As Microsoft and Amazon push for federal regulation of facial recognition, an overview of related local laws that have been passed and tech lobbying efforts
Brian Fung / CNN : Tweets: @tobywalsh and @einsteinsattic Tweets: Toby Walsh / @tobywalsh : IBM, Microsoft, and Amazon's face recognition bans don't go far enough: “We need a full-on recall of all of these technologies.” https://www.fastcompany.com/ ... Phil Booth / @einsteinsattic : Some very good points in this article. The companies' actions might be more convincing if they all actively lobbied FOR *general* #DataProtection grounded in #HumanRights, rather than pick and choose which services & #algorithms they sold to the police. https://www.fastcompany.com/ ...
Context & Ripple Effects
The lobbying push CNN covers did not appear overnight. Microsoft first stepped up its calls for federal facial recognition rules in December 2018 under pressure from AI Now to open its algorithms to auditing, and by February 2019 Amazon had followed suit with its own 'responsible use' guidelines — two vendors asking Washington to set the rules they were already selling against.
By mid-2020 the picture sharpened: an overview of how US law enforcement actually deploys the technology documented the transparency gap critics keep citing, IBM, Microsoft, and Amazon announced moratoria on police sales, and lawmakers told CNET that federal legislation was unlikely within a year — which is exactly why the local laws this article surveys carry the weight.
First-order effects
- City and state councils drafting facial recognition bans become the de facto rule-makers for Amazon and Microsoft's police-facing business while Congress stalls, forcing the vendors to navigate a patchwork instead of one federal standard.
- Critics like Toby Walsh and Phil Booth immediately frame the companies' moratoria as insufficient — a full recall of deployed systems and lobbying for general rights-based data protection, not selective product choices, is what would count as real action.
Second-order effects
- With federal regulation unlikely in the near term per the CNET reporting after the Amazon, IBM, and Microsoft moratoria, compliance costs shift onto law enforcement agencies, which must audit or drop tools their vendors just walked away from.
- Smaller facial recognition vendors that do not follow the big three out of the police market gain a window to pick up contracts the moratorium vacated — without the reputational overhead the majors now carry.
Third-order effects
- If the pattern holds — federal inaction plus state-level accumulation — governance settles into a states-first regime, a trajectory the NPR coverage confirms years on: facial recognition still federally unregulated while 23 states restrict mass scraping of biometric data.
- Vendor-led 'regulate us' advocacy becomes a durable template for AI policy: the companies with the most deployed models shape the rules, while auditors like AI Now press the counterargument that self-chosen guidelines are not accountability.
The trend: US facial recognition governance is consolidating around state and local law plus vendor self-regulation rather than federal statute, setting the template for how other AI categories get governed.