AI Regulation Tracker / Enforcement and biometric AI
FTC Bans Rite Aid From AI Facial Recognition and Orders It to Delete the Algorithms
A five-year ban, plus deletion of the images and the models built from them. On December 19, 2023, the Federal Trade Commission announced a settlement barring Rite Aid from using facial recognition technology for surveillance for five years, after the retailer ran an AI system that falsely flagged shoppers as criminals. It is the FTC's cornerstone biometric AI enforcement action, and it set the disgorgement-plus-safeguards template every US operator deploying biometric AI now gets measured against.
This is the case to know if you touch biometric AI in the United States, and it is worth being precise that it is not new. The FTC announced it on December 19, 2023. I am covering it now because it has become the anchor citation for how the agency handles reckless facial recognition, and because too many operators still treat it as a retail story rather than what it actually is, which is the FTC's template for enforcing against automated biometric systems under Section 5.
Here is what Rite Aid did. From 2012 to 2020 it deployed AI-based facial recognition in hundreds of stores to spot people it believed were shoplifters. The technology was fed tens of thousands of images, many of them low quality, pulled from security cameras, employee phones, and even news stories. It generated thousands of false-positive matches. The FTC says it sometimes matched a customer to someone enrolled based on activity thousands of miles away, or flagged the same person at dozens of stores across the country. Employees acting on those false alerts followed shoppers, searched them, ordered them out, called police, and publicly accused them of theft, sometimes in front of their families. The agency found the errors fell hardest on women and people of color, and that the technology was more likely to produce false positives in plurality-Black and Asian communities than in plurality-White ones.
What the order actually requires
Three provisions carry the weight. The first is the ban. Rite Aid is prohibited from using facial recognition technology for surveillance purposes for five years. If it wants to deploy any automated biometric system that tracks or flags people as security risks, it has to be able to control the risks to consumers, and it must stop using the technology if it cannot.
The second is the part I want operators to sit with, because it is the real teeth. The order requires Rite Aid to delete not just the data but the models built on it. In the FTC's words, the company must "Delete, and direct third parties to delete, any images or photos they collected because of Rite Aid's facial recognition system as well as any algorithms or other products that were developed using those images and photos." That is algorithmic disgorgement. You do not get to keep the model you trained on improperly used data. The asset itself is forfeit. For anyone building on top of biometric or scraped inputs, that is the sentence to internalize.
The third is the safeguards package. Rite Aid must build a comprehensive program to prevent this class of harm before deploying automated biometric systems, run a robust information security program overseen by its top executives, obtain independent third-party assessments, notify consumers when their biometric information is enrolled and when action is taken against them, provide clear and conspicuous notice of biometric surveillance in stores, investigate and respond in writing to complaints, delete biometric information within five years, and hand the Commission an annual certification signed by the CEO. The accountability runs to the top of the company on purpose.
Why the FTC called it groundbreaking
Samuel Levine, Director of the FTC's Bureau of Consumer Protection, did not hedge. He said Rite Aid's "reckless use of facial surveillance systems left its customers facing humiliation and other harms, and its order violations put consumers' sensitive information at risk," and that "Today's groundbreaking order makes clear that the Commission will be vigilant in protecting the public from unfair biometric surveillance and unfair data security practices." Read the operative words. Reckless. Unfair biometric surveillance. Unfair data security practices. Those are the hooks the FTC will reach for again, and the standard is not whether you meant well. It is whether you tested, monitored, documented, and controlled the system before you pointed it at the public.
What this means for US operators and counsel
The through-line is that a biometric or automated system is not a gadget you switch on and trust. The FTC's complaint reads as a checklist of what Rite Aid failed to do, and you can invert it into what the agency expects. Assess and mitigate the risk of misidentifying people, including heightened risk tied to race and gender. Test accuracy before deployment, and get real information from your vendor about how the technology was tested rather than taking a sales sheet on faith. Keep low-quality inputs out. Monitor false-positive rates after launch and track the actions taken on those alerts. Train the people operating the system, and tell them plainly that it can be wrong.
For counsel, the disgorgement remedy is the planning point. If your client's model was trained on improperly collected biometric or personal data, the exposure is not just a fine and a consent decree, it is the destruction of the model. That changes the math on data provenance. It makes documenting the lawful basis for training inputs a business-survival question, not a compliance nicety. And the CEO certification and executive-owned security program mean this is not something a client can quietly delegate to a vendor and forget. When the FTC comes back to biometric AI, and it has signaled it will, Rite Aid is the order it will build from.
Questions professionals are asking
When did the FTC ban Rite Aid from using facial recognition?
The FTC announced the settlement on December 19, 2023. This is a settled federal court order, not recent or pending news. It bars Rite Aid from using facial recognition technology for surveillance purposes for five years and requires a package of safeguards.
What is algorithmic disgorgement in this order?
The order requires Rite Aid to delete, and to direct third parties to delete, any images or photos collected through its facial recognition system as well as any algorithms or other products developed using those images and photos. In plain terms, the company does not just delete the data, it must destroy the models built from it.
Why does this case matter for US businesses using AI?
It is the FTC's first order banning a company's use of AI facial recognition and its cornerstone biometric AI enforcement action. It signals that reckless deployment of automated biometric or surveillance systems is an unfair practice under Section 5, and that remedies can include destroying the model, not just paying a penalty.
What safeguards did the FTC require?
Comprehensive risk-prevention measures before deploying biometric systems, a robust information security program overseen by top executives, independent third-party assessments, consumer notice when biometric information is enrolled and when action is taken, clear and conspicuous notice of biometric surveillance in stores, written responses to complaints, deletion of biometric information within five years, and an annual certification signed by the CEO.
What should counsel advising on biometric AI take from it?
Document the lawful provenance of every input used to train a biometric or personal-data model, because an improperly built model can be ordered destroyed. Require accuracy testing and vendor evidence before deployment, monitor false-positive rates afterward, disclose the use of biometric surveillance, and put executive-level accountability on data security rather than delegating it to a vendor.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how this order or any biometric AI requirement applies to your situation with qualified counsel in the relevant jurisdiction.