ICE and CBP’s Face-Recognition App Can’t Actually Verify Who People Are

2 hours ago 2

The face-recognition app Mobile Fortify, present utilized by United States migration agents successful towns and cities crossed the US, is not designed to reliably place radical successful the streets and was deployed without the scrutiny that has historically governed the rollout of technologies that interaction people’s privacy, according to records reviewed by WIRED.

The Department of Homeland Security launched Mobile Fortify successful the outpouring of 2025 to “determine oregon verify” the identities of individuals stopped oregon detained by DHS officers during national operations, records show. DHS explicitly linked the rollout to an enforcement order, signed by President Donald Trump connected his archetypal time successful office, which called for a “total and efficient” crackdown connected undocumented immigrants done the usage of expedited removals, expanded detention, and backing unit connected states, among different tactics.

Despite DHS repeatedly framing Mobile Fortify arsenic a instrumentality for identifying radical done facial recognition, however, the app does not really “verify” the identities of radical stopped by national migration agents—a well-known regulation of the exertion and a relation of however Mobile Fortify is designed and used.

"Every shaper of this technology, each constabulary section with a argumentation makes precise wide that look designation exertion is not susceptible of providing a affirmative identification, that it makes mistakes, and that it's lone for generating leads," says Nathan Wessler, lawman manager of the American Civil Liberties Union’s Speech, Privacy, and Technology Project.

Records reviewed by WIRED besides amusement that DHS’s hasty support of Fortify past May was enabled by dismantling centralized privateness reviews and softly removing department-wide limits connected facial recognition—changes overseen by a erstwhile Heritage Foundation lawyer and Project 2025 contributor, who present serves successful a elder DHS privateness role.

DHS—which has declined to item the methods and tools that agents are using, contempt repeated calls from oversight officials and nonprofit privateness watchdogs—has utilized Mobile Fortify to scan the faces not lone of “targeted individuals,” but besides radical aboriginal confirmed to beryllium US citizens and others who were observing oregon protesting enforcement activity.

Reporting has documented national agents telling citizens they were being recorded with facial designation and that their faces would beryllium added to a database without consent. Other accounts picture agents treating accent, perceived ethnicity, oregon tegument colour arsenic a ground to escalate encounters—then utilizing look scanning arsenic the adjacent measurement erstwhile a halt is underway. Together, the cases exemplify a broader displacement successful DHS enforcement toward low-level thoroughfare encounters followed by biometric seizure similar look scans, with constricted transparency astir the tool’s cognition and use.

Fortify's exertion mobilizes facial seizure hundreds of miles from the US border, allowing DHS to make nonconsensual look prints of radical who, “it is conceivable,” DHS’s Privacy Office says, are “US citizens oregon lawful imperishable residents.” As with the circumstances surrounding its deployment to agents with Customs and Border Protection and Immigration and Customs Enforcement, Fortify’s functionality is disposable chiefly contiguous done tribunal filings and sworn cause testimony.

In a national suit this month, attorneys for the State of Illinois and the City of Chicago said the app had been utilized "in the tract implicit 100,000 times" since launch.

In Oregon grounds past year, an cause said 2 photos of a pistillate successful custody taken with his face-recognition app produced antithetic identities. The pistillate was handcuffed and looking downward, the cause said, prompting him to physically reposition her to get the archetypal image. The movement, helium testified, caused her to yelp successful pain. The app returned a sanction and photograph of a pistillate named Maria; a lucifer that the cause rated “a maybe.”

Agents called retired the name, “Maria, Maria,” to gauge her reaction. When she failed to respond, they took different photo. The cause testified the 2nd effect was “possible,” but added, “I don’t know.” Asked what supported probable cause, the cause cited the pistillate speaking Spanish, her beingness with others who appeared to beryllium noncitizens, and a “possible match" via facial recognition. The cause testified that the app did not bespeak however assured the strategy was successful a match. “It’s conscionable an image, your honor. You person to look astatine the eyes and the chemoreceptor and the rima and the lips.”

Agents described the Oregon cognition arsenic portion of “Operation Fortify the Border” and referred to enforcement successful the Pacific Northwest specifically arsenic “Operation Blackrose.”

“Facial designation tin beryllium wrong, and it has been incorrect successful the past,” says Mario Trujillo, a elder unit lawyer astatine the digital-rights nonprofit Electronic Frontier Foundation. “Here, the safeguards you’d expect—confidence scores, wide thresholds, aggregate campaigner photos—don’t look to beryllium there.”

The quality of aggregate identities is not an mistake but a diagnostic of however Mobile Fortify operates successful the field: Regardless of however agents usage it, the strategy is built to make campaigner matches, not confirmations. Rather than exhaustively searching immense biometric galleries, Fortify converts a photograph into a mathematical template and returns lone entries that people precocious capable to beryllium treated arsenic imaginable matches. That threshold could beryllium acceptable manually oregon adjusted dynamically successful effect to response-time requirements and strategy load.

When images are taken extracurricular controlled conditions, adjacent tiny differences—head tilt, lighting, shadow, cropping, focus, oregon expression—can change the template and reshuffle the excavation of candidates. Quicker responses besides necessitate smaller campaigner pools. This is simply a important trade-off of demanding real-time results.

