
Stop Blaming Facial Recognition for Workplace Surveillance
Facial recognition has become the villain of choice in the workplace surveillance debate—the first technology critics name when they warn that America's factories and warehouses are turning into surveillance zones. That broader debate has reached Congress: Sens. Ed Markey (D-MA) and Brian Schatz (D-HI) reintroduced the Stop Spying Bosses Act and the No Robot Bosses Act in June 2026 to rein in employer surveillance of workers. States are pushing further: New York's Bossware and Oppressive Technology (BOT Act) would restrict electronic monitoring of employees, while a California bill that died in February would have banned workplace monitoring tools that use facial, gait, or emotion recognition—though its successor is already moving through the legislature. Rather than impose overly restrictive policies that limit facial recognition's utility in the workplace, policymakers should regulate what employers do with workplace data, not which device collects it.
Part of the problem is vocabulary. As ITIF has explained, “facial recognition” is often used imprecisely as a catch-all term for a family of distinct technologies. Facial detection merely determines whether an image contains a face. Facial analysis estimates characteristics such as age or drowsiness without determining whose face it is. Facial recognition, by contrast, compares a face against stored templates, either to verify a claimed identity or to determine whether a person matches someone on a predefined list and, if so, retrieve information associated with that match. These uses involve different data and raise different privacy risks. They also rely on different technologies: cameras generally capture facial images, while some systems supplement them with infrared sensors. Other workplace devices collect different kinds of data altogether: a badge reader logs a credential, a handheld scanner logs task times, and a wearable logs motion. The same device can support very different data practices depending on its software, which is why rules aimed at the device can so easily miss their target.
In American factories and warehouses, facial recognition mostly does one mundane job: proving that workers are who they say they are at time clocks and secured access points. UKG, one of the largest workforce-management vendors, sells terminals that verify a face so employees can punch in hands-free, and one timeclock maker reported selling five face-scan units for every fingerprint model in 2020. The appeal is practical: badges can get lost, shared, or cloned, and industry research has long found that most companies lose money to “buddy punching,” where one worker clocks in for an absent coworker. Gloves, dirty hands, and dry skin can all defeat fingerprint scanners in industrial settings. Facial recognition for these purposes is much more privacy-protective than many critics suggest; each scan is a momentary, one-to-one match against the worker's own template, closer to flashing an ID at the gate than to surveillance.
Americans’ views of workplace facial recognition vary substantially depending on how it is used. According to a 2023 Pew Research Center report, tracking attendance was the only workplace use surveyed that drew net support. Respondents opposed tracking workers’ breaks roughly two to one, while 70 percent opposed using facial recognition to analyze workers’ facial expressions. These distinctions matter: facial recognition can be used simply to verify identity, or it can be used to infer characteristics or behavior from facial data. Blanket restrictions can obscure these important differences.
Many companies do not even use facial recognition to pursue the workplace goals critics worry about most. Typically, vendors engineer the cameras that watch factory floors not to identify faces. Toyota has been rolling out computer vision across all 14 of its North American plants to study assembly-line motion and ergonomics, and its vendor stresses that the system contains “no facial recognition.” Intenseye, a safety platform Amazon uses to flag hard-hat violations on its docks, irreversibly blurs faces by default. Voxel, whose customers include the cold-storage operator Americold, likewise identifies unsafe events, not individuals.
Safety systems that point cameras at workers’ faces deserve thoughtful treatment, but they’re often not focused on identifying workers. The fatigue-detection cameras that mining giant Newmont has effectively standardized across its operations track eye movement and head position to catch a driver falling asleep before a haul truck drifts. Notably, the European Union, which banned AI systems that detect emotions in workplaces, included an exception for medical and safety uses, and its guidance treats fatigue detection as a physical state, not an emotion. California's failed workplace surveillance bill contained no comparable nuance.
The fact that facial data can serve legitimate purposes does not eliminate the need for safeguards. Unlike a badge or password, a worker’s face cannot simply be replaced if its biometric information is compromised. As the Ninth Circuit noted in a Biometric Information Privacy Act case against Facebook, quoting the Illinois legislature, a person whose biometric identifier is compromised “has no recourse.” The better approach is to regulate how employers use biometric data rather than banning useful applications, with safeguards that limit collection to specified purposes, establish rules on retention and secondary uses, and require appropriate security. Colorado’s biometric privacy law, for example, permits employers to use biometric identifiers for defined purposes including timekeeping and workplace safety while imposing additional requirements on other uses.
Bills aimed at restricting employers from using devices to automatically collect worker data keep dying: California's monitoring-tool ban died in February, and a similar Washington bill died in March. Illinois's experience with biometric regulation illustrates one risk of focusing restrictions on data collection itself. Under the state's biometrics law, most class actions targeted employee time clocks rather than the punitive uses of worker data that critics warn about. White Castle, for example, faced a potential $17 billion in damages over fingerprint scans before settling for $9.4 million, and lawmakers finally ended per-scan damages in 2024.
The problem with the Markey-Schatz bills is that they regulate workplace technologies based on how much data they collect rather than on how employers use the data. This approach fails to distinguish opaque, punitive surveillance from legitimate workplace monitoring and oversight, such as monitoring intended to prevent fraud and injuries. It is reasonable for Congress to debate whether an employer should be allowed to use automation without human oversight to dock pay, deny a break, or end a job, but it is not reasonable to write laws that ban employers from using any technology in their facilities that recognizes workers.
