The legal issues around Flock AI false-positive police stops are no longer theoretical procurement risks. In Aurora, Colorado, Brittney Gilliam and four children were held at gunpoint after police treated an automatic license plate reader hit as a stolen-vehicle match. The vehicle was not stolen. Aurora later agreed to pay $1.9 million to resolve the case, a figure large enough to move the discussion out of the technology-demo room and into the claims file.[1]
That is the practical shift. A plate reader alert may begin as a machine-readable event, but the legal exposure begins when people in government act on it: dispatchers, patrol officers, supervisors, records staff, procurement officials, and agency lawyers who later have to explain why a bad match became a seizure.

The settlements are beginning to define the risk
Gilliam is the clearest example because the settlement amount, the roadside facts, and the human consequence line up in one file. The false hit did not merely inconvenience a driver. It produced a high-risk stop involving children, weapons, and a later municipal payout. For a city attorney, that distinction matters. A vendor error that stays inside a database is one kind of problem. A vendor error that becomes a Fourth Amendment event is another.
Toledo shows why Gilliam should not be treated as a lone bad stop. Denise Green received a $495,000 settlement after a Flock-related false hit led police to ambush her vehicle; reporting on the case described systemic errors rather than a single unlucky keystroke.[2] Brandon Upchurch settled for $35,000 after a misread plate was followed by a police dog mauling; in proceedings tied to the dispute, a judge stated that “Flock Flocked up.”[1] Jason Burkleo received a $45,000 settlement in another Toledo false-positive matter.[1]
The amounts are not uniform, and they should not be flattened into one story. Gilliam’s case involved children and a gunpoint detention. Upchurch’s involved physical injury from a dog. Green’s case carried its own stop dynamics and settlement posture. But taken together, they show a pattern useful to lawyers: plaintiffs are not limited to complaining that a camera was wrong. They can trace the alert into police conduct, injury, emotional distress, training, supervision, and municipal policy.
Oakland adds a different jurisdictional signal. Brian Hofer settled for $49,500 after an ALPR error led to a wrongful police stop, according to the Electronic Frontier Foundation’s account of the incident.[3] The dollar figure is smaller than Gilliam’s, but it matters because it reinforces the same remedial chain: a plate-reading error, a police response, a person detained, and a government payment.
| Matter | Reported outcome | Why it matters legally |
|---|---|---|
| Brittney Gilliam, Aurora, Colorado | $1.9 million settlement | False ALPR hit became a gunpoint detention involving children |
| Denise Green, Toledo, Ohio | $495,000 settlement | Reported as part of a broader pattern of Flock-related errors |
| Brandon Upchurch, Toledo, Ohio | $35,000 settlement | Misread plate was followed by a police dog mauling |
| Jason Burkleo, Toledo, Ohio | $45,000 settlement | Additional Toledo false-positive settlement |
| Brian Hofer, Oakland, California | $49,500 settlement | Wrongful stop tied to ALPR error |
The recurring failure is not just optical character recognition
The technology explanation only gets useful when it explains recurrence. Reporting on Flock-related incidents has identified character misreads such as 7 being read as 2, H as M, and O as 0; partial-plate entries in NCIC; stale stolen-vehicle records; and officer handling of alert confidence as sources of bad outcomes.[2] Those are not the same defect. A camera misread, a bad hotlist record, and an officer’s decision to rely on a low-confidence hit present different proof problems.

That distinction is important in litigation because the camera’s first read is rarely the last legally relevant act. Someone has to decide whether the alert is strong enough to justify a stop. Someone has to compare the plate, the make, the model, the state, the timestamp, and the underlying stolen-vehicle record. Someone has to decide whether the stop should be treated as a high-risk felony stop or a lower-level investigative encounter.
A city defending one of these cases may want to describe the triggering event as a data error. Plaintiffs will usually try to move the factfinder past that point. Their question will be narrower and more damaging: what did the agency know about false hits, what verification steps were required, and why did the officer proceed as if the alert were enough?
Audits and local data make foreseeability harder to deny
The strongest defense posture for an agency is usually that an error was rare, unforeseeable, and handled contrary to policy. That posture becomes harder when public audits or local transparency data show meaningful error levels. Business Insider reported that an LAPD Inspector General audit found 32.3% of Flock alerts inaccurate over a two-month period and identified 161 vehicles falsely flagged as stolen.[1]
Oak Park, Illinois, presents another local warning sign. A review published by Freedom to Thrive Oak Park reported that 40% of Flock-initiated stops were mistakes caused by bad data or officer error, and that Black drivers were disproportionately affected.[4] That finding does not prove every Flock deployment has the same error profile. It does show why agencies cannot responsibly treat false positives as impossible or merely anecdotal.
For litigation purposes, these materials do not have to establish a universal national error rate. They can be used in a more targeted way: to show that ALPR false positives were a known category of risk, that verification procedures mattered, and that local agencies had reason to measure their own alert outcomes before relying on the system in high-risk stops.
Section 1983 exposure turns on the human decision after the alert
The federal civil rights question is not simply whether Flock’s system generated a bad match. The more important question is whether police used that match in a way that violated the Fourth Amendment and whether the municipality can be tied to the violation through policy, custom, training, supervision, or deliberate indifference.
A false alert alone may not answer probable cause or reasonable suspicion. Courts will look at what officers knew and what they did with it. Did the officer visually confirm the full plate? Was the vehicle make and model consistent with the hotlist entry? Was the plate state the same? Was the stolen-vehicle record current? Did the alert show confidence information, and did the officer understand it? Did policy require dispatch confirmation before a stop? Those facts convert a technical mistake into a constitutional record.
The severe-stop cases are especially dangerous for municipalities because the damages story is easy to understand. A person pulled from a car at gunpoint, a child handcuffed, or a driver bitten by a police dog does not need a jury to understand computer vision. The plaintiff only has to show how an unverified or mishandled alert became state force.
Failure-to-train theories fit the known failure modes
Failure-to-train claims become more plausible when the alleged error pattern is specific. It is one thing to say officers should be trained on technology generally. It is another to point to recurring partial-plate problems, stale stolen-vehicle data, character confusion, confidence-level handling, and felony-stop escalation. Those are trainable issues, and they are auditable issues.
The records that matter will often be ordinary municipal documents: rollout emails, vendor training slides, general orders, dispatch protocols, hotlist update procedures, body-camera footage, CAD notes, and after-action reviews. If those records show that officers were told an alert was only an investigative lead, the defense has one kind of case. If the records show that the system was marketed internally as near-certain and officers were given little verification guidance, the risk profile changes.
California privacy claims move the fight beyond the roadside stop
The pending Gibbs Mura class action changes the focus from the false stop to the data-sharing architecture. Filed in February 2026, the lawsuit alleges that Flock violated California privacy law by sharing ALPR data with out-of-state agencies millions of times.[5] The case remains pending, so the allegations should not be treated as adjudicated facts. But the theory is significant because it does not require a plaintiff to have been stopped at gunpoint to claim legal harm.
California Civil Code §1798.90.54 is the statute at issue in that risk channel, and the research materials identify a minimum statutory amount of $2,500 per violation for unauthorized ALPR data access or sharing.[5] That number is what gets counsel’s attention. In a roadside-stop case, damages usually turn on the facts of the detention. In a data-sharing case, exposure can be argued through the number of allegedly unlawful accesses or disclosures.
This is where contract diligence becomes more than a procurement formality. A public agency using ALPR data has to understand who can access it, which agencies receive it, whether sharing crosses state lines, how user permissions are granted, how audits are logged, and whether the vendor’s default settings match the agency’s legal authority. The wrong answer may not produce a dramatic body-camera scene, but it can still produce statutory exposure.

