False Flags, Personal Agendas, and Why Human-in-the-Loop Is Non-Negotiable

Automated license plate reader networks like Flock Safety were sold as force multipliers for public safety. In practice they have produced two recurring failures: AI systems that misidentify plates and trigger enforcement actions against innocent people, and privileged users who turn the same systems into tools for personal agendas. Both problems thrive where trust is implicit rather than continuously verified. The solution is the same at every level of government—local, state, and federal: rigorous human-in-the-loop processes combined with Zero Trust principles, or what is more simply called watching the watchers.

AI False Positives and Wrongful Enforcement Against the Innocent

Flock and similar ALPR systems rely on optical character recognition that is imperfect. Dirt, glare, plate covers, lighting, or character confusion (0/O, 2/7, H/M) produce misreads. Even high claimed accuracy rates generate large numbers of errors at the volume of billions of monthly scans. When officers treat an alert as sufficient cause for action without rigorous human verification, innocent people pay the price.

Documented cases include:

  • In Toledo, Ohio (2024), a Flock camera misread a “7” as a “2” on Brandon Upchurch’s plate and flagged the vehicle as stolen. Officers stopped him at gunpoint, released a K9 that bit his arm and dreadlocks, and arrested him. Charges were later dismissed. He was hospitalized, lost work and housing, and settled a lawsuit for $35,000.
  • In Sherwood, Arkansas (February 2026), a single-character misread led officers to detain a couple at gunpoint in a parking lot while their six-week-old baby sat alone in the car.
  • In Morristown, Tennessee, the plate “LOVEY” was misread as the stolen “L0VEY.” An elderly couple was ordered out at gunpoint and handcuffed in front of their young granddaughter.
  • The Institute for Justice has documented at least 27 similar ALPR error cases since 2018 (majority recent and heavily involving Flock), with officers drawing firearms in roughly two-thirds before discovering the mistake. Victims have included families with children, a journalist tracked for days and subjected to a coordinated takedown, and others facing temporary detention or charges later dropped.
  • An LAPD Office of the Inspector General audit found 161 vehicles falsely flagged as stolen by Flock cameras in just two months of 2025—roughly 32 percent of the examined stolen-vehicle hits. The department allowed the contract to expire.

While pure automated civil tickets from Flock misreads are less common (the system is primarily investigative), the false alerts routinely produce high-risk stops that result in temporary arrests, citations, or charges against people who have committed no crime. In one documented instance, Georgia State Patrol used a Flock camera image to issue a traffic citation for phone use; the ticket was later dropped. The pattern is clear: algorithmic error plus insufficient human verification equals wrongful enforcement against the innocent.

Misuse for Personal Agendas

The same systems that generate false positives also create opportunities for deliberate or negligent personal abuse. Because the data is searchable and access is often lightly monitored, officers have used Flock and similar ALPR tools to track romantic partners, exes, and acquaintances for private reasons.

The Institute for Justice has identified at least 24 cases in recent years of officers using ALPR systems, including Flock, to stalk romantic interests. Nearly all resulted in criminal charges and job loss. Specific examples include a Milwaukee officer who conducted more than 170–200 searches tracking a dating partner and her ex, and multiple Georgia officers and deputies arrested or fired in 2026 after audits revealed personal lookups of family members and non-investigative targets across several agencies.

Company personnel have also crossed lines. A Flock vice president accessed a camera feed covering a children’s gymnastics area at a community center; the company later restricted such demonstration access.

Federal involvement has centered more on data-sharing and mission expansion than individual personal stalking—reports document ICE, CBP, and Border Patrol accessing Flock networks, sometimes without clear local authorization or in ways that conflicted with state or departmental policy. Privileged access without continuous verification enables both personal agendas at the local level and unauthorized expansion at higher levels.

