There is a pattern we keep seeing across venue-operator litigation: a private corporation deploys biometric identification at building perimeters, cross-references the resulting fingerprints against attorney-of-record lists from open lawsuits, and bars counsel from entry — regardless of whether that counsel personally has any history with the venue. The current case involves attorney John Scola, who represents a New York Police Department officer suing over injuries allegedly sustained while working security at a Madison Square Garden property in 2025. The ban arrived before the case reached substantive motion practice. That sequence — identification, list-matching, exclusion — is the pattern. It is also a threat model most security writing fails to articulate.
The Venue-as-Surveillance-Operator Pattern
The pattern: a private operator of physical spaces deploys identification infrastructure with the operational posture of a state intelligence service, and the legal posture of a nightclub bouncer.
MSG Entertainment has operated facial recognition at Madison Square Garden, Radio City Music Hall, the Beacon Theatre, and the Hulu Theater since 2018, according to its own public statements and contemporaneous reporting in major outlets in late 2022 when the policy first attracted regulatory attention. The vendor stack is consistent with what is publicly known about commercial venue deployments — NEC NeoFace and Idemia LFIS are the two dominant biometric matching engines in this segment, both rated against NIST FRVT 1:N benchmarks. The matching threshold an operator chooses is a business decision, not a technical constant. A venue that wants zero false negatives at the cost of high false positives will set the threshold loose. A venue that wants the inverse will tighten it. Neither choice is regulated. Neither choice is disclosed to the ticket-holder.
What turned a quiet biometric perimeter into a litigation surface was the operator's decision to ingest attorney-of-record data from open lawsuits and load it as a watchlist alongside the bag-thief and trespasser lists every venue maintains. The Scola situation is the second-generation version of the same pattern. The first generation surfaced in late 2022 when MSG used the same architecture to bar attorneys from at least five law firms with active litigation against the company. The New York State Liquor Authority opened an investigation citing NY ABC Law § 118 liquor-license obligations. The Attorney General's office sent a formal inquiry under NY Civil Rights Law § 40-b, the statute requiring places of public entertainment to admit holders of valid tickets without arbitrary exclusion.
The architecture has not changed since. Only the names on the list rotate.
The Adversarial Watchlist Pattern
The pattern: any system that matches an identity against a list will be only as trustworthy as the list, and the list is curated by the entity that benefits from exclusion.
This is the core security flaw and it is not a software bug. Biometric matching engines do not validate the semantic correctness of the lists they ingest. A face template matched against the wrong category — "criminal trespasser" versus "represents-plaintiff-in-active-litigation" — yields the same exclusion outcome at the turnstile. The protocol-level mitigation is list-curation governance. There is none here. The operator writes the list. The operator enforces the list. The operator decides what category an entry belongs to. There is no auditor, no scope statement, no third-party verification analogous to what Cure53 or PwC publishes for VPN no-logs claims. The closest analog in the venue-security literature is the EFF v. Clearview AI litigation history, and even that addresses upstream data acquisition rather than downstream list-construction.
A ticket-holder presenting at the entry doors is therefore subject to an exclusion authority with three properties that should alarm anyone who has read RFC 3552's threat-model conventions: the authority is private, the criteria are undisclosed, and the appellate path is the courthouse — which is the same venue where the dispute originated. The asymmetry is the entire story. A consumer who buys a ticket on the secondary market has no notice, no consent ceremony, and no machine-readable disclosure that their face will be compared against a list whose composition is a litigation strategy variable.
The operator who curates the watchlist is the same operator who benefits from each successful exclusion, and there is no third party in the loop to notice that the conflict exists.
The Scola fact pattern is the cleanest illustration to date. Counsel's only connection to the venue is professional representation of a plaintiff in an injury matter; the venue's response is a perimeter exclusion that pre-empts the discovery posture an in-person visit would normally permit. Whatever one's view of the underlying tort claim, the procedural posture is now a fact pattern for civil-procedure scholars: a defendant has used its private control of a physical space to constrain plaintiff's counsel's access to that same space during litigation about events that occurred there. The list-construction logic is the mechanism that makes this possible at scale.
