How Does Facial Recognition Work?
There is no single accuracy figure for facial recognition, and asking for one is the wrong question.
The evidence for that is not an opinion. The US National Institute of Standards and Technology runs the standing evaluation that the whole field is measured against, and its published data shows the same top-ranked algorithm, unchanged, failing on 0.14% of comparisons in one setting and 3.34% in another. Roughly twenty-four times worse, because the pictures were different. The two were measured at different thresholds, and the better figure came from the stricter one, so the real gap is not smaller than that.
This article walks through what the system actually does, why there are two kinds of error rather than one, where a human chooses the tradeoff, and what the current government evaluation data shows about accuracy and about who bears the errors.
What the system does
Four steps, and the vocabulary matters because it is where the confusion starts.
Detection. The software first has to find a face in the image. This is a separate problem from identifying whose face it is, and it was largely solved before modern machine learning: the classic approach scans the image, discards background regions quickly, and spends effort only on face-like areas.
Template. The system does not store a photo. It produces a template: a compact numerical representation. NIST's testing interface defines it as a data structure holding an embedding, a mapping from a face image into a numerical space where distance corresponds to similarity. One influential method compressed a face to 128 bytes. A template is specific to the algorithm that produced it. It is not a portable copy of your face.
Comparison. Two templates go in and a single number comes out. NIST specifies that algorithms return "a similarity score, higher is more similar." The system does not say yes or no. It produces a number.
Threshold. Somebody decides how high that number has to be. NIST puts it plainly: comparisons are "subject to noise and presentation variations that require setting an acceptance threshold."
That last step is where a human judgment gets baked into a system that then looks purely technical.
One-to-one and one-to-many are different jobs
This distinction does more work than anything else in the subject, and most confusion about facial recognition comes from collapsing it.
Verification is one-to-one. You claim to be someone, and the system compares your face to one stored template. Unlocking a phone, or matching a traveler to their own passport photo. The EU AI Act defines it as "the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data."
Identification is one-to-many. An unknown face is compared against a database. The same regulation defines this as establishing identity "by comparing biometric data of that individual to biometric data of individuals stored in a database."
The consequences of an error are not symmetrical, and NIST's Patrick Grother put it better than anyone: "In a one-to-one search, a false negative might be merely an inconvenience. You can't get into your phone, but the issue can usually be remediated by a second attempt." A false positive in a one-to-many search, by contrast, "puts an incorrect match on a list of candidates that warrant further scrutiny."
NIST also distinguishes two ways one-to-many gets used. In identification mode a threshold is set and the system supports mostly automated decisions. In investigation mode the threshold is zero, the system returns a fixed list of fifty candidates, and it is, in NIST's words, "assumed and necessary that a human will be used to review the candidates."
Two errors, one dial
Every biometric system has two ways to be wrong, and they trade against each other.
A false non-match is failing to match two images of the same person. A false match is matching two images of different people. NIST's authentication guidance defines them in ordinary language: "there is some probability that a comparison will not result in a match, which is referred to as a false non-match rate. Similarly, there is a probability that an impostor comparison will result in a match, referred to as a false match rate."
The threshold sets the balance. Raise it and you get fewer false matches and more false non-matches. NIST describes the usual choice: "the chosen threshold usually emphasizes a low FMR to maximize security since false non-matches can often be mitigated by repeating the measurement."
One detail here is easy to miss and it matters later. NIST observes that "the vast majority of biometric systems are configured with a fixed threshold against which all comparisons are made," not tailored to cameras, conditions or demographics. Its own authentication guidance makes this a requirement rather than an accident. A biometric system "SHALL be configured with a fixed threshold," because "it is not feasible to change the threshold for each demographic."
One dial, one setting, everybody.
How accurate is it, actually
Accuracy improved dramatically and then the question changed shape.
NIST's 2018 evaluation found that searching mugshots in a gallery of 1.6 million people, the most accurate algorithm of June 2018 made "a factor of 20 fewer misses than the most accurate algorithm in 2013." NIST attributed this to deep neural networks and wrote that "face recognition has undergone an industrial revolution."
Current figures, from NIST's evaluation data as of 1 September 2026, show the ceiling and the floor at once.
| What is being compared | Threshold it was measured at | Best failure rate |
|---|---|---|
| Visa portrait against a border photo | 1 false match per million comparisons | 0.14% |
| Mugshot against mugshot | 1 false match per 100,000 comparisons | 0.20% |
| Border photo against a self-service kiosk photo | 1 false match per 100,000 comparisons | 3.34% |
| Mugshot against a 90 degree profile shot, 1.6 million gallery | 0.3% false alarm rate on searches | about 1 in 22 |
| Mugshot against mugshot, 12 million gallery | 0.3% false alarm rate on searches | about 1 in 2,000 |
Read the first and third rows together. That is the same top-ranked algorithm. NIST describes border images as "moderately poor webcam border-crossing photos that exhibit pose variations, poor compression, and low contrast," and kiosk images as having "considerable downward pitch angle." The technology did not change between those rows. The photograph did, and so did the threshold, which is why the table states it: the better figure was measured at the stricter setting.
Every one of these numbers is meaningless without its dataset, its threshold and, for a search, the size of the database.
It is not a password
Two properties separate a face from a passcode, and NIST states both. "Biometric characteristics do not constitute secrets. They can often be obtained online or otherwise without consent. A facial image can be obtained by taking a picture." And they cannot be reissued: schemes that would allow revocation exist in the research literature, but NIST notes "the availability of such solutions is limited."
NIST's conclusion follows: biometrics "SHALL only be used as part of multi-factor authentication with a physical authenticator," an alternative non-biometric option must always be available, and biometric comparison "is probabilistic, whereas the other authentication factors are deterministic."
NIST's twins data is the vivid illustration. On its identical-twins track, the algorithm ranked most accurate on ordinary mugshots accepts identical twins as the same person about 99.5% of the time. Apple concedes the same for twins, similar-looking siblings and children under 13. Google is blunter: your device "can be unlocked by someone who looks a lot like you, like an identical sibling," and "can also be unlocked by someone else if it's held up to your face."
That last point is what liveness detection addresses. ISO/IEC 30107 covers presentation attack detection: telling a live face from a photograph, a replay or a mask. Synthetic faces are a separate subject, covered in Lathic's article on deepfakes. NIST requires detection for federal authentication and has evaluated 82 such algorithms from 45 developers, finding it "varies widely across algorithms, use cases and attack types."
Who bears the errors
This is the part most often reported inaccurately, in both directions.
NIST's landmark 2019 study found the two error types behave differently: "false positive differentials are much larger than those related to false negatives and exist broadly, across many, but not all, algorithms tested. Across demographics, false positives rates often vary by factors of 10 to beyond 100 times. False negatives tend to be more algorithm-specific, and vary often by factors below 3."
The direction depends on the algorithm and the dataset. On one set of photos, false positives were highest for West and East African and East Asian people and lowest for Eastern Europeans, but NIST noted that "with a number of algorithms developed in China this effect is reversed." It also found false positives higher in women than men, consistently across algorithms though smaller than the effect of race, and elevated in the elderly and in children.
The mechanisms differ. NIST attributes false negatives largely to image quality, including lighting that underexposes darker skin, and false positives primarily to "anatomic similarity of the faces," occurring "in images of pristine quality," with a contribution from under-representation in training data.
Current data is sharper, and worth reading exactly. NIST's 1:1 demographic test, updated 1 September 2026, ranks 658 algorithms on one figure: the false match rate for the worst-affected demographic group set against the average across all groups, each algorithm's threshold fixed to give an overall false match rate of 3 in 10,000. The most equitable scores about 2.6. At the far end of the ranking the figure is around 326. The gap between algorithms is much wider than the gap between demographic groups inside any one algorithm, which is NIST's own point. In both the most equitable algorithm and the one at the far end, the worst-affected group was the same: women aged 65 and over born in West Africa.
