Police-tech platform Flock is aggressively restricting access across its network of 120,000 automated license plate recognition (ALPR) cameras, forced into damage control as municipal clients cancel contracts over rampant misuse. The commercial reckoning follows a series of high-profile abuse scandals—including a Washington Post investigation documenting 46 instances of officers using Flock feeds for unauthorized personal surveillance, such as stalking romantic partners.
To curb customer churn and head off mounting regulatory scrutiny, Flock is converting previously optional security guardrails into mandatory defaults. Law enforcement operators must now enter a verified criminal case number before running a query, backed by an automated auditing module designed to flag anomalous search patterns to departmental supervisors. Flock is also enabling municipalities to restrict out-of-jurisdiction agency queries and advising clients to compress data retention windows from 30 days down to seven. Yet the core vulnerability remains unaddressed: because the system relies on self-reported case numbers without third-party validation, civil liberties advocates like the ACLU point out that intentional bad actors can still bypass controls with dummy entries.
For enterprise computer vision and physical monitoring vendors, Flock's crisis is a stark case study in the structural risks of B2G deployments. Scaling hardware footprints without strict, day-one access governance and immutable audit trails creates fatal regulatory and reputational liabilities. Retrofitting controls after institutional customers begin tearing up contracts is a reactive, expensive fix—and unverified text fields are unlikely to satisfy skeptical city councils.