
Clearview AI
A 3-Billion-Face Database Built by Scraping the Internet, Then Breached
Clearview AI quietly assembled a facial-recognition database of more than 3 billion images by scraping photos from Facebook, YouTube, Venmo, LinkedIn, Twitter and the wider web, all without the consent of the people pictured.
- 01TRIGGERClearview AI quietly assembled a facial-recognition database of more than 3 billion images by scraping photos from…
- 02MACHINE ACTIONAutonomous actor
- 03MISSING GATENamed SME review and decision audit trail
- 04IMPACTData security
The short version
Clearview AI quietly assembled a facial-recognition database of more than 3 billion images by scraping photos from Facebook, YouTube, Venmo, LinkedIn, Twitter and the wider web, all without the consent of the people pictured.
Case telemetry
- INCIDENT
- SS-IR-022
- DATE
- February 26, 2020
- SYSTEM
- Clearview AI
- LOCATION / SCOPE
- Global (United States / European Union)
- EVIDENCE
- Official finding
- AI ROLE
- Autonomous actor
- HARM
- Data security
- SOURCES
- 3 cited records
The event
Clearview AI quietly assembled a facial-recognition database of more than 3 billion images by scraping photos from Facebook, YouTube, Venmo, LinkedIn, Twitter and the wider web, all without the consent of the people pictured. It sold the resulting "search any face" tool to over 600 law enforcement agencies and private companies. A New York Times investigation exposed the operation on January 18, 2020. Five weeks later, on February 26, 2020, an intruder exploited a flaw and stole Clearview's entire client list, including customer names, the number of accounts each had set up, and how many searches they had run. Regulators across Europe later ruled the scraping unlawful: France's CNIL and Italy's Garante each fined the company EUR 20 million, Greece added EUR 20 million, and the Netherlands imposed EUR 30 million, with multiple orders to delete the biometric data and stop processing it.
What the machine did
The AI was a face-matching engine trained and operated on a dataset whose entire legal and ethical basis was never validated by anyone with the authority to say no. There was no human SME consent-and-lawfulness gate in front of the data ingestion pipeline: the scraper ran autonomously across the open web, vacuuming biometric data at machine scale, and the matching model was shipped to police on the assumption that "public photo" equals "fair game." No data-protection officer, no legal review, and no jurisdictional check stood between the crawler and 3 billion faces. The model worked exactly as built. The problem was that nothing in the build process required a human to confirm the source data was lawful to collect, lawful to retain, or lawful to sell, before it became a product used to identify real people.
Where the failure landed
Clearview's complete customer list was exfiltrated, exposing which police forces and companies were secretly using face surveillance. Cease-and-desist letters arrived from Facebook, Google, YouTube, Twitter and Venmo for terms-of-service violations. Regulators ruled the company had no lawful basis to process the biometric data of EU residents: CNIL (France) and the Garante (Italy) each levied EUR 20 million, Greece another EUR 20 million, and the Netherlands EUR 30 million, alongside binding orders to delete EU citizens' data and a EUR 100,000-per-day penalty for non-compliance in France. In the U.S., an ACLU lawsuit under Illinois's BIPA forced Clearview to permanently stop selling its database to most private companies. Millions of people had their faces enrolled into a police-grade identification system without ever being asked.
Official finding
Supported by a court, regulator, inquiry, or other official record cited below.
SOURCE RECORD UPDATED 2026-07-09
3 cited records
- 01
- 02
- 03Secondary / analysisEDPB: The French SA (CNIL) fines Clearview AI EUR 20 million (2022)
Named SME review and decision audit trail
The failure pattern in this case: Automated judgment without accountable review.
The moment the path could change
A qualified reviewer tests the basis, context, and disparate impact before the decision reaches a person.
Autonomy is a design choice.
See the operating model that keeps AI useful while preserving human authority at consequential moments.
Compare AgenticAI and AugmentedAI →