You Can See My Face, Why Can’t I? Facial Recognition and Brady

HRLR Online April 12, 2021
Rebecca Darin Goldberg[1]*

Table of Contents


I. The Benefits and Risks of Facial Recognition Software

A. What is Facial Recognition and How Does it Work?

B. The FBI’s Facial Recognition System 268

C. Challenges with Facial Recognition Accuracy and Misuse

D. Facial Recognition as an Investigative Tool

E. Issues with Eyewitness Identification in Criminal Cases

II. Brady Applied to Facial Recognition

A. Scope of the Brady Doctrine

B. Facial Recognition Disclosure Concerns in Lynch v. State

C. Brady Disclosure

1. Brady Disclosure of Biometric Data

2. Brady’s Applicability to Investigative Tools

3. Brady Materiality Standard and Facial Recognition

4. Brady and the Reliability of an Investigation 

III. Recommendations for the Fair Use of Facial Recognition in Criminal Cases

A. Courts’ Role in Requiring Brady Disclosure

B. New Standards for Eyewitness Identification 

C. Regulation of Facial Recognition



On September 12, 2015, two undercover narcotics detectives driving around Jacksonville, Florida, were flagged down by a Black man who asked them, “[y]ou good?”[2] One of the detectives responded that he was looking for $50 worth of crack cocaine.[3] The man went inside a nearby residence, returned moments later, and exchanged the drugs for cash.[4] Taken by surprise when the man approached them, the detectives’ typical surveillance equipment was not activated during the exchange.[5] Knowing that they would need to know the identity of the man in order to later arrest him, one of the detectives pretended to take a call on his cellphone so he could discreetly snap photographs.[6] Before the detectives drove away, the man said to them, “you see me around, my name is Midnight.”[7]

The detectives sent the photographs to the Jacksonville Sheriff’s Office Crime Analyst, who ran one photograph through a facial recognition system to see if it would match with any arrest photographs in the county.[8] The system provided several possible matches, but none of the results had greater than “one-star” confidence[9] of being correct.[10] The crime analyst sent only the first result, containing Willie Lynch’s photograph, to the officers, along with Lynch’s criminal history.[11] The officers accepted the crime analyst’s suggestion and arrested Lynch.[12] But as Somil Trivedi, a senior staff attorney at the ACLU, put it, “anyone who’s used Yelp can figure out that [one-star confidence is] not a high degree of confidence in your restaurant choice for lunch.”[13]

At trial, the state’s case was based on the detectives’ testimony claiming they recognized the defendant as the man who had sold them drugs.[14] Lynch’s defense was that they had the wrong guy.[15] Despite the Supreme Court’s holding in Brady v. Maryland, mandating that a defendant have access to exculpatory information,[16] the state did not disclose to Lynch any of the other matches that the facial recognition system provided, nor did it inform him about the confidence levels of the matches.[17] The jury convicted Lynch, and the judge sentenced him to eight years.[18]

For Lynch and many other defendants who are involved in criminal cases in which facial recognition software is used, receiving exculpatory information under Brady could be the difference between a guilty verdict and an acquittal.[19] The use of facial recognition software has become a routine investigative tool for police agencies across the country, and is on track to become one of the most pervasive surveillance technologies relied on by law enforcement.[20] Despite its growing use, Lynch v. State appears to be the first case to raise Brady issues claiming that the use of the facial recognition software created exculpatory information.[21]

Part I of this Note provides a general overview of facial recognition software and the differences between facial recognition and other types of biometric data. Part II applies Brady to facial recognition software, detailing how defendants are not receiving potentially exculpatory information and discussing the due process implications of such inaction. Part III suggests that law enforcement agencies, courts, and Congress make changes to ensure the fair and effective[22] use of facial recognition.

I. The Benefits and Risks of Facial Recognition Software

This Part explores how facial recognition is currently used in criminal cases and how it is different from other forms of biometric data. This Part will focus on the FBI’s facial recognition systems, since these are the most widely used.[23] Section I.A describes facial recognition and highlights the benefits and drawbacks of its application to criminal cases. Section I.B briefly examines the FBI’s facial recognition system. Section I.C discusses challenges to facial recognition, including its accuracy and misuse. Section I.D addresses the fact that facial recognition is currently only publicly used as an investigative tool. Finally, Section I.E describes eyewitness identification, a central component of the use of facial recognition, and the implications of its fallibility.

