Skip to main content
Incident intelligence/SS-IR-011CASE FILE OPEN
Symbolic editorial illustration for SS-IR-011SERVANTSTACK // INCIDENT INTELLIGENCEFORENSIC IMAGE // VERIFIED FRAME
SS-IR-011 // INCIDENT REPORTReported

Amazon

Rekognition Falsely Matched 28 Members of Congress to Arrest Mugshots

EXECUTIVE BRIEF

In July 2018 the ACLU ran every sitting member of the U.S.

FAILURE CHAINTRACE COMPLETE
  1. 01TRIGGERIn July 2018 the ACLU ran every sitting member of the U.S.
  2. 02MACHINE ACTIONDecision system
  3. 03MISSING GATENamed SME review and decision audit trail
  4. 04IMPACTRights & due process
01 // INCIDENT SUMMARY

The short version

In July 2018 the ACLU ran every sitting member of the U.S.

02 // KEY FACTS

Case telemetry

INCIDENT
SS-IR-011
DATE
July 26, 2018
SYSTEM
Amazon
LOCATION / SCOPE
United States (Washington, D.C. / nationwide)
EVIDENCE
Reported
AI ROLE
Decision system
HARM
Rights & due process
SOURCES
2 cited records
03ENTRY POINT // WHAT HAPPENED

The event

In July 2018 the ACLU ran every sitting member of the U.S. House and Senate through Amazon Rekognition, the same face-matching service Amazon was actively selling to police departments. Using Amazon's default configuration, the tool compared 535 official congressional portraits against a database of 25,000 publicly available arrest mugshots. It returned 28 false matches, flagging 28 sitting lawmakers as people who had been arrested for a crime. The errors were not evenly distributed: nearly 40 percent of the false matches were people of color, even though people of color make up only about 20 percent of Congress. Six members of the Congressional Black Caucus were misidentified, including civil rights leader Rep. John Lewis. The entire test cost the ACLU 12 dollars and 33 cents to run.

04CAUSAL TRACE // AI'S ACTUAL ROLE

What the machine did

Rekognition operated as a fully automated identity-matching system with no human verification gate between the algorithm's output and the this-person-was-arrested verdict. The system ran at Amazon's out-of-the-box default confidence threshold of 80 percent, a setting low enough for routine misidentification, yet it was the configuration a police user would inherit by default. There was no SME-tuned threshold, no documented validation of the model against the demographic population it would be used on, and no required human review of low-confidence matches. The disparate error rate against people of color exposed unvalidated demographic bias baked into the model, shipped to law enforcement with zero oversight controls and zero published accuracy testing for the high-stakes use case being marketed.

Decision systemAutomation was a causal participant—not a decorative label for the system around it.
05BLAST RADIUS // CONSEQUENCES

Where the failure landed

No one was wrongly arrested in the ACLU test itself, but the demonstration showed that the production system police were already buying would falsely tag innocent people as criminals at a measurable, racially skewed rate. Three of the misidentified lawmakers (Senators Edward Markey and Cory Booker, Rep. Luis Gutierrez) demanded answers from Amazon, and the episode became a centerpiece of congressional oversight hearings and a national push for a moratorium on police facial recognition. It fed directly into Amazon's later one-year, then indefinite, moratorium on selling Rekognition to police in 2020. The lasting harm is the precedent: an unvalidated, biased identification tool was deployed to law enforcement where a false match can become a stop, a search, or an arrest of an innocent person, disproportionately a person of color.

06 // EVIDENCE STATUS

Reported

Documented in the cited public record. Follow the sources for the precise evidentiary posture.

SOURCE RECORD UPDATED 2026-07-09

07 // SOURCE LEDGER

2 cited records

  1. 01
  2. 02
08CONTROL FAILURE // MISSING GOVERNANCE

Named SME review and decision audit trail

The failure pattern in this case: Automated judgment without accountable review.

09INTERVENTION POINT // HUMAN IN THE MIDDLE

The moment the path could change

A qualified reviewer tests the basis, context, and disparate impact before the decision reaches a person.

AI PROPOSESHUMAN OWNS THE DECISIONSYSTEM EXECUTES
10CONTROL DEPLOYMENT // AUTHORITYGATE

SME routing · decision audit trail

The AuthorityGate Operational Resilience framework treats deploying a biased or untuned identity-matching model to a high-stakes user as a change that cannot ship without passing a human SME validation gate. Before any face-matching model is released for law-enforcement use, a designated domain SME must sign off on a documented validation report covering accuracy across demographic subgroups and the confidence threshold set for the specific operational context. Out-of-the-box vendor defaults are blocked: the change-validation gate requires that any threshold used in a consequential decision be explicitly reviewed, justified, and approved by a human SME against the actual population, not inherited silently. A match below the SME-approved threshold cannot auto-produce an identity verdict; it is routed to mandatory human adjudication. The 40-percent-of-errors-on-people-of-color disparity would have been a hard fail at the validation gate, and the 80-percent default would never have reached a police user unreviewed. No SME sign-off on the bias report and threshold, no deployment.

RELEVANT KEYSTONE CONTROLHuman-in-the-Loop ValidationHow high-risk actions route to a named subject-matter expert who owns the go or no-go decision.
12 // THE ALTERNATIVE

Autonomy is a design choice.

See the operating model that keeps AI useful while preserving human authority at consequential moments.

Compare AgenticAI and AugmentedAI →