Sainsbury’s has apologised and says the East Dulwich system will remain paused while it investigates and retrains staff. Facewatch, the supplier, says a valid alert was delivered but mishandled in-store; Sainsbury’s similarly calls it human error rather than a failure of the technology.
That account may be technically possible, but it is incomplete in the way that matters to anyone deploying automated decision systems. Facewatch’s own documentation describes the software as a recommendation that requires a human reviewer to compare the alert with the person standing in the shop before deciding whether to intervene. If staff acted on an alert against the wrong person, the human review was not an external safeguard that caught the system’s uncertainty. It was an operational dependency that failed at the precise moment the system was used against a customer.
The “human review” control failed twice at Sainsbury’s
Arnold’s experience is the second publicly reported case this year in which a Sainsbury’s customer was removed or challenged after a Facewatch-related alert was handled incorrectly. In February, The Guardian reported that Warren Rajah was told to abandon his shopping and leave his regular Sainsbury’s in Elephant and Castle after staff mistook him for a person of interest.
Rajah later submitted a photo and passport image to Facewatch, which confirmed that he was not on its database. Sainsbury’s apologised and, according to reporting by the Press Association and The Independent, offered him a £75 voucher. The company’s explanation in that case was also that staff had approached the wrong person, rather than that Facewatch had made an incorrect match.
The common thread is important. Neither case, based on the companies’ accounts, is necessarily a conventional biometric false positive in which the algorithm identifies the wrong person as a watchlist subject. Instead, the alleged breakdown happened after an alert: staff had to identify the person to whom it applied, assess the situation, and choose an intervention.
That is still a failure of the deployed system.
Enterprise IT teams do not get to describe a flawed workflow as “not a software issue” merely because an employee clicked the wrong ticket, selected the wrong account, or acted on an ambiguous dashboard alert. If a tool sends a high-stakes prompt to a busy worker, and the normal working conditions make a harmful mistake predictable, then the interface, policy, training, staffing, escalation path, and audit trail are all part of the control environment.
Sainsbury’s has not publicly explained what its managers are meant to see when an alert arrives, what identifying information is displayed, whether managers can access more than one image, whether the store’s CCTV view is integrated with Facewatch’s alert view, or what positive verification steps are required before a customer is challenged. Those omissions matter more than the phrase “human error.”
Facewatch’s verification model puts the burden on store operations
Facewatch says its retail system uses two AI-based comparison stages and human checks before action is taken. Its published privacy material says that a potential match can be assessed by Facewatch staff and then by the retailer receiving the alert. The retailer is meant to decide whether the person physically present matches the alert before following its own procedure, which can range from no action to intervention.
That architecture is more cautious than a system that automatically locks a customer out, flags a payment card, or calls the police. But it also creates a chain of custody for identity decisions. Once a manager receives an alert, the store is being asked to translate a biometric recommendation into an in-person confrontation, often while handling queues, age-restricted sales, theft concerns, and customer-service duties.
Facewatch says it does not retain the biometric data of people who do not match its database and that a rejected alert can be marked “no match,” after which the alert image and biometric data are deleted. It also says alert data without images or biometric data may be retained for seven days to assess accuracy and improve the system. Those are relevant privacy controls, but they do not address the immediate consequence when an employee acts first and reviews later.
The incident at East Dulwich also shows why a nominal human in the loop is not enough to make a surveillance system accountable. The reviewer must have time, training, a clear decision rule, and permission to reject the system’s recommendation. Most importantly, the workflow needs a low-risk default: an uncertain match should lead to observation or a discreet customer-service interaction, not a public accusation or expulsion.
Facewatch’s older public material has suggested that retailers might respond to an alert by engaging the person normally and monitoring the interaction. The reports involving Rajah and Arnold suggest that whatever policy exists on paper, it has not reliably prevented more confrontational outcomes in Sainsbury’s stores.
Sainsbury’s expansion makes the operational gap more consequential
The East Dulwich pause comes weeks after Sainsbury’s announced a substantial expansion of Facewatch. In its June 30 first-quarter trading statement, the retailer said facial-recognition technology was live in more than 55 stores following a trial and that it planned to add up to 150 further sites before Christmas 2026.
