CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
facial-recognition

Facial Recognition Privacy Concerns: MSG's $30,000 Fine and the Data Behind It

facial recognition privacy concerns, facial recognition technology is ripe, venue entry camera scanning a visitor's face at a turnstile
A venue entry camera captures a visitor's face, illustrating the facial recognition privacy concerns raised by MSG's use of the technology. Illustration: CaraComp

Here's a sentence that should stop you mid-scroll: a company can run your face through an algorithm, get a "match," act on it immediately, and never once explain, to anyone, what score triggered that decision or how often the system gets it wrong. That's not a hypothetical. That's what happened at Madison Square Garden, and it just cost the venue $30,000.

TL;DR: Facial recognition privacy concerns aren't really about the algorithm being wrong, they're about organizations treating a similarity score as a final answer instead of one clue in a bigger decision, and MSG's $30,000 fine is proof of what happens when nobody builds a process around it.

TL;DR

Facial recognition privacy concerns show up in a very human way in this case: MSG used facial comparison to identify and remove lawyers involved in litigation against the company, without a documented threshold, human review process, or a way for anyone to challenge a wrong result.

Here's what actually happened. Madison Square Garden used facial recognition technology at its entrances, not to catch shoplifters or ban troublemakers, but to spot and exclude attorneys whose law firms had active lawsuits against the company. The New York State Liquor Authority sued over it. Then, in a twist nobody quite expected, the authority dropped the lawsuit but still slapped MSG with a $30,000 fine, for paperwork violations, according to Gothamist. Not for the facial recognition itself. For failing to properly notify the state about how the system was being used.

That distinction matters more than it sounds like it should. And once you understand why, you'll never look at a "facial match" the same way again.

Why Facial Recognition Privacy Concerns Start With a Number, Not a Face

Every time a facial recognition system compares two photos, it doesn't say "yes" or "no." It spits out a similarity score, a number that says how close two faces are, mathematically, once they've been mapped as data points. Somebody, somewhere, has to decide what number counts as a "match." That decision point is called a decision threshold, and it's the single most important, and most invisible, piece of the whole system.

Set that threshold too low, and you get a flood of false matches: innocent people flagged for looking vaguely like someone else. Set it too high, and you miss real matches entirely. According to the National Academies, a common industry practice is to tune that threshold so false accepts happen only about 1 in 1,000 or 1 in 10,000 times. Sounds small. But MSG never told anyone what threshold it used, what score triggered an exclusion, or how many people got flagged incorrectly. That silence is the whole story. It's also a data protection failure as much as a technical one: without disclosed biometric data practices, nobody outside the company could audit what the facial recognition data actually showed or how it was handled.

1 in 1,000,000
roughly the false match rate industry benchmarks aim for under lab conditions, real-world venue scans rarely hit that bar
Source: NIST face verification testing, via Bipartisan Policy Center

Facial Recognition Technology Is Ripe for Misuse Without a Process

Facial recognition technology is ripe for exactly this kind of trap: a tool that produces confident-looking output gets treated as a verdict instead of a lead. The tech isn't necessarily broken. The process wrapping around it is. MSG's system may have worked exactly as designed, and still produced an outcome nobody could defend, because no documented human sign-off, written criteria, or appeal process existed for someone wrongly flagged. This article is part of a series, start with Illinois Bipa Court Says A Recorded Voice Is Now A Face Scan.

How MSG Facial Recognition Turned a Score Into an Automatic Decision

Think about what actually has to happen for facial comparison to lead to a fair outcome. The camera captures your face at the door. The system searches its database and returns candidates ranked by similarity. Then, and this is the step everyone skips in their head, a human is supposed to look at those candidates and confirm identity before anything happens to you.

That confirmation step is not optional. It's the whole ballgame. According to the National Academies' research on face recognition governance, accuracy in real deployments depends on both the algorithm and the human reviewing its output. When MSG's system flagged someone, the exclusion appears to have followed almost automatically, no documented verification that the "match" was actually the person the club intended to exclude, no confirmation the litigation record was current, no review of whether excluding that specific person was even legally sound.

The New York Attorney General flagged something else too: barring people from a public venue because their law firm is suing you can bump up against human rights and anti-retaliation law. That's a legal risk layered on top of a technical one. A face match told MSG "this might be the person." It could never tell MSG "and therefore we're allowed to do this."

