University of Kentucky Installs Facial Recognition Tech Around Campus, Sparking Privacy Debate

University of Kentucky’s Alcatraz AI face-scan pilot lacks published retention timelines, access controls, and independent performance data

Rex Edison Avatar
Rex Edison Avatar

By

AI facial scanner located in the vestibule of Woodland Glen IV on Sunday, Sept. 27, 2026, on Central Campus at Woodland Glen IV in Lexington, Ky. Photo by Thomas Gibbons | Kentucky Kernel.

Key Takeaways

Key Takeaways

  • Alcatraz AI converts facial scans into encrypted templates, deleting raw photos immediately after enrollment.
  • Demand UK publish retention schedules, deletion protocols, and independent performance reviews before expanding the pilot.
  • Keeping Wildcard access fully functional ensures “optional” biometric enrollment remains a genuine choice for students.

It’s late. You’re back at Woodland Glen IV, arms full, phone buried in your bag. Instead of fumbling for your Wildcard, you just look at the wall-mounted camera and the door opens. That’s the pitch for the University of Kentucky’s voluntary pilot of Alcatraz AI‘s Rock system. The question worth asking isn’t whether that’s convenient. It’s what happens to your face after enrollment, and whether the university has honest answers ready. The risks aren’t hypothetical , a surveillance app built to target specific populations shows how quickly biometric tools can be turned against the people they’re meant to serve.

The stakes here are higher than a forgotten key card. You can cancel a compromised card number. You cannot issue yourself a new face.

How the System Actually Works

Rock is facial authentication, not a crowd-scanning surveillance feed, and that distinction matters before judging what it does and doesn’t protect.

During enrollment, Rock captures a temporary facial image and converts it into an encrypted mathematical representation that Alcatraz AI calls a Facial Signature. The raw photo is deleted immediately after, and matching happens locally on the device itself. The template is tied to a badge number rather than your name, according to Alcatraz AI’s privacy materials.

Alcatraz AI CEO Tina D’Agostin told WKYT: “You’re zeros and ones to us once you’ve been scanned.” That’s a vendor assertion rather than an independently verified fact, but it does clarify what the system is designed to do. The system is not built to scan crowds, search external databases, or identify unknown people.

Rock also claims to detect tailgating: one authenticated scan shouldn’t let two people through the door. The company describes multi-person detection at the doorway as a core feature. Real-world effectiveness at UK specifically hasn’t been independently demonstrated, and no public performance data from the pilot has surfaced in the reviewed sources.

The Questions the University Hasn’t Answered

“Optional” is only meaningful if the university commits to keeping it that way, and three concrete gaps in the public record need closing before this pilot earns broader trust.

Start with retention. Alcatraz AI’s privacy policy defers the template retention period to the “solution owner,” which is the university. How long does UK keep your Facial Signature after you graduate, transfer, or unenroll from the pilot? The reviewed UK materials do not state a specific retention period or deletion deadline. Students deserve a concrete number, not a pointer to a vendor document.

Next, consider access. The template connects to a badge number, not a name, but the university’s own access-control infrastructure holds the bridge between that credential and your identity. Who inside UK can query that connection, under what circumstances, and with what oversight? The reviewed public materials don’t address that process in detail , a transparency failure that echoes broader patterns of secretly tracking users without adequate institutional accountability.

Then there’s the question of what “optional” actually guarantees. University documents reviewed by Kentucky.com under an open-records request state that the pilot “adds a strictly optional, hands-free access into building entrances and does not replace Wildcard ID or mobile ID access.” Hold that statement against a hypothetical future where card readers receive fewer maintenance dollars or slower response times. Optional has a way of quietly becoming the path of least resistance.

To UK’s credit, its public biometric-access page notes that students who aren’t recognized can still use their Wildcard ID or mobile ID. That fallback exists. What the reviewed materials don’t provide is a specific error-rate figure or a detailed escalation process for repeated failures, and those details matter for residents depending on the system at midnight.

What Comes Next

The accountability gap, not the technology itself, is what needs urgent attention before this pilot expands.

Biometric authentication is already familiar to many consumers; your phone’s Face ID works on the same general principle. The leap here is that the credential is tied to the door of your home rather than your personal device, which raises the stakes considerably. Communities facing similar expansions of institutional surveillance camera networks have pushed back hard when accountability structures failed to keep pace with the technology.

UK needs to publish four things: a retention schedule with a specific deletion timeline, a deletion protocol for departing students, an independent performance review of the pilot, and a written commitment that nonbiometric access will never be degraded. Publish those, and this pilot becomes a reasonable model for campus security. Without them, students are living inside an experiment whose full terms remain unclear.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →