CRBC News
Security

You Can End Up in a Federal Biometric Database Without a Criminal Record — What HART Means for Your Face

You Can End Up in a Federal Biometric Database Without a Criminal Record — What HART Means for Your Face
Image: Deposit Photos

HART (Homeland Advanced Recognition Technology) is DHS’s planned biometric database to replace IDENT and is projected to hold about 260 million identities, including face and iris data with possible future additions like voice or DNA. Independent evaluations (including NIST and a 2024 U.S. Commission on Civil Rights report) have documented substantial demographic accuracy gaps, with some groups experiencing 10–100× higher false-positive rates. Key governance questions remain unresolved: data retention, who can query HART, remedies for false matches, and whether independent, real-world audits will occur. Without clear oversight, the system’s scale and the permanence of biometric data pose serious civil liberties risks.

At a U.S. border checkpoint, a camera can scan your face in under a second. In that instant, a remote database may confirm who you are — or think it does — and that determination can shape whether you move on or are stopped. The public deserves clear, concrete answers about what happens during that moment and how the collected data are stored, shared, and governed afterward.

What HART Is

HART (Homeland Advanced Recognition Technology) is the Department of Homeland Security’s planned replacement for the legacy IDENT biometric system. Planning documents projected HART could contain roughly 260 million identities, a scale larger than the population of many countries. HART is multimodal: it currently includes face images and iris scans and reportedly contemplates adding voiceprints, DNA profiles, and physical markers such as scars or tattoos.

Technical and Contract Details

Northrop Grumman won approximately $95 million to develop the first phases of the system, and HART is designed to run on Amazon Web Services’ GovCloud infrastructure. Each biometric modality represents a different technical method for recognizing people across varied lighting, distance, and image quality conditions — and each modality brings distinct privacy and security implications.

Why Biometrics Are Different From Passwords

Unlike a leaked password, you cannot change your face or iris. A large-scale breach exposing biometric identifiers would leave affected people permanently vulnerable in ways a password reset cannot remedy. That permanence makes governance, oversight, and strong technical safeguards far more consequential.

Documented Accuracy Gaps and Operational Risk

Demographic disparities in facial-recognition performance are well documented. The National Institute of Standards and Technology (NIST) evaluated hundreds of facial-recognition algorithms and found that, in one-to-one verification tests, false-positive rates for some Asian and Black cohorts were often 10 to 100 times higher than for Caucasian cohorts. The U.S. Commission on Civil Rights’ 2024 report highlighted these gaps and warned of especially acute consequences in border and immigration contexts.

One-to-one verification (checking whether two photos match) is a different technical task from a one-to-many search (scanning one face against millions of records). Error rates and the operational consequences can scale dramatically in one-to-many searches.

Governance Questions That Matter

The central policy problem is not only technical capability but the absence of clear, public answers to basic governance questions: How long are records retained? Which agencies or contractors may query HART and under what legal authorities? What remedies exist for someone incorrectly matched by the system? Are independent audits performed to assess demographic performance in real-world deployments? Instances of secret tracking or use without meaningful oversight show how fast accountability gaps can widen when governance lags behind deployment.

Why This Matters

Border identity checks are a routine government responsibility, and large-scale identity infrastructure is not intrinsically illegitimate. What is harder to defend is deploying a system touching the records of roughly 260 million people — storing biometric identifiers that are far more difficult to replace or revoke than passwords — without a governance architecture proportionate to that reach. Transparency, independent testing, clear access rules, and effective remedies for false matches are essential to preserve civil liberties and public trust.

Your face is not a password. Treating it like one, without commensurate oversight and accountability, is the core governance shortfall HART still needs to fix.

Help us improve.

Related Articles

Trending