The clean version of the pitch is easy to understand from a security desk. Flock Safety launched its Business Network in June 2025 as a private-sector security collaboration product already serving more than 1,000 businesses, including 4 of the NRF Top 10 Retailers, 7 of the 10 largest U.S. malls, and 10 of the 40 largest U.S. health systems.[1] For a distribution center dealing with trailer break-ins, stolen tractors, fraudulent pickups, or repeat vehicle traffic around a yard fence, automatic license plate recognition is not an abstract surveillance debate. It looks like a faster way to know which vehicle just entered the property and whether it belongs there.
Flock’s own logistics example lands exactly where operators feel pain. In an anonymous customer case study, a logistics company says it stopped “8-figure losses” and flagged more than 700 stolen vehicles in two months using Flock’s system.[2] That is the kind of claim that gets a pilot moved from “interesting” to “budgeted.” It is also the kind of claim that should make a buyer slow down, because the case is not a named, independently auditable deployment. The outcome may be real for that customer; the problem is that another company cannot test the facts, the baseline loss rate, the false-hit handling, or the sharing terms behind it.

That is the buying moment behind the privacy-lawsuit risk. A company is not deciding whether cameras are useful. It is deciding whether a private yard-security deployment can be defended after the same vendor’s ALPR network becomes evidence in lawsuits, public-records disputes, immigration-enforcement reporting, and false-stop investigations.
The private network is not isolated from the public controversy
Flock markets the Business Network around private-sector collaboration and permission-controlled partnerships. That matters; a retailer, freight broker, or warehouse operator should not assume every law-enforcement practice automatically applies to every private deployment. But the risk review cannot stop at the product brochure. The value proposition depends on cameras, plate reads, databases, alerts, and the ability to share information across organizational boundaries. Those are the same functional parts now being tested in public disputes.
The uncomfortable question for a supply chain buyer is operational, not philosophical: if a camera installed to protect a trailer yard contributes data to a searchable or shareable ALPR environment, who else can touch that data later, under what authority, and with what notice to the company whose facility generated it?
In May 2025, 404 Media reported that ICE gained access to Flock data through local police “side door” searches.[3] That reporting does not prove that a private company’s Business Network deployment will be used for immigration enforcement. It does show why “we bought this for yard security” may not be enough of a public answer if company-generated vehicle data enters a wider sharing environment. Once a surveillance tool becomes useful to another enforcement workflow, the company that installed the camera can be pulled into a fight it did not design.

Public-records exposure is another place where private assumptions can fail. A Washington judge ruled that Flock camera images purchased with tax dollars are public records subject to FOIA-style requests.[4] That ruling is about public-agency records, not a blanket rule that every private yard image becomes public. Still, it is a warning about shared infrastructure: if a private company’s data is routed into, accessed by, or retained inside a public law-enforcement system, records law may become part of the deployment risk in ways the security team did not price into the project.
The California case turns sharing into a procurement issue
The consolidated California class action, In re Flock Safety ALPR Litigation, No. 3:26-cv-02375, is still early. It should not be treated as a final finding that Flock violated the law. The April 3, 2026 amended complaint alleges that Flock shared California ALPR data out of state without authorization, and related reporting says the San Francisco Police Department database was searched more than 1.6 million times by outside agencies in seven months while Los Altos was searched more than 1 million times.[5][6]
For a supply chain organization, the filing matters less as a courtroom prediction than as a due-diligence checklist. If a company signs a Business Network agreement, it should be able to answer these questions before cameras go live:
- Can the company prevent its plate reads from being searched by law enforcement agencies unless a defined legal process or written approval exists?
- Can it audit every search, alert, export, or shared hotlist match tied to its cameras?
- Can it set a retention period shorter than the vendor default, and can deletion be verified?
- Can it prohibit immigration-enforcement use, out-of-state sharing, or sensitive-location surveillance where state law or company policy requires it?
- Can it suspend sharing without disabling the facility-security function it actually bought?
Those are not paperwork preferences. They determine whether a security director can tell the general counsel, the board, a regulator, or a major customer what happened to vehicle data after the gate camera captured it.
This is the same vendor-risk discipline supply chain teams already need for other AI partnerships. ChainSignal’s related analysis of the Apple-Alibaba AI partnership makes the same larger point in a different setting: an AI tool cannot be evaluated only by what it does on a demo screen. The regulatory context, partner incentives, and data-routing structure are part of the product.
False alerts are not a back-office error
Accuracy risk deserves its own review because ALPR mistakes do not stay inside a dashboard. A false inventory count can create rework. A false stolen-vehicle alert can put a driver, contractor, employee, or customer into a police encounter.
The Los Angeles Police Department Inspector General found that 32.3% of Flock alerts reviewed were inaccurate, including 161 vehicles falsely flagged as stolen over two months.[7] Business Insider separately documented at least a dozen incidents involving armed stops, handcuffings, and police dog attacks after Flock camera misreads.[8] Those are not the same as a controlled benchmark for every deployment, and they do not prove that every Flock camera has the same error rate. They do show the consequence chain a company must plan for before it treats ALPR as ordinary perimeter monitoring.
