License plate readers offer a lesson for police AI: Verify before acting

James Leynse via Getty Images
COMMENTARY | Compliance, training and verification should be the floor, not the finish line, as law enforcement seeks to use new technologies.
An automated license plate reader helped Florida authorities recover a 13-year-old girl who had been abducted from her home. Elsewhere, officers have been accused of using the same kind of system to track intimate partners, while stale or incorrect information has contributed to dangerous stops.
More than 50 agencies or communities have canceled or suspended contracts, rejected proposals or deactivated cameras this year, and lawmakers in both parties are pursuing new restrictions. The same technology can save a life — and invade one — depending on the rules and the people behind it.
For mayors, city managers, police chiefs and state lawmakers, the choice cannot be simply to abandon useful technology or trust vendor safeguards. The harder operational question is deciding what must be in place before a digital alert can lead to a traffic stop, detention, arrest or use of force? An alert should prompt verification, not automatic enforcement.
License plate readers are not synonymous with generative AI, but their image recognition functions may use AI-based computer vision, while matching a plate number against a hot list can be a conventional database operation. They raise the same questions that broader police AI will intensify — accuracy, data quality, access, retention, sharing, auditing and human verification. The public is right to demand limits.
Compliance is the Floor
I learned that distinction through experience. Leading Newark, New Jersey’s implementation of a federal consent decree taught me that a camera does not create accountability. Policy, training, supervision, auditing, transparency and consequences do.
I saw the same principle tested in Minneapolis. An independent audit of the police department’s 2023–2024 license plate reader activity — a period covering my tenure as chief — found compliance with all state statutory requirements governing their use. Access was limited to personnel with investigative or analytical responsibilities, and required training was verified.
Auditors nevertheless recommended formally approved procedures for system access, retention, deletion and periodic review, along with documented reviews of vendor-assurance reports. Compliance is the floor, not the finish line.
Results from Los Angeles show why every failure point matters. During a two-month review, in-car license plate reader alerts led to 337 stolen-vehicle recoveries and 68 stops resulting in 74 arrests. Officers also acknowledged 161 alerts as correct plate matches even though later investigation found the vehicles were not stolen. A camera can misread; a hot list can be stale; a person can enter the wrong plate; an officer can fail to corroborate. The origin of the error changes, but the government’s duty does not.
Responsibility must also be shared. When immigration-related searches drew scrutiny, Flock Safety said customers owned the data and controlled its use and sharing. That is only part of the answer. Chiefs are accountable for agency policy and officer conduct; city managers and councils for contracts and oversight; vendors for product design, security defaults and auditability; lawmakers for enforceable limits.
Flock has since recommended shorter retention and announced requirements for case codes and audit monitoring, along with automatic suspensions for abnormal searches pending review. Those are meaningful controls, but product settings cannot substitute for law, effective supervision or independent review.
AI could help agencies organize evidence, search video, connect cases and reduce paperwork. It could also magnify bad data and weak policy at far greater speed and scale. Because networked systems cross jurisdictional lines, state law should establish a governance floor while local governments retain authority to adopt stricter limits and write them into contracts.
Verification failures do not require AI. Recently released findings from San Francisco’s police watchdog determined that officers used unreasonable and excessive force after one officer manually entered the wrong plate and failed to verify the result before breaking the driver’s window. It was not an automated reader misread or an AI failure; it was a human data entry problem and a failure to verify.
Five Safeguards Before Action
State and local leaders should require five safeguards:
- Define the use. Authorize specific purposes and expressly prohibit others.
- Test independently. Validate performance and failure modes under real-world conditions before deployment and after material updates.
- Control the data. Minimize retention, sharing and access, and put vendor-assurance and deletion requirements into contracts.
- Verify before action. Corroborate an alert before any stop, detention, arrest or use of force.
- Audit and enforce. Log every search, review records independently, report results publicly and impose consequences for misuse.
Properly governed technology can make some policing tasks faster and more precise. It cannot make policing legitimate. Legitimacy comes from public rules, independent scrutiny and accountability. Public safety and civil liberties are not competing objectives — policing in democracy requires both. Every digital alert must remain a lead, and every consequential decision must remain answerable to the public.
Brian O’Hara served as the 54th Chief of the Minneapolis Police Department and as a Deputy Mayor and Public Safety Director in Newark, New Jersey. He is a Distinguished Fellow at the Rutgers Center on Public Security and principal of the O’Hara Leadership Group.




