State Facial Recognition Law Patchwork After Virginia's July 2026 Restrictions
Virginia's facial recognition authorization sunset on July 1, 2026, flipping the default from permitted-with-reporting to prohibited absent express authorization. How that compares to the other state models.
By IPA-IAC · 6 min · 6 August 2026

Virginia’s facial recognition change on July 1, 2026 is widely described as the state adopting the most detailed police-specific facial recognition rules in the country. That description has the direction backwards, and the error matters for any agency reading Virginia as a model.
Virginia did not add a rulebook. It let one expire.
What Actually Happened on July 1
The 2022 General Assembly passed SB 741, which amended §§ 15.2-1723.2 and 23.1-815.1 and added § 52-4.5, authorizing Virginia law enforcement to use facial recognition for investigative purposes — with an express expiration date of July 1, 2026.
That authorization was detailed. While in effect it provided:
- Fourteen enumerated authorized uses, from reasonable-suspicion identification through victim, missing-person, trafficking, deceased-person, and undercover-officer vetting
- A procurement accuracy floor: the Division of Purchases and Supply could approve only systems evaluated by NIST showing “at least 98 percent true positives” with “minimal performance variations across demographics”
- A prohibition on real-time tracking of an identified person through public spaces, and on building facial recognition databases from live video feeds
- An evidentiary limit: a facial recognition match could not be included in an affidavit to establish probable cause, though it was admissible as exculpatory evidence
- A State Police model policy, which agencies had to adopt or match with their own equal-or-stronger version
- Nine categories of mandatory record-keeping and annual public reporting by April 1
The reporting regime was unusually granular. Virginia’s DCJS reporting guide required agencies to submit record-level data for every query — not aggregate totals — including the authorized-use category, offense type, repository queried, subject race, ethnicity and gender, whether a candidate list resulted, whether an examiner offered an investigative lead, and whether a case closed with that lead confirmed. Agencies with no queries had to file a zero report to avoid being flagged non-compliant.
All of that sat inside the statute that expired.
The Regime That Replaced It
The versions of § 15.2-1723.2 and § 23.1-815.1 that took effect July 1, 2026 are much shorter, and considerably more restrictive in their default posture. The operative rule for local agencies:
No local law-enforcement agency may purchase or deploy facial recognition technology unless such purchase or deployment is expressly authorized by statute.
With a closing device that does real work: statutes that do not explicitly reference facial recognition technology cannot be construed as providing authorization. General surveillance or investigative authority does not carry over.
Approved technology must remain under the agency’s exclusive control, with data kept confidential, not disseminated or resold, and accessible only under a search warrant issued per Title 19.2, Chapter 5, or an administrative or inspection warrant. Commercial air service airports remain exempt, as they were before.
Notably absent from the new versions: the fourteen enumerated uses, and the provision barring facial recognition matches from probable-cause affidavits. The permission structure and its accompanying evidentiary guardrail lapsed together.
Agencies should verify current status against the official Code before acting — sunset dates attract amendment, and the General Assembly may revisit this. But as the Code publishes it, Virginia moved from permitted for enumerated purposes subject to heavy reporting to prohibited absent express statutory authorization.
Why This Is a Different Regulatory Model
Most state facial recognition laws regulate how police use the technology. Virginia now regulates whether they may at all, and answers no by default.
That distinction is worth drawing carefully because the two approaches fail differently. A use-regulating statute assumes deployment and constrains it — which requires ongoing auditing to mean anything, as the ALPR enforcement actions of 2026 demonstrated when agencies discovered prohibited queries had been running against their own data for months. An authorization-gating statute puts the decision in the legislature and requires nothing of auditors, but it also produces no data about performance, because there is no permitted program generating any.
Virginia’s expired framework was the country’s best source of disaggregated facial recognition performance data by subject demographics. Whatever one concludes about the sunset, that dataset stops growing.
Where the Other States Sit
The Center for Democracy and Technology organizes the state landscape along four axes, which is the most useful way to compare them:
Judicial authorization — Montana and Utah generally require a warrant before use. Maine requires probable cause. Massachusetts requires a court order but on a lower standard: the government must show identification is relevant to an investigation, not that probable cause exists. Washington also imposes a warrant or court-order requirement. The spread between Maine’s probable cause and Massachusetts’s relevance standard is wide enough that “court authorization required” tells you almost nothing without reading which.
Serious-crime limits — Illinois, Maine, Maryland, Montana, Utah, and Vermont restrict use to enumerated serious offenses, rather than permitting it across any investigation.
Notice — Colorado, Maryland, Montana, New Jersey, and Washington require some form of notice, whether to defendants, to the public, or both.
No sole-basis arrests — Alabama, Colorado, Maine, Maryland, Montana, Virginia, and Washington bar a facial recognition match from being the sole basis for an arrest. This is the closest thing to a national consensus provision, and it is the one most directly responsive to the documented misidentification cases.
Illinois sits partly outside this frame. BIPA regulates commercial biometric collection — written consent, private right of action — rather than police use specifically. Its practical effect on law enforcement runs through vendors and the data they may lawfully hold, which is a different and in some ways more durable lever.
What This Means Operationally
For agencies in Virginia: confirm you have express statutory authorization before any purchase or deployment. Reliance on general investigative authority is specifically foreclosed. Retain the records generated under the prior regime — they remain discoverable in cases where queries were run.
For agencies elsewhere: do not model policy on secondhand descriptions of Virginia’s framework. Much of what circulates as “Virginia’s rules” describes a statute that has expired. If the goal is a defensible operational model, the 2022 framework’s reporting design is the part worth borrowing — per-query records with authorized-use category, repository, demographics, and outcome — because it is what makes any use limit auditable rather than aspirational.
For anyone drafting: the NIST-evaluated 98 percent true-positive floor with minimal demographic variation is the most concrete procurement standard any state adopted, and it is technology-neutral in a way enumerated-use lists are not. It also has a clear failure mode worth anticipating: an accuracy threshold measured under NIST test conditions does not predict field performance on low-quality probe images, which is where misidentifications actually originate.
The federal vacuum is what produces the patchwork, and nothing in 2026 suggests it closes soon. Multistate agencies and task forces should expect to operate under the most restrictive applicable rule rather than a harmonized one — and, as with AI-generated police report disclosure, to track it statute by statute rather than by regional convention.