A. What is Facial Recognition and How Does it Work?

Facial recognition has become a staple investigatory tool for law enforcement around the world.[24] While a few American states and cities have banned its use,[25] many of the nation’s most influential police departments, including those in New York City and Chicago, use facial recognition.[26] The technology is so widespread that, in 2010, the FBI began replacing its fingerprinting system with Next Generation Identification (NGI) facial recognition technology.[27]

In general, facial recognition software works by creating a map of facial features from a probe photograph and comparing that information to a database of stored images.[28] Most Americans are now part of these databases[29] as photographs in the databases are sourced from driver’s licenses, government identification records, mugshots, and social media accounts. The specific source(s) depends on the law enforcement agency.[30]

Compared to other forms of biometric data, facial recognition programs are unique in their matching process.[31] Most facial recognition systems calculate a probability match score, or a confidence score, between an unknown person and known persons in the database.[32] They offer several possible matches ranked in order of likelihood and provide confidence levels to accompany each match.[33] DNA and fingerprint comparisons, on the other hand, indicate whether the DNA profile or fingerprint ridges, respectively, matches the DNA profile or fingerprint at the crime scene.[34] If the sample is contaminated or does not have enough of the biometric data, either insufficient DNA or a partial latent fingerprint, the result is inconclusive.[35] Facial recognition is different; even if the matches include the correct suspect, the analyst conducting the search and selecting the match to forward to investigators may choose the wrong individual.[36] The correct match may not even be in the list of results identified by the software, but the analyst reviewing the results may find a match anyway, thereby implicating an innocent person (a false positive).[37]

B. The FBI’s Facial Recognition System

The FBI has access to hundreds of millions of photographs[38] and has said that facial recognition is critical to its mission.[39] The FBI has two programs that use facial recognition: the Next Generation Identification System Interstate Photo System (NGI-IPS), for external agencies, and the Facial Analysis, Comparison, and Evaluation (FACE) Services, which is internal to the FBI.[40] As of April 2019, the collective databases searchable by FACE contained 641 million photographs.[41] When FBI agents request a search, biometric image specialists within the FBI FACE Services unit review any matches received from external partners before releasing results.[42] Unlike NGI-IPS, which returns between two and fifty results depending on the user’s specification, when a search is conducted using FACE, a specialist completes a review, and no more than two photos are returned as a lead to the requesting FBI agent.[43] The number of results is relevant to defendants who are seeking this information as part of Brady disclosure because additional results can help defendants make a case that an alternative suspect may have been the perpetrator.[44]

C. Challenges with Facial Recognition Accuracy and Misuse

Facial recognition’s use is expanding in part due to the increased availability of photos.[45] It is becoming increasingly likely that crimes will be caught on camera,[46] which will in turn contribute to law enforcement’s increased use of facial recognition software. There are reasons to be concerned about this increased reliance, however, due to issues with the accuracy of facial recognition.[47]

The accuracy of facial recognition systems, measured by whether the software correctly identifies the person in the probe photograph, can vary based on a number of factors, including camera quality, light, distance, database size, algorithm, and the target’s race and gender.[48] Generally, advanced systems can achieve false positive error rates below 10%.[49] In 2016, the FBI reported that their systems successfully included the correct candidate in a list of fifty potential matches only 86% of the time.[50] In other words, one out of every seven searches returned a list of fifty innocent candidates (and failed to identify a correct match).[51]

False positives are especially problematic in criminal cases because they provide law enforcement with an incorrect identity, which can lead investigators to pursue an innocent person. Furthermore, facial recognition software varies across law enforcement agencies,[52] and many agencies have lower standards of accuracy than the FBI or do not conduct accuracy tests at all.[53] In 2019, the FBI announced its plan to use a new vendor that claims an accuracy rate of over 99%, [54] but due to incomplete reporting on accuracy, there is reason to doubt this figure.[55]

Though there are almost eighteen thousand local police agencies in the United States,[56] there exist no uniform standards or regulations for facial recognition software.[57] Therefore, police departments across the U.S. differ in their uses of facial recognition software with varied levels of accuracy, some of which have even been described as “fringe techniques.”[58] The same is not true for DNA evidence, which, when used through the National DNA Index System (NDIS) or the Combined DNA Index System (CODIS), has strict and standardized requirements.[59]

There are neither accuracy requirements for facial recognition software nor standards for what law enforcement can submit as probe photographs.[60] Because probe photographs in criminal cases often come from surveillance footage, most probe photographs are imperfect: they are often low resolution and not front-facing.[61] In order to overcome these imperfections, some law enforcement agencies allow officers to substantially edit the photographs by replacing facial features on the probe photograph with those from stock photographs or by digitally approximating the other side of the face.[62] The more editing that is done to the probe photograph, however, the less reliable the results.[63]

Moreover, facial recognition technology is particularly inaccurate when identifying women, people of color, and young people.[64] According to a study by the National Institute of Standards and Technology (NIST), the majority of facial recognition algorithms exhibit demographic differentials.[65] These inaccuracies increase the probability that people of color will improperly become investigative targets.[66] Despite the inaccuracies and inconsistencies in the way facial recognition is used, facial recognition continues to be heavily relied on by law enforcement.[67]

D. Facial Recognition as an Investigative Tool

Currently, facial recognition is principally used as an investigative technique to identify suspects who, thereafter, are identified by eyewitnesses or matched by a testifying witness to a surveillance photograph.[68] The software is purportedly not used on its own to establish probable cause for an arrest.[69] But research shows that in reality, many law enforcement agencies have relied almost exclusively on facial recognition systems to make an arrest.[70] Further, even if the results produced by the technology are used as a lead and confirmed by an eyewitness, eyewitness identifications are notoriously unreliable.[71]

E. Issues with Eyewitness Identification in Criminal Cases

The disclosure of facial recognition results is particularly important due to established fallibility regarding eyewitness identification and human memory.[72] While eyewitness identification is among the most common types of evidence admitted into courtrooms, it is also one of the most problematic due to the rate of misidentification.[73] In fact, a recent study by the Innocence Project found that 75% of wrongful convictions in the U.S. have involved eyewitness misidentification.[74] Given the problems with eyewitness identification and the fact that eyewitness misidentification is associated with more wrongful convictions than any other cause,[75] disclosure of the process used to identify a defendant is all the more important. Courts have recognized the importance of this type of evidence and found that “[i]dentification testimony may be outcome determinative” and is therefore required to be disclosed to defense counsel.[76]

The inclusion of a suspect selected by facial recognition in an identification procedure may increase the chance of eyewitness misidentification because eyewitnesses are likely to positively identify look-alikes, regardless of whether the look-alikes are actually the perpetrator.[77] Moreover, facial recognition programs are specifically designed to produce results that look like the perpetrator.[78] Misidentification occurs less frequently in cases in which the eyewitness knows the defendant well,[79] yet most cases using facial recognition involve a police officer serving as an in-court witness testifying to having seen the event or having compared the match photograph to the suspect.[80] The issue is plain: investigations that use facial recognition to identify the suspect rely both on technology with unreliable levels of accuracy and on humans with unreliable capabilities of identification.[81]

Not only are facial recognition and human identification fallible on their own, but also errors in facial recognition can be compounded through suggestive identification procedures.[82] Suggestive procedures can occur when law enforcement signals to witnesses that facial recognition has been used.[83] When law enforcement tells eyewitnesses that facial recognition was used, eyewitnesses may have a false belief that the perpetrator must be present in the photographs presented,[84] thereby increasing the chances that the wrong individual is selected.

Suggestiveness of facial recognition is a serious concern as it can increase the likelihood of misidentification.[85] In the context of biometric data, however, suggestiveness is a problem that is unique to facial recognition because neither DNA nor fingerprint analysis involves eyewitness identification procedures. Despite this difference, the results of DNA and fingerprint analysis are consistently turned over to defense, while facial recognition results are not.[86] When facial recognition is used, the analyst who conducts the search knows what the suspect looks like.[87] Once the facial recognition system releases results, the analyst conducts a visual analysis to identify a match and determine the identity of the suspect.[88] This identification procedure is ripe for misidentification because while the software releases several possible matches, the analyst conducting the search makes the final identification.[89]

Despite the fact that facial recognition increases the risk of misidentification,[90] information regarding facial recognition identification procedures is not disclosed to the defense.[91] The Supreme Court has said that “the vagaries of eyewitness identification are well-known; the annals of criminal law are rife with instances of mistaken identification.”[92] In order to address the concerns of an “irreparable misidentification”,[93] facial recognition identification results and confidence scores must be disclosed under Brady.

The next Part of this Note will apply Brady to facial recognition and will argue that information generated by facial recognition searches should qualify as Brady material and therefore be provided to defendants.

