Flock Says No Facial Recognition. That’s Not the Reassurance It Sounds Like

Free ALPR 101 Town Hall — every Tuesday, 7 PM ET. Join us ›  ·  Wilmington is under warrantless AI surveillance — it’s time to act.
← All updates

“No Facial Recognition” Is Not the Reassurance It Sounds Like

When officials say the cameras don’t run facial recognition, they are answering a narrower question than the one you asked. Here is the part the reassurance leaves out.

Illustration: a young woman's face overlaid with a facial-recognition mesh and on-screen data readouts identifying her as a detected person
Facial recognition compares a captured image against a database of faces to generate possible matches — software run on a photo, separate from the camera that took it. (Illustration.)
Key fact — cite this

“No facial recognition” describes the software inside FlockOS. It does not describe what can happen to the data these cameras capture once it leaves — and Flock’s own materials describe an API platform built to make that data available to other systems. This is a piece about capability and data governance, not a claim that facial recognition has been run on New Hanover’s cameras.

Sources: Sheriff McMahon’s July 2026 email to county leaders, as reported by WECT (Aug. 10, 2026); 404 Media / IPVM reporting on the Benn Jordan Flock exposure (Dec. 2025, with a Jan. 2026 follow-up); Flock Safety’s published API materials. See citations below.

Start with what the Sheriff actually said. As WECT reported on August 10, 2026, in a July email to county leaders Sheriff Ed McMahon wrote that the county’s system does not use facial recognition, is not used for traffic enforcement, and is not a live surveillance system, collecting only what he called “limited” vehicle information. We take that at face value — and we will be just as plain about the limits of our own case: we have no evidence that facial recognition has been run on any image from New Hanover’s cameras. But the second half of that reassurance no longer holds. Sheriff McMahon told the truth — but not the whole truth. Flock’s platform does not run facial recognition. The Sheriff’s Office, however, bought its own: the county’s own contracts show it purchased Clearview AI — “Clearview Search PRO,” $12,995 per year (plus a $500 setup fee), County Contract #24-0236 — procured through Carahsoft and set to auto-renew. Facial recognition is not something New Hanover might acquire; it is software the Sheriff’s Office already owns. This is not an accusation that any camera image has been run through it. It is about two things that are documented — what that reassurance leaves out, and where the county’s own data is built to travel — and one question the county has not answered: who can pull that data, and what becomes of it once they do.

What “no facial recognition” answers — and what it doesn’t.

A camera captures an image. Facial recognition is separate software that compares a face in one image against a database of other faces to generate possible matches — the FBI, for one, describes its own system as returning ranked candidate leads, not a positive identification. It need not run in the same place as the camera. So “FlockOS does not perform facial recognition” is a true statement about one piece of software. It is not the same statement as “an image from these cameras can never be run through facial recognition” — and that second question turns on something the Sheriff’s assurance does not address: where the captured data goes, and who can pull it. He answered the first. The second is open.

The stronger point: once data leaves Flock, the 30-day deletion goes with it.

This part concerns known system behavior, and Flock’s own words carry most of it. The company calls its APIs “the foundation of any open system” and markets a set of core APIs that let outside systems pull Flock data out — its LPR Search API, for example, lets another platform query a customer’s plate captures by plate, time range, and location. Flock names the platforms it connects to: real-time crime-center software including Fusus (Axon), Motorola’s Command Central, and Genetec, alongside dispatch and evidence-management systems. Access is governed by sign-ins, permissions, and logs. But the stated purpose of the platform is to move data into other systems.

That carries a consequence the county’s assurances do not reach. Flock’s 30-day deletion setting governs data retained in Flock. It does not, by itself, establish when a copy that has been exported into or ingested by another system must be deleted — that depends on the integration, the receiving platform, and the governing agreement. We are not asserting that such copies exist in New Hanover; we are pointing out that the 30-day promise cannot speak for them. And Flock effectively concedes the gap: in the same materials it says data integrity “is eroded when third parties disregard” a community’s democratically set retention rules, and that partners should respect those rules. That is an acknowledgment that once data crosses into another system, its deletion becomes a separate question — one answerable only with documents: the list of enabled integrations, the agencies connected, and the retention terms that govern each. We have asked the county for exactly that.

Is it technically possible? A researcher already showed it is.

The feasibility is not in dispute, and it does not rest on speculation. In December 2025, 404 Media and the technologist Benn Jordan reported that Flock Condor cameras — the pan-tilt-zoom, live-video model — were streaming to the open internet through a misconfiguration, exposing live feeds and archived footage from dozens of devices. From that footage Jordan ran the captured faces through publicly available, open-source tools to identify people on camera. Flock called it a limited misconfiguration on a small number of devices and said it has since been fixed. (A January 2026 follow-up detailed how he found them.)

Read that narrowly, because the narrow reading is the strong one — and because two separate things are true here that must not be blurred. The Jordan case was a security misconfiguration, since patched. It is not evidence that Flock’s API ships face images to partner systems by design, and we do not offer it as that. It proves one thing only: that once anyone holds a captured face, identifying it is an off-the-shelf step that happens outside FlockOS. Whether the everyday, authorized API moves that kind of image is a different question — one we treat separately, and honestly, below. The exposure speaks to feasibility of the downstream step; it says nothing about what New Hanover has done, what Flock’s customers generally do, or what anyone here intends. (We covered what that exposure revealed separately.)

A word about the Condors, and about the Sheriff’s exact wording.

