On August 2, 2020, Brittney Gilliam drove her sister, her 6-year-old daughter, and two nieces to get their nails done in Aurora, Colorado.
The salon was closed. She sat in the car park, looking up another salon.
That’s when the police surrounded the car.
Guns drawn, officers ordered everyone out and onto the pavement. It was 87 degrees that afternoon. Gilliam, her sister, and her 12-year-old niece were handcuffed. The cuffs didn’t fit her 6-year-old daughter, so officers had her lie face-down with her hands raised instead.
They held the family there for nearly two hours.
A license plate reader (ALPR) had flagged Gilliam’s SUV as a stolen vehicle. The plate numbers matched.
And therein lay the problem.
The stolen vehicle was actually a motorcycle. Registered in Montana. Gilliam’s SUV (and plates) were in Colorado.
The measurement was never the problem
The license plate reader did exactly what it was built to do. It read the plate correctly, character for character, and matched it against a police “hot list.”
That is purely a measurement question, and the system got it right.
But what it could not do, something it was never asked to do, was confirm that the vehicle attached to that plate was the vehicle being searched for. A Colorado SUV and a Montana motorcycle sharing a string of digits is not evidence of anything. It is a coincidence a five-second glance from a human would have caught.
Aurora’s own written policy says as much: no action gets taken on ALPR data alone. An officer has to confirm it first.
That is not a measurement problem. It is an authority problem, and one that only existed on paper.
The gap the policy didn’t close
The question that never went answered before this unfortunate incident was: Confirm what, exactly?
“Confirming” the plate number is trivial, that had already been done by the machine. But confirming the vehicle, its make, model, color, state, is a quite different, slower, more deliberate check ..
And it’s the one that would have stopped this distressing incident from ever happening.
Nothing in the record suggests anyone made that distinction explicit. So officers did the only confirmation the system had made easy: they confirmed the digits matched, and treated that as enough to authorize a felony stop.
Critically: A measurement was allowed to stand in for a judgement nobody had actually made.
The consequences
The city settled Gilliam’s lawsuit for $1.9 million in 2024. This was the first case filed under a new Colorado law that stripped officers of qualified immunity; the legal shield that had made it difficult to hold officers personally accountable in court. The district attorney’s office cleared the officers of criminal charges but called what happened “disturbing.” The children, per the family’s attorney, spent years in weekly therapy afterward.
This wasn’t a one-off. This same failure – a plate match mistaken for a vehicle match, has cost San Francisco $495,000 and Oakland $49,500 in separate, unrelated ALPR cases.
Same mechanism. Different departments, different years, same missing step.
The three questions this needed, before that afternoon
What decisions needed making? Somebody needed to write down, in advance, every category of ALPR alert and ask: which of these can trigger action on the match alone, and which require a human to verify something the machine can’t see. This would include whether the vehicle itself, not just its plate, matches what’s being searched for.
Where does the system measure, and where does a human judge? Reading a plate is measurement. It has a right answer, and the system correctly found it. Whether that match is strong enough to justify guns drawn on a family is not measurement. This is a threshold call, and it is exactly the kind of call two reasonable officers, given the same alert, might handle differently.
Treating a plate match as sufficient on its own erased that judgement call entirely.
Who has the authority to act on that judgement, and can they actually use it? Aurora’s policy says a human must confirm before acting. But authority without a defined process is authority in name only. Nobody had specified what confirmation required. So officers confirmed the only thing left to confirm; the plate number, which had already been matched by the reader.
The moment of design
This is not a story about bad technology. The reader worked. This is a story about what happens when a system is trusted to answer a question it was never built to answer, because nobody drew the line between what it could confirm and what a person still had to.
Somewhere in your organisation, right now, a match is being treated as a decision. The honest question isn’t whether a human is technically in the loop. It’s whether anyone has ever specified, in writing, what that human is actually required to check before they act — and whether that specification exists anywhere outside a policy page nobody consulted on a hot Sunday afternoon in August.
Follow-Up
If you currently have an AI workflow in production or pilot, ask your team one question: “What is the system explicitly authorised to do below a certain confidence score?”
If you can’t find that answer in writing within 10 minutes, your boundary isn’t set.
If you’d like to stress-test that workflow before an edge case does it for you, let’s run a 30-minute boundary review: mattsheehan@spatialnext.io


