Immigration as a Test Case for Executive AI Governance
DHS deploys AI in immigration enforcement largely untested, undisclosed, and unreviewed, a preview of how AI could reshape executive power.
In the wake of the Sept. 11, 2001, attacks, the PATRIOT Act and the Homeland Security Act were enacted as urgent responses to reorganize and bolster the U.S. counterterrorism apparatus. Some of these authorities were intended to be temporary emergency measures. Subsequent reauthorizations and agency practice, however, transformed key elements of those laws into enduring infrastructure through which domestic surveillance expanded, became normalized, and ultimately extended well beyond the terrorism-related purposes that initially justified them.
Much of that infrastructure was first deployed to target noncitizen communities, among whom constitutional protections are weakest, judicial review is most deferential, and political accountability is limited. The watchlisting systems, biometric databases, and information-sharing networks developed in immigration enforcement did not remain confined there. Today, they have become part of the broader surveillance architecture that affects everyone.
Once again, these systems are being developed and normalized first on noncitizens before expanding to all. The Department of Homeland Security (DHS) is now deploying artificial intelligence (AI) systems that already exhibit many of the governance problems AI scholars warn could emerge as more capable systems enter government. These systems operate at a speed that can outpace meaningful oversight. They make accountability more difficult when decisions go wrong. And they do so with remarkably little public visibility into how they function or how they are used.
Records produced through recent Freedom of Information Act (FOIA) litigation by Just Futures Law, Pangea Legal Services, and Mijente show that Immigration and Customs Enforcement (ICE) operated roughly 42 AI tools internally as of May 2024, but only 23 tools appeared in DHS’s public AI Use Case Inventory at the time. Customs and Border Protection (CBP) operated approximately 75 AI systems in the same FOIA-era records, 62 of them active, a figure that has since converged with CBP’s public inventory page, which lists roughly 60 active use cases.
Taken together, these gaps are a live example of how AI is already reshaping the exercise of executive power.
In a recent article, Cullen O’Keefe, Alan Rozenshtein, and Christoph Winter introduced the concept of “ExecAI:” the use of advanced AI systems within the executive branch and the ways those systems could erode the separation of powers. They ask what happens when presidential directives can be executed without the institutional friction that human decision-makers often provide: opportunities for dissent, whistleblowing, meaningful attribution when errors occur, and enough time for courts to intervene.
The piece presents these as emerging challenges, but the immigration system offers a concrete case study because it already combines broad executive discretion, limited constitutional protections, and the rapid adoption of AI-enabled decision-making.
What Is Already Operating
The federal government has not needed frontier AI to begin reshaping executive power. It has done so through ordinary procurement and existing immigration authorities.
ImmigrationOS, ICE’s operational platform, combines government records and commercial data into a single picture that helps prioritize enforcement targets. Hurricane Score, an algorithm previously used in ICE’s Alternatives to Detention program, estimated the likelihood that participants would abscond based in part on demographic and case-related information, including characteristics that raise significant equal protection concerns. And the U.S. Citizenship and Immigration Services (USCIS) Asylum Text Analytics tool flags asylum applications for additional scrutiny and monitors attorneys and preparers as a network rather than reviewing cases in isolation.
FOIA records show USCIS expanded the tool nationally before the Privacy Impact Assessment required by the E-Government Act had been approved. Applicants are not informed when their case has been flagged, and officers must obtain special authorization before raising AI-derived findings during an interview.
These systems differ in purpose and design, but they reflect the same broader trend. AI is increasingly embedded in decisions about whom the government investigates, monitors, or subjects to additional scrutiny, often with limited public understanding of how those decisions are made.
Three Missed Opportunities for AI Governance
The FOIA records also point to three opportunities where governance could have altered this trajectory.
Under the Office of Management and Budget’s (OMB’s) 2024 guidance on agency use of AI, systems classified as safety- or rights‑impacting are supposed to undergo real‑world testing and an AI impact assessment—covering accuracy, bias, and reliability—before agencies deploy them operationally. Independent testing at this stage could have identified problems before AI systems became embedded in enforcement decisions, when errors are cheaper to catch and correct.
DHS’s own internal review suggests that opportunity was largely missed. The department’s Office of Inspector General found that DHS has not done enough to demonstrate that its AI systems comply with required governance and risk‑management practices, including documenting how the systems are tested and evaluated for privacy and civil rights impacts. Testing that should have functioned as a gate before deployment appears, in practice, to have been treated as a formality completed alongside it.
The second comes at the point of action. Human review matters only if it serves as a meaningful check rather than a procedural formality. Hurricane Score, the ICE algorithm used to estimate a participant’s likelihood of absconding, illustrates why. The algorithm incorporated information about the level of monitoring a participant had already received. Someone placed on more intensive supervision therefore became more likely to be classified as high risk, which could justify even greater supervision. Without meaningful human review, automated systems can create feedback loops that reinforce their own conclusions.
The third opportunity is transparency. Courts, Congress, researchers, and the public cannot meaningfully evaluate systems that remain largely hidden. When agencies disclose only a small fraction of the AI tools they operate, accountability becomes reactive rather than preventive. By the time errors become visible, those systems may already be deeply embedded in government decision-making.
That is the stage we are in now.
The Scale of AI-Assisted Enforcement
ICE has awarded contracts to 13 private companies to provide nationwide “skip tracing” services, leveraging commercial data brokers and AI‑assisted research to locate individuals for immigration enforcement. Federal contracting records and investigative reporting indicate that each contractor may receive up to 50,000 cases per month under these agreements.
At the same time, ICE is moving forward with plans to establish a 24/7 social media surveillance operation, hiring nearly 30 private contractors to monitor platforms such as Facebook, Instagram, TikTok, X, YouTube, and Reddit for deportation leads, and has procured access to an AI‑driven platform capable of analyzing more than 8 billion posts per day. Thirty contractors cannot meaningfully review 8 billion posts a day. This is enforcement operating at a scale and speed no human review process was designed to match. As that scale grows, mistakes become harder to catch before they cause irreversible harm.
This is why it is important to embed privacy and surveillance protections from the outset in government technology. Infrastructure first developed where legal protections are weakest rarely remains confined there. The data systems supporting immigration enforcement do not neatly distinguish among noncitizens, family members, neighbors, or bystanders whose information enters the same networks; as we saw with post‑9/11 surveillance authorities built in the name of national security, tools first justified in immigration and border contexts quickly expanded to cover broader populations.
As the scale of enforcement grows, so too does the potential reach of those systems beyond the population on whom they were first tested.
From Theory to Practice
O’Keefe, Rozenshtein, and Winter pose 33 questions about ExecAI and the rule of law, organized around empowering citizens, strengthening Congress and the courts, and reforming internal executive checks. Their framework provides a road map for understanding how AI may reshape executive power.
The immigration system offers an opportunity to begin answering many of those questions today.
A targeting model developed and validated in immigration enforcement does not require a new legal theory to reach citizens. It requires only access to different data. The history of post‑9/11 surveillance shows how systems first built where legal protections were weakest can expand as the underlying architecture becomes normalized. For example, PATRIOT Act powers and watchlisting regimes that were initially justified as counterterrorism tools now underpin routine data collection and screening affecting millions of Americans. The AI infrastructure being built today appears to follow the same path, only faster and with far less public visibility.
The immigration system therefore offers more than an illustration. It provides a setting in which governance reforms can be developed and evaluated against technologies that are already operating rather than hypothetical future systems.
Three reforms emerge from the record to date. Additional FOIA litigation by Just Futures Law is underway to continue uncovering AI uses in immigration enforcement, focusing on ICE systems including ELITE and ImmigrationOS. That litigation exists because DHS decides for itself which of its AI systems are sensitive enough to withhold from public view. The full extent of the executive branch’s use of AI in immigration enforcement and adjudications will likely become clearer over time.
The first is disclosure. USCIS training materials state that applicants are not informed when an algorithm flags their case, and officers require special authorization before confronting applicants with AI-generated findings. Individuals subject to AI-assisted enforcement or adjudication should receive notice and an opportunity to challenge those determinations.
