69 AI Prompts, One Camera Network: Flock's 'OS Investigate' Turns Every License Plate Into a Behavioral Profile
Chasing the alpha, one block at a time.
Someone leaked the backend. And what's sitting inside Flock Safety's "OS Investigate" tool isn't just a license plate reader anymore — it's 69 preloaded AI prompts engineered to flag human movement patterns as suspicious. Not stolen vehicles. Not AMBER Alerts. Your patterns. How you drive. Where you linger. Which neighborhoods your tires cross at 2 AM. Sixty-nine behavioral templates, embedded in code, quietly deciding who gets reported to police and who doesn't (citation:2).
This isn't hypothetical. Flock's February 13 press release openly touts an "Expansive AI and Data Analysis Toolset for Law Enforcement" — their words, not mine. The system now offers "Multi-State Insights" that alert officers when suspect vehicles have been detected across state lines, "Linked Vehicles" or "Convoy Search" to uncover cars frequently seen together, and "Multiple Locations Search" to surface vehicles appearing in multiple spots (citation:2). Each of these features runs on prompts. Prompts that define what "suspicious" looks like. Prompts nobody outside Flock has ever audited.
Speed is the only currency that matters, and right now, the surveillance state is sprinting faster than any privacy protocol developer I know.
The Architecture Nobody Asked For
Here's what most people don't understand about Flock: it's not a camera company. It's a data aggregation company that happens to sell cameras.

Flock deploys nearly 90,000 cameras across roughly 7,000 networks nationwide as of July 2025 (citation:3). Every single one of those cameras streams license plate data — plates, timestamps, geolocation — into Flock's private cloud servers. From there, any police department in the network can search the entire national database. A small-town sheriff in rural Oregon can pull the movement history of a car registered in Boston. No warrant required. No probable cause demonstrated. Just a search field and a button (citation:3).
The incentive structure is brutal in its simplicity. If a department shares its data with the entire nationwide network, that department can also search the entire nationwide network. "You show me yours, I'll show you mine" — Flock's own training video demonstrates a single-click toggle labeled "Enable National Lookup" that instantly grants access to the full dragnet (citation:3). Departments also have the option to automatically accept sharing requests from any other agency, eliminating even the friction of manual approval (citation:3).
The result? Over 80 Massachusetts police departments alone have spent over $2 million in taxpayer funds on Flock technology, and their data is now searchable by agencies in Texas, Florida, and thousands of other jurisdictions (citation:3). Officers in Dallas can track a Massachusetts resident's daily commute. Florida Highway Patrol can pull up every trip a car made through Boston's Back Bay over the past year. All without a judge ever signing anything.
From the front lines of the hype cycle, I've watched enough surveillance tech launches to know: the pitch is always narrower than the product. Always.
69 Prompts and the Surveillance Oracle Problem
Let me break down why the "69 preloaded AI prompts" detail matters so much — especially for anyone reading this through a crypto lens.
In DeFi, we talk constantly about oracle risk. Chainlink feeds stale price data, a liquidation cascade wipes out millions. The entire system depends on external data being accurate, timely, and resistant to manipulation. Now apply that same framework to law enforcement AI.
Flock's OS Investigate runs 69 behavioral prompts against license plate movement data. These prompts define patterns that the system flags as potentially linked to "large-scale criminal activities — such as human and narcotics trafficking and Organized Retail Crime" (citation:2). But here's the oracle problem: nobody outside Flock knows what those 69 prompts actually contain. What constitutes a "suspicious" movement pattern? How many data points trigger a flag? What's the false positive rate?
We don't know. Flock is a private company not subject to open records laws or elected-official oversight (citation:2). The algorithm's logic, training data, and error rates are entirely opaque. Imagine if Chainlink published no documentation, ran no audits, and told you to just trust the feed. That's exactly the epistemic position Flock's AI occupies — except instead of liquidating your collateral, it's flagging you to police.

And the biases baked into this system are predictable. Flock's cameras are deployed disproportionately in certain neighborhoods. The training data for criminal behavior patterns almost certainly reflects decades of over-policing in low-income communities and communities of color (citation:2)(citation:6). Just living in a particular zip code could make your movement patterns inherently "suspicious" to an algorithm trained on arrest data that already encodes systemic racial bias (citation:6).
Turning red candles into green lessons — except in this context, the "red candles" are wrongful arrests, and the "lessons" are that algorithmic bias compounds just as viciously in surveillance systems as it does in DeFi liquidation engines.
The Data Broker Bridge: LPR to Person in One Click
The surveillance infrastructure doesn't stop at license plates. Flock is actively integrating with commercial data brokers offering "people lookup" services — a product that lets police "jump from LPR to person" (citation:1).
Flock has long maintained the fiction that license plate data doesn't constitute personally identifiable information. That claim was always hollow — plates map to registered owners, addresses, and VINs — but the data broker integration makes the falsity explicit (citation:1). The company is essentially automating the kind of dossier-building that Congress banned government agencies from doing in the 1970s after agencies were caught building Stasi-like files on citizens not suspected of any crime (citation:1). The workaround? Buy the data from ethically shady, frequently inaccurate private brokers instead of compiling it yourself. The Privacy Act didn't anticipate a world where corporations would do the dirty work and sell the output back to law enforcement at scale.
This is the bridge that turns a mass surveillance infrastructure into a mass surveillance state. Camera captures plate. Plate resolves to person. Person's movement history gets fed into 69 AI prompts. Prompts flag behavioral pattern. Officer receives alert. All of this happens without the target ever knowing they were evaluated.
Live from the edge of the unknown — except the edge is now a private server in Atlanta, and the unknown is which behavioral template just tagged your morning commute.
Who's Actually Getting Caught in This Net?
The ACLU's reporting reveals the real-world consequences already materializing.
Local police departments are using Flock's nationwide search capability to conduct immigration enforcement on behalf of ICE. Records obtained by 404Media show that many searches listed immigration purposes — including the notorious Enforcement and Removal Operations division — as the reason (citation:1). Officers in Oregon were providing informal assistance to ICE through Flock's system, bypassing sanctuary city policies that were specifically designed to prevent exactly this kind of federal-local data sharing (citation:1).
In Texas, a police officer used Flock's nationwide search to track down a woman who had a self-administered abortion — illegal in the state (citation:1). An abortion rights group reported to 404Media that women are experiencing "an overwhelming fear" that they're "being watched and tracked by the state" (citation:1). The surveillance system is creating a chilling effect that extends far beyond anyone actually flagged by the algorithm. It changes how people move through space. It changes where they're willing to drive. It changes whether they'll cross state lines for medical care.
This is the contrarian angle nobody in the crypto space talks about enough: privacy isn't just a feature for darknet markets and tax evaders. It's the infrastructure that enables people to access healthcare, attend protests, and exist without self-censoring every trip to the grocery store.
Pivoting when the chart says pause. The chart — in this case, the ACLU's network audit data — says pause. Police departments in over 42 states are participating in Flock's network (citation:4). The expansion isn't slowing. It's accelerating.
The Crypto Parallel Nobody's Building Fast Enough
Here's where my software engineering background kicks in, and where the blockchain angle becomes more than academic.
The core problem with Flock's architecture is that it's a centralized, private, unauditable system that aggregates movement data at national scale and applies opaque AI to generate suspicion. Every component of that sentence describes a design choice, not a technical inevitability. License plate recognition itself is neutral technology. The aggregation model, the data sharing incentives, the proprietary AI prompts — those are choices.
In principle, blockchain-based identity and data sovereignty frameworks could offer an alternative architecture. Decentralized identifiers (DIDs), zero-knowledge proofs for selective disclosure, on-chain access control for surveillance data — the theoretical toolkit exists. A system where camera operators record plate hits locally, encrypted against a user's DID, with access requiring cryptographic consent or judicial authorization, would fundamentally change the power dynamics Flock has constructed.

But nobody's building this at the speed the surveillance infrastructure is expanding. The privacy tech stack in crypto remains fragmented — a dozen Layer 2s all chasing the same small pool of users, not scaling but slicing already-scarce liquidity and developer attention into fragments (citation:5). Meanwhile, Flock is deploying 90,000 cameras and onboarding thousands of agencies. The asymmetry is staggering.
Surviving the winter to plant for spring — but the surveillance spring is already here, and the privacy protocol garden is barely sprouting.
The Unreported Angle: What Flock Means for On-Chain Privacy Narratives
There's a deeper contrarian take that I think the crypto media ecosystem is whiffing entirely.
Every time a privacy coin faces regulatory pressure — Monero delistings, Tornado Cash sanctions — the industry frames it as a crypto-specific problem. But Flock's expansion reveals something much broader: the default state of digital infrastructure in 2026 is surveillance, and the regulatory apparatus is designed to preserve that default, not challenge it.
When ICE leverages local police Flock data to conduct immigration raids (citation:1), when Texas officers use the system to hunt women who've had abortions (citation:1), when 7,000 agencies can track any American's movements without a warrant (citation:3) — these aren't edge cases. They're the primary use cases of mass surveillance infrastructure. The system was built for this. The 69 AI prompts weren't designed to protect communities. They were designed to classify, sort, and flag human beings based on movement patterns that no one has independently validated.
Privacy in crypto isn't a niche feature for cypherpunks anymore. It's becoming a survival mechanism for anyone who doesn't want a private algorithm deciding whether their Tuesday afternoon errand run constitutes "suspicious activity." The question isn't whether we need decentralized privacy infrastructure. It's whether we can build it before every highway in America becomes a behavioral assessment zone.
The sprint never stops, only the pace. Right now, the surveillance sprint is winning. The question I keep coming back to — the one that keeps me chasing this story block by block — is whether the crypto privacy ecosystem can match that velocity before the 69 prompts become 690, and the network grows from 90,000 cameras to 900,000.
That's the forward-looking thought I'll leave you with. Not a summary. A question with real stakes: In a world where a private company's algorithm can flag your movement as suspicious and report you to police — without a warrant, without transparency, without recourse — what is the decentralized alternative, and who's actually building it?
Because right now, the answer to the second part of that question is: nobody, fast enough.