British Transport Police spent the first half of this year pointing live facial recognition cameras at people walking through London’s busiest railway stations. Between February and July it ran 18 deployments, scanned more than half a million faces and spent £320,786 on equipment hire and staffing, according to figures Liberty Investigates obtained under the Freedom of Information Act and published with The Guardian. The cameras raised one alert, and it was wrong.
The Register’s write-up has the reaction, which ranges from incredulous to angry, and it ends on the line everyone will quote: after half a million faces, the only person the cameras picked out was the wrong one. That was true of those six months. BTP’s own figures for the weeks since tell a more useful story, and it is not really about cameras at all.
What the first six months found
BTP’s system compares every face passing through a marked zone with a watchlist of people wanted by the police or the courts, or subject to court orders with conditions. When the software scores a face above its threshold, an officer reviews the alert before deciding whether to stop anyone, and BTP says the images of people who do not cause an alert are deleted immediately. It describes the deployments as intelligence-led and aimed at crime hotspots.
The six months produced that one false alert and no arrests from the cameras. According to Liberty’s figures they used almost 100 hours of officers’ time, and the cost works out at roughly £17,800 a deployment. BTP points out that officers made other arrests while deployed, for offences including assault, theft and possession of an offensive weapon, but it is careful to add that “as these arrests did not result directly from an LFR alert, they are not included within LFR performance data.”
That caveat is honest, and it cuts both ways. Putting officers in a busy station concourse catches people, which is evidence for officers rather than for cameras.
The rest of the register
BTP publishes a deployment register for the pilot, and it deserves credit for that, because it lets people outside the force check the claims. For every deployment it records the watchlist size, the threshold, the alerts and their outcomes, and an estimate of the faces seen, and it now runs to 24 September.
Two things stand out. The threshold never moved: every deployment ran at a minimum setting of 0.64. And the watchlist was small, holding between 381 and 546 people across the first six months.
The pilot carried on after July, extended to November and moved partly onto the Underground. The register records nine more deployments in August and September, with watchlists of up to 862 people, and four alerts it classes as true, three of them confirmed. BTP told The Guardian that the three confirmed matches were people found to be complying with sexual harm prevention orders or other court conditions, and the register records no action and no arrests.
The list, not the lens
Compare the Metropolitan Police, whose annual report on live facial recognition covers September 2024 to September 2025. It ran 207 deployments, 203 of them at crime hotspots, saw about 3.1 million faces and raised 2,077 alerts, ten of them false, and it arrested 962 people from those deployments. It has worked at a threshold of 0.64 since July 2024, the same setting BTP uses.
So the camera settings are not the difference. The list is: the Met says a typical crime-hotspot watchlist holds around 10,250 people wanted by the courts or for serious crimes, and BTP’s has held a few hundred.
A camera can only find people who are on the list and who walk past it. Put 455 names on the list, stand in King’s Cross for four hours, and the chance that one of them passes is small, however good the software is. The pilot’s numbers are what a short watchlist produces, and no amount of work on the camera will change that much.
Read it like a detection rule
I spend my working life around detection systems, and this is a familiar shape. In a security operations centre we judge a detection rule on two things: how often it is right when it fires, and how much of what matters it catches. A rule that fired once in half a million events, and fired wrongly, would be retired or rewritten.
To be fair to the technology, the false alarm rate here is excellent. Five alerts in more than 900,000 faces, only one of them wrong, is a very quiet system, which is what a cautious threshold is for. Every detection engineer knows the price of that setting: tune for silence and you also hear very little.
So the honest question is not whether the cameras work. It is whether the yield, measured in people found who needed finding, justifies scanning everyone else to get it.
The trade-off the pilot has exposed
That is where the law comes in. For the police, matching faces against a watchlist is sensitive processing under Part 3 of the Data Protection Act 2018, because it uses biometric data to identify people, and section 35 allows it only where it is “strictly necessary” for a law enforcement purpose. Necessity is a question of evidence, and six months without a single correct match is evidence pointing the wrong way.
The obvious way to raise the yield is a longer watchlist, and that is the uncomfortable part. More names mean more people exposed to the system’s judgement, and the breadth of discretion over who goes on a watchlist is exactly what the Court of Appeal found wanting in the Bridges case in 2020. In July, writing about supermarkets using facial recognition, I quoted the ICO’s warning that it may be harder to justify processing images of large numbers of people to identify only a few.
BTP’s pilot is a clean demonstration of the dilemma. With a short list the intrusion is hard to justify because it finds almost nobody, and with a long list it finds more people and intrudes further. The Home Office consulted over the winter on a legal framework and a single regulator for this technology, and until that exists, each force is making the choice for itself.
What a pilot is for
A pilot is an experiment, and an experiment needs a question, and an answer that would change your mind, written down before it starts. Something like: we will judge this on people found per deployment, at a cost per person found below a stated figure, with false alerts below a stated rate, and we will stop if we miss those marks by a stated date. With that written down, six months of results either clear the bar or they do not.
BTP’s stated reason for taking the pilot onto the Underground was to “assess the technology in a different transport environment”, which is a fair question. The register suggests the variable that matters more is the watchlist, so the next phase should say how long the list will be, how people are chosen for it, and what result would end the pilot in November.
If BTP believes the cameras also deter people on its watchlists from using the stations, it should say so and find a way to measure it, because a benefit that cannot be measured cannot carry the weight of scanning hundreds of thousands of people. And somewhere in the first six months is one person who was wrongly flagged. What happened to them belongs in the evaluation too.
The point
Measurement is privacy’s friend, not its enemy. BTP deserves credit for publishing enough data for anyone to see what its pilot is doing, and that data says the camera works and the list is short.
Whether a longer list is justified is a question for Parliament and the public, not for a pilot that grows by default. Until it is settled, the first six months stand as the clearest measurement yet of what live facial recognition costs when the list is short: half a million faces, £320,786, and one wrong alert.