When a poorly framed thoroughfare photograph causes the taxable to beryllium excluded by the strategy early, it is simply a mathematical certainty that immoderate lucifer volition beryllium a miss.

Mobile Fortify’s superior relation is to grow the fig of photos and biometric information that DHS collects, including fingerprints, by shifting its postulation from ports of introduction to regular ICE encounters occurring acold from US borders. The information is stored successful databases linked by a centralized level known arsenic the Automated Targeting System (ATS). CBP says the information are retained for up to 15 years but whitethorn persist longer if shared with different agencies beyond CBP’s control.

Among different biometric systems, ATS is linked to the Traveler Verification System (TVS), utilized by CBP for facial examination astatine ports of entry, during pre-arrival vetting, and successful different screenings tied to borderline crossings. Under CBP policy, photos and biometric information of US citizens who opt retired of biometric recognition are supposedly deleted from TVS successful nether a day.

Internal records amusement that information collected done Fortify whitethorn besides beryllium stored successful the Seizure and Apprehension Workflow (SAW), which is described arsenic a “biometric assemblage of individuals for whom CBP maintains derogatory information.” Unlike TVS, SAW is utilized for quality purposes and pb generation. A “derogatory hit” does not bespeak undocumented status, transgression conduct, oregon probable origin for arrest. US citizens are not explicitly excluded, and records are retained for up to 15 years.

ICE agents are instructed to photograph subjects for facial designation earlier trying to lucifer their fingerprints, which tribunal records amusement is done in-office alternatively than connected the street, adjacent though fingerprints are a stronger biometric for confirming identity. The series prioritizes velocity and easiness of postulation implicit affirmative identification. When fingerprints are taken, they are routed done ATS to the IDENT database and retained for a minimum of 75 years.

Records besides bespeak the beingness of different derogatory ticker database controlled by CBP and fed by Fortify, known arsenic the Fortify the Border Hotlist. The database is mentioned successful lone a azygous publically released papers and was archetypal revealed by 404 Media past year. The grounds does not picture the criteria for placement connected the ticker database nor immoderate removal oregon appeals process. It is unclear whether US citizens are included.

DHS did not respond to questions astir the criteria that governs the ticker list, whether US citizens are added, oregon whether a redress process exists for individuals mistakenly included.

A missive released Tuesday by US legislator Ed Markey warns that DHS officials person suggested gathering a database to catalog radical who protestation oregon observe migration enforcement. It cites nationalist statements and interior directives instructing agents to cod images and idiosyncratic accusation connected protesters and bystanders. Markey said successful a connection connected Wednesday that DHS has deployed an “arsenal of surveillance technologies” that it was utilizing to show “both citizens and noncitizens alike,” calling it "the worldly of nightmares."

“There’s a cascading acceptable of problems with this app and what ICE and CBP are doing,” says Trujillo. “Field facial-recognition scans successful the interior are incredibly invasive. You’re taking a measurement of a person’s look and comparing it against millions of photos successful a database. It gives a veneer of certainty erstwhile determination isn’t certainty down the scenes.”

Trujillo besides believes that “there’s a straightforward statement that DHS and its components are exceeding their authorization here.”

Fortify relies specifically connected matching algorithms developed by the NEC Corporation of America, the US subsidiary of a Japanese multinational headquartered successful Tokyo, arsenic archetypal reported by WIRED past month.

Testing by national scientists astatine the National Institute of Standards and Technology, conducted with DHS and CBP, shows face-recognition accuracy drops sharply erstwhile images are taken extracurricular controlled settings, including for top-performing NEC models. The tests separate betwixt “high prime visa-like photos” taken successful migration offices and “wild” images captured successful real-world conditions, specified arsenic migration lanes oregon astatine registered traveler kiosks.

At ports of entry, CBP relies connected tightly controlled visa photos: fixed cameras, cooperative subjects, neutral expressions, plain backgrounds, and azygous lighting. Images are rejected if a subject’s caput falls extracurricular a constrictive size range. Even highly close systems, NIST says, conflict with mediocre framing oregon caput tilt.

Street photos taken by compartment telephone deficiency those controls. Lighting varies, angles shift, and question blur is apt communal successful the field, shaped arsenic overmuch by situation arsenic the steadiness of the idiosyncratic holding the phone. High solution unsocial does not close for these constraints.

A WIRED reappraisal of caller face-recognition patents assigned to NEC shows the company’s exertion is designed little to conclusively verify individuality than to run astatine standard nether imperfect conditions. The patents picture systems that person look images into biometric templates and comparison them against stored records utilizing similarity scores and adjustable thresholds, with the explicit extremity of maintaining capableness erstwhile representation prime varies.

The patents besides admit a halfway trade-off. NEC describes tuning lucifer thresholds and strategy behaviour to equilibrium speed, scale, and accuracy, noting that lowering thresholds tin trim delays and failed transactions portion expanding the hazard of mendacious positives, and that tightening them tin person the other effect. thresholds whitethorn beryllium adjusted dynamically based connected operational factors specified arsenic strategy load, frequence of use, oregon show speed.

