asking local oversight bodies for procurement and policy documents. You can also track and report patterns via /ai-incidents/ and find organizing steps at /fighting-back/.

Conclusion: Facial recognition facial recognition ethics isn’t a niche tech debate—it’s about whether face recognition AI becomes a normal way to identify and track people in public, with known bias risks and real wrongful arrests. If you want to push back, start local (city/state rules and bans), document harms, and use Ban the Bots tools to take action: learn about related power shifts at /ai-layoffs/, join policy efforts at /fighting-back/, understand the infrastructure behind surveillance at /data-center-map/, see public response at /ai-backlash/, and follow accountability battles at /ai-lawsuits/.

How to block facial recognition: a practical guide

A small industry has grown around defeating facial recognition — makeup, glasses, masks, and clothing designed to confuse the algorithms. Here's what actually exists, with an honest caveat up front: none of these are guaranteed to work against modern systems, and effectiveness varies a lot by which specific software is being used.

Adversarial makeup

Artist and researcher Adam Harvey's CV Dazzle project popularized using asymmetric, high-contrast makeup patterns and hair styling designed to break up the facial landmarks that recognition algorithms look for — the bridge of the nose, the curve of the brow, the symmetry of the eyes. It works reasonably well against older, simpler detection systems. Modern deep-learning-based systems, trained on far more varied and adversarial data, are considerably harder to fool with makeup alone.

IR-blocking and reflective glasses

Some eyewear, including products from companies like Reflectacles, is designed to block or reflect infrared light used by certain facial recognition and detection systems, or to obscure key points around the eyes that many algorithms rely on. Results vary significantly depending on the target system's technology — infrared-based systems are more affected than purely visible-light camera systems.

Masks and coverings

A simple mask or covering that hides the nose and mouth can meaningfully disrupt many facial recognition systems, since most algorithms rely on the geometry of the whole lower face along with the eyes. That said, some newer systems are specifically trained on mask-era data (a side effect of the COVID-19 pandemic pushing this research forward) and can still identify people from the eye region and forehead alone.

Adversarial clothing and accessories

Clothing printed with patterns designed to trigger false face detections, or accessories designed to create glare and shadow across the face, have shown mixed results in independent testing — sometimes defeating a specific system in a lab setting, then failing against a different vendor's software entirely.

The honest bottom line: anti-facial-recognition wearables can raise the difficulty for casual or lower-end systems, but no product on the market is proven to reliably defeat every facial recognition system in every lighting condition. Treat them as one layer of privacy protection, not a guarantee.

Facial recognition: frequently asked questions

Can facial recognition tell twins apart?

Not reliably. Identical twins share the facial geometry most recognition algorithms measure, which makes them one of the hardest cases for the technology. Some higher-end systems have improved on this, but twins remain a well-known weak spot.

Can facial recognition be fooled by masks, sunglasses, or a photo?

It depends on the system. Sunglasses and masks can meaningfully disrupt older or simpler systems by hiding key facial landmarks, though some newer systems are trained specifically to work around partial occlusion. A printed photo can fool some systems that don't check for "liveness" (signs the face in front of the camera is a real, live person), which is why many modern systems now include liveness detection specifically to block photo and video spoofing attempts.

How accurate is facial recognition?

Accuracy varies significantly by system, image quality, lighting, and — this part is well documented in academic research — by demographic group. The National Institute of Standards and Technology runs an ongoing Facial Recognition Vendor Test (FRVT) program that has repeatedly found higher error rates for darker-skinned faces and for women compared to lighter-skinned male faces, across many (though not all) tested algorithms. That gap has narrowed in top-performing systems over time but hasn't disappeared industry-wide.

Facial recognition vs. facial detection vs. fingerprint — what's the difference?

Facial detection just answers "is there a face in this image?" — it doesn't identify anyone. Facial recognition goes further and answers "whose face is this?" by comparing it against a database of known faces. Fingerprint identification is a completely different biometric technology, using the ridge patterns on a fingertip rather than facial geometry — it requires physical contact (or a very close scan) rather than working from a distance like a camera.