II. Brady Applied to Facial Recognition

This Part imposes the Brady framework on the facial recognition context, detailing the justified concern that defendants are not receiving potentially exculpatory information with regard to facial recognition results. Section II.A discusses the scope of Brady. Section II.B explores the Brady concerns that surfaced in Lynch v. State. Section II.C reviews the Brady materiality standard and argues that facial recognition results and confidence scores are material. Section II.C also addresses concerns regarding Brady’s application to facial recognition when the technology is used only as an investigative tool.

A. Scope of the Brady Doctrine

In 1963, the Supreme Court announced, in Brady v. Maryland, one of the most significant rules for criminal defendants: prosecutors must disclose “exculpatory” evidence.[94] The Court held that “the suppression by the prosecution of evidence favorable to an accused upon request violates due process where the evidence is material either to guilt or to punishment, irrespective of the good faith or bad faith of the prosecution.”[95] The Court reasoned that suppression of such exculpatory information was a violation of the Due Process Clause of the Fourteenth Amendment.[96]

Despite the seemingly expansive rule, Brady is limited by the element of materiality. Brady demands the disclosure only of evidence that is “material” to the defendant’s case,[97] but since the Brady Court did not provide a standard of “materiality,” courts have interpreted this obligation differently.[98] While many courts originally concluded that Brady requires the disclosure of all evidence favorable to the defendant, the Supreme Court has more recently made it clear that Brady requires only the disclosure of material exculpatory evidence.[99]

B. Facial Recognition Disclosure Concerns in Lynch v. State

Defendants have reason to seek information about the number of matches provided by a facial recognition search because if more than one result is provided, the defendant has a stronger case for mistaken identity. In Lynch v. State, although FACES, the facial recognition program, returned several possible matches to the cellphone photograph, the prosecution never disclosed this information.[100] The probe photograph taken of the suspect was blurry and captured from a side angle, and none of the search results expressed more than “one-star” confidence—information that would have strongly called the identification into question.[101] Notwithstanding the possibility of alternative suspects, the crime analyst sent only Lynch’s name to the requesting officers.[102]

The Florida First District Court of Appeals rejected Lynch’s Brady argument because the court found that Lynch did not show “a reasonable probability that the result of the trial would have been different if the suppressed documents had been disclosed to the defense.”[103] The court reasoned that because Lynch could not show that the other facial recognition matches resembled him, he was unable to argue that they would have supported his contention that someone in one of the other results was the culprit.[104] The issue with this reasoning, however, is that the photographs were in the possession of law enforcement. When Lynch learned that facial recognition was used, he requested that the state disclose the photographs of the other potential matches.[105] The state refused, and Lynch was never able to view the other matches.[106] In rejecting Lynch’s Brady argument, the court essentially “reward[ed] the state for its discovery violation.”[107] On appeal, the Florida Supreme Court declined to hear the case for lack of jurisdiction.[108] Lynch, however, did not settle the question of whether facial recognition results should qualify as Brady material.

Despite the thousands of criminal cases in which facial recognition is currently being used,[109] Lynch v. State is the only case that has attempted to litigate these Brady issues.[110] While it is possible that some disclosure of facial recognition is currently taking place, most cases have remained under the radar,[111] likely because defense counsel were not aware that facial recognition was used in their clients’ cases.[112] The lack of cases litigating these Brady issues suggests that defendants are consistently being denied access to such information.[113] Notwithstanding the fact that FACES, created by the Pinellas County Sheriff’s Office, runs eight thousand monthly facial recognition searches,[114] the Pinellas County Public Defender reports that they have never received facial recognition information as part of Brady disclosure.[115] Consequently, it appears that defendants whose cases involve the use of facial recognition software are, perhaps unknowingly, being denied their due process rights.[116]

C. Brady Disclosure

1. Brady Disclosure of Biometric Data

There are meaningful differences between traditional forms of biometric data and facial recognition that suggest facial recognition results and confidence levels should be Brady material. A plaintiff must establish three elements to prove a Brady violation: “(1) the evidence at issue must be favorable to the accused, either because it is exculpatory or because it is impeaching; (2) the evidence must have been suppressed by the state, either willfully or inadvertently; and (3) prejudice must have ensued.”[117]

Test results from DNA and fingerprints found at the crime scene almost always meet these elements.[118] While defendants generally receive access to Brady material for DNA and fingerprint results, that is not the case for facial recognition results.[119] There are, however, differences between these types of biometric data that highlight why facial recognition should be disclosed under Brady.[120]

