Split image: left shows a police officer with a laptop in a red filter, right shows silhouettes of people with digital ove...

Flock’s New AI Search Tools Let Police Hunt for People by Description, Not Just Plates

Flock AI search tools now let police find people by description, but reviews show warnings may log misuse without stopping it.

Updated September 3, 2026 1:54 pm

In short

Flock’s AI police-search tools now include its long-running FreeForm person search, while new reporting shows some safeguards can still be left off for now and that flagged queries send detailed audit data back to Flock.

  • Flock’s search tools now support person-based queries, expanding police surveillance beyond license plates.
  • WIRED found the company’s moderation layer can warn or block searches, but warnings can be overridden.
  • The system logs flagged queries and officer responses, but many details of the server-side controls remain opaque.
  • Civil liberties experts say the safeguards may record misuse more than they prevent it.
  • The controversy comes amid broader backlash, canceled contracts, and allegations of police stalking and improper data access.

Update — September 3, 2026 1:54 pm

WIRED’s latest review adds that Flock’s plain-language person search is sold as “FreeForm” and has been in use for years. On video cameras, the company says it can search for clothing, colors, objects, and other case-related details; on license-plate cameras, person characteristics cannot be searched at all.

The report also says departments can still configure some searches without a reason, case number, or automated misuse-detection system for now, though Flock says those controls will be mandatory by the end of the year. WIRED found that search activity is logged, but Flock would not say whether server-side safeguards would actually stop a search submitted without those required fields.

The new piece further notes that Flock’s moderation records not only the query, but also the category, confidence score, and the officer’s response to a warning, sending those details back to the company’s servers. Flock did not explain how long those records are kept or whether they are used to refine the system.

Flock Safety has expanded the AI search tools in its police surveillance platform so officers can look for people by written description, not only for vehicles or license plates, raising new concerns about accuracy, free expression, and abuse. The changes matter because they sit inside a system already tied to dozens of allegations of police misuse and stalking, and because the company’s new safeguards appear to warn about risky searches more often than they stop them.

WIRED reviewed code from the platform, built a mockup of the officer interface, and found that the software can filter, flag, or permit search terms before those queries are sent through Flock’s server-side AI moderation layer. The result is a system that tries to govern police use of sensitive search prompts, while still leaving officers able to proceed past many warnings with a click.

Flock Safety, the fast-growing maker of networked security cameras and automated license plate readers, has become one of the country’s most controversial surveillance vendors. Its latest search tools show how far that debate has moved beyond plates and toward a bigger question: what happens when police can ask an AI system to find a person across thousands of cameras by describing clothing, behavior, tattoos, or other visible traits?

What Flock’s new search tools do

Flock’s platform now gives officers multiple ways to search surveillance footage. Some searches are familiar, like looking up a license plate or narrowing a vehicle by color, make, and model. Others are more expansive, using plain language to hunt for people or objects seen by cameras across a city, county, or wider network.

In the person-search mode highlighted by WIRED’s analysis, an officer can type a short description such as “person wearing scrubs” and ask the system to return footage that appears to match. That search is then processed by a model on Flock’s servers, which decides whether the query is allowed, blocked, or simply warned about before the officer can continue.

The company also offers a watchlist-style feature that lets an officer draw a boundary on a map and tell the system to continuously scan cameras in that area for anyone fitting a written description. Separately, a People Detection Alert can watch for a person inside a single camera frame and trigger when the system believes a human is present.

How the AI search works

The system combines language understanding with visual ranking. A text prompt is converted into numerical data, and each image in the camera network is also represented numerically. The model compares the two sets of data and orders the footage it believes is most relevant. Officers then review the results, and a “smart sort” feature can let them reshape the ranking by approving or rejecting some of the images returned.

That means the interface is not just a search box. It is a guided workflow that lets police refine results, steer the ranking, and expand or narrow the search path using software decisions that ordinary users cannot fully see.

Feature What it does Key limitation or risk
FreeForm person search Lets officers search for people using natural-language descriptions Can be imprecise and may return incorrect or incomplete results
Vehicle search Filters cars by attributes like color, make, body type, and accessories Still depends on how the model interprets the query and footage
Watchlist area search Scans cameras inside a drawn map boundary for described people Can trigger repeated alerts and widen surveillance over an entire area
People Detection Alert Flags when the system sees a person inside a camera’s view Requires at least 75% certainty that the camera is seeing a person
Smart Sort Uses officer votes to reorder the search results Can amplify whatever the user selects, even if the search is flawed

Why the new safeguards matter

The latest version of Flock’s search tools arrives after a year of intense scrutiny. Police departments around the United States have canceled contracts, some city councils have reversed earlier approvals, and lawmakers have pressed the company after reports of controversial searches and misuse.

Among the incidents that drew public attention was a case in Texas in which a deputy reportedly searched more than 83,000 cameras while looking for a woman who had had an abortion. Illinois also found that Flock had allowed federal immigration agents access to state camera data in a way that violated state law.

In response, Flock announced a package of changes in August. Those updates shorten the default data-retention window, require case codes for searches, and add automated auditing to detect suspicious use. Flock says those protections will be mandatory by the end of the year.

But WIRED’s review of code and interface behavior suggests the safeguards do not work as hard as the company’s marketing might imply. The controls can discourage misuse and create a record of it, but they do not necessarily stop a determined officer from pressing ahead.

What happens when a search is flagged?

When the moderation system spots a sensitive query, it can issue one of three outcomes: allow, warn, or block. A block prevents the search. A warning, however, can still be overridden after the officer acknowledges the message and adds a comment.

That matters because the tool stores not only the search language but also the category assigned by the model and the confidence score behind the decision. Some of that information is visible to the company, not to the department using the tool, since the model runs on Flock’s servers.

Flock says its search tools are designed to help police find relevant information while maintaining safeguards on use, but the company did not explain how its model is trained, how it is instructed, or what distinguishes one warning from another.

Flock also says officers are responsible for any inaccuracies in the results. The company’s own warnings acknowledge that results may be incomplete or wrong, but the burden still lands on the person running the search.

How Flock’s AI moderation decides what police can search for

Flock’s moderation layer examines the wording of an officer’s query and compares it against a set of sensitive categories before the search is allowed to proceed. WIRED’s analysis found that the system considers eight broad groups of content, including race or ethnicity, religion, nationality, offensive content, and subjective or biased terms.

Some categories lead to an immediate block. Others trigger a warning. One category—political, social, and cultural expression—appears to generate only a warning, which means the officer can continue if they choose to click through.

That distinction is now at the center of the criticism. Flock’s moderation is aimed at stopping certain searches that could be discriminatory or improper, but the company appears more willing to let officers override a warning than to truly prevent a query from being run.

Which search terms are blocked or warned?

The most restrictive categories include race or ethnicity, religion, nationality, offensive language, and other explicitly sensitive content. The system also blocks many person-related terms in vehicle mode, including references to gender, clothing, and behavior.

By contrast, political and cultural expression is treated more lightly. A description involving a protest, slogan, shirt, badge, or emblem may raise a warning, but the officer can proceed after confirming the search and documenting a reason.

That design choice has drawn particular criticism from free-speech and surveillance experts, who say the First Amendment often gives the strongest protection to political expression.

Tom Bowman of the Center for Democracy and Technology said political and cultural expression is among the most protected categories under the First Amendment and questioned why Flock’s system appears least restrictive in that area.

Why experts say the system is easy to misuse

Experts who study content moderation and automated screening say Flock has asked its AI to do a job that no system performs reliably at this scale: decide which person descriptions should be allowed across a huge surveillance network. They warn that the system’s performance cannot be independently measured because the company controls the model, the server-side logic, and the underlying results.

That opacity matters because even a small error rate can create serious consequences in law enforcement. If the model wrongly permits a harmful search, the tool may turn into a vehicle for discrimination, retaliation, or stalking. If it wrongly blocks a legitimate search, police may claim they were hampered in an investigation. In both cases, outside observers cannot tell how often the system errs or which groups are affected most.

Kate Ruane of the Center for Democracy and Technology said the category Flock leaves as a warning rather than a block is particularly troubling because it can still be bypassed. In her view, an officer who is determined to keep searching can simply acknowledge the warning and continue.

Ruane argued that no large-scale moderation system is perfectly accurate, and that video analysis is even harder than text moderation because moving images add more room for error.

Deepak Kumar, who studies trust and safety systems at the University of California San Diego, said warnings can be useful for logging and oversight, but they are only as effective as the humans reviewing them. In his view, a warning often functions more like a paper trail than a true deterrent.

Jay Stanley of the ACLU said the moderation layer looks like a narrow fix placed atop a much larger surveillance apparatus. In his view, the main problem is not just a few bad searches, but the existence of a system that allows broad fishing expeditions across massive databases.

What the interface reveals about police surveillance power

Flock’s software does more than search by description. It can track plates, infer associations between vehicles, scan shared camera networks, and extend searches across local, statewide, and sometimes nationwide systems depending on agency permissions and agreements.

That means a single query may reach far beyond the officer’s own department. A search can run against the agency’s cameras, cameras shared by partners, or large regional and national plate-reader networks. The practical reach depends on local policy, technical permissions, and interagency agreements.

In many cases, the officer is not looking at a static database. They are asking a live surveillance layer to assemble a trail across time and space from every camera it has access to.

How far can a search go?

That depends on the mode, the agency’s settings, and the access permissions tied to the network. A local department might only search its own cameras, while a larger network can extend the same query across partner systems and broad plate-reader infrastructure.

For people searches, the scope can be especially sensitive because the system is not just finding a vehicle; it is attempting to infer who a person is from a limited visual description. That makes the questions of accuracy, fairness, and misuse much harder to dismiss.

How officer abuse shaped the public backlash

Flock’s controversy did not emerge in a vacuum. Across the United States, officers have repeatedly been accused of using law-enforcement databases to monitor ex-partners, romantic interests, relatives, and other people with no clear policing purpose.

Recent reporting has identified at least 50 officers who have been charged with or accused of misusing automated license plate readers, with 46 of those cases tied to Flock. In more than half of the cited cases, the target was a romantic partner, ex-partner, family member, or woman the officer wanted to meet.

Those cases echo a much older pattern. A 2016 Associated Press investigation documented officers abusing databases for personal reasons, with hundreds of suspensions, firings, and forced resignations across agencies. More recent reporting has shown similar misuse inside immigration and border enforcement databases, where staff members allegedly searched for dates, relatives, and colleagues.

The recurring pattern is what makes Flock’s new features so controversial. When the tool allows natural-language searches for people, critics worry it lowers the barrier to the same abuses that already plagued older systems—only now at much larger scale and with less public visibility.

What Flock says and what it did not answer

Flock responded to WIRED’s findings with a written statement saying its tools are meant to help police locate relevant information while maintaining clear safeguards around use. The company says queries are checked against its content policies and that searches using prohibited attributes will be blocked.

But the statement left many important questions unresolved. Flock did not explain how its model was trained, what prompts or rules guide its decisions, how long flagged-search records are stored, who can review them, or whether those records are used to improve the moderation system.

That silence matters because the moderation layer is not just a warning screen. It is a data pipeline. When a query is flagged, the company can receive the language used by the officer, the category assigned by the model, the confidence score, and the officer’s response to the warning. That creates an internal record of both the search attempt and the way the human operator behaved afterward.

What remains unclear

  • How Flock built the moderation model.
  • Which internal staff can access flagged search data.
  • How long those records are kept.
  • Whether the data are used to retrain or evaluate the system.
  • Whether server-side rules can block searches even if the interface only warns.

Those unanswered questions are important because some of the strongest protections appear to exist only at the interface level, while the real enforcement may depend on hidden server-side logic the public cannot inspect.

Who is responsible for policing the police tool?

Flock says local agencies are responsible for setting the rules that govern how its system is used. That position is not unusual for surveillance vendors, and former police leaders say departments do need to define the legal and operational boundaries before they deploy the technology.

Don De Lucca, a former Miami Beach police chief and past president of the International Association of Chiefs of Police, said vendors can recommend protections, but the department ultimately has to tie the system to a legal reason for use.

That is the core dilemma: a vendor can add restrictions, a department can set policy, and an administrator can review logs, but none of that fully prevents misuse when a powerful search tool is already in the hands of someone with access and motive.

Some law-enforcement officials argue that any technology can be abused and that the answer is stronger oversight, not bans. Critics counter that the scale and opacity of this system make oversight too weak to serve as a real safeguard.

Why this debate extends beyond one company

Flock is not the only company building AI tools for policing, but it is among the most visible examples of how machine learning is now being folded into everyday surveillance. The company’s search interface shows how AI is changing the practical meaning of police access: no longer just retrieving known plates or explicit identifiers, but generating searches from vague descriptions and making judgments about which prompts are too sensitive to permit.

That shift raises broader policy questions for cities, state lawmakers, and federal regulators. If police can search for people by clothing, social symbolism, or location-based descriptions, the line between investigative policing and general surveillance becomes harder to see. If warnings are easy to bypass, then moderation may amount to documentation rather than prevention. If the model’s decisions are proprietary and unmeasurable, public accountability becomes almost impossible.

It also raises a civil-liberties question that cannot be solved by interface design alone: whether police should be able to ask an AI system to identify people across a network of cameras based on open-ended descriptions in the first place.

What comes next for Flock and its customers

Flock says its mandatory changes will be in place by the end of the year, but the company’s own code and user interface appear to leave room for officers to keep using the tool in ways critics believe are risky. The real test will be whether departments adopt stricter policies, whether administrators actually review flagged searches, and whether the company’s promised controls work the same way on its servers as they do in its public explanations.

For now, Flock’s search system sits at the intersection of police work, AI moderation, and surveillance law. It is a product meant to help officers find relevant evidence faster. It is also a reminder that the faster search becomes, the easier it may be to search for the wrong person, for the wrong reason, and at a scale that is hard to audit after the fact.

That is why the latest changes matter so much. They are not just product updates. They are an attempt to answer a growing public suspicion that the tools used to find suspects can just as easily be used to watch everyone else.

Timeline of the controversy

Date Event Why it matters
2016 AP reports widespread police misuse of official databases Shows the long history of officers using tools for personal tracking
2023 Reporting finds misuse inside ICE and CBP systems Demonstrates that large surveillance systems remain vulnerable
July 2026 Reports emerge that officers are using Flock FreeForm searches for people Signals expansion from vehicle tracking to person-based searches
August 2026 Flock announces new safeguards and auditing features Company response to criticism and legal scrutiny
September 2026 WIRED analyzes code and interface behavior Finds warnings may log misuse without stopping it

The deeper issue is not simply whether one vendor has added the right warning label. It is whether police surveillance systems that can search for people by description should exist with so little transparency, so much discretion, and so few meaningful barriers when that discretion is abused.

Frequently asked questions

What is Flock’s AI search tool for police?

Flock’s AI search tool is a surveillance feature that lets police query camera networks using license plates, vehicle traits, and, in some modes, plain-language descriptions of people or objects. It is designed to help officers find relevant footage faster across large camera networks.

Can police search for people with Flock’s system?

Yes. Flock’s FreeForm search allows officers to type descriptions such as clothing or other visible traits and search for matching footage. The company says some person-related searches are restricted in certain camera modes, but the interface still supports people-focused queries in others.

Do Flock’s safeguards stop abusive searches?

Not always. WIRED’s analysis found that some searches are blocked, while others generate warnings that officers can override by acknowledging the alert and adding a comment. Experts say that makes the system better at logging misuse than preventing it.

Why are privacy advocates worried about Flock?

Privacy advocates worry because the tool can search huge camera networks using vague descriptions, and the model’s decisions are largely hidden from public scrutiny. They say this creates a risk of discriminatory searches, retaliation, and stalking, especially when warnings are easy to click through.

What has Flock said in response?

Flock says its search tools are meant to help police find information while maintaining safeguards, and it says prohibited terms will be blocked. The company has not fully explained how its model is built, how it decides between warnings and blocks, or how flagged-search data are stored.

Share this 🚀