The Grocer reported the same plan as an expansion to more than 200 locations by year end. Sainsbury’s said its early deployment reduced incidents involving theft, harm, aggression, and antisocial behaviour by 46%, while more than 90% of identified offenders did not return.
Those figures are company-reported outcome claims, not independently audited measures. Sainsbury’s has not published the baseline incident counts, the stores used for comparison, the methodology for defining an “identified offender,” the number of alerts generated, or the number of alerts rejected by staff. Without those data, readers cannot tell whether the reported reduction reflects deterrence, displacement to other stores, changes in reporting, staffing changes, or the effect of Facewatch itself.
The company also has not disclosed how often managers reject alerts, how often the system or its operators identify the wrong person, or how often an innocent customer is approached after a valid alert is sent for someone else. Those are not minor statistical footnotes. They are the measurements that determine whether a claimed 99% or 99.98% matching threshold translates to an acceptable real-world error rate.
Even a highly accurate matching tool can create frequent mistakes at supermarket scale when it processes a large number of faces, uses a shared database, and depends on frontline workers to make fast identity judgments. The relevant risk is not simply “does the model ever get a match wrong?” It is: how many people can be wrongly confronted after all stages of the system — camera capture, watchlist inclusion, algorithmic matching, analyst review, store verification, and staff intervention — have run?
That is the end-to-end failure rate Sainsbury’s needs to measure before increasing deployment by almost four times.
A private watchlist creates a different accountability problem
Retail facial recognition also differs from an ordinary CCTV system because it acts on a shared watchlist. Facewatch describes its database subjects as people reasonably suspected of unlawful acts, supported by subscriber incident reports and reviewed by Facewatch. The practical result is that a person added after an incident at one participating retailer may trigger alerts at other subscriber locations, subject to Facewatch’s sharing rules.
That model can help retailers identify repeat violent offenders and staff abusers. It also raises the stakes of a bad record, an inaccurate submission, or an unclear mechanism for contesting a listing. Rajah’s case illustrated the burden on a person who believed he had been falsely associated with the system: he was directed to Facewatch and asked to provide identifying documents to establish that he was not in its database.
For a security platform built around suspected criminal activity, the ability to challenge a record, correct it promptly, and understand what data was used is as important as the matching threshold. Sainsbury’s has not said whether Arnold was given a written explanation, whether an incident record was created, whether he will receive the relevant alert evidence, or whether the company has changed procedures across its other Facewatch-equipped stores following either case.
The fact that the East Dulwich deployment has been paused is a meaningful response, but it is local. The company has not announced a wider suspension, a review across the existing 55-plus locations, or the results of any audit of manager decisions. Training at one branch does not answer whether the same dashboard, instructions, incentives, and time pressure exist elsewhere.
The next control should be evidence, not another assurance
Sainsbury’s now needs to show what has changed before Facewatch returns to East Dulwich. A credible response would include a documented verification procedure, a requirement that managers confirm a live alert using the available reference images before approaching anyone, a clear prohibition on ejecting customers based solely on an alert, and centrally reviewed logs of rejected and acted-on matches.
It should also publish aggregate data on alerts, no-match determinations, customer interventions, complaints, and confirmed errors across its estate. The company need not reveal watchlist identities or sensitive security methods to disclose whether its safeguards work. IT and security teams routinely report false positives, missed detections, response times, and incident outcomes when assessing endpoint security, fraud controls, and automated monitoring systems. Biometric surveillance should not receive a lower standard merely because its targets are shoppers.
For customers at East Dulwich, the immediate consequence is simple: Facewatch alerts are off while Sainsbury’s investigates. For the retailer’s wider rollout, the harder fact remains that the supposed backstop — trained human verification — has now featured in two public failures. Until Sainsbury’s can demonstrate that staff can reliably turn an automated alert into a fair, evidence-based interaction, adding another 150 cameras will scale the unresolved weakness along with the system.