Surveillance technology startup Flock Safety announced a suite of new policies and accompanying technological tools on Thursday, aimed at addressing persistent concerns regarding the potential for misuse of its automated license plate reader (ALPR) systems and enhancing accountability among its law enforcement clientele. The company’s initiative comes at a critical juncture, as reports of improper use of its technology by police officers continue to surface, sparking debate among privacy advocates and civil liberties organizations about the efficacy and transparency of such surveillance measures.
The core of Flock’s updated approach involves significant adjustments to data retention periods and the introduction of enhanced oversight mechanisms. Historically, Flock recommended that its law enforcement partners retain ALPR data for up to 30 days. In a notable shift, the company is now advocating for a reduced retention period of just seven days. This recalibration aims to minimize the window of opportunity for data to be accessed or exploited for unauthorized purposes, thereby bolstering privacy protections for the general public.
However, recognizing that certain investigations may necessitate longer data preservation, Flock has introduced a feature termed "Evidence Mode." This mode is designed for use in "exceptional cases" and requires the assignment of a specific case number, providing a structured and auditable pathway for extended data retention. Furthermore, the company is empowering its customers to implement granular controls over data sharing with other agencies or entities. These new limitations are based on the specific type of offense under investigation, allowing for a more targeted and restricted dissemination of sensitive information.
Audit Assistance: A Central Pillar of Flock’s Transparency Push
A key component of Flock’s announced reforms is the widespread implementation and mandated use of its "Audit Assistance" tool. First launched in April, this feature is designed to provide an automated layer of oversight for ALPR system usage. According to Flock, over one-third of its customers have already adopted Audit Assistance since its introduction, and the company is now requiring all its clients to enable the tool by the end of the current year.
Flock describes Audit Assistance as a system that "detects abnormal activity and flags it for Administrator review." The tool is engineered to identify patterns of usage that deviate from standard protocols or appear unusual. In instances where suspicious activity is detected, Audit Assistance can automatically suspend user access, effectively locking out the flagged individual until an administrator can investigate and intervene. Flock asserts that this proactive approach has already proven instrumental in helping some of its customers identify and prevent instances of misuse.
Despite the emphasis placed on Audit Assistance by Flock executives, a degree of opacity surrounds its precise operational mechanics. While various officials have highlighted its capabilities, detailed explanations of how the underlying "algorithm" functions remain scarce.
Unpacking the Functionality of Audit Assistance
Official statements offer glimpses into the intended scope of Audit Assistance, though they often become less specific when describing the technical processes involved. Ashley Haber, Flock’s head of trust and compliance, has indicated in video statements that the tool can identify "what may look like an odd search history from a specific user," thereby assisting customers in understanding how their personnel are interacting with the system. Paige Todd, a co-founder of Flock, elaborated in another video, stating that Audit Assistance "flags unusual patterns early. Think a user searching the same plate repetitively for more than 30 days."
A notable testimonial comes from Major Patrick Krieg of the Dunwoody, Georgia Police Department, a Flock customer. In a press release, Major Krieg described Audit Assistance as "an algorithm that has notified us of any type of bias." This suggests a potential for the tool to identify not only routine misuse but also patterns that might indicate discriminatory practices or biased targeting. Flock’s own compliance documentation characterizes Audit Assistance as a feature capable of "surface[ing] atypical activity early and review[ing] it quickly with a clear, documented workflow."
However, fundamental questions persist regarding the technical underpinnings of Audit Assistance, which TechCrunch has sought to clarify. Specifically, inquiries have been raised about the exact nature of the "algorithm," the data sets upon which it has been trained, and whether artificial intelligence or large language models were employed in its development. Furthermore, the precise definition of "abnormal activity" and the types of patterns the tool is designed to detect remain areas requiring further illumination.
Flock has clarified that Audit Assistance is not based on machine learning or artificial intelligence. Instead, the company characterizes it as a "data tool that flags atypical search patterns for further review." An illustrative example provided by Flock to explain a trigger for a flag is a scenario where a user searches for the same license plate using multiple different case codes. Such a pattern, the company explained, "could potentially indicate abuse." It is crucial to note, Flock emphasizes, that "a flag does not mean that it is definitely abuse ā it only means it warrants further investigation."
Despite these clarifications, significant unanswered questions linger. These include whether Flock possesses quantifiable data demonstrating the tool’s effectiveness, its rates of false positives and false negatives, and whether the system has undergone independent third-party audits to validate its performance and reliability.
