Skip to main content

TSA and CBP Biometric Surveillance Programs (2017–ongoing)

  • Programs: TSA Biometric Technology Rollout (airports nationwide); CBP Biometric Entry/Exit Program
  • Statutory basis: TSA rollout has no specific authorizing statute — it operates under general DHS authority. CBP Entry/Exit authorized under 8 U.S.C. § 1365b; final rule effective December 26, 2025
  • Administered by: Transportation Security Administration; U.S. Customs and Border Protection
  • Daily throughput: Over 2 million travelers pass through TSA checkpoints every single day

The government is scanning your face every time you board a flight. Not because a court ordered it. Not because Congress passed a law specifically authorizing it. Because TSA decided it could, nobody stopped them, and Congress has been writing checks for it ever since. There has never been a comprehensive Privacy Impact Assessment for this program. Five U.S. senators demanded it be halted and were ignored. The system has a documented 100-times-higher error rate for Asian and African-American faces than for white men. And if you think you can opt out — you cannot.

How It Passed

No single vote created the TSA biometric surveillance program. That is the point. TSA's facial recognition rollout happened through a combination of budget appropriations, agency rulemaking, and deliberate avoidance of the statutory authorization process that would have required Congress to go on record.

TSA began piloting facial recognition in 2017. The program expanded quietly year by year — airport by airport, checkpoint by checkpoint — with Congress appropriating funds for "biometric technology" in DHS budget bills without ever passing a specific law authorizing facial recognition of U.S. citizens at airports.

By 2023, TSA had deployed facial recognition systems at dozens of major airports and was accelerating the expansion. That same year, five U.S. senators — including Senators Merkley, Markey, Booker, Blumenthal, and Gillibrand — sent a formal letter demanding TSA halt the program. Their letter called it "a risk to civil liberties and privacy rights." TSA did not halt the program. TSA kept expanding it.

CBP's Biometric Entry/Exit program moved on a parallel track. Its final rule — effective December 26, 2025 — authorizes CBP to collect facial biometrics from ALL noncitizens at airports, land ports, seaports, and on private aircraft. The rule expanded the program to cover Canadian visitors who were previously exempt and positioned CBP to eventually extend mandatory biometric collection to U.S. citizens at international borders. As of May 2025, TSA had never published a single comprehensive Privacy Impact Assessment for its facial recognition program.

What It Does To You

The Two Modes — One Is Mass Surveillance

TSA operates facial recognition in two modes:

  • One-to-one verification — your face is compared against your ID document to confirm you are who you claim to be. This is an identity check.
  • One-to-many identification — your face is compared against a database gallery of expected travelers. The system searches the database for a match to your face. This is mass surveillance. It means your biometric data is being run against a list of people — a list whose composition you do not control, cannot inspect, and did not consent to populate.

TSA has been deploying both modes. The one-to-many mode is fundamentally different from showing your ID at a checkpoint. It is running your face through a database every time you fly.

CBP's Biometric Dragnet

The CBP Entry/Exit final rule of December 2025 authorizes collection of facial biometrics from all noncitizens at airports, land ports, seaports, and on private aircraft. Noncitizens' facial images are retained for up to 75 years. The CBP program is not limited to international travelers — it covers Canadian visitors at land border crossings, travelers on private aircraft, and anyone arriving by sea.

These systems are deployed first on foreign nationals, then expanded to cover citizens. CBP is already scanning U.S. citizens at international borders, and TSA's domestic program already captures U.S. citizens at airport checkpoints.

No Meaningful Opt-Out

If you use TSA PreCheck or the standard security lane at a participating airport, you are scanned. There is no posted notice explaining your options. There is no form to complete before you reach the checkpoint. You cannot know which airports have the system deployed before you travel. The practical opt-out — requesting a manual ID check — requires knowing you have the right, knowing to ask at the right moment, and being willing to accept the social pressure of a line of people waiting behind you while an agent processes a non-standard request.

That is not a meaningful opt-out. It is an opt-out designed to be ignored.

Rights It Strips

Fourth Amendment — Biometrics Are Different

The Supreme Court has never specifically ruled on whether airport facial recognition scanning constitutes a Fourth Amendment search. The government's position is that the airport environment, combined with the voluntary nature of air travel, eliminates your Fourth Amendment interest in your own face. This argument depends on the third-party doctrine — the idea that information you "expose" to others (your face, visible to everyone) carries no reasonable expectation of privacy.

Your face has always been visible. What has changed is that the government is now capturing your unique biometric identifier, converting it to a mathematical representation, storing it in a database, running it against galleries of other faces, and retaining the record — potentially for decades. The fact that your face is visible to passersby does not mean you consented to government biometric capture and database retention every time you fly.

Due Process — No Notice, No Consent, No Recourse

There is no process through which a traveler can learn whether their biometric data has been retained, what database it was searched against, whether a false match occurred, or how to challenge a result. If the system falsely identifies you as someone on a watchlist, you may face additional screening, detention, or denial of boarding — with no advance notice and no clear avenue for challenge. You will not be told a database match triggered your detention. You may not be told anything at all.

