Skip to content

Risk Digest

How to Challenge AI Evidence in ICE Detention Cases

When a client is detained by ICE, AI-generated evidence—from facial recognition to address extraction—may be error-prone and undisclosed. This verification workflow gives immigration attorneys a step-by-step framework to discover, preserve, and litigate the role of AI tools in enforcement actions.

By Editorial TeamUpdated Jul 27, 2026Verified Jul 28, 2026
REPORTED — UNVERIFIED
Jurisdiction
US Federal
Court
Immigration Court
AI tool named
Mobile Fortify
Ruling date
Jul 14, 2026
Source document
View primary court order ↗
Last verified
Jul 28, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

The first legal question in a case like Lorenzo Thompson’s is usually not “Was AI used?” It is narrower and more useful: what did the officer rely on, what system or contractor may have supplied the lead, and what records will disappear if counsel waits?

Lorenzo Thompson’s detention gives that question a concrete setting. Thompson, a Southwest Airlines flight attendant, was detained by ICE at Nashville International Airport on July 14, 2026, while working. Public reporting says he entered the United States on April 17, 2021, on a six-month tourist visa, has a pending asylum case, holds a valid work permit, and has no criminal record.[1]

No source in the present record confirms that facial recognition, address-extraction software, skip-tracing data, or any other AI tool was used in Thompson’s detention. That limitation matters. Counsel should not plead a machine into the facts just because the facts feel automated. The point is different: DHS now acknowledges a large AI footprint, including ICE tools that can affect identification, targeting, and enforcement triage. In a detention case, the lawyer’s job is to find out whether any of those systems touched the client before the government’s narrative hardens into “the officer knew.”

Legal documents on a detention table overlaid with digital surveillance and facial recognition patterns

Start with the detention record, not the technology

The first intake call should build a timeline that can later be compared against databases, device use, contractor records, and officer testimony. Do not begin with “Did they use AI?” Most detained clients and family members will not know. Begin with what they saw, heard, signed, photographed, unlocked, or lost.

  • Where did the first contact occur: airport gate, employee checkpoint, jet bridge, public terminal area, home, workplace, traffic stop, jail transfer, USCIS appointment, or courthouse?
  • Who made contact first: ICE, CBP, airport police, local law enforcement, TSA, an employer representative, a contractor, or someone who did not identify an agency?
  • Did anyone scan a face, fingerprints, passport, work authorization card, driver’s license, phone, badge, or boarding credential?
  • Did an officer use a phone, tablet, handheld biometric device, laptop, or camera before announcing a status conclusion?
  • What exact words did officers use: “match,” “hit,” “confirmed,” “database,” “biometric,” “address,” “overstay,” “warrant,” “target,” “lead,” or “status verified”?
  • Did officers already know a home address, work schedule, flight assignment, vehicle, phone number, employer, family member, or prior address that the client had not provided that day?
  • Were there screenshots, badge scans, body-worn camera recordings, airport surveillance footage, text messages, employer communications, incident reports, or custody paperwork?
  • What documents did the client have: asylum receipt, work permit, parole document, visa record, I-94, state ID, passport, union credential, or employee badge?
  • What is at immediate risk of deletion: airport video, employer security