While facial recognition tech remains unregulated at the US federal level, 23 states have passed or expanded laws to restrict mass scraping of biometric data
Bobby Allyn / NPR : LinkedIn: Pete Fussey . Bluesky: @eff.org . Forums: r/technology LinkedIn: Pete Fussey : Interviewed for this NPR story on US State-level initiatives to regulate biometrics in the absence of Federal interventions. … Bluesky: @eff.org : “What we need are laws that change the behavior of technology companies” regarding biometric privacy, EFF's Adam Schwartz told @NPR.org. “Otherwise these companies will continue to profit on what should be our private information.” www.npr.org/2025/08/28/... Forums: r/technology : With no federal facial recognition law, states rush to fill void
Context & Ripple Effects
The coverage arc has moved from unresolved concerns about facial-data collection in a growing market to industry calls for national rules, including Microsoft and Amazon’s push for federal facial-recognition regulation.
State and local policy has not followed a single path: some jurisdictions had been retreating from outright facial-recognition bans amid public-safety pressures. The new state-level restrictions instead focus attention on how biometric data is gathered at scale.
First-order effects
- Companies that mass-scrape biometric data now face new or expanded state-level limits on collecting and using that data, while federal policy remains absent.
- Privacy advocates gain a concrete state-law route to press for changes in corporate biometric-data practices, rather than relying on voluntary commitments.
Second-order effects
- A growing set of state rules creates a fragmented compliance environment for biometric-data businesses and the organizations that supply them with images or other identifying inputs.
- The policy debate shifts from facial recognition’s downstream use toward upstream data acquisition—an issue flagged earlier when concerns about facial-data collection lacked clear rules.
Third-order effects
- If more states adopt restrictions, biometric-data governance may be shaped primarily by state permission and privacy boundaries rather than a uniform federal facial-recognition framework.
- The durable fault line will be whether rules constrain collection itself or only specific uses of facial recognition; the differing state approaches suggest that distinction will remain contested.
The trend: Biometric AI governance is increasingly being built through state-level limits on data collection as federal regulation remains unresolved.