> Fixing Flock: The controls needed now that misuse patterns are clear
[DATE: 25/09/2026 08:25]
[LANGUAGE: EN]
Flock Safety has stirred widespread debate of late. Flock builds interconnected networks of automated license-plate readers and other public safety cameras. Those systems can help police solve serious crimes, but they also log sensitive personal location data and make it searchable across agencies and jurisdictions. The question is no longer whether the technology has value. It is what controls Flock must build now that patterns of misuse are clear.
We have sympathy for the police officers and analysts trying to use Flock responsibly. Consider a 911 call after a carjacking. An analyst checks nearby footage, identifies a likely vehicle and adds the plate or description to a hotlist. License-plate readers then produce a focused trail showing where the car went. Flock demonstrates this workflow in its Safe City materials. Its FlockOS platform can connect 911 calls, video, plate readers, police records, drones and other sensors. The software narrows the evidence before a person reviews it. That’s a use of technology that can save lives.
We also have sympathy for those concerned about Flock, given the abuse already documented. Society needs a more robust debate about how modern technology is changing privacy expectations. More surveillance can improve safety, but it creates tradeoffs. Healthy tension and hearty discussion are the only path toward the right balance.
The debate is often framed as whether to rip out Flock or let it rip up our privacy. Neither may be the right answer. Flock has invested heavily in expanding what law enforcement can do, but not enough on limiting data access only to that needed for the job. But removing Flock will not return us to a world without cameras. It will push us toward a decentralized collection of public and private systems with even fewer controls. Without intelligent search, investigators will watch footage from hundreds of cameras, exposing thousands of innocent people to human review and creating more opportunities for misuse or accidental disclosure. When computers stop filtering and prioritizing information, people must do it. Done properly, the smart layer can be the privacy layer.
The landmines in a data product are not always intuitive at launch. Teams build for the analyst trying to find the carjacker, not the officer tracking an estranged spouse, the agency trying to evade another state’s law or the feature that quietly expands access. We do not fault a product team for failing to imagine every abuse before launch. Once the pattern is visible, however, the obligation changes: Move quickly, build the lesson into the product and prove the controls work.
The risks emerge after launch
Flock is no longer just a company that sells cameras. It says it serves more than 6,000 communities, 5,000 law-enforcement agencies and over 1,000 businesses. The Washington Post reports that the network includes more than 120,000 cameras across 49 states and processes about 20 billion plate observations a month. The platform now includes video, audio detection, drones, 911 integration and software that searches police records and other systems.
Flock FreeForm lets users search video and plate data for descriptions such as a dark SUV with bumper damage or a person wearing particular clothing. Flock says it does not use facial recognition, but it can search for people through observable characteristics. Each capability may appear modest in isolation. At network scale, billions of observations searchable across time and geography can reveal where someone sleeps, works, worships, seeks medical treatment, attends a protest or spends the night. And as has been documented repeatedly, some police have abused their access.
Flock has begun responding
On Aug. 13, 2026, Flock announced several changes. It set a seven-day default for ordinary plate records, with longer preservation for active cases. It says case codes will be required for law-enforcement searches by the end of 2026, emergency overrides will be reviewed, customers can limit the offenses for which outsiders search their data, and multifactor authentication will be mandatory. Its expanded Audit Assistance system is intended to detect abnormal searches and lock users out pending review, with adoption required for law-enforcement customers by year-end. The Associated Press account of Flock’s reforms independently describes the announcement and the concerns behind it. These steps show that Flock can change the product in response to misuse. The question is how quickly the controls become universal and how fully they address the known risks.
Seven days is a sensible privacy-protective default, not a universal ceiling. Flock says more than 90% of searches that begin without a full plate occur within a week. That describes product use; it does not prove that serious crimes are solved within seven days. In an All-In interview, CEO Garrett Langley pointed to homicides and delayed reports of rape as investigations that may need more time. The example can sound rhetorical, but the point is sound: Consequential cases are often complicated, and investigators may not know which vehicle matters until later.
At Facebook, we learned the same lesson from the other side. Short retention windows made it harder to reconstruct abuse because complaints, patterns and corroborating facts often arrived later, so we widened some windows. Deletion removes risk, but it can also destroy evidence needed to expose misuse. The better model is graduated retention backed by graduated controls. Seven days can remain the default. A community seeking more time should approve it publicly and accept stronger requirements, including verified identity, case-bound access, added justification for older data, supervisor review for sensitive searches, automated abuse detection, immutable logs, periodic renewal and independent audit. Retention should follow investigative value and control maturity. It cannot carry the burden that access control and accountability should carry.