The withdrawal of the case should not be read as an endorsement of any exclusion policy, facial-recognition practice, or admission practice. New York State Liquor Authority statement, as reported by TicketNews

MSG Facial Recognition and the Camera Angle Problem

Here's something most people never think about: the score you get from a controlled photo comparison, good lighting, straight-on angle, high resolution, is not the same math as the score from a security camera at a turnstile, catching someone mid-stride at 6:45pm in low light. Image quality changes the odds. Blurry or low-resolution captures measurably increase what's called the false positive identification rate, meaning the system is more likely to say "match" when it's actually looking at two different people. A real-time venue scan and a lab-quality comparison are not the same test, even when they spit out numbers that look identical on a screen.


The Real-World Analogy That Makes This Click

Picture a rapid at-home test, the kind that gives you a positive line in five minutes. A good doctor doesn't hand you a prescription off that line alone. She orders a confirmatory lab test, checks your symptoms and history, and writes down her reasoning. The rapid test narrowed things down. It didn't make the diagnosis by itself.

A facial comparison score works exactly the same way. It narrows the field. It says "these two images are geometrically close enough that a human should look closer." What MSG appears to have done is skip the doctor's visit entirely and act on the positive line alone. That's the mistake. Not the test, the decision to treat the test as the whole answer.

Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

What People Get Wrong About Facial Recognition Privacy Concerns

Most people assume that if a facial recognition system says "match," the identity is basically settled. It's an understandable assumption, the number on the screen looks precise, almost scientific, and humans are wired to trust precise-looking numbers. But a similarity score only answers one narrow question: do these two images look like the same geometric shape? It cannot tell you whether the underlying record is current, whether the database entry is even correct, whether the action being taken is legally justified, or who's accountable if the match is wrong.

Two separate types of error hide inside every system like this, and both point back to unresolved bias in how thresholds get set. A false non-match happens when the algorithm fails to connect two photos of the same real person, it says "no match" when there should be one. A false positive match happens when the system confidently links two photos of two completely different people. According to the National Academies' research, less distinctive facial features actually need a higher threshold to hit the same error rate as more distinctive ones, meaning two people can get the identical confidence score and carry wildly different real odds of being wrong. Previously in this series: China Facial Recognition Rules Uk Scanned 4m Faces First Pod.

What You Just Learned About Facial Recognition Privacy Concerns

  • 🧠 A score is not a verdictsimilarity numbers show geometric closeness, not confirmed identity
  • 🔬 Image quality shifts the oddsa blurry venue camera scan carries more error than a lab comparison
  • 💡 Thresholds are invisible to the publicMSG never disclosed the confidence level that triggered an exclusion
  • ⚖️ Process, not tech, was the failure pointno documented human review, no appeal, no disclosure

What Should Guide Venue Face Scan Decisions Instead of a Score Alone

So if a match score can't make the decision, what should? This is where detection and decision-making need to split into two separate jobs. Detection is the technical part: does the system flag a possible identity? Decision-making is the human part: given that flag, what's the right, legal, documented action to take? Collapsing those two jobs into one automatic step is exactly the mistake that produced MSG's fine.

Automatic match-as-decision approachDocumented review-based approachStatus
Threshold score kept privateThreshold and error rate disclosed for auditData protection gap
No human confirms candidate identityHuman reviewer verifies the match before any actionRights at risk
No record of legal justificationDocumented reasoning tied to policy and lawRights unaddressed
No path to challenge a wrong resultClear appeal process for the person affectedRights unenforced
Regulatory risk: fines, lawsuits, retaliation claimsRegulatory posture: defensible, auditable, consistentData exposure

Facial Recognition Data and Why Regulatory Bodies Care About Documentation

Regulators aren't generally trying to ban facial comparison outright, most cases, including this one, hinge on documentation and disclosure, not the technology existing at all. The Bipartisan Policy Center notes that face verification systems are typically benchmarked to keep false match rates around 1 in 100,000 to 1 in a million under lab conditions, a standard that only means something if organizations actually track and disclose where their real-world systems land against it, and where data protection obligations are taken seriously rather than treated as an afterthought. MSG's fine wasn't for using the tech. It was, per Gothamist's reporting, tied to paperwork, the state's way of saying: you didn't show your work.

This is where a lot of everyday facial recognition privacy concerns actually live, not in some dystopian sci-fi scenario, but in mundane gaps: a missing form, an undisclosed threshold, a decision nobody wrote down. It's less dramatic than people expect, and honestly, that makes it worse. Quiet paperwork failures are exactly the kind of thing that slips through until a $30,000 fine shows up, and each one represents data that was collected, used, and never accounted for.

