Flock Safety Tightens Surveillance Controls as Police Misuse Sparks a Growing Crisis of Trust + Video

Listen to this Post

Featured Image

A Surveillance Technology Facing a Trust Reckoning

The promise behind automated license plate readers is straightforward: help investigators find stolen vehicles, identify suspects, locate missing people, and solve crimes faster. But when a technology capable of recording where vehicles travel becomes available to thousands of law enforcement users, the same system can become deeply invasive when access is abused.

That tension is now at the center of a growing controversy surrounding Flock Safety, one of the most prominent companies in the automated license plate reader (ALPR) industry. Flock has faced mounting criticism after cases emerged in which police officers allegedly used its surveillance network to investigate romantic partners, former partners, and other people for personal reasons.

In response, Flock CEO Garrett Langley says the company is changing how its technology is governed. The company is introducing stricter auditing, mandatory case numbers, shorter default data retention, and tighter controls over how agencies can share and search information.

The changes represent a significant shift in

But there is a much bigger question underneath these changes: Can technical safeguards restore public trust in a surveillance system that many communities never fully trusted in the first place?

What

Flock’s network is built around automated license plate reader cameras positioned along public roads. These cameras photograph passing vehicles and use computer vision to capture information such as license plates, vehicle color, make, model, and other identifying characteristics.

The resulting information can be searched by participating law enforcement agencies. The appeal for investigators is obvious. Rather than manually searching through hours of video footage, an officer can query a system and potentially determine whether a vehicle appeared near a particular location.

That capability can be extremely useful during investigations involving stolen vehicles, shootings, burglaries, missing people, and other crimes.

But the same capability creates a fundamentally different privacy problem.

A camera does not need to know whether someone is a suspect before recording a vehicle. It can capture information from ordinary drivers simply because they happened to pass a camera.

That means the central issue is not merely what the technology can do. The more important question is who can search the information, under what circumstances, and what prevents that access from being abused?

The Human Weakness Behind the Technology

Flock’s recent changes come after a series of cases involving alleged misuse by police officers.

One of the most striking examples involved former Milwaukee police officer Josue Ayala, who was accused of using the Flock system to track people connected to a romantic relationship. Investigators found that one license plate was searched 124 times and another 55 times during the period under investigation.

The case is especially troubling because the searches were not simply isolated mistakes.

Repeated access to the same vehicles demonstrates how a legitimate investigative tool can potentially become a personal surveillance mechanism when internal controls fail.

Ayala ultimately resigned and pleaded guilty in the case, according to later reporting.

The broader lesson is uncomfortable: a surveillance system can have detailed audit logs and still fail to prevent abuse if nobody acts on those logs quickly enough.

Flock Says Misuse Is Completely Unacceptable

Garrett Langley has acknowledged that the company has a responsibility beyond simply selling surveillance technology to police departments.

In discussing the

That realization appears to have changed

The company now says it has an obligation to help establish stronger standards for how its products are used.

This is an important admission because the controversy surrounding Flock is not only about individual officers.

It is also about the architecture of surveillance itself.

If a system makes it easy for authorized users to access sensitive information but difficult for communities to understand how that information is being used, public distrust can grow even when the technology successfully helps solve crimes.

Audit Assistance Moves From Optional to Mandatory

One of the most important changes is

The system is designed to identify unusual or abnormal search behavior.

Instead of waiting for a supervisor, journalist, victim, or outside investigator to discover suspicious activity, the software can flag patterns that may indicate misuse.

When the system identifies unusual behavior, the user can be locked out while an administrator reviews the activity.

Flock says roughly one-third of its agency customers had already activated Audit Assistance before the company announced that it would become mandatory.

That distinction matters.

A security feature that customers can voluntarily ignore is not the same thing as a security control built into the platform’s baseline operation.

Making auditing mandatory therefore represents one of the stronger elements of the company’s new policy.

The Biggest Change May Be the Case Number Requirement

Flock is also moving toward requiring users to enter a case number to justify searches.

This changes the philosophy behind the system.

Previously, an officer could potentially conduct a search while entering a relatively vague justification. A mandatory case number creates a stronger connection between the search and a documented law enforcement activity.

There will still be exceptions for genuine emergencies, but Flock says those emergency searches will automatically be flagged for review.

The concept is simple:

No case, no ordinary search.

That does not eliminate abuse. An officer could potentially attach a legitimate case number to an illegitimate search.

But it raises the accountability threshold and creates another data point that supervisors and investigators can examine.

Seven Days Instead of Thirty

Flock is also reducing its standard data retention period from 30 days to seven days.

This is a major privacy change because retention determines how far back investigators can potentially reconstruct vehicle movements.

The longer information remains available, the greater the opportunity for both legitimate investigations and potential misuse.

Flock’s existing documentation has historically described 30 days as its default retention period, while allowing different periods when required by law or policy.

Moving toward seven days reduces the amount of historical information available by default.

That is a meaningful privacy improvement, although it does not mean every Flock deployment will necessarily delete information after seven days.

Agencies can still have different retention requirements based on local or state rules.

Evidence Mode Creates an Important Exception

There is an obvious problem with extremely short retention periods.

Investigations do not always move at the speed of technology.

A crime could happen on Monday, investigators might identify a suspect on Thursday, and the relevant data might otherwise disappear before investigators realize it is important.

Flock’s new evidence mode is designed to address that problem.

When a search is connected to a specific case number, agencies can preserve relevant information beyond the normal retention period.

The distinction is important because it separates broad surveillance retention from targeted evidence preservation.

Ideally, information is not kept simply because it might someday be useful.

Instead, investigators preserve it because there is a documented reason connected to a specific case.

Local Governments Get More Control

Another significant change gives local jurisdictions more control over how outside agencies can search their camera data.

For example, a community could potentially allow searches connected to theft investigations while restricting searches for immigration enforcement.

This reflects a broader debate surrounding surveillance interoperability.

Once information is accessible across jurisdictions, the policies of one community can potentially be affected by the policies of another.

A city might approve Flock cameras for local criminal investigations while strongly objecting to their use for unrelated federal enforcement activities.

Giving local jurisdictions the ability to establish those boundaries could therefore become one of the most consequential elements of the new system.

The Immigration Question Is Bigger Than Flock

The ability to restrict certain search purposes is particularly important because surveillance databases can become attractive sources of information for agencies outside the jurisdiction that originally purchased the cameras.

A city might believe it is purchasing technology to locate stolen cars.

But if another agency can use the same database for a different purpose, the practical scope of surveillance becomes much broader than the original public discussion surrounding the purchase.

This is why data-sharing rules matter just as much as camera placement.

A privacy policy is only as strong as the weakest organization allowed to access the information.

Why Trust Has Become a Business Problem

Flock’s controversy is no longer only a civil liberties debate.

It is becoming a commercial problem.

Some cities have cancelled Flock contracts following concerns over surveillance and misuse, while other municipalities have turned toward competitors such as Axon.

That means public trust can directly affect the company’s growth.

If communities conclude that Flock cameras represent uncontrolled surveillance, local officials may face increasing pressure to terminate contracts regardless of the technology’s crime-fighting benefits.

Flock therefore has an economic incentive to prove that stronger safeguards are not merely public relations.

They need to demonstrate that the safeguards actually work.

The Technology Is Not Automatically the Enemy

It is important not to reduce this debate to the idea that every ALPR camera is inherently harmful.

There are legitimate uses for these systems.

Finding a stolen vehicle can help a victim recover property. Locating a missing person can save a life. Identifying a vehicle connected to a violent crime can help investigators move faster.

The problem emerges when the capabilities created for those purposes become available for unrelated personal surveillance.

That distinction is critical.

The question should not simply be:

Should society have surveillance technology?

A more useful question is:

What limitations should exist when governments deploy surveillance technology capable of monitoring millions of ordinary people?

The Real Weakness Is Often the Human Operator

Technology can identify suspicious behavior, but technology cannot replace institutional accountability.

An officer who deliberately abuses a system may also attempt to manipulate the system’s controls.

That is why effective governance requires multiple layers.

There should be automated detection, supervisor review, documented justification, disciplinary consequences, independent oversight, public transparency, and meaningful legal penalties.

If only one of those layers exists, the system remains vulnerable.

A perfect audit tool is meaningless if supervisors ignore its alerts.

A perfect logging system is meaningless if nobody examines the logs.

And a perfect policy is meaningless if officers know violations will rarely result in consequences.

Why Automated Detection Matters

Human supervisors cannot realistically inspect every surveillance search manually.

Modern police departments can conduct enormous numbers of database queries.

That makes automated anomaly detection increasingly important.

A system can potentially identify patterns such as repeated searches of the same vehicle, searches involving an officer’s own address, searches outside an officer’s normal geographic responsibilities, searches involving known associates, or unusually frequent queries.

These patterns do not automatically prove misconduct.

But they can identify activity that deserves human attention.

That is precisely where machine-assisted auditing can provide value.

The Danger of False Confidence

However, automated auditing also creates a potential danger: false confidence.

A police department might assume that because Flock has an audit system, misuse is automatically under control.

It is not.

Detection is not prevention.

Flagging suspicious activity after dozens of searches have already occurred does not undo the privacy violation.

The strongest systems therefore need to intervene as early as possible.

That is why

Surveillance Can Become Personal

The most disturbing misuse cases are not necessarily sophisticated cyberattacks.

They can be remarkably ordinary.

An officer may become angry with a former partner.

Someone may want to know where an acquaintance is going.

An employee may become curious about a neighbor.

A person with privileged access may decide to use government resources for a personal dispute.

Those scenarios demonstrate why authorization alone is insufficient.

The person holding the credentials is also part of the security boundary.

The Authorized User Problem

Traditional cybersecurity often focuses on stopping unauthorized users.

But surveillance systems create another category of threat: authorized users acting without authorization.

An officer may legitimately have permission to access the system.

That does not mean the officer is legitimately allowed to search any person or vehicle.

This distinction is fundamental.

A system can authenticate the correct person and still facilitate an illegal search.

Therefore, identity management alone is not enough.

Contextual authorization is required.

What Good Surveillance Governance Should Look Like

A properly governed ALPR system should ideally answer several questions for every search.

Who searched the database?

When did they search?

What did they search for?

Why did they search?

Which case was associated with the search?

Was the search within the

Was the search connected to an approved offense type?

Was the information subsequently shared?

Who accessed the information afterward?

And, perhaps most importantly, was the search reviewed when its behavior looked unusual?

Flock’s new controls move closer to this model.

But implementation will determine whether the policy becomes meaningful.

Deep Analysis: Commands for a Safer Surveillance Model

Command 01 — Require Purpose Before Access

Every ordinary search should have a documented investigative purpose before results are displayed.

This reduces casual browsing and creates accountability from the beginning rather than after misuse has occurred.

Command 02 — Tie Searches to Cases

A case number should become the central accountability mechanism for investigative searches.

The system should be capable of automatically checking whether the case exists and whether the officer is authorized to work on it.

Command 03 — Detect Behavioral Anomalies

The platform should continuously examine user behavior for patterns that differ dramatically from normal activity.

A sudden increase in searches should trigger investigation.

Command 04 — Detect Personal Connections

Where legally and technically appropriate, systems should identify potential conflicts involving officers’ own addresses, known associates, family members, or other sensitive relationships.

The goal should not be to create another database of private relationships.

The goal should be to identify situations where access deserves additional scrutiny.

Command 05 — Lock Suspicious Accounts

High-risk activity should temporarily suspend access rather than merely generate another notification.

An alert that nobody reads is not a security control.

Command 06 — Require Supervisor Review

Automated systems should assist humans rather than replace them.

Supervisors should determine whether flagged searches were legitimate, mistaken, or abusive.

Command 07 — Preserve Emergency Accountability

Emergency access is necessary in genuine crises.

But emergency access should never mean unrestricted access.

Every emergency search should automatically generate a review record afterward.

Command 08 — Minimize Retention

Data that does not need to exist should not remain available indefinitely.

Shorter default retention limits the damage caused by future misuse, breaches, unauthorized access, or policy changes.

Command 09 — Separate Evidence From General Surveillance

Investigative evidence should be preserved through explicit case-based mechanisms rather than allowing entire databases to remain permanently searchable.

Command 10 — Restrict Cross-Jurisdiction Searches

Local governments should be able to determine how outside agencies access their surveillance infrastructure.

A local community should not lose control of its data simply because another agency has access credentials.

Command 11 — Create Independent Oversight

Police departments should not be the only institutions responsible for policing their own surveillance systems.

Independent oversight can provide another layer of accountability.

Command 12 — Publish Transparency Reports

Communities deserve meaningful information about how surveillance systems are used.

Reports should include aggregate search volumes, misuse investigations, disciplinary actions, retention practices, external agency access, and policy violations.

Command 13 — Penalize Abuse

The consequences of misuse must be strong enough to discourage it.

If unauthorized searches merely result in a warning, technical safeguards will have limited deterrent value.

Command 14 — Audit the Auditors

Even

Companies and agencies should periodically test whether suspicious behavior is actually being detected.

Command 15 — Test the System Like an Attacker

Organizations should conduct controlled misuse scenarios.

Security teams should ask:

Can an officer search a former partner?

Can an officer search their own vehicle?

Can an officer repeatedly search the same person?

Can a user bypass the case-number requirement?

Can an outside agency access restricted information?

Can an administrator ignore an alert?

These tests can expose weaknesses before real people become victims.

What Undercode Say:

The Core Problem Is Bigger Than Flock

Flock’s announcement is important, but the fundamental issue is not a single company’s software.

The larger issue is the rapid expansion of surveillance infrastructure without equally rapid development of oversight mechanisms.

Technology can scale incredibly quickly.

Regulation usually cannot.

That mismatch creates a dangerous window in which surveillance capabilities can expand faster than the rules governing them.

Accountability Must Be Designed Into the Product

For years, technology companies have often treated abuse as something that happens after deployment.

That approach is increasingly inadequate.

If a system is capable of revealing sensitive information about where people travel, accountability needs to be built into the architecture itself.

Security should not depend entirely on an employee remembering to behave correctly.

The Milwaukee Case Is a Warning

The Milwaukee case illustrates exactly why audit systems matter.

An officer allegedly conducted dozens of searches involving people connected to his personal life.

The problem was not that the system lacked records.

The system had records.

The problem was whether those records were being examined quickly and effectively enough to prevent repeated abuse.

That distinction should guide the future of surveillance technology.

Logging Is Not the Same as Oversight

One of the biggest misconceptions in modern security is that logging automatically creates accountability.

It does not.

A system can record everything and still fail.

Effective accountability requires detection, escalation, investigation, documentation, and consequences.

Without those steps, logs become historical evidence rather than preventative controls.

Seven Days Is a Meaningful Privacy Improvement

Reducing default retention from 30 days to seven days is one of Flock’s most defensible changes.

Every additional day of stored location information creates additional privacy exposure.

Shorter retention limits the amount of historical movement data available to search.

But the policy will only deliver its full benefit if agencies actually adopt the shorter default and do not routinely extend retention without strong justification.

Local Control Could Become the Most Important Feature

Giving communities greater control over outside searches could fundamentally change how surveillance networks are governed.

Local governments should not have to accept an all-or-nothing model.

They should be able to define which investigations qualify for access.

They should be able to understand who can search their data.

And they should be able to impose restrictions that reflect local laws and community expectations.

Surveillance Needs Purpose Limitation

The principle of purpose limitation should become central to ALPR governance.

If cameras were installed to help locate stolen vehicles, their information should not automatically become a universal investigative database for every conceivable purpose.

