Flock's chief executive told a reporter this month that he wants the company's cameras in every one of America's roughly 17,000 cities. That is not a leak or a hostile characterization. It is the stated goal, said out loud, to the press.

So when you ask when this ends, the vendor has already answered. It ends when there is nowhere left to put one. Nothing in the current arrangement is structurally capable of producing any other outcome, and the reason is not that the technology is unusually powerful. It is that the entity we would normally expect to regulate it is the entity buying it.

We build automated systems that read vehicle data for a living. We know exactly how often this class of machine is wrong, and exactly what it costs to build the validation gate that keeps a wrong answer from reaching a person. So read the rest of this as an engineering critique of a procurement failure, not a political one.

The consumer-protection reflex never fires

Think about how a harmful product normally gets checked. Customers get hurt, they complain, journalists dig, a regulator notices, and the state applies pressure to the company. The mechanism depends on one structural fact: the government and the company are on opposite sides of the table.

Here they are on the same side. The buyer is the police department. The budget line is approved by a city council. The subscription runs at a reported $2,500 per camera per year, on contracts that auto-renew and that, as reported, limit a city's ability to audit the system or control how other agencies use the data it collects. The customer, the regulator and the beneficiary are the same institution, which means the pressure that normally corrects a bad product has nowhere to enter.

Now scale that up. Reporting from 404 Media this spring put the FBI in the market for nationwide access to plate-reader data, and noted that only a couple of vendors could plausibly fulfill it. When the federal government becomes the anchor customer for a national tracking network, the theory that federal oversight will eventually rein it in stops being optimistic and starts being incoherent.

This is the answer to the question, and it is not satisfying. Elected officials are not failing to act against this. Many of them are procuring it, on a subscription, with automatic renewal.

The escalation is already patented

Here is what makes the timing urgent rather than merely grim.

The legal fig leaf for plate readers has always been narrow and specific: a license plate is issued by the state, displayed publicly, and visible to anyone on the road, so the argument goes that you have no reasonable expectation of privacy in it. Whatever you think of that reasoning, it at least described a real limit. A plate is one identifier, on one vehicle, in public view.

Leonardo, the US arm of the Italian defense group and a competitor to Flock, holds a patent granted in March 2024 for what it now markets as ELSAG SignalTrace. It is a sensor that clips onto license plate cameras already mounted on poles, overpasses and patrol cars, and it reads the wireless identifiers that nearby devices broadcast: Bluetooth from phones, watches, fitness trackers and wireless earbuds; Wi-Fi from hotspots, tablets and laptops; RFID from key cards and asset tags and, per the company's own product sheet, pet microchips; and signals from a car's own tire-pressure sensors and infotainment system.

When the same devices repeatedly travel with the same vehicle, the system bundles them into what the company calls an "electronic fingerprint" and ties it to the plate and a timestamped location. The product sheet states plainly that this works "even if a suspect changes or removes a plate." 404 Media's Joseph Cox summarized the shift precisely: it turns cameras focused on tracking cars into ones that can more readily track the location of particular people.

Be clear about what that means. Your plate identifies your car. The phone in your pocket, the watch on your wrist and the earbuds in your ears identify you, and they keep identifying you in whatever car you are sitting in, including someone else's.

The honest state of play, which matters: as of the most recent reporting, no police department, city or pilot program has been publicly documented using SignalTrace. It is patented, marketed and being sold into an installed base of over 100,000 cameras. It is a trajectory, not a deployment, and anyone telling you it is watching you today is ahead of the evidence.

"It functions like a license plate reader"

That line is from Leonardo's own product sheet, in the passage explaining that SignalTrace captures only publicly broadcast device signals and does not decrypt or store any content.

Read it again, because it is the most important sentence in this entire story, and it is not an engineering description. It is a legal argument, pre-loaded into the marketing copy.

The whole defense of plate readers rests on a doctrine about information you knowingly expose in public. SignalTrace is engineered so that the identical doctrine covers your phone: we are not intercepting your communications, we are merely observing an identifier you are broadcasting into the air, exactly as a plate reader observes a plate you are displaying on your bumper. Same argument, same shape, applied to the device on your body rather than the metal on your car.

That portability is the design. And it generalizes with nothing to stop it, because almost everything you own now announces itself continuously. The doctrine was built for a number stamped on steel by the state. It is being stretched to cover every radio you carry, and if it holds there it holds for whatever you carry next.

Flock, separately, holds its own patent, granted in 2022, describing neural network modules that classify people captured in footage by attributes including gender and race, along with clothing, estimated height and weight, and storing those classifications in a searchable database. That is a patent, not a shipped product, and it should be described as one. But a company does not spend money patenting a capability it has no interest in.

Every safeguard you are being offered has already failed somewhere

The standard reassurance is that rules and audits will manage this. Test that against the record.

Rules barely exist. University of Michigan research put the number of states with any form of ALPR regulation at sixteen, as of 2024. Most of the country has none.

Where rules exist, they are broken at scale. California passed SB 34 in 2015. A 2023 EFF investigation found 71 police agencies across 22 counties sharing data illegally out of state. San Francisco's department alone was reported to have allowed roughly 1.6 million improper searches by out-of-state agencies across 2024 and 2025. The state attorney general's first enforcement action landed in 2025, against one city, a decade after the law passed. A rule enforced once in ten years is not a rule, it is set dressing.

The prohibited uses are exactly the ones that happen. Illinois bars sharing this data for immigration enforcement. The Illinois Secretary of State's audit of a dozen agencies found unauthorized pilot programs giving federal immigration authorities access anyway, and 47 out-of-state agencies were subsequently cut off. One suburban department logged 262 immigration-related searches in the first months of 2025. In another, a detective handed his login to a federal agent who ran 28 searches labeled as immigration violations. Note the mechanism in that last one: no hack, no exploit. Somebody shared a password.

Audits are archaeology. Nearly every documented abuse surfaced through a complaint or a later review, not through a control that stopped it happening. A Wisconsin officer was charged in January 2026 with misconduct after allegedly running five unauthorized searches on his ex-partner. That is the system working as designed after the harm, which is not the same as working.

And "anonymized" is doing no work at all. Contracts reportedly grant a perpetual, worldwide, royalty-free license to anonymized data, with anonymization defined to permit retaining things like vehicle make, model, color and location patterns. The research on this is not close. An MIT study found four time-and-place points enough to uniquely identify 95 percent of people in a location dataset. Later work re-identified drivers from vehicle sensor data with 97 percent accuracy. Location data about a specific vehicle is not anonymizable in any meaningful sense, so a contractual promise built on that word is void on the science regardless of anyone's good faith.

The accuracy problem is worse than the anecdotes

We wrote up the individual stops in One Letter Off, Guns Drawn and will not repeat them. What has changed since is that the failure rate is starting to be measured rather than anecdotally collected, and the measurements are not survivable.

Gizmodo reported at the end of July that in one California city, Flock cameras got the wrong license plate 71 percent of the time. One city, not a national figure, and it should be cited that way. But sit with it anyway, because in our line of work a component with that error profile does not get a remediation plan. It gets pulled out of the pipeline the same afternoon.

The reason a bad read becomes a drawn weapon rather than a shrug is that there is no validation gate between the machine's guess and the officer's adrenaline. That gate is not hard to build. In any system we ship, a match that triggers a consequential action gets a second independent check before a human ever sees it as actionable. The technology to compare the alert photo against the alert text and refuse to fire on a mismatch is trivial. It is a comparison. The absence of that check is not a technical limitation, it is a choice about who absorbs the cost of being wrong, and right now that is the person in the car.

The honest counterarguments

Three, and they deserve better than dismissal.

It solves crimes. It does, sometimes. Indiana State Police used plate-reader data to identify suspects in an interstate shooting within days. That is a real outcome and pretending otherwise would be dishonest. The question was never whether a total surveillance net produces arrests. It obviously does. The question is what else it produces, and whether we agreed to it.

Your phone already leaks more. Bruce Schneier made this point directly about SignalTrace, and he is right about the volume. He is not right that it settles anything. The data your phone collects flows to a company you have a contract with, that you can in principle leave, and reaching it generally requires legal process. The pole offers no contract, no alternative provider and no opportunity to decline, and it exists specifically to be queried without one. The distinction that matters is not how much is collected. It is consent and legal process, and the roadside sensor is engineered to need neither.

The courts will sort it out. They might, eventually, and the early signals are genuinely mixed rather than hopeless. A federal judge in Virginia allowed a Fourth Amendment challenge to Norfolk's network to proceed, leaning on Carpenter, the Supreme Court decision requiring warrants for historical phone location data, and finding the camera network notably similar. Court filings in that case described two residents whose vehicles were recorded 526 and 849 times in four and a half months. But other judges in the same district have gone the other way, and appellate resolution is years out. Meanwhile the cameras go up daily, and every month of delay is another month of the network becoming infrastructure that is politically harder to remove.

So when does it end

Not with a federal privacy law. There is not one coming, and the patchwork that arrived instead was built for marketing data, not for policing.

It ends the way any bad vendor relationship ends. Somebody with signing authority declines to renew.

That is not a rhetorical flourish, it is the only lever with a working handle, and it has just been pulled. The LAPD suspended its use of the cameras this month. Public records rulings have started forcing this data into daylight, including a Washington judge who ordered footage released precisely because it was so broad and indiscriminate that it could not qualify as investigative intelligence. Residents in multiple cities are showing up to council meetings, and a searchable public map of camera locations now exists. The vendor's own chief executive has acknowledged that police abuse of the system is a problem, while continuing to defend the company, and has called the constitutional question cut and dry, which is a thing people say when it is not.

The practical opening is that this is a procurement decision, and procurement is the one part of government built to be attended by ordinary people. A federal privacy bill is not something you can show up to. A council vote on a $2,500-per-camera renewal is. So the questions worth asking in that room are specific and answerable, and a vendor who cannot answer them on the record has told you what you need to know:

What is the measured misread rate on our own installation, not the national marketing figure. What independent validation happens between an alert and an officer acting on it. Who outside this department can query our residents' data, and can we technically prevent it rather than merely prohibit it. What happens to the data at termination, and does the perpetual license to anonymized data survive. Can we audit the system ourselves, on demand, or does the contract prevent it. And who signs off before a sensor that reads the devices in a car, rather than the plate on it, gets clipped to hardware we already paid for.

Our position

We are not anti-camera and we are not naive about crime. We automate vehicle data for a living and we think this class of technology has legitimate uses under real constraints.

But the thing on the pole was sold as a plate reader and is becoming a population-scale identity graph, and the sales copy for the next stage is already written and already argues that your phone is legally indistinguishable from your bumper. There is no natural stopping point in that trajectory, no regulator positioned to impose one, and a vendor whose stated ambition is every city in the country.

The uncomfortable part is that nobody has to be a villain for this to end badly. Every actor is behaving rationally inside their own incentives. Departments want the tool. Vendors want the contract. Councils want to look serious about crime. The result is a national tracking system that nobody voted for, assembled one purchase order at a time, and the only place it can be interrupted is at the same purchase orders.

You want to know when we are going to say tech has too much power. The honest answer is that the power was not taken. It was bought, in public, at a posted price, by people who work for us.