BetaMaShop is in public beta. We improve it continuously, and your feedback shapes what comes next.
MaShop/Blog/Industry/They Offered to Match Every Face That Walks In
IndustryAugust 31, 2026
Read · 5 min
facial recognition · biometrics

They Offered to Match Every Face That Walks In

A camera vendor will tell you the matching is compliant. The rule that actually stops a shop is not the one in the headlines, and it differs by region.

The pitch is always the same and it is always persuasive. Your camera system already records everyone who walks in. For a small monthly fee the vendor will add matching, so the software recognises the four people who have stolen from you before and sends a notification to the till. No extra hardware. It works from the footage you already have.

Before anything else, one fact worth holding onto: the only retailer in this story that got into serious trouble did not get there through a privacy law. It got there because the matching was wrong about real customers, repeatedly, and staff acted on it.

Key takeaways
  • The EU AI Act does not ban a shop from matching customer faces. Its real time biometric identification prohibition is aimed at law enforcement, a distinction most coverage collapses.
  • What actually blocks it in Europe is data protection law, where biometric data used to identify someone is a special category that is prohibited unless a narrow condition applies.
  • The AI Act does prohibit things a vendor might sell you: inferring race or beliefs from faces, building a database by untargeted scraping, and inferring your staff's emotions at work.
  • In the United States there is no general federal rule, and the binding constraint is state biometric law. Illinois attaches damages of 1,000 dollars for a negligent violation and 5,000 for a reckless one, enforceable by the customer.
  • The FTC banned a pharmacy chain from surveillance facial recognition for five years in December 2023, on unfairness grounds, after false matches led staff to search and eject innocent shoppers.
  • False positives were more common in that chain's stores in plurality Black and Asian communities, which turns an accuracy problem into a discrimination problem.

Does the EU AI Act ban facial recognition in shops?

No, and the belief that it does has led plenty of European retailers to relax about a system that remains unlawful for a different reason. Getting this right matters, because the two regimes fail in different places and the compliance work is not the same.

Read what Article 5 of the AI Act actually prohibits. The much quoted ban on real time remote biometric identification in publicly accessible spaces is written for law enforcement, and even there it carries exceptions for things like searching for a victim or an imminent threat, subject to judicial authorisation. A shop is not law enforcement, so that paragraph is not the one that decides your case.

Three other prohibitions in the same article are aimed squarely at products a vendor may try to sell you, and these do apply to a private business. Biometric categorisation systems that classify people by their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation are prohibited outright. So is creating or expanding facial recognition databases through the untargeted scraping of facial images from the internet or CCTV footage. So is using AI to infer the emotions of a person in the workplace, with narrow medical and safety exceptions.

Note

That third one catches more shops than the others and almost nobody expects it. It is about your staff rather than your customers. A workforce analytics feature that scores whether an employee looks engaged, stressed or happy on camera sits inside the workplace emotion prohibition. If a vendor demonstrates that alongside the security matching, the demonstration is the compliance problem.

What actually blocks it in Europe, then?

Data protection law, and specifically the rule that treats a faceprint as a category of data you are presumed not to be allowed to process at all. This is the constraint that matters and it existed years before the AI Act.

Under Article 9 of the GDPR, biometric data processed for the purpose of uniquely identifying a natural person sits alongside health data, racial or ethnic origin and religious belief in the special categories. Processing it is prohibited unless one of the conditions in Article 9(2) applies. The condition a shop would have to reach for is explicit consent, given for one or more specified purposes.

Now try to make that work at a shop door. Explicit consent has to be freely given, specific and informed, and it has to be as easy to withdraw as to give. A sign in a window saying that entry implies agreement is none of those things. Neither is a system that scans everyone and asks nobody, which is what the vendor's product does by design, since it cannot know in advance which face belongs to a repeat thief.

Diagram comparing what stops a shop matching customer faces in the EU and UK against the United States, covering data protection, consent and private lawsuits

That is the whole European answer, and it is why the question of whether the AI Act bans it turns out to be a distraction. The AI Act adds specific product prohibitions. Data protection law removes the lawful basis for the core use case. A vendor who answers the first objection has not touched the second.

What about the United States?

No general federal rule, a patchwork of state biometric statutes reaching any retail business, and one crucial structural difference: in some states the person who can sue you is the customer, not a regulator.

Illinois is the state that matters most, because its biometric statute carries a private right of action and real money attached to it. As King and Spalding's summary of the 2024 reform sets out, the law requires consent before a private entity collects or discloses biometric information, and requires published policies covering use, retention and destruction. Liquidated damages run at 1,000 dollars for a negligent violation and 5,000 dollars for an intentional or reckless one, plus attorneys' fees.

Those numbers used to be far more dangerous than they look. Every individual scan or transmission triggered separate liability, so a system that scanned the same employee twice a day for two years produced an arithmetic that ended companies. Senate Bill 2979, effective 2 August 2024, changed that: collecting the same biometric identifier from the same person by the same method is now a single violation with at most one recovery.

The reform reduces the exposure without removing it, and the consent requirement is untouched. A shop scanning ten thousand customers who never agreed still faces ten thousand claims, one per person, at a thousand dollars each on the gentlest reading. That is a different kind of risk from a regulator's fine, because it does not depend on a regulator deciding to look.

EU and UKUnited States
What the faceprint triggersSpecial category data, presumed prohibitedNothing federally, state biometric law where it exists
The realistic lawful basisExplicit consent, impractical at a shop entranceWritten notice and written release before collection
Extra product bansAI Act Article 5 on categorisation, scraping and workplace emotionNone equivalent, FTC unfairness authority instead
Who brings the claimA data protection regulatorThe individual, in Illinois, plus the FTC
What it costsAdministrative fines and an order to stop1,000 dollars negligent or 5,000 reckless per person, plus fees

What actually happened to the retailer that tried it?

It was banned from the technology for five years, and the case was not brought under any biometric privacy statute. That detail is the most useful thing in this article for anyone outside Illinois or Europe, because it shows the exposure does not depend on having a specific law about faces.

The Federal Trade Commission announced the order on 19 December 2023. According to the Commission's own account of the case, the pharmacy chain deployed facial recognition across hundreds of stores between 2012 and 2020 without reasonable safeguards, and the system falsely flagged consumers as matching someone previously identified as a shoplifter.

What happened next is the part every shop owner should sit with. Staff acted on those false flags. They followed people around the stores, searched them, ordered them to leave, called the police to confront or remove them, and publicly accused them. Not shoplifters. People the software got wrong.

The FTC also found that the technology was more likely to generate false positives in stores located in plurality Black and Asian communities than in plurality White ones. A false positive rate that varies by neighbourhood is not a technical footnote. It converts an accuracy problem into a discrimination problem, and it is the reason the Commission reached for its unfairness authority rather than waiting for a privacy statute.

The obligations in the order read like a specification for doing it properly, which is useful even if you never touch the technology. Delete the images and make third parties do the same. Tell people when their biometric information goes into a database and when action is taken against them by an automated system. Investigate and answer complaints in writing. Post clear notice in stores. Run a data security programme with independent assessments and annual certification by the chief executive. Stop using the system entirely if the risks cannot be controlled.

Is there a version of this that is actually lawful?

Yes, and it is the version nobody pitches, because it is narrower and sells for less. The lawful shape is face matching against people who chose to enrol, for a purpose they understood, with a way out. Everything difficult about the technology comes from applying it to people who did none of those things.

The distinction is easiest to see in the settings where it already works. A gym that offers members entry by face, where joining is voluntary, the alternative is a card, and deleting the faceprint takes one request. A workplace door where staff opted in and a fob still works for anyone who did not. A members' club, a locker system, a self service collection point. In each case the person is identifiable, present and actually asked, which is what explicit consent means in practice rather than in a privacy notice.

