Flock Safety's 'Marauder's Map' Surveillance: Edge ML, Legal Loopholes, and the Fight for Privacy

Flock Safety, a U.S. technology company valued at several billion dollars, operates an extensive network of AI-powered automated license plate readers (ALPRs) across thousands of communities. Its flagship Falcon cameras use an edge-ML pipeline in which on-device neural networks identify and classify vehicle attributes such as make, model, color, dents, rims, roof racks, and distinctive stickers, creating what the company describes as a vehicle fingerprint. Rather than continuously uploading raw video, the system extracts structured metadata and transmits it to Flock’s cloud platform, where it can be used to build a searchable database of vehicle sightings. Law enforcement agencies can use this information to investigate vehicle movements, compare sightings against hot lists for stolen vehicles and other alerts, and receive notifications when vehicles matching specified criteria are detected. In effect, the system creates a large-scale searchable map of vehicle movements across participating communities. Aggregated historical data can also reveal patterns associated with where vehicles regularly appear, including residential areas, workplaces, and other frequently visited locations.

The widespread deployment of Flock’s technology raises significant questions about privacy and the Fourth Amendment. One important legal concept is the third-party doctrine, which developed through several U.S. Supreme Court decisions in the 1970s. Under this doctrine, information voluntarily shared with a third party may receive less Fourth Amendment protection because individuals are generally considered to have a reduced expectation of privacy in information they disclose to others. However, subsequent Supreme Court decisions—most notably Carpenter v. United States in 2018—have placed important limits on applying this principle to certain forms of extensive digital location data. Consequently, describing the third-party doctrine simply as a blanket authorization for warrantless government access is misleading.

Flock’s systems have also attracted scrutiny over potential misuse and inadequate controls. Investigations and audits have documented instances in which law-enforcement personnel used ALPR systems for purposes unrelated to legitimate investigations, including searches involving personal relationships and immigration enforcement. These cases have fueled concerns about whether sufficiently strong access controls, auditing, and accountability mechanisms are in place when agencies deploy large-scale vehicle surveillance systems.

Public opposition has consequently grown in some communities, with certain cities reconsidering or ending their contracts with Flock Safety and civil-liberties organizations challenging the broader use of automated license-plate surveillance. Flock has continued expanding beyond ALPRs into areas such as gunshot detection, drones, and its broader Flock OS platform. Its relationship with Amazon’s Ring has also attracted scrutiny as questions about privacy and law-enforcement access to surveillance data have intensified.

In response to the expansion of these systems, community-led initiatives such as DFlock have attempted to document and map the locations of Flock cameras. These projects represent an interesting inversion of the surveillance relationship: citizens are using technology and crowdsourced information to make the surveillance infrastructure itself more visible. The result is a growing debate not only about what AI-powered surveillance systems can do, but also about who should be allowed to operate them, what information they should retain, how that information can be accessed, and what safeguards should exist against abuse.