What AI at the border actually covers
Border and immigration technology tends to get discussed as a single subject, but it covers at least three quite different things, with different risks attached to each.
The first is biometric identity verification: facial recognition at automated e-gates, fingerprint and iris matching in visa and asylum processing. This is the most mature and, in narrow technical terms, the least contested application. It is a one-to-one matching problem, comparing a person against a document they have presented, which is a substantially easier task than picking a face out of a crowd.
The second is automated risk assessment: systems that score or triage travellers, visa applications or asylum claims to direct human attention. This is closer to the predictive policing debate, and carries similar questions about what the training data actually encodes.
The third is the one that has produced the most documented controversy recently, and it is not really a border technology at all. It is immigration enforcement gaining access to surveillance infrastructure built and paid for by someone else, for a different stated purpose.
Surveillance built for one purpose, used for another
Automated licence plate reader networks in the US are largely commercial products bought by individual cities and police departments, most prominently from Flock Safety, whose network is reported to cover more than 5,000 law enforcement agencies. The stated purpose at the point of purchase is typically local: stolen vehicles, serious crime investigation, missing persons.
An Illinois state audit found that federal agencies including US Customs and Border Protection had obtained access to state plate-read data through an undisclosed pilot arrangement, in apparent tension with an Illinois law restricting data sharing for immigration enforcement purposes. Illinois subsequently removed 47 agencies from data access. Separately, the police chief in Mountain View, California disclosed to the city council that federal agencies had accessed the city's camera data without the city's knowledge; the council voted unanimously to terminate the contract.
What makes these cases significant is the mechanism rather than the individual facts. A city council approving a plate reader contract is making a judgement about a specific, bounded local purpose. If the resulting database can subsequently be queried by agencies the council never contemplated, for purposes it never approved, then the consent it gave was for something narrower than what it actually got. Both cases are recorded with full sourcing on the deployment tracker, and the underlying system is covered on the Flock Safety ALPR page.
Direct contracting for facial recognition
Immigration authorities have also bought facial recognition capability outright. Clearview AI, whose database is assembled from images scraped from the public web, has reported contracts with US Immigration and Customs Enforcement, with US Customs and Border Protection, and with a US Army special operations command.
The significance here is what Clearview's database is. Unlike a passport or visa photo held for an identity-verification purpose, a scraped web image was never provided by the subject for any government use at all. Privacy regulators in Canada, the UK and Australia each separately found the company's collection practices breached their national law and ordered it to stop gathering their citizens' images. Those findings did not stop the company operating in the US, and they carry no weight over a US federal contract. The system is covered in more detail on the Clearview AI page.
Why the oversight picture differs from domestic policing
Border and immigration functions commonly sit under a different legal framework from ordinary policing. Powers at the border are frequently wider, the threshold for exercising them lower, and data protection regimes often contain explicit carve-outs on immigration control or national security grounds. In the UK, the exemption in data protection law relating to immigration control has been the subject of sustained legal challenge for precisely this reason.
There is also an asymmetry in who is affected. The people subject to these systems are disproportionately non-citizens, who may have fewer practical routes to contest an adverse decision, less standing to bring a challenge, and in some cases a strong incentive not to draw attention to themselves at all. A system whose errors are mostly experienced by people poorly placed to complain about them will generate fewer complaints, and a low complaint rate is easily mistaken for a low error rate.
That is not an argument that these systems are necessarily wrong. Border control is a legitimate state function and identity verification is a legitimate part of it. It is an argument that the feedback mechanisms which surface problems in domestic policing, complaints, litigation, press coverage and regulator intervention, all operate more weakly here, so the absence of visible controversy is weaker evidence of a well-functioning system than it would be elsewhere.
Where the rules sit
There is no single instrument governing AI at borders. In the UK the relevant framework is assembled from data protection law and its immigration exemption, human rights law, the Equality Act, and the Home Office's own policies. In the EU, the AI Act designates several migration and border management uses as high risk, which brings specific obligations, though the interaction between those obligations and existing national security carve-outs is still being worked through. In the US, there is no comprehensive federal framework, and the most consequential constraints to date have come from state legislatures, as in Illinois and Washington State.
Follow the coverage
PoliceAI News tracks borders and immigration technology as it develops: new deployments, data sharing disclosures, regulator findings, litigation and procurement records. The feed refreshes every 30 minutes.
View Borders and Immigration Stories