One meaningful difference between fingerprint and facial recognition results is that fingerprint analysts are required to go through rigorous training.[121] Many agencies require fingerprint examiners to have a four-year degree in a related field in addition to certification by the International Association for Identification.[122] Additionally, two separate fingerprint examiners review the potential matches before making a final determination.[123] Currently, for facial recognition analysis, there are no national training requirements—training requirements vary widely by law enforcement agency, and some law enforcement receive no training at all on how to conduct facial recognition analyses.[124]

Similar to fingerprint analysts, but strikingly different from their facial recognition counterparts, DNA analysts are required to meet continuing education requirements stipulated by the FBI’s Quality Assurance Standards.[125] Furthermore, despite being used in similar ways, the national DNA database, authorized by statute, is highly regulated, while facial recognition databases are not.[126] There is no congressional act overseeing the use of facial recognition.[127] DNA databases also have strict data requirements about what DNA records can be submitted,[128] but no such requirements exist for facial recognition.[129]

Even with relatively high levels of regulation and accuracy, the overwhelming majority of courts have found that biometric data, including DNA and fingerprint analysis results, qualify as Brady material, due to their exculpatory nature.[130] Meanwhile, though facial recognition is much less regulated and has lower rates of accuracy,[131] no court has ruled that facial recognition results and confidence levels should qualify as Brady material.[132]

2. Brady’s Applicability to Investigative Tools

An important question is whether it matters, for purposes of Brady, that facial recognition is currently used for investigative leads and not as the sole basis to establish probable cause for an arrest or as the basis for lay or expert testimony at trial.[133] The fact that facial recognition is not yet (at least publicly[134]) used on its own to establish probable cause is not determinative because courts have found that Brady applies to material that can lead to probable cause, not only material that establishes probable cause.[135] Courts have reasoned that information that is “both favorable and of such importance that it can be said to be material to the outcome of a probable cause determination” may cast doubt on the strength of the prosecutor’s case and therefore must be disclosed.[136]

Similarly, most jurisdictions mandate disclosure of exculpatory information that can lead to admissible evidence, even if the exculpatory information is not admissible in its current form.[137] Since the Supreme Court’s decision in Wood v. Bartholomew, which held that a Brady violation occurs when the disclosure of evidence makes it “reasonably likely” that a different result would have been obtained at trial,[138] the First, Sixth, Eighth, Eleventh, and D.C. Circuits have all held that Brady violations can occur when inadmissible evidence leads to admissible evidence.[139] Similarly, the Fifth Circuit has held that Brady violations can occur when inadmissible evidence would likely affect the outcome of the trial.[140] Each court has concluded that where the disclosure creates a reasonable probability of altering the verdict, the inadmissible evidence is material and disclosure is therefore required.[141]

Despite the due process implications pertaining to favorable and material information, defendants are not receiving access to such information in the context of facial recognition.[142] Courts should apply the conclusions of the First, Sixth, Eighth, Eleventh, and D.C. Circuits to the facial recognition context and find that facial recognition results and confidence information must be provided to defendants under Brady, regardless of the admissibility of that evidence or whether it was used to establish probable cause, as long as the information is material and exculpatory.

3. Brady Materiality Standard and Facial Recognition

Under the Kyles materiality standard, which was affirmed in the Supreme Court’s most recent opinion on the issue of materiality,[143] Brady demands the pretrial disclosure of facial recognition confidence scores and alternative matches:[144]

The question is not whether the defendant would more likely than not have received a different verdict with the evidence, but whether in its absence he received a fair trial, understood as a trial resulting in a verdict worthy of confidence. A reasonable probability of a different result is accordingly shown when the government’s evidentiary suppression undermines confidence in the outcome of the trial.[145]

In Kyles, prosecutors withheld information relating to inconsistent eyewitness identification statements and license plate numbers from the crime scene that did not match the defendant’s alleged license plate.[146] The Court found that the inconsistent eyewitness statements and the information pertaining to the license plates were Brady material, and the prosecution’s lack of disclosure merited reversal.[147] The Court reasoned that the defense could have used that information to “attack[] the reliability of the investigation in failing even to consider [an alternate suspect’s] possible guilt.”[148] The Court further concluded that the government’s suppression undermined confidence in the outcome of the trial because “disclosure of the suppressed evidence to competent counsel would have made a different result reasonably probable.”[149]