The Biometric Identification Threat Model
The pattern: every biometric deployment fits inside a threat model, and the threat model determines whether the deployment is a defense, a neutral utility, or — as here — an adversarial instrument pointed at the ticket-holder.
The threat-model framing for a venue biometric perimeter has four axes. The adversary is the venue operator itself; this is the inversion that distinguishes this deployment from, for instance, an airport security gate where the adversary is the would-be hijacker and the operator is at least nominally aligned with passenger interests. The capability is 1:N matching at sub-second latency against a watchlist whose upper bound is constrained only by the matching engine's gallery size — for NEC NeoFace deployments documented in NIST FRVT 1:N evaluations, that ceiling sits well above 10 million templates with subsecond response. The user's exposure is exclusion from a ticketed, paid-for performance. The mitigation is — and this is the uncomfortable part of the analysis — close to nil at the user's end.
The arithmetic for false-positive exposure is worth working through because the marketing literature for these systems makes it sound trivially small. Take the FRVT 1:N false-positive identification rate (FPIR) at the operating point most commercial venues use: roughly 0.001 at FNIR 0.01 for top-decile algorithms in the NIST FRVT 1:N 2023 report. That sounds tight. Now compute the operational arithmetic. A venue processes 18,000 ticket-holders for a single arena event. Each face is compared against a watchlist; assume a conservative watchlist of 5,000 entries. Single-face FPIR of 0.001 means the expected number of false matches *per face* against the *full watchlist* is roughly 0.001 × 5,000 / 5,000 — that is, 0.001 at the per-face level — yielding an expected 18 false positives per event at the loose operating point. Tighten the threshold to FPIR 0.0001 and the number drops to 1.8 per event. Neither number is zero. Neither number is published. The ticket-holder has no view into where the threshold sits.
The closest analog to a CVE-style disclosure here is the NIST FRVT Demographic Effects 2019 report (NISTIR 8280), which documented false-positive rate differentials of 10× to 100× across demographic cohorts on commercially deployed algorithms in operational use at the time of testing. The disclosure was public. The remediation status, six years on, is uneven; vendors have released revised models but the threshold-setting decision remains the venue's. No venue operator is required to disclose the specific algorithm version it runs, the specific operating-point setting, the demographic-validation evidence it relies on, or the audit scope of any third-party assessment. The information asymmetry is total.
The takeaway for the threat-modeller: a venue biometric perimeter is structurally an adversarial system from the ticket-holder's perspective whenever the venue operator and the ticket-holder have an unresolved dispute. That set of conditions includes — but is not limited to — active litigation, prior ejection, prior refund disputes, prior contractual negotiation, or membership in any category the operator quietly designates as adverse. The Scola situation belongs to the first category. The deployment surface that processes him is the same surface that processes every other ticket-holder at the door.
So What Do You Actually Do
If you are a litigator with active or contemplated matters against a venue operator that runs biometric perimeters, treat physical site visits as a discovery action and serve notice rather than relying on a ticket. The Scola sequence forecloses the casual-entry option; the procedural workaround is to request access through formal discovery channels, with the exclusion itself documented as evidence of operator conduct. Co-counsel arrangements with attorneys whose biometric template has not been ingested are a tactical option, but the durability of that arrangement against expanded list ingestion is unknown. Plan for the list to grow.
If you are a ticket-holder with no litigation posture but a general concern about biometric exposure at private venues, the honest answer is that no consumer-side mitigation is robust. Physical countermeasures — masks, glasses, hats — degrade matching confidence at the margin but do not defeat well-tuned 1:N systems and are increasingly proscribed by venue dress codes for reasons that read as related though are not publicly tied. The durable path is regulatory, not technical: state-level legislation requiring disclosure of biometric perimeter operation, watchlist composition criteria, and an independent appellate mechanism. Bills along those lines have been introduced in multiple US state legislatures since 2023; none has yet produced an operational regime comparable to the Illinois Biometric Information Privacy Act in its enforcement posture.
