On the afternoon before Thanksgiving 2025, San Diego police arrested Hugo Parra on felony charges tied to an attempted carjacking. Officers had a witness description, a vehicle that roughly matched, and a hit from the city’s Flock Safety license plate reader network. Parra insisted he was innocent. They jailed him anyway.
The Flock data they relied on placed Parra’s friend’s red Alfa Romeo roughly five miles from the crime scene—and timestamped that capture just 23 seconds after officers lost sight of the actual suspect vehicle. As Ars Technica reported, the timeline made it physically implausible that the car police were pursuing was the same one Flock flagged. Parra spent nearly a month in jail, housed with violent offenders, before prosecutors dropped the charges. No trial. No conviction. Just a month of his life gone because a camera said his car might have been somewhere it couldn’t have been.
Parra’s case is not an outlier. It is a preview.
A National Dragnet Built Without a Vote
Flock Safety is a private surveillance company that has deployed more than 120,000 automated license plate reader cameras across 49 states. When a vehicle passes a camera, machine learning converts the plate—and often the vehicle’s color, make, and model—into searchable data. That data is checked against hot lists drawn from databases like the FBI’s National Crime Information Center (NCIC), which includes stolen vehicles, wanted persons, and missing persons. When the system finds a match, it sends a real-time alert to law enforcement.
This is not a handful of dash cams on patrol cars. It is a privately operated surveillance network spanning the country, installed city by city, often with minimal public debate. The Congressional Research Service notes there is no comprehensive federal legislative framework governing how ALPR systems are deployed, what accuracy standards they must meet, or what happens when they get it wrong.
The chain looks straightforward: camera reads a plate, system flags a match, police respond. But at each step, errors compound—and the person on the receiving end of that chain is expected to prove the machine wrong, not the other way around.
Documented Failures
The Institute for Justice has cataloged more than two dozen cases in which Flock camera errors led to innocent motorists being pulled over at gunpoint, detained, or jailed. Business Insider identified at least a dozen additional instances involving gunpoint stops, jail time, or police dogs. These are not hypotheticals.
Hugo Parra, San Diego. Police linked Parra to a violent carjacking based on a Flock alert, a witness lineup, and a vehicle description—despite Flock timestamps showing his car was five miles away when the pursuit began. He spent nearly a month in jail before charges were dropped. He and the vehicle’s owner are now suing the city. (Times of San Diego)
Sherwood, Arkansas. On February 11, 2026, a Flock camera misread a license plate ending in “X” as “Y,” flagging an innocent family’s SUV as stolen. Officers approached with guns drawn, handcuffed both adults, and left their infant in the car while they sorted out the error. The officer who made the stop had not verified the plate before initiating the stop—a violation of department procedure. (Arkansas Democrat-Gazette)
Eva Pizzarelli, Cumberland, Rhode Island. After a brief pursuit of a vehicle Pizzarelli had no connection to, Cumberland police used a Flock camera image of the driver and compared it to her driver’s license photo—concluding they matched despite Pizzarelli having dyed her hair brown seven weeks before the incident. She was arrested on a warrant months later during a routine traffic stop. The criminal case was eventually dropped. Flock’s LPR cameras do not use automated facial recognition; this was an officer making a visual match from surveillance footage. But the camera made that match possible, and the result was a wrongful arrest. (ACLU of Rhode Island)
Steven Melvin, York County, South Carolina. A Flock camera falsely flagged Melvin’s BMW as stolen in February 2024. A deputy approached with his gun drawn and ordered Melvin to kneel with his hands over his head for more than five minutes. Notably, Flock had correctly read Melvin’s plate 13 times that same month before the false hit. Officers blamed a tinted plate cover—but the camera had read through it just fine on every prior pass. (Rock Hill Herald)
Joel Feder, Plymouth, Minnesota. A car reviewer testing a Range Rover was ambushed by four police cars after Flock’s system matched his New Jersey plate to a partial NCIC entry from California. Flock’s machine learning ignored the “10” in the middle of his plate and matched on “34 DTM” instead. Officers saw the full plate in Flock’s own photo but did not enter the complete sequence to verify. Flock’s VP of policy told Feder the alert “does not equal probable cause. It’s like an alarm going off.” That disclaimer did not prevent guns from being drawn. (The Drive)
Roseville, California. Between 2023 and 2024, Roseville police received 1,427 Flock alerts for stolen or felony-linked vehicles. Their own analysis found that in 71% of those alerts, the software had misread the license plate. None of those incorrect alerts led to a stop or arrest—because Roseville requires officers to verify plates independently. But 71% wrong on the alerts that matter most is a staggering failure rate for a system marketed as highly accurate. (Business Insider)
The Institute for Justice found that roughly one-third of documented wrongful stops stemmed from machine error, and two-thirds from human error—officers failing to verify alerts, entering wrong data, or misinterpreting what the system reported. The AI does not need to be wrong every time. It only needs to be wrong once, and for an officer to treat the alert as proof.