When was facial recognition invented?

Facial recognition research dates back to the 1960s, when early computer scientists first experimented with having machines measure facial features to identify people. It stayed a research curiosity for decades. Modern deep-learning-based systems — the kind that actually work well enough for real-world deployment — became viable roughly in the 2010s, as larger datasets and more powerful computing made today's accuracy levels possible.

UK police facial recognition vans

In the UK, the Metropolitan Police has deployed live facial recognition (LFR) vans at various public locations across London — including outside train stations and in busy shopping areas — scanning the faces of passersby in real time against a watchlist. Exactly which boroughs and locations get deployments changes over time and is announced deployment by deployment, so treat any specific date or location as a snapshot rather than a fixed rule.

How it works

A camera-equipped van parks in a public area and scans faces in the crowd, comparing them in real time against a police watchlist. Anyone flagged as a possible match can be stopped by officers nearby. Anyone not on the watchlist is, in principle, not stored — though the practice of scanning every face that passes, matched or not, is exactly what civil liberties groups object to.

The legal pushback: R (Bridges) v Chief Constable of South Wales Police

The leading UK judicial precedent on facial recognition's lawfulness didn't come from London — it came from Wales. In R (Bridges) v Chief Constable of South Wales Police (2020), the Court of Appeal ruled that South Wales Police's use of live facial recognition violated privacy rights and data protection law, partly because the force hadn't done enough to ensure the technology didn't have a discriminatory effect and hadn't given the public enough information about who could end up on a watchlist. Although the case involved a different force than London's Metropolitan Police, it set the national legal standard that all UK police forces deploying live facial recognition — vans included — now have to reckon with.

Ongoing controversy

Civil liberties organizations in the UK continue to challenge facial recognition van deployments as function creep — expanding an emergency surveillance tool into routine, everyday policing of public spaces. Police forces maintain the vans target only people on legitimate watchlists. The tension between those two positions remains an active, unresolved debate in UK policing.

Frequently asked questions

How does facial recognition work step by step?
Facial recognition typically (1) detects a face in an image, (2) normalizes it for angle and lighting, (3) encodes it into a numeric faceprint, (4) compares that faceprint to stored faceprints and generates similarity scores, and (5) applies a threshold to label a match or non-match.
What are the biggest facial recognition issues and ethics concerns?
The biggest concerns are mass surveillance (chilling free assembly and expression), lack of consent and notice, demographic accuracy gaps that increase wrongful targeting, and biometric privacy risks—because biometric identifiers can’t be changed like passwords after a breach.
How many wrongful arrests have been caused by facial recognition in the U.S.?
As of 2026, at least 14 people in the U.S. have been wrongfully arrested due to facial recognition false positives, and all publicly confirmed cases involve Black people.
Is facial recognition legal in the U.S. right now?
There is no federal facial recognition law in the U.S. as of 2026. Rules vary by state and city: nearly two dozen states have biometric privacy laws, and at least 16 cities (including San Francisco, Boston, and Portland) ban police use of facial recognition; Milwaukee banned it in February 2026.
What does the EU AI Act say about live facial recognition in public?
The EU AI Act, fully applicable from August 2, 2026, prohibits real-time facial recognition in public spaces by law enforcement, with narrow exceptions, and classifies mass facial recognition databases as “unacceptable risk” AI.
Do anti facial recognition glasses, masks, or makeup actually work?
They may reduce matching in some situations by obscuring key facial regions or changing how cameras capture features, but they are not a guaranteed defense and can create social or legal risks depending on local rules. Policy limits and bans are more reliable protections than personal workarounds.
What is Section 702 of the Foreign Intelligence Surveillance Act?
Section 702 is a US law that lets intelligence agencies collect foreign communications without a warrant; Americans' data is often swept up too. Congress reauthorized it in April 2024. It does not authorize facial recognition itself, but it is part of the broader surveillance system that face data can feed into.

Latest related briefings