Skip to content
← All news
4 min read

500,000 face scans at London stations, one alert, and it was wrong

British Transport Police scanned more than half a million faces at nine London railway stations for £320,786. The one alert was a false positive, and no arrest came directly from the cameras.

£320,786 and almost 100 officer hours bought one alert. The number that would explain it was never counted.

A British Transport Police trial of live facial recognition scanned more than 500,000 faces at London railway stations between February and July 2026 and produced one watchlist alert. That alert was a false positive. No arrest came directly from the technology, Liberty Investigates reported on September 29, from a Freedom of Information document it shared with The Guardian.

18 deployments, nine stations, £320,786

The FOI document covers 18 deployments across nine London stations. Liberty Investigates shows London Bridge; the other eight are not named. Equipment hire and police staffing cost £320,786, and the trial used almost 100 officer hours.

BTP said officers made other arrests during the deployments, for offences including assault and theft. It left them out of the LFR performance data because they "did not result directly from an LFR alert."

In August, BTP extended the trial by four months and added London Underground stations, starting at Victoria on August 11, The Register reported. It now runs until November. BTP said there have been three confirmed alerts since the extension, all of people found to be complying with sexual harm prevention orders or other court conditions, the Evening Standard reported.

What an alert is in this pipeline

Live facial recognition works as a funnel. Cameras detect faces. Software compares each face against a watchlist, and a comparison that scores above a set threshold becomes an alert. An officer then compares the images by eye and decides whether to stop the person, according to BTP's process as described by Biometric Update. Images of people not on the watchlist are deleted immediately.

The Register reported that the trial uses NEC's NeoFace M40 algorithm. No source gives the match threshold or the watchlist size. BTP said only that it "began with a more limited watchlist" and grew it in a "deliberate, controlled" way.

On that funnel, the first phase reads: more than 500,000 faces in, one alert, zero correct identifications, zero arrests from alerts.

Why half a million scans can produce zero hits

One false alert in more than 500,000 faces is a false-alert rate below 0.0002%. On that measure the system almost never flagged the wrong person.

Precision tells a different story, and a weak one. With one alert, precision is 0 out of 1. A sample of one says almost nothing about the next hundred alerts.

The number that decides hits is missing from the FOI data: how many watchlisted people walked past the cameras. If that number was zero, a perfect algorithm would also have produced zero true alerts. When the targets are rare in the crowd, their base rate caps the hit count, and the number of faces scanned does not raise that cap. A smaller watchlist makes the base rate lower. A stricter threshold cuts false alerts and also misses more true matches, so a low false-alert rate alone cannot show which of those two things happened.

The cost of each outcome

Across 18 deployments, the average was about 28,000 faces and £17,800 per deployment, or at most about 64p per face scanned. Those are costs per unit of activity. The cost per correct identification in the first phase has no finite answer, because £320,786 bought zero of them.

The false alert has a cost too: officer time, and possibly a stop of someone who was not on the list. The sources do not say whether that person was stopped. The extension's three confirmed alerts are real outcomes, but no cost figure for the extension has been published, so a cost per confirmed alert cannot be calculated yet.

Why a build studio cares

Faces scanned and deployments run are activity metrics. They go up with effort whether the system works or not. The metric that tests this system is correct alerts per watchlisted person who passed a camera, and nobody can compute it from the published data because that denominator was never counted. BTP's rule of keeping associated arrests out of LFR data is the honest attribution choice, and it is also why the headline outcome is zero. When we audit software, including the agent pipelines we build, this is the first gap we check for: a count at every stage of the funnel, a cost at every stage, and a success number written down before launch. A trial could get the missing denominator by walking consenting test subjects on a known list past the cameras and counting how many the system catches.

Next step: read Liberty Investigates' report for the FOI figures and BTP's full response. If a system you run reports how much it processes but not what it gets right, write to us at hello@gattyworks.com.

PrivacySurveillanceAILondonBritishTransportPoliceTfLLiveFacialRecognitionFacialRecognitionSurveillanceBiometricsPrivacyComputerVisionAIAccountability

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call