Skip to main content
    All Blog articles
    General Cybersecurity
    15 min read

    Clearview AI: Facial Recognition at Internet Scale

    A review of how large-scale facial recognition systems are built, deployed, and regulated, and the implications for privacy, accuracy, and civil liberties.

    Author
    By Catherine “Cat” Karow
    Published
    Published December 27, 2025
    Updated
    Updated May 10, 2026
    General Cybersecurity

    ZoraSafe Blog

    Clearview AI: Facial Recognition at Internet Scale

    Clearview AI: Facial Recognition at Internet Scale

    A review of how large-scale facial recognition systems are built, deployed, and regulated, and the implications for privacy, accuracy, and civil liberties.


    The Pitch

    Facial recognition systems are designed to identify individuals by comparing an image of a face against a large database of reference images.

    Clearview AI is a company that developed one of the largest known facial recognition databases by collecting images from publicly accessible websites across the internet. According to the company, users can upload a photograph and receive potential matches that include links to other images of the same person found online.

    Clearview AI markets its product primarily to law enforcement agencies, positioning the technology as an investigative tool that can assist in identifying suspects or unknown individuals.

    Public reporting has described the company’s database as containing tens of billions of images sourced from social media platforms, news sites, and other publicly available webpages. Individuals whose images appear in the database are not notified and do not provide consent.


    The Origin Story

    Clearview AI was founded in 2017 by Hoan Ton-That, an Australian-born software developer. Early reporting indicates that the company emerged from a network of technology entrepreneurs, political activists, and investors operating in New York and Silicon Valley.

    Investigative reporting by multiple outlets documented that some early figures associated with the company had histories of political activism and controversial online activity. Clearview AI has stated that certain individuals referenced in early reporting were not employees and that the company does not endorse or promote political ideologies.

    The company received early investment from Peter Thiel and other venture capital sources. Ton-That has stated publicly that Clearview AI’s mission is to assist law enforcement in solving crimes and identifying victims, while emphasizing that the technology searches only publicly available images.


    How the Technology Works

    Clearview AI’s system operates in three general stages.

    Step 1: Image Collection

    Automated tools are used to collect images from publicly accessible webpages. These images may include photographs from social media profiles, news articles, professional websites, and other online sources.

    Clearview AI has acknowledged that it does not seek permission from individuals whose images are collected and that it has disputed claims that scraping violates website terms of service.

    Step 2: Biometric Processing

    Each image is processed to extract facial features, creating a biometric template sometimes referred to as a “faceprint.” These templates are stored in a searchable database and linked to the URLs where the images were found.

    Biometric templates are considered sensitive personal data under many privacy laws because they uniquely identify an individual.

    Step 3: Search and Matching

    Authorized users upload an image, and the system returns potential matches ranked by similarity. Results include links to source images, which may reveal names, affiliations, or other contextual information.

    Clearview AI states that its system is intended to generate investigative leads rather than definitive identification.


    Scale of Deployment

    Public reporting and court filings indicate that Clearview AI’s system has grown rapidly.

    Database Size

    • More than 50 billion images collected from online sources
    • Continuous growth through automated scraping

    Users

    • Thousands of individual users across U.S. state and local law enforcement agencies
    • Federal agencies including ICE, DHS, and the FBI
    • Government agencies in multiple countries outside the United States

    Usage

    • Law enforcement agencies have conducted hundreds of thousands of searches
    • Searches may involve images from security cameras, social media, or personal devices

    Clearview AI has stated that its database includes images of most individuals who have appeared in publicly accessible photographs online.


    Accuracy and Misidentification

    Multiple academic studies and government assessments have found that facial recognition systems can produce higher error rates for certain demographic groups, particularly people with darker skin tones.

    Several publicly documented cases involve individuals who were wrongfully arrested after facial recognition matches were treated as evidence rather than investigative leads.

