TL;DR: The UK's two Biometrics Commissioners, Prof. William Webster (England and Wales) and Dr. Brian Plastow (Scotland), have published findings warning that police facial recognition is "nowhere near as effective as the police claim it is." Plastow says forces are "marking their own homework" on accuracy. Error rates jump over 9% outside controlled testing environments. Police can lower match thresholds without any judicial oversight. Retail chain Facewatch has documented cases of staff maliciously adding people to watchlists. Essex Police has already paused its deployment. The commissioners are calling for binding legislation, a Biometric Surveillance Act, before more forces roll out systems that do not work as advertised. But deployments keep expanding anyway.
"Marking Their Own Homework"
When police forces in England claim their facial recognition systems are accurate, who checks? The forces themselves.
Dr. Brian Plastow, the Biometrics Commissioner for Scotland, said it plainly: police are "really just marking their own homework" when it comes to accuracy claims [1]. There is no independent auditing body. No mandatory testing standard. No external verification before a force deploys live facial recognition on a city street.
The result is a system where the Metropolitan Police can set a minimum similarity threshold of 0.6 (where 1.0 is a perfect match) and call that accurate enough to stop people on the street. South Wales Police uses 0.64. Essex Police tried a score of 55 on a different scale before pausing its program entirely [1].
Each force picks its own threshold, runs its own tests, and publishes its own results. The National Physical Laboratory recommends a 0.64 threshold, but that recommendation has no legal force. A police commander can lower the threshold to catch more faces, accepting more false matches, without asking a judge, a regulator, or anyone else for permission.
The 9% Problem
Here is what happens when you move facial recognition out of the lab and into the real world: error rates jump over 9% [1].
In controlled settings (good lighting, front-facing subjects, high-resolution cameras) modern facial recognition systems perform well. The vendors' marketing materials are not lying about lab accuracy. But a camera on a police van scanning a crowded high street is not a lab. Angles change. Lighting shifts. Hats, scarves, masks, sunglasses, aging, weight changes: all of it degrades performance.
The Croydon pilot offers a window into what real-world deployment looks like. During the trial, the system generated 19 alerts, which led to 9 arrests and 2 stop-and-question incidents [1]. That means at minimum 8 of the 19 alerts (over 40%) did not result in any police action. Were those false matches, or people the police decided not to pursue for other reasons? The data does not say, because the data is self-reported.
The Patchwork
Prof. William Webster, the Commissioner for England and Wales, described the legal framework governing facial recognition as a situation where "the horse had gone before the cart": technology deployed first, law trailing behind [1].
Right now, police facial recognition in the UK operates under a patchwork of:
- The Data Protection Act 2018
- The Equality Act 2010 (which requires bias assessments the Met never published for its early deployments)
- Common law police powers (stretched to cover a technology Parliament never contemplated)
- Individual force policies that vary from region to region
There is no single statute that says: this is what facial recognition can be used for, this is who oversees it, and this is what happens when it gets it wrong. Former commissioner Fraser Sampson has called for a dedicated Biometric Surveillance Act to replace the patchwork with binding standards [1]. Webster called this a "once-in-a-generation opportunity to get a legal framework right."
That opportunity is being wasted. While the commissioners publish warnings, more forces are deploying.
The Retail Problem
It is not just police. Private companies are running their own facial recognition systems in UK shops, and the guardrails are even weaker.
Facewatch, a facial recognition company used by retailers across the UK, has documented 10-15 cases of shop staff maliciously adding individuals to watchlists [1]. That means a retail worker who does not like the look of you (or has a personal grudge) can flag your face in a system shared across multiple stores. You walk into a different shop, the camera matches your face, and security approaches you before you have touched a product.
Separately, 21 people have reported being wrongfully placed on retail facial recognition watchlists [1]. These are individuals with no shoplifting history, no criminal record, who found themselves flagged and confronted by security because a system (or a staff member) decided they belonged on a list.
There is a dark irony here. Fraser Sampson, the former Biometrics Commissioner who advocated for a Biometric Surveillance Act, is now a non-executive director at Facewatch [1]. The person who warned about the need for regulation went to work for the company that needs regulating.
The Bigger Pattern
Britain's facial recognition expansion is happening alongside similar pushes in the US. Our roundup of US state legislation tracks the patchwork developing on the other side of the Atlantic. Madison Square Garden's use of facial recognition to ban critics and track a trans woman shows what happens when private companies deploy the technology without oversight.
The UK is supposed to be further along on regulation than the US. It has dedicated commissioners. It has a data protection framework inherited from the EU. It has a history of public debate about CCTV that stretches back decades.
And yet the commissioners' own conclusion is that the system is broken: police grade their own accuracy, lower thresholds without oversight, deploy in conditions where error rates spike, and operate under laws that were never designed for biometric surveillance. The patchwork is not a bug. It is the feature that lets deployment keep expanding.
What Comes Next
- Essex Police paused: The force suspended its facial recognition deployment in June, citing the need for further evaluation. Watch whether it resumes, and at what threshold
- The Biometric Surveillance Act: The commissioners want one. Parliament has not scheduled a debate. The longer the delay, the more forces deploy under the patchwork, and the harder it becomes to roll back
- EU AI Act comparison: The EU classifies retrospective facial recognition for law enforcement as high-risk AI, with mandatory compliance requirements kicking in August 2026. The UK, post-Brexit, has no equivalent. The gap between UK and EU standards is about to become measurable
- Retail expansion: Facewatch and similar companies continue signing up shops. Without binding rules on watchlist management, the malicious-addition problem will grow
The UK's own surveillance watchdogs are saying the technology does not work as claimed, the law does not cover it, and the oversight does not exist. The response from police forces and retailers: deploy faster.
Sources
Published: May 6, 2026