Confidence ratings and alternative matches provided by facial recognition software can undermine the confidence in a conviction and should be provided to defendants similarly to material undermining the credibility of a witness.[150] Regarding confidence ratings, in Lynch, facial recognition identified Lynch and several other people in its list of results.[151] All of the results had one-star confidence levels.[152] If a human witness identified, with similar confidence, several other people as possible suspects, that information would unquestionably have qualified as Brady material had that witness testified at trial.[153]

Similarly, if a testifying witness expresses a low level of confidence in an eyewitness identification, such information would be Brady material.[154] The prosecutor would have to disclose information about the lack of certainty to the defense.[155] In-court witnesses providing confidence information is analogous to facial recognition confidence scores. If it is Brady information when a human witness informs law enforcement of her lack of certainty, it should be Brady information when facial recognition does, too.

The next step in this analysis requires considering that facial recognition results may lead an eyewitness to identify the defendant, but a fallible process would have led to that identification.[156] This can further undermine the confidence in a conviction. Even if the initial facial recognition results serve only as an investigative lead, eyewitness identifications that confirm the identity of a match would form the foundation of the investigation and, in many cases, would serve to establish probable cause to make an arrest.[157] Given the issues with facial recognition accuracy and eyewitness identifications, however, the identity of the suspect may be wrong.[158] This issue would likely go undetected and would result in the investigation and possibly conviction of an innocent person.[159]

Improper handling of the alternate matches provided by facial recognition software can similarly impact an investigation. Consider a scenario in which a testifying eyewitness viewing a police lineup pointed to three of the five people in the lineup, the defendant and two fillers, and then says, “It was one of these three people.” The prosecutor would have to disclose this information.[160] When facial recognition provides multiple results, the software is doing the same, identifying multiple people. If it is Brady information when a human witness identifies multiple suspects, it should be Brady information when facial recognition does the same.

Moreover, investigations that focus on a suspect who was identified by facial recognition may suffer from confirmation bias and tunnel vision. These issues can occur when the testifying investigator, after using facial recognition to identify the defendant, ignores or inadvertently suppresses evidence that points away from the defendant.[161] Tunnel vision can exacerbate due process concerns as there could be exculpatory evidence indicating alternative perpetrators, which would “undermine confidence in the outcome of the trial.”[162] Ultimately, then, not disclosing evidence of alternative perpetrators would constitute a Brady violation.[163] Overall, courts have found that Brady material includes any information that links someone other than the defendant to the crime.[164] Brady should therefore apply to alternative matches and confidence levels provided by facial recognition, and that information should be turned over to defendants.

4. Brady and the Reliability of an Investigation

Had the defense known about the use of facial recognition in Lynch’s case, counsel could have raised questions about the reliability of the investigation under the Kyles standard.[165] The FACES analyst expressed that she did not know how FACES worked and, further, that she was unaware there was a range of possible confidence ratings.[166] Additionally, the officers conducting the investigation testified that they had accepted the analyst’s suggestion of Lynch’s identity without further investigation, even though FACES produced several alternative matches, each of which had the same low confidence rating.[167]

The investigation in Lynch appears to have been even less robust than the investigation that occurred in Kyles.[168] The same reasoning should therefore apply to Lynch and other cases involving facial recognition: if the defense could have used that information to “attack[] the reliability of the investigation in failing even to consider [an alternate suspect’s] possible guilt,”[169] it must be turned over. As Jake Laperruque, Senior Counsel at the Constitutional Project, stated:

Without knowing that facial recognition was used and the details, it’s impossible for defendants to know if its use in advancing an investigation was proper. It’s the equivalent of police basing their investigation on an eyewitness account, but then not letting the defendant know the witness was used, or if what they saw was from 5 or 500 feet away.[170]

There are circumstances when materiality will not be met in this context, such as when the individuals in the alternative matches provided by facial recognition could not possibly have committed the crime in question (for example, because of incarceration or death). But as long as the confidence levels of a match or other possible matches could “attack[] the reliability of the investigation in failing even to consider [an alternate suspect’s] possible guilt”[171] or “‘undermine confidence’ in the verdict,”[172] defendants should have the chance to review other possible matches and assess the associated confidence scores. To address these concerns, facial recognition results and confidence scores must be disclosed.

