All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Flock’s AI-powered license plate reader network is already under fire for creating a mass surveillance system across the US. But a new report from Wired has revealed that the company is taking its surveillance capabilities a step further with a new AI tool called OS Investigate.[1]
The tool can analyze data from Flock’s vast camera network, search for vehicles based on behavior and location rather than a specific license plate or crime, and link that information with police records and commercial databases. It can even identify vehicles that frequently appear together and build profiles around their movements.Jay Stanley, a senior police analyst, said that such aggressive deployment of AI by Flock leaves very little space left between what can be done and what is being done, in some ways similar to China.
That could turn ordinary driving habits into searchable police intelligence, allowing authorities to identify, track, and profile people who may have done nothing wrong, while exposing highly sensitive information such as their addresses, phone numbers, and relatives.
Here’s everything you need to know about Flock’s new AI tool, how it works, and why it could be a privacy nightmare.
What’s stopping Flock’s AI from being abused
Flock’ed by controversies
Flock is just one part of a growing car-based surveillance network
Flock faces growing pushback over surveillance
Bottom line
How Flock’s AI can track people without a name or license plate
Flock describes itself as a simple camera-based data collection company that photographs a license plate and converts it into text, allowing officers to check it against police watchlists.
However, Wired’s research found that Flock’s new AI tool completely inverts this workflow.
Now, an officer can supply a plate, a behavior pattern, or a time window, and the system can return people who fit those criteria, requiring no name or license plate, or even a specific crime, to start with.
The tool, called “OS Investigate” but previously known as “NightShift,” draws its data from Flock cameras that log drivers’ movements across more than 6,000 communities.
Wired found around 45 tools giving the AI access to various forms of data, such as plate scans, arrest records, ballistic results, case files, camera metadata, as well as commercial databases, which could contain personally identifiable information such as Social Security numbers, phone numbers, and even birth dates.
The privacy-invasive prompts behind Flock’s AI
The system has 69 pre-built prompts, which officers can select, review, and edit, while also allowing them to compose their own prompts to get the results they want.
Wired’s report reveals various prompts that could seriously compromise people’s privacy. For instance:
- One pre-written prompt could find witnesses based on which vehicles were spotted the most in a given neighborhood over a particular period of time.
- Another prompt could fetch data on everyone arrested more than twice in two years for any offense except narcotics and generate background workups of the top three people in the selected dataset.
- A workup, as defined by Flock, is a one-command background check that could reveal details such as a person’s name, birth date, prior suspect listing, online accounts, and phone numbers associated with the vehicle’s driver.
- 19 of the prompts are designed to hunt for behavioral patterns, while 14 require no plate, name, or physical description at all. An officer simply provides a location, time window, and behavior, and the AI does the rest.
- One group of these prompts could flag vehicles that visit three or more retail stores in three days, or multiple gas stations or banks in a given period of time, none of which are tied to any specific incident
- The system also comes with a filter that could exclude commercial vehicles such as work vans, buses, or trailers, so that delivery drivers are filtered out of any such data.
- Another prompt can track cross-city travel, spotting cars that left a city and returned within a week, or those making repeated round trips to the same destination over a given period of time, such as two weeks.
It can track your movements and identify your associates
What’s more concerning is that the system can plot a vehicle’s movements and identify its “top three associates,” using advanced algorithms and machine learning.
This flags vehicles that appear at the same cameras within a two-minute window of the target vehicle and returns results with a “confidence threshold” set at a default of 0.75.
More open-ended prompts allow officials to search based on physical descriptions alone, including characteristics such as sex, race, ethnicity, height, weight, build, scars, marks, and tattoos.
For example, an officer could search for matching descriptions such as a male, 6 feet tall, wearing a black hoodie with a forearm tattoo, near a chosen location or within a radius drawn on a map.
Jay Stanley, a senior policy analyst, said that such aggressive deployment of AI by Flock leaves very little space left between what can be done and what is being done, in some ways similar to China.
Noel Picardo, an ex-police officer in Rhode Island, said, “I don’t know how anyone can argue against the idea that Flock literally tracks people.”
What’s stopping Flock’s AI from being abused
Although Flock argues that there are several guardrails around this new AI system, they seem to be there only for namesake.
For instance, officers are asked for a justification before running a search. But there are no specific content requirements for that justification. One could put just any random reason and get along with the process.
In a review by the Electronic Frontier Foundation, 20% of the 12 million logged searches on Flock had only vague justifications, such as “suspect” or “investigations.” Despite this history of vague search justifications, there doesn't appear to be evidence that OS Investigate has significantly stronger safeguards.
Plus, officers would also need to enter a case number to run a search. However, the only requirement is that the number should be at least three characters, with no indication that it’s checked against a known database.
Wired couldn’t determine whether Flock performs any additional checks on its servers after the information is submitted.
Flock’s AI camera data has already seen instances of misuse in the past. For instance, a Texas officer ran a search across 83,000 cameras to find a woman who had undergone a self-administered abortion.
And a recent Washington Post analysis found 50 officers misusing the plate-reader system to track people, with 26 of them trying to track girlfriends, wives, or exes.
The company has said that it will address these concerns and add new safeguards before the feature rolls out, including monitoring for abnormal searches and automatically flagging users.
Moreover, if information such as email addresses, phone numbers, and birth dates is compromised, cybercriminals could use it to launch targeted phishing attacks and social engineering scams, potentially leading to identity theft and financial fraud.
Flock’ed by controversies
Flock has been surrounded by controversy ever since its cameras overstepped data collection and started bordering on the lines of mass surveillance.
As per a report from 404 Media, local police departments were found carrying out informal searches of Flock data on behalf of federal immigration authorities.
Audit logs showed thousands of searches with reasons such as “immigration,” “ICE,” and “ICE + ERO,” referring to ICE’s Enforcement and Removal Operations division.
This allowed federal agencies a backdoor into a surveillance network they otherwise have no direct control over.
An audit in Oxnard, California, found that agencies outside the state were allowed to access the city’s license plate data without any approval, which ultimately led to a lawsuit against Flock.
In another instance, an innocent data-entry error made by a dealership in California led to its loaned Range Rover being marked as stolen. Police tracked the vehicle and ultimately surrounded it with guns in a shopping center parking lot.
Flock is just one part of a growing car-based surveillance network
Unfortunately, Flock isn’t the only data-hungry, privacy-invasive company after your car-related data. Car-based surveillance is spreading across the US, with companies like Leonardo developing technologies that can track you even if you don’t own a car.
Leonardo’s SignalTrace can capture wireless signals from smartphones and other devices as they pass sensors installed alongside ALPR cameras. Over time, it can identify recurring clusters of devices traveling with a particular vehicle and store those signatures in a searchable database.
Since these sensors sit next to ALPRs, SignalTrace could identify patterns of the same smartphone signals appearing next to one another and treat that recurring cluster of devices as a kind of signature associated with a particular vehicle.
Leonardo says the system does not identify people directly. However, those persistent movement patterns could potentially be combined with other records to identify individuals. A Scientific Reports study found that just four time-and-place points were enough to uniquely identify 95% of people.
Flock faces growing pushback over surveillance
Recently, in June, city workers in Dayton, Ohio, covered Flock Safety cameras with trash bags after it was found that the company had secretly shared data for immigration enforcement.
Earlier, in September 2025, Evanston also did something similar after it was found that Flock had granted U.S. Customs and Border Protection access to its cameras across the state. Other cities, such as Los Altos Hills, Santa Cruz, and Mountain View, have also scrapped these cameras and/or terminated their contracts altogether.
Flock’s new AI system is expected to lead to more such public outcries, which could eventually put pressure on legislators to take matters into their own hands. Connecticut has already passed various measures to limit how sensitive vehicle data is collected, retained, or shared.
Despite surveillance reaching increasingly dystopian levels, there’s realistically very little an individual car owner can do to stop Flock or similar systems from tracking their vehicle.
You can’t exactly avoid every road equipped with an ALPR camera. What you can do is limit the potential fallout if your personal information is exposed or misused.
An identity theft protection service can’t stop Flock from collecting your data, but it can alert you if your personal information appears in a data breach or on the dark web, or is used to open accounts or commit fraud in your name.
Bottom line
Despite growing public dissent, Flock appears to be doubling down on its surveillance network. Now, it plans to launch a new AI tool that can analyze vehicle movements, behavioral patterns, and personal data to build detailed profiles.
Unfortunately, the only real way to stop this is for authorities to step in with stronger legislation and tighter restrictions on how this data can be collected, accessed, and shared.
Until then, there’s little an individual can do to stop being tracked. The most practical step is to use tools such as an identity theft protection service to help prevent your personal data from being misused by cybercriminals.