FTC v. Rite Aid — five-year ban on facial recognition surveillance
What happened
From 2012 to 2020 the pharmacy chain Rite Aid ran AI facial recognition in hundreds of stores to flag suspected shoplifters, using tens of thousands of low-quality images collected without telling customers. The system generated thousands of false matches — sometimes to people in other states — and staff acted on them, following, searching and publicly accusing innocent shoppers. Deployment was concentrated in neighbourhoods with large Black, Latino and Asian communities, where error rates were higher. Rite Aid had not tested accuracy or set up oversight.
The rule
Section 5 of the FTC Act (unfair practices). The FTC said deploying biometric surveillance without reasonable safeguards, accuracy testing, staff training or vendor oversight is unfair, and that Rite Aid also breached a 2010 data-security order.
Outcome
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
What this means for you
Buying an AI tool does not outsource the responsibility. Before deploying anything that identifies or scores people, test accuracy across demographic groups, train the humans who act on its outputs, keep a way to challenge results, and supervise your vendor. Regulators treat the absence of those safeguards as the violation.
Laws involved
- Texas TRAIGAIn forceUS-TX
- EU AI ActIn forceEU
- NIST AI RMFVoluntaryintl-standard
Sources
- Rite Aid Banned from Using AI Facial Recognition — FTC press release ↗
- Rite Aid Corporation, FTC v. — case page ↗
- Coming face to face with Rite Aid's allegedly unfair use of facial recognition technology — FTC Business Blog ↗
Last reviewed Sep 25, 2026.