III. Recommendations for the Fair Use of Facial Recognition in Criminal Cases

Defendants face meaningful barriers to challenging the use of facial recognition results. Since results are ultimately in the hands of law enforcement, prosecutors should play a role in ensuring that defendants receive access to exculpatory information. Furthermore, it can be difficult to monitor the discretionary application of Brady.[173] Thus, this Part argues that courts, law enforcement agencies, and legislatures must make changes to ensure the proper and beneficial use of facial recognition. Section III.A argues that courts should take an active role in ensuring that facial recognition results are provided as part of Brady disclosure by applying the Kyles standard of materiality.[174] Section III.B suggests that law enforcement should adopt new guidelines for eyewitness identifications. Section III.C suggests that legislative bodies should create regulations to ensure minimum levels of accuracy and proper use of facial recognition. Only with these advancements can facial recognition be used in a fair and beneficial way.

A. Courts’ Role in Requiring Brady Disclosure

Courts must play a role in ensuring defendants receive exculpatory material in the facial recognition context. Unfortunately, it has been noted that “violations of Brady are the most recurring and pervasive of all constitutional procedural violations.”[175] Furthermore, when the Innocence Project examined DNA exonerations, 37% of the cases “involved the suppression of exculpatory evidence.”[176] Despite the scope of Brady non-compliance, legal scholars have noted that courts have taken few steps to improve Brady disclosure.[177]

While the duty of Brady disclosure rests with the prosecution, the Brady doctrine has become so complex that “it is virtually impossible to identify clear and consistent norms of compliance by prosecutors as to what evidence is required to be disclosed, when it must be disclosed, and permissible reasons for noncompliance.”[178] Moreover, even if prosecutors were to ask their law enforcement partners for Brady material, law enforcement agencies do not currently have policies regarding the disclosure of facial recognition search results.[179] The government is not required to provide courts with an inventory of evidence or of what has been disclosed,[180] but judges are in an ideal position to oversee compliance with Brady.[181] While some may suggest that it is difficult for courts to monitor discretionary disclosure, if courts were to apply the Kyles materiality standard, prosecutors will have articulable guidelines for disclosure, thereby alleviating the burden on courts.

Several courts have already followed the Kyles standard, which was affirmed in the Court’s recent decision in Turner v. United States,[182] for other types of discovery.[183] Adopting the Kyles standard will ensure that defendants are given access to facial recognition results, since facial recognition confidence scores and alternative matches can “undermine[] confidence in the outcome of the trial.”[184] As previously mentioned, in Kyles, the Court reasoned that the defense could have used information to “attack[] the reliability of the investigation in failing even to consider [an alternate suspect’s] possible guilt.”[185] In cases in which the identification of the defendant is in question, facial recognition results and confidence scores can jeopardize the reliability of an investigation due to the failure to consider an alternative suspect.

Additionally, the Court determined that materiality applies to information that can “affect[] the judgment of the jury.”[186] Both facial recognition confidence scores and results can affect the jury’s judgment. First, the jury can determine that the unreliability of a low-confidence identification made by facial recognition software may undercut the reliability of the prosecution’s proof at trial. Alternatively, the jury can decide that the defendant visually resembled several other individuals, any of whom could have been the perpetrator. Either way, this information may alter the outcome of the proceeding.[187] Therefore, because they are material under the Kyles standard and potentially exculpatory, facial recognition confidence scores and results would qualify as Brady material.[188]

Critics may argue that prosecutors will not always have to disclose facial recognition results because such results are not always material.[189] This Note does not dispute that claim. But in the majority of cases, as long as it was reasonable that another individual listed in the search results was the perpetrator, defendants should have access to the search results and confidence levels to dispute the reliability of the investigation.[190]

Even if one does not accept that Brady compels the disclosure of facial recognition results and confidence levels, as Justice Kagan articulated in Turner, fairness concerns compel prosecutors to provide expansive disclosure.[191] Still, neither expansive disclosure nor the application of the Kyles standard can address all of the problematic issues underlying facial recognition software.

B. New Standards for Eyewitness Identification

To minimize highly consequential human errors, the manual inspection procedures of facial recognition results need to be standardized.[192] As part of this standardization, all law enforcement agencies should be required to adopt the January 2017 Procedures for Conducting Photo Arrays set forth by the U.S. Department of Justice (DOJ).[193] Several of the recommendations, however, must be specifically adapted to the facial recognition context.

