top of page

Flock Safety Senate Hearing Exposes a Surveillance Accountability Gap

Sep 25
12 min read

Flock Safety faced bipartisan scrutiny on September 23, despite CEO Garrett Langley declining to appear before senators investigating the company’s nationwide camera network. The Flock Safety Senate hearing turned a privacy controversy into a direct challenge from Washington.

The Senate Judiciary Subcommittee on Crime and Counterterrorism examined automated license plate readers, commonly called ALPRs. These cameras photograph passing vehicles and convert plate numbers and other vehicle details into searchable records.

Flock says this information helps police find stolen cars, missing people, and criminal suspects. Critics see something much larger: a privately operated location network that can follow ordinary drivers across jurisdictions without a warrant.

That conflict is no longer divided neatly by party. Republican subcommittee chair Josh Hawley and Democratic Senator Dick Durbin both called for stronger protections. Their agreement shifted the debate from whether abuses exist to who must prevent them.

What Changed at the Flock Safety Senate Hearing

Flock entered the hearing as a technology vendor, but left it looking like the operator of national surveillance infrastructure.

Hawley convened the hearing under the title “Always Watching: Flock’s Nationwide AI Surveillance Network.” His framing mattered because it rejected the idea that each camera was merely a local police tool.

Flock connects cameras deployed by thousands of customers through software that can make vehicle records searchable across participating agencies. A local installation can therefore contribute to a much broader investigative system.

The September 23 session followed an investigation Hawley opened in August. He demanded documents covering Flock’s collection, retention, use, and distribution of vehicle data.

Hawley then invited Langley and the leaders of Axon, Motorola Solutions, and Verkada to testify. All four declined, according to reporting from the hearing.

The absence created an immediate contrast. Senators heard from people affected by the systems and from policy specialists, but not from executives responsible for building them.

Hawley had previously identified Flock as the standout company in this market. His hearing invitation said the company operated 120,000 AI-powered cameras across the United States.

Flock did not get the opportunity to challenge that characterization from the witness table. Its absence instead allowed critics to define the network, its dangers, and the necessary response.

At the hearing, Hawley argued that searchable collections containing billions of images threaten privacy and the presumption of innocence. Durbin emphasized how current systems differ from older plate readers used for toll collection.

The distinction is important. A toll camera records a vehicle at a known payment point for a narrow purpose. A connected ALPR network supports searches across many locations and agencies.

Senators also confronted a basic legal mismatch. Police can collect observations made on public roads, but aggregated movement histories reveal far more than one roadside sighting.

A search can connect separate appearances and reconstruct patterns. It can indicate where someone works, worships, receives medical care, or spends the night.

The hearing did not produce a new federal law. It did establish that voluntary company rules no longer satisfy lawmakers from either party.

That is the central change. Flock now faces a federal accountability debate, not only scattered objections at city council meetings.

Why Flock Became Washington’s Main Target

Flock’s scale turns mistakes, permissive settings, and weak oversight into risks that can travel far beyond one police department.

ALPR technology predates Flock, and several companies sell cameras or vehicle intelligence services. However, Flock’s rapidly expanding customer network has made it the clearest symbol of the category.

Its system captures a vehicle’s plate, location, and time. Cameras can also record attributes such as color, type, and distinctive features.

Those records become useful when police have a legitimate target. An officer can search for a stolen vehicle or investigate a car connected to a serious crime.

The same architecture creates a different possibility. An authorized user can search a person’s movements for an improper purpose, or assist an agency that lacks direct access.

That risk grows when departments share data. A city may impose strict local rules, yet another connected agency might operate under different policies or laws.

Federal immigration access sharpened this concern. An Associated Press investigation found that Border Patrol once had access to at least 1,600 Flock readers across 22 states.

The Border Patrol investigation also described local agencies conducting searches for federal authorities. Some of those searches occurred in states restricting immigration-related data sharing.

Flock told the AP that it had paused pilot programs with Customs and Border Protection and Homeland Security Investigations. The company did not disclose the volume or precise scope of data involved.

California provided another warning. State law restricts public agencies from sharing ALPR information with federal and out-of-state authorities.

A San Francisco police audit nevertheless found hundreds of improper queries by outside entities. The affected arrangement involved authorized organizations and analysts, rather than an unknown intruder breaking into the platform.

That distinction does not eliminate the concern. It shows how access can produce unlawful outcomes without a conventional cybersecurity breach.

Flock argued that the incident was not caused by a software failure or unauthorized access. The company said authorized users conducted searches later found inconsistent with California requirements.

The San Francisco audit illustrated the accountability gap. Every organization could describe its role as limited, while drivers still faced searches that should not have happened.

Flock has since announced additional restrictions for California. Federal agencies cannot join lookup networks there, and agencies cannot initiate or accept out-of-state sharing.

The company also says California searches related to immigration or reproductive care are automatically blocked. Every search must use a standardized offense category, and sharing-setting changes receive permanent logs.

These California guardrails show that technical limits are possible. They also raise an uncomfortable question about why stronger controls followed public discoveries rather than preceding them.

Flock acknowledged that earlier logging limitations made the cause of some sharing incidents impossible to determine. That admission weakens any claim that audit records alone can resolve every historical dispute.

The company’s response has moved toward greater centralized responsibility. Flock once stressed that customers controlled their data and legal compliance.

It now says technology providers must take a more active role. That shift reflects the pressure Washington applied during the hearing.

The Flock Safety Senate Hearing Exposed a Control Problem

Flock’s core tradeoff is not public safety against privacy alone. It is network utility against enforceable control.

A broad network becomes more valuable to police when officers can search across jurisdictional boundaries. A suspect vehicle rarely stops because it reaches a city limit.

Restricting every department to its own cameras would reduce the system’s reach. Expanding access, however, increases the number of users, policies, and legal regimes affecting each record.

Flock’s customer-control model tries to resolve that tension. Local agencies decide what they collect, retain, and share, while the company supplies access settings and audit tools.

That structure can work only when customers understand their settings and review their users. It also depends on every connected organization following the restrictions attached to another agency’s data.

The California incidents showed the weakness of that assumption. An agency can authorize a partner without anticipating how the partner staffs overnight searches or responds to outside requests.

The national network adds another complication. A search may be technically valid within one department yet unlawful against records collected elsewhere.

Company-enforced rules can reduce those conflicts. Standardized offense codes, federal-sharing switches, blocked terms, and immutable setting logs all add friction and visibility.

Yet product controls remain private governance. Flock can modify them, customers can configure some of them, and lawmakers do not automatically review each change.

That is why Durbin’s call for balance carried more weight than a general privacy statement. He argued that Congress must lead instead of leaving the boundary to vendors and police departments.

Hawley approached the issue from a different political direction. He questioned whether Congress had ever authorized the network that surveillance companies assembled.

Their concerns meet at the same point. A private platform now mediates government access to a detailed record of public movement.

The company does not need to identify every driver by name for the data to matter. Police can connect a plate to registration records and other investigative databases.

Nor does the network need complete nationwide coverage. Repeated observations at strategically placed roads can reveal meaningful travel patterns.

This makes retention rules particularly important. One observation indicates that a vehicle passed one camera, while months of observations can describe a routine.

The hearing’s policy experts proposed competing answers. The American Civil Liberties Union argued for eliminating ALPR surveillance, calling narrower safeguards insufficient.

Chad Marlow, the ACLU’s senior policy counsel, warned that these systems can support immigration enforcement and other forms of tracking. His written testimony urged lawmakers to ban the technology.

Alasdair Whitney of the Institute for Justice offered a less absolute model. He supported warrants for historical location searches, restrictions on real-time access, retention limits, and tighter sharing rules.

Whitney said those protections would still permit urgent searches for stolen cars or missing children. He described a warrant requirement as the minimum protection for historical data.

That disagreement helps define the legislative choices. Congress can ban certain uses, require judicial authorization, limit retention, restrict sharing, or combine those approaches.

Flock would probably prefer enforceable rules that preserve lawful searches. A total ban would challenge its central product rather than merely changing customer workflows.

The company’s latest safeguards could become evidence that regulation is workable. They could also become evidence that voluntary measures arrived only after repeated failures.

