Twenty-five years since Sept. 11, 2001, much of the legal and institutional architecture erected in response to the terrorist attacks still stands. The Department of Homeland Security, which was created to fill the intelligence and law enforcement gaps the attacks had exposed, has become one of the largest federal agencies in the country. The 2001 Authorization for the Use of Military Force, which Congress passed to bless a military response to the attacks, remains on the books and has been used as legal justification for operations in various countries. Guantanamo Bay, which opened in 2002 to house “the worst of the worst” terrorists responsible for the attacks, has been home to more than 800 detainees over the years, 15 of whom remain there today, and none of whom have been tried for perpetrating the attacks. And law enforcement powers expanded in the name of counterterrorism, including expanded surveillance authorities and broadened material support statutes, have largely outlasted the initial threats that inspired them and have been repurposed for new circumstances.

Rather than focusing on the well-documented debates over whether the response to 9/11 was good or bad, or on the day’s enormity, Lawfare editors and contributors examine how 9/11 remains—or doesn’t—embedded in current legal and policy frameworks. Twenty-five years later, our editors and contributors set out to answer the question: What aren’t people seeing about that legacy?


Executive Branch Surveillance & Privacy Terrorism & Extremism

Ordinary Origins: How 9/11 Built Today's Immigration Enforcement Machine

Chinmayi Sharma
Friday, September 11, 2026, 4:55 AM
Post-9/11 data-sharing systems built for security quietly became the infrastructure for today’s automated immigration enforcement.
DHS ICE and Enforcement and Removal Operations agents in Baltimore, 2023 (usicegov, https://tinyurl.com/36pz3bjd, Public Domain)

[Editor's note: This piece is part of Lawfare's collection "9/11 at 25: The Legal Architecture of the War on Terror, Twenty-Five Years On," examining how 9/11 remains—or doesn't—embedded in current legal and policy frameworks, a quarter century after the attacks. Read the full collection here.]

***

The Department of Homeland Security’s fingerprint repository holds more than 290 million distinct identities and answers nearly 350,000 biometric queries a day from state and local law enforcement, the intelligence community, and foreign governments. The State Department says it now monitors and re-evaluates more than 55 million people who hold a U.S. visa, continuously, against information that comes to light after issuance. None of this was built in the past two years. Very little of the sharing was built for immigration enforcement, and none of it was built for what it now does.

Sept. 11, 2001 recast immigration as a national security problem, and a national security problem invites an intelligence solution: more data, more sources, fewer barriers between them. That reframing did four things at once. It changed how the public and the political class talked about immigrants. It produced a new agency, then statutes and executive orders that expanded what the executive could do without asking permission from Congress. It moved the courts toward deference, because immigration was now national security, where deference to the political branches runs deepest. And it built the technical capacity to execute. Enforcement then became a political mission measured in volume; volume demanded efficiency, and efficiency demanded automation. None of it was built for end-to-end automated enforcement. That ambition arrived around 2018. By then the capacity was standing, the law authorized it, the doctrine would not review it, and the public had been taught to call it security. What made today’s system possible was a seemingly ordinary response to an extraordinary tragedy.

From Immigration To National Security

Two thousand nine hundred seventy-seven people were killed on 9/11; 343 of them were New York City firefighters. Within weeks, letters carrying anthrax began arriving on the doorsteps of major media outlets and members of Congress; five people died. At that moment, no one in government had reason to think the calamities would end. And the facts about the hijackers pointed toward immigration systems: They had entered on visas the government issued, most were in lawful status on the day of the attacks, and the ones who were not had gone unnoticed. The lesson drawn was not that immigration law had failed. It was that the government had not been looking hard enough at what it already knew.

The 9/11 Commission supplied the organizing principle for the response: The problem was the government’s “resistance to sharing information.” Valuable information sat in databases not usually treated as intelligence, including customs and immigration records. Border security, the commission’s staff concluded, had not been understood as a counterterrorism tool; now it had to be. The diagnosis was brutally simple: The information that could have prevented 9/11 had been there, but “someone had to ask for it.” A cataclysmic national security event turned on access to immigration data; the prescription to the diagnosis was to build a system that made asking unnecessary.

