Submit incident
Documented

The Met Ran Over 2,000 Unauthorized Face Searches Through a Commercial Website

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1473View source ↗
LinkedInX

What happened

London's Metropolitan Police Service accessed PimEyes, a commercial facial recognition tool available to anyone with an internet connection, more than 2,000 times in a single three-month period. The force had no official policy authorizing the use. The disclosure came not from any internal review but from a joint investigation by iNews and the civil liberties organization Liberty, which obtained records of access from Met Police computers.

PimEyes lets a user upload a photograph of a face and search the open web for matches, returning results that can connect that face to a name, a social media account, or other identifying details scraped from public sources. The iNews/Liberty investigation found that Met Police computers had accessed the service 2,337 times during the period examined. PimEyes imposes no warrant requirement and no departmental oversight. Any officer with a device and a browser could run a search, and nothing in the commercial product's design would record that it had happened.

The Metropolitan Police Service acknowledged the accesses but said they may have reflected officers researching the software rather than using it for operational purposes. The force said it had since blocked access to PimEyes on Met devices and strengthened relevant safeguards. The statement did not explain how 2,337 accesses across three months could be characterized as research, nor did it address whether any of those searches had contributed to active investigations.

Privacy advocates have argued for years that commercial face-search tools create an informal route around the legal constraints applied to official police biometric programs. The concern is not limited to accuracy, though commercial tools of this type carry meaningful error rates. The more structural problem is that an officer running a PimEyes search generates no mandatory audit trail, requires no supervisor sign-off, and triggers no departmental record of having acted. The operational benefits of facial recognition become available without any of the accountability structures that are supposed to accompany them.

What the investigation revealed was not a single officer acting out of turn but a pattern spanning three months, with no internal mechanism that flagged it before journalists did. The Metropolitan Police learned about its own officers' behavior from outside the organization. That failure points directly to the absence of a provable record of what a system did, who ran each query, and under what authority. When public-sector bodies deploy surveillance tools without logging requirements attached, stated policies about permitted and prohibited use are only as strong as the external reporting that eventually tests them.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
The Met Ran Over 2,000 Unauthorized Face Searches Through a Commercial Website
2024