A Wrongful Arrest Made the Risk Personal

The strongest testimony was not about abstract data collection. It concerned a woman jailed after investigators relied on a mismatched vehicle image.

Lindsey Isaacs told senators that authorities wrongfully accused her in a fatal Florida hit-and-run investigation. A Flock image of her vehicle contributed to the case against her.

According to hearing coverage, the photographed vehicle was far from the crash scene. Yet investigators treated the image as a significant lead.

Isaacs spent 13 days in jail before her release. Her experience gave senators a concrete example of what can happen when a camera match gains more authority than it deserves.

An ALPR observation is not proof that a registered owner was driving. It is also not proof that visually similar vehicles are identical.

The system records a vehicle at a location and time. Investigators must still validate the plate, examine other evidence, and exclude conflicting facts.

Errors can enter through multiple paths. A plate can be misread, a vehicle description can match many cars, or an officer can overvalue a partial image.

The technology’s role also needs careful framing. Flock did not arrest Isaacs, and a camera record alone did not make the final legal decision.

Police and prosecutors remained responsible for assessing the evidence. That human responsibility does not make the platform irrelevant.

Search tools shape which leads appear first and how investigators understand them. A highly ranked or apparently precise match can create confirmation bias, especially under pressure.

The Isaacs case therefore cuts through a familiar defense. Saying that an officer made the final decision does not answer whether the system encouraged an unreliable inference.

At the Senate hearing, Isaacs appeared alongside privacy advocates rather than company executives. That image reinforced the imbalance senators wanted to highlight.

The case also broadens the issue beyond surveillance. Privacy asks whether the government should possess and search movement data.

Accuracy asks whether a search result describes the correct vehicle. Due process asks what investigators must verify before acting on that result.

These questions require different safeguards. Access controls cannot correct an image mismatch, and better image recognition cannot prevent an improper search.

Departments need policies for each stage. They must govern who can search, which cases justify searches, how long records remain available, and how officers validate results.

Audit logs can reveal who searched and why. They cannot independently prove that the stated reason was honest or that investigators interpreted the result correctly.

Standardized categories improve review, but they can become box-checking exercises. A user can select an accepted offense without documenting the factual basis for a search.

Case numbers add another layer of accountability. Their value depends on supervisors checking whether the referenced case exists and supports the query.

Flock’s public response emphasizes stronger technical controls. Senators are likely to ask whether those controls address wrongful identification as directly as unauthorized sharing.

That question becomes more urgent as AI-based vehicle search expands. Searching by color, body type, damage, accessories, or travel pattern can return candidates without a known plate.

Such tools can help when witnesses provide incomplete information. They can also produce broader pools of innocent vehicles.

Police must treat those results as leads, not conclusions. The Isaacs testimony showed what happens when that distinction collapses.

Flock’s Competitors Cannot Avoid the Same Questions

Flock received most of the attention, but the hearing placed the entire networked surveillance market under notice.

Hawley invited Axon CEO Rick Smith, Motorola Solutions CEO Greg Brown, and Verkada CEO Filip Kaliszan alongside Langley. None appeared.

These companies do not operate identical systems. Their products, network structures, customers, and sharing features differ.

Verkada stressed one important distinction through a spokesperson. The company said customers can access only information held in their own systems because no national Verkada network exists.

That response illustrates why network architecture matters. A locally bounded camera system presents different sharing risks from a searchable multi-agency database.

It does not remove every concern. Local systems can still support unjustified monitoring, excessive retention, or weak internal access controls.

Motorola Solutions has long participated in public-safety technology, while Axon is best known for body cameras and conducted-energy devices. Both increasingly sell connected software and data services.

The hearing therefore reached beyond roadside cameras. Lawmakers were examining how private vendors aggregate, analyze, and mediate access to government-generated records.

Flock remains the focal company because its network creates a vivid national map. Its name has also become shorthand for community fights over roadside cameras.

That visibility brings commercial advantages. A larger network gives customers more possible observations and makes the platform harder to replace.

It also concentrates reputational risk. A misuse by one customer can undermine confidence among cities that never authorized similar conduct.

Competitors can market tighter boundaries as a differentiator. Verkada’s statement about lacking a national network was an early example of that strategy.

Flock can answer by emphasizing safeguards, auditability, and successful investigations. However, claims about effectiveness require independent evidence and consistent measurement.

A stolen vehicle recovery is easy to describe. Measuring whether a camera caused the result, displaced crime, or justified mass collection is harder.

That evidence problem matters for local buyers. Police departments often present compelling individual cases when requesting contracts or renewals.

City councils must also assess false leads, staffing costs, retention, sharing exposure, and legal liability. Those burdens may not appear in a success-story count.

The industry could benefit from common federal rules. Uniform requirements would reduce the patchwork of state restrictions and customer configurations.

However, federal standards could also legitimize broad collection if Congress sets weak limits. A compliance framework is not necessarily a privacy framework.

The most consequential debate will concern warrants. Requiring one for historical movement searches would change the speed and volume of routine queries.

Emergency exceptions could preserve urgent use cases. Legislators would still need to define emergencies narrowly enough to prevent them from becoming the default.

Retention is another dividing line. Shorter storage reduces the depth of searchable history but also limits later investigations.

Sharing rules will determine whether local approval retains meaning. A city cannot promise residents strict limits if partner agencies can route around them.

The competitors’ absence did not remove them from this debate. It postponed the moment when each company must explain its architecture under oath.

What Comes Next for Flock Surveillance

Three signals will show whether the hearing becomes a policy turning point or another temporary burst of scrutiny.

The first signal is compulsory congressional action. Hawley initially requested documents, but lawmakers can escalate through subpoenas, additional hearings, or legislation.

A subpoena for Langley would intensify the conflict. It would force Flock to defend its data practices directly instead of responding through statements and product updates.

A second hearing featuring executives would also expose differences among vendors. Senators could compare retention, network access, audit design, and federal partnerships on the same record.

The second signal is whether Flock’s new controls produce verifiable reductions in misuse. Announcing safeguards is easier than proving they work across thousands of customers.

Audits should show whether prohibited sharing declines, whether administrators review alerts, and whether improper users lose access. Public reporting would make those claims testable.

California will be a critical test. Flock says its platform now automatically prevents federal and out-of-state sharing there.

If later audits find restricted access continuing, the problem will appear structural. If incidents fall sharply, the company can argue that enforceable product controls work.

The third signal is what cities do with renewals and new contracts. Local governments control many purchasing decisions even while Congress considers national rules.

Contract cancellations would show that reputational damage has reached revenue decisions. Renewals with stricter terms would indicate that buyers still value the product but demand limits.

Cities should request access to full audit records before renewing. They should also specify retention periods, permitted search purposes, partner access, and consequences for violations.

Independent reviews matter because vendor and police incentives align around deployment. Both benefit when officials focus on successful investigations rather than systemwide costs.

Flock also needs an answer for the Isaacs case. Better sharing controls do not explain how customers should prevent a vehicle match from driving a wrongful arrest.

The company can require clearer warnings and stronger verification workflows. It can also give supervisors tools to review searches tied to arrests or high-risk decisions.

Lawmakers, meanwhile, must decide which protections belong in statute. Private policies cannot substitute for rights that apply across companies and jurisdictions.

The Flock Safety Senate hearing did not prove that every ALPR search is abusive. It showed that useful investigations and dangerous surveillance use the same underlying infrastructure.

That makes the policy challenge unusually difficult. Weak controls preserve speed but invite misuse, while strict limits can slow legitimate police work.

Congress now has testimony supporting warrants, retention limits, sharing restrictions, and even a complete ban. Flock has responded with safeguards, but their effectiveness remains unsettled.

The next one to three months should reveal whether senators demand executives, cities reconsider contracts, and independent audits validate the new controls.

Readers should watch those outcomes rather than another polished safety announcement. The central question is whether enforceable limits can keep pace with a network already operating nationwide.

Will Congress convert bipartisan concern into binding protections, or will Flock continue writing the most important rules itself? The answer will shape far more than roadside cameras. It will establish how much control private technology companies can exercise over government surveillance infrastructure.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page