Madison Square Garden appears to have done more than scan the faces of people walking through its doors: according to a report by 404 Media, the venue kept an internal document profiling the activists campaigning against its facial-recognition system. The file — reportedly titled "Facial Recognition Activists.docx" and stored in a folder called "Activists" — is said to name three well-known digital-rights campaigners, log their contact details and follower counts, and reproduce their critical tweets. It surfaced inside a large cache of MSG data that hackers stole and published online this month. MSG did not respond to 404 Media's request for comment. The honest bottom line: the same camera system sold as a security measure was, on this evidence, also used to keep tabs on its own critics.
This piece reflects reporting as of June 2026. The document's contents come from 404 Media's review of a stolen data cache rather than from records we could inspect independently; details of the breach itself are still being reported and may change.
What the leaked file is said to contain
404 Media reports that the document lists three people: Evan Greer of the digital-rights group Fight for the Future, Albert Fox Cahn of the Surveillance Technology Oversight Project, and Adam Schwartz of the Electronic Frontier Foundation. For each, the file is said to hold background information, contact details where available, social-media handles and follower counts, and quotes the person had made about MSG's facial-recognition programme. It reportedly includes screenshots of several of Greer's tweets — one of them posted, the document notes, sixteen hours before the screenshot was taken. The file is dated 23 December 2022 and was, per 404 Media, sitting in an MSG SharePoint instance, which suggests it was visible to staff beyond whoever wrote it. All of the above is 404 Media's account of a document inside the leaked cache; AIToolBible has not inspected the file itself.
All three named campaigners are public figures who have been quoted about MSG in major outlets. Greer told 404 Media the file showed why private companies should not be trusted with the technology: "Large companies can and will use surveillance tech to punish critics." (Greer's full statement, also issued via Fight for the Future, continues that such firms will "exploit workers, and consolidate power".)

Why this is bigger than one venue
Madison Square Garden has run facial recognition to identify people entering its venues since 2018. What makes it a recurring news story is how the system has been used. The venue has turned away lawyers whose firms were in litigation with MSG — even lawyers not personally involved in the case. In one widely reported instance, a mother was removed from a Rockettes show because of where she worked. A WIRED investigation this year reported that MSG's security operation went looking for these people, visiting the websites of more than ninety law firms and feeding photographs of roughly 1,200 lawyers into its software.
The activist dossier, if it is what 404 Media describes, extends that pattern from legal adversaries to public critics. That is the part worth sitting with. Facial recognition is often defended as a neutral safety tool — it spots a banned troublemaker, it speeds up entry. But a system that can match a face to a name at the door can equally match a face to a file: a record of what you have said, who you work for, and how many followers you have. The technology does not decide which of those uses it is put to. People do.
How biometric entry systems actually work
The mechanics are not mysterious. A camera captures faces in the entry queue and converts each one into a mathematical "faceprint". That faceprint is compared against a watchlist the venue controls. If there is a match, staff are alerted. The watchlist is the whole game: it is built and maintained by the operator, and nothing about the technology limits what goes on it. An exclusion list can hold known ticket-fraudsters — or, as the MSG reporting suggests, lawyers and campaigners the owner would rather keep out.
For anyone weighing up the AI tools sold to businesses, that is the general lesson. The accuracy of the model is rarely the real issue. The governance around it — who can add a name, what counts as a reason, whether anyone outside the company ever sees the list — is where the risk lives, and it is usually invisible from the outside.

The regulatory picture
Live facial recognition sits in very different legal places depending on where you are. In the United States there is no federal ban; a handful of cities and states restrict it, but a private venue in New York has had wide latitude, which is why the MSG case has run for years without being stopped. In the United Kingdom and the European Union the position is tighter: biometric data is "special category" data under the UK GDPR, and the EU's AI Act places real-time remote biometric identification in public spaces among its most heavily restricted uses. None of that makes the technology impossible to deploy — UK police have trialled live facial recognition repeatedly — but it raises the bar for a private operator wanting to keep a file on named individuals.
FAQ
Did Madison Square Garden confirm the dossier exists?
No. According to 404 Media, MSG did not respond to a request for comment. The document's existence and contents are based on 404 Media's review of a leaked data cache, not on any statement from the company.
Is facial recognition itself the problem here?
Not exactly. The reporting suggests the issue is how MSG used a watchlist it fully controlled — to track critics and bar adversaries — rather than a flaw in the matching technology. The same point applies to most AI tools: the model is rarely the risk; the rules around it are.
Could this happen at a venue in the UK?
It would be harder. Biometric data is tightly protected under the UK GDPR, and an organisation compiling a file on named individuals would need a lawful basis and would face data-protection scrutiny. "Harder" is not "impossible", but the legal exposure is greater than in New York.
How did the document become public?
It was part of a large cache of MSG data that hackers stole and published online this month. Reporting attributes the leak to a group known as ShinyHunters, which published the data this month after a ransom deadline passed; details of the breach are still being reported.
The takeaway
The strongest version of this story is not "AI is watching you" — it is narrower and more useful than that. A private company bought a face-matching system, built its own secret watchlist, and the leaked evidence suggests that list grew to include the very people arguing the system shouldn't exist. The cameras did nothing wrong; the choices behind them did. If you are assessing any tool that identifies, scores or flags people, the question to ask is not how clever the model is. It is who controls the list, what lands someone on it, and whether anyone outside the building will ever know.
Sources
- 404 Media — "Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition" (23 June 2026)
- 404 Media — "Hackers Publish Knicks and Madison Square Garden Data Online" (June 2026)
- The New York Times — MSG using facial recognition to enforce a lawyer "exclusion list" (December 2022)
- The New York Times — MSG's facial recognition system, first reported (March 2018)
- NBC New York — Girl Scout mother removed from a Rockettes show over her employer
- Information Commissioner's Office — UK GDPR guidance on personal and special-category data