
Flock Safety is defending its surveillance business as criticism intensifies over police misuse, broad access to vehicle-location data, and the company’s role in expanding automated monitoring across the United States. CEO Garrett Langley has called for a “compromise” between public safety and privacy while the company makes several controls mandatory rather than optional.
The changes affect searches across Flock’s network of license plate readers, which MIT Technology Review reported includes roughly 120,000 cameras. Officers must now enter a criminal case number before searching, and Flock is requiring an automated auditing system intended to flag suspicious activity. The company has also recommended reducing default data retention from 30 days to seven.
Those measures arrive as elected officials, civil liberties groups, and local communities question whether Flock’s safeguards can prevent abuse at the scale its network enables. The debate matters beyond one surveillance vendor: it is testing how public agencies should govern searchable location data, automated monitoring, and police access to privately operated infrastructure.
Flock announced the policy changes in response to a backlash that has included allegations of officers using its tools to stalk current or former romantic partners. A Washington Post investigation identified 46 cases in which officers were accused of unauthorized use, according to both TechCrunch and MIT Technology Review.
The company had previously offered case-number entry and automated auditing as options. Under the new rules, both are required. Flock says the case number is intended to establish a legitimate investigative purpose, while the auditing feature analyzes search behavior and alerts administrators to activity it considers suspicious.
The controls are not fully independent checks. MIT Technology Review reported that Flock will not verify whether submitted case numbers are genuine. Agencies and officers may therefore still be able to enter meaningless or generic information. The publication also cited earlier findings from the American Civil Liberties Union, which found officers entering vague explanations or mocking search prompts when similar requirements were in place.
Flock’s retention change is also a recommendation rather than an absolute limit. Agencies can override the seven-day default, including through an “Evidence Mode” setting that permits longer storage. Departments can additionally restrict searches by other agencies to specified purposes, such as kidnapping investigations rather than immigration enforcement. That protection still relies on users accurately stating why they are searching.
Langley has acknowledged that victims of alleged misuse were harmed. After hearing from one alleged victim, he told CBS News, “I apologize. It kills me that she went through that.” He has nevertheless argued that Flock did not create police abuse, saying the company built tools that make such conduct visible.
In a Fox News interview cited by TechCrunch, Langley said the country should seek a balance between privacy and safety rather than prioritize only one. He also argued that insufficient regulation and accountability affect Flock and other technologies, and has called for states to make illegal use of Flock data a criminal offense.
Flock’s explanation for lost customers is disputed. Langley told MIT Technology Review that misinformation was the main reason the company had lost business, including mistaken beliefs that Flock performs facial recognition or sells collected data to commercial buyers. Critics, including the ACLU, have challenged the company’s public descriptions of its capabilities and policies.
The strongest claims about the new auditing system remain unverified externally. Flock has not publicly provided accuracy figures for the tool or opened it to independent evaluators, according to MIT Technology Review. That leaves agencies, researchers, and the public without a clear basis for judging how often suspicious searches are detected or how many false positives the system produces.
Opposition to Flock is no longer confined to civil liberties organizations. TechCrunch reported criticism from Democratic politicians, including Vermont Senator Bernie Sanders and Michigan Senate candidate Abdul El-Sayed. On the other side of the political spectrum, three House Republicans introduced legislation that would prevent the federal government from purchasing automated surveillance systems using facial recognition, biometric identification, or license plate recognition, including Flock cameras.
MIT Technology Review reported that some cities have dropped Flock contracts amid protests. NPR found at least 30 cities had ended contracts during the prior year, while the activist group DeFlock reported a higher figure. Flock has said cancellations represent a small share of the roughly 5,000 agencies it counts as customers, but the exact scale of contract losses remains difficult to establish.
Some jurisdictions are considering or passing restrictions on license plate readers altogether. Others are shifting to competing providers such as Axon and Motorola. The movement puts pressure on Flock to show that its changes can protect residents without making the system too difficult for police departments to use.
For the ACLU, however, individual incidents are only part of the issue. Chad Marlow, a senior policy counsel at the organization, told MIT Technology Review that the deeper concern is the sheer volume of location information available for investigation without a warrant or an established suspicion of wrongdoing. In that view, better auditing may reduce abuse without addressing the underlying scale of surveillance.
Flock’s response illustrates a recurring governance problem for AI-enabled and automated public-sector systems: a safeguard that exists as an option may have little practical effect if agencies can decline to use it. Making case numbers and auditing mandatory is a meaningful operational change, but the value depends on verification, enforcement, and transparent measurement.
For enterprise and government buyers, the controversy highlights questions that should be settled before deployment. Who can search the data? What evidence must justify a query? How long is information retained? Can another agency access it, and for what purpose? Who reviews alerts from automated monitoring, and what happens when an administrator ignores them?
Builders face a related design challenge. Flock’s system is not simply a camera product; it is a searchable network whose risk increases as more agencies contribute data and gain access to it. A technical control that works within one department may be inadequate when information crosses jurisdictional boundaries. Product teams developing AI agents, search systems, or public-sector analytics tools should treat auditability and access boundaries as core product requirements rather than optional compliance features.
The dispute also shows why vendor assurances are unlikely to settle public concerns on their own. Independent testing of automated auditing, public reporting of misuse incidents, and clear retention and access logs would give agencies and residents stronger evidence than internal claims. Without those disclosures, Flock’s policy changes may be judged mainly by their stated intent rather than measurable outcomes.
The next test will be whether Flock publishes evidence that its automated auditing catches improper searches reliably. Independent evaluation, rather than company-reported performance, would help determine whether the mandatory system is a substantive control or mainly a procedural one.
Local contract decisions will provide another signal. Cities that are considering renewal, cancellation, or a switch to Axon or Motorola may weigh not only crime-fighting claims but also whether Flock’s retention, cross-agency access, and enforcement rules satisfy local requirements.
Lawmakers’ next steps will also matter. Federal legislation targeting automated surveillance purchases, state criminal penalties for illegal data use, and local restrictions on license plate readers could reshape the market more directly than Flock’s internal policies.
Finally, scrutiny will focus on “Evidence Mode” and other override mechanisms. If agencies routinely extend retention or permit broad searches, the seven-day default and purpose-based access controls may have limited effect. If overrides are rare, logged, and independently reviewable, Flock will have a stronger argument that its new rules are changing real-world behavior.
Flock’s call for compromise is an attempt to reposition the company from a surveillance vendor defending its utility to a platform operator promising enforceable limits. The distinction is important: privacy protections are credible only when they constrain the customer, the administrator, and the vendor—not merely when they are available in a settings menu.
The company has responded to specific failures with specific controls, but the central question remains unresolved. A nationwide network of searchable vehicle data creates a structural privacy risk that cannot be assessed solely through individual abuse cases. Flock’s next phase will be defined by whether it accepts independent scrutiny and demonstrates that its guardrails work under real operating conditions.
Flock Safety is tightening access to its license plate data as CEO Garrett Langley urges a privacy-safety compromise amid mounting public scrutiny.