Skepticism from Privacy Advocates and Civil Liberties Experts
The unveiling of Flock’s new measures has been met with considerable skepticism from privacy experts and critics of widespread surveillance technology. Chad Marlow, senior policy counsel at the American Civil Liberties Union (ACLU), expressed his reservations in response to Flock’s announcement, stating that "there is no evidence that the tool works consistently" to curb misuse.
Marlow specifically addressed Flock’s claims that recent arrests of officers for misconduct are proof of the auditing tool’s efficacy. He argued, "While dozens of officers have recently been arrested, fired, or otherwise disciplined for misusing Flock for personal reasons, Flock claims these arrests are proof its auditing tool works. However, unless we know the number of officers misusing the system, we cannot conclude if Flock and its auditing tools are catching 95% of violators or 5%." Marlow concluded by emphasizing the need for an independent evaluation of Flock’s auditing tool to ascertain its true effectiveness, suggesting that without such an assessment, it remains unclear whether the tool represents a genuine security measure or merely "window dressing."
Cooper Quintin, a security researcher and senior public interest technologist at the Electronic Frontier Foundation (EFF), offered a more pragmatic, albeit equally critical, perspective. Quintin suggested that the effectiveness of Audit Assistance might be a secondary concern. He posited, "If it does work, law enforcement will figure out ways to get around it." Quintin stressed that the ultimate measure of success lies in whether abusers are apprehended and held accountable. He further stated, "If there are no consequences for abuse and whoever [the tool] reports to is the same police agency that is doing the abuse, itās just a fig leaf for Flock." According to Quintin, the most robust approach to ensuring accountability involves legislative action to restrict the use of ALPR technology and mandate warrant requirements for its deployment.
Rachel Levinson-Waldman, director of the Brennan Center’s Liberty and National Security Program, acknowledged that making Audit Assistance mandatory represents a step in the right direction, and that "in theory" the tool is "a great idea." However, she echoed concerns about the lack of transparency, asserting that the tool "needs to be audited" due to insufficient information regarding its practical application and efficacy.
A Pattern of Misuse and Flock’s Response
Flock’s latest announcements follow a history of documented incidents where its technology has allegedly been misused by law enforcement agencies. These reports have fueled ongoing debates about the balance between public safety and individual privacy rights in an era of pervasive digital surveillance.
Just days before Flock’s policy update, three former deputies from the Bibb County Sheriff’s Office in Georgia were arrested and charged with allegedly using Flock cameras to stalk individuals with whom they had "personal relationships at the time." The Bibb County Sheriff, David Davis, specifically credited Flock’s Audit Assistance tool for uncovering this alleged misconduct, highlighting its role in the investigation. This incident, among others, underscores the persistent challenges in preventing the misuse of powerful surveillance tools.
The series of events leading to these policy changes suggests a reactive rather than proactive approach by Flock to address systemic issues. For years, privacy advocates have pointed to numerous instances of law enforcement officers abusing Flock’s ALPR systems for personal reasons, ranging from tracking ex-partners to monitoring individuals for non-criminal purposes. These concerns have been amplified by reports of officers being disciplined, arrested, or even fired for such violations, often necessitating internal investigations or media exposĆ©s to bring the misconduct to light.
The company’s revised data retention policies and the mandatory implementation of Audit Assistance appear to be direct responses to these escalating criticisms and documented failures. By shortening the default data retention period, Flock aims to mitigate the risk of data being stored indefinitely and potentially accessed without cause. The "Evidence Mode" provides a controlled exception for legitimate investigative needs, requiring explicit justification and case documentation. Similarly, the enhanced data sharing controls are intended to prevent the uncontrolled proliferation of sensitive license plate data across different jurisdictions or entities.
However, the recurring theme in the critical commentary from privacy organizations is the need for independent verification and robust legal frameworks. The assertion that a tool designed to detect abuse is itself effective hinges on its demonstrable accuracy, its resistance to circumvention, and the presence of genuine consequences for those who violate its protocols. Without independent audits and clear legislative guidelines, the utility and trustworthiness of such technological solutions remain subjects of ongoing debate and scrutiny. The effectiveness of Flock’s latest measures will ultimately be judged not only by their technical implementation but also by their real-world impact on preventing the misuse of surveillance technology and safeguarding civil liberties.