Three caveats NIST insists on. Results do not generalize: announcing the 2019 study, NIST's Patrick Grother said that "while it is usually incorrect to make statements across algorithms, we found empirical evidence for the existence of demographic differentials in the majority of the face recognition algorithms we studied." More accurate algorithms generally produce smaller differentials. And NIST tests submitted algorithms in a laboratory rather than deployed systems, which is why the 2019 report concluded that "it will usually be informative to specifically measure accuracy of the operational algorithm on the operational image data."
Now connect this to the threshold. One fixed setting serves everyone, so a group with a higher false match rate at that setting absorbs more of the error, by design rather than by malice. Lathic's article on AI bias covers the general mechanism; this is the specific version.
What goes wrong in practice
The documented failures are not algorithms declaring guilt. They are processes.
In 2020 Robert Williams was arrested in Detroit after a facial recognition lead. He sued, and the case settled with an order entered in June 2024. The terms are the useful part, because they name the actual failure. Probable cause "must be established using legally authorized methods other than Facial Recognition," and "the photographic lineup shall not contain an image derived from facial recognition."
That second provision is the mechanism. A lead from a search fed a photo lineup, which then appeared to confirm it. The court retained jurisdiction to enforce the agreement for four years.
Practice varies widely. The US Government Accountability Office found that of seven federal law enforcement agencies using facial recognition between October 2019 and March 2022, all seven initially did so without requiring staff training, only two required it by April 2023, and only three had policies addressing civil rights and civil liberties.
Retail has one federal enforcement action. In December 2023 the Federal Trade Commission said Rite Aid had deployed facial recognition across hundreds of stores without reasonable safeguards, generating thousands of false matches, and that it "was more likely to generate false positives in stores located in plurality-Black and Asian communities than in plurality-White communities." The order imposed a five-year ban.
What the law says, and where
Rules vary enormously by jurisdiction, and general statements are almost always wrong. Four specifics, each tied to a place and a date.
The EU AI Act does not ban facial recognition. Article 5 prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, with narrow exceptions for searches for victims and missing persons, imminent threats to life, and locating suspects for serious offenses, and even then requires prior judicial or independent authorization. All four qualifiers matter. It separately bans building facial recognition databases by untargeted scraping from the internet or CCTV. Those prohibitions have applied since 2 February 2025, ahead of the Regulation's general application on 2 August 2026. One-to-one verification is carved out of the high-risk category.
Illinois has the strongest US state law. Its Biometric Information Privacy Act covers a "scan of hand or face geometry," requires written notice and a written release before collection, and provides liquidated damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless one. The Illinois Supreme Court held in 2019 that a person need not show injury beyond the violation itself.
There is no single US federal statute. What exists is fragmentary: FTC enforcement, agency rulemaking, and state law. At the US border, a DHS rule effective 26 December 2025 allows photographing all non-citizens on entry and departure, while participation by US citizens is voluntary and CBP states it does not retain citizens' photographs beyond 12 hours.
Where you actually meet it
| Setting | Task | Where the matching happens |
|---|---|---|
| Phone unlock | One-to-one verification | On the device |
| Airport and border | One-to-one, against your own travel document photo | Cloud service |
| Retail loss prevention | One-to-many, against a watchlist | Operator's system |
| Police investigation | One-to-many, against a large gallery | Operator's system |
Phone unlock is the least like the others. Apple states that Face ID data "doesn't leave your device, is never available to iOS or iPadOS, apps, or Apple." Google states the face model "is stored securely on your device and never leaves the device." Both are vendor claims. Neither product appears in NIST's published list of evaluated algorithms, which is not the same as having failed it.
Android grades phones differently from police tools. Its three biometric classes all require the same false accept rate of one in 50,000 and the same 10% false reject rate; what separates them is spoof resistance. Class is about how hard a system is to fool, not how accurate it is.
The one thing to take away
Facial recognition is not one technology with one accuracy. It is a pipeline whose output depends on the photograph, the task, the size of the database, the person in front of the camera, and a threshold somebody set.
When you see a number, ask what was compared to what, at what setting, and against how many people. NIST publishes all three for every figure it reports. A number given without them cannot be checked, and should not be trusted.
Related AI terms
Frequently Asked Questions
Can facial recognition be fooled?
Sometimes, and systems are graded on exactly this. ISO/IEC 30107 covers presentation attack detection: telling a live face from a photograph, a replay or a mask. NIST evaluated 82 such algorithms from 45 developers and found detection varies widely by algorithm and attack type. Android grades phone biometrics primarily on spoof resistance.
How accurate is facial recognition?
There is no single number, and any source giving one has left out what matters. NIST reports two error types separately, at operator-chosen thresholds, per dataset. In its September 2026 data the best algorithm fails on 0.14% of comparisons between a visa portrait and a border photo, at a threshold allowing one false match per million, and 3.34% between a border photo and a kiosk photo, at one per 100,000. Same algorithm, different pictures, and different settings.
Is facial recognition illegal?
It depends entirely on where you are and who is using it for what. The EU prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, with narrow exceptions and judicial authorization required, and that has applied since 2 February 2025. It does not ban the technology generally. In the US there is no single federal statute; Illinois requires written notice and a written release before a private entity collects face geometry, with liquidated damages. Other jurisdictions differ.
Does facial recognition work differently on different people?
Yes, and the two error types behave differently, which most coverage flattens. In 2019 NIST found false match rates varying between demographic groups by factors of ten to beyond a hundred in many, though not all, algorithms tested, driven by facial similarity and training data representation. False non-match rates vary much less, usually under a factor of three, and are driven mainly by image quality. Because real systems use one threshold for everyone, a group with a higher false match rate at that setting absorbs more of the error.
What is the difference between face verification and face identification?
Verification is one-to-one: you claim an identity and the system compares your face to one stored template, as when you unlock a phone. Identification is one-to-many: an unknown face is searched against a database. The error that matters differs. A failed verification is an inconvenience you can retry. A false match in a database search puts the wrong person on a list of candidates for further scrutiny. That is how the wrongful arrest settled in Detroit in 2024 began.
Does my phone send my face to a company?
According to both major vendors, no. Apple states Face ID data does not leave the device and is never available to Apple, and Google states the face model is stored on the device and never leaves it. Those are the companies' own statements, and neither product appears among the algorithms NIST has evaluated. Airport and border systems work differently: CBP's service is cloud-based.
Sources
- NIST, "Face Technology Evaluations FRTE/FATE," program page, updated 22 April 2025. https://www.nist.gov/programs-projects/face-technology-evaluations-frtefate
- Patrick Grother, Mei Ngan, Kayee Hanaoka, Jason Yang and Austin Hom, "Face Recognition Technology Evaluation Part 1: Verification," NIST, draft dated 1 September 2026. https://pages.nist.gov/frvt/reports/11/frvt_11_report.pdf
- NIST, "FRTE 1:1 Verification" results, leaderboard and demographic data last updated 1 September 2026. https://pages.nist.gov/frvt/html/frvt11.html
- NIST, "FRTE 1:N Identification" results, last updated 3 September 2026. https://pages.nist.gov/frvt/html/frvt1N.html
- Patrick Grother, Mei Ngan and Kayee Hanaoka, "Face Recognition Vendor Test Part 3: Demographic Effects," NISTIR 8280, December 2019. https://nvlpubs.nist.gov/nistpubs/ir/2019/NIST.IR.8280.pdf
- NIST, "NIST Study Evaluates Effects of Race, Age, Sex on Face Recognition Software," 19 December 2019. https://www.nist.gov/news-events/news/2019/12/nist-study-evaluates-effects-race-age-sex-face-recognition-software
- Patrick Grother, "Face Recognition Vendor Test Part 8: Summarizing Demographic Differentials," NISTIR 8429, July 2022. https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8429.ipd.pdf
- NIST, "Face Recognition Technology Evaluation: Demographic Effects" overview page. https://pages.nist.gov/frvt/html/frvt_demographics.html
- Patrick Grother, Mei Ngan and Kayee Hanaoka, "Ongoing Face Recognition Vendor Test Part 2: Identification," NISTIR 8238, November 2018. https://nvlpubs.nist.gov/nistpubs/ir/2018/NIST.IR.8238.pdf
- NIST, "FRVT 1:1 Validation and API," version 6.0, 6 April 2023. https://pages.nist.gov/frvt/api/FRVT_ongoing_11_api.pdf
- Mei Ngan, Patrick Grother and Kayee Hanaoka, "Face Analysis Technology Evaluation Part 10: Performance of Passive, Software-Based Presentation Attack Detection Algorithms," NIST IR 8491, September 2023. https://nvlpubs.nist.gov/nistpubs/ir/2023/NIST.IR.8491.pdf
- NIST, "Digital Identity Guidelines: Authentication and Authenticator Management," NIST SP 800-63B-4. https://pages.nist.gov/800-63-4/sp800-63b.html
- Florian Schroff, Dmitry Kalenichenko and James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering," CVPR 2015. https://arxiv.org/abs/1503.03832
- Paul Viola and Michael J. Jones, "Robust Real-Time Face Detection," International Journal of Computer Vision 57(2), 2004. https://link.springer.com/article/10.1023/B:VISI.0000013087.49260.fb
- ISO/IEC 30107-1:2023, "Information technology, Biometric presentation attack detection, Part 1: Framework." https://www.iso.org/standard/83828.html
- Anil K. Jain, Karthik Nandakumar and Abhishek Nagar, "Biometric Template Security," EURASIP Journal on Advances in Signal Processing, 2008. https://link.springer.com/article/10.1155/2008/579416
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024, Articles 3 and 5 and Annex III, Official Journal, 12 July 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1689
- Illinois Biometric Information Privacy Act, 740 ILCS 14. https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
- Rosenbach v. Six Flags Entertainment Corp., 2019 IL 123186, Supreme Court of Illinois, 25 January 2019. https://law.justia.com/cases/illinois/supreme-court/2019/123186.html
- Williams v. City of Detroit, No. 21-10827 (E.D. Mich.), settlement order entered 28 June 2024. https://assets.aclu.org/live/uploads/2024/06/Final-Order-of-Dismissal-and-Settlement-Agreement.pdf
- US Government Accountability Office, "Facial Recognition Services: Federal Law Enforcement Agencies Should Take Actions to Implement Training, and Policies for Civil Liberties," GAO-23-105607, 2023. https://www.gao.gov/products/gao-23-105607
- Federal Trade Commission, "Rite Aid Banned from Using AI Facial Recognition After FTC Says Retailer Deployed Technology without Reasonable Safeguards," 19 December 2023. https://www.ftc.gov/news-events/news/press-releases/2023/12/rite-aid-banned-using-ai-facial-recognition-after-ftc-says-retailer-deployed-technology-without
- Department of Homeland Security, "Collection of Biometric Data From Aliens Upon Entry to and Departure From the United States," Final Rule, 90 FR 48604, 27 October 2025. https://www.federalregister.gov/documents/2025/10/27/2025-19655/collection-of-biometric-data-from-aliens-upon-entry-to-and-departure-from-the-united-states
- Apple, "About Face ID advanced technology," Apple Support, updated 18 September 2026. https://support.apple.com/en-us/102381
- Google, "Unlock your Pixel device with your face," Pixel Phone Help. https://support.google.com/pixelphone/answer/9517039?hl=en
- Android Open Source Project, "Measure biometric unlock security." https://source.android.com/docs/security/features/biometric/measure
- US Customs and Border Protection, "Biometrics." https://www.cbp.gov/travel/biometrics