Ai Governance
Governance Audit of Three Facial-Recognition Platforms
AI Ethics Summer School, Pan-Africa Center for AI Ethics, August 2025. Clearview AI and Face++, AnyVision (Oosto), and Trueface scored against a 28-metric governance framework covering disclosure, bias auditing, consent, redress, and human oversight.
Thematic Area 2, AI in Security and Surveillance: used by public agencies and private companies for threat detection. Solo submission, Jiyae Choi, August 2025. Originally submitted as a Google Doc; published here verbatim, ratings as scored.
Clearview AI / Face++ (Megvii’s product)
Facial recognition, with controversial use in policing and immigration. Ratings are given as Clearview AI / Face++ where the two were scored separately.
| # | Metric | Comment | Rating |
|---|---|---|---|
| 1 | Disclosure of AI Use | Clearview AI: Facial recognition platform for law enforcement and public safety, limiting the uses of its system to agencies engaged in governmental or lawful investigative processes. Face++: Face detection, comparing, searching, emotion recognition, landmarks, beauty score, gaze estimation, etc. | 4/4 |
| 2 | Model Information | Clearview AI: Mentions 99% “highly accurate” algorithm and database scale (60B+ public images) but no architecture, training details or eval protocol beyond claims. (https://pages.nist.gov/frvt/reports/11/frvt_11_report.pdf) Face++: Provides access to API documentation but lacks details on model architecture, training data, or performance. (https://console.faceplusplus.com/documents/6329700) | 2/1 |
| 3 | Explainability Features | Clearview AI / Face++: No product-facing explanations of why a match appears or confidence/feature rationale found. | 0 |
| 4 | Public Documentation | Clearview AI: (https://app-na1.hubspotdocuments.com/documents/6595819/view/840811180?accessId=1a94e9) Face++: Offers FAQs, API docs, blog, and “Commitment to the Responsible Use of AI products” pages. | 3 |
| 5 | Privacy Policy Clarity | Clearview AI: Documentation exists, but privacy clarity requires more specificity. (https://app-na1.hubspotdocuments.com/documents/6595819/view/840811180?accessId=1a94e9) (https://www.clearview.ai/privacy-policy) Face++: AI Ethics Code of Conduct, AI Ethics Committee, Research Institute, Information Security Committee exists. But unable to view. | 2/2 |
| 6 | Data Collection Disclosure | Clearview AI: The largest known database of 60+ billion facial images sourced from public-only web sources, including news media, mugshot websites, public social media, and other open sources. Face++: Original pictures, videos and other data actively provided by the Clients. | 3/1 |
| 7 | Data Retention & Deletion Options | Clearview AI: Deindex Request, offers a tool to remove links from its search results. (https://app.clearview.ai/privacy/deindex) Face++: Users have rights: access, rectification, deletion, refusal of automated decisions; subject to legal/technical constraints; response within 30 days. | 4/4 |
| 8 | Third-Party Data Sharing | Clearview AI: Client-uploaded probe images are not shared, while public internet images are only shared with government customers for lawful investigations and public protection, or as legally required. Face++: Indicates personal data not shared with third parties without consent, except clients or per law. No explicit detail on vendors or categories. | 3/1 |
| 9 | Opt-in/Opt-out Options | Clearview AI: (https://app.clearview.ai/privacy/requests) Face++: The right to refuse automatic decision-making mentioned though not clear enough. | 4/2 |
| 10 | Bias Auditing | Clearview AI: Ensures unbiased data by returning images only when a 99% or better accuracy threshold is met across all demographic groups; otherwise, no results are provided. Face++: No published audit results or bias/fairness test data on their site. | 4/0 |
| 11 | Inclusive Design | Clearview AI: Website accessibility menu exists. No product UI accessibility features. (https://www.clearview.ai/accessibility) Face++: No documentation on accessibility features found. | 1/0 |
| 12 | Language & Cultural Inclusion | Clearview AI: Only in English, no information on multi-language support. Face++: English, Chinese support. No mention of product-level multilingual support. | 0/0 |
| 13 | Equity Commitments | Clearview AI: no comment recorded. Face++: AI Ethics Code of Conduct, AI Ethics Committee, Research Institute, Information Security Committee exists. But unable to view. | 3/2 |
| 14 | Editable Outputs | Clearview AI / Face++: No interface to correct or edit outputs. | 0/0 |
| 15 | Clear Consent for Data Use | Clearview AI: Privacy Policy consent for specific communications such as SMS. No general consent for web-scraped images that are for data training. (https://www.washingtonpost.com/technology/2022/02/16/clearview-expansion-facial-recognition/) Face++: Privacy Policy consent mentioned. | 1/3 |
| 16 | Child Safety Measures | Clearview AI: Authorized only for use of images of persons under the age of 16 for the purposes of protecting the child's safety, victim identification, when the child’s welfare is at risk, in connection with investigations of violent felonies, and to help protect against the spread of CSAM, where legally authorized. Face++: The guardian's prior consent has been authorized for the using minors’ data (under the age of 14). | 3/3 |
| 17 | Responsible AI Policy | Clearview AI: Responsible use policy documentation exists. (https://app-na1.hubspotdocuments.com/documents/6595819/view/270713220?accessId=542b4b) Face++: Includes a “Commitment to Responsible Use of AI products” but lacks a standalone ethics policy. AI Ethics Code of Conduct, AI Ethics Committee, Research Institute, Information Security Committee exists. But unable to view. (https://cdnstatic.megvii.com/proposal/proposal_en.html?t=1713256668610) (https://en.megvii.com/Responsible_AI) | 2/2 |
| 18 | Public Reporting | Clearview AI: (https://www.clearview.ai/principles) Face++: No transparency, impact, or audit reports published. | 3/0 |
| 19 | Independent Oversight | Clearview AI: Tested systems through industry-standard testing by objective third parties (National Institute for Standards and Technology). (https://pages.nist.gov/frvt/reportcards/11/clearviewai_000.html) Face++: No evidence of external audits or certifications mentioned. | 4/0 |
| 20 | Redress Mechanisms | Clearview AI: (https://app.clearview.ai/privacy/requests) Face++: Not mentioned at all. | 4/0 |
| 21 | Misuse Prevention | Clearview AI: Enforces strict conditions on its technology's use, enabling it to stop any customer globally who violates their obligation to use the technology only for lawful and authorized purposes. Face++: No explicit terms-of-use or restrictions. | 3/0 |
| 22 | Security Measures | Clearview AI: Safeguards over 60 billion facial images on a secure cloud platform, employing end-to-end encryption for data transmission and system design that records all usage for legal reconstruction during investigations. All live data is stored in a secured data center with strict internal access controls. Face++: Mentions encryption and security reviews but no details. | 4/1 |
| 23 | Incident Response | Clearview AI: Controls the use of its cloud-based image database, ensuring customers only use it for lawful and authorized purposes and can halt access if any abuse is identified. Face++: Not mentioned. | 3/0 |
| 24 | Dual-Use Awareness | Clearview AI: (https://www.clearview.ai/post/a-practitioner-s-guide-to-the-responsible-use-of-facial-recognition-technology) Face++: Not mentioned. | 4/0 |
| 25 | Human Oversight | Clearview AI: Provides results for human review and then subject to non-automated human review and verification. Face++: No statements on requiring human review for high-risk cases. | 4/0 |
| 26 | User Impact Assessment | Clearview AI: Specific actual use cases mentioned. (https://www.clearview.ai/success-stories) Face++: No specific actual scenarios mentioned. | 5/0 |
| 27 | Energy Efficiency Disclosure | Clearview AI / Face++: No environmental or energy usage information found. | 0/0 |
| 28 | Social Responsibility Commitments | Clearview AI: Highlights child-exploitation work and partnership press with ICMEC. Face++: The parent company (Megvii) has some figures on AI related research. (https://en.megvii.com/megvii_research) | 3/1 |
AnyVision (now Oosto)
Biometric surveillance.
| # | Metric | Comment | Rating |
|---|---|---|---|
| 1 | Disclosure of AI Use | Clearly highlights its use of AI in facial recognition solutions, to enhance access control, public safety, and enterprise operations. | 3 |
| 2 | Model Information | General technical overviews are referenced (e.g., “spoof-proof face recognition”), but no details on model architecture, training data, or performance metrics. | 1 |
| 3 | Explainability Features | No public mention of tools or mechanisms to explain AI outputs. | 0 |
| 4 | Public Documentation | Offers resources like blog posts, eBooks, case studies, and podcasts. No simple FAQs. | 2 |
| 5 | Privacy Policy Clarity | A dedicated and accessible Privacy Policy outlines how personal information is collected and used. (https://oosto.com/privacy/#section-1) | 4 |
| 6 | Data Collection Disclosure | Addresses data collection in websites and general services. No specific mentions about key data sources. | 2 |
| 7 | Data Retention & Deletion Options | Briefly mentioned in Privacy Policy. No explicit retention period or user deletion workflow. | 2 |
| 8 | Third-Party Data Sharing | No clear detail on data sharing with third parties like service providers or partners. | 1 |
| 9 | Opt-in/Opt-out Options | Enables customers to choose whether to record the faces of individuals not enrolled in the watchlist, avoiding unnecessary compliance risk. | 3 |
| 10 | Bias Auditing | Approach towards demographic bias is mentioned but no explicit audit results are provided. | 1 |
| 11 | Inclusive Design | No publicly documented accessibility features. | 0 |
| 12 | Language & Cultural Inclusion | Only in English, no information on multi-language support. | 0 |
| 13 | Equity Commitments | Emphasizing AI ethics and data privacy. No concrete equity initiatives are publicly stated. | 2 |
| 14 | Editable Outputs | No interface to correct or edit outputs. | 0 |
| 15 | Clear Consent for Data Use | Not enough consent mechanisms are evident. | 1 |
| 16 | Child Safety Measures | Explicitly mentioned from the private policy that for the user under the age of 18, it does not provide any information to us without the involvement of a parent or a guardian. | 3 |
| 17 | Responsible AI Policy | Introduces six principles (Fairness, Transparency, Accountability, Non-discrimination, Notice and Consent, Lawful Surveillance). (https://oosto.com/ai-ethics/) | 5 |
| 18 | Public Reporting | Blogs and eBooks exist. No formal transparency or impact reports available. | 2 |
| 19 | Independent Oversight | No external audits, certifications, or third-party oversight mentioned. | 0 |
| 20 | Redress Mechanisms | No explicit user redress channels. | 0 |
| 21 | Misuse Prevention | Is aware of responsible usage. No public policies or terms of service addressing misuse cases. | 0 |
| 22 | Security Measures | Software runs in each customer’s closed environment and does not require any outside connections. Only stores the vector images of POI with encryption, minimizing image data. No explicit technology resources. | 2 |
| 23 | Incident Response | No information on incident handling or breach response protocols. | 0 |
| 24 | Dual-Use Awareness | Is aware of responsible usage. No detailed mitigation practices. | 0 |
| 25 | Human Oversight | No statements suggest mandatory human review of AI decisions or oversight mechanisms. | 0 |
| 26 | User Impact Assessment | Ebook resources of real cases exist. (https://oosto.com/resources/type/case-study/) | 5 |
| 27 | Energy Efficiency Disclosure | No environmental or energy usage information found. | 0 |
| 28 | Social Responsibility Commitments | Has an internal Ethics Board who reviews ethical compliance mandates. (https://oosto.com/ethical-facial-recognition-best-practices/) Also partners with a variety of tech partners including NextGen Security, Honeywell, and NVIDIA to deliver reliable high-end face recognition capabilities. | 4 |
Trueface.ai (Bigbear.ai product)
Identity verification and threat detection.
| # | Metric | Comment | Rating |
|---|---|---|---|
| 1 | Disclosure of AI Use | Used for AI-based facial recognition, object detection, and spoof mitigation services. No real-life use cases mentioned. | 2 |
| 2 | Model Information | Reveal architectural details through documentation. No specification on model SDK (assuming this is confidential). (https://docs.trueface.ai/) (https://medium.com/trueface-ai/trueface-tutorials-converting-mxnet-models-to-work-with-high-performance-inference-frameworks-9b6cd709670f) | 4 |
| 3 | Explainability Features | No evidence of output explanation tools (e.g., confidence scores, rationale) publicly available (assuming this is confidential). | 0 |
| 4 | Public Documentation | Blog posts, tutorials on Medium, documentation, and case studies. (https://docs.trueface.ai/) (https://medium.com/trueface-ai/) (https://github.com/getchui) | 4 |
| 5 | Privacy Policy Clarity | Clear policy describing visitor data collection and usage. | 3 |
| 6 | Data Collection Disclosure | Describes site data (cookies, form data), but lacks specifics on face data use. | 2 |
| 7 | Data Retention & Deletion Options | No visible user deletion tools or retention timelines. | 0 |
| 8 | Third-Party Data Sharing | Unclear details on data sharing. | 0 |
| 9 | Opt-in/Opt-out Options | No user-facing opt-in/out controls. | 0 |
| 10 | Bias Auditing | Explains detailed bias mitigation efforts using FairFace dataset (TFV4 vs. TFV5). (https://medium.com/trueface-ai/pangiam-continues-to-eliminate-bias-in-face-recognition-algorithms-c85e58e07814) (https://medium.com/trueface-ai/trueface-tackles-facial-recognition-gender-and-ethnicity-bias-4c8b53de7806) | 4 |
| 11 | Inclusive Design | No publicly documented accessibility features. | 0 |
| 12 | Language & Cultural Inclusion | Only in English, no information on multi-language support. | 0 |
| 13 | Equity Commitments | Shares ethical commitments such as eliminating bias in face recognition algorithms (performance parity). (https://medium.com/trueface-ai/pangiam-continues-to-eliminate-bias-in-face-recognition-algorithms-c85e58e07814) | 3 |
| 14 | Editable Outputs | No interface to correct or edit outputs. | 0 |
| 15 | Clear Consent for Data Use | Consent for site usage only. No consent options provided for biometric data. | 1 |
| 16 | Child Safety Measures | No published policies regarding minors. | 0 |
| 17 | Responsible AI Policy | Has strong ethical stance, early bias transparency, and supports federal regulation of facial recognition. | 4 |
| 18 | Public Reporting | Publishes performance metrics: detailed FairFace bias analyses, DHS Biometric Rally results, and NIST FRVT speed ranking. (https://docs.trueface.ai/nist-frvt-results-analysis) | 5 |
| 19 | Independent Oversight | Audited by external benchmarks like NIST FRVT analysis. (https://docs.trueface.ai/nist-frvt-results-analysis) | 5 |
| 20 | Redress Mechanisms | No explicit user redress or appeal framework documented. | 0 |
| 21 | Misuse Prevention | Emphasizes ethical deployment on risk awareness. No explicit misuse controls. | 1 |
| 22 | Security Measures | On-premises deployment is available (implying data control). No formal certifications are mentioned. | 2 |
| 23 | Incident Response | No incident reporting or response procedure publicly described. | 0 |
| 24 | Dual-Use Awareness | Ethical posts reflect awareness of misuse risks. But no mitigation guidelines were published. | 2 |
| 25 | Human Oversight | No explicit requirement for human review of AI decisions. | 0 |
| 26 | User Impact Assessment | Shares potential impact (e.g., reduced bias, performance improvements) but no formal assessments. | 1 |
| 27 | Energy Efficiency Disclosure | No environmental or energy usage information found. | 0 |
| 28 | Social Responsibility Commitments | Emphasizes on ethical deployment, safer world vision, and public partnership (e.g., industry partnership with ISaBeL lab). No open datasets. | 2 |