Submit incident
Documented

Staff Logged the Wrong Person and a Facial Recognition System Did the Rest

January 1, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC2035View source ↗
LinkedInX

What happened

A woman walks into a shop, pays for what she needs, and leaves. On a later visit she walks into a different branch of the same chain and is publicly removed by security. That is what happened to Danielle Horan, a makeup business owner from Greater Manchester, after she was incorrectly added to Facewatch, a facial recognition watchlist used by Home Bargains stores across the UK.

The core failure was not algorithmic. Staff at one of the stores mistakenly recorded Horan's details as those of a shoplifter, despite her having paid for the items in question. Facewatch then did exactly what it was designed to do: it matched her face on subsequent visits and flagged her for removal. The system had no way to know the entry was wrong. It relied entirely on the accuracy of the data fed into it, and that data was inaccurate from the start.

Horan was publicly ejected from two stores. Her mother was present during one of the incidents. The experience caused her severe anxiety and distress, damaged her reputation, and barred her from retail spaces she had every right to enter. These are the practical consequences of a blacklisting error that the system was not built to catch, and that the people operating it were not equipped to question before it propagated.

After Horan's case was reported publicly, the stores involved provided staff with further training and suspended local use of the Facewatch system. Those responses are appropriate as immediate remedies, but they leave open the question of how many other people may have been incorrectly logged and not yet discovered. An error that generates no visible alert, whose subject has no access to the watchlist entry against them, can sit in a database for months before it surfaces through a humiliating public confrontation.

This is what the absence of verification infrastructure produces: a system that acts on data it cannot audit, affecting people who have no knowledge of what has been recorded about them and no clear mechanism to challenge it. A provable record of what a system did, who entered the data that drove its decision, and when that entry was last reviewed would have surfaced the error before a paying customer was ejected from a checkout queue. Without that, every retail watchlist is one wrongly logged name away from repeating this.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
Staff Logged the Wrong Person and a Facial Recognition System Did the Rest
2025