Case in one sentence
For eight years a pharmacy chain used facial recognition to flag suspected shoplifters in hundreds of stores, and — on the Federal Trade Commission’s account — never tested whether it worked, never tracked how often it was wrong, and let staff search, expel, and call the police on the people it misidentified.
Case status note
Almost everything below is an allegation. The FTC filed its complaint and a negotiated settlement on the same day, 19 December 2023. Rite Aid “neither admit[ted] nor den[ied] any of the allegations in the Complaint.”1 No court weighed the evidence, no witness was cross-examined, and Rite Aid never filed an answer. What is established is the order: its terms bind, and they are labelled Verified below. What Rite Aid did is labelled Attributed throughout, and readers should hold it that way.
The company did say something that day, and it is not what the complaint says. Rite Aid’s press release stated that it was pleased to reach agreement but disagreed with the allegations, and characterised them as relating to “a facial recognition technology pilot program the Company deployed in a limited number of stores”, adding that it had stopped using the technology more than three years earlier, before the FTC opened its investigation.2 The complaint describes hundreds of stores over eight years. Both statements are in this case; neither is resolved here. The company’s reaches it at two removes, through a mirror of a news report, because the outlets that carried it are unreachable from this sandbox.
Executive summary
Between 2012 and 2020 Rite Aid deployed facial recognition in hundreds of its retail pharmacies to identify people it believed had shoplifted or behaved badly, using technology from two third-party vendors it does not name.3 Most installations were in and around New York City, Los Angeles, San Francisco, Philadelphia, Baltimore, Detroit, Atlantic City, Seattle, Portland, Wilmington, and Sacramento.3
The system compared shoppers against a database of “enrollments” — images of individuals with names, birth years, and notes about alleged conduct. Images came from CCTV excerpts, the facial recognition cameras themselves, mobile phone photographs, and in some cases photographs of driver’s licences or of images displayed on video monitors. Employees were trained to “push for as many enrollments as possible”, and tens of thousands of people were enrolled.3
The Commission’s central charge is not that the technology was biased. It is that Rite Aid never found out. The complaint alleges the company failed to test accuracy before deployment, failed to enforce its own image-quality standards, failed to train the staff who acted on alerts, and failed to implement any procedure for tracking the false-positive rate after go-live.3
What the records that did exist showed: thousands of false-positive alerts recorded between December 2019 and July 2020; more than 5,000 alerts fired in stores over 100 miles from the store that created the enrollment; over 2,000 alerts so close in time across distant locations that the same person could not have been in both; and, in one five-day stretch, more than 900 alerts for a single enrollment across more than 130 stores — a majority of every location running the technology.3
Staff acted. They followed people, searched them, ordered them out, publicly accused them, and called the police.3 An 11-year-old girl was stopped and searched on a false match; her mother missed work because the child was so distressed.43 Police were called on a Black customer over an alert generated against an image later described as depicting “a white lady with blonde hair.”4
Rite Aid did not tell customers the technology was in use, and instructed employees not to reveal it.3
The settlement bans Rite Aid from using facial recognition in any retail store, retail pharmacy, or online retail platform for five years, and requires deletion of the biometric information collected.1 The company had filed for Chapter 11 two months earlier, and needed the Bankruptcy Court’s approval to enter the order at all.1
Research question
What happens when an organisation deploys a system whose errors fall on members of the public, and never builds the one measurement that would tell it how often it is wrong?
Organization and operating context
Rite Aid Corporation was one of the largest US pharmacy chains. The relevant fact about its posture is that it was already under a federal order: in 2010 the FTC charged it with deceptive practices over its handling of personal information, and the resulting order — still in effect — required it to maintain a comprehensive information security program and to retain compliance documents.3 The 2023 complaint charges violations of that order as a second count alongside the facial recognition claims.1
By the time the action was filed, Rite Aid and its headquarters entity had petitioned for Chapter 11 relief, on 15 October 2023.1
The technology came from two outside vendors who “operated and supported the technology on Rite Aid’s behalf and at its direction”; one also supplied biometric technology for Rite Aid’s distribution centres.3 Neither is named in the complaint, which matters: without knowing the algorithm, nobody can check its measured performance against published benchmarks.
The situation before AI
Retail loss prevention before facial recognition is human: staff watch, security officers patrol, and known repeat offenders are recognised by memory or by a photograph pinned in a back room. That system has its own well-known failure mode — it also produces wrongful accusations, and disproportionately.
What facial recognition changed is scale and transferability. A memory does not travel between states. An enrollment does: the complaint’s most striking allegation is a single database entry generating hundreds of alerts in New York and Los Angeles, over 100 in Philadelphia, and more in Baltimore, Detroit, Sacramento, Delaware, Seattle, Manchester, and Norfolk — within five days.3
The AI intervention or event
Enrollment. People were added to the database when Rite Aid believed they had engaged in criminal activity at a store, or on “BOLO” information from law enforcement. Entries carried images plus, where known, names, birth years, and notes on alleged behaviour.3
Rite Aid had image-quality standards — subjects facing forward, eyes aligned with the tops of the ears, glasses off, neutral expression.3 The complaint alleges it routinely ignored them, using blurry camera captures, overexposed and glare-affected images, and photographs taken in low natural light. A Rite Aid employee told the vendor that “[t]he majority of images captured by [Rite Aid’s facial recognition] cameras” and enrolled were of inadequate quality, noting that the cameras did not adjust to changing daylight and that much of the activity being captured happened at night.3
Matching and alerting. When the system matched a shopper against an enrollment, it alerted employees.4 Store-level staff typically did not receive confidence intervals that would have helped them judge whether a match was likely false.4
Action. Employees followed consumers, searched them, ordered them to leave, publicly accused them — sometimes in front of friends or family — and called the police.3
What was not done. No accuracy testing before deployment. No enforcement of the image standards. No meaningful training or oversight of the staff interpreting alerts. And no procedure of any kind for tracking the false-positive rate once the system was live.3 The complaint alleges that an internal presentation about expanding the programme identified exactly one risk: “[m]edia attention and customer acceptance.”4
Where it was deployed. Approximately 80% of Rite Aid stores were in plurality-White areas. About 60% of the stores running facial recognition were in plurality non-White areas.3 The complaint alleges Rite Aid prioritised what it called “urban” areas and stores along public transport routes without considering the distributional effect.3
Outcomes and economics
There is no revenue figure, no cost figure, and no measure of loss prevented anywhere in this record. Rite Aid never quantified what the system caught, and the FTC did not need to.
What is quantified is error, from the records Rite Aid did keep:3
| Indicator, December 2019 to July 2020 unless stated | Figure |
|---|---|
| False-positive match alerts recorded by employees | thousands |
| Alerts in stores more than 100 miles from the enrolling store | over 5,000 |
| Alerts implausibly close in time across distant locations | over 2,000 |
| Alerts from one enrollment in a five-day period | over 900, across 130+ stores |
| Individuals enrolled in the database | at least tens of thousands |
| Rate of false positives tracked by any Rite Aid procedure | none |
The last row is the case. Every number above is a byproduct of records kept for other reasons; the complaint alleges there was “a general failure to record the accuracy or outcomes of match alerts.”3 Nobody at Rite Aid could have said what fraction of alerts were wrong, because nobody counted.
The remedy. Five years’ prohibition on deploying or using any facial recognition or analysis system in any retail store, retail pharmacy, or online retail platform; deletion of the covered biometric information; and comprehensive programme requirements.1 No monetary relief to consumers appears in the order read here, and the company entering it was in Chapter 11.
Causal assessment and competing explanations
Labelled descriptive. The record documents a deployment and an enforcement action. It contains no measured error rate for Rite Aid’s system, no controlled comparison against loss prevention without the technology, and no estimate of how many of the alerts staff acted on were wrong.
Three things deserve careful separation, because they are routinely collapsed.
“The technology is racially biased” is not what the FTC established, and not quite what it alleged. The complaint’s paragraph 42 states the general proposition — that many facial recognition technologies produce more false positives for Black or Asian subjects than White, and higher error rates for women than men — as background.3 It then alleges that Rite Aid “made no effort” to consider it. NIST’s own testing supports the general proposition and complicates it: false positive differentials by race and country of birth can reach a factor of 100, women show consistently higher false positives than men, and the elderly and children are elevated — but the effect is reversed for some algorithms developed in China, and a few developers submitted identification algorithms with undetectable false positive differentials.5 Differentials are a property of particular algorithms, not of the technology as such. Which is exactly why NIST’s stated implication is that “it is incumbent upon the system owner to know their algorithm”, measured on operational data.5
So the honest formulation is narrow and worse for Rite Aid than the loose one: the company deployed an unnamed algorithm in disproportionately non-White neighbourhoods without ever measuring whether that algorithm misidentified the people living there. NIST published the instruction to measure in December 2019, during the deployment.5
Disparate deployment is established more clearly than disparate error. The 80%-versus-60% comparison describes where the cameras were, which the complaint alleges from Rite Aid’s own footprint.3 It does not establish differential error rates within the system, because those were never measured.
“Neither admit nor deny” is not a finding of innocence, and settlement is not proof. Rite Aid was in bankruptcy, negotiating with a regulator that already held a 2010 order against it. A company in that position has reasons to settle that are independent of the merits, in either direction. This case does not resolve which applied.
Failures, limitations, and governance
- No false-positive rate, ever. Eight years of operation with no procedure to track how often the system was wrong — the single omission from which most of the rest follows.3
- No accuracy testing before or after deployment.3
- Image quality standards existed and were not enforced. The company knew its own cameras produced inadequate images; an employee told the vendor so.3
- The only recorded risk was reputational. An expansion presentation identifying “media attention and customer acceptance” as the risk is a governance artefact worth reading twice: the harm being managed was to the company.4
- Alerts arrived without confidence information. Store staff were asked to act on a match with no indication of how confident the system was.4
- Enrollment volume was an incentive. “Push for as many enrollments as possible” grows the database — and a larger gallery of low-quality images raises the false-positive rate.3
- Consumers were not told, deliberately. Employees were instructed not to reveal the technology’s use.3
- Deployment was concentrated where the population was least like the training assumptions nobody checked.3
- A prior federal order was already in force and, the FTC charged, being violated.31
- The remedy landed on a company already in Chapter 11. A five-year prohibition binds an entity whose future was being decided in bankruptcy court.1
What this case demonstrates
- An organisation can operate a consequential classifier for eight years without ever knowing its error rate, if nobody requires the measurement. The absence was not a lapse in a monitoring system; there was no monitoring system.
- Precision is the metric that matters when errors fall on the public, and it is the metric most often absent. This library has now recorded the same gap in a hospital that published sensitivity without positive predictive value and a factory that published recall without precision. Here nothing was published because nothing was counted.
- Automation makes an accusation portable. A single enrollment produced over 900 alerts in more than 130 stores in five days — a scale of repeated misidentification that a human memory cannot generate.
- Where a system is deployed is a design decision with distributional consequences, independent of the model. Cameras concentrated in plurality non-White neighbourhoods redistribute error before any algorithm runs.
- Independent benchmarks existed and pointed at the right action. NIST’s 2019 testing did not say “facial recognition is biased” — it said differentials vary by algorithm and owners must measure their own on their own data.5
- A risk register that lists only reputational risk is evidence about what an organisation thinks it is protecting.
- Human review is not a safeguard when the human is given an alert and no confidence estimate, no training, and an instruction to act.
- Enforcement can reach an AI deployment through ordinary consumer-protection law. The FTC did not need an AI statute; unfairness under Section 5 was sufficient.
- Settlements buy remedies, not facts. The ban is real and the findings are not, and a case record has to keep those apart.
What this case does not demonstrate
- It does not establish that Rite Aid did any of the things alleged. The company neither admitted nor denied, and no court weighed the evidence.1
- It does not establish the system’s false-positive rate, because on the FTC’s own account it was never measured.
- It does not show that Rite Aid’s algorithm had demographic differentials. The vendors are unnamed, the algorithm untested, and NIST’s finding is that differentials are algorithm-specific.5
- It does not quantify how many people were wrongly stopped, searched, expelled, or reported to police. The complaint describes categories of harm and specific incidents, not totals.
- It does not show the system prevented any theft, or what it cost to run. Neither figure exists in this record.
- It does not tell you whether the deleted biometric information was in fact deleted, or how the five-year prohibition was monitored in a company undergoing bankruptcy.
- It does not describe retail facial recognition generally. This is one chain’s deployment as characterised by its regulator.
- It does not address whether the technology could be operated responsibly. The FTC’s theory is about the absence of safeguards, not the impossibility of them, and the order is a five-year prohibition rather than a permanent one.
Evidence assessment
Grade B — authoritative primary documents about an action, resting on allegations nobody ever tested.
The documentary quality is high. The complaint is a federal court filing authorised by a 3-0 Commission vote, drawing on an investigative record that includes Rite Aid’s internal presentations, its correspondence with its vendor, its employee training material, and its own alert records — material no outside party could obtain.3 The order is court-entered and binding.1 The Commissioner’s statement footnotes every factual claim to a numbered paragraph.4 And on the one general proposition the complaint asserts as background, NIST supplies a genuinely independent chain: 189 algorithms, 99 developers, 18.27 million images, published protocol, exhaustive annexes.5
What holds the case at B is structural and cannot be repaired from this record.
The allegations were never tested. Paragraph 5 of the stipulated order records that the defendants neither admit nor deny them.1 A complaint is the prosecuting party’s best case, drafted to establish liability, quoting internal documents it selected. Rite Aid never answered it. Under this library’s rules an unproven allegation is Attributed, never Verified, and the material claims table applies that without exception to conduct.
Three of the five sources are one chain. The complaint, the order, and the Commissioner’s statement all issue from the same action on the same day and trace to the same investigation; the statement is explicitly a reading of the complaint. NIST is a separate chain but speaks only to the general behaviour of facial recognition algorithms, not to anything Rite Aid did. So the prosecuting account of the conduct still has exactly one source.
The company’s side of it reaches this case at two removes. Rite Aid’s press statement is the only account of the conduct here that is not the FTC’s, and it matters: it disputes the scale directly. But reuters.com and cnbc.com are both unreachable from this sandbox, so it is read through the AI Incident Database’s mirror of a CNBC report quoting the release.2 That is a relay of a relay and is labelled as one. It is enough to move a claim from Attributed to Disputed — recording that two parties say different things is a low bar and the right one — and nowhere near enough to settle which is right. The same relayed report names the two vendors the complaint withholds, on the authority of a 2020 Reuters investigation this review could not read; those names are deliberately not repeated in this case.
The reporting that started it is out of reach. The FTC’s action followed press investigation of Rite Aid’s use of the technology. That journalism could not be read from this sandbox, so it is not cited, and the case is poorer for lacking any account of these events that is not the government’s.
The vendors are unnamed. Without knowing which algorithms ran, the deployment cannot be assessed against NIST’s per-algorithm results — which is the assessment NIST says a system owner should have done, and the one the complaint alleges Rite Aid never did.
Two conflicts are worth naming rather than assuming. The FTC drafted the complaint to win; it is not a neutral history. And Rite Aid settled while in Chapter 11 and subject to a prior 2010 order, a position that gives a company reasons to settle regardless of the merits.
One clarification about NIST, because the shorthand version of its finding is misleading and this case declines to use it. NIST did not find that facial recognition is uniformly biased. It found large differentials that vary by algorithm — reversed for some developers, undetectable for others — and concluded that owners must measure their own system on their own data.5 That is a more demanding standard than “the technology is biased”, and it is the standard the FTC alleges Rite Aid failed.
Material claims
| Claim | Label | Evidence | What would change this |
|---|---|---|---|
| Rite Aid used facial recognition in hundreds of stores from 2012 to 2020. | Disputed | Alleged in the FTC’s complaint and neither admitted nor denied; Rite Aid’s own statement the same day calls it “a facial recognition technology pilot program the Company deployed in a limited number of stores”312 | Adjudicated findings, store-level deployment records, or the Reuters investigation that reported on the deployment’s extent |
| Rite Aid stopped using the technology before the FTC opened its investigation. | Attributed | The company’s own statement; the complaint’s own end date of 2020 is consistent with it but does not establish the investigation’s start23 | The investigation’s opening date, or an FTC response to the claim |
| Rite Aid never implemented any procedure for tracking the false-positive rate. | Attributed | Alleged as a specific failure in the complaint’s unfairness count3 | Production of a monitoring procedure, or adjudicated findings |
| The system generated thousands of recorded false-positive alerts between December 2019 and July 2020. | Attributed | Alleged from Rite Aid’s own records, which the complaint says were kept only incidentally3 | The underlying records, or adjudicated findings |
| One enrollment produced over 900 alerts in more than 130 stores in five days. | Attributed | Alleged with locations itemised — New York, Los Angeles, Philadelphia, Baltimore, Detroit, Sacramento, Delaware, Seattle, Manchester, Norfolk3 | The alert logs, or adjudicated findings |
| Employees searched, expelled, publicly accused, and called police on people flagged by false matches. | Attributed | Alleged, with an 11-year-old girl stopped and searched, and police called on a Black customer over an image later described as “a white lady with blonde hair”34 | Adjudicated findings, or contemporaneous records contradicting the incidents |
| About 60% of stores using the technology were in plurality non-White areas, against about 80% of all Rite Aid stores being in plurality-White areas. | Attributed | Alleged from Rite Aid’s store footprint3 | An independent count of store locations against census data |
| Rite Aid did not inform consumers and instructed employees not to reveal the technology’s use. | Attributed | Alleged in the complaint3 | Evidence of signage or disclosure, or adjudicated findings |
| An internal expansion presentation identified only “media attention and customer acceptance” as a risk. | Attributed | Quoted by a Commissioner from the complaint’s record4 | The presentation itself, or adjudicated findings |
| Rite Aid neither admitted nor denied the allegations. | Verified | Stated at paragraph 5 of the court-entered stipulated order1 | Nothing; this is the order’s text |
| Rite Aid is prohibited for five years from using facial recognition in any retail store, retail pharmacy, or online retail platform, and must delete covered biometric information. | Verified | Provisions I and II of the court-entered order1 | Modification or dissolution of the order |
| Rite Aid was in Chapter 11 when the order was entered and needed Bankruptcy Court approval for it. | Verified | Recited in the order’s opening and in its stipulations1 | Nothing; this is the order’s text |
| Facial recognition algorithms show demographic differentials in false positive rates. | Verified | NIST tested 189 algorithms from 99 developers on 18.27 million images: false positives highest in West and East African and East Asian subjects on application photos with differentials up to a factor of 100, higher in women than men consistently, elevated in the elderly and in children5 | A larger or more recent benchmark reaching different conclusions |
| Those differentials are uniform across algorithms. | Disputed | NIST found the effect reversed for a number of algorithms developed in China, and undetectable for some identification algorithms — which is why it recommends owners test their own5 | A benchmark showing uniformity across developers |
| Rite Aid’s own algorithm misidentified Black, Asian, or women customers at elevated rates. | Unknown | Never measured by Rite Aid on the FTC’s account, and the vendors are unnamed so no published benchmark can be matched to the system35 | Identification of the vendors plus benchmark results, or testing of the retained system |
| The system prevented theft, or what it cost to operate. | Unknown | No figure for loss prevented, system cost, or benefit appears in any source read | Disclosure by Rite Aid or in bankruptcy proceedings |
| The ordered deletion of biometric information was carried out. | Unknown | No compliance report was found; the company was in bankruptcy | An FTC compliance filing or enforcement action |
Direct quotations
“Defendants neither admit nor deny any of the allegations in the Complaint, except as specifically stated in this Stipulated Order or in the Decision and Order set forth in Attachment A.”
— The stipulated order, on the evidentiary status of everything the complaint alleges1 · locator: Stipulated Order, FINDINGS, paragraph 5
“IT IS ORDERED that Respondents, in connection with the activities of any Covered Business, are prohibited for five (5) years from the effective date of this Order from deploying or using, or assisting in the deployment or use of, any Facial Recognition or Analysis System, whether directly or through an intermediary, in any retail store or retail pharmacy or on any online retail platform.”
— The operative prohibition1 · locator: Decision and Order, Provision I, “Use of Facial Recognition or Analysis Systems Prohibited”
“Rite Aid trained store-level security employees to ‘push for as many enrollments as possible.’”
— The FTC’s complaint, on how the database grew3 · locator: Complaint, paragraph 23
“In fact, although approximately 80 percent of Rite Aid stores are located in plurality-White (i.e., where White people are the single largest group by race or ethnicity) areas, about 60 percent of Rite Aid stores that used facial recognition technology were located in plurality non-White areas.”
— The FTC’s complaint, on where the cameras went3 · locator: Complaint, paragraph 41
“[E]very black man is not [a] thief nor should they be made to feel like one.”
— A consumer writing to Rite Aid after being confronted on a false match, quoted in the complaint3 · locator: Complaint, paragraph 92
“A Rite Aid employee stopped and searched an 11-year-old girl because of a false match. The girl’s mother reported that she missed work because her daughter was so distraught about the incident.”
— Commissioner Bedoya, summarising complaint paragraph 914 · locator: Statement of Commissioner Bedoya, section 1, first bullet
“Operational implementations usually employ a single face recognition algorithm. Given algorithm-specific variation, it is incumbent upon the system owner to know their algorithm.”
— NIST, four years before the FTC’s action and during Rite Aid’s deployment5 · locator: NISTIR 8280, Executive Summary, “Implications of these tests”
Revision notes
-
2026-09-13 — Source review. Added the one voice this case was missing: Rite Aid’s own. Its press statement on the day of settlement disputes the complaint’s scale directly, calling the programme “a facial recognition technology pilot program the Company deployed in a limited number of stores” against the complaint’s hundreds of stores over eight years, and says use stopped more than three years before the FTC opened its investigation. The scale claim moves from
AttributedtoDisputedand a second claim is added; neither is resolved, per the rule on recording discrepancies rather than settling them. The source is a relay of a relay and says so on its face — reuters.com and cnbc.com are both unreachable from this sandbox, so the release is read through the AI Incident Database’s mirror of a CNBC report. Grade stays B: a defendant’s denial is a competing account, not corroboration. One thing was deliberately left out. The same relayed report states that a 2020 Reuters investigation named Rite Aid’s two vendors, which this case’s upgrade path asks for; the names are not repeated here, because the identification sits two removes from an unreachable original and concerns third parties who were never before the Commission. The upgrade path now records where that identification lives so a future editor with Reuters access can close it in one step. -
2026-09-13 — Initial publication at Grade B. The library’s first
retailcase, and its first built primarily on an untested pleading, which shapes everything: the complaint, the stipulated order, and the Commissioner’s statement are one evidentiary chain from one action on one day, and Rite Aid neither admitted nor denied any of it. Every conduct claim is therefore labelled Attributed and the case carries a status note above the executive summary saying so, rather than letting a well-sourced complaint read as findings. Only the order’s own terms are Verified. NIST’s FRVT Part 3 is the second chain and is cited with care: it supports demographic differentials in general and explicitly contradicts the uniform version of that claim, which is recorded asDisputed. The press investigation that preceded the FTC action could not be read from this sandbox and is not cited, leaving the case without any account of these events that is not the government’s — a gap named in the evidence assessment. Related to AAI-2026-006 and AAI-2026-013 by the recurring absence of a precision figure, and to AAI-2026-009 by distributional harm from an unvalidated selection system.
Footnotes
-
Federal Trade Commission and Rite Aid Corporation, Stipulated Order for Permanent Injunction and Other Relief, FTC v. Rite Aid Corporation, Case 2:23-cv-05023 (E.D. Pa.), filed 2023-12-19. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17
-
Rite Aid Corporation’s press-release response to the FTC settlement, quoted in “Rite Aid to be barred from using facial recognition under proposed FTC settlement”, CNBC, 2023-12-19, read through the AI Incident Database’s mirror, report 3511. A relay of a relay: neither reuters.com nor cnbc.com is reachable from this sandbox and neither original was read. ↩ ↩2 ↩3 ↩4
-
Federal Trade Commission, Complaint for Permanent Injunction and Other Relief, FTC v. Rite Aid Corporation and Rite Aid Hdqtrs. Corp., Case 2:23-cv-05023 (E.D. Pa.), filed 2023-12-19. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33 ↩34 ↩35 ↩36 ↩37 ↩38 ↩39 ↩40 ↩41 ↩42
-
Alvaro M. Bedoya, “Statement of Commissioner Alvaro M. Bedoya On FTC v. Rite Aid Corporation & Rite Aid Headquarters Corporation”, FTC File No. 202-3190, 2023-12-19. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
Patrick Grother, Mei Ngan, and Kayee Hanaoka, “Face Recognition Vendor Test (FRVT) Part 3: Demographic Effects”, NISTIR 8280, National Institute of Standards and Technology, 2019-12-19, doi:10.6028/NIST.IR.8280. ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
Evidence ledger
BWell supported
Credible original evidence supports the central account, but access, corroboration, measurement, completeness, or reproducibility carries a material limitation.