The country had connected immigration and terrorism before. After the first World Trade Center bombing in 1993, Congress required cities to permit employees to share immigration-status information with federal authorities. But the Immigration and Naturalization Service (INS) had fewer than 2,000 immigration agents, and identifying someone in a local jail for federal enforcement still depended on a local official choosing to ask and a federal official choosing to answer. Six weeks after 9/11, then-Attorney General John Ashcroft made the new theory explicit: Mundane visa overstays would be used as counterterrorism tools, and criticism of the administration’s tactics was cast as assistance to terrorists. The narrative born of 9/11 remains with us today: Immigration is a national security concern.

Building The Information-Sharing State

The institutional response mirrored the prevailing narrative: Immigration and national security were inextricably tied. The Homeland Security Act of 2002 pulled 22 agencies and roughly 180,000 employees into a new Department of Homeland Security, the largest federal reorganization since the creation of the Department of Defense. DHS was given an “overriding and urgent mission” centered on counterterrorism: prevent attacks, reduce the country’s vulnerability to them, and minimize the damage when they occurred.

Immigration appeared later in the statutory list, almost as an afterthought, as a function inherited from the now-dissolved INS. The ordering captured the change. Immigration administration had been moved inside an institution whose organizing purpose was security. The statute also embedded the architecture that matters here: DHS was to ensure information sharing among border-management, law-enforcement, and intelligence databases, backed by the data-mining and analytical tools needed to use what those systems produced. Immigration and national security were not merely placed in the same department. Their information systems were supposed to speak to one another.

Congress made that command concrete the same year. The Enhanced Border Security and Visa Entry Reform Act ordered an “interoperable electronic data system” giving immigration officials current and immediate access to federal law-enforcement and intelligence databases. Two years later, the intelligence-reform statute created an information sharing environment built around “direct and continuous online electronic access” and access to data rather than merely to particular systems or networks. By 2007, Congress envisioned the “full range of analytic and operational activities” occurring without centralizing the underlying information. That distinction was consequential. A single warehouse is expensive, visible, and bounded. Interoperability lets separate systems remain where they are while making their contents available across institutional lines—and lets new systems plug in later.

The category of information eligible for sharing was correspondingly broad: information that could improve identifying or investigating a suspected terrorist—a definition that appeared boundless. Congress imported that definition into the Information Sharing Environment in 2007, while executive orders pushed agencies toward ever broader information-sharing—including information that might seem wholly unrelated to counterterrorism—within the executive branch and with state, local, tribal, and private-sector partners. The point was not to build one database. It was to build a standing capacity to reach across as many of them as possible.

The legal architecture was already unusually deferential. Immigration doctrine had long committed questions of admission and removal largely to the political branches, with courts applying only narrow review to decisions by Congress or the president. Enforcement doctrine gave the executive more room still to decide whom to pursue and whom to remove. Recasting immigration as national security layered one deferential domain onto another.

The biometric border shows how 9/11 changed the political price of that project. Congress had ordered an automated entry-exit system in 1996, but resistance from border states, Canada, and industry stalled it; Detroit’s mayor warned the system could turn downtown into a “virtual parking lot.” In 2000, Congress expressly promised no new documentary or data-collection requirements. Six weeks after 9/11, however, the PATRIOT Act ordered the system built “with all deliberate speed” and directed particular attention to biometric technology.

Biometric entry was fully operational at every port by December 2006. Biometric exit is taking far longer and remains incomplete; as of 2025, it is only operational in commercial airports, even after 17 years and eight statutes. Even now, part of the system is funded by the “9-11 Response and Biometric Entry-Exit Fee,” a surcharge on employers sponsoring certain H-1B and L-1 workers. A Customs and Border Protection (CBP) rule taking effect Sept. 9 extends that fee to extension petitions as well, substantially expanding the share of sponsored petitions subject to it. Twenty-five years on, a fee named for the attacks still helps pay for the machinery built in their name.

Interoperability Moves Inward

The same architecture extended beyond the border through fusion centers. Fusion centers are state owned and operated intelligence hubs—roughly 80 nationwide—that gather, analyze, and share threat-related information among federal, state, local, tribal, and territorial agencies. They made the post-9/11 information-sharing project physically present inside state and local government. Rather than combine federal and local databases into one warehouse, the governing guidelines embraced access to “a variety of disparate databases.” Counterintuitively, and somewhat ironically, privacy objections to immigration surveillance justified the shift to an interoperable apparatus rather than an integrated one. Instead of forging a single, centralized database, the government intentionally kept systems separate but interconnected, therefore ensuring the apparatus remained nimble and extensible.

