In a significant legal development that could reshape how technology companies are held accountable for their products in the criminal justice system, Amazon Web Services has been added as a defendant in a federal lawsuit filed by a St. Louis man who spent seventeen agonizing months behind bars based on a flawed facial recognition match. The case centers on Christopher Gatlin, who alleges that his arrest and subsequent prosecution were the direct result of a cascade of failures: shoddy police work, inadequate training for officers, and a defective facial recognition system developed by Amazon. The amended complaint, filed last Thursday, specifically identifies Amazon Rekognition as the technology that generated the lead which ultimately put Gatlin in handcuffs, marking a dramatic expansion of a case that previously focused only on how local police misused the technology after it identified him as a possible match. This new filing raises fundamental questions about whether the tech industry bears legal responsibility when its tools, marketed for public safety purposes, contribute to miscarriages of justice.
The story of how Gatlin came to be caught in the machinery of the justice system begins with a violent crime that left a victim with no memory of his attackers. On December 7, 2020, a MetroLink security guard was brutally assaulted at a station in north St. Louis County, suffering a traumatic brain injury that left him unable to remember the men who had attacked him, despite repeated attempts by police to jog his memory. Detectives turned to surveillance footage, which captured the attack on video, and one investigator eventually extracted an image of one suspect to submit to the St. Louis Mugshot Recognition Technology system. The problems with this approach were evident from the start. The image itself was, according to the federal court record, grainy, blurry, and taken from a distance, with the camera positioned above the suspect’s face. The man in the image wore a hood that covered part of his forehead, and a medical mask obscured the lower portion of his face, leaving barely enough visible features for a human to identify anyone, let alone a machine designed to match faces against a database of more than 250,000 mugshots. Prior to this facial recognition search, investigators had absolutely no information pointing to Gatlin as a suspect. He was not known to them, had no connection to the crime, and no independent evidence linked him to the assault. The algorithm alone generated his name, and from that moment, Gatlin’s life began to unravel.
What happened next illustrates a disturbing pattern in how police departments across the country have come to rely on facial recognition technology. Rather than treating the algorithmic match as a weak lead requiring substantial corroboration, investigators treated it as a solid identification and built their case around it. The most troubling step came in August 2021, when police presented Gatlin’s photograph to the assault victim as part of a six-person lineup. The victim, who had consistently and repeatedly stated that his memory of the attack was poor, was shown the photos while officers held a photo of Gatlin from the facial recognition match. Body camera footage later revealed what actually happened during that lineup, and it painted a damning picture of police procedure. The victim initially leaned toward another man in the lineup, then wavered between that man and Gatlin. At that critical moment of uncertainty, an officer encouraged him to consider specific characteristics like complexion and clothing, effectively steering the witness toward the man the algorithm had identified. The victim eventually selected Gatlin, and that identification became the primary evidence used to pursue charges against him. The lineup, as it turned out, had been constructed entirely around the facial recognition result, meaning the algorithm was essentially confirming its own finding through a process that appeared to corroborate it but actually just recycled the same flawed lead.
Gatlin was arrested on August 14, 2021, but his ordeal was far from over. Unable to afford the seventy-five thousand dollar cash bond set by the court, he was remanded to jail, where he would remain for approximately seventeen months while his case slowly moved through the system. The criminal charges against him continued to hang over his head until March 2024, meaning Gatlin spent nearly two years of his life incarcerated and then face the ongoing threat of prosecution for a crime he did not commit. The case only began to crumble when his defense attorneys obtained the body camera footage of the photo lineup, the same footage that would ultimately reveal how deeply flawed the identification process had been. At a February 2024 hearing, St. Louis County Circuit Judge Brian May suppressed the witness identification, ruling that officers had departed from accepted procedures for conducting an impartial lineup. The judge’s finding was clear: the officers had not followed proper protocol, and the identification could not be used as evidence. With the identification thrown out and no other substantial evidence linking Gatlin to the crime, prosecutors were forced to dismiss all charges the following month. But by then, Gatlin had already lost seventeen months of his life, months that no verdict or settlement could ever fully restore. Instead of celebrating his exoneration, he filed a lawsuit in January 2025 against the officers involved, the city of St. Louis, and St. Louis County, alleging constitutional violations and various state law claims arising from his arrest and prosecution.
The lawsuit has already survived its first major legal challenge, which suggests that the courts are taking his allegations seriously. In October 2025, U.S. Magistrate Judge Abbie Crites-Leoni declined to dismiss most of the claims challenged by the city and St. Louis police officer Matthew Welle, though the ruling did not establish that the defendants were actually liable. At this stage of litigation, the court was required to accept Gatlin’s properly pleaded factual allegations as true, so the ruling does not prove that misconduct occurred, but it does mean that his case has enough merit to proceed to the next phase. Judge Crites-Leoni found that Gatlin had plausibly alleged a reckless investigation and malicious prosecution, among other claims, and crucially, she allowed a municipal failure to train claim over facial recognition to proceed. That ruling is significant because it recognizes that officers were given access to facial recognition technology without adequate training, despite the well-documented danger of misidentification. The court essentially agreed that Gatlin’s allegations, if proven, would establish that the police department failed in its duty to ensure that officers understood both how to use the technology and its limitations. But while this legal roadmap was being established, the case against the local officials was only half the story. The new filing now seeks to extend liability upstream to Amazon itself, arguing that the company’s technology was defective and that AWS bears some responsibility for what happened to Gatlin as a result.
Amazon’s own documentation for Rekognition paints a picture of a product with known limitations that may not align with how it was actually used by police in this case. Current AWS guidelines state that the face-matching technology does not support images that are too blurry or grainy for a human to recognize a face, nor does it support images where large portions of a face are obscured. The technical guidance explicitly recommends sharp images with visible faces and warns against masks or other objects that block facial features. Yet the image that investigators submitted in Gatlin’s case contained several of these exact problematic conditions: it was grainy and blurry, taken from above, and the suspect’s face was partially hidden by a hood and a medical mask. These are precisely the conditions under which facial recognition is known to fail, and yet the system returned Gatlin as a possible match. Amazon’s service terms also describe Rekognition matches as predictions about the likelihood that the same person appears in two images, rather than definitive identifications, a distinction that has become central to the broader debate about police use of the technology. The company’s law enforcement guidance further states that facial comparison results should be considered alongside other compelling evidence and should not be the sole basis for action affecting a person’s civil liberties. The lawsuit now asks whether Amazon should be held liable if its product, despite these disclaimers, still leads to the kind of chain of events that sent Gatlin to jail for seventeen months.
The broader context of Gatlin’s case extends far beyond one man’s wrongful incarceration. A Washington Post investigation published in January 2025 examined detailed facial recognition records from twenty-three police departments and found that fifteen of them had arrested at least one artificial intelligence-identified suspect without obtaining independent evidence connecting that person to the crime, often in direct violation of their own policies. At the time of that investigation, the Post had identified at least eight Americans who had been wrongfully arrested following facial recognition searches. Gatlin’s case illustrates a particularly insidious danger of this technology: once software puts a specific face in front of investigators, subsequent investigative steps can reinforce the machine-generated lead rather than independently test it. A suspect generated by facial recognition can be placed into a photo lineup, and a witness’s selection of that person can then appear to corroborate the original algorithmic result, even though the lineup itself was created because of that result. It becomes a self-fulfilling prophecy where the technology is used to confirm its own questionable conclusion. This is essentially the chain of events Gatlin alleges occurred in St. Louis, and the court has already found his allegations sufficient for most of his claims to proceed. By adding Amazon to the case, the amended complaint now asks another fundamental question: whether the technology company that created and sold this facial recognition system should also bear legal responsibility for its role in a process that ultimately sent an innocent man to jail. The answer to that question could have profound implications not just for Amazon, but for every technology company that sells tools to law enforcement agencies across the country.

