Two weeks ago we wrote that the only lever with a working handle on the license plate reader business was procurement, and that the way this changes is somebody with signing authority declining to renew. Since then a lot of people have declined. Agencies in twenty-three states have cancelled. More than twenty local jurisdictions dropped their cameras or started the process in July alone, the highest single month since the activist group that tracks them began counting in 2021. In Macon County, North Carolina, the vote was unanimous, and the Republican commissioner who described the room to Politico said there were "work boots and Subarus in our parking lot and they were united."

On Thursday the vendor answered. Flock cut its default data retention from thirty days to seven, made misuse audits mandatory, required a case number before an officer can run a search, and gave departments filters over which other departments can query their data. Asked by the BBC's Kali Hays whether it had taken the company too long to do any of it, chief executive Garrett Langley said: "Yeah... yes."

So the lever worked. What we want to look at is what it bought, because all four of those concessions are settings. Not one of them is a constraint. That distinction is the entire subject of this piece, and it is not really about cameras. It is about the difference between a safeguard you can switch off and a safeguard you cannot, which is a question every buyer of every automated system should be able to answer about their own stack and almost none can.

What actually changed

Take the announcement seriously first, because it is a real move and the people who forced it should get to say so.

Retention. The recommended default drops from thirty days to seven. Per MIT Technology Review, agencies can overrule it. Flock's vice president of government affairs confirmed to StateScoop that the retention schedule remains up to each agency. The ACLU's recommendation is forty-eight hours.

Case numbers. Officers now have to enter a criminal case number to run a search. The feature launched as an option last year and is now required. Flock does not verify the numbers.

Audits. The automatic auditing system that flags anomalous search behavior was also optional last year and is now mandatory. Flock has not published how accurate it is and has not opened it to independent evaluators.

Sharing filters. A department can now restrict what other departments are allowed to search its data for, permitting a stated reason like kidnapping and excluding others. It works on the reason the searching officer types in.

Langley's own framing of the shift is worth quoting in full, because he did not have to say it. "Historically, my point of view as a chief executive of a private company was, I don't know if I should be making these decisions. I don't know if it's my job to say how long data should be retained," he told the BBC. And then: "Our employees and communities have said loud and clear, they expect companies like Flock to have a stronger point of view as the expert. I resisted that because I didn't want to have that responsibility." He also said he now agrees with the ACLU and the EFF that a search should require an active case number. "They're right. I think it should be required."

That is a chief executive publicly conceding that declining to hold an opinion was itself a decision. We have made a version of that argument in this space repeatedly about automation, and it is genuinely better to hear it from the vendor than from us. The EFF's Cooper Quintin then described the package to the BBC as "piecemeal, voluntary, and reversible" updates that "fall short," which is not a slogan. It is a precise, three-word engineering critique, and the third word is the one that matters.

There is a reason "reversible" lands harder here than it might coming from another critic. All four changes are verified by the vendor's own account of its own system, and the vendor's account is precisely what is in dispute. In a July piece, the ACLU's Chad Marlow and Jay Stanley catalogued statements Flock made to city councils and police departments that later did not hold up: that the system did not create a heat map of an individual's movements, which the company subsequently acknowledged it does for up to a month, after which the council in Oshkosh, Wisconsin revoked approval in a single day; that it held no federal contracts, when it had pilot arrangements with Customs and Border Protection and the Department of Homeland Security, which Langley later attributed to having "clearly communicated poorly"; and, in Urbana, Illinois in 2021, that Flock had worked with groups like the ACLU to design an ALPR system, which the ACLU says never happened.

That is the ACLU's characterization and the ACLU is an interested party, so hold it accordingly. Hold the other side the same way: Langley told MIT Technology Review that the main reason Flock loses customers is "misinformation," specifically the belief that it does facial recognition or sells the data it collects. MIT's James O'Donnell noted in the same paragraph that the misinformation charge cuts both ways. Both can be true at once, and neither is checkable from outside the company, which is not a rhetorical stalemate. It is the finding. When every safeguard is self-attested and the self-attestation is contested, you do not have a disagreement about facts. You have an unverifiable system.

A default is not a constraint

Here is the test we use, and you can run it on any vendor in your stack this afternoon. For each safeguard you were sold, answer three questions. Who can turn it off. How long does it take them. Who finds out.