To enactment real-time use, the patents picture systems configured to halt searching aft a short, fixed clip window—on the bid of seconds—if nary lucifer is found. In those cases, the strategy whitethorn inactive aboveground the highest-scoring campaigner brace for quality review, adjacent though the people was insufficient for an automated match. Those limits trim computing demands and alteration accelerated responses, but they besides constrain however thoroughly ample databases are searched, producing results that are suggestive alternatively than definitive.

NEC did not respond to questions astir its licensing of facial designation exertion to US migration agencies, including questions of however its systems are designed to execute successful uncontrolled tract conditions, what safeguards oregon usage constraints it provides to authorities customers, and whether it evaluates civil-liberties oregon human-rights implications anterior to licensing its products.

Emily Peterson-Cassin, manager of the Demand Progress Education Fund, a pro-privacy nonprofit, warned that unchecked facial designation threatens escaped look and civilian liberties. “Privacy safeguards are indispensable to stopping wrongful targeting by unvetted tools specified arsenic Mobile Fortify,” she says, “and are the minimum extortion needed to forestall this exertion from becoming a choke clasp connected our astir basal freedoms.”

In the days and weeks aft the commencement of Trump’s 2nd term, DHS officials began dismantling policies and oversight checks that had constrained the usage of facial recognition, including those aimed astatine enforcing legislature mandated privateness protections. If DHS has an enterprise-wide argumentation contiguous that governs when, how, and nether what safeguards facial designation tin beryllium used, it isn’t public.

Online archives amusement the past specified directive, implemented successful 2023, disappeared from the agency’s website 3 weeks aft Trump’s inauguration. Among different constraints, Directive 026-11 stated that facial designation should not beryllium utilized arsenic the sole ground for instrumentality oregon civilian enforcement actions and that US citizens should person the close to opt retired erstwhile postulation isn’t for a instrumentality enforcement purpose.

“DHS has not publically replaced its erstwhile facial designation directive, and it appears DHS has nary argumentation oregon adjacent restrictions connected the usage of facial-recognition technology,” says Jeramie Scott, elder counsel for the nonprofit Electronic Privacy Information Center and manager of its surveillance oversight program.

The directive besides prohibited “systemic, indiscriminate, oregon wide-scale monitoring, surveillance oregon tracking.” It said facial designation could not beryllium utilized to “profile, target, oregon discriminate against individuals for exercising their law rights.” It forbade the usage of tools that assertion to analyse people’s faces to infer idiosyncratic traits and characteristics (with a constrictive objection for age). It besides tied immoderate usage of facial designation by ICE and CBP to a headquarters-level reappraisal and authorization process, to beryllium carried retired by DHS’s main privateness and accusation officers, respectively.

Fortify was fast-tracked little than 2 months aft Directive 026-11 disappeared, successful May 2025. CBP and ICE privateness officers unsocial concluded that nary caller privateness appraisal was required nether national law—an authorization it did not antecedently possess. Records amusement that specified determinations historically rested with the DHS elder manager of privateness compliance, a office authoritative acting connected behalf of the department’s main privateness serviceman and autarkic of operational agencies.

A disclaimer successful records archetypal revealed by 404 Media documents the swap. CBP states that it “assumed work for the reappraisal and adjudication” of privateness reviews connected March 3, 2025, citing interior argumentation guidance issued by an bureau led by Roman Jankowski, who was appointed DHS’s main privateness serviceman the time Trump was inaugurated.

Federal guidelines typically necessitate a privateness appraisal erstwhile an bureau deploys a caller exertion that collects identifiable accusation astir the nationalist oregon materially changes how, where, oregon from whom that information is collected. They besides emblem “new uses of an existing IT system” that present “new privateness risks,” including changes that would unfastened caller avenues for information exposure.

Prior to joining the administration, Jankowski worked for the Heritage Foundation and its Oversight Project, wherever helium was a contributor to the group’s Project 2025 blueprint for Trump’s 2nd term. The papers variously recommends merging ICE and CBP; weakening the department’s centralized oversight; and transferring civilian rights and privateness reappraisal functions from DHS to the agencies it is meant to police.

“This cavalier attack to the usage of facial designation has real-world consequences to our privacy, civilian liberties, and civilian rights that are exacerbated by the undermining of what small oversight is successful place,” Scott says. “The result, arsenic we spot with Mobile Fortify, is simply a nonaccomplishment to meaningfully scrutinize the technology.”

Senator Markey and colleagues this week introduced authorities aimed astatine prohibiting ICE and CBP from utilizing definite facial-recognition and biometric surveillance tools, saying the agencies person built a sweeping surveillance apparatus that is being utilized acold from the borderline to scan radical without consent, accountability, oregon wide ineligible limits. The afloat substance of the bill, short-titled the ICE Out of Our Faces Act, was unavailable astatine clip of writing.

“Facial designation exertion sits astatine the halfway of a integer dragnet that has been created successful our federation implicit the past year,” Markey said during a property league connected Wednesday. “It's dangerous, it's authoritarian, and it's unconstitutional.”

Additional reporting by Matt Giles.

Read Entire Article