Rite Aid banned from using AI facial recognition for five years
ftc.gov
ftc.gov
Trying to understand what to look for..
I read about it a couple years ago. Anyone has a link to that story?
There's also a bunch of "enrollment" store employees did that they're kind of murky on. The whole thing is a shit show from what I read under "Rite Aid’s Enrollment Practices":
21. In connection with its use of facial recognition technology, Rite Aid created, or directed its facial recognition vendors to create, an enrollment database of images of individuals whom Rite Aid considered “persons of interest,” including because Rite Aid believed the individuals had engaged in actual or attempted criminal activity at a Rite Aid physical retail location or because Rite Aid had obtained law enforcement “BOLO” (“Be On the Look Out”) information about the individuals. Individual entries in this database are referred to herein as “enrollments.” Enrollments in the Rite Aid database included images of the individuals (“enrollment images”) along with accompanying information, including, to the extent known, individuals’ first and last names, individuals’ years of birth, and information related to criminal or “dishonest” behavior in which individuals had allegedly engaged.
22. Rite Aid regularly used low-quality enrollment images in its database. Rite Aid obtained enrollment images by, among other methods, excerpting images captured via Rite Aid’s closed-circuit television (“CCTV”) cameras, saving photographs taken by the facial recognition cameras, and by taking photographs of individuals using mobile phone cameras. On a few occasions, Rite Aid obtained enrollment images from law enforcement or from media reports. In some instances, Rite Aid employees enrolled photographs of individuals’ driver’s licenses or other government identification cards or photographs of images displayed on video monitors.
23. Rite Aid trained store-level security employees to “push for as many enrollments as possible.” Rite Aid enrolled at least tens of thousands of individuals in its database.
24. It was Rite Aid’s general practice to retain enrollment images indefinitely.
Reuters has more details on the cameras themselves: https://www.reuters.com/investigates/special-report/usa-rite...> The cameras were easily recognizable, hanging from the ceiling on poles near store entrances and in cosmetics aisles. Most were about half a foot long, rectangular and labeled either by their model, “iHD23,” or by a serial number including the vendor’s initials, “DC.” In a few stores, security personnel – known as loss prevention or asset protection agents – showed Reuters how they worked.
> The cameras matched facial images of customers entering a store to those of people Rite Aid previously observed engaging in potential criminal activity, causing an alert to be sent to security agents’ smartphones. Agents then reviewed the match for accuracy and could tell the customer to leave.
The FTC report also says that while they employees were sent details used to confirm the match they were never sent confidence scores while any and all matches were sent to employees as alerts.
Especially in small theft incidents where police can't be bothered to intervene (eg. Stole $15 of stationary), it makes sense to have this system automatically collate thefts by the same criminal to eventually do a prosecution.
Remember that browser cookies and software was once used for good and legitimate purposes. But since there is no (enforced) legislation against their misuse, online stalking and spyware has become the norm.
https://www.nytimes.com/2023/01/16/technology/madison-square...
Rite Aid deployed facial recognition systems in hundreds of U.S. stores - https://news.ycombinator.com/item?id=23975255 - July 2020 (293 comments)
It would be great to get the list of those service providers and anyway I wouldn't want to be the C*O with the responsibility of monitoring them and be sure that they are not fooling me with false statements of compliance.
Add the remediations and maybe it costs less to lose some items from the shelves.
Nothing will change until there's real personal repercussions.
I was at Target the other day buying Command hook adhesive strips. The price in the Target app on my phone was $4.49 with a disclaimer “when purchased online”, and the price in the store was $3.99.
I can easily see businesses giving different prices or coupons resulting in different prices to different people based on what they think they will be willing to pay. My friend already gets different Target Circle rewards than me, so I think being able to better price segment customers is at least partly the goal.
Here in California, one such state, whenever I go to a Walgreens, and this sounds like hyperbole, but I assure you it is not, at least one person shoplifts and just walks out of the store without a hint of hurry in their step. The worst occasion I saw four people just straight up come in, help themselves, and walk out.
These aren't even people who visibly seem to be short of money that they could spend on these items, they're just taking advantage of a lax regulatory environment. Which, perhaps some stores have technical workarounds that they can afford, but what this really does is kill small businesses and locally owned stores entirely.
> In a January earnings call, Walgreens' CEO told investors that "maybe we cried too much" when reporting rising shoplifting the previous year.
> NRF data from its annual Retail Security Survey indicates that the percentage of shrink attributed to external theft, including organized retail crime, has largely remained around 36% since 2015.
There is a Walgreens in Chicago that was recently redesigned into exactly that due to the amount of theft going on.
Not a ban. They'll have some oversight, and a little slap on the wrist.
Boo hoo. This isn't a win for consumers. This is a win for Rite Aid.
> IT IS ORDERED that Respondents, in connection with the activities of any Covered Business, are prohibited for five (5) years from the effective date of this Order from deploying or using, or assisting in the deployment or use of, any Facial Recognition or Analysis System, whether directly or through an intermediary, in any retail store or retail pharmacy or on any online retail platform.
> IT IS FURTHER ORDERED that Respondents, in connection with the operation of any retail store or retail pharmacy or online retail platform by any Covered Business, must not use any Automated Biometric Security or Surveillance System in connection with Biometric Information collected from or about consumers of such retail store, retail pharmacy, or online retail platform, unless ...
So, it is a ban on facial recognition, and additionally any use of biometric information is subject to this bureaucracy.
> I. Use of Facial Recognition or Analysis Systems Prohibited
> IT IS ORDERED that Respondents, in connection with the activities of any Covered Business, are prohibited for five (5) years from the effective date of this Order from deploying or using, or assisting in the deployment or use of, any Facial Recognition or Analysis System, whether directly or through an intermediary, in any retail store or retail pharmacy or on any online retail platform.
https://www.ftc.gov/system/files/ftc_gov/pdf/2023190_riteaid... (PDF, page 14)
So it's not that the data was wrong, just not properly scoped to stores in a given city/region? Or was it misidentifying people because they looked like someone in the database?
The complaint has more specific details:
> a. In numerous instances, Rite Aid’s facial recognition technology generated match alerts that were likely false positives because they occurred in stores that were geographically distant from the store that created the relevant enrollment. For example, between December 2019 and July 2020, Rite Aid’s facial recognition technology generated over 5,000 match alerts in stores that were more than 100 miles from the store that created the relevant enrollment. ...
> b. Some enrollments generated high numbers of match alerts in locations throughout the United States. For instance, during a five-day period, Rite Aid’s facial recognition technology generated over 900 match alerts for a single enrollment. The match alerts occurred in over 130 different Rite Aid stores (a majority of all locations using facial recognition technology), including hundreds of alerts each in New York and Los Angeles, over 100 alerts in Philadelphia, and additional alerts in Baltimore; Detroit; Sacramento; Delaware; Seattle; Manchester, New Hampshire; and Norfolk, Virginia. In multiple instances, Rite Aid employees took action, including asking consumers to leave stores, based on matches to this enrollment.
> c. Between December 2019 and July 2020, Rite Aid’s facial recognition technology generated over 2,000 match alerts that occurred within a short time of one or more other match alerts to the same enrollment in geographically distant locations within a short period of time, such that it was impossible or implausible that the same individual could have caused the alerts in the different locations. For example, for a particular enrollment image that was originally captured at a Los Angeles store, Rite Aid’s facial recognition technology generated over 30 match alerts in New York City and Philadelphia between February 2020 and July 2020. Each of the New York and Philadelphia matches occurred within 24 hours of a match alert in a California store and thus was likely a false positive.
I like the outcome but i don’t understand the statutory or constitutional authority involved here
why is the FTC doing this as opposed to… some other agency?
Either this one is an overreach, or I can think of a lot of other normalized moderately inconvenient private business practices to sic the FTC on
I disagree with the parent comment.
I don't think they appreciate the scope of change over the last 20 years. From mobile, tablet and headset interfaces, to social media, to infrastructure (ADSL never mind fibre), WiFi, cell tech. Voice assistants, chatgpt, I could go on.
Crumbs, the Web didn't even have ajax back then.
We're not even close to duplicating that scale of change over the next 5 years.
First mover disadvantage.
By then everyone else will have been using it for a while.
[0] https://www.wired.com/story/when-it-comes-to-gorillas-google...
The problem with coming up with reasonable ones for this sort of thing is that the customers are in a public place. Are businesses not allowed to record on their property and analyze those recordings? What about a security guard spotting someone who shoplifted last week? Or a business tracking credit card numbers across stores?
In order for things to be different, the policy makers need reasons to draw lines between this and examples like the above that most people would agree businesses can do. Here, accuracy helped be that reason, but it’s only a matter of time before the models are more accurate.
Quite a bit exists and caters to protect those who own things in this country.
Is your concern that they're recording people in the store? Are there non-clown show countries where they were forward thinking and put a stop to the collection of that biometric data decades ago? Or that they're looking at the recordings? Comparing the recordings to other recordings? Like... what's the too far step that America needs to ban to not be a clown show?
Recording via CCTV for security purposes is not the same as using facial recognition technology. Facial recognition technology produces data which may or may not be shared/sold to unknown (to me) third parties.
Do something for good.
Stronger federal and state privacy laws are probably needed to curb the current abuses.
https://web.archive.org/web/20231220025346/https://www.ftc.g...
https://webcache.googleusercontent.com/search?q=cache:https:...
That said:
Rite Aid will be prohibited from using facial recognition technology for surveillance purposes for five years to settle Federal Trade Commission charges that the retailer failed to implement reasonable procedures and prevent harm to consumers in its use of facial recognition technology in hundreds of stores.
makes me happy we (Australia) put a temporary stop at least on the roll out of facial recognition of "untrustworthy shoppers" by Bunnings (Australian Hardware store with a sideline in sausages). FTC says Rite Aid technology falsely tagged consumers, particularly women and people of color, as shoplifters;
It seems likely that the same base level issues exist across most implementations of (alleged) "bad actor" recognition systems.Also - very strange, I'm in AU too. The site's working for me now though.
Talk about kicking someone while they’re down.