If you are writing about VPNs, venue surveillance, or any other identification-bearing system, the methodology transfers cleanly. State the adversary. State the capability. State the user's exposure. State the mitigation and its scope. The Scola matter is not a story about one lawyer or one arena. It is a fact pattern that exposes the structural shape of a wider class of deployments — every system in which a private operator runs an identification infrastructure against a privately curated watchlist with no third-party scope statement and no appellate path. There are many such systems. They are not all venues.
The New York Attorney General's December 2022 letter to MSG Entertainment, in the matter of facial recognition exclusion of attorneys with active litigation, requested a written response within four weeks and remains publicly posted on the office's site.
FAQ
What law governs whether a venue can refuse to admit a ticket-holder?
In New York, the operative statute is NY Civil Rights Law § 40-b, which prohibits places of public entertainment from refusing admission to a ticket-holder except for specific enumerated reasons. The statute predates biometric perimeters by several decades. The question whether attorney-of-record status constitutes a § 40-b enumerated reason has not been resolved by the Court of Appeals. Lower-court rulings to date have addressed narrower procedural questions about injunctive relief and the scope of the venue's contractual notice on the ticket itself.
Are venue biometric systems regulated at the federal level in the US?
No federal statute directly regulates private-venue biometric deployment. The Federal Trade Commission Act § 5 unfair-practices framework has been used as enforcement leverage in adjacent matters, and the Illinois Biometric Information Privacy Act is the strongest state-level regime, with a private right of action and statutory damages. Most US states have no equivalent statute. A venue operating in a non-BIPA jurisdiction faces no specific biometric-disclosure obligation beyond general consumer-protection law.
Can a face mask or sunglasses reliably defeat venue facial recognition?
Modeling on NIST FRVT evaluations of face-occlusion robustness suggests well-tuned commercial algorithms retain meaningful matching capability under partial occlusion. A standard surgical mask degrades top-tier algorithm accuracy at the margin but does not produce reliable defeat. Sunglasses combined with a mask perform better but conflict with venue dress and entry policies that increasingly prohibit face covering. The countermeasure cannot be characterized as robust against an attentive operator.
What is the difference between this and airport facial recognition?
The threat model is inverted. At an airport security checkpoint, the operator is nominally aligned with passenger interests against an external adversary. At a private venue running an adversarial watchlist, the operator is itself the adversary from the perspective of any ticket-holder on the list. The technology stack is similar. The trust posture is opposite. Most consumer commentary collapses the two cases, which produces the wrong threat-model analysis for the venue case.
How large can a venue watchlist plausibly be?
Commercial 1:N matching engines documented in NIST FRVT 1:N 2023 support gallery sizes well into the millions of templates with sub-second response. The operational ceiling for a venue watchlist is not technical. It is curatorial — how many entries the operator chooses to maintain. There is no public disclosure obligation, no third-party audit, and no scope statement attaching to the list's composition. Externally, the list size is unknown by design.
Has any third-party audit of a venue biometric deployment been published?
No published audit comparable in scope and rigour to the Cure53 penetration tests of VPN protocol stacks, or the PwC server-configuration assessments of no-logs claims, has appeared in the public record for any major US venue biometric deployment. Audits of vendor algorithms exist through the NIST FRVT program, but those address algorithm performance in laboratory conditions, not operator-side list-construction governance or threshold-setting decisions.
What evidence will be discoverable in litigation against a venue operating this system?
Discovery in active matters has produced documents addressing the existence and general purpose of the watchlists, the categories of persons placed on them, and the operator's policy framework. Specific algorithm version, operating-point threshold settings, demographic-validation evidence, and full watchlist composition are positions venues have actively resisted disclosing on trade-secret and security grounds. The discovery-scope question is unsettled and varies by jurisdiction and the framing of the underlying claim.