Submit incident
Documented

A Vending Machine Error Message Exposed Covert Facial Recognition on a Canadian Campus

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1348View source ↗
LinkedInX

What happened

In February 2024, a student at the University of Waterloo noticed something unusual on the screen of an M&M-branded vending machine on campus: an error message that should never have been visible to someone buying a snack. The message pointed to facial recognition software running inside the machine. The student posted about it online, others started looking more closely at the machines, and within days students were covering a small concealed camera hole with chewing gum and sticky notes.

The machines were supplied by Invenda Group and operated on campus by Adaria Vending Services. A product brochure that students found online described a built-in "demographic sensor" designed to estimate the age and gender of anyone who approached. The stated purpose was to enable AI-powered product recommendations tailored to the person standing in front of the machine. The machines had been running this analysis silently, with no visible notice to the students walking up to them.

Invenda maintained that the machines did not store or transmit personally identifiable imagery, framing the demographic estimation as an anonymous inference rather than a record of individual faces. The University of Waterloo took a different view. It demanded the facial recognition software be disabled and ordered the machines removed from campus.

The incident fits a recognizable pattern in Canadian retail and public spaces. Cadillac Fairview, one of the country's largest mall operators, had previously operated hidden cameras with facial recognition to monitor shoppers, and Canadian Tire had used similar technology to collect customer demographic data. In each case the systems were already running by the time the public found out. The Waterloo case followed the same sequence: deployment first, disclosure never, exposure only by accident, triggered not by a compliance review but by a software glitch on a candy machine.

What the incident makes clear is the accountability gap running beneath all three cases. No student consented to having their face analyzed when they approached a vending machine, and nothing in the machine's appearance indicated that was happening. The university itself appears to have had limited visibility into what the machines were actually doing until students raised the alarm. That is precisely the gap a provable record of what a system did, on whose authorization it was deployed, and when collection began is meant to close: not a vendor's assurance offered after public exposure, but a documented trail that exists before the error message appears.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
A Vending Machine Error Message Exposed Covert Facial Recognition on a Canadian Campus
2024