The E-Government Act of 2002, the foundational federal e-government and information governance statute, created a government-wide privacy impact assessment (PIA) requirement. It requires agencies to analyze how new information systems collect, use, and share identifiable data, and to build privacy protections into those systems before they go live.
The FOIA record, however, shows it was treated as a post-hoc paperwork obligation rather than a genuine gate. Strengthening enforcement of that requirement, specifically by suspending deployment of any system operating without a completed and publicly available PIA, would not require new legislation. It would require agencies to follow the existing law.
The second is meaningful human review. Systems such as Hurricane Score and ImmigrationOS nominally keep a human in the decision loop, but they also illustrate how quickly that safeguard becomes ineffective if review is reduced to procedural approval rather than genuine independent judgment. Human-in-the-loop requirements are also asymmetric by design: They are built to catch cases where the AI recommends a harsher outcome than a human would, but they do nothing to catch cases where the AI is wrong in ways a human reviewer, rushed or deferential to the system, fails to notice. That asymmetry is compounded by what these systems are being asked to assess in the first place. A risk score or a targeting flag reduces a person’s ties to family, community, and livelihood to inputs a model can weigh; a meaningful human reviewer has to hold the parts that don’t reduce, which is exactly the judgment a rushed or procedural review has no room for. Human review requires documented standards and meaningful accountability when those standards are not met.
The third is independent oversight. The fact that DHS currently determines for itself which AI systems are sufficiently sensitive to withhold from public disclosure is precisely the kind of self-certification regime the ExecAI agenda warns against: agencies determining how much scrutiny their own systems should get. Independent auditing would provide far greater confidence that government agencies are accurately assessing the risks posed by their own systems.
None of these reforms requires waiting for comprehensive federal AI legislation. Existing statutory authority, including the E-Government Act’s privacy impact assessment requirement, the Privacy Act’s rules for systems of record, and OMB’s AI governance memo, already provide avenues to strengthen disclosure, oversight, and procedural safeguards.
States have been among the most active actors in pursuing these protections through procurement rules, data-sharing restrictions, and transparency requirements governing public-sector AI. Whether they will be allowed to continue doing so remains an open question. A December 2025 executive order seeks to limit state AI governance despite acknowledging that no comprehensive federal framework exists yet. It uses litigation threats and fiscal incentives to discourage states from adopting standards the administration considers burdensome. The conflict echoes immigration policy, where federal efforts to preempt state action have often focused on punishing jurisdictions that adopted different policy choices before establishing a national alternative.
Immigration is not simply one example of executive AI governance. It is where many of the rule-of-law questions surrounding executive AI are already being tested in practice. The systems are operating. The legal authorities exist. The people most affected have the fewest opportunities to challenge them.
* * *
In March 2025, ICE agents arrested Mahmoud Khalil, a Columbia University student and prominent pro-Palestinian activist after DHS claimed that his student visa, and then his green card, had been revoked. His case was an early test of the State Department’s AI-enabled “Catch and Revoke” initiative, which scrapes social media to identify foreign nationals who appear to support Hamas or other designated terror groups and cancel their visas. Framed as a counterterrorism measure, the tool functions as a dragnet capable of sweeping up ordinary, constitutionally protected speech. It is one piece of a much larger build-out: DHS’s own AI use case inventory shows that immigration components such as ICE, CBP, and USCIS already rely on AI for social media surveillance, visa revocations, targeting “self‑deportation,” and triaging asylum and benefits cases—applications that directly affect who is arrested, detained, or allowed to stay. Reporting based on internal DHS and CBP documents has revealed, for example, that CBP uses an AI tool to scan online content for “sentiment and emotion” to generate enforcement leads, and has tapped into the online advertising ecosystem to track people’s movements using commercially sourced location data.
Immigration is also where durable governance safeguards can first be built. The window to establish disclosure requirements, meaningful human review, and independent oversight while these systems are still evolving is not open ended. Every month that passes is another month in which this infrastructure becomes more deeply embedded, for a population that was never going to be the last one it reached.
