Four Audits, One Camera, and the Grade TSA Won’t Show You

An airport security checkpoint with a biometric kiosk in the foreground, blue light emanating from a screen scanning a face. The background shows a long terminal corridor with muted overhead lighting and a few blurred travelers. Institutional, slightly clinical atmosphere. Muted tones of grey, blue, and white. Photorealistic editorial style.

The Department of Homeland Security’s Inspector General wants you to know that TSA’s facial recognition program is basically fine. It also wants you to know that the part of the audit said to support that claim is classified, so you will have to take the agency’s word for it, which is the exact arrangement the entire program has run on since it started scanning faces at airport checkpoints.

That is the honest summary of OIG-26-27, released September 15, 2026, and it is only the newest entry in a pile of oversight reports that keeps growing while the program itself keeps expanding unbothered.

The Test You Are Not Allowed to Grade

DHS OIG ran covert tests at airport checkpoints to see whether TSA’s facial recognition and identification technology actually catches fraudulent IDs and persons of interest, which is the entire stated justification for the program’s existence. The results produced three findings and six recommendations. TSA agreed with five and flatly refused the sixth. Two of the six recommendations remain open and unresolved months after the audit closed.

And then, in the same paragraph, the report informs the reader that “additional details related to this part of our audit are classified or otherwise not available for public release.” No specifics on what the covert testers found, no breakdown of how often officers caught a fake ID versus missed one, nothing. The one part of this audit that speaks directly to whether the program works is the one part the public isn’t permitted to see.

Security agencies classify testing methodology as a matter of course, and there’s a defensible argument for not publishing a how-to guide for beating a checkpoint. But an agency that non-concurs with one sixth of its own inspector general’s recommendations, on the classified section, is not asking for the benefit of the doubt so much as demanding it.

The Vendor Who Let Itself In

The unclassified half of the audit is more concrete, and worse. OIG examined how TSA’s Credential Authentication Technology 2 units, the kiosks that scan your driver’s license or passport at the podium, handle the biometric and biographic data they collect. Routine deletion practices checked out fine. The problem was the vendor.

According to the audit, the CAT-2 vendor was able to access and extract sensitive passenger information, including driver’s license and passport images, during system troubleshooting and software enhancements, and TSA had no idea when this was happening. There was no policy governing it, no log tracking when data left the system, and no way to confirm the vendor actually deleted what it took. Passengers whose documents were pulled this way were never told.

TSA concurred with all three recommendations attached to this finding, which sounds like accountability until you notice that one of the three is still listed as open and unresolved. The agency agreed a contractor had unsupervised access to your passport photo and still hasn’t finished fixing it.

Three Watchdogs, One Stalled Bill

This is not the first time someone has told TSA this. In May 2025, the Privacy and Civil Liberties Oversight Board released a staff report capping a six year review of the same program. Its headline finding was that DHS’s own Chief Privacy Officer never conducted the compliance review required under internal DHS policy, and that TSA has offered no schedule for when, or whether, that review will happen. PCLOB’s recommendations included independent public audits, a real privacy impact assessment, and mandatory demographic accuracy testing from vendors before deployment, not after.

A year earlier, the Government Accountability Office reached a related conclusion from a different angle. GAO-24-106293 found that facial recognition accuracy has genuinely improved under laboratory conditions, but that almost nobody has rigorously studied how these systems perform in the field, across demographic groups, at the scale TSA is now deploying them. Improved in the lab and unverified in the wild is not the same claim as safe to use on the traveling public, though TSA’s messaging tends to obscure the difference.

Meanwhile, TSA’s own public factsheet still describes the program in the language of pure customer service, as a security enhancement, a convenience, entirely voluntary, with no penalty for opting out and photos deleted after a match except in a limited testing environment.

Every one of those assurances is now sitting next to an OIG finding about an outside vendor quietly copying passport images with nobody watching.

The factsheet has not been updated to mention it.

A Bill That Never Boards

Congress has had an off ramp sitting on the table for three years and has yet to take it. Senator Jeff Merkley first introduced a bill to ban TSA facial recognition outright in 2023; it died without a vote. The current version, the Traveler Privacy Protection Act of 2025, S.1691, is considerably softer, restricting rather than banning the technology, requiring a non-biometric alternative at every checkpoint, and limiting how long TSA can retain the data it collects. It has bipartisan cosponsors and has gone precisely nowhere since being referred to committee, a fate Merkley’s own office has spent years narrating in press releases that read increasingly like dispatches from a stalemate.

Put the four documents side by side and a pattern appears that no single report captures on its own. An inspector general audits the program and classifies the part that would tell the public whether it works. A privacy oversight board spends six years concluding that the agency responsible for auditing itself never actually did so. A government watchdog finds the underlying technology has been tested in laboratories but not in the world it is actually deployed in. And a bill written to address all three problems sits untouched in committee while the program it would constrain keeps expanding to more airports every year.

None of this requires a conspiracy. It only requires an agency confident enough in its own mission that it treats oversight as a formality to be managed rather than a question to be answered, and a Congress content to keep writing reports about the problem instead of legislating one out of existence. TSA is not hiding a coverup. It is doing something more mundane and more durable: it is simply outlasting everyone who asks it to explain itself.

Sources: DHS OIG, OIG-26-27: TSA’s Use of Facial Recognition Technology (September 2026); Privacy and Civil Liberties Oversight Board, Use of Facial Recognition Technology by TSA (May 2025); GAO-24-106293, Facial Recognition Technology: TSA Should Establish Goals and Measures for Evaluating the Impact on Screening (2024); TSA Facial Recognition Technology factsheet; S.1691, Traveler Privacy Protection Act of 2025.

Fediverse reactions

Discover more from Bureaucracy Times

Subscribe to get the latest posts sent to your email.