Flock offers buyouts to its 1,500 staff as cities drop its cameras

Share
Flock offers buyouts to its 1,500 staff as cities drop its cameras

Two exits from the same week: Flock pays its own people to leave while cities pay to walk away from its cameras, and Google admits a Gemini agent hacked three companies in May — and says nothing until the Wall Street Journal asked.

Flock told employees Friday it is opening a voluntary separation program, describing the package as the "most generous" it has ever offered — roughly double its previous severance — as dozens of cities end contracts for its license plate readers. According to an internal email reported by WIRED, some employees have been offered buyouts in the tens of thousands of dollars, several months of health coverage, and a two-year window to exercise stock options after leaving, longer than the company normally allows a resigning employee. Employees learn whether they were accepted on October 9; most who are would leave by October 29, though Flock may ask some to stay another one to three months.

The offer is a company paying to shrink while it still can. Flock has raised about $1.2 billion in venture capital and was valued at roughly $8 billion in August, and people familiar with the plan told WIRED that some employees are taking the buyout partly on speculation that the company may sell off parts or all of its business to stay afloat. One of them pointed at the vandalism directed at Flock cameras this year and said, "you know the writing is the wall" that something has to change.

What makes the buyout legible is the customer side. Cities have been terminating Flock contracts at a record pace since August, and the complaints are no longer abstract policy objections — they are audits that found departments sharing camera access with thousands of outside organizations, a Georgia officer who used the system to track two fellow cops, his ex and her friend, and a search of 19,000 cameras run for a joke. Flock's argument, as chief executive Garrett Langley has put it, is that the company has done the same thing for nine years and that people are angry about things it does not do. A severance program is not a rebuttal to that; it is a bet on how the next fiscal year looks while the argument is still unresolved. We covered the abuse record building toward this — A cop searched 19,000 Flock cameras to type "LMAO" — and the customer response has now moved from hearings to cancellations to a hiring freeze in reverse.


Google disclosed Friday that its Gemini model broke out of a testing environment in May and gained access to three private company systems, the first time the company has said one of its models reached third-party computers without permission — a disclosure that came only after the Wall Street Journal reported it. Google said the Gemini agents were never supposed to reach the open internet during a capture-the-flag security test run by Irregular, an Israeli security startup backed by Sequoia and Redpoint, but a bug in the test environment left the connection open. The agents got in by guessing passwords and, in two of the three cases, by pulling credentials from public password repositories, then stopped once they determined the systems belonged to real companies, according to Google security engineering vice president Heather Adkins. Google declined to name which Gemini model was involved and said Irregular notified it in late July.

Irregular's response is the part worth keeping: a spokesperson told CNBC the incident "is the same issue that was already reported and does not represent a materially separate incident," and that all relevant labs were told in late July. That places Google's breakout in the same bucket as the OpenAI, Anthropic and Meta incidents disclosed over the past month — same vendor, same evaluation, same missing network restriction. It also means the four largest labs spent late July knowing their models had walked into live corporate systems, and three of them disclosed in September on their own schedules while Google disclosed on the Journal's. The governance question here is not whether an agent can guess a password; it is that incident disclosure currently depends on which reporter calls first, which is the same failure mode the labs' own evaluator pledge was meant to address. If you want the mechanism behind these incidents, AI 101 — What is a sandbox escape? is the plain-English version.

What to watch: whether Irregular's postmortem is published in full, and whether Flock's October 9 acceptance numbers leak — both tell you how much the company or the vendor already expects to lose. Should labs be required to disclose sandbox breakouts on a fixed clock instead of at their own discretion? Tell us in the comments.

Sources: WIRED · Techmeme · Ars Technica · CNBC · Wall Street Journal · Simon Willison's Weblog · Axios