Card listing three conditions that make face matching lawful in a business setting, covering voluntary enrolment, a non biometric alternative and easy deletion

Two design details separate a defensible enrolment scheme from a decorative one. The first is that the alternative has to be genuinely equivalent. If the face queue moves and the card queue does not, the consent stops being freely given, because you have priced the refusal. The second is that deletion has to actually delete, including from any vendor system and any backup the vendor holds, which is a contract question rather than a technical one and belongs in the agreement before you sign it.

The awkward truth is that this lawful version does nothing about shoplifting, which is what the vendor was really selling. A thief does not enrol. The enrolment model works for access and convenience, and it is useless for security against people who have every reason to avoid it. Any pitch that presents one as a stepping stone to the other is describing two different systems under one price.

There is a middle option worth knowing about, which is matching without identifying. A system that counts how many people entered, how long a queue is, or which aisle is busy does not need to know who anybody is, and if it is built so that no faceprint is stored or compared against a database, it sits outside the special category rules entirely. That is a real product category and a genuinely useful one for a shop working out staffing. The question to ask a vendor is blunt: does anything persist that could be used to recognise this person tomorrow. If the answer is no, most of this article stops applying. If the answer is yes, all of it applies, whatever the feature is called on the pricing page.

What should you actually do when the vendor calls?

Ask four questions, in this order, and let the answers decide it. Each one is answerable in a sentence by a vendor who has done the work and evaded by one who has not.

What is my lawful basis, in my jurisdiction, in writing? Not whether the product is compliant, which is a claim about the software. Whether you, processing faces in your shop, have a basis. In Europe the honest answer is usually that you do not have a workable one. A vendor who cannot name the basis and the article it comes from is selling you their risk.

What is the false positive rate, measured on whom? A rate quoted without a population is not a rate. Ask specifically whether it was measured across skin tones and lighting conditions resembling your actual door, and ask what happens to the number in poor light, which is what a shop entrance in winter provides.

What is my staff instructed to do on a match? This is the question that decides whether you end up in the Rite Aid position, and it is entirely within your control. A match that triggers discreet observation is a very different business from one that triggers a search or an ejection. Write the instruction down before the system is switched on, because it will be written either way, and afterwards it gets written by whoever was on shift.

Who is on the database, how did they get there, and how do they get off? A list assembled from previous incidents by staff judgement is a list of accusations. If there is no route to challenge an entry and no expiry, you have built a permanent private register of people you have decided are thieves, which is a thing you will eventually have to defend.

If those answers are unsatisfying, the alternatives are duller and considerably safer. Better lighting, a member of staff near the door, till level loss reporting, and stock controls address the same loss with none of the exposure. Age checks are a genuinely different case with its own rules, which we worked through in our piece on what an AI age estimate can and cannot be relied on to do.

Where does this sit in the rest of the AI rules?

Near the top of the risk pile, which is exactly where you would expect a technology that identifies people without asking them. Biometric identification is one of the areas the AI Act treats as high risk when it is not prohibited outright, which brings documentation, human oversight and record keeping obligations along with it.

If you are working out which parts of the AI Act reach your business at all, the obligations sort more cleanly than the headlines suggest, and we mapped them in the AI Act compliance map, obligation by obligation. The timing question is separate and equally practical, since the prohibitions and the high risk rules arrive on different dates, which we set out in the AI Act as a decision tree and a timeline.

Whatever you decide, write it down. A short internal position saying which AI features you permit, which you refuse and why is worth more than any vendor assurance when somebody asks you in two years what you were thinking. Ours is public, and the structure is copyable if you need somewhere to start: our own policy on how we use AI exists for the same reason.

The camera vendor's pitch will remain persuasive because the underlying frustration is real. Theft costs small shops money and the footage genuinely is already there. What the pitch leaves out is that the system's mistakes land on the innocent, that the mistakes are not evenly distributed, and that in most of Europe there is no lawful basis to run it at all. Those three facts do not appear on the pricing page. They are, however, the entire subject.

Comments 0

0 / 4000Your email stays private.
No comments yet. Be the first.

Keep reading picked for you.

Describe it. MaShop builds it.

Commerce apps and websites from one sentence. No card to start.

Start building