A case number matters only if it is real and the user is assigned to it. An anomaly detector matters only if it works and triggers timely action. A portal matters only if it is complete and used. Engineering takes time, but interim protection often does not. Flock can disable high-risk sharing, require supervisor approval, review suspicious searches, restrict older data and suspend problematic accounts while permanent controls are built.
In just the last few weeks we’ve heard more reasons to move quickly. Boston’s newly released surveillance report says its contract required data sharing to be off, yet outside agencies could reach Boston’s data during the opening days of its pilot because nationwide sharing had been enabled in error. Separately, a September review of historical Flock logs found searches justified with entries such as “LMAO,” “idk” and “TBD.” Flock later replaced free text with preset categories, but a dropdown still cannot prove that a real case exists or that the user is assigned to it.
What we learned at Facebook and Uber
At Facebook and Uber, we did not begin with mature privacy and integrity systems. We built them as failure modes became visible. Once misuse repeats, the problem belongs to the system. Policies must become product requirements, logs must become detection systems, review bodies need authority and executives need to know which risks remain open.
At Facebook, customer-support employees could not type in a person’s name and access their account. Access began with a real support ticket assigned to that employee, often by a queue or random assignment. A short-lived token allowed only the data needed for that ticket. When the task ended, access ended.
At Uber, we built a platform for law-enforcement requests that kept responsive data in Uber’s environment. An authorized officer could view it through a secure portal and had to make a separate decision to download a copy. Many requests were never viewed because the investigation changed direction; others were viewed but never downloaded. In both cases, the portal prevented an unnecessary durable copy from landing on a government server.
We also made sure each request was tied to a badge number and authenticated government email account. We separately logged the request, portal view, affirmative download decision and completed transfer. Those attributes created the foundation for accountability by tying the person, case, access and transfer together. A request, a view and a download are different events, and the system should treat them differently. Flock should treat a badge number and government email as attributes, not proof. It should independently confirm employment, case assignment and authority through agency or court integrations, not by replying to the same email. New devices, unusual locations, abnormal volumes and recently created accounts should trigger added verification. Fake legal process keeps changing, so detection must keep changing too.
Facebook tokenization addressed who could look. Uber’s portal addressed when data should leave the platform. Flock needs both.
The controls Flock needs
Flock should build the following controls into the product:
Bind access to a real task. Replace free-form case codes with short-lived tokens issued from trusted systems such as 911 dispatch, records management, a supervisor-assigned investigation, a stolen-vehicle report or a documented private-security incident. Scope each token to the individual, case, plate or description, data sources, geography, time and permitted actions. Integrate with agency systems so legitimate context and audit records arrive automatically. A good investigator should experience better automation; an abuser should experience friction.
Verify every individual and request. Tie each user to a badge number, verified agency, authenticated government account and named login. Ban shared role accounts, require phishing-resistant multifactor authentication, prefer managed devices and repeatedly confirm employment and authorization. Validate legal process through an independent channel, with added checks for unusual devices, locations, volumes or new accounts.
Separate requesting, viewing, preserving and downloading. Portal viewing should be the default, with records remaining at the originating customer or in Flock’s controlled environment until needed. Unused permission should expire without creating an outside copy. A download should require a separate affirmative action tied to the investigator and validated case, then generate its own log.
Measure human exposure. For each workflow, document what the computer processes, what a person sees and how unrelated results are suppressed. Give the analyst a focused set of plausible matches, not unrestricted access to everyone in the area. Track raw footage kept from human view, people who opened a case, results viewed, exports and secondary copies.
Make sharing restrictive by default. Keep purpose and legal restrictions attached to every result, alert, export and API response so recipients cannot strip them or forward data for a prohibited use. Sharing should identify the recipient, offenses, purpose, geography and duration. Customers should see every organization with access and revoke it immediately.
Require informed approval for expanded access. Product changes that add a capability or sharing path should be opt-in. Preserve the complete, versioned history of when each feature and relationship was enabled or disabled, not merely the setting shown when a report is generated.
Narrow Flock’s rights in customer data. Flock’s terms say customers own their data while granting the company a perpetual, irrevocable license to use it for providing and improving products. Limit that license to defined purposes and periods. Training models on customer images should require explicit authorization and meaningful de-identification testing.
Treat device security as part of system integrity. Roadside cameras should use hardware-backed key storage, secure boot, signed firmware and tamper detection. When a camera disappears, its credentials should be revoked immediately, and a remote wipe should be queued if it reconnects. Physical theft should be treated as an expected attack, not an exceptional one.
Turn Audit Assistance into a tested detection system. Look for repeated searches of the same vehicle outside an active case, after-hours or out-of-jurisdiction activity, volumes inconsistent with a user’s role, recycled case numbers and repeated emergency overrides. Seed known abuse scenarios and publish detection rates, false flags and response times.
Give a centralized integrity team authority to act. Serious cases should not depend solely on the user’s agency. Flock needs investigators, response deadlines and power to suspend a user or disconnect a customer.
Create append-only audit records. Log the user, device, authentication, validated case, purpose, legal authority, query, jurisdictions reached, results viewed, preservation, exports, hotlist changes, emergency overrides, administrator actions and Flock employee access. For every retention, sharing or feature change, record the old and new values, approver, time, reason and product version in a store ordinary administrators cannot alter or delete. If an alert causes a mistaken stop, investigators should be able to reconstruct the model, hotlist and configuration that produced it.
Test accuracy independently. Flock says it receives fewer than nine human-reported errors per million alerts, but that counts complaints, not errors. Roseville, California, reviewed 1,427 of its own alerts from 2023 and 2024 and found the plate had been read incorrectly in 71 percent of them. The Drive’s wrongful-stop account, by Joel Feder, shows how an erroneous source record, character recognition that ignored part of a plate, a broad partial match and absent officer verification can compound into an armed stop of the wrong person. Publish precision, recall, false alerts and misses. Show the source and age of every alert, and require visual confirmation of the plate and active source record before consequential action.
Provide a remedy. Operate an independent complaint channel, preserve relevant logs and propagate corrections across the network. Notify affected people when misuse is confirmed unless a court-approved investigative need temporarily prevents it.
Make transparency continuous and vendor-attested. Require public-customer portals showing retention, sharing partners, permitted offenses, queries, emergency overrides, exports, confirmed misuse, accuracy and security incidents, and public-safety outcomes. Flock should host and certify the factual layer so an agency cannot rewrite history. Each configuration event should be time-stamped, digitally signed and cryptographically linked to make deletion or reordering detectable, with a public validation receipt and independent reconciliation to raw events.
Those product controls need institutional authority behind them:
Create board and executive accountability. Establish a board-level privacy, civil-liberties and integrity committee and give a senior executive independent of sales power to delay or block a launch. Review every material product, data source, search capability, model and integration against foreseeable misuse. No review will find every landmine. The standard is whether Flock looked seriously, documented the risk and moved quickly when experience exposed what it missed.
Require testing and attestation. Independent assessors should test controls rather than accept management assurances. Executives should certify effectiveness and disclose material weaknesses. Flock should periodically attest to log completeness, customer configuration history, known collection gaps and material failures for a defined period, with an accountable executive’s signature and independent testing against raw events. Flock should be the source of record for what the product did, while outside verification tests that record. Publish platform totals for requests, views, preservation, downloads and permissions that expired unused; the last figure shows how many unnecessary disclosures the architecture prevented.
Measure public-safety value independently. Fund pre-registered research on missing people found, stolen vehicles recovered, serious cases materially advanced, false leads, mistaken stops, complaints and confirmed abuse. Evidence remains mixed and thin. A National Institute of Justice randomized study, last updated in 2013, found no significant crime effects, though what it tested was plate readers on patrol rather than anything resembling a searchable national network. The National Policing Institute, summarizing the existing literature, describes operational benefits such as stolen-vehicle recovery alongside limited evidence on broader crime reduction. Nobody has rigorously evaluated the product Flock sells today.
Support enforceable rules. Legislation should require publicly approved retention, validated cases, graduated controls for older data, limits on sharing, tamper-evident logs, continuous reporting and consequences for misuse. Long movement histories, reverse searches and similarly revealing uses should require a warrant, with narrow exceptions for stolen vehicles, endangered people and genuine emergencies. Courts are still defining constitutional limits, but Flock need not wait years to establish a defensible standard. The Center for Democracy & Technology’s ALPR recommendations are a useful starting point.
Move while there is still trust to preserve
Most people using Flock are honest law enforcement trying to find missing people, recover stolen cars and solve violent crimes. Good officers hate misuse because it endangers the public and makes their own work harder to trust. The system should help them identify outliers, remove access quickly and prove when a department stayed inside the rules.
Flock’s initial reforms show that many protections are technically possible. We know builders will not see every possible misuse before users find it for them. That does not justify delay once the pattern is clear. You may not see every landmine at launch. Once you find one, you have to move fast.