    Documented Cases

    In multiple cases reviewed by journalists and civil rights organizations:

    • Facial recognition matches were used to justify arrests
    • Individuals later demonstrated that they were not the person depicted
    • Charges were ultimately dropped

    Researchers and oversight bodies have emphasized that facial recognition results should be corroborated with additional evidence and not used as the sole basis for enforcement action.

    Clearview AI has stated that its software provides high accuracy under appropriate conditions and that errors result from misuse or overreliance by end users.


    International Regulatory Response

    Outside the United States, data protection authorities have taken enforcement action against Clearview AI.

    Reported Actions

    • Netherlands: Administrative fine for unlawful processing of biometric data
    • France: Penalty for collecting facial images without a legal basis
    • Italy: Enforcement action under data protection law
    • United Kingdom: Initial fine later overturned on jurisdictional grounds
    • Australia: Order to stop collecting images of Australian residents

    Regulators in Canada characterized the company’s practices as mass surveillance and concluded that they violated national privacy law.

    Clearview AI has stated that it does not operate offices in certain jurisdictions and has disputed the applicability of some enforcement actions.


    The United States Response

    The United States does not have a comprehensive federal biometric privacy law. Enforcement has occurred primarily at the state level.

    Illinois Litigation

    Under Illinois’ Biometric Information Privacy Act (BIPA), Clearview AI agreed to a settlement that restricted sales to private entities and certain state and local agencies. The settlement did not prohibit use by federal agencies.

    Class Action Settlement

    A separate class action lawsuit resulted in a settlement providing plaintiffs with an equity stake in the company rather than monetary damages. Several state attorneys general objected to the structure of the settlement, citing concerns about incentives and accountability. The court approved the agreement.


    Ongoing Business Operations

    Despite regulatory scrutiny and litigation, Clearview AI continues to operate and maintain government contracts. The company has stated that it is refining its policies and compliance practices while continuing to market its technology as a public safety tool.

    In recent years, Clearview AI has also promoted programs aimed at assisting public defenders, presenting facial recognition as a tool that could be used to identify wrongful arrests as well as suspects.


    Why This Matters

    Clearview AI illustrates broader issues associated with large-scale biometric surveillance.

    1. Loss of practical anonymity

    Facial recognition reduces the ability to remain unidentified in public spaces, including at protests, religious gatherings, or medical facilities.

    2. Disparate impact risks

    Errors and misuse may disproportionately affect certain populations, particularly when oversight is limited.

    3. Lack of consent

    Individuals typically cannot opt out of facial recognition databases created from publicly available images.

    4. Data security concerns

    Large biometric databases present long-term security risks if breached or misused.

    5. Limited regulatory clarity

    Legal standards governing facial recognition vary widely by jurisdiction, creating inconsistent protections.


    Protecting Yourself

    Options for individuals are limited, but may include:

    • Reviewing privacy settings on social media platforms
    • Limiting public tagging and image sharing where possible
    • Supporting legislation that regulates biometric data collection and use
    • Understanding rights related to facial recognition in law enforcement contexts

    These steps may reduce exposure but do not eliminate inclusion in third-party databases built from public images.


    Looking Ahead

    Clearview AI is part of a broader trend toward biometric identification at scale. Similar technologies are being developed and deployed by governments and private companies worldwide.

    Policy debates continue around accuracy, consent, oversight, and appropriate use. While some jurisdictions have restricted facial recognition, others continue to expand its deployment.

    The long-term implications for privacy, accountability, and civil liberties remain unresolved.


    Cat Karow is the CEO of ZoraSafe, an AI-powered cybersecurity platform focused on helping individuals and families better understand and reduce digital risk.


    Sources

    • The New York Times, reporting on Clearview AI (2020–2024)
    • HuffPost, investigative reporting on Clearview AI (2020)
    • BuzzFeed News, reporting on law enforcement use of facial recognition
    • The Marshall Project, analysis of facial recognition and wrongful arrests
    • Dutch Data Protection Authority enforcement actions
    • CNIL (France) enforcement actions
    • University of Miami Law Review, analysis of Clearview AI litigation
    • Public court filings and regulatory decisions

    Share this article

    Share: