Retail shrinkage covers everything from admin error to supplier fraud, but the part that keeps store managers up at night is theft, particularly the repeat offenders who move between stores confident that nobody will recognise them. Traditional security struggles with exactly that pattern. Facial recognition is built to close the gap. It also sits under more regulatory scrutiny than any other use of the technology in Australia, so it pays to understand both halves of the picture before you deploy anything.
Why traditional security falls short
CCTV records, but it doesn't recognise. Guards and staff can't be everywhere, can't remember every face and turn over often. By the time footage is reviewed, the stock and the person are long gone. The result is a system that documents loss after the fact rather than preventing it, which does little to deter the organised, repeat offenders who cause the most damage.
What AI loss prevention actually does
AI loss prevention needs a camera that can actually see faces at the point people come in. Whether that means using something you already have or adding one comes down to the quality and placement of your existing cameras, which is a quick thing to check. Either way it is a small, targeted setup rather than a replacement for your CCTV. When a person your store has added to its watchlist enters, the system quietly alerts staff so they can be present, attentive and visible. Presence is the point. A staff member who appears at the right moment prevents far more loss than any after-the-fact report.
It also helps the other way around. By flagging only the small number of genuine matches, it lets staff focus their attention where it matters instead of treating every customer with suspicion.
Deterrence beats recovery
The cheapest stolen item is the one that never leaves the shelf.
The real value isn't catching people after the fact. It is deterrence. When repeat offenders know a store can recognise them, they move on. When staff are prompted to engage early and visibly, opportunistic theft drops. The goal is a calmer, safer store, not a bigger evidence file.
Doing it without creating a privacy problem
Recognition in a retail setting raises a fair question: what about everyone else who walks in? A responsible system answers it in its design. If a person isn't on your watchlist, their biometric data is discarded on the spot. They are not identified and no profile is built. The only biometric information the system keeps belongs to people your store has put on the list. Detection runs in-store and data stays in Australia under strict access controls. The aim is narrow and specific: deter repeat offenders, leave ordinary shoppers alone.
What Australian law actually requires
This is the part most vendors skip. A recent ruling confirmed that facial recognition for loss prevention can be lawful in Australia without asking every shopper for consent, where the purpose is preventing crime and protecting staff from violence.
What has tripped retailers up is everything around that: not documenting a proper privacy assessment before switching on, then not telling customers clearly enough that the technology is in use. Updated OAIC guidance expects each deployment to be assessed on its own facts. The short version: the technology isn't the problem. Deploying it without documented assessment and clear notice is. Those are both solvable before you switch anything on.
Who goes on the watchlist
This is the first question a careful retailer asks. It is also the one regulators looked hardest at. In Ottica, you set the rules. Your team decides what puts someone on the list, records a reason against every entry, sets how long that entry lasts and reviews it on your own schedule. The system enforces what you configure, including removing entries when they lapse rather than letting a list grow forever.
Our advice is to write that policy down before you add a single person, because a watchlist with a documented reason, a defined duration and a review process is a defensible one. An open-ended list of people someone thought looked suspicious is not. Getting that right is the difference between a defensible deployment and a regulatory problem.
Built for Australian retail
Ottica's facial recognition is built and maintained in-house in Australia and already runs across hundreds of gaming venues, an environment where privacy obligations, signage rules and record-keeping are written into a government code of practice. That is the same engineering, plus the same discipline, applied to a retail floor. Loss prevention only works long term if it is something you can stand behind with customers, staff and regulators alike.
If shrinkage is hurting your margins and you want to see what defensible loss prevention looks like in practice, we're happy to show you.
Current as at August 2026. This article is general information, not legal advice. Get your own advice before deploying facial recognition in a retail setting.
Sources
OAIC — Facial recognition technology in retail settings. OAIC — Updated guidance on facial recognition in retail spaces (July 2026). OAIC — Privacy Commissioner statement on the Administrative Review Tribunal decision.