Atlanta as a Local Illustration

Flock Safety is headquartered in Atlanta and has been extensively deployed across the city and Georgia. Company materials and local reporting credit the technology with assisting high numbers of case clearances, including claims that one detective solved 35 homicides in a single year with the support of Flock data—far above typical individual clearance benchmarks. Clearance (solving crimes after they occur) is distinct from incidence (the number of crimes that happen). Atlanta homicides peaked at approximately 161 in 2021 and 170 in 2022, then declined substantially in subsequent years—falling to around 135 in 2023, roughly 123–125 in 2024, and further to the mid-90s or lower in 2025, representing roughly a 43 percent drop from the 2022 peak according to Atlanta Police Department figures.

Even in a jurisdiction with dense Flock use and claimed investigative successes, the same systems have been involved in the documented patterns of personal misuse by officers and the broader risks of false-positive enforcement. Georgia agencies have seen clusters of officers charged or terminated for unauthorized personal searches. This dual reality underscores a core point: technology can aid investigations, but simply trusting AI alerts or privileged access without strong human controls still produces harms to innocents and enables misuse—intentional or negligent.

Human-in-the-Loop Is the Critical Safeguard

The common thread running through false flags and personal agendas is the absence of rigorous human judgment at the points where harm occurs. Treating an AI alert as authoritative without verification turns OCR errors into gunpoint stops of families with infants. Treating an officer’s badge as sufficient justification for unlimited queries turns a public-safety tool into a personal tracking device.

Human-in-the-loop requirements directly address both failure modes:

  • Before any enforcement action based on an ALPR alert—especially a high-risk “stolen vehicle” stop—officers must visually confirm that the original camera image matches the hotlist entry, verify vehicle description consistency, and perform secondary checks where feasible. Documentation of that verification is required.
  • Access itself must be continuously monitored. Every query needs a specific, auditable purpose. Behavioral analytics flag anomalies such as repeated personal searches or patterns inconsistent with assigned caseloads. Independent review teams examine both individual activity and systemic trends.

These are not bureaucratic add-ons. They are the practical application of Zero Trust principles (never trust, always verify; continuous validation of identity, purpose, and context; least privilege; assume potential misuse) to the people and systems that hold power over citizens’ location data.

Federal agencies already operate under related mandates: Executive Order 14028 drove adoption of Zero Trust Architecture, while Insider Threat Programs under Executive Order 13587 require continuous monitoring of privileged access. Local and state agencies deploying mass location surveillance must apply equivalent discipline. The administrative level does not change the risk.

Watching the Watchers: Insider Threat Programs with User Activity Monitoring

Public safety tools that track the movements of millions of ordinary people concentrate power. Power without continuous, independent oversight invites both technological failure and human abuse. The documented cases of innocent families held at gunpoint over misread plates, temporary charges against people who committed no crime, and officers using the same cameras for personal stalking demonstrate the cost of trusting the watchers by default.

An effective Insider Threat program that includes robust User Activity Monitoring (UAM) directly mitigates and helps prevent these harms. UAM continuously logs and analyzes every privileged action—queries, access patterns, timing, volume, and justifications—against established baselines. Anomalous behavior, such as repeated searches on personal associates, after-hours activity inconsistent with caseloads, or high volumes of non-investigative queries, can be flagged in near real time for independent review. Combined with mandatory human-in-the-loop verification of AI alerts before enforcement action, UAM creates a closed accountability loop: algorithmic outputs are checked by humans before they cause harm, and the humans who operate the system are themselves continuously monitored. This approach deters intentional misuse, detects negligent or unauthorized access early, supports timely intervention, and strengthens the integrity of any legitimate investigative benefits the technology may provide.

Accountability at the local, state, and federal levels requires the same standards: assume potential error or misuse, continuously verify every privileged action through tools like UAM, limit access to the minimum necessary, monitor the monitors independently, and insert human judgment at the points where harm can occur. Technology can assist clearance rates, as claimed in places like Atlanta. It cannot replace human verification of alerts or continuous oversight of those who wield the tool. Simply trusting the AI or the badge is what allows both false flags against the innocent and personal agendas—intentional or not—to flourish.

Watching the watchers through formal Insider Threat programs with User Activity Monitoring is not optional. It is the minimum condition for legitimate use of these systems