A WIRED investigation reveals that Flock Safety built an AI tool identifying drivers, contradicting its public claims. With documented misuse and inadequate oversight, the episode mirrors broader failures in AI self-regulation.
Flock’s New AI Tool Tracks Drivers Despite Denials
For years, Flock Safety told the public that its license-plate cameras were not a threat to privacy because the technology “cannot recognize, identify, or track individuals.” That is no longer true—and it may never have been the whole story. A WIRED investigation published August 19, 2026 obtained the company’s code and revealed that Flock Safety had built a powerful artificial intelligence tool capable of identifying drivers and tracking vehicles by their patterns of movement. The revelation directly contradicts the company’s long-standing assurances and exposes a gap between public relations and engineering reality that has become all too familiar in the surveillance industry.
The new AI system represents a fundamental shift. Instead of simply recording license plates and cross-referencing them against databases of stolen vehicles or wanted persons, Flock’s tool can link plates to individual identities and monitor a driver’s movements over time without needing a prior hit. The code shows that the company engineered the capability to perform “driver identification” and “vehicle pattern tracking” – functions that Flock had explicitly denied having. The WIRED report notes that the company has not publicly disclosed this capability to its customers or to the communities where its more than 120,000 cameras are deployed.
Flock Safety’s public stance had been a key argument against calls for stricter oversight. In testimony, marketing materials, and interviews, executives maintained that their devices were merely “license-plate readers,” not individual surveillance tools. That distinction mattered: it allowed law enforcement agencies to deploy the cameras with fewer privacy safeguards and allowed the company to claim it was respecting civil liberties. The discovery that Flock built a person-identifying AI tool undermines that narrative and raises serious questions about what other undisclosed capabilities may exist.
Documented Misuse and Missing Oversight
The AI revelation is not happening in a vacuum. A Washington Post investigation published the same week found that police officers across the country have misused Flock cameras for personal reasons—tracking ex-partners, acquaintances, or people of personal interest—often without their departments’ knowledge. The Post’s reporting forced at least two departments to discipline officers, but it also revealed that many police agencies had no monitoring systems in place. The problem was not just rogue employees; it was the absence of any mechanism to catch them.
These findings align with broader patterns of surveillance abuse. In Utah, a nonprofit investigation by the Utah Civic Compact found that records from just ten Flock cameras in Weber County were searched more than 5 million times between February 2022 and July 2026. Nearly 97 percent of those searches came from out-of-state agencies across 45 states. Utah Governor Spencer Cox told reporters he was “deeply troubled” by the findings and called for a formal review of the state’s privacy rules. The Utah Civic Compact noted that there is no way for Utah authorities to verify whether out-of-state agencies are complying with state privacy laws—an oversight vacuum that renders existing statutes almost meaningless.
Meanwhile, a coalition of civil rights groups filed a complaint under Maryland’s new Data Privacy Act against Flock and six other companies, accusing them of improperly collecting, sharing, and selling vehicle location data, including with U.S. Immigration and Customs Enforcement (ICE). The complaint, reported by CBS Baltimore, argues that the companies’ practices violate the state law, which took effect in July 2026. Some of the named companies, such as PenLink and Thomson Reuters, have denied wrongdoing and said they comply with all applicable laws. The Maryland attorney general’s office is reviewing the complaint.
Flock’s Response and the Limits of Self-Regulation
In response to mounting backlash, Flock Safety announced platform changes in mid-August. The company said it would require law enforcement customers to implement an audit tool that flags abnormal search behavior and locks users out pending internal review. It also mandated that each search be tied to a specific case code from a records management system, with emergency overrides flagged for scrutiny.
But critics have called these measures insufficient. The AP report quotes civil liberties advocates describing the changes as “window dressing” that does not address the core problem: the company designs and controls the technology, decides what capabilities to build, and then self-certifies its own compliance. There is no independent verification of Flock’s audit tools, no requirement for third-party penetration testing, and no obligation to disclose new features before they are deployed. The same dynamic has played out in the broader AI industry, where companies like OpenAI, Google, and Meta have made promises about content filtering and safety guardrails, only to be caught releasing models with minimal oversight. The Flock case is a pointed reminder that without external auditing and legislative mandates, self-regulation tends to fail.
Knowns, Unknowns, and Open Questions
What is now established: Flock Safety built an AI tool that identifies and tracks drivers, contradicting years of public denials. Police misuse of the cameras is widespread and often undetected. State-level privacy laws exist but are difficult to enforce when data crosses jurisdictional lines. What remains unknown is the full extent of the AI tool’s deployment—whether it is in active use, how many agencies have access, and whether other surveillance vendors have similar undisclosed capabilities. Flock has not detailed the rollout of the new feature, and neither law enforcement nor the public has a clear picture of its reach.
Disagreements among sources are significant. Flock and other named companies maintain they are compliant with privacy laws and that their tools are used lawfully. Civil rights groups counter that the very architecture of the systems—mass data collection, cross-agency sharing, and opaque vendor practices—violates privacy rights by design. The Utah governor’s call for review suggests that even conservative-leaning states are starting to question the unchecked expansion of surveillance networks.
Synthesis: The Surveillance Trust Deficit
The Flock Safety revelations are not an isolated incident. They illustrate a recurring pattern in surveillance technology: vendors make public promises about privacy protections while quietly engineering capabilities that undermine those assurances. This mirrors the ongoing debate about AI guardrails and content moderation. In both domains, companies resist external oversight, claiming that internal policies are sufficient. Yet time and again, those policies prove hollow when the code is actually examined.
The pushback is growing. The Maryland complaint, the Utah review, and the Washington Post investigations all point toward a demand for structural accountability: independent audits, legislative mandates, and real consequences for misleading the public. But the underlying tension remains unresolved. How can legitimate law enforcement needs be balanced with effective privacy protections when vendors control both the technology and the narrative? Are audit logs and case-code requirements enforceable, or will they become another box-ticking exercise? And can state-level privacy laws truly constrain a data market that includes federal immigration enforcement, when that market operates across state lines and often in the shadows?
These are not rhetorical questions. They are the open challenges that communities, legislators, and courts will have to address as the full implications of Flock’s AI tool—and the industry’s broader pattern of saying one thing while building another—continue to unfold.
FAQ
Did Flock Safety actually build an AI tool that identifies drivers?
Yes. A WIRED investigation obtained code showing that Flock Safety developed an AI system that can identify drivers and track vehicles by movement patterns, directly contradicting years of public statements that its technology could not recognize or track individuals.
What did Flock Safety previously claim about tracking individuals?
Flock Safety had repeatedly told the public and media that its technology “cannot recognize, identify, or track individuals.” The company used this assertion to defend its privacy practices and deflect criticism from civil liberties groups.
How were Flock cameras misused by police?
A Washington Post investigation found instances of police officers using Flock cameras for personal reasons—such as tracking ex-partners or acquaintances—often without their departments’ knowledge. Many departments lacked basic oversight mechanisms to detect such abuse.
What reforms has Flock Safety announced in response?
Flock announced platform changes including an audit tool to flag abnormal searches and a requirement that each search be tied to a specific case code. Critics, however, call these measures insufficient and describe them as window dressing that does not address systemic issues.
Why does this episode matter for the broader debate about AI guardrails?
The Flock case illustrates how self-regulation by technology vendors can fail when there is no independent verification. It parallels concerns about AI content filtering and censorship, where companies make public promises but deploy capabilities that undermine them, highlighting the need for legislative mandates and external audits.