Older testing by IPVM found an approximately 1-in-10 state misidentification rate in 2021, and Flock says accuracy has improved since then.[8] That older result should not carry the whole case against a current deployment. The fresher LAPD audit and Business Insider incidents are more important because they describe recent operational harm, not just lab-style performance questions.
A warehouse or carrier that deploys ALPR should therefore decide, in writing, what happens before anyone acts on a hit. Who verifies the plate image? Who checks whether the vehicle is actually on the property? Who calls law enforcement? Who tells a driver that a delay resulted from a vendor alert? Who preserves the record if the alert turns out to be wrong? If the answer is “the system sends the alert and the shift supervisor figures it out,” the company has not finished buying the product.
Courts and states are starting to define the boundaries
The Fourth Amendment fight in Norfolk is not a complete map for private facilities, but it is a useful signal. On January 27, 2026, a federal judge ruled that Norfolk’s 176 Flock cameras did not currently violate the Fourth Amendment, while warning that a constitutional “tipping point” could arrive as surveillance networks expand; the case is now on appeal to the Fourth Circuit.[9] A security buyer does not need to become a constitutional lawyer to see the procurement implication: a system that is lawful at one scale, under one fact pattern, may attract a different analysis as coverage, sharing, and retention expand.
Washington has already moved from concern to hard limits. SB 6002, effective March 30, 2026, created a 21-day ALPR data-retention cap, banned immigration-enforcement use, and prohibited cameras near health care facilities, schools, and places of worship.[4] That law does not govern every state or every private deployment. It does show the direction of travel: regulators are no longer treating ALPR as just another camera purchase.
Contract reversals add another warning. Mountain View terminated its Flock contract in February 2026 after discovering that Flock had enabled out-of-state data sharing without the city’s knowledge, and Oshkosh revoked its contract within 24 hours in April 2026 after Flock lied about heat-map capabilities, according to public-sector roundups.[4] Those are municipal examples, not warehouse examples. But vendor trust failures in public deployments can spill into private procurement because the same brand, support model, and governance posture are being evaluated.
What a defensible deployment would require
There is no need to pretend the Business Network has no legitimate use. A freight yard with repeated theft and vehicle fraud has a real security problem, and a well-controlled ALPR deployment may reduce losses. The question is whether the organization can defend the deployment six months later, after a subpoena, public-records request, mistaken stop, customer inquiry, union grievance, journalist call, or state-law change.
| Risk area | Minimum procurement standard |
|---|---|
| Data sharing | Written limits on law-enforcement access, out-of-state searches, immigration-enforcement use, hotlist participation, and third-party sharing. |
| Auditability | Exportable logs showing who searched, received, matched, shared, or deleted data tied to company cameras. |
| Retention | A defined retention period, deletion verification, and a process to adjust retention when state law changes. |
| False alerts | Human verification before escalation, incident documentation, driver-treatment rules, and a correction process for bad reads. |
| Public exposure | Legal review of whether data could become subject to public-records requests once shared with a public agency. |
| Reputation | Board-level or executive signoff on the possibility that the company will be associated with policing, immigration, or civil-liberties disputes. |
The absence of an alleged data breach is important. The current concern is not that Flock has been shown to lose data to hackers; the concern is that authorized or semi-authorized data flows may carry the company into uses it did not intend, cannot easily explain, or cannot unwind. That is a different risk category, and it belongs in legal review before the purchase order is signed.
For a supply chain organization, the practical answer is not a blanket ban. It is a high-risk vendor classification. Flock Safety’s Business Network should be treated as AI surveillance infrastructure, not as a simple camera subscription. Before deployment, the buyer should require legal review, enforceable data-sharing controls, audit rights, retention limits, false-hit escalation procedures, and executive-level reputational signoff. If those controls are unavailable, untestable, or dependent on informal vendor assurances, the security benefit may still be attractive, but the organization is no longer just protecting a yard. It is joining a contested surveillance network.
References
- Flock Launches First-Ever Business Network to Strengthen Private Sector Security Collaboration — Loss Prevention Media
- Flock's own customer case study — Flock Safety
- ICE Taps into Nationwide AI-Enabled Camera Network, Data Shows — 404 Media, May 2025
- MRSC Insight — MRSC, April 2026
- Flock Safety License Plate Reader Cameras Lawsuit – Gibbs Mura — Gibbs Mura
- Class action lawsuit alleges Flock license plate readers violate CA law — KTVU
- LAPD suspends use of Flock surveillance cameras over privacy issues — Los Angeles Times
- Flock Safety's AI Cameras Misread Plates. Innocent People Pay. — Business Insider, March 2026
- A federal judge ruled Norfolk's Flock surveillance cameras don't invade people's privacy – yet — WHRO, January 27, 2026
Comments
Join the discussion with an anonymous comment.