Buyer's guideRetail
AI loss prevention in retail: a buyer's guide
AI loss prevention tools differ less in their models than in what they detect, what evidence they produce and what happens after an alert. Before comparing vendors, decide which shrink source you are attacking, how staff will respond safely, and what privacy law allows in each market, especially for anything biometric. Then run a controlled pilot on stores with accurate inventory, so any reduction in shrink can be attributed to the tool rather than to chance.
On this page
- What you are actually buying when you buy loss prevention AI
- Four AI loss prevention approaches compared
- Questions to put to any loss prevention vendor
- Privacy and biometric rules that shape store deployments
- Running a pilot that measures shrink honestly
- Where to start, by shrink profile
- Scoring two shortlisted approaches
- Questions and answers
- Sources
What you are actually buying when you buy loss prevention AI
Shrink has four broad sources: external theft (from opportunistic shoplifting to organized retail crime), internal theft and sweethearting by staff, process and administrative error (mis-scans, wrong receipts, unrecorded waste and markdowns) and vendor fraud or short delivery. A camera at self-checkout does nothing about a supplier who delivers short, and a POS exception report will not stop a sweep of a cosmetics fixture.
So the purchase is really three things: a detection method aimed at a specific source, an evidence trail that a manager or investigator can trust, and an intervention workflow that keeps staff safe and customers treated fairly. Vendors tend to sell the first. Most of the cost and risk sit in the second and third.
ColdAI's retail work includes camera and sensor-based detection of out-of-stocks, planogram compliance and shrinkage8; the guide below is written so it can be used to assess any provider, including us.
Four AI loss prevention approaches compared
Each approach addresses different shrink sources and carries a different privacy and staffing load.
| Criterion | POS exception analytics | Self-checkout vision | Shelf sweep detection | ORC link analysis |
|---|---|---|---|---|
| Main shrink source addressed | Staff fraud, refund abuse, process error | Non-scans, item switching at self-checkout | Bulk theft from high-value fixtures | Repeat offenders and networks across stores |
| Data needed | Transaction logs, voids, refunds, discounts | Overhead video synchronized with scan events | Shelf-facing video or shelf weight sensors | Incident reports, case files, transaction patterns |
| Evidence produced | Patterns over many transactions | Clip of the moment plus the receipt line | Clip and time of the event | Linked cases for investigators and police |
| False-positive exposure | Low impact; reviewed offline | High; shoppers are challenged in the moment | Medium; restocking can look like sweeping | Medium; wrong links can taint a person |
| Privacy weight | Employee monitoring rules | Customer video; biometric if faces are matched | Customer video in aisles | Personal data on suspects; strict access |
| Store labor on alerts | Investigator time, not floor staff | Attendant intervention at the lane | Floor response to live alerts | Central team; little store time |
Characteristics are typical of each approach, not of any named product. Many retailers combine two, usually POS analytics with one camera-based method.
Questions to put to any loss prevention vendor
Privacy and biometric rules that shape store deployments
General Data Protection Regulation (EU) 2016/679, with the UK GDPR[^1]
EU and UKApplies whenCameras or analytics process personal data of shoppers or staff1.
ICO Opinion on the use of live facial recognition technology in public places[^2]
UKApplies whenA controller uses live facial recognition in places open to the public, including stores2.
- The controller must complete a DPIA before deployment and show the processing is fair, necessary and proportionate2.
- The ICO accepted in a later case that crime prevention is a legitimate interest for retail facial recognition, while finding the original deployment fell short on fairness and lawfulness3.
Illinois Biometric Information Privacy Act (740 ILCS 14)[^4]
US (Illinois)Applies whenA private entity collects biometric identifiers such as face geometry from people in Illinois4.
EU AI Act, Regulation (EU) 2024/1689[^5]
EUApplies whenA retailer deploys an AI system in the EU, especially one using biometrics5.
- The prohibition on real-time remote biometric identification in public spaces covers law enforcement use; a retailer's own remote biometric identification system is classed as high-risk under Annex III5.
- Emotion recognition of employees in the workplace is prohibited except for medical or safety reasons5.
- Annex III application dates were amended by Regulation (EU) 2026/1744, so check the consolidated text for the date that applies6.
Running a pilot that measures shrink honestly
Fix inventory accuracy in pilot and control stores
Run full counts and correct item records before the pilot. Shrink is measured as a difference between book and physical stock, so inaccurate records swamp any effect.
Choose matched control stores
Pair each pilot store with a similar store by format, sales, shrink history and local crime levels, and keep the controls untouched.
Define the measurement window and categories
Agree in advance which categories count, how long the pilot runs and how counts are timed. Short windows and seasonal swings produce false wins.
Measure the workflow, not only the model
Record alerts, alert precision, interventions, customer complaints and staff incidents alongside shrink.
Compare change, not level
Compare the change in shrink in pilot stores with the change in controls over the same period, by category.
Decide with the full cost in view
Set the estimated reduction against hardware, licenses, labeling, monitoring and store labor before scaling.
Where to start, by shrink profile
- If
Refunds, voids and discount abuse dominate your known losses.
ThenStart with POS exception analytics on data you already hold.
It needs no new hardware, carries the lightest customer privacy load and is reviewed offline by investigators.
- If
Losses concentrate at self-checkout.
ThenPilot scan-event vision on a few lanes with attendant-led, non-accusatory prompts.
Prompting a shopper to rescan corrects many genuine mistakes without any accusation.
- If
High-value fixtures suffer repeat sweeps, often across several stores.
ThenCombine fixture-level detection with central case linking for organized retail crime.
Store response alone rarely deters organized groups; linked cases support action by police and prosecutors.
- If
Unknown loss is large but nobody can say where it arises.
ThenInvest in inventory accuracy and loss attribution before buying any detection tool.
Without attribution you cannot pick a tool or prove that it worked.
Scoring two shortlisted approaches
Questions and answers
Is facial recognition legal in retail stores?
It depends on the jurisdiction and how it is used, and in many places it is high-risk. In the EU and UK, matching faces against a watchlist processes special-category biometric data, needs a specific legal condition and a DPIA, and regulators expect strict necessity and proportionality. In Illinois, BIPA requires written notice and a written release before collection. Take legal advice market by market.
How should we measure the ROI of a shrink reduction tool?
Compare the change in shrink in pilot stores with the change in matched control stores over the same window, by category, after correcting inventory records. Put the estimated reduction against full costs: hardware, licenses, video storage, labeling, monitoring staff and store labor spent on alerts. Include softer costs too, such as complaints and incidents from wrong interventions.
What should store staff see when an AI flags a possible theft?
Only what they need to act safely: what happened, where and a suggested non-accusatory response such as offering help or a rescan. Detailed evidence and any personal data should go to trained investigators. Staff should never be asked to physically intervene on the strength of an alert, and policies should say how a wrong alert is recorded and corrected.
Can a retailer use video analytics without identifying anyone?
Yes, many approaches do. Scan-event vision and sweep detection can work on actions and objects without facial matching, and some systems process video on store devices and keep only flagged clips. That lowers, but does not remove, data protection duties, because the video itself is still personal data where people are identifiable.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Information Commissioner's Opinion: The use of live facial recognition technology in public places — Information Commissioner's Office · checked 10 October 2026
- ICO outcome letter to Facewatch Limited — Information Commissioner's Office · checked 10 October 2026
- Biometric Information Privacy Act (740 ILCS 14) — Illinois General Assembly · checked 10 October 2026
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2026/1744 amending the Artificial Intelligence Act (Digital Omnibus on AI) — EUR-Lex · checked 10 October 2026
- Rite Aid Corporation, FTC v. (case page) — Federal Trade Commission · checked 10 October 2026
- Retail: computer vision inventory and shrinkage use cases — ColdAI