First, in addition to the suspected perpetrator, there should be at least five possible matches included in every list of facial recognition results.[194] Second, searches should include the use of blind administrators, whereby neither the officer conducting the facial recognition search nor the officer running the identification procedure is the investigating officer.[195] Third, witnesses viewing the photo array should be required to make a statement of confidence, and that statement should additionally qualify as Brady material.[196] Fourth, officers conducting the photo array should make it clear to the witness that the perpetrator “may or may not be present” in the photo array.[197] Fifth, witnesses should be assured that the investigation will continue even if they don’t make a selection, thereby ensuring that witnesses do not feel pressured to make a selection.[198] Finally, photo arrays using facial recognition results should be shown sequentially to witnesses.[199] Together, these measures may decrease the chance of mistakenly identifying an innocent person.[200]

C. Regulation of Facial Recognition

Several organizations have argued that facial recognition is too dangerous and should be outright banned.[201] This Note does not suggest that law enforcement’s use of facial recognition should end. Its use and accuracy, however, must be regulated to ensure the lowest possible level of misidentification. While the technology will continue to develop, regulations can be adopted to harness the beneficial uses of the software while minimizing its risks.[202]

Despite the fact that more than 117 million American adults are included in facial recognition databases across the country, the use of these databases and searches remains unregulated.[203] Notwithstanding the number of individuals implicated in facial recognition searches, no state has passed a law comprehensively regulating facial recognition[204] or governing the type of edits law enforcement can make to probe photographs before searching for matches.[205]

To address the disparities in facial recognition’s use, legislators should pass a law to regulate law enforcement’s use of facial recognition, parts of which should be modeled after the DNA Identification Act of 1994.[206] Under such a law, the FBI should have authority to establish a national facial recognition index system for law enforcement purposes and to create standards for the quality and use of probe photographs across all law enforcement agencies, similar to NDIS and CODIS.[207]

Specifically, facial recognition software should be required to meet a minimum threshold of accuracy, and there should be regulations on the types of editing allowed.[208] The FBI should partner with NIST to create these standards. Furthermore, Congress should require that all law enforcement facial recognition programs participate in NIST accuracy tests and tests for racially biased error rates and publicly report the results. Law enforcement agencies should be required to disclose information annually and publicly, comparable to the level of disclosure required by the Wiretap Act.[209] This should include the number of facial recognition searches conducted, the crimes that the searches were used to investigate, and the arrests and convictions that resulted from the searches.[210] Lastly, as part of their authority, the FBI should require special training for law enforcement officials who conduct facial recognition searches. This training should include lessons in eyewitness identification as well as the mechanics behind facial recognition, and should be modeled off of training and certification requirements for fingerprint analysts.[211]

If Congress works with the FBI and state and local law enforcement agencies to address the concerns outlined in this Note, facial recognition has the potential to be safely used as a powerful tool for law enforcement.[212]


As law enforcement continues to use facial recognition software,[213] more and more individuals will be at risk of being denied the right to a fair trial.[214] Unless changes are made to recognize facial recognition results and confidence levels as Brady material, defendants like Lynch will continue to be deprived of this information. As this Note suggests, law enforcement, judges, and legislators should rethink current standards for facial recognition to ensure that defendants receive access to material that could “undermine confidence” in their verdicts.[215] Without addressing the current lack of regulation of facial recognition both in the courtroom and in criminal investigations, the software is prone to continued misuse, whether by failing to identify the correct suspect or, worse, identifying the wrong individual.

If the tool is used properly, the design is improved upon to effectively control for bias, and the results are properly disclosed, facial recognition could have the potential to be beneficial—criminal defendants could be identified with accuracy, thereby reducing convictions of innocent people.[216] If used improperly, however, it could lead to unjust outcomes. Courts should apply the Kyles standard of materiality[217] to ensure facial recognition information qualifies as Brady material. Prosecutors and law enforcement should disclose facial recognition results and confidence levels. Finally, Congress should regulate facial recognition to make sure it is used fairly, beneficially, and accurately. Facial recognition is rapidly becoming a pillar of law enforcement investigations, but if the checks on its use are insufficient, it will implicate innocent people.[218]

* J.D. Candidate 2021, Columbia Law School; B.A. 2015, Tufts University. The author would like to thank Professor Daniel Richman for his invaluable guidance and encouragement. The author would also like to thank the Honorable Jed S. Rakoff for his ongoing support, Saritha Komatireddy for her generous feedback, and the staff of the Columbia Human Rights Law Review for their editorial assistance. In addition, the author acknowledges the unwavering support of her parents, Marc and Donna, sister, Haley, and partner, Mike.

