Independent · Updated continuously
Artificial Intelligence in Law Enforcement
Analysis · 3 September 2026 · 9 min read

The best public record of UK facial recognition is the one forces publish themselves

Essex, Surrey, Sussex and Merseyside all now publish material about their own facial recognition deployments. These pages are the strongest public evidence available on how the technology is being used. No two forces publish the same things, and on one force's page the figures do not reconcile with each other.

For most of the past decade, establishing where and how British police used live facial recognition meant reconstructing it from other people's work. Freedom of information responses. Campaign group research. Court papers. Local reporting of individual deployments, one town centre at a time.

That is no longer the position. A growing number of forces now publish their own facial recognition pages, and several publish a running register of every deployment with the figures attached. For anyone trying to keep an accurate record, these pages have quietly become the single most useful source available.

They are also uneven, inconsistent between forces, and in at least one case internally contradictory. Both of those things are worth understanding, because the number of forces operating this technology is about to rise sharply.

What a deployment register actually contains

Essex Police publishes the most detailed register found in this review. For each deployment it gives the date, the location, the number of faces seen, the watchlist size, total alerts, positive alerts, positive interventions, incorrect alerts, incorrect interventions, arrests, other disposals and an incorrect alert rate. The whole set is also downloadable as a CSV file.

That is a serious level of disclosure. It allows anyone to calculate the ratio of faces scanned to arrests, watch how watchlist sizes move between deployments, and see which towns the vans return to. The force also publishes its policy, its procedure, its legal mandate, two stages of data protection impact assessment, an equality impact assessment, and the two independent evaluations of its algorithm.

Compare that against the position two years ago, when the same information would have required a freedom of information request and a wait. It is a genuine improvement, and it should be said plainly before anything critical is said about it.

The figures on a single page do not always agree

The forty deployments listed on the Essex page at the time of writing run from 4 April to 16 August 2026 and total 528,361 faces seen.

Elsewhere on the same page, in the section explaining the risk of being falsely identified, the force states that it has recorded four false positive alerts across 76 deployments and more than 108,000 faces scanned.

Those two figures cannot both describe the current position. The published register alone, covering less than five months, records roughly five times the number of faces in the second figure. The page does not date the smaller figure or say what period it covers, so a reader cannot tell whether it is a stale total left in place after the register was updated, or a count of something narrower.

The same section then gives the likelihood of a false positive as under 0.2 per cent, and separately as fewer than one false alert per 57,000 faces scanned. Four false positives in 108,000 faces would be closer to one in 27,000. Again, these may be measuring different things. The page does not say which.

None of this suggests the force is concealing anything. The register is right there, published voluntarily, in more detail than any regulator currently requires. But a headline accuracy figure that a reader cannot reconcile against the force's own data is a weaker piece of transparency than the register sitting above it.

What a register does not record

Essex suspended its live facial recognition deployments in March 2026, after two independent evaluations it had itself commissioned under the Public Sector Equality Duty returned conflicting findings on demographic performance.

The University of Cambridge study found the system statistically significantly more likely to correctly identify Black participants than participants from other ethnic groups, and suggested lowering the sensitivity threshold. National Physical Laboratory testing of the same algorithm found no statistically significant disparity at the thresholds tested. The force sought advice from the Police Chief Scientific Adviser and retained its threshold setting.

To the force's credit, its page sets out both studies, links to both reports, and explains the disagreement rather than quoting only the one that suits it. That is better practice than most.

What the page does not do is record that deployments stopped. It states that Essex Police has been deploying the technology since summer 2024, and the register begins on 4 April 2026, which is after the suspension ended. A reader arriving today would find no indication that use was ever interrupted, or why.

A register that shows only what happened, and never what stopped happening, records activity rather than history. The interruption is arguably the most informative event in the whole programme: it is the one occasion when published evidence changed operational behaviour.

Every force publishes something different

Surrey Police and Sussex Police run a joint programme, having bid together for two Home Office funded vans, first deployed in November 2025. They publish a deployment register, a standard operating procedure, and advance notice of where the vans will be. Deployments are authorised at superintendent rank or above.

Local reporting drawing on that register recorded 206,834 faces seen across fourteen deployments in the first six months, producing 26 alerts, no false positives and nine arrests. That is a usable evidence base, and it exists because the forces chose to publish it.

Merseyside Police publishes a facial recognition page with forthcoming deployment locations and a detailed set of questions and answers, but the outcome figures appear in individual news releases rather than in a single register. After a Birkenhead deployment in March 2026 the force reported five alerts, two arrests and no false alerts. Useful, but it has to be assembled release by release.

The Metropolitan Police published headline results from its fixed-camera pilot in Croydon, reporting that almost half a million faces were scanned with one false alert. The full evaluation report was not released alongside it. In response to a freedom of information request from Statewatch, the force indicated the detail would appear in an annual report expected around October 2026.

So the picture across four forces is four different formats, four different levels of detail, and four different definitions of what counts as a published result. There is no common schema, no shared vocabulary and no single place to look.

Shared equipment makes force counts misleading

There is a further complication for anyone counting deployments rather than reading them.

Merseyside's first deployment used vans supplied by the Home Office to Greater Manchester Police. Bedfordshire has lent its vans to Cambridgeshire for use in Peterborough. Surrey and Sussex share two vans between two forces under a single joint programme.

This matters for how the record is kept. Counting vans and counting forces produce different numbers, and counting forces without noting shared assets can turn one capability into two entries. It is one of the reasons the live facial recognition record on this site treats a jointly operated programme as a single deployment rather than splitting it, and why every entry on the deployment tracker carries the source it came from.

The regulator has already asked for better records

In August 2026 the Information Commissioner's Office published the outcomes of audits of five forces using facial recognition, issuing 107 recommendations, all of which were accepted in full or in part. Compliance was generally better for live facial recognition than for retrospective image searching, which attracts far less public attention.

Among the areas flagged for urgent attention were senior oversight, staff training, and comprehensive logging of facial recognition use. The recommendations were addressed to every force using the technology, not only the five audited. An audit of the Metropolitan Police is due later in 2026.

Logging is the point that connects most directly to these pages. An internal audit trail and a public register are not the same thing, but a force that cannot reconstruct its own use of the technology internally is unlikely to be able to publish a reliable account of it externally. Anyone reading a published register is, in effect, reading the visible end of a record-keeping system they cannot otherwise inspect.

The scale is about to change

The Home Office has committed funding for 40 additional live facial recognition units, taking the total available from around ten to around fifty, enough in principle for at least one per force in England and Wales. Alongside that sits £26m for a national facial recognition system, and £115m over three years for a National Centre for AI in Policing.

The government has also said it will create a public registry of the artificial intelligence being deployed by police forces, including the steps taken to assure reliability before operational use. No detail of that registry has appeared yet.

If it arrives and it is well built, it solves most of the problems described above at a stroke: one place to look, one format, one definition of a deployment. If it arrives and it records only that a force holds a capability, without the deployment-level figures Essex and Surrey already publish voluntarily, the national picture will be less informative than the local one it replaces.

How to read a force transparency page

Until then, these pages have to be read carefully rather than simply quoted. Some questions worth asking of any of them:

  • Does it publish individual deployments, or only totals?
  • Does the register give faces seen and watchlist size, or only alerts and arrests?
  • What is the earliest date in the register, and does that match how long the force says it has been using the technology?
  • Do the summary figures reconcile with the register on the same page?
  • Are periods when deployments stopped recorded anywhere?
  • Is the supplier named?
  • Are the underlying evaluations published in full, or only summarised?
  • Is the page dated, and is there any indication of when it was last updated?

Those questions are not hostile. Most of them are answered well by at least one force already, which is the strongest argument that they can be answered by all of them.

Publication is not the same as accountability

The forces publishing this material are, by any reasonable measure, doing more than they are required to. The regulatory framework for live facial recognition in England and Wales still rests on general data protection and human rights law rather than a dedicated statute, with new legislation promised but not yet passed.

What has happened instead is that a handful of forces have set a de facto standard, and it is a reasonably good one. The risk now is that the standard stays voluntary as the number of operators rises from around ten to around fifty. A voluntary standard is followed by the forces who were already inclined to follow it.

The gap between a force that publishes a full CSV of every deployment and a force that publishes nothing is not a gap in technology, funding or capability. It is a gap in what each force has decided the public is entitled to see.

Which raises the question the promised national registry will have to answer: if forty more forces are about to start scanning faces in town centres, is publishing the record going to be a requirement, or will it remain a choice?

More from the blog