By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer

TL;DR: Chuck Gallagher, AI ethics speaker and author, argues that Clearview AI has never once won on the question of whether its business is right — it has won, over and over, on the question of who has authority to ask — and that any company treating jurisdiction as its ethics program is running a clock, not a policy.

One is a Chicago police officer. The other is a federal agent. Both are holding a photograph of the same unidentified person. For the city officer, running that photo through Clearview AI’s facial recognition database is off the table — Illinois law and a court settlement put it there, and the penalties are real. For the federal agent standing next to him, it’s a Tuesday.

Same photo. Same face. Same sidewalk. Same second.

Different rules.

Nothing about the ethics of that search changed in those three feet. Only the jurisdiction did. And if that gap strikes you as a technicality, consider that an entire company has been built inside it.

How Did Illinois Become the Line?

Illinois passed the Biometric Information Privacy Act in 2008. Long before anybody worried about this. BIPA requires informed consent before a company collects biometric identifiers like a faceprint. It authorizes $1,000 in liquidated damages for a negligent violation and $5,000 for a reckless or intentional one, plus attorney fees, plus injunctive relief. It is the strongest biometric privacy law in the country. Not close.

The ACLU sued Clearview under it in 2020. The settlement came down in Illinois state court in May 2022, and it did real work: Clearview was permanently enjoined from giving database access to private parties except in compliance with BIPA, and required to build an opt-out program for Illinois residents. In practical terms it ended Clearview’s business with private companies in the U.S. Its customers since then have been government agencies and their contractors.

Here’s what that settlement could not do. A state law and a state court settlement reach state and local actors. Federal agents operating inside Illinois sit outside both.

So Clearview’s Illinois problem quietly became Clearview’s Illinois map.

What Does Clearview Do When a New Law Passes?

It complies. Narrowly, locally, and only where it has to. When California and Virginia passed biometric privacy laws, Clearview extended its opt-out program to those states — or stopped doing business in a state altogether when that was easier. Not New York, though. A New York biometric privacy bill passed the state senate on June 3, 2026, which suggests that particular seam is closing.

Overseas, the same logic runs louder. Regulators in France, Italy, Greece, and the Netherlands assessed roughly 100 million euros in penalties against the company. Reporting indicates Clearview has paid none of it. Not a euro. The argument was about jurisdiction: no European office, no European customers, therefore no European authority. Nobody had to say a word about right and wrong. Its founder’s public answer to deletion orders was that you cannot determine residency from a public photograph.

And it worked. A UK tribunal overturned a 7.5 million pound fine in 2023, finding the company’s data processing sat beyond the material scope of European privacy law because its service was used only by law enforcement outside the UK and the EU.

As an AI ethics speaker and author, I want you to notice what is absent from every one of those fights. Not once did anyone successfully argue that the scraping was right. The entire contest, in every venue, on two continents, was about who has standing to ask the question.

What Happens When the Buyer Has No Rules Either?

So far this is a story about one company. It isn’t anymore.

In September 2023 the Government Accountability Office published a review of seven federal law enforcement agencies using commercial facial recognition services. All seven began using the technology without requiring staff to complete any training. Six of them, where data existed, ran roughly 60,000 searches while no training requirement was in place. At the FBI, 196 staff accessed the service and 10 completed the training — the bureau told internal stakeholders training was required but in practice only recommended it. Four of the seven agencies had no facial recognition policy addressing civil rights and civil liberties at all.

Ten out of 196. You may want to read that one twice.

Give credit where it’s due. All ten of GAO’s recommendations were accepted. Customs and Border Protection let its services expire at the end of fiscal 2023, told staff to stop, and built a training course. ICE created a process in June 2024 to verify that only trained staff can open an account.

But three of GAO’s privacy recommendations are still sitting open — two at the Justice Department as of January 2026, one at Homeland Security. Two and a half years after the finding. And the DHS directive governing face recognition, issued in September 2023, came off the department’s public website in February 2025. An oversight board flagged the removal and reported that the department never clarified whether the directive still applies. DHS called it routine site maintenance and said no policy had changed.

Maybe that’s all it was. But “we didn’t change the policy, we just took it down” is a sentence that means precisely nothing to the person whose face got searched.

What Is Your Compliance Map Actually Telling You?

Every organization has one. Where the regulator’s arm stops. Which entity holds the risk. Which jurisdiction’s law governs the contract. That’s not sinister — that’s competent lawyering, and you’d be negligent not to know your map.

The trouble starts when the map becomes the answer.

As an AI ethics speaker and author, here’s the test I put to leadership teams. If the only reason you’re able to do this is that nobody with authority over you has gotten around to prohibiting it yet — is that a decision, or is that a delay?

Trust me on the difference. I once had a long list of reasons why what I was doing wasn’t really the thing it was. The list held up fine right until the day somebody with authority asked.

Because the seams close. New York is closing one. The Dutch regulator has said it intends to pursue directors personally, on the theory that liability attaches the moment you know the law is being broken, you have the authority to stop it, and you don’t. An Austrian privacy group filed a criminal complaint aimed at executives. Congress keeps introducing bills. Some year one of them passes. The wheels may move slowly. They come around.

The map you’re standing on gets redrawn. And it gets redrawn by people who watched exactly what you did while you were standing on it.

Frequently Asked Questions

Why can’t Illinois police use Clearview AI when federal agents in Illinois can?

Illinois’s Biometric Information Privacy Act, and a May 2022 ACLU settlement enforcing it, restrict Clearview from selling database access to private parties and to state and local agencies in Illinois except in compliance with the statute. State law and a state court settlement bind state and local actors. Federal agencies operating within Illinois were never parties to that settlement and are not governed by state biometric law, so the same search can be prohibited for a city officer and unrestricted for a federal agent standing beside them.

Has Clearview AI paid its European fines?

Reporting indicates it has not paid the roughly 100 million euros assessed by regulators in France, Italy, Greece, and the Netherlands. The company’s position is jurisdictional. It maintains it has no place of business in the EU, no EU customers, and therefore falls outside European privacy law. A UK tribunal accepted a version of that reasoning in 2023, overturning a 7.5 million pound fine on the ground that the processing fell beyond the material scope of the GDPR.

What did the GAO find about federal use of facial recognition?

Its September 2023 report examined seven law enforcement agencies at the Departments of Homeland Security and Justice. All seven initially deployed commercial facial recognition without requiring staff training; six conducted about 60,000 searches with no training requirement in place. At the FBI, 10 of 196 staff who accessed the service had completed training. Four of the seven agencies lacked any facial recognition policy addressing civil rights and civil liberties at all. All ten GAO recommendations were accepted. Several are now implemented.

Is there a federal law governing facial recognition in the United States?

No comprehensive one. Facial recognition in the U.S. is governed by a patchwork of state biometric statutes — Illinois, Texas, and Washington among the earliest — plus agency-level policies that can be revised or withdrawn without legislation. Bills have been introduced in Congress repeatedly, including privacy legislation in the current session. None has become law. That gap is precisely what makes the jurisdictional question so decisive.

What should companies take from Clearview’s jurisdiction strategy?

That a defense built on authority rather than merit is a timing bet. As an AI ethics speaker and author, the point I make to leadership teams is that if the only argument for a practice is that no regulator currently reaches it, the practice has an expiration date — and when the rule finally arrives, the record of what you did in the meantime arrives right along with it. Regulators in the Netherlands are already pursuing individual directors on exactly that logic.

Let’s Talk

Somewhere in your organization there’s a practice that survives on a map — legal because of where the entity sits, or which agency has authority, or which statute hasn’t been written yet. Your lawyers know exactly where that line is, and they should. The question nobody’s assigned to ask is what happens the day the line moves, because the line always moves, and it moves toward whatever you were doing when nobody was watching. I work with boards, executive teams, and compliance leaders on the difference between what you’re permitted to do and what you’re willing to defend — particularly around AI systems, biometric and customer data, and the gap between a policy that exists and a policy that bites. If your team is building on ground that could get redrawn, let’s have that conversation now. Learn more at ChuckGallagher.com.

Five Questions for Reflection

1. Name one practice in your organization that is permitted only because no one with authority over you has prohibited it yet. Would you defend it publicly?

2. Clearview never argued the scraping was right — only that the regulator couldn’t reach it. Where does your company make an authority argument instead of a merits argument?

3. Four of seven federal agencies had no facial recognition policy at all while running searches. Which of your AI tools is in use ahead of the policy governing it?

4. A policy came off a website and the department said nothing changed. What’s the difference, in your organization, between a rule that exists and a rule that bites?

5. If the law governing your industry changed tomorrow and applied retroactively to conduct, not just to going-forward practice, what would you want to have already stopped?

Leave a Reply