A Facial Recognition System Flagged the Wrong Palestinians, and the IDF Acted on It
What happened
In early 2024, Israeli military and intelligence units operating in Gaza began using a facial recognition system developed by the Israeli company Corsight. The product, marketed as Forsight, catalogued the faces of Palestinians without their knowledge or consent, building an identification database from images gathered across an active conflict zone. Its stated purpose was to identify Hamas operatives and locate Israeli captives held in Gaza.
The pipeline that fed the system compounded its risks from the start. Palestinian detainees were asked to name people from their communities they believed had ties to Hamas. Those names became search targets. Forces would then look for those individuals, hoping each new detention would produce more intelligence. The system provided a face match, and the record shows that match was treated as sufficient grounds to act, with no visible step requiring independent confirmation before someone was seized.
The consequences were concrete. Scores of Palestinians were abducted, interrogated, and physically beaten on the basis of misidentifications. Among those swept up was Mosab Abu Toha, a Palestinian poet whose wrongful detention was later documented by the New York Times and the New Yorker. His case made visible what the aggregate numbers alone did not: each error was a discrete act of state violence triggered by a system that, in that moment, had simply returned the wrong answer.
Corsight's CEO Robert Watts stated publicly that the company's technology was built with privacy, ethics, and bias reduction at its core. That claim sat alongside a documented pattern of harm in one of the most contested environments on earth. A facial recognition model deployed to identify combatants in a warzone, and fed with names drawn from coerced testimony, carries compounding sources of error that a self-assessed ethics commitment cannot correct. The distance between what the system was said to do and what it actually produced was paid for, in each wrongful case, by the person the system misidentified.
What this incident makes plain is the absence of any independent check between a system's output and the force applied because of it. Nothing in the public record describes a mechanism for an operator to confirm a match before someone was detained, a trail that would let a detainee understand why they were flagged, or an audit log that would surface a pattern of errors before scores of people had already been harmed. That is precisely the accountability gap that matters: not just a model returning the wrong face, but an institutional arrangement that acted on that output without a provable record of what the system did, who verified it, and on what basis the decision to detain was made.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.