One phrase in the Sheriff’s statement deserves care, because a contradiction is only as good as its precision. He wrote the system is “not a live surveillance system” collecting only “limited” vehicle information. In fairness, he may have meant the plate-reader network — the Falcons, which are what most of the debate concerns, and which do capture only vehicle data. That is a reasonable reading, and we note it.

But the same contract the Sheriff’s Office signed also bought eight Solar Condor cameras: pan-tilt-zoom units that capture live video and can zoom in on people, not only plates. A live-video camera that follows a person is a different device than a fixed plate reader, and it is the kind of image on which downstream recognition works — the same model in Jordan’s demonstration. We are not saying the Condors run facial recognition; by Flock’s account they do not, and we have no evidence otherwise. We are saying three narrower things, each documented: the Condors capture the raw material a recognition tool would need, they are capable of live video rather than “limited” still captures, and the county still will not say where they are. Residents have located a few, including one with a clear line on a children’s soccer field.

Does the county own facial-recognition software? We’ve found no evidence it does.

We want to be precise, because precision is the whole point of this project. No public record we have found shows New Hanover County or its Sheriff’s Office buying or owning facial-recognition software. The Flock system is not it; the Sheriff says so, and on this record we have no reason to doubt that specific claim. If the county has purchased a facial-recognition tool, we have not seen the paper — and we will say so plainly the day we do.

But not owning facial recognition is not the same as being unable to use it. A police agency does not need to own the software to run a face through it. Several technical and institutional routes exist, and some of the infrastructure is already in place locally:

  • Export through the API. As above, Flock’s platform is built to move capture data into other systems — and whether any of those downstream systems run facial recognition is a property of the destination, not of FlockOS.
  • The real-time crime center the city already runs. Wilmington’s STING Center operates on Fusus (Axon), a platform built to integrate third-party tools. The governing directive we obtained through public records neither enables facial recognition nor forbids it — a door left open, not a lock.
  • State and federal systems. An agency can request a facial-recognition search through a partner without buying anything: the NC DMV has run facial-recognition comparisons for law-enforcement agencies, and the FBI’s Next Generation Identification system accepts probe photos from state and local police.
  • A vendor trial. One documented route is a free demo — how Clearview AI reached dozens of North Carolina agencies, often with no purchase order behind it.

The right question, then, is not whether the county owns the software. It is whether any data from these cameras has been run through facial recognition — by anyone, through any route — and whether the county could even tell. We have asked for the records that would answer it.

In fairness: most of this sharing is mundane, and lawful.

The integrations are not sinister in themselves, and it would be unfair to imply they are. Agencies link these systems for ordinary, defensible reasons: a stolen-plate hit routed into dispatch, a missing-person alert pushed to officers in the field, a hot-list match shared among departments working the same case. Most of what moves through a law-enforcement API is metadata, used lawfully, and interoperability genuinely helps the work — that is the case the county would rightly make, and it has weight. Our concern sits one level up from the sharing itself: not that data moves, but that when a copy leaves Flock, no public record yet shows who holds it, how long they keep it, or who audits the exchange. A system can be useful and unaccountable at the same time. The remedy is not to end the cooperation; it is to document and govern it.

What we can say, and what we can’t.

We hold ourselves to the standard we ask of the county, so here is the ledger, plainly. What we cannot say: that any image from New Hanover’s cameras has ever been run through facial-recognition software, that the Sheriff’s Office intends to, or that any local partner — the Wilmington STING Center included — keeps exported Flock data past Flock’s own 30 days. We have no evidence for those; the STING retention question in particular is simply unverified, and it is one of the things our records requests seek. The Benn Jordan case, too, was an exposure Flock says it has closed, not the routine authorized path. What we can say — and now can, from the county’s own contracts: the Sheriff’s Office owns facial-recognition software. It purchased Clearview AI in 2024 — “Clearview Search PRO,” County Contract #24-0236, $12,995 a year, auto-renewing, bought through Carahsoft. Facial recognition is downstream software, not a camera feature; the Flock platform the county bought is built to export its capture data to other systems; and Flock itself says the 30-day rule depends on downstream partners respecting it, so the county’s deletion setting cannot speak for copies that have left Flock. The upshot: the two pieces — a camera that captures a face, and software built to identify one — now sit inside the same Sheriff’s Office. That is why “Flock doesn’t use facial recognition” does not answer the question a resident is actually asking. It is true. It is not the whole truth.

The questions worth asking on August 17.

“Do the cameras use facial recognition?” invites a true and comforting answer. The questions that actually govern the risk are about data, and every one of them is answerable with records rather than adjectives: Which outside systems and agencies can pull New Hanover’s camera data through Flock’s API, and which are connected today? What may each of them keep, and for how long? And who audits whether an exported copy outlives the county’s 30-day promise? We have put those questions to the Sheriff’s Office in a public-records request (No. 26-1244), and the commissioners meet Monday, September 21. The facial-recognition headline is what draws the eye; the data-governance answer is where the record will be made. (How to speak · the records behind all of this.)

New Hanover County’s Commissioners hold the lever that ends Flock here. They need to hear from you.

Sources

Facial-recognition capability described here refers to third-party software applied to images the cameras capture, not to a feature of FlockOS; Flock states its own products do not perform facial recognition. The Benn Jordan / 404 Media findings involved a device misconfiguration Flock says it has remedied. General information and opinion for public discussion, not legal advice. Published August 12, 2026.

Your move

You’re not a suspect. So stop being tracked like one.

It takes one minute. Add your name, then tell your county commissioners to cancel the Flock contract.