The “Optimal Conditions” Fine Print
I want to be fair: if Flock’s cameras worked as advertised in the real world, they would be a legitimate investigative tool. Stolen cars get recovered. Missing persons get found. Roseville’s police department credits Flock with helping solve crimes that might otherwise have gone cold. The concept of ALPR technology is not inherently bad.
The problem is the gap between what Flock claims and what its cameras deliver on actual American roads.
Flock publishes accuracy figures on its website: over 99% plate capture in clear and rainy conditions, over 98% at dawn and dusk, over 96% OCR accuracy, and over 97% plate-state identification. Every figure is qualified with “under optimal conditions” or “optimal deployment conditions.” Flock has not published the methodology, sample size, or test environment behind any of these numbers. In litigation, the company has also cited 93% plate-level accuracy—a third figure that does not reconcile with the 96% character-level claim.
So what are “optimal conditions”? Flock’s own Customer Implementation Guide and municipal spec sheets suggest they include: cameras mounted at roughly 65 feet with a 15-foot field of view, positioned after intersections to capture rear plates in the direction of travel, clear line of sight free of trees and glare, current-generation hardware, verified power and LTE connectivity, and a Flock technician site survey approving each location. “Optimal” also assumes officers independently verify every alert before taking enforcement action.
Real deployments diverge from this spec constantly:
- Privacy tradeoffs. Roseville configured its cameras for rear-only capture at higher, farther mounting points specifically to avoid photographing drivers’ faces. Flock blamed this “particularly unique deployment” for the 71% alert error rate—then continued the contract.
- Physical reality. License plate covers and frames, tinted covers, trees, blur at distance, and more than 8,000 different plate formats across the country all degrade accuracy. Flock’s own ML director suggested Roseville officers ask drivers to remove plate frames; the department declined.
- Partial matching. Flock’s system can match substrings against NCIC entries—asking “is this sequence present?” rather than “is this an exact match?” That is how Joel Feder’s full plate matched a truncated database entry.
- Stale databases. Even a perfect OCR read flags an innocent driver if the underlying NCIC record is wrong. The ACLU has documented that NCIC data is notoriously inaccurate.
- Installation shortcuts. Forbes reported cameras installed without required DOT permits in Florida. A 2026 nationwide audit of 100,000+ poles was triggered because many installations did not meet basic roadside engineering standards.
Here is the math Flock does not put in its marketing. Red Banyan calculated that 96% per-character accuracy on a seven-character plate compounds to roughly 71% fully correct plate reads (0.96^7 ≈ 0.71). Roseville’s measured 71% alert error rate is not a freak anomaly. It is what you would expect from Flock’s own published accuracy applied to real plates. When a police chief buys “96% accurate” cameras, they reasonably expect 96% of plates to be read correctly on their streets—not 96% of individual characters under laboratory conditions their city cannot replicate.
How many of Flock’s 120,000 cameras actually operate under “optimal conditions”? Nobody knows. Flock declined to tell Business Insider whether it independently tests camera accuracy. The only third-party test, conducted by research firm IPVM in 2021, found roughly 10% state misidentification and regular make/model errors. Flock then blocked IPVM from purchasing cameras for follow-up testing—unlike every major competitor in the market.
Flock claims fewer than nine “human-reported errors” per million alerts nationwide. That is errors a person chose to report—not errors that occurred, not errors that led to stops, and not errors that went unnoticed. Roseville reported dozens of issues to Flock over four years. That feedback does not appear in the national stat.
And the human verification step that “optimal conditions” assumes? Only four states—Montana, Virginia, Washington, and Kentucky—legally require officers to verify ALPR hits before stopping someone. California, home to both Roseville and San Diego, does not.
Cars get independently crash-tested before families trust them on the highway. Flock’s system can put you in handcuffs, and it has never been independently audited at scale. “Optimal conditions” is doing the work that crash-test ratings do for automobiles—except nobody checked whether your town’s cameras passed.
The Burden Hasn’t Moved on Paper. It Moved to the Parking Lot.
The Fifth and Fourteenth Amendments guarantee that no person shall be deprived of life, liberty, or property without due process of law. The Supreme Court held in In re Winship that the prosecution must prove every element of a crime beyond a reasonable doubt. The presumption of innocence is not a courtesy. It is a constitutional requirement.
But constitutional requirements operate in courtrooms. Flock alerts operate in parking lots, on highways, and in jail intake rooms—long before any judge sees the case.
When a Flock camera sends an alert, the practical sequence is: guns drawn, handcuffs applied, booking processed. The citizen’s job, at that moment, is to convince armed officers that the machine made a mistake. That is not the government proving guilt. That is the accused proving innocence—exactly what the Constitution says should not happen.
Flock acknowledges this, at least in policy statements. The company tells law enforcement that alerts “should be treated as investigative leads” and that officers should “independently verify the license plate, vehicle details, and surrounding circumstances before taking any enforcement action.” The Congressional Research Service confirms that an NCIC match alone is not sufficient for probable cause or arrest.
But those disclaimers do not reach the citizen with a gun in their face. Automation bias—the tendency to defer to algorithmic outputs even when they conflict with other evidence—is well documented. When Hugo Parra’s Flock data showed he was five miles away, police arrested him anyway. When Steven Melvin’s plate had been read correctly thirteen times that month, a deputy still drew his weapon on the fourteenth. When Flock’s VP told Joel Feder the system asked “is it there?” rather than “is it an exact match?"—that is an admission that the technology is designed for recall, not precision. It casts a wide net and leaves innocents to fight their way out.
The burden of proof has not moved on paper. It moved in practice, to the parking lot and the jail cell.
We Wouldn’t Flip a Coin at a Grand Jury
In my view, AI-generated evidence should be treated with extraordinary skepticism in criminal proceedings—and in many cases, deemed inadmissible entirely.
Here is why. AI systems do not observe facts. They produce probabilistic outputs: confidence scores, pattern matches, statistical likelihoods. A Flock alert is not a witness who saw a crime. It is an algorithm that guessed a plate might match a database entry, with a confidence level that neither the officer nor the defendant can inspect.
We would laugh at the idea of flipping a coin to decide whether to indict someone before a grand jury. Yet we allow probabilistic machine outputs—outputs the defense often cannot examine, challenge, or reproduce—to trigger arrests, support prosecutions, and in some cases, serve as evidence at trial.
Current U.S. law does not ban AI evidence. Courts apply Daubert or Frye standards, requiring judges to act as gatekeepers and assess whether scientific evidence is reliable. But as the National Association for Presiding Judges noted, proprietary AI systems create a fundamental problem: when a defendant cannot examine the code, training data, or error rates behind an algorithmic conclusion, the right to cross-examination becomes largely theoretical. The Wisconsin Supreme Court warned of exactly this in State v. Loomis, where a proprietary risk assessment tool was admitted despite the defendant’s inability to challenge its methodology.
European legal scholars have argued that when courts cannot grant sufficient access to AI system design and validation data, the evidence should be excluded entirely to preserve the right to a fair trial. I agree with that principle as a policy matter, even though it would require new legislation rather than a restatement of existing doctrine.
My position: AI-generated identifications should be inadmissible in criminal court absent independent corroboration and full algorithmic disclosure. If the government cannot explain how the machine reached its conclusion—and cannot prove the conclusion is correct beyond a reasonable doubt—it should not be able to use that conclusion against a citizen whose freedom is at stake.
This Should Concern You Even If You’ve Done Nothing Wrong
There is no federal framework governing ALPR deployment, accuracy standards, or accountability. Cities adopt Flock cameras through police department budgets and vendor contracts, often with limited public input. If you drive on a public road in America, your vehicle has likely been scanned, logged, and stored in a database you did not consent to and cannot opt out of.
At 120,000 cameras and counting, errors are not a bug. They are a statistical certainty. Flock’s own marketing math tells you so.
Pushback works. After Eva Pizzarelli’s wrongful arrest, three Rhode Island towns—South Kingstown, Narragansett, and Glocester—canceled their Flock contracts within two weeks. Communities that ask hard questions before signing vendor agreements are communities that protect their residents.
The question is not whether these cameras will get it wrong again. They will. The question is whether you will have to prove they did—and whether anyone in power will listen before you spend a month in a cell proving your innocence to a machine that never had to prove your guilt.
What You Can Do
- Ask your local officials whether your town or county uses Flock or other ALPR systems, and request data on alert error rates.
- Support state legislation requiring independent verification of ALPR hits before traffic stops, and mandating public reporting of false alert rates.
- If you are stopped based on an ALPR alert, remain calm, do not consent to searches, and document everything—badge numbers, timestamps, and the stated reason for the stop.
Sources
Investigative reporting:
- Institute for Justice — Dozens of Innocent Motorists
- Business Insider — Flock AI Cameras Misread Plates
- Business Insider — Roseville 71% Alert Error Rate
- CBS News — When License Plate Readers Get It Wrong
Key cases:
- Times of San Diego — Hugo Parra
- Ars Technica — Parra jailed despite exculpatory Flock data
- Arkansas Democrat-Gazette — Sherwood, AR gunpoint stop
- ACLU of Rhode Island — Eva Pizzarelli false arrest
- Rock Hill Herald — Steven Melvin, York SC
- The Drive — Joel Feder ambush
Legal and policy:
- Congressional Research Service — ALPRs (R48160)
- NAPCO — AI in Criminal Courts
- Law & AI — Presumption of Innocence in the Algorithm Era
Accuracy and company claims:
