Flock Safety has spent 2026 as the most contested vendor in American policing. Its automated license-plate-reader (ALPR) network, deployed by more than 5,000 police departments, has become the default nervous system for local law enforcement — and, increasingly, a flashpoint for civil liberties groups across the political spectrum. On August 13, 2026, the company announced a package of reforms aimed at defusing that backlash. The question is whether a vendor can regulate itself out of a surveillance problem it built, sold, and profited from.
What Flock Actually Changed
According to Flock's own announcement, the default retention window for license-plate scans drops from 30 days to 7. The company says internal data show more than 90% of plate-only searches are completed within a week, making the shorter window workable without gutting investigative utility. Agencies that need longer retention must use a new "Evidence Mode," which ties extended storage to an active case rather than open-ended browsing. Flock also added offense-based access filtering — a city can let a neighboring department query its cameras for a stolen-vehicle or violent-crime case while blocking immigration-related searches outright — plus a strengthened audit system that proactively locks out officers whose search patterns look abusive, with mandatory case codes and audit-assistance adoption required of all law-enforcement customers by the end of 2026.
These are not cosmetic changes. A seven-day default is a real reduction in the surface area for abuse, and offense-based filtering is a direct response to reporting that federal immigration authorities were reaching Flock's network through local police access — including, per Sen. Ron Wyden's disclosures, roughly 200 searches by Homeland Security Investigations alone. The reforms also follow a well-documented pattern of misuse: The Washington Post has tallied close to 50 cases of officers investigated or fired for running plates on ex-partners, love interests, or family members, and more than 50 cities and counties have canceled or suspended Flock contracts since January, according to the advocacy tracker DeFlock.
The Steelman: Why EFF Says This Isn't Enough
The Electronic Frontier Foundation's response, published under the headline "Too Little, Too Late," makes a case worth taking seriously. EFF argues that Flock is "addressing a problem that Flock itself has created," and that meaningful oversight requires a warrant, signed by a judge, before police can search historic ALPR data tied to a specific vehicle — not a company dashboard setting. Its sharpest point is structural, not rhetorical: "what is stopping Flock from reversing course on [these reforms] if their law enforcement customers respond by defecting to another ALPR vendor? Nothing." A retention limit that exists because a company decided it should is, definitionally, a retention limit the company can undo the next time a customer complains that seven days is too short for a slow-moving investigation.
That argument has real force. Flock's reforms arrived only after two years of investigative reporting, a wave of contract cancellations, and congressional letters — not because the company anticipated the harm on its own. A system in which the ground rules for a nationwide surveillance network rest entirely on one vendor's risk tolerance is fragile by design, and EFF is right that "we should not be letting companies decide how much privacy we deserve."
Where Proportionality Actually Points
But EFF's remedy — a warrant for every historic query — would treat a routine stolen-vehicle lookup the same as a months-long location-tracking request, which is neither proportionate nor how courts have generally approached ALPR data so far. In January 2026, a federal judge in the Eastern District of Virginia granted summary judgment to the city of Norfolk in Schmidt v. City of Norfolk, rejecting a Fourth Amendment challenge to its 176-camera Flock network on the grounds that a 66-square-mile system wasn't yet extensive enough to reconstruct someone's whole pattern of movement — while explicitly warning that a denser or longer-retention network could tip that balance. That case, now on appeal to the Fourth Circuit, illustrates that courts are already drawing exactly the kind of proportionality line critics say self-regulation can't provide.
The more durable answer isn't banning ALPRs or requiring judicial sign-off on every plate lookup — it's what a handful of states have already built: an enforceable statutory floor that survives a vendor's next product decision. Virginia caps ALPR retention at 21 days by statute, restricts queries to criminal investigations, missing-persons and trafficking cases, and makes unauthorized access a criminal misdemeanor. California's ALPR privacy law imposes its own usage and retention constraints on state and local agencies. Neither state waited for Flock to volunteer anything.
That's the model worth generalizing: legislatures, not vendors, set the retention cap, the permissible-use list, and the audit-transparency requirement — while companies compete on how well they implement it. Flock's August reforms are a reasonable floor to legislate into permanence, not a reason to stop legislating. Innovation in public-safety technology and enforceable privacy limits aren't in tension; leaving the limits entirely to the seller of the technology is the actual failure mode here, and it's one only state and federal lawmakers can fix.