Purpose matters.

Context matters.

Authorization matters.

The Data Has Power Because Movement Has Meaning

A license plate may look like a simple string of characters.

But when combined with timestamps and locations, it can reveal patterns of movement.

Those patterns can expose where people live, work, socialize, worship, seek medical services, meet friends, or spend their private time.

That makes ALPR data significantly more sensitive than a simple vehicle registration number.

The Risk Increases With Scale

A single camera creates a limited surveillance footprint.

A nationwide network creates something very different.

The larger the network becomes, the more valuable its database becomes.

And the more valuable the database becomes, the stronger the incentives for misuse, unauthorized access, political pressure, data requests, and attacks against the infrastructure.

Scale therefore changes the risk calculation.

AI Will Make the Problem More Complicated

Today’s ALPR systems already use computer vision.

Future systems are likely to become even more sophisticated.

AI could potentially identify vehicles more accurately, correlate movement patterns, detect anomalies, and connect information across multiple sources.

That could make investigations dramatically faster.

It could also make privacy violations dramatically more powerful.

The more intelligent surveillance becomes, the stronger the governance must become alongside it.

Competitors Are Watching

Flock’s business challenge is also becoming a technology-market challenge.

If municipalities believe competing platforms offer stronger privacy controls, companies such as Axon can benefit.

That creates an unusual incentive structure.

Privacy may increasingly become a competitive feature rather than merely a regulatory burden.

Trust Is Becoming Part of the Product

Flock CEO Garrett Langley’s statement that the community should be considered the company’s customer is strategically significant.

Police departments may purchase the technology.

But residents are the people living under the surveillance infrastructure.

If residents believe the system is being abused, political opposition can eventually affect contracts.

That means public trust is not simply an ethical issue.

It is a business asset.

Regulation Should Not Depend on Corporate Promises

Flock’s voluntary policy changes are useful.

But nationwide standards should not depend entirely on whether one company chooses to impose stronger controls.

Other surveillance vendors could adopt different standards.

Police departments could have different policies.

Different states could establish different rules.

That creates a fragmented landscape.

State-Level Rules Could Change the Equation

Langley has also argued that regulators should require stronger accountability from law enforcement.

That is a significant point.

If unusual-use detection, regular audits, case-based searches, and meaningful penalties become legal requirements across surveillance technologies, responsible companies would no longer be competing against weaker competitors that offer fewer restrictions.

Privacy Should Not Depend on Geography

A person’s privacy should not depend entirely on whether they happen to live in a city with strong surveillance rules.

Two neighboring jurisdictions could theoretically have completely different standards for the same technology.

That creates loopholes.

A stronger regulatory framework would establish baseline protections while still allowing local governments to impose stricter requirements.

The Most Dangerous Feature May Be Convenience

Surveillance abuse does not always require malicious intent.

Sometimes the danger is simply that information is too easy to obtain.

When a powerful database is only a few clicks away, the psychological barrier to accessing it becomes smaller.

That is why friction can be a security feature.

Requiring a case number, justification, and supervisor review introduces deliberate friction.

Good Security Makes Abuse Harder

The best surveillance controls do not merely tell employees what they should not do.

They make inappropriate behavior technically difficult.

That is the direction

The more steps required to conduct a questionable search, the greater the likelihood that misuse will be detected or abandoned.

But Technology Cannot Create Ethics

No software can completely eliminate unethical behavior.

A determined insider can sometimes find ways around controls.

That is why organizational culture remains essential.

Officers must understand that surveillance privileges are responsibilities, not personal conveniences.

Departments must enforce that principle.

Public Transparency Could Become the Missing Layer

One of the strongest long-term solutions may involve giving communities more visibility into how these systems operate.

Residents should know where cameras are deployed.

They should understand retention periods.

They should know which agencies can access the information.

They should understand what types of searches are permitted.

And they should have meaningful mechanisms for challenging misuse.

Independent Audits Would Strengthen the Model

Flock’s internal tools are useful, but independent audits could provide greater credibility.

A third party could periodically examine whether agencies are following policies and whether the technology’s controls are functioning as advertised.

Independent verification is particularly important when the technology affects fundamental civil liberties.

The Business Future Depends on Trust

Flock’s technology may remain valuable to law enforcement.

But the

If trust improves, stricter controls could become a competitive advantage.

If trust continues collapsing, technical improvements may not be enough to prevent more municipalities from abandoning the platform.

The Surveillance Debate Is Entering a New Phase

The next stage of this debate will not simply be about whether cameras should exist.

It will be about governance.

Who controls the data?

Who can search it?

How long is it stored?

Why was it searched?

Who audits the search?

What happens when someone abuses access?

And who is accountable when the system fails?

Those questions will determine whether ALPR technology becomes a responsible investigative tool or another example of technology expanding faster than society’s ability to control it.

✅ Flock Is Introducing Stronger Mandatory Controls

Flock has announced that Audit Assistance and case-number requirements will become mandatory for its agencies by the end of 2026, according to current reporting. The company says the tools are intended to identify unusual searches and strengthen accountability.

✅ The Milwaukee Misuse Case Is Documented

The claim that a Milwaukee officer used Flock searches to monitor people connected to his romantic life is supported by court-related reporting. Investigators found searches involving two license plates, including 124 searches of one plate and 55 of another.

⚠️ The Seven-Day Retention Policy Needs Context

The article’s description of a seven-day standard retention period reflects Flock’s newly announced policy changes, but retention can vary according to state and local requirements. Flock’s published policy has historically described a 30-day default and allows different retention periods under applicable rules, so readers should not interpret seven days as a universal deletion rule for every deployment.

Prediction

(+1) Surveillance Controls Will Become a Competitive Advantage

Flock’s decision to make stronger auditing and case-based controls mandatory could encourage competing surveillance companies to introduce similar safeguards.

Over time, privacy protections may stop being viewed as optional compliance features and become part of the competition between surveillance technology vendors.

(+1) Local Governments Will Demand Greater Control

As communities become more aware of how ALPR networks operate, municipalities are likely to demand more control over retention, outside-agency access, permitted search purposes, and transparency.

That could gradually move surveillance technology away from a centralized model and toward stronger local governance.

(+1) Automated Misuse Detection Will Become Standard

Manual review of every database search is unrealistic at scale.

As a result, automated behavioral monitoring is likely to become a standard feature of law enforcement technology, similar to fraud detection in banking and anomaly detection in cybersecurity.

(-1) Public Distrust May Continue Even After the Changes

Technical safeguards cannot immediately erase concerns created by years of surveillance expansion and documented misuse.

Some communities may conclude that the fundamental problem is not how the system is controlled, but whether widespread vehicle-location surveillance should exist at all.

(-1) Criminals and Abusers May Adapt

Any security system that becomes widely deployed will eventually face attempts to circumvent it.

An officer who deliberately intends to misuse surveillance technology may attempt to disguise behavior through legitimate-looking cases or other methods.

That makes continuous auditing and independent oversight essential.

(+1) Regulation Will Likely Catch Up

The strongest long-term outcome would be the emergence of clear state and federal standards covering surveillance retention, access, auditing, sharing, and penalties for misuse.

If that happens,

Final Outlook

Flock is attempting to solve a problem that extends far beyond one company or one group of police officers.

The real challenge is finding the boundary between useful surveillance and uncontrolled surveillance.

Its new controls — anomaly detection, mandatory case numbers, shorter default retention, evidence preservation, and greater local control — are steps in the right direction.

But the ultimate test will not be the announcement.

It will be what happens when the next officer attempts to abuse the system.

If the technology stops that misuse before a victim is harmed, Flock will have demonstrated that its new safeguards are more than promises.

If another case emerges despite the new controls, the public will ask a much harder question:

Was the problem ever the absence of safeguards, or was it the decision to build such a powerful surveillance network in the first place?

▶️ Related Video (80% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: edition.cnn.com
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube