What problem does it solve?
A guard cannot watch a hundred camera feeds at once, and a metal detector at a school or stadium entrance forces a line, a bag check and a pat down that slows everyone down. School board members weighing that tradeoff have raised concerns about how the process makes students feel, particularly students of color. When something does go wrong, an investigator is left scrubbing hours of footage camera by camera to find the moment that matters.
Two kinds of AI have moved into this gap. Walk through scanners use sensor data, not just video, to flag a likely weapon shape without a full stop and search. Video platforms let an investigator search recorded footage by what something looked like, a logo, a bag, a colour of clothing, instead of by camera and timestamp. Both promise faster response and faster investigation, and both are the subject of real, public disputes about how well they actually work, which is why every claim on this page carries its source.
How does it work?
- Watch continuously, or index for search. Cameras or walk through sensors feed the model either live, to flag something as it happens, or continuously, to make the footage searchable by content afterwards.
- Score against known patterns. A weapon shaped object, a restricted area entry, or a described attribute such as clothing or a logo is matched or scored by the model.
- Raise an alert or a hit, never a verdict. A weapon scanner highlights where on a person's body it thinks an object is; a search tool returns a list of matching clips.
- A human verifies before anything happens. A guard checks the highlighted area or reviews the clip before anyone is stopped, searched or reported to the police.
- Feed outcomes back. Confirmed hits, false alarms and any miss found another way are logged, so the team can see whether the alert is actually earning the attention it demands.
- Audience
- Employee facing
- Autonomy
- Assist
- Adoption
- Early adopters
- Channels
- Internal tools, Microsoft Teams, API and system to system
What is it worth?
Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.
No public deployment has disclosed a measurable outcome yet.
Value drivers: Risk and loss reduction, Lower cost to serve, Speed and cycle time.
Indicative value
A retail chain with 20 stores, each running one to three loss prevention investigations a week
USD 6500 to USD 99,840
Annual loss prevention investigation time cost avoided per year
How this is calculated
Formula: stores * investigationsPerStoreWeek * 52 * hoursPerInvestigationBefore * timeSavedShare * costPerHour. The low scenario uses every low input, the high scenario every high input.
| Input | Low | High | Basis |
|---|---|---|---|
| Stores stores, stores | 20 | 20 | The reference chain. |
| Loss prevention investigations per store per week investigationsPerStoreWeek, investigations per store per week | 1 | 3 | Editorial assumption, replace with your own case volume. |
| Investigation time without content based search hoursPerInvestigationBefore, hours per investigation | 0.5 | 1 | Harry Rosen's loss prevention team describes a search without the tool as taking easily an hour with no guarantee of finding the footage; used here as an upper baseline. Source |
| Share of investigation time saved timeSavedShare, fraction of investigation time | 0.5 | 0.8 | Conservative against Verkada's Harry Rosen case study, which reports minutes instead of hours. Source |
| Fully loaded cost of a loss prevention analyst costPerHour, USD per hour | 25 | 40 | Editorial assumption, replace with your own fully loaded cost. |
What it leaves out: Investigation time only. It leaves out the value of any loss actually prevented, the cost of the camera or sensor platform itself, and any extra staff time spent on false alarms.
Who already uses it?
3 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.
Harry Rosen
Canada · Retail and ecommerce · 2024
Harry Rosen is a Canadian luxury menswear retailer with 19 stores. Its loss prevention team replaced a fragmented set of camera, access control and alarm systems from different vendors with Verkada's cloud platform, then adopted Verkada's AI powered search to look up footage by what a suspect was wearing or carrying, such as a logo on a hat or a specific bag, instead of scrubbing through recordings camera by camera and hour by hour.
No outcome disclosed.
Charlotte-Mecklenburg Schools
United States · Education · 2023
Charlotte-Mecklenburg Schools, a North Carolina district, installed Evolv walk through weapons scanners. District officials told Louisville Public Media that the number of guns found on campus fell from 30 in the 2021 to 2022 school year to three in the 2022 to 2023 school year. The same reporting quotes a district spokesperson saying only one of those three guns was actually caught by the Evolv scanner; the other two were found before anyone tried to bring them into a building. The drop in guns found is therefore the district's own account of the deployment as a whole, not a confirmed detection rate for the scanner by itself.
No outcome disclosed.
Utica City School District
United States · Education · 2023
Utica City Schools in upstate New York spent 3.7 million USD on an Evolv weapons detection system. The district's acting superintendent told Louisville Public Media that the district shelved the system after it failed to detect a knife that was used in a stabbing at a district school, and that the system also missed a state trooper's service weapon twice when the trooper went through the sensor with the weapon on his hip. Utica City Schools then spent 250,000 USD on metal detectors and bag X-ray machines, while continuing to pay off the Evolv contract.
No outcome disclosed.
How do you implement it?
A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.
Data you need
- Camera or sensor coverage of the areas being screened, with clear sightlines
- A written escalation and secondary screening procedure for every alert type
- Historical incident and false alarm data to tune alert thresholds
Systems to integrate
- Video management system or walk through sensor platform
- Access control system for door and badge events
- Incident and case management system for investigations
- Alerting into the guard station or the security team's own communication channel
Complexity: Medium
The detection model, whether a walk through sensor or camera based search, is bought from a specialist vendor. The work for the security team is camera or sensor placement, wiring alerts into how guards already work, and writing a secondary screening procedure that holds up when the alert turns out to be a laptop rather than a weapon.
- 1
Pilot on the highest risk entry points or aisles first
Start where the volume of people and the risk are both high enough to learn quickly, rather than rolling out to every site before the false alarm rate is known.
- 2
Write the secondary screening procedure before go live
Decide who checks an alert, how, and with what training, before the first alert fires. A chromebook or a water bottle will set off a weapon scanner; know in advance how staff are meant to tell it apart from the real thing.
- 3
Set a false alarm budget you can live with
Track how often staff develop workarounds, such as holding common items away from the body so they do not trigger an alarm, because the same workaround can also hide a real weapon.
- 4
Ask for independently tested numbers, not only the vendor's own benchmark
A vendor funded, vendor scoped accuracy report is not the same as an independent test. Treat the vendor's own figures as a floor, and look for third party testing before a large rollout.
- 5
Review alert quality on a schedule, not only after an incident
Sample confirmed hits and false alarms every month so the threshold gets tuned from ongoing data, not only relearned after something goes wrong.
Guardrails
- A flagged weapon, intrusion or theft alert always goes to a trained human for secondary screening before any action is taken on a person
- Every alert is logged with the frame or clip, the model's confidence and the human's verdict
- Staff who conduct secondary screening are trained specifically for that role, not assigned informally on the day
- Facial recognition or identity matching, if used at all, is a separate, explicitly approved capability, not a default of detection or search
KPIs to instrument
- Investigation time per case, before and after
- Confirmed detections against false alarms, by alert type
- Incidents found by the system against incidents found another way, such as a self report
- Staff hours spent on secondary screening
Human in the loop
A guard or investigator verifies every alert before anyone is stopped, searched or reported. The security team owns the false alarm rate and keeps it low enough that staff keep taking every alert seriously, and reviews it again whenever the vendor changes the underlying model.
Common failure modes
- A missed detection with a real weapon
- Utica City Schools shelved its walk through system after it failed to detect a knife used in a stabbing, and separately missed a state trooper's service weapon twice when he went through the sensor with it on his hip. Treat any miss as an incident with a root cause review, and know which object types the technology is weak on before relying on it as the only layer.
- Alert fatigue from common false alarms
- Reporting on Evolv's school deployments describes chromebooks, water bottles, umbrellas and binders setting off alerts. Staff workarounds, such as holding an item away from the body, can also hide a real weapon; measure and disclose the false alarm rate rather than letting an informal workaround become policy.
- Marketing claims outrun independent testing
- Investigative reporting found that a vendor's own "independent" accuracy report was self funded, with the vendor choosing the scoring criteria and editing findings out across multiple drafts, including a finding that the system detected only about half of knives. Ask any vendor for a genuinely independent, unedited test result.
What are the risks and rules?
EU AI Act
Depends on design
Screening for a weapon shape, or searching footage by a described attribute such as clothing, is not itself the remote biometric identification or categorisation of a natural person, as long as it flags an object or an attribute rather than matching or categorising an individual. It becomes high risk under Annex III point 1(a) if the system performs remote biometric identification, whether real time or after the fact and in any setting, for example matching faces against a watchlist, and under Annex III point 1(b) if it performs biometric categorisation. It is high risk under Annex III point 6 if used by or on behalf of law enforcement for profiling a natural person. Real time remote biometric identification by or on behalf of law enforcement in a publicly accessible space is prohibited outright under Article 5(1)(h), subject only to its narrow, listed exceptions.
Controls to put in place
- Independent testing of detection accuracy before a large rollout, not only the vendor's own benchmark
- A written, trained secondary screening procedure with defined roles
- Logged alert and outcome history, reviewed on a schedule and after every miss
- No facial recognition or watchlist matching without its own separate legal basis and impact assessment
When it went wrong elsewhere
- FTC complaint and proposed settlement with Evolv Technologies over weapons detection accuracy claims. The FTC alleged Evolv had overstated its screening system's ability to detect all weapons and ignore harmless items. Under the proposed, stipulated settlement order, Evolv would be required to stop the unsupported claims and let certain K-12 school customers cancel their contracts.
- Incident 349: Evolv AI weapons detection system allegedly misrepresents accuracy, leading to school security gaps. Independent record in the AI Incident Database of the reported gap between marketed and real world detection accuracy in schools.
Frequently asked questions
- Can AI reliably detect weapons on a camera or a walk through scanner?
- Not on its own, and not without a trained human checking every alert. The FTC alleged that one major vendor's system missed weapons in schools while flagging harmless items, and a New York district shelved the same technology after it failed to detect a knife used in a stabbing. Treat the technology as one layer that raises alerts for a person to verify, not as a replacement for that person.
- What is AI powered video search, and how is it different from weapons detection?
- Weapons detection screens people as they walk through, looking for an object's shape or signature. Video search, such as the tool Harry Rosen uses, works on recorded footage after the fact, letting an investigator search by a described attribute like clothing or a bag instead of scrubbing through camera by camera. They solve different problems and usually come from different vendors.
- Does this kind of system use facial recognition?
- Not by default. The deployments on this page describe object detection and attribute based search, not matching a person's face to an identity. Facial recognition or watchlist matching is a separate, higher risk capability that needs its own legal basis and impact assessment.
- How much can AI video search reduce investigation time?
- Verkada's own case study on Harry Rosen reports that investigations now take minutes instead of hours. Harry Rosen's director of loss prevention, in his own words, says a search without the tool "would have taken easily an hour" with no guarantee of finding the footage. That is a vendor case study naming one customer, so treat it as an indication rather than a guaranteed result for any other site.
How to cite this page
Blits.ai AI Use Case Library, "AI video analytics and screening for physical security", last verified 29 September 2026, https://www.blits.ai/ai-use-cases/physical-security-video-analytics. Licensed under CC BY 4.0. Method: how we verify use cases.
Changelog
- 29 September 2026: First published