First Amendment — Biometric Surveillance Chills Everything

When attending a political event, protest, or government building requires submitting your face to a government biometric database, the chilling effect on political activity is not theoretical. People who know their movements are being biometrically tracked change their behavior. They attend fewer rallies. They avoid certain airports. They do not go to events where facial recognition cameras are deployed. The government does not need to explicitly threaten anyone. The surveillance itself does the work.

Documented Harms

The NIST Error Rate Study — 100 Times More Likely to Be Wrong

A 2019 study by the National Institute of Standards and Technology evaluated 189 facial recognition algorithms and found documented racial and demographic bias across virtually all of them. Asian and African-American people were up to 100 times more likely to be falsely matched than white men. Native Americans had the highest false-positive rates of any demographic group. Elderly people and children were more likely to be misidentified than adults of working age.

TSA selected its vendors from this same universe of algorithms. A false match at a TSA checkpoint can mean additional screening, detention, missed flights, and confrontations with federal agents — for people who did nothing wrong. The error rate falls disproportionately on people who are already disproportionately subjected to discriminatory screening.

No Privacy Impact Assessment

As of May 2025, TSA had never published a single comprehensive Privacy Impact Assessment for its nationwide facial recognition program. The Privacy Impact Assessment is a federal baseline — required under the E-Government Act of 2002 — for any federal system that collects personally identifiable information. TSA has been deploying a biometric surveillance system at airports used by over 2 million people per day without completing this basic legal requirement.

Congressional Demand Ignored

In February 2023, five sitting U.S. senators sent TSA a formal letter calling the program "a risk to civil liberties and privacy rights" and demanding it be halted pending a comprehensive privacy review. TSA did not halt the program. It continued to expand. Senators of the United States sent a written demand and were functionally ignored by an agency that answers to the executive branch.

EPIC v. CBP — Ongoing Legal Challenge

The Electronic Privacy Information Center has filed a legal challenge to the CBP Biometric Entry/Exit Program. The challenge argues that CBP's expansion of biometric collection exceeds statutory authority and violates constitutional privacy protections. The litigation is ongoing.

Who Pushed This

DHS and TSA leadership are the primary institutional architects of these programs. TSA has positioned biometric screening as a security modernization initiative — faster, more accurate, more convenient than document checks — and has used that framing to avoid the harder questions about consent, retention, and racial accuracy.

The biometric technology industry has lobbied aggressively for airport facial recognition deployment. Companies including NEC Corporation of America, Idemia (formerly Morpho), SITA, and others have active contracts with TSA and CBP for biometric identification systems. These companies sell the technology, operate the systems under federal contract, and have a direct financial interest in expansion. They have spent significant sums on federal lobbying.

Defense and homeland security contractors more broadly — including Palantir and Leidos — have worked to integrate biometric data with broader federal identity and watchlist databases. The airport biometric program is a data pipeline, and the downstream uses of that pipeline extend far beyond confirming a traveler's identity at a checkpoint.

The Department of Homeland Security has used the September 11 authorization framework — the argument that any aviation-related security measure is presumptively valid in the post-9/11 era — to expand biometric programs without the statutory authorization that would require Congress to publicly debate and vote on facial recognition of U.S. citizens.

CBP pushed the December 2025 final rule through administrative rulemaking rather than seeking new statutory authority from Congress, treating a massive expansion of biometric surveillance powers as a routine regulatory update.

Key Votes

There is no single congressional vote on TSA facial recognition of U.S. citizens because TSA has deliberately avoided seeking specific statutory authorization. The program was funded through annual DHS appropriations bills — hundreds of line items, few floor debates, no recorded votes specifically on airport facial recognition.

DHS Appropriations — FY2019 through FY2025: Each year, Congress appropriated funds for TSA "biometric technology" and CBP "biometric entry/exit" as components of larger appropriations packages. No floor amendment specifically restricting facial recognition of U.S. citizens has ever passed either chamber.

February 2023 Senate Letter: The five senators who signed the demand-to-halt letter — Merkley (D-OR), Markey (D-MA), Booker (D-NJ), Blumenthal (D-CT), and Gillibrand (D-NY) — are among the few members of Congress who have taken a documented public position demanding a halt. Every senator and representative who voted YES on DHS appropriations funding this program without attaching facial recognition restrictions voted to fund it.

The Senate Commerce Committee held a hearing on facial recognition in 2023 but did not advance legislation restricting TSA deployment.

Why This Matters for We The Citizens

This program is the template. Biometric surveillance is the government's preferred method of tracking physical movement — because biometrics cannot be forged, transferred, or left at home. Once the government has your facial recognition profile linked to your name, your travel history, your device data, and your financial records, you have no meaningful anonymity in public space.

The TSA and CBP programs are not about airport security. They are about building the infrastructure for population-scale identity and movement tracking. The airport is the easiest place to start — a controlled environment where you must comply to board. But the same cameras, the same algorithms, and the same databases are being deployed in transit systems, sports venues, and public streets.

Any candidate who voted to fund this program without demanding statutory authorization, a public Privacy Impact Assessment, and an explicit opt-out mechanism for U.S. citizens chose the surveillance state over your Fourth Amendment rights. That vote is on the record.

See also: Bad Laws Overview | CBP Border Device Searches | No-Fly List | REAL ID Act