In some ways, automated license plate readers (ALPRs) like Flock and similar technology-driven surveillance tools are nothing new.
We know that our phones and apps generate extensive location data. We know there are cameras on most busy city corners. We know that social-media companies retain enormous amounts of personal data about our political leanings, the items we buy, and our browsing habits.
Privacy advocates have been sounding alarm bells about all of this for years, usually with little traction in the form of sustained public outcry.
So why has Flock touched such a nerve?
One possibility is that Flock is simply the culmination of incremental advances in privacy-piercing police technology that happened to catch a disgruntled public at the right time. But it seems more likely that there is something demonstrably creepier about Flock.
A police officer sitting on the side of a public road can see your car, read your license plate, and write down the time you passed. Generally speaking, none of that is considered a Fourth Amendment “search.” You exposed the car and its legally required license plate to public view.
Flock takes that ordinary observation and transforms it into persistent, searchable, networked memory. Its cameras attempt to photograph every passing vehicle. The system reads plates and records other visible characteristics, including make, type, color, roof racks, bumper stickers, and other distinguishing features. Those observations are uploaded into a database that cops can search retrospectively and can connect easily with other information like criminal records and video sources. And this information is often shared across jurisdictions.
But the public reaction also seems driven by factors beyond just the capabilities of Flock.
The public is starting to realize that advances in AI and machine learning make it possible to analyze and correlate far more data than any human police department could realistically process on its own. We all reasonably expect that Flock data will eventually be fed into a machine that also includes data from sources like our cell phone location records, our payment data, and our browsing history, and that machine will come to conclusions about our potential criminal behavior.
The reaction may be different if we were confident that combining mass surveillance with AI would produce flawless policing, or even just policing free from the abuses already present in our system. But the public is being asked to trust that the technology will reliably identify the right person, and that the authorities wielding it will use it responsibly. When AI sold to us as the “future” is improperly labeling Kentucky on a map or inventing elements on the periodic table, and police armed with Flock identify the incorrect Dodge Durango involved in a murder investigation, skepticism about both sides of that trust equation is hardly surprising
Another potential factor in the public response is that Flock is not simply the outgrowth of police developing a new surveillance tool or adapting some ordinary consumer technology to an investigative purpose. It is a private company explicitly building surveillance infrastructure for police departments. In doing so, it inevitably plays a role in policy decisions about how the system operates: how long data is retained, who receives access, what training is required, which searches are permitted, and how agencies share information. Moreover, because Flock serves thousands of agencies, it can enable information sharing across jurisdictions in a way that seems to turn local police departments into participants in something resembling a quasi-national surveillance effort.
Which of these factors triggered the current reaction is hard to parse. But we have reached a moment when many people are saying that the government (with the assistance of a private company) has gone too far in prying into our everyday movements. And when that happens in the United States, the natural next question is whether some constitutional principle protects us from that overreach.
Fourth Amendment implications
My old law professor, Orin Kerr, recently raised the question of whether Flock cameras implicate a Fourth Amendment “search” such that some level of constitutional protection may apply.
Taking one picture of a publicly visible license plate is almost certainly not a search under existing law. But “using Flock” can describe several different government actions:
Photographing and recording every passing vehicle.
Retaining those observations in a database for future queries.
Receiving a real-time alert about a vehicle on a hotlist.
Searching the entire database for an unknown vehicle matching a description.
Reconstructing movements using data from multiple jurisdictions.
Those actions may not all have the same constitutional answer.
I will save a comprehensive Fourth Amendment analysis for another post. But I am inclined to view ALPR networks differently from a cop photographing a car leaving a suspected drug deal or hit-and-run. I approach the question through the broader policy lens that I bring to much of my work: how do we create an environment that respects the same constitutional principles in the digital world that we have historically protected in the physical world?
Perhaps today, we can see sufficient similarities between Flock and the cop with a camera. But is that analogy still apt when there are cameras on every corner, limitless retention, facial recognition, AI-enhanced searches, universal sharing across jurisdictions, and integrations with equivalent systems analyzing every piece of data we produce online? The beginnings of such integrations have already been teased in code uncovered by Wired. As we continue down that path, it is hard for me to imagine that we see no role for the Fourth Amendment in preserving some amount of privacy and protecting us against mass surveillance in public spaces. The Supreme Court seemingly agrees based on its recent decisions in Carpenter and Chatrie but there is still considerable debate about the breadth of those decisions.
Flock also leaves us with no meaningful way to avoid surveillance absent legal protections. We can conceivably turn off location tracking, leave a phone at home, use encrypted messaging, or decline to use a particular service. But we are legally required to display license plates, and driving is practically indispensable for millions of people. Privacy therefore cannot realistically depend on individual technological self-defense.
An important warning
Earlier this year, a federal district court rejected a challenge to Norfolk, Virginia’s Flock system in Schmidt v. City of Norfolk. The court found that Norfolk’s 176 cameras, arranged in 75 clusters, did not capture anything close to the whole of a person’s movements in a manner that would implicate the Fourth Amendment.
However, the court cautioned that its holding “should not be indiscriminately extended because, as the number and capabilities of ALPR cameras expand, the constitutional balancing could conceivably tip the other way.”
This is an astute observation as the case proceeds on appeal, and there is a cautionary lesson here from the Bank Secrecy Act. Early in its lifespan, the Supreme Court rejected a constitutional challenge to the BSA’s comparatively limited scope. This helped create a premise that later, dramatically expanded versions of the financial-surveillance regime must also be constitutional. We have argued how the current version and application of the BSA tests constitutional boundaries but there is still little appetite for that argument. My worry is that we may fall prey to the same assumptions with early cases about ALPR systems. - Jason
What else we’re reading
China Wants to Shape What the World’s A.I. Knows - The Chinese government is working to export AI training data that reflects its worldview.
U.S. Investigated Left-Leaning Groups During Minnesota Immigration Crackdown - This is of particular interest to us because it involves an apparently political search of the targeted groups’ financial records as an inquiry into “domestic terrorist financing.”
Countries are hiding censorship in ‘cybercrime’ bills. A UN treaty could make things worse.