- Material sources
- 5
- Independent chains
- 3
- Archived
- 0 of 5
The 5 sources below trace back to 3 separate origins. Whether those origins corroborate one another on this case's central claims is assessed in the case, not implied by the count. 1 chain carries more than one source; those sources corroborate each other's reporting, not the underlying evidence.
What would strengthen this case
The central obstacle to grade A is that the allegations were never tested: Rite Aid neither admitted nor denied them and the case settled before any evidence was weighed. Adjudicated findings would resolve that, and cannot now arise from this action. Short of it: the underlying investigative record — the internal presentations, the vendor correspondence, the employee training material the complaint quotes — would let a reader check the FTC's characterisations; the identity of the two vendors, which the complaint withholds, would allow the technology itself to be assessed against published benchmarks — a 2020 Reuters investigation is reported to name them, but reuters.com is unreachable from this sandbox and the only readable account of that naming is two relays from the original, so this case does not name them and a future editor with access to the Reuters piece can close the gap in one step; and any measurement of Rite Aid's own algorithm on its own images, which on the FTC's account never existed, would settle whether the demographic differentials NIST documents in general were present in this deployment in particular.
Chain 1 of 3Shared origin:
ftc-riteaid-actionComplaint for Permanent Injunction and Other Relief, FTC v. Rite Aid Corporation and Rite Aid Hdqtrs. Corp., Case 2:23-cv-05023 (E.D. Pa.)
Primary investigationDiscovery
- Access
- The Commission's investigative file: Rite Aid's internal presentations, employee training material, correspondence between Rite Aid staff and its facial recognition vendor, the match-alert records the company did keep, and consumer complaints made to the company.
- Method
- A federal agency's civil complaint under Sections 5(a) and 5(n) of the FTC Act, pleading unfair acts or practices. It is an accusatory pleading, not a finding: it states what the Commission alleges it could prove, and no court weighed any of it.
- Conflicts
- The prosecuting party's account of the conduct it is prosecuting, drafted to establish liability. It quotes internal documents selectively by design, and Rite Aid's answer to it was never filed because the case settled the day it was brought.
- Corroboration
- The order entered alongside it confirms the charges brought and the relief agreed, not the facts. Its general claim about demographic differentials in facial recognition is independently supported by NIST's own testing; its specific claims about Rite Aid are corroborated by nobody.
- Accountability
- Filed in federal court under a docket number, authorised by a 3-0 Commission vote, publicly available in full, with exhibits identified.
- Notes
- Read in full, 38 numbered pages across a 54-page PDF. Every factual allegation drawn from it is labelled Attributed in this case, because Rite Aid neither admitted nor denied them. Paragraph numbers are given as locators where quoted.
Accessed Sep 13, 2026No archive snapshot
Stipulated Order for Permanent Injunction and Other Relief, FTC v. Rite Aid Corporation, Case 2:23-cv-05023 (E.D. Pa.)
Direct evidence
- Access
- The negotiated terms themselves, agreed by both parties and submitted for entry by the court.
- Method
- A consent order. It records the charges, the relief, and the parties' stipulations. Its findings are jurisdictional only; paragraph 5 states that the defendants neither admit nor deny the allegations.
- Conflicts
- A negotiated document, agreed by a company that had filed for Chapter 11 two months earlier and needed Bankruptcy Court approval to enter it. The terms reflect what the parties would accept, not what a court determined.
- Corroboration
- Its terms are restated accurately in the Commission's public announcement of the action.
- Accountability
- Court-entered order with a docket number, binding and enforceable, publicly available in full.
