Rite Aid’s use of facial recognition software has become a major warning sign for retailers experimenting with AI-powered surveillance. The Federal Trade Commission said the drugstore chain’s program exposed shoppers to false accusations, public confrontations and risks to sensitive information.
The result is a five-year ban on Rite Aid using facial recognition technology, along with requirements that reach beyond simply switching off the system.
What the FTC order requires
The FTC found that Rite Aid’s facial surveillance systems were used recklessly and harmed customers who were wrongly identified as people suspected of wrongdoing. The order bans the company from using facial recognition software for five years.
The order is still subject to approval from the U.S. Bankruptcy Court because Rite Aid filed for Chapter 11 bankruptcy protection in October. If approved, it will also require Rite Aid to delete images collected through the facial recognition rollout.
That deletion requirement extends to products built from those images. The company must also put in place a robust data security program for personal data it collects.
Those requirements matter because the FTC’s concerns were not limited to whether the software worked well. The agency also focused on how the company gathered, stored, used and protected information connected to customers’ faces.
How Rite Aid used the technology
A Reuters report from 2020 said Rite Aid had secretly introduced facial recognition systems across some 200 U.S. stores over an eight-year period starting in 2012. The report said the rollout used “largely lower-income, non-white neighborhoods” as the testbed for the technology.
According to the FTC’s allegations, Rite Aid worked with two contracted companies to create a “watchlist database.” That database contained images of customers the company said had engaged in criminal activity at one of its stores.
The FTC said those images were often poor quality. They came from sources including CCTV footage and employees’ mobile phone cameras.
When a customer entered a store and the system claimed to match that person to an image in the database, employees received an automatic alert. Most often, the instruction was to “approach and identify,” which meant checking the customer’s identity and asking them to leave.
The central problem, according to the FTC, was that many of those alerts were wrong. False positives led employees to treat customers as suspected shoplifters or wrongdoers when they had been incorrectly identified by the system.
The human cost of false matches
The FTC said the false alerts caused “embarrassment, harassment, and other harm.” In practical terms, that meant customers could be singled out in a store, questioned, searched or removed based on an automated match.
The complaint says: “Employees, acting on false positive alerts, followed consumers around its stores, searched them, ordered them to leave, called the police to confront or remove consumers, and publicly accused them, sometimes in front of friends or family, of shoplifting or other wrongdoing,”
That sequence shows why facial recognition is different from many other retail technologies. A bad match does not stay inside a database. It can quickly become a public accusation in a physical space.
The FTC also said Rite Aid did not tell customers that facial recognition technology was in use. The agency said the company instructed employees specifically not to reveal that information to customers.
That lack of notice made the situation more serious. Customers could be scanned, matched and confronted without knowing that facial recognition was part of the store’s security process.
Accuracy, bias and oversight failures
The FTC’s findings also pointed to the risk of bias in AI systems. The agency said Rite Aid did not mitigate risks to certain consumers because of their race.
According to the findings, the technology was “more likely to generate false positives in stores located in plurality-Black and Asian communities than in plurality-White communities.” That meant the same surveillance program could create different levels of harm depending on where it was used.
The FTC also said Rite Aid failed to test or measure the accuracy of its facial recognition system before deployment or after it was already in use. For a system that could trigger in-store confrontations, that absence of accuracy checks was a major failure point.
Several issues stand out from the FTC’s account:
- The system relied on poor-quality images in the watchlist database.
- Employees were prompted to act on automated alerts.
- False positives led to customers being accused of wrongdoing.
- Customers were not told facial recognition was being used.
- The company did not adequately test or measure the system’s accuracy.
Taken together, those issues show how a flawed surveillance program can turn ordinary shopping into a high-stakes encounter. The technology did not merely observe customers; it shaped how employees treated them.
Rite Aid’s response and the wider signal
Rite Aid said in a press release that it was “pleased to reach an agreement with the FTC,” while also disagreeing with the core allegations. The company described the program as a pilot in a limited number of stores.
Rite Aid said: “The allegations relate to a facial recognition technology pilot program the Company deployed in a limited number of stores,” The company also said: “Rite Aid stopped using the technology in this small group of stores more than three years ago, before the FTC’s investigation regarding the Company’s use of the technology began.”
The case lands during a broader backlash against facial recognition software. The source article notes that cities have issued expansive bans on the technology, politicians have pushed to regulate police use of it, and companies such as Clearview AI have faced lawsuits and fines around the world tied to data privacy breaches involving facial recognition technology.
For retailers, the lesson is direct. Facial recognition systems can create legal, privacy and customer trust risks when companies deploy them without transparency, testing and strong safeguards. The Rite Aid order shows that regulators are willing to treat flawed biometric surveillance as more than a technical problem.