In early 2026, TSA expanded its facial recognition program to more than 250 airport security lanes across the United States. CBP has been running biometric checks at international departure gates for several years. What began as a limited pilot has become standard infrastructure — and if you flew through a major U.S. airport recently, there is a real chance your face was captured and compared against a government database before you reached the gate.
The program is different in kind from a lot of other digital privacy concerns because it operates in physical space without your active participation. You don’t download an app, agree to terms, or sign in. You stand in line, and your face is scanned.
Understanding what this means requires separating the technology from the legal framework, and both of those from the practical question of what you can actually do about it.
What the TSA Facial Recognition Program Is
The TSA facial recognition program runs through Credential Authentication Technology (CAT-2) units installed at airport security checkpoints. When you approach the lane, the unit captures a live image of your face, compares it against a database of government-issued identity photos, and verifies that the face in front of it matches the person named on the boarding pass being presented.
The verification happens in seconds. When it works, you move through. When there’s a mismatch — which can result from image quality, photo aging, or a database gap — a TSA officer performs a manual document review.
The databases used for comparison include photos from Department of Motor Vehicles records, U.S. passport images from State Department records, visa photos, and DHS Biometric Identity Management System (IDENT) records. These databases already exist. TSA isn’t building a new biometric database from scratch — it’s accessing records already on file to perform real-time comparison.
What Data Is Actually Kept
For U.S. citizens at domestic checkpoints: TSA’s program documentation states that images of U.S. citizens taken at CAT-2 units are deleted immediately after the identity comparison is complete. The photo is not added to any TSA database or retained for future use. A log of the match result — confirmed or unconfirmed — is kept for a limited period for auditing and program evaluation.
This applies when the system processes a normal, clean verification. Images flagged for manual review or associated with security incidents may be retained longer under different policies.
For travelers at CBP international departure gates: The rules are different. CBP’s Biometric Exit program, which runs at international departure terminals across major airports, retains biometric data based on citizenship.
Photos of U.S. citizens departing the country are held for up to 12 hours and then deleted. Photos of non-U.S. citizens are enrolled in IDENT, where they may be retained for up to 75 years as part of the traveler’s biometric identity record.
This asymmetry matters. If you are a foreign national traveling through U.S. airports, your facial biometric data becomes part of a long-term government record. If you are a U.S. citizen, the nominal retention is short — but “nominal” is doing real work in that sentence, because the policies that govern what happens in non-standard cases are less clearly documented.
The Opt-Out Right
You can decline facial recognition at TSA security checkpoints.
TSA’s policy allows passengers to request alternative identity verification through a manual document check — an officer physically reviews your ID and boarding pass the traditional way. You are not subject to additional screening or scrutiny for making this request, and you cannot be denied boarding for declining the facial scan.
In practice, execution is inconsistent. Some passengers report the opt-out being handled smoothly and without friction. Others report confusion from agents who are unfamiliar with the policy, delays, or mild pressure to use the standard lane. The policy exists and is documented in TSA guidance; the operational reality varies by lane, airport, and shift.
At CBP biometric boarding lanes, U.S. citizens also retain the right to opt out and receive alternative processing. The procedure may require involving a supervisor, which adds time. The right is real, but using it requires asserting it clearly.
Non-U.S. citizens do not have the same opt-out right at CBP departure checkpoints under current DHS rules. A DHS rule that took effect on December 26, 2025, expanded CBP’s authority to collect facial biometrics from additional categories of travelers, including some who had previously been outside the program’s scope.
How This Differs From a Border Device Search
If you’ve read about border device searches — CBP agents manually reviewing photos, messages, and documents on your phone when you enter the United States — it’s worth being clear that airport facial recognition is a different program, with a different legal basis and different implications.
Device searches involve accessing the content of a device you own: photos, messages, documents, browser history. CBP’s border search authority allows this without a warrant and without needing to show suspicion. The privacy concern is about what personal content can be read, extracted, or copied.
Facial recognition is identity verification using biometric data. The privacy concern is different: it involves collecting a biometric identifier — your face geometry — that cannot be changed, correlating it against existing databases, and potentially retaining it as part of a long-term identity record.
Both touch on personal data. Neither requires a warrant. But they answer different questions. Device searches expose the content of your digital life. Facial recognition captures a permanent physical identifier and adds it to government identity infrastructure.
The risks compound rather than cancel. If you are concerned about both, the steps for limiting each are different — opting out of the facial scan at the checkpoint is separate from managing what is stored on your device before you travel.
The Legal Landscape
There is no comprehensive federal biometric privacy law in the United States. Protection comes from a patchwork of state laws, program-specific policies, and some constitutional cases still working their way through courts.
Illinois has the nation’s strongest biometric privacy law (BIPA), which requires informed written consent before collecting biometric identifiers including facial geometry. Illinois residents haven’t successfully used BIPA to block federal airport biometric programs — federal programs operate under federal authority that generally preempts state law in these contexts.
Several states enacted biometric privacy laws in 2025 and early 2026, building on frameworks similar to Illinois and Texas. These laws create meaningful protections for biometric data collected by private companies, but government biometric programs at transportation hubs exist in a different legal space.
In the EU, airport facial recognition is subject to the GDPR and the EU AI Act’s restrictions on biometric identification in public spaces. High-risk biometric surveillance in publicly accessible spaces is heavily restricted under Article 5 of the AI Act, with limited exceptions. The contrast with U.S. policy — where the programs have expanded rapidly with limited legal constraint — is substantial.
What Is Coming Next
TSA has publicly indicated its intention to expand facial recognition to most major U.S. airports. The current deployment of more than 250 lanes represents meaningful scale, but it is not yet universal.
Airlines have begun running their own biometric boarding programs at departure gates, separate from CBP and TSA. Under these programs, passengers check in biometrically with the airline directly, and gate agents use a quick facial scan instead of scanning a boarding pass at boarding. These programs are voluntary and opt-in — passengers can decline and board with a traditional boarding pass — but as they become standard at more airports, the default is shifting toward biometric interaction.
The data collected through airline biometric boarding is subject to the airline’s own terms of service, not federal program policies. Data retention, use, and sharing with third parties varies by airline and is governed by whatever the airline’s privacy policy says.
What to Think About for Your Personal Files
Facial recognition at airports captures biometric data — your face. What it does not do, in the standard checkpoint context, is access the content of your phone, photos, documents, or personal files.
If you are concerned about both your biometric data and your personal digital content when you travel, the considerations are parallel but separate.
For biometric data at checkpoints: knowing the opt-out right exists, and being willing to use it, is the main practical tool available under current law.
For personal files and photos during travel: border agents have the authority to conduct device searches at ports of entry, which is a different risk with different mitigations. Keeping sensitive personal files in encrypted cloud storage — accessible only through a secure app once you’ve arrived — rather than stored locally on your device keeps them out of scope for a device inspection. Files that aren’t on the device at the time of a search can’t be searched.
Your biometric data and your personal file collection are both worth protecting. The tools and legal frameworks for each are different, and it helps to understand which protection applies to which risk.
The Longer Question
Facial biometric data collected at scale has value that goes beyond any current stated purpose. A database of traveler face scans, combined with future technology improvements, creates potential uses — tracking movement through public spaces, correlating identities across systems, retrospective identification — that don’t exist today but are plausible in five or ten years.
Biometric identifiers are permanent. Unlike a password or an account number, your face can’t be changed if it is compromised or misused. That permanence makes decisions about collection more consequential than they might appear at a Tuesday morning security checkpoint.
The opt-out exists under current policy. Using it is a legitimate choice, and an opt-out that requires asking for it doesn’t become unavailable just because most travelers don’t know it’s there.