There is a particular kind of stillness required of the body at a border. You place four fingers flat against a cold glass plate, and then a thumb, and then the other hand, and a machine you cannot see the inside of decides, in less than a second, something about who you are. Then a camera, mounted slightly too high or too low for anyone’s actual height, takes your photograph without asking you to smile. Anyone who has stood in that line, in any airport, in any year of the last two decades, has done this. Almost no one asks afterward where the picture goes.
I want to answer that question in this essay, plainly, because I think the plain answer is stranger than most people assume. The photograph, and the fingerprints, do not simply verify that you are who your passport says you are and then vanish. Under a rule that took effect on December 26, 2025, U.S. Customs and Border Protection may retain a non-citizen’s biometric entry-and-exit photograph for up to seventy-five years.1 Seventy-five years is not a security measure. It is closer to a life sentence of documentation, one that will very likely outlast the government agency currently issuing it, and quite possibly the country’s present form of government altogether. I do not think that comparison is rhetorical excess. I think it is arithmetic.
I. The Expanding Definition of You
For most of the last century, immigration biometrics meant three things: a fingerprint, a photograph, a signature. In November 2025, the Department of Homeland Security proposed a rule that would formally redefine “biometrics” to include facial imagery, palm prints, iris and retina scans, voice prints, and DNA, while removing the age restrictions that had previously exempted young children and the elderly from collection.2 A separate final rule, covering biometric collection at actual ports of entry and exit, took effect that same December, extending mandatory photography to every non-citizen crossing a U.S. border — permanent residents included — regardless of age, at every airport, seaport, and land crossing in the country.3
All of this collected material funnels, eventually, into a system called the Homeland Advanced Recognition Technology database, or HART, which has been under construction since 2016 as the successor to an older fingerprint system called IDENT.4 The National Immigration Law Center has described HART as a system built largely without public scrutiny, one whose stated purposes have crept, over successive rulemakings, from verifying identity toward something closer to permanent, searchable surveillance — the information, once inside DHS’s custody, may be searched and shared for purposes well beyond the immigration application that generated it.5 I do not think “purpose creep” is too strong a phrase for this. A fingerprint taken to prove you are eligible for a green card was, at the outset, understood as a single-use key. It has become something closer to a permanent record, held by an agency that, according to its own privacy assessments, does not always control or verify the accuracy of everything inside it.
II. Where It Goes, and How Long It Stays
The word “retention” undersells what is actually happening. U.S. citizens who are photographed for identity verification at the border have their images discarded within twelve hours.6 Everyone else — every green-card holder, every visa holder, every asylum seeker — is enrolled in a system that keeps the image for up to seventy-five years, a period DHS itself has justified as necessary to support “subjects of interest” in immigration, border management, and law enforcement activity indefinitely.7 Once that data exists, it does not stay quietly inside a single filing cabinet. Immigration and Customs Enforcement’s Homeland Security Investigations division holds a multimillion-dollar contract with Clearview AI, the private company whose facial recognition tool draws on a database of more than fifty billion images scraped from the open internet.8 ICE’s use of the tool, originally described as limited to child-exploitation investigations, has since been expanded to identifying people who assault its own agents — a use case nobody involved in the original contract appears to have anticipated.9
Illinois passed a law in 2008, the Biometric Information Privacy Act, that requires companies to obtain consent before collecting a person’s faceprint or fingerprint, and Clearview eventually settled a lawsuit brought under that law by agreeing to stop selling its database to private companies and Illinois police.10 That settlement, however, does not bind federal agencies. Chicago reporters found, in the fall of 2025, that ICE continues to use the very tool state law forbids local police from touching, with what civil liberties advocates describe as almost no independent oversight.11 I find something almost darkly comic in this arrangement, if I am honest: a state legislature decided a technology was too invasive for its own police department, and the federal government responded by using that same technology on the state’s residents anyway, simply by virtue of being federal. Sovereignty, in this instance, functions less as a form of accountability than as a loophole.
III. The Question of Accuracy, and Who Pays for the Error
It is worth pausing on whether any of this even works as advertised, because the honest answer is contested and depends heavily on which algorithm and which study you are reading. The National Institute of Standards and Technology’s landmark 2019 evaluation, drawing on eighteen million images including immigration and border-crossing photographs, found that many of the facial recognition algorithms it tested were, in certain matching tasks, ten to one hundred times more likely to misidentify a Black or East Asian face than a white one.12 Industry groups and some technology researchers have pushed back hard on that framing, arguing that the very best-performing algorithms in the same NIST testing pool showed accuracy differences across demographic groups that were, in their words, undetectable, and that the disparity exists mainly among lower-tier algorithms that no serious government system ought to be using in the first place.13
Both of these things can be true simultaneously, and I think that is precisely the danger. It is not that facial recognition is universally, uniformly broken. It is that its accuracy varies by vendor, by dataset, by lighting, by the age of the photograph on file — and an immigrant does not get to choose which algorithm, which vendor, or which decade-old passport photo is used to judge them at a checkpoint. A false match, for most consumer technology, means an inconvenience: a locked phone, a rejected purchase. A false match inside an immigration enforcement system can mean detention, a missed hearing, a family separated at a border while a machine’s confidence score is manually re-checked by a human being who is, understandably, in a hurry. The stakes of an error are not evenly distributed. They fall almost entirely on the person with the least power in the interaction.
IV. What I Think We Should Ask of This
I do not think biometric identification is inherently sinister. There are real, defensible reasons a government wants to know that the person crossing its border is who they claim to be, and fingerprints have been used for exactly that purpose, imperfectly but functionally, for more than a century. What troubles me is not the fact of collection. It is the absence of a limiting principle around it — no clear end date, no meaningful path for a person to inspect, correct, or challenge what is held about them, and a widening gap between what the data was originally collected to do and what it is now quietly permitted to do.
A password, if it is stolen, can be changed. A face cannot. A fingerprint cannot. This is the plain, physical fact that ought to govern every policy conversation about biometric data, and it rarely does, because the conversation tends to happen in the register of security and efficiency rather than the register of permanence. I go back, in my mind, to that border line — the flat glass plate, the too-high camera — and I think the honest thing to tell the person standing there is this: what is being taken from you today will very likely outlive you, and very likely outlive the specific reason anyone gave you for taking it. That is not a reason to refuse the plate. It is a reason to insist, as a matter of law and not merely of assurance, on knowing exactly where the picture goes.