Congress then put on paper the deepening marriage of immigration enforcement and counterterrorism. In 2007, lawmakers required DHS officers and analysts assigned to fusion centers to receive appropriate access to all relevant federal databases and information systems, and they prioritized the deployment of CBP and Immigration and Customs Enforcement (ICE) personnel to centers located near borders. By 2017, ICE officials were detailed to 11 centers. The immigration function arrived through personnel and access even though immigration was not the centers’ stated purpose.

Their reach was also enormous and their mission, malleable. A bipartisan Senate investigation in 2012 found that it could not identify a fusion-center report that uncovered a terrorist threat; much of the reporting concerned ordinary crime, and federal spending could be estimated only within a range of $289 million to $1.4 billion. DHS nevertheless continued to fund their maturation and enhancement. Fusion centers are thus a useful miniature of the larger story: Counterterrorism supplied the rationale; interoperability supplied the design; and the resulting capacity traveled well beyond terrorism.

Secure Communities carried the same logic into local jails. The underlying fingerprint systems predated 9/11: After the Border Patrol released a serial-murder suspect because INS and FBI systems could not communicate, Congress pressed to link them. Post-9/11 funding and mandates produced the bridge between DHS’s IDENT system and the FBI’s fingerprint system. Secure Communities, launched in 2008, then made fingerprints that local jails already sent to the FBI automatically run against immigration records as well. The local decision whether to notify ICE—a phone call that local politics could reach—was engineered out of the process. Interoperability is no longer a passive feature; it is an active trigger. The commission’s failure had been a request no one made. The remedy obviated the need for one.

Section 287(g) moved people and data through the same channels. The 1996 statute authorizing federal deputization of state and local officers as immigration agents went unused for six years. The first agreement came in Florida in 2002 and trained officers serving on post-9/11 domestic-security task forces. From one agreement, the program grew to 67 by 2008, much of that growth occurring in Southern jurisdictions responding to new immigrant populations rather than terrorist threats. It fell to 35 by the end of the Obama administration, passed 1,000 agreements in September 2025, and now exceeds 2,000. Beyond deputizing officers, 287(g) added new data flows: ICE supplied participating agencies with secure connections, workstations, and fingerprint equipment linking them directly to federal immigration databases, and trained deputized officers to search and enter information into those systems. The legal authority was old. The national security reframing reinvigorated it, and the infrastructure made it scalable.

The failed effort to make government data speak a common public language paved the way for the rise of private vendor involvement in immigration enforcement. The National Information Exchange Model, launched in 2005 as a common data standard, never achieved universal adoption; by 2010, six of 26 surveyed agencies did not use it at all, and only its two founding agencies used it at enterprise scale. Vendors increasingly supplied the interoperability that ultimately mattered: Proprietary data models and platforms could connect systems the government had not standardized itself.

And where government systems did not contain enough information, agencies bought it. The Privacy Act governs systems of records operated by or on behalf of an agency, but federal officials treated commercial data resellers’ databases as outside that rule because the vendors served multiple customers. By 2006, 91 percent of reported federal reseller use was for law enforcement or counterterrorism, and ICE was already DHS’s largest customer; agencies commonly bought address and vehicle information—where people were. The scale advantage was dramatic: in one 2005 test, a TSA contractor sent roughly 240,000 passenger names to three commercial providers and received more than 100 million records back. Interoperability could connect government silos; the commercial market could fill the gaps between them.

Programs Change; The Pipes Remain

This architecture survived precisely because the most visible programs did not have to. Congress defunded Total Information Awareness in 2003, but the prohibition itself contained an exception for certain counterterrorism intelligence processing and collaboration tools described in a classified annex. The Pentagon’s own advisory committee warned that tools of this kind, used against people without an adequate predicate, risked becoming the 21st century equivalent of general searches. Seven months after the ban, the Government Accountability Office counted 199 data-mining efforts across 52 agencies, 77 of them drawing on other agencies’ data and only 14 classified as counterterrorism. The cross-agency plumbing had already spread beyond the program Congress killed.

The National Security Entry-Exit Registration System (NSEERS) is the sharper example. The post-9/11 special-registration program fingerprinted, photographed, and interviewed 83,519 nonimmigrant men from 25 designated countries and placed 13,799 of them in removal proceedings during its nine years in operation. The system was suspended in 2011 and repealed in 2016. But the government’s explanation for repeal was that the information was already captured through “more comprehensive and efficient systems”: CBP now fingerprinted and photographed nearly all nonimmigrants, regardless of nationality. A notorious program aimed at 25 countries disappeared because universal biometric collection had made it redundant.

