Is it facial recognition that's the problem here, or the policy itself? In theory, they could hand out pictures of everybody who wasn't allowed in to the security staff and use low-tech facial recognition to enforce the same policy - assuming it was scalable, would it be OK then? I remember reading that IBM got into trouble when it first computerized its personnel files because some exec noticed that the computer could scan through all the personnel files and fire people who were close to retirement to save on paying out their pensions. It would have been prohibitively expensive to pay a person to do that, but with the computer, it was a quick SQL query (or whatever query language IBM used back then). The problem wasn't that the personnel files were computerized, it was that they were being used in a very evil way.