Police use of facial recognition is legal in most of the United States, but it is no longer unregulated: San Francisco banned its use by city agencies in May 2019, Illinois barred police use of the technology statewide in January 2021, and Detroit agreed in June 2024 to tighten its facial recognition policies after the wrongful arrest of Robert Williams, who was detained when a facial recognition match misidentified him. The rules that bind departments now come as much from city councils and courts as from police manuals.
USA Daily News 24 is an online publication, not a law firm, and it publishes information, not legal advice. Departments, vendors, and individuals facing a specific dispute over biometric data should get advice from licensed counsel in the relevant jurisdiction.
How do police actually use facial recognition?
The typical workflow is simple. Investigators feed a probe image — often a low-quality still from a surveillance camera — into software that compares it against a gallery of known faces, usually driver's license photos or arrest mugshots. The system returns ranked candidates with similarity scores. An analyst reviews the candidates, passes a pick to a detective, and the investigation proceeds from there. The federal benchmark for accuracy is the National Institute of Standards and Technology's Face Recognition Vendor Test, which in its December 2019 demographic study found that many algorithms produced far higher false-positive rates for Asian and African American faces than for white ones — a finding that reshaped the public debate.
Which cases put the technology on trial?
Three lines of litigation define the terrain. The first is wrongful arrest. Robert Williams was arrested at his home in a suburb of Detroit in January 2020 after a facial recognition match to grainy watch-store footage; he sued with support from the American Civil Liberties Union and the National Association of Criminal Defense Lawyers, and in June 2024 the city settled, adopting a written policy that limits when officers may act on facial recognition leads. Porcha Woodruff, eight months pregnant, was arrested in Detroit in February 2023 on a warrant generated the same way and later cleared. Neither case produced a judicial ruling on the technology's constitutionality — both ended in settlement — which is precisely why the policy outcome matters more than case law so far.
The second line is biometric privacy. Illinois's Biometric Information Privacy Act, in force since 2008, lets people sue over the collection of face geometry without informed consent. The state's highest court in Rosenbach v. Six Flags in 2019 held that a person need not show actual harm to sue, and in Cothron v. White Castle in February 2023 it held that each scan can restart the five-year limitations clock — a ruling with enormous damages exposure that pushed the legislature to amend the statute for business-related collections in 2024.
The third line is data brokers. Clearview AI scraped billions of photos from social media to build a search engine sold to police; under a May 2022 settlement with the ACLU enforced under the Illinois law, Clearview agreed to stop selling its faceprints to most private entities and to Illinois agencies, reshaping who can buy that kind of capability. Together the three lines of litigation cover the whole supply chain: the match, the database, and the arrest that follows.
Related stories: Due Process in Immigration Detention: The Time Limits and Safeguards That Apply · Section 2 of the Voting Rights Act After Callais: What Still Works.
What have governments actually banned or required?
The map is a patchwork that runs from prohibition to procurement rules:
- San Francisco barred city agencies, including police, from using facial recognition in May 2019, the first major American city to do so, followed within months by Oakland and Berkeley.
- Illinois enacted a statewide ban on police use of facial recognition in January 2021, tied to its biometric privacy framework.
- Massachusetts restricted the technology statewide in 2020 to a single registry run by the state police, with judicial authorization required before a search.
- Detroit tightened its own program after the Williams settlement in June 2024: searches must be documented, matches cannot be the sole basis for an arrest, and the department must audit use.
- Federal agencies operate under a 2021 memorandum from the Office of Management and Budget requiring agencies to assess accuracy and privacy risks before adopting the technology; Congress has debated, but never passed, a comprehensive facial recognition statute.
- Virginia restricted local police use in 2021, then re-authorized it in 2022 only under standards set by the Department of Criminal Justice Services — an example of a state experimenting, retreating, and regrouping.
Do the courts treat a face scan as a search?
No Supreme Court decision has squarely addressed facial recognition under the Fourth Amendment, so the closest analogies govern. Courts that have examined the technology in suppression disputes have largely declined to suppress evidence, reasoning that a person has no greater expectation of privacy in a face shown in public than in any other publicly observable feature. Critics counter that the aggregation of every camera in a city changes the calculus, an argument that echoes the reasoning the Supreme Court used for historical cell-site location data in Carpenter v. United States in 2018. The question remains open, which is why state and local legislation, not constitutional doctrine, is where the binding rules actually live.
What does this change going forward?
As of mid-2026, the practical effect is a two-tier country. Where legislatures have acted, facial recognition is a documented, audited, sometimes judicially supervised tool, and a bad match is a policy violation with paper trails. Where nothing has passed, the technology runs on internal department policy alone, and the only real check is the wrongful-arrest lawsuit filed after the fact. Accuracy will keep improving with better algorithms, but accuracy was never the whole problem: the December 2019 NIST findings, the Detroit settlements, and the Illinois damages cases all show that the failure mode is not the software alone — it is an unverified match treated as an identity. The governing insight from the past six years is that the human confirmation step, not the algorithm's score, is where rights are won or lost. Williams's case proved the point in both directions: the pipeline that arrested him had no paper trail, and the settlement he won now requires one.