Vendor credibility now belongs in the legal file
The ACLU’s July 2, 2026 credibility report accused Flock Safety of repeatedly misleading city councils, police departments, and the public across the country.[6] That report is advocacy, not a judicial finding. Still, for municipal counsel, it is relevant contracting context. If a city relied on vendor statements about safeguards, accuracy, sharing limits, or oversight, those statements may become exhibits after a bad stop or an unlawful-sharing claim.
The problem is not that a vendor made an optimistic sales pitch. Public agencies buy optimistic sales pitches all the time. The problem is that ALPR systems feed directly into police encounters and criminal-investigation workflows. Representations about accuracy, data access, retention, and interagency sharing therefore bear on constitutional risk, statutory compliance, and indemnity disputes.
Flock’s internal accuracy data is not publicly published in the materials reviewed here. That absence should not be filled with unsourced error-rate claims, and it should not be ignored either. Agencies evaluating these systems should separate vendor disclosures from independent audits, local stop data, public-records material, and litigation evidence.
What a defensible ALPR file has to answer
The practical legal file is broader than the contract. It should answer how the agency verified alert accuracy, how officers were trained to treat alerts, how hotlists were maintained, and how the vendor’s data-sharing settings were constrained. Those questions are not policy abstractions once settlements and pleadings show the path from alert to injury.
- Accuracy evidence: whether the agency has local false-positive data, audit rights, and access to alert-confidence information.
- Hotlist hygiene: whether stolen-vehicle records, partial-plate entries, and stale records are checked before a stop.
- Alert verification: whether policy requires visual confirmation of the full plate, state, make, model, and current record status.
- Officer training: whether officers are trained that ALPR alerts are leads, not automatic probable cause.
- Data-sharing authority: whether interagency access, out-of-state sharing, retention, and user permissions match state law.
- Contract remedies: whether indemnity, audit access, data logs, deletion duties, and cooperation clauses survive an actual claim.
None of those questions decides liability by itself. They do, however, determine whether an agency can show that it treated false positives as a known operational risk rather than a surprise after the plaintiff’s lawyer served the complaint.
The risk is now documented enough to be foreseeable
Flock false positives have produced significant settlements, pending privacy litigation, audit findings, and public controversy over vendor representations. The current record does not prove that every Flock deployment is defective, and it does not support a single national error rate. It does support a narrower and more important legal conclusion: false-positive ALPR stops are a documented category of foreseeable risk.
That changes the posture for public agencies and the company alike. Future plaintiffs will not have to frame a bad stop as an isolated machine mistake. They can frame it as a foreseeable failure in a deployed surveillance workflow: an alert generated, a record left stale, a confidence level missed, a plate insufficiently checked, a policy not followed, a training gap left open, or a data-sharing setting approved without legal authority.
This article is a risk synthesis, not legal advice. Specific claims will still turn on jurisdiction, policy language, officer conduct, contract terms, and proof. But as of July 19, 2026, accuracy evidence, hotlist hygiene, alert verification, officer training, indemnity, audit access, and data-sharing authority are liability questions, not procurement afterthoughts.
References
- Flock Safety ALPR cameras misreads, Business Insider, March 2026.
- Inside The Flock Dragnet: How Systemic Errors Led To Police Ambushing Me For No Reason, The Drive.
- The Human Toll of ALPR Errors, Electronic Frontier Foundation, November 2024.
- Erroneous Flock Stops in Oak Park, Freedom to Thrive Oak Park.
- Flock Safety License Plate Reader Cameras Lawsuit, Gibbs Law Group.
- Flock Safety Credibility Lost As It Repeatedly Lies to City Councils, Police Departments, and Public Across the Country, ACLU, July 2, 2026.
Comments
Join the discussion with an anonymous comment.