Run it on the retention window. A single agency administrator can turn it off. It takes one screen. Nobody finds out, least of all the residents whose movements are now kept for thirty days again instead of seven. Under that test, retention is not a safeguard. It is a preference, and preferences revert. They revert at budget time, they revert when the administrator changes, they revert quietly after an incident that makes somebody want more history, and they revert without a public meeting because nothing about a settings screen requires one.

We made this point in The Bucket Called Other in a different context and it keeps proving out: a configured value is a promise a human keeps, and a property of the system is a fact about the system. Every safeguard announced on Thursday is in the first category. The default is better than it was. The floor did not move.

Which is worth saying plainly, because the loudest version of this criticism is that the changes are worthless. They are not worthless. Seven days is materially better than thirty for the large majority of agencies that will never touch the setting, and defaults do most of the work in most systems precisely because most people leave them alone. The problem is not that a default does nothing. The problem is that a default does nothing reliably, and reliability is the only property a safeguard is actually for.

Now look at what a constraint looks like in the same story. Virginia enacted an ALPR law last year. Agencies cannot share the data outside Virginia. They cannot share it with federal agencies including ICE and the FBI. Misuse or unlawful sharing is a Class 1 misdemeanor, with likely job loss on top. There is no screen where a department administrator turns that off. The ACLU's Chad Marlow put the general form of it to StateScoop: "Police policies can be changed at the drop of a hat. This is too dangerous a technology to leave up to policy. There has to be laws governing them." The Center for Democracy and Technology's Tom Bowman was blunter about the announcement itself, calling it "the same 'Just Trust Us' policy with a fresh coat of paint."

You do not have to agree with either advocate to use the distinction. It is the same one you would apply to a subprocessor, a data retention clause, or an API rate limit. Ask whether the protection lives in a settings screen, a contract, a statute, or the code itself, because those four have wildly different half-lives and vendors routinely describe all four with the same word.

Nine in a million

The most useful thing published this week was a reporter refusing to accept an accuracy number, and it is worth walking through slowly because the shape of it will be familiar to anyone who has ever evaluated a vendor.

Flock's site claims 96% accuracy. That figure is for counting vehicles. The company makes no public claim about the accuracy of reading plates, which is the function that ends with a police officer approaching a car. Notice what has already happened: the published number describes a different task from the one the product is bought for.

StateScoop pressed on the missing four percent, asking whether those were false positives or some other kind of error. The answer came back as a different number entirely: of every one million alerts sent to local law enforcement, nine are flagged back to Flock as inaccurate reads. That works out to 99.9991%, which the reporter noted is both better than 96% and statistically improbable. The company attributed the gap to low confidence reads being filtered out before they ever become alerts.

But the two figures are not really in conflict, because they are not measuring the same thing, and this is the part worth taking to your own vendor calls. Ninety-six percent is a performance rate. Nine per million is a complaint rate. A complaint rate is an error rate multiplied by the probability that somebody noticed the error, understood it was an error, knew where to report it, bothered to, and was believed. In a system whose subjects overwhelmingly never learn they were scanned at all, that multiplier is close to zero, which means the number is close to meaningless as a measure of accuracy while being entirely accurate as a measure of complaints. We have been handed a ticket volume dressed as a defect rate by more than one vendor, and by more than one internal team.

Then there is the third number. The police department in Roseville, California audited almost 1,500 of its own Flock alerts last year and found a 71% failure rate on plate reads. We cited that figure in the last piece from secondary reporting and treated it carefully as one city. The provenance turns out to matter more than we knew: it was not an advocacy study or a journalist's sample. It was the customer, measuring its own installation, on its own alerts.

So: 96%, nine in a million, and 71%. All three can be true simultaneously because each has a different denominator, and only one of the three was produced by the buyer. That is the finding. Not that anybody lied, but that two of the three numbers answer questions nobody asked.

And then the detail that reframes all of it. Flock told StateScoop that it allows and actively pursues independent third-party reviews of its security, including tests for cybersecurity vulnerabilities, but that it does not allow third-party audits of its accuracy claims. Read that twice. The company opens the door to strangers on the question of whether it can be broken into, and closes it on the question of whether it works. Whatever else that is, it is information. A vendor's audit policy tells you which of its numbers it expects to survive contact with someone who does not work there.

Nobody can tell you how big it is

Here is something we did not expect to find. Over six days, from four outlets, working from the same company and the same public sources, the size of this network was reported as:

Over 80,000 cameras (Politico, August 9). Over 120,000 across 49 states, which is Flock's own figure (Mashable, August 12, and MIT Technology Review, August 13). Almost 100,000, and installed in every state rather than 49 (StateScoop, August 14).

The customer counts do the same thing. Flock has been quoted putting its own agency count at 5,000 and at more than 6,000 in the same week. DeFlock counts more than 6,400 agencies using the system. Politico reports more than 7,000 law enforcement agencies plus more than 6,000 private sector customers.

The cancellation counts too. NPR found at least 30 cities had dropped Flock over a year, in February. The BBC reports at least 50 cities cutting ties this year. StateScoop says agencies in 23 states have cancelled. DeFlock counted more than 20 jurisdictions moving to drop in July alone.

Against all that motion, one number holds perfectly still: Flock's claim that for every city that does not renew, roughly seven new ones sign. The CEO gave the BBC a 7:1 ratio of new customers to lost ones and said 16 cities that had switched Flock off came back within three months. A company spokesperson gave Politico the same ratio in almost the same words. It is the only figure in the entire week that survives unchanged across outlets, and it is also the only one with no published denominator and no way for anyone outside the company to check it.

Meanwhile the best public inventory of the network is a volunteer project. DeFlock, crowdsourced by contributors and published onto OpenStreetMap, has 128,988 devices mapped, 82% of them attributed to Flock, which works out to about 105,770 and just under 90% of what the company says it has out there. Its own documentation makes the point deliberately: "Camera locations come from volunteers and the OpenStreetMap community, not a private company or government agency." Those figures and the map itself were reported by Mashable's Shannon Connellan, and by The Hill, whose copy we were unable to retrieve and are therefore not quoting.

We are going to resist the political version of that and give you the operational one, because it is the one that transfers. When the most credible census of a system is a hobbyist map, nobody is doing asset management. We have said the identical thing to clients about their own ad accounts, their own tag containers and their own data pipelines, usually after discovering that a spreadsheet maintained by one person who left is the only accurate record of what is running. If a volunteer with an open source map has a better inventory of your estate than you do, you do not have an estate. You have a bill.

The count that started it

The proximate cause of Thursday's announcement was a Washington Post investigation published on August 2 into officers using plate reader systems to track women.

We could not read it. The Post's page refused every request we made from here, and we do not cite what we have not read, so here is the secondary reporting and here is how it disagrees with itself. MIT Technology Review reports the Post found 46 cases of officers accused of using Flock's cameras for unauthorized purposes such as stalking. Kayla Gaskins of The National News Desk, the Sinclair national service, says the Post found at least 50 law enforcement officers charged or accused of improperly using license plate reader technology, with 26 cases in which investigators or prosecutors said officers tracked wives, girlfriends, ex-partners, their exes' new partners or women they wanted to meet. Angela Fu and Amaris Castillo at Poynter, writing about the investigation's effect on the company, describe dozens of examples and one police chief who searched his ex-girlfriend's plate more than 500 times.

Those are not the same claim. One counts cases on one company's system; another counts officers across the whole technology category, which includes competitors. We are not going to pick one, and you should be suspicious of anyone who does without saying which they read.

What is not in dispute comes from the vendor. The automatic audit feature launched as an option earlier this year. Most police customers switched it on. And per the BBC's account, misuse proved rampant enough that Langley decided the feature had to be standard. Sit with the sequence: the company found out how bad the problem was by shipping the instrument and reading the dial. That is the most damning sentence available on the subject, and nobody hostile to the company had to write it.

The case the other way, on the record

A piece that only stacked up the bad week would be dishonest, and the counterexample in this reporting is unusually specific.

Jon Bridges has been with the Richmond, Virginia police department for twenty years, mostly in homicide and violent crime, and is now its director of strategic implementation. Richmond has had a Flock contract since 2023 and runs 99 cameras. He calls it a "huge benefit" and a "game changer" for certain investigations, and he gave StateScoop numbers: across six public housing communities in 2025, there were 23 homicides and his department cleared 21 of them, a 90% clearance rate. StateScoop notes parenthetically that one analysis of FBI data puts the national average around 50%.

Take that for exactly what it is. It is one department's account of its own year in its own selected geography, and Bridges says himself that those communities had already invested in a separate video camera system that had been "tremendous" on its own. It is not a controlled comparison, and he does not claim it is.

But it is the most interesting passage of the week for a reason that has nothing to do with the number. Richmond is in Virginia, the state with the statute. Bridges describes monthly audits, a detailed signed user agreement, and a restriction to law enforcement purposes. Then he says the quiet part directly: the conduct Georgia officers were in the news for "would be against the law here in Virginia."

The operator most willing to defend this technology on the record is the one working under the tightest legal constraints in the story. That is not a coincidence and it is not an accident of who was available for interview. Constraint is what makes a defensible deployment defensible, and it is the one thing a vendor structurally cannot sell you, because the value of a constraint is precisely that the person bound by it did not get to choose it.

The other side of the ledger is equally on the record. Eric Couture, first selectman of Killingworth, Connecticut, told Politico the cameras "didn't help us with anything. From a utility aspect, they were just kind of not useful," and called the whole thing "a net negative." Both accounts are true. Which one a community ends up with looks a lot more like a function of how the thing is governed than of what the thing is.

The playbook

Six moves, none of which require you to have an opinion about policing.

1. Ask what the denominator is, and who counted. Every accuracy claim is a fraction. Make the vendor state the numerator, the denominator and the measurement window out loud, and notice when the answer describes a different task than the one you are buying.

2. Sort every safeguard into settings and constraints. Write the actual list. For each one: who can change it, how long that takes, and who gets notified. Anything where the answers are "one admin," "one screen" and "nobody" goes in the settings column, no matter what the vendor's announcement called it.

3. Buy the audit right, not the audit report. A report is a snapshot the vendor commissioned. A right is a clause that lets you or a third party measure the system on your data, on your schedule. Get it in the contract before you sign, because your leverage is never higher than the week before renewal and never lower than the week after.

4. Measure the thing you care about, not the thing that is easy to log. Complaint rates, ticket volumes and escalation counts all masquerade as quality metrics and all of them silently include the term "and somebody noticed." If your defect measure depends on a human catching it, sample the output yourself and count.

5. Keep your own inventory. Of the cameras, the tags, the accounts, the API keys, the models, the agents. If an outsider can produce a more accurate map of your estate than you can, that is the finding, and it is a bigger one than whatever prompted you to look.

6. Put the load-bearing promise where a settings change cannot reach it. A contract term, a statute, or code you control. Everything else is a preference with good intentions attached, and preferences revert on a schedule nobody publishes.

Our position

This is the third time we have written about this network. The first was about what a wrong answer costs the person in the car. The second argued that no regulator was positioned to intervene because the government is the customer, and that procurement was the only lever with a working handle. This one is about what happened when a lot of people pulled it at once.

The honest summary is that it worked, partially, and that the reward for a genuinely nonpartisan nationwide revolt was four default values moved in the right direction and two optional features switched on by the vendor rather than by the buyer. That is not nothing, and we would rather have it than not. It is also all reversible, per department, in an afternoon, with no notice to anyone affected. Seven days can be thirty days again on Monday and no resident of that town will ever know it happened.

We are not telling anyone to be more suspicious of vendors, which is cheap advice and mostly useless. We are suggesting one narrower question, which we ask about our own systems and which we would ask about yours: which of my safeguards would survive a bad quarter, a new administrator and a budget cycle? The ones that would are constraints. Everything else is a setting, and the fact that a setting is currently in the right position tells you nothing whatsoever about where it will be next year.

Langley said something to the BBC that we think is more true than he intended. "Because you can see our cameras, it's easier to get mad." He is right, and it is the best argument in the piece against his own position. The poles are the only visible part of this system. The retention window, the sharing agreement, the audit threshold and the real plate-reading accuracy rate are all invisible, all adjustable, and every one of them matters more than the hardware anybody can point at.

Sources

Every claim above is carried from the reporting below, credited in the body and linked here. Where our sources disagree we have said so rather than picked, and where we could not read something we have said that too.