FTC bans Rite Aid from using AI facial recognition after misidentifying customers
FTC settles with Rite Aid, banning its use of facial recognition for five years after finding the AI system generated false shoplifting matches without safeguards.
- Courts & copyright
- Minor
The Federal Trade Commission announced a settlement with Rite Aid resolving allegations that the pharmacy chain violated Section 5 of the FTC Act by deploying facial recognition technology in hundreds of stores without reasonable safeguards against harm. The FTC said the system, used to identify suspected shoplifters, “falsely tagged consumers, particularly women and people of color, as shoplifters,” and that in some cases Rite Aid employees publicly accused customers of crimes, searched them, or had them removed from stores on the strength of a false match.
The settlement bars Rite Aid from using facial recognition or analysis technology for surveillance purposes, in stores or online, for five years. It also requires the company to delete photos, videos and any derivative data, models or algorithms built from the system, to implement safeguards if it later resumes any biometric surveillance, and to maintain a comprehensive information-security programme overseen by senior executives — obligations that run for 20 years, well beyond the five-year technology ban itself. Rite Aid disputed the FTC’s characterisation, saying the facial-recognition programme had been a limited pilot that it discontinued more than three years before the investigation began.
The case was among the FTC’s first major enforcement actions targeting an AI system specifically for inadequate testing and disparate impact rather than for a data-privacy violation, and became a frequently cited precedent in the argument that “unreasonable” deployment of an automated decision system — not just its outputs — could itself be an unfair trade practice.