Flock under pressure: how America’s largest LPR network became a test case for connected surveillance

August 25, 2026

In just a few years, Flock Safety has built one of the largest connected automatic licence plate recognition networks in the United States. Police departments use the platform to search for vehicles across jurisdictional boundaries and accelerate investigations. But disputed data access, legal challenges over warrant requirements and criticism from civil liberties organisations have pushed a more fundamental question to the fore: how much control do public authorities retain once local cameras become part of a nationwide surveillance infrastructure?

Flock Safety is no longer simply a manufacturer of automatic licence plate recognition cameras. According to the company, its network now comprises more than 120,000 cameras across 49 US states and over 6,000 communities. The systems record licence plates, time, location and additional vehicle characteristics. Their real value, however, comes from connectivity: depending on permissions and data-sharing arrangements, law enforcement agencies can search vehicle records beyond municipal and state boundaries.

That network effect is also at the centre of the controversy surrounding Flock. The company stresses that customers retain ownership of their data and determine who may access it. A series of incidents, however, has demonstrated how complicated that control can become once thousands of cameras and agencies are connected through a common platform.

One of the clearest examples emerged in Illinois in 2025. State law restricts the use of automatic licence plate reader data for certain out-of-state abortion and immigration investigations. Nevertheless, a police department in Texas was able to access data originating in Illinois during an abortion-related investigation. The Illinois Secretary of State’s office described the access as unlawful and demanded restrictions.

A subsequent review by the Mount Prospect Police Department found that Flock’s activated “National Lookup” function had enabled searches by other agencies. The local police department later said it had not fully understood the reach of the feature.

The episode illustrates a wider problem in connected security architectures. Formal data ownership is only one part of the equation. Equally important is who can technically access the information, under which rules, and whether restrictions on purpose and use are actually enforced within the platform itself.

Transparency and control come under scrutiny

Flock’s communication with public authorities and the wider public has also faced criticism. In 2025, CEO Garrett Langley acknowledged that the company had not communicated sufficiently clearly about pilot projects involving US Customs and Border Protection and Homeland Security Investigations. “We clearly communicated poorly,” Langley said. Flock subsequently paused the relevant pilots and announced measures intended to separate access rights more clearly.

The American Civil Liberties Union has also accused the company of providing inaccurate or misleading descriptions of certain system capabilities to municipalities. In Oshkosh, Wisconsin, a dispute over whether Flock’s technology could display the movements of a vehicle in the form of a heat map contributed to renewed political scrutiny. The city council later withdrew its earlier approval for the project.

Flock rejects the characterisation of its platform as an uncontrolled surveillance system and points to audit logs and individual user accounts as safeguards. Searches can, according to the company, be attributed to specific users and reviewed retrospectively.

That position reveals one of the central dividing lines in the debate. Flock emphasises accountability after a search has taken place. Some civil liberties organisations argue instead that certain database searches should require independent authorisation before access is granted.

The Institute for Justice is pursuing litigation that seeks to clarify when aggregated collection and searching of vehicle movements constitutes a search under the Fourth Amendment and should therefore require a warrant. Flock, for its part, points to court decisions in which the use of fixed licence plate readers has not been found inherently unconstitutional. The legal position in the United States therefore remains contested rather than settled.

Flock tightens its safeguards

Growing political and legal pressure has already led to changes in the platform. In August 2026, Flock announced that the standard retention period for licence plate data would be reduced from 30 days to seven days. A separate “Evidence Mode” is intended to allow selected data to be preserved for longer where it is required for an active investigation.

The company also plans to make its “Audit Assistance” system mandatory for law enforcement customers. The tool is designed to identify unusual search behaviour and alert administrators to potential misuse. By the end of 2026, Flock also intends to require case codes or case numbers for database searches as a general rule. Automated restrictions in response to suspicious user behaviour are also planned.

These changes show how the terms of the debate have shifted. Connected licence plate recognition can no longer be assessed solely by recognition rates, image quality or investigative speed. Data retention, access rights, cross-agency sharing and auditability are becoming equally important performance criteria.

For Europe, the US debate is relevant even though the legal and data protection frameworks are fundamentally different. As licence plate recognition, video surveillance, cloud platforms and AI-based analytics become increasingly interconnected, European public authorities face a similar architectural question: can institutional oversight and legal control scale at the same pace as the technology itself?

The Flock case demonstrates the tension clearly. The operational value of a security network increases with the number of connected sensors, databases and participating agencies. But so do the potential consequences of misconfigured permissions, unclear sharing rules or abusive access.

For the next generation of public security systems, the decisive measure may therefore no longer be only how reliably a platform recognises a vehicle or identifies an event. It will also be whether control over the resulting data grows as effectively as the ability to collect, connect and analyse it.

From 5 September 2026, EURO SECURITY will publish an extended feature on the Flock controversy in the DACH 8/9-2026 edition.

Related Articles

Editor’s note: Organised crime has become a service industry

Operation Jackal IV is significant not simply because of the number of arrests it produced, but because of what it reveals about the structure of contemporary organised crime. Technical infrastructure, social engineering and money laundering are increasingly...

Interpol operation targets West African organised crime networks

Fifty-eight arrests, 263 identified suspects and investigations spanning six continents: Interpol’s Operation Jackal IV has targeted West African organised crime networks involved in financial fraud, money laundering and Crime-as-a-Service. The cases illustrate how...

dm integrates Wero into German online shop

dm integrates Wero into German online shop

German drugstore chain dm is among the first major retailers in the country to introduce the European payment solution Wero in e-commerce. Payments are processed directly between bank accounts via SEPA Instant Credit Transfers, without the need for a credit card. The...

Share This