The full story

Sainsbury's Paused Facial Recognition at One Store

A muted blue-grey painterly scene of a self-service supermarket checkout aisle under cold fluorescent strip lights, shelves fading into a hazy background.
AI-generated editorial illustration. Not a documentary image.

But left it on in 54 others, with up to 150 more planned

Back to the summary

A red circle around his own face

Matt Arnold was doing nothing more remarkable than paying for his shopping. The 46-year-old, who promotes comedy nights, was at the East Dulwich Sainsbury's superstore on 6 August when staff approached him and told him they could not serve him, linking him to an incident earlier in the week. As he was turned away he caught sight of a CCTV monitor, and on it, drawn around his own face, a red circle. A machine had picked him out of the crowd, and the people around it had acted on what it said.

"What upset me was thinking this is what the future could be," Arnold told LBC afterwards, "people just listen to what the machine tells them to do without thinking about the consequences." He called it a terrifying glimpse of the future. Sainsbury's later apologised and, according to reporting on the case, gave him a £150 voucher. But the apology and the voucher are the end of the story, not the interesting part. The interesting part is what the machine was, why it was there, and how a shop with 55 of these systems running described what went wrong.

What Facewatch actually is

The technology is not the barcode scanner or the weight-check at a self-service till. It is live facial recognition, made by a firm called Facewatch, and it works by building a biometric map of every face that enters a store and checking it, in real time, against a watchlist the retailer maintains of people it has flagged for previous incidents. When the software believes a face on the shop floor matches a face on that list, it fires an alert to staff. Sainsbury's began trialling it in September 2025 in just two shops — Sydenham and Oldfield Park in Bath, and at the time stressed a safeguard: a shopper's face data would be deleted immediately if the system did not match it to anyone. The reassurance was that most people's faces would pass through and vanish.

That question — whether a camera can reliably pick a named individual out of a moving crowd — is the same one that runs under the wearable version of this technology, which Meta built into smart glasses, shipped dormant, then deleted when the implications became clear. In a shop the company did not hesitate; it scaled up.

From two stores to a rollout

Within a year the two-store trial had become 55 branches, and Sainsbury's has signalled it wants up to 150 more fitted before Christmas. That is the number that reframes the week's headline. "Sainsbury's pauses facial recognition" sounds like a retreat. What Sainsbury's actually did was switch the system off in one store: the East Dulwich branch where Arnold was stopped, while it investigated, and leave it running in the other 54. The expansion plan was not paused, withdrawn, or made conditional on the investigation in anything the retailer has said. A single-store suspension pending a look at one incident is a very different thing from a company reconsidering whether to watch its customers' faces at all, and only the first of those happened.

"A correct alert was sent"

The most revealing part is how the two companies described the failure, because they did not describe it as a failure of the technology at all. Sainsbury's said the Facewatch system carries a 99.98 per cent accuracy rate, that every match is reviewed by a trained manager before anyone acts on it, and that the East Dulwich incident came down to human error rather than the software. Facewatch went further in the same direction: "We can confirm that our live facial recognition technology was not at fault in this incident. A correct alert was sent to the retailer, but was subsequently subject to human error in the way it was handled and communicated."

Read those two statements against the fact that Arnold was innocent, and a gap opens that neither company has closed. If a "correct alert" was sent, what was it correct about? If the answer is that the safeguard, the trained manager who is supposed to check every match, is exactly what failed, then the human review being offered as the reason to trust the system is the same human review being blamed when it misfires. That accuracy figure is the companies' own claim, not an independently tested one, and even taken at face value the 99.98 per cent is a rate, not a promise: across the millions of faces a 55-store estate scans, a 0.02 per cent slip is not a rounding error but a steady supply of Warren Rajahs and Matt Arnolds. The number that is meant to reassure is the one that guarantees this keeps happening.

Not the first, and campaigners saw it coming

Arnold's case was not isolated. Warren Rajah was marched out of the Elephant and Castle branch in February after the same software flagged him; Facewatch later confirmed there had been no alert associated with him whatsoever. Beyond Sainsbury's, the civil-liberties group Big Brother Watch has documented other misfires with the same vendor: including a teenage girl it identifies only as Sara, wrongly stopped at a Home Bargains store in May 2024, searched, removed and barred from other shops using the software. The group's objection is not that the technology occasionally errs but that its whole design puts ordinary people on lists they never knew about. When Sainsbury's began its trial, Big Brother Watch's Madeleine Stone said the retailer and Facewatch were "adding customers to secret watchlists with no due process, meaning people are being falsely accused," turning "shoppers into suspects," and called the technology "dangerously out of control in the UK."

For a shopper wrongly flagged, the practical problem is that the harm and the recourse are badly matched. Being circled in red and walked out of a supermarket in front of a queue is public and immediate; challenging the biometric record behind it is slow, technical and largely invisible. The awkward legal ground here is the same one that runs through the debate over suing someone for capturing your face without consent — a faceprint is personal data, but the routes to act on a wrongful one are narrow and rarely tested.

What the regulator actually said

Facewatch is not operating in a vacuum. The Information Commissioner's Office investigated the company and, in 2023, concluded it could rely on the "legitimate interest" lawful basis to process people's faces for crime prevention. But that clearance came with a history and with conditions. The ICO had identified concerns across several data-protection principles and required improvements before it was satisfied: narrowing the data collected to focus on repeat or more serious offenders, appointing a data protection officer, and protecting people classed as vulnerable from being swept onto watchlists. The regulator then said no further action was needed. That is a conditional, negotiated permission, and it is a long way from an endorsement that facial recognition in shops is straightforwardly safe. Big Brother Watch, which filed the complaint that prompted the ICO's look in July 2022, maintains the processing still does not meet data-protection and human-rights standards.

The honest state of it

Put it together and the week reads differently from its headline. A technology built to turn faces into watchlist checks flagged the wrong man; the shop that runs it in 55 branches switched it off in one, apologised, blamed human error, and kept the other 54 running and the expansion on schedule. Both companies insist the software works as intended, and in a narrow sense they may be right: the trouble is that "as intended" includes a rate of error that reliably lands on innocent people, checked by a human step that has now failed at least twice in public this year. Nothing dated stands in the way of the next 150 stores. The only thing scheduled is more of the cameras, and the only correction on offer is an investigation, at one branch, with no date on it.

Can Your Employer Make You Wear Recording Glasses at Work? — an employer's facial-recognition match going wrong is the high-risk case worker-monitoring law treats as special-category biometric data

An AI Detector Flagged a Berkeley Professor's Op-Ed as 33% AI — an automated system's confident score misreading a specific person, with the burden landing on them

Sources and verification

This piece reports what Sainsbury's, Facewatch, the ICO and Big Brother Watch have said, and gives no reader advice on their own legal position if they are wrongly flagged. The accuracy figure of 99.98 per cent is the companies' own claim and is presented as such, not as an independently verified measurement. How a "correct alert" resulted in an innocent shopper's ejection has not been explained by either company in any source read for this article, and no explanation is asserted here.