Regulators and inspectorates pull in opposite directions on facial recognition
The ICO found police facial recognition governance needs urgent work. Two days later, Scotland's chief inspector urged faster adoption. Both landed in the same week.
Two documents published within 48 hours of each other set out the week's central tension in British policing. On 18 August the Information Commissioner's Office published the conclusions of a year spent auditing how five police forces use facial recognition, and found governance wanting. On 20 August Scotland's chief inspector of constabulary published his annual report and urged Police Scotland to adopt the same technology faster.
Neither is wrong. But read together they capture where this subject has arrived: the regulator asking whether forces can be trusted to run these systems properly, and the inspectorate asking why they are not running them already.
The ICO finds a mixed picture, and an unexpected weak spot
The ICO audited five forces between June 2025 and March 2026: South Wales and Gwent, Essex, Leicestershire, West Yorkshire and Greater Manchester. It issued 107 recommendations across them. Every one was accepted or partially accepted.
There was real assurance in the findings. Forces generally had a lawful basis identified and documented. They were careful not to collect more data than a deployment needed. Breach reporting procedures were in place.
The more interesting finding is the one that runs against the grain of public debate. Compliance was generally higher for live facial recognition than for retrospective searches. Live deployment is the version that attracts the cameras, the protests and the court cases. Retrospective searching, where an officer runs an image against a database after the fact, happens quietly and at far greater volume. On the ICO's evidence it is also the version forces are handling less well.
Four areas were flagged for urgent attention: senior oversight and staff training, record-keeping on where personal data comes from and who it is shared with, controls on the sources and retention of images used for retrospective searches, and checking that systems are accurate and that steps are taken to reduce the risk of bias.
The regulator was explicit that these findings are meant for every force using the technology, not only the five audited. It is working with the National Police Chiefs' Council to push consistent improvement, and will share the findings with Police Scotland and the PSNI. Its audit of the Metropolitan Police, by some distance the largest user, is still to come later this year.
The algorithm behind the national database is still being replaced
The ICO also restated something that deserves more attention than it gets. Testing by the National Physical Laboratory found bias in the algorithm used for retrospective facial recognition searches against the Police National Database, increasing the likelihood of incorrect matches for people in some demographic groups.
The Home Office and the NPCC have put mitigations in place, including staff training, oversight reporting and equality impact assessments, and plan to replace the algorithm. The ICO says it is monitoring cases of detriment from incorrect matches and reserves the right to take further regulatory action.
That is a regulator saying, in careful language, that a national system is running on an algorithm known to be biased while its replacement is arranged. Our page on retrospective facial recognition tracks that database and the searches run against it.
Scotland is asked to move faster
In his HMICS Annual Report 2025-26, HM Chief Inspector of Constabulary Craig Naylor told the Scottish Government and Police Scotland to "be ambitious" about operational technology. Drones and facial recognition, he argued, could reduce threats from high-risk sex offenders, organised crime groups and violent offenders.
His framing was direct: the challenge is not whether to adopt these technologies, but how quickly they can do so safely, ethically and effectively.
The specific application he raised is football disorder. Pitch incursions and pyrotechnics have marred a series of fixtures over two seasons, and an independent review for the Scottish FA described clashes at a Rangers and Celtic cup tie as a near miss. Naylor suggested facial recognition could enforce football banning orders by identifying people who should not be at a match.
Police Scotland does not currently use live facial recognition. It has been deliberately slow, running a National Conversation on the technology in 2025 and consulting on a joint biometrics strategy with the Scottish Police Authority between January and March this year. That consultation drew 1,040 responses and found greater public concern about live facial recognition than about other biometric technologies.
Separately, and reported this week, the Scottish Institute for Policing Research is funding an academic study into how live facial recognition should be governed, led by researchers at Stirling and Edinburgh. It runs until spring 2027.
So Scotland now has an inspectorate urging speed, a regulator urging care, a public consultation showing unease, and a research project that will not report for another 18 months.
Australia's trial produces its first numbers
Western Australia Police became the first Australian force to use live facial recognition on the public when its five-month trial began in June, using NEC's NeoFace M40 from cameras on marked police vans.
The early figures are worth recording carefully. In the first week the system scanned more than 130,000 faces around Perth and Fremantle. Reporting indicates those scans generated 33 alerts, which led to 18 arrests and two false alerts.
Two false alerts against 130,000 faces is a low error rate by any measure. It is also two people wrongly flagged to police in seven days, and the ratio matters as much as the rate: 130,000 people had their faces converted to biometric templates so that 18 arrests could be made. Whether that is proportionate is a policy question rather than a technical one, and it is not resolved by improving the algorithm.
Melbourne Law School's Jake Goldenfein noted the familiar concern that these systems have historically performed worse for people of colour and for women, and worse still for women of colour, because of what the training data contained.
Vendor benchmarks improve, which is not the same as deployments improving
Idemia Public Security announced top results in the latest round of NIST's Face Recognition Technology Evaluation for one-to-many identification. Its algorithm placed first across the tested gallery sizes in frontal mugshot matching, including NIST's largest evaluation against a gallery of 12 million identities, and recorded a false negative identification rate of 1.11 per cent against that gallery.
NIST's evaluation is independent and the results are real. The announcement is the vendor's own, and it is worth separating the two. Idemia supplies police biometric systems in several countries, and our page on the company records where.
The gap this points at runs through the whole week. Laboratory accuracy on controlled mugshot-to-mugshot comparison keeps improving. The ICO's audits were not about accuracy. They were about oversight, training, record-keeping and retention, none of which a better algorithm fixes.
What to watch
The ICO's audit of the Metropolitan Police is due later this year and will be the most consequential of the six, given the Met's deployment volume.
The Home Office consultation on a new legal framework for police use of biometrics closed in February. The government's response has still not been published, more than six months on. Until it is, the largest facial recognition deployment in Europe continues to operate on force policy rather than statute.
You can follow the systems mentioned here on our deployment tracker, which records who uses what, on what legal basis, and under what oversight.