This is also the exact gap that professional facial comparison work is built to close. At CaraComp, comparisons come with documented methodology and reports built for accountability, not a bare score handed over with no explanation, which is precisely the setup that got MSG in trouble.


Facial Recognition Privacy Concerns: Where This Leaves You

Facial recognition privacy concerns raise significant concerns for a simple reason: your face isn't like a password you can reset. Passwords get changed after a breach. Faces cannot be changedwhich is exactly why organizations that use facial comparison carry a heavier obligation to get the process right, not just the algorithm. When a facial-recognition vendor or a venue operator builds a system that scans the public, the privacy implications multiply, because a wrong or undocumented decision follows a person around in a way a canceled credit card never does.

The MSG case also raises significant ethical questions that go beyond biometric accuracy, questions about retaliation, about who gets to enter a public space, about whether a private company can quietly build a system that decides who's welcome based on legal disputes rather than actual conduct. Businesses that deploy this kind of system without a clear policy expose themselves to exactly the regulatory and legal risk MSG just paid for, and they risk trampling the same rights regulators are now watching closely.

Key Takeaway

Facial recognition privacy concerns aren't solved by better algorithms, they're solved by documented thresholds, human review, and an appeal path, because facial recognition technology raises several privacy risks that only show up the moment a match gets treated as a final answer instead of a first clue. Up next: Illinois Bipa Court Says A Recorded Voice Is Now A Face Scan.

So here's the aha moment worth carrying out of this. A face match isn't proof. It's a tip. The moment an organization treats that tip as an automatic yes-or-no answer, no human check, no written criteria, no way to push back, it's not really running facial recognition anymore. It's running a black box with a person's real life, and their rights, on the other end of it. MSG didn't get fined for scanning faces. It got fined for never writing down what it did with the data.

Facial Recognition Privacy Concerns: Frequently Asked Questions

What are the biggest facial recognition privacy concerns for regular people?

The biggest facial recognition privacy concerns aren't really about being secretly identified in a crowd, they're about decisions being made based on a match with no human review, no clear rules, and no way to challenge a wrong result. Since faces cannot be changed the way a password can, a bad match can follow someone with real consequences: being excluded from a venue, flagged at an airport, or denied service, often without ever learning why, and often without the underlying data ever being disclosed to the person it describes.

Does facial recognition technology raise legal risk for businesses?

Yes. Facial recognition technology raises several privacy risks and legal risks for businesses that deploy it without documentation. In the MSG case, the New York State Liquor Authority issued a $30,000 fine tied to disclosure failures, and the state's attorney general separately raised concern that excluding people over litigation could violate human rights and anti-retaliation law. Businesses using this technology need a written policy, a documented threshold, a data protection plan, and a human review step.

Why do facial recognition systems raise significant ethical questions?

Facial recognition systems raise significant ethical questions because they collect sensitive information, your face, converted into biometric data, often without clear consent, and can be used to make decisions affecting where you can go or what you can do. The MSG case is a clear example: a company used facial comparison to enforce a policy tied to lawsuits, not safety or misconduct, which pushed the technology into territory regulators saw as retaliation, not security.

Can a facial recognition match alone justify banning someone from a venue?

No, and that is the central lesson of the MSG case. A facial recognition match confirms that two images are likely to show the same person, it does not confirm whether an action taken against that person is fair, legal, or justified, or whether their rights were properly considered. A defensible venue face scan process needs documented criteria, a human reviewer confirming the match, and a way for the person to contest the decision before or after it's enforced.

How does police use of facial recognition differ from private venue use?

Police use of facial recognition typically operates under specific legal frameworks, oversight bodies, and audit requirements, though these vary widely by jurisdiction. Private venue use, like MSG's, often lacks that same regulatory structure, which is part of why the New York State Liquor Authority stepped in, private businesses collecting and acting on biometric data face fewer built-in checks than law enforcement systems, making internal policy, data protection, and disclosure even more important.

What does "annihilating privacy" mean in facial recognition debates?

Critics use the phrase "annihilating privacy" to describe how widespread facial recognition collection could, in theory, eliminate the ability to move through public spaces without being identified and tracked. The MSG case is a smaller-scale version of that same concern: a private venue quietly building a system that identifies specific people for a specific undisclosed purpose, without the individual ever knowing they were flagged, what data was kept, or why.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search