Skip to content

Power

A Store’s Shoplifting Photo Can Follow You to the Police

A blurry retail still can become a watchlist entry, a vendor record and a police lead. The machinery moves faster than the process for correcting it.

Kurt HalloranPower — Politics & Media

August 12, 2026 · 8 min read

A dark baseball cap beside a retail surveillance monitor showing an indistinct store aisle.

The dark baseball cap is worn brim-forward in the surveillance still from a Shinola store in Detroit. Beneath it, the face is compressed by distance, camera angle and retail lighting. That image helped produce one of the best-known facial-recognition failures in the United States: Detroit police arrested Robert Williams after software suggested his driver’s-license photo as a possible match.

Williams was not the man in the cap. The charges were later dismissed, and a 2024 settlement with Detroit imposed restrictions on how the city’s police use facial recognition. By then, however, the image had already done what these systems ask images to do. It had left the store, acquired an incident narrative, entered a police workflow and been treated as evidence of identity rather than a lead requiring skepticism.

That distinction matters. Store surveillance does not need to be clear enough to prove anything before it begins traveling. It only needs to be useful enough for the next institution to accept.

The image becomes a case file

A retail theft investigation usually starts with loss prevention, the retailer’s internal security function. An employee may export a still or video clip, attach a time and location, describe clothing, record the merchandise allegedly taken and assign an incident number. The person in the picture becomes a record before anyone knows the person’s name.

Large retailers can keep those records in centralized case-management software rather than on one store manager’s desktop. The software lets investigators connect incidents across branches, search descriptions and assemble evidence packages. Some systems include watchlists, meaning collections of people a retailer has associated with previous incidents or marked for attention. A watchlist entry may contain a face image, an alleged name, vehicle information, notes from employees and links to other cases.

The incentive is plain. Retailers want one shoplifting event to explain another, particularly when executives are under pressure to describe inventory losses as organized rather than ordinary. A searchable network turns scattered incidents into patterns. It can also turn a poor assumption into a durable corporate fact.

The cap in the Shinola still shows the weakness. Clothing is useful for following someone through one sequence of camera views, but it is weak identity evidence across days or locations. A face extracted from the same frame may look more authoritative because software places a score beside it. The score does not repair the source image.

It measures similarity under the vendor’s model and conditions, which is a narrower claim than the screen tends to suggest.

Vendors widen the route

Retailers rarely build the entire surveillance stack themselves. They buy cameras, cloud storage, incident software, facial-recognition tools and access-control systems from vendors whose business improves when more locations and more records sit inside the same product.

A biometric template, a numerical representation of facial features used for comparison, may be generated when a retailer enrolls an image in a facial-recognition watchlist. New camera footage can then be checked against enrolled templates. Other products stop short of automated recognition but still let employees distribute photos, label suspected repeat offenders and notify nearby stores.

Access varies by contract and configuration. A vendor may host the data while the retailer decides who can view it. Corporate investigators may see records from several branches. Retail crime associations can provide another route for sharing intelligence among businesses and law enforcement.

Some police departments receive reports through vendor portals; elsewhere, a loss-prevention employee sends an email, uploads a packet or calls an officer who already works with the store.

This is where the public-facing language becomes slippery. Companies sell “information sharing,” “incident management” or “real-time intelligence,” phrases that describe workflow while politely avoiding the fact that a person’s face can move from a private store dispute into a larger enforcement network. The retailer gains reach. The vendor gains recurring revenue and a product that becomes harder to replace as it accumulates cases.

Police gain cameras and investigators they did not have to fund.

The accused person gains no comparable dashboard.

Public scrutiny has shown what happens when weak images meet aggressive deployment. In a 2023 complaint, the Federal Trade Commission alleged that Rite Aid’s facial-recognition program produced false-positive alerts that led employees to follow, search, eject or call police on customers, with harms falling disproportionately on women and people of color. The proposed settlement included a five-year ban on Rite Aid using facial recognition for surveillance purposes. Rite Aid’s case was not proof that every retailer runs the same system.

It exposed the incentives and failure modes of one that did.

Police turn a resemblance into a name

Once police receive an image, they may compare it manually with known people or submit it to a facial-recognition system. Depending on the jurisdiction, the search database can include mug shots, driver’s-license images or other government photographs. The system returns candidates. It does not discover identity in the way a fingerprint examiner might claim an association; it ranks faces according to mathematical similarity.

