Wegmans has long enjoyed a reputation as a customer-first brand—known for clean stores, attentive service, and a kind of grocery-store loyalty that borders on devotion. That reputation was tested last month when reports revealed that the company had begun quietly collecting and storing biometric data on shoppers in some locations, including New York City, as part of a loss-prevention effort.
According to Wegmans, the system is designed to alert employees when people who are believed to have shoplifted in the past reenter a store. The Rochester-based chain has emphasized that the data is not shared with third parties and is used strictly for security purposes. (Wegmans did not respond to a request for comment from Focal Point.)
Still, the response was swift. Customers, lawmakers, and data privacy advocates raised concerns about facial recognition, consent, and whether scanning large numbers of shoppers to identify a relatively small number of offenders was a proportionate response to retail theft.
The problem is not just that of Wegmans—other grocery chains (like Whole Foods), retailers (Macy’s), plus banks, credit card companies, healthcare firms, stadiums and other enterprises are barrelling ahead with biometric systems. The New York State Assembly currently has a bill pending that would require “clear notice and privacy protections” when retailers use biometric technology in stores.
Rachel Barnhart, a Monroe County legislator in New York who penned a letter to Wegmans, says she was struck by the immediacy and intensity of the backlash. “There was an overwhelming sense of, ‘I’m just going to the grocery store—why is my face being scanned?’” she says.
The backlash was also about how the move landed: quietly, with little public explanation, and in a moment during which people are already deeply skeptical of how companies deploy artificial intelligence (AI)—especially when it operates in physical spaces.
“When you don’t have clear standards or consistent regulation, organizations end up making their own rules. And that’s where risk creeps in.”Melissa Bischoping, senior director of security and product design research, Tanium
For organizations watching this unfold, the Wegmans episode underscores the risks of public-facing AI: Trust is fragile, governance gaps are costly, and scrutiny often intensifies only after the systems are already live, notes Melissa Bischoping, senior director of security and product design research at Tanium, an innovator in cybersecurity solutions and autonomous IT (and publisher of this magazine).
“When you don’t have clear standards or consistent regulation, organizations end up making their own rules,” Bischoping says. “And that’s where risk creeps in.”
AI governance and the trust tradeoff of high-friction AI
When organizations deploy AI that directly affects people in physical spaces—whether in grocery stores, airports, or city streets—they are reshaping how customers experience the brand.
“Customers cannot reset their face or their voice if something goes wrong, so the company is taking on a permanent liability for what is often a temporary problem.”Dr. Saiph Savage, assistant professor and director of Northeastern University’s Civic AI Lab
Dr. Saiph Savage, an assistant professor at Northeastern University who studies human-centered AI, says organizations often underestimate how surveillance-oriented technologies can clash with expectations of hospitality or service. “You have to ask how much you want to change the customer’s relationship with the brand just to optimize an operational metric,” she says.
That tension becomes especially pronounced when the perceived benefit is narrow—such as reducing shoplifting—while the perceived intrusion affects everyone who walks in through the door, she says. In the Wegmans case, critics questioned whether the company had clearly articulated why biometric data collection was necessary at all, let alone worth the reputational fallout.
[Read also: The new biometrics dilemma—will they make us safe or sorry?]
Savage, who directs Northeastern’s Civic AI Lab, frames this as a proportionality problem. Collecting immutable personal identifiers to address a long-standing retail challenge forces executives to confront uncomfortable tradeoffs. “Biometric data is an unchangeable asset,” she says. “Customers cannot reset their face or their voice if something goes wrong, so the company is taking on a permanent liability for what is often a temporary problem.”
Permanent data, long-term liability
From a cybersecurity standpoint, biometric data fundamentally alters an organization’s risk profile. Unlike payment card numbers or passwords, biometric identifiers cannot be rotated after a breach. Once exposed, they remain exposed.
“Very few people need access to the raw data. The fewer people who can see it, the smaller the blast radius if something goes wrong.”Bischoping
Biometric data also occupies a complex regulatory gray area in the United States. Privacy protections vary by state, and there is no comprehensive federal standard governing how biometric information must be handled. For organizations that operate across jurisdictions, that lack of uniformity introduces compliance challenges before security risks are even considered.
“There’s a lot of wiggle room in how companies describe what they’re doing with biometric data,” Bischoping says.
That wiggle room constricts when things go wrong. In the event of a breach, the consequences extend beyond immediate financial loss. Bischoping points out that biometric data that appears anonymized at first can become dangerous when combined with other breached datasets over time. “You start to see patterns of behavior—where people shop, where they work, where they live,” she says, noting that such exposure can be especially harmful for individuals facing stalking or domestic violence risks. “Brand damage is not to be understated. If customers don’t feel safe, they will stop showing up.”
[Read also: Brands and board reputation—7 cyber steps to boost investor and consumer confidence]
Rather than focusing only on near-term return, Savage urges executives to consider the full lifecycle of risk. “Is reducing shoplifting over five years worth a 50-year liability if biometric data is breached?” she asks, arguing that long-term exposure often outweighs short-term operational gains.
AI governance before AI deployment—not after
One of the clearest lessons from the Wegmans episode is that governance cannot be an afterthought, Savage says. Organizations often deploy AI systems—particularly those involving biometric data—before they have fully defined acceptable use, accountability, or exit criteria.
“Once biometric data is out there, there’s no undo button.”Rachel Barnhart, Monroe County (NY) legislator, D-Rochester
Savage emphasizes that safeguards are not just about protecting data. “They’re about defining the boundaries where the technology is no longer permitted to operate,” she says, pointing to the need for clear thresholds around error rates, bias, and false positives.
Governance must also extend to infrastructure and access controls. Bischoping says biometric data does not need to be broadly available to be operationally useful. “Very few people need access to the raw data,” she says. “The fewer people who can see it, the smaller the blast radius if something goes wrong.”
Third parties and patchwork legislation—surprise tripwires for AI governance
Retention policies are equally critical. Vague language about keeping data “as long as necessary” leaves too much room for sensitive information to linger indefinitely, Bischoping adds. “That’s how data gets forgotten—and forgotten data becomes a treasure trove in a future breach.”
Given the privacy and regulatory risks associated with the use of biometric technology, experts advise that any smart governance framework should also include enhanced compliance management. Increased visibility into personal data can lead to compliance issues and privacy concerns if not managed under strict frameworks, and these risks are only bound to increase as public discomfort with AI puts pressure on lawmakers of various jurisdictions to act, resulting in a patchwork of legislation.
Third-party vendors add another layer of risk. If biometric data is processed or stored externally, organizations must understand where that data lives, who can access it, and what happens if the vendor’s business changes. Those scenarios are far easier to manage when governance frameworks anticipate them, rather than reacting after trust has already been lost, Bischoping says.
Organizations have to assume that whatever data they collect today will exist longer than they expect, Bischoping says.
“Companies can experiment with this technology, but they don’t personally absorb the consequences if it fails,” Barnhart adds. “Consumers do. And once biometric data is out there, there’s no undo button.”
