What Flock Safety teaches us about AI accountability
Flock Safety is having a very bad year, and almost none of it is a technology problem. It’s a trust problem. And trust problems don’t get fixed with product updates, press releases, or apologies. They get fixed with proof.
Flock Safety is having a very bad year, and almost none of it is a technology problem. It’s a trust problem. And trust problems don’t get fixed with product updates, press releases, or apologies. They get fixed with proof.
How we got here
In early August, The Washington Post reviewed police and court records and identified at least 50 law enforcement officers accused, charged, or convicted of using license plate readers for unauthorized purposes. Flock’s system appeared in 46 of those cases. In 26 of them, investigators said officers used the technology to spy on wives, girlfriends, exes, or women they wanted to meet.
The fallout has been fast. The advocacy group Secure Justice documented 93 governments ending Flock contracts in August 2026 alone, Florida’s Department of Transportation revoked all active ALPR permits on state highway rights of way, and Texas halted state funding for Flock deployments around the same period. Now Flock has offered employees voluntary buyouts and says it will grant them to most of those who apply. Wired’s sources said that without the buyouts, the company would almost certainly need to lay off staff.
It's not just Flock
Let’s be fair about one thing: Flock isn’t the only company in this business, and it isn’t the only one with problems. It’s just the one whose name became the category. Flock is the Kleenex of license plate readers. To most people, every camera on a pole is a “Flock camera.”
The industry is much bigger than one brand. The ACLU points out that a DHS roundup lists 16 providers, IPVM tested nine products for accuracy, and another analyst counts 46 vendors in the space. Even in the Post’s count, Flock appeared in 46 of the 50 misuse cases, which means the rest involved someone else’s system.
The other big names have their own baggage. A class action filed in July 2026 alleges that Motorola and its subsidiary Vigilant facilitated unlawful cross-jurisdictional sharing of California ALPR data and maintained an inadequate privacy policy. Rekor provides ALPR services to Westchester County police, which is the subject of a class action by the NYCLU and other groups.
Meanwhile, competitors are happily picking up Flock’s cancelled contracts. Axon is explicitly positioning itself as a “more ethical” alternative. The EFF’s Matthew Guariglia told NPR that switching from Flock to Axon just trades one color of camera for another, since the ability to track vehicle movements is basically unchanged. Some cities have figured this out: in September, Tallahassee voted unanimously to suspend its contracts with both Flock and Motorola.
That’s the real lesson. Swapping the logo on the pole doesn’t change the risk. As one watchdog site put it, the contract, configuration, access policy, and audit process are what determine whether the privacy model actually changes.
The response: more of the same
To its credit, Flock responded. It announced it would require officers to label every search with a criminal case number and automatically review all searches for abnormal activity, a previously voluntary feature used by about a third of its 7,000 law enforcement agencies. It also cut the default data retention period from 30 days to seven.
Those are reasonable changes. But look at who’s vouching for them: Flock.
CEO Garrett Langley told CBS he doesn’t think Flock created police abuse, and that Flock is the first company to shine a light on it and build the tools to find it. Meanwhile, a spokesperson insisted that so far in 2026, new city partnerships have outpaced nonrenewals by roughly 10 to 1.
Maybe both of those things are true. Nobody outside the company can tell. That’s the whole problem.
Controls that exist vs. controls that work
Here’s the part that should worry every buyer of AI systems, not just police departments. Flock already had audit logs. The tools were there. But a follow-up Post investigation found cops who had misused Flock whose departments didn’t know, because those departments and many others had not done basic oversight. As Cybernews noted, Flock’s audit logs are usually reviewed only after complaints prompt an investigation.
That’s the gap between a control that exists and a control that operates. A feature that a third of your customers turn on is not a safeguard. A log nobody reads is not accountability. And a vendor telling you its safeguards work is not evidence.
This is checkbox theater, and it’s everywhere in AI right now.
What independent audit actually proves
This is exactly what independent audit and certification are for. ISO/IEC 42001 is the first international standard that specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system. It’s structured like ISO 9001 for quality and ISO/IEC 27001 for information security, which means it’s built to be audited by a third party, not self-attested.
It covers the things Flock is getting hammered on: AI risk assessment, performance evaluation through monitoring and audits, and continual improvement with corrective actions. Its controls address intended use, human oversight, and monitoring of deployed AI, along with due diligence across suppliers, customers, and partners. That last one matters for Flock specifically. When your system’s biggest risk is how 7,000 customers use it, customer-side controls have to be in scope.
And auditors want evidence the system works: risk and impact assessments, incident and nonconformity logs, training records. Not a blog post. Not a spokesperson quote.
Why Flock should go first
Being the Kleenex of ALPR is a liability right now. Every officer who misuses any plate reader, on any vendor’s system, lands on Flock’s brand. Flock absorbs the whole industry’s reputation whether it earned it or not.
But that also makes Flock the company with the most to gain. No one outside of law enforcement believes law enforcement, and right now no one believes the vendors either. Every statement gets read as spin. Every new feature gets read as damage control.
An independent audit changes the conversation from “trust us” to “check us.” If Flock’s controls are real, certification proves it publicly. If they aren’t, it surfaces the gaps before the next Post investigation does. And if the brand name is already the category, Flock going first sets the bar every competitor then has to clear. “A Flock camera” stops meaning “surveillance nobody checks” and starts meaning “the one that’s been independently audited.”
No company in this space has taken that step. Not Flock, not Axon, not Motorola. At some point, someone will, and whoever goes first gets to define what accountable surveillance technology looks like.
Flock can keep grading its own homework. The market has already told it what that grade is worth.
Share this article
Related Articles
The Reskilling Illusion: When AI Transformation Means "You're Fired"
Oct 03, 2025