Secure Communities likewise demonstrated how little policy reversal required infrastructure reversal. DHS “discontinued” the program in 2014 but replaced it with one that continued relying on the same booking fingerprints sent by local law enforcement to the FBI. A January 2017 order revived Secure Communities; a January 2021 order revoked that order in a sentence and said nothing about the fingerprint pipeline. Three administrations changed policy at the surface. None dismantled the pipes. The executive order that had directed an interoperable terrorism-information-sharing environment in 2005—and made sharing with state, local, tribal, and private-sector entities a priority—remains in force today.

From Capacity To Automation

By 2018, the ambition had a name. A presidential memorandum described the “national vetting enterprise” not as a new program but as the coordinated work agencies were already doing. It claimed no new authority. Instead, where authorized and appropriate, agencies were to process information on a recurrent basis using relevant federal intelligence and law-enforcement information—the same categories Congress had ordered connected in 2002—and a National Vetting Center would coordinate the work.

When I wrote about the National Vetting Enterprise in 2019, the ambition still surpassed the technology. A 2017 executive order demanded a process to assess whether an applicant was likely to become a “positively contributing member of society,” and ICE asked industry for a system that could make that determination continuously. Fifty-four technical researchers responded that no computational method could reliably or objectively measure the traits ICE wanted. ICE ultimately shifted the project from a technology contract to a labor contract, and the National Vetting Center later said it did not use automated analysis to discover predictive patterns or anomalies.

But automation’s siren song could only be resisted for so long. The enforcement mission itself was growing in scale—first a little, then a lot. Interior enforcement staffing had grown from fewer than 2,000 agents in the INS era to roughly 21,800 positions in fiscal 2024, with ICE appropriations above $10 billion. After 2024, though, the expectations and the resources to fund them grew outlandishly. The July 2025 reconciliation act then appropriated $191 billion for DHS through fiscal 2029, nearly three-quarters directed to ICE and CBP; a second reconciliation act in June 2026 added another $69.5 billion. One ICE officer testified that a team of nine to 12 officers had been directed to target eight arrests a day. A mission funded and measured this way cannot depend on humans making one individualized decision at a time. Volume demands efficiency; efficiency demands automation. And doctrine developed in a world that already granted exceptional deference over immigration and national security gives the executive unusual room to use the machinery Congress built.

The legal ambition has now caught up. In January 2025, Executive Order 14161 directed agencies to vet and screen “to the maximum degree possible” noncitizens seeking admission and those already inside the United States, including for “hostile attitudes” toward American citizens, culture, government, institutions, or founding principles—a standard no more computable than the one vendors could not build in 2017.

In November 2025, DHS proposed continuous immigration vetting under which lawful residents could be required to submit biometrics at any time until citizenship. The technology still cannot deliver true end-to-end immigration enforcement, but the infrastructure to house such a biometric capability already exists. The databases are connected, the access rules are in place, the biometrics are already collected, state and local systems feed federal ones, commercial vendors supply what the government lacks, and the policy layer can be changed by signature.

The people who laid this groundwork were not designing for what it does today. The Commission’s diagnosis was not irrational. The pre-9/11 objections to automated entry-exit focused on commerce and federalism. Fusion-center guidelines were written in part to protect privacy. Secure Communities solved a real interoperability problem. But together these choices produced a standing immigration enforcement capacity for which no administration has had to claim full accountability, insulated by a narrative that calls it security, statutes that authorize it, and doctrine that reserves its deepest deference for those magic words.

That is the harder problem. No single scandal, lawsuit, program, or administration is the cause, so no single one is the cure. But it is also an opportunity. Every pipe was laid by a statute, a rule, a memorandum, or a contract, and each remains reachable through ordinary law. Reversal is still available through ordinary democratic processes. How that software Pangea actually works, and why the remedies aimed at it keep missing, is the subject of a companion piece.


Chinmayi Sharma is an associate professor at Fordham Law School. Her research and teaching focus on internet governance, platform accountability, cybersecurity, and computer crime/criminal procedure. Before joining academia, Chinmayi worked at Harris, Wiltshire & Grannis LLP, a telecommunications law firm in Washington, D.C., clerked for Chief Judge Michael F. Urbanski of the Western District of Virginia, and co-founded a software development company.
}