Image quality matters. So do the composition of the search database, the algorithm and the threshold used to present candidates. Testing by the National Institute of Standards and Technology has documented demographic differences in facial-recognition performance, although results vary widely among algorithms. A low-resolution store frame, with a low cap brim cutting across the face, adds another source of error before the search even begins.

The human review that follows is supposed to protect against automation bias, the tendency to defer to a machine’s output because it appears objective. It can instead launder the suggestion. An analyst selects a candidate, an investigator looks for supporting details, and a witness may later see that person in a photo array. Each stage appears independent on paper even when every stage traces back to the same algorithmic lead.

That was central to the failure in Williams’s case. The face under the dark cap became a candidate from a government photo database, then a police identification process, then an arrest. Detroit’s later settlement bars arrests based solely on a facial-recognition result and requires additional evidence, among other safeguards. Those rules recognize a basic point the sales material tends to blur: a candidate list is an investigative prompt, not probable cause with nicer graphics.

Correction is fragmented by design

A false match does not create one record. It creates several, held under different rules.

The store may retain an incident report and watchlist entry. Its vendor may host copies, logs or backups. Police can hold the original referral, the facial-recognition request, the returned candidates, analyst notes and any later reports. Prosecutors may receive another case file.

If the image passed through a retail crime association, that organization may have its own retention policy.

There is no universal appeal button. A person trying to correct the record first has to identify which records exist, who controls them and whether the relevant law grants access, deletion or correction rights. State privacy laws may provide consumer requests for certain business-held data, while biometric privacy statutes can impose separate duties around face templates. Exemptions differ, especially for security investigations, fraud prevention and law-enforcement records.

This is a systems guide, not legal advice, and local rules control the available route.

Retailers may have customer privacy portals or corporate loss-prevention contacts, but a store employee at the door often cannot review a centralized watchlist. A written dispute can ask the company to identify the incident, the source image, the basis for the match, the recipients of the record and the retention period. Receipts, account histories and location records may help distinguish the person from the image, though producing them costs time and can require surrendering more personal data to the same institution.

Police records can be sought through public-records or discovery procedures, subject to investigative exemptions and redactions. Useful documents include the original image, the facial-recognition request, the candidate list, the algorithm or vendor used, the analyst’s conclusion and policies governing human review. If an arrest or prosecution followed, challenges usually run through criminal defense and court procedure. Civil-rights agencies, state attorneys general and privacy regulators may offer complaint channels, but they do not function as fast correction desks.

Deletion presents the hardest problem. One institution can amend its file without reaching copies already disclosed elsewhere, while a vendor may claim it merely processes data for the retailer and the retailer may point back to the vendor’s technical controls. Backups can survive after a front-end record disappears. Police retention schedules may override a retailer’s decision.

Even a corrected case can remain searchable under the original allegation.

The machinery is distributed because distribution benefits everyone operating it. Responsibility is distributed for the same reason. The person in the image has to reconstruct the chain one institution at a time, starting with the low brim of a dark baseball cap and ending wherever the copies went.

Questions people ask

Can a store put my face on a watchlist without telling me?

Often, yes, although the answer depends on state law, the technology used and what notice the retailer provides. Facial-recognition enrollment may trigger biometric privacy requirements in some jurisdictions, while an ordinary photo attached to an internal incident report may receive fewer protections. Security and fraud-prevention exemptions can narrow access or deletion rights.

Does a facial-recognition match prove someone shoplifted?

No. A match is a ranked similarity result between images, not proof of identity or conduct. Poor camera angles, compression, lighting and partial obstructions such as a cap brim can weaken the comparison. Police and retailers still need reliable human review and independent evidence rather than recycling the software’s suggestion through several official-looking steps.

How can someone find out where the image went?

Possible routes include retailer privacy requests, corporate loss-prevention contacts, police public-records requests and court discovery when a case exists. The useful records are disclosure logs, vendor names, watchlist entries, match reports and retention policies. No single request is guaranteed to reach every copy, and exemptions vary by jurisdiction.

Will correcting the retailer’s record remove the police copy?

Not necessarily. Retailers, vendors, police and prosecutors can each hold separate records under separate retention rules. A correction should identify the original allegation and every known recipient, but one organization may lack authority to delete another’s files. That fragmentation is why false matches can outlive the incident that produced them.

Was this worth your time?
ShareFacebook
surveillancepolicing and courtsretail surveillancefacial recognitionshopliftingprivacypolice databases

One update a day

Today's story, in your inbox

One story each morning — no hype, no filler, no algorithm deciding for you.

Read next