- Notes
- Read in full. This is the only document in the case whose contents are established rather than alleged, which is why the order's terms are labelled Verified here while the conduct is not.
Accessed Sep 13, 2026No archive snapshot
Statement of Commissioner Alvaro M. Bedoya On FTC v. Rite Aid Corporation & Rite Aid Headquarters Corporation
Analysis
- Access
- The same complaint, read by a Commissioner who voted for it, with footnoted paragraph citations throughout.
- Method
- A concurring statement. It selects from the complaint and places the case against prior facial-recognition misidentifications reported elsewhere. It argues a position rather than establishing facts.
- Conflicts
- Written by a Commissioner who voted to bring the action, and who came to the FTC from privacy scholarship on facial recognition. It is advocacy, and it is careful to write 'the Commission alleges' where the complaint is its source.
- Corroboration
- Every claim about Rite Aid in it is footnoted to a numbered paragraph of the complaint, so it is a reading of that source rather than a second one.
- Accountability
- Signed, dated, published on the Commission's site with a file number and full footnotes.
- Notes
- Read in full. Cited here for the 'white lady with blonde hair' incident at complaint paragraph 48, the single risk identified in Rite Aid's expansion presentation, and the absence of confidence intervals for store staff.
Accessed Sep 13, 2026No archive snapshot
Chain 2 of 3Origin:
riteaid-public-responseRite Aid's press-release response to the FTC settlement, quoted in "Rite Aid to be barred from using facial recognition under proposed FTC settlement"
Participant account
- Access
- The accused company's own characterisation of the conduct, issued the day the complaint and settlement were filed. It is the only place in this record where Rite Aid describes the programme in its own words.
- Method
- Not an investigation. A company press statement, quoted in a news report, read here through a third-party mirror of that report. Two of its assertions are checkable against the complaint and one is not.
- Conflicts
- The defendant describing its own conduct on the day it settled, while in bankruptcy, having neither admitted nor denied the allegations. Every incentive runs toward minimisation.
- Corroboration
- Its claim that use stopped before the investigation is consistent with the complaint's own end date of 2020. Its characterisation of scale — a pilot in a limited number of stores — is not consistent with the complaint's hundreds of stores over eight years, and this case records the conflict rather than picking a side.
- Accountability
- A company press release, attributable to Rite Aid and issued publicly, but reaching this case at two removes. Neither reuters.com nor cnbc.com is reachable from this sandbox; the AI Incident Database's mirror of the CNBC report is, and is cited as the relay it is.
- Notes
- A relay of a relay, and labelled as one. It is in this record because the case otherwise contains no account of the conduct except the prosecuting party's. The same relayed report states that a 2020 Reuters investigation identified Rite Aid's two vendors by name; this case deliberately does not repeat those names, because the identification is two removes from an unreachable original and concerns third parties who were never before the Commission.
Accessed Sep 13, 2026No archive snapshot
Chain 3 of 3Origin:
nist-frvtFace Recognition Vendor Test (FRVT) Part 3: Demographic Effects
Primary investigationAnalysis
- Access
- 18.27 million images of 8.49 million people from four operational US government datasets — domestic mugshots, immigration benefit application photos, visa photos, and border crossing photos — processed through 189 algorithms from 99 developers.
- Method
- Standardised benchmark testing of submitted algorithms across demographic groups defined by sex, age, and race or country of birth, reporting false positive and false negative rates separately for one-to-one verification and one-to-many identification, with more than 1,200 pages of per-algorithm charts in annexes.
- Conflicts
- None disclosed. NIST is a federal measurement laboratory with no stake in any vendor; the report notes that identifying commercial products does not imply endorsement.
- Corroboration
- The largest independent evaluation of its kind at the time, and the source the FTC Commissioner's statement cites for the same proposition.
- Accountability
- Named authors, an interagency report number, a DOI, exhaustive published annexes, and a documented test protocol.
- Notes
- Read for this case: the executive summary and results summary, not the 1,200 pages of annexes. Published on 19 December 2019, during Rite Aid's deployment. Its finding is more careful than the shorthand: differentials are large but algorithm-specific, reversed for some developers, and undetectable for a few — which is why its own recommendation is that system owners measure their own algorithm on their own data.
Accessed Sep 13, 2026No archive snapshot