Why AI That Watches Your Store Should Never Recognize Faces
Sooner or later every camera-AI conversation reaches face recognition. Somebody asks whether the system can keep a list of known shoplifters and alert the counter when one walks in. It sounds like the natural end point of the technology.
We do not build that, and we will not. Not as a feature we are holding back, and not as a premium tier. Here is the reasoning, because it is worth understanding whoever you buy from.
The legal exposure is real and it lands on the store
A face template is biometric data, and several states regulate it specifically. Illinois' Biometric Information Privacy Act requires that before a private entity collects face geometry it inform the person in writing and receive "a written release executed by the subject of the biometric identifier". Damages are $1,000 per negligent violation and $5,000 per intentional or reckless one, plus attorneys' fees, and BIPA carries a private right of action - meaning a customer can sue directly. A 2024 amendment softened the arithmetic by making repeated scans of the same person by the same method count as a single recovery, but it did not change who can sue or why.
The sums attached to these cases have not been small. Facebook's BIPA settlement over photo tagging was $650 million, with a judge noting it would put at least $345 into the hands of every class member who claimed. Texas, under its own biometric statute, obtained a $1.4 billion settlement from Meta, which the attorney general's office called the largest ever from an action brought by a single state. Some cities have gone further and banned private use outright: Portland's ordinance states that “a Private Entity shall not use Face Recognition Technologies in Places of Public Accommodation”, with damages of $1,000 per day of violation.
A national chain can carry that risk with a legal department. For a store with four cameras and an owner behind the counter, one complaint is an existential event - and the vendor who sold the feature is not the defendant.
It fails, and it does not fail evenly
Even setting law aside, the technology's error profile makes it a poor fit for a store. NIST tested 189 algorithms from 99 developers against 18.27 million images and found higher false-positive rates for Asian and African American faces than for Caucasian ones in one-to-one matching, with differentials that “often ranged from a factor of 10 to 100 times, depending on the individual algorithm”. In one-to-many searching - which is exactly the "check this face against our list" use case - false positives were highest for African American women.
We have already seen what that produces in retail. The FTC banned Rite Aid from using facial recognition for five years after the company ran it in hundreds of stores; “the system generated thousands of false-positive matches”, more of them in stores in plurality-Black and Asian communities, and employees acted on those matches by following, searching and ejecting customers and calling the police on people who had done nothing wrong.
Think about what that means at the counter of a small store. The false positive is not an abstraction. It is a regular who gets accused, tells her family, and does not come back. In a neighbourhood where everyone knows everyone, neither do the neighbours.
The industry's own biggest players read the same evidence and stepped back. Amazon announced a moratorium on police use of its face recognition in 2020. Meta shut down its face recognition system in 2021 and said it would “delete more than a billion people's individual facial recognition templates”.
It answers a question you did not ask
Here is the practical objection, and for us it is the decisive one. Identity is rarely what a store owner needs to know.
Go back through the things that actually cost a store money: the lottery terminal used with no customer at the counter, a delivery left unsigned, the back door propped open after ten, a cooler door left open overnight, a register drawer opened with no sale. Every one of those is a description of a behaviour, in a place, at a time. Knowing the name of the person involved adds nothing to the alert; you either recognise your own employee on the clip or you do not.
So our system describes behaviour. The first AI writes down what is happening on each camera in plain English - a person in a grey jacket walked down the frozen aisle, someone is at the counter, the back door opened - and the second AI confirms the clip before you are texted. It does not build a face template, it does not keep a watch list, and it cannot tell you who someone is. When you look at the clip, you make that judgment yourself, which is where it belongs.
The privacy design reinforces it. Video is not stored in the cloud; what leaves the store is text, and the clip attached to an alert expires within 24 hours. There is no gallery of faces because there is no gallery.
What to ask a vendor
Ask directly: does your system create biometric templates of the people in my store? Does it keep a watch list? If I never turn that feature on, is anything about faces still being computed or stored? Get the answers in writing, and check them against the privacy policy rather than the salesperson.
A store does not need to know who someone is to know that something is wrong. Refusing to answer the first question is what makes it safe to answer the second.
Shobdo VideoRAG is an AI agent for the security cameras your store already owns. It writes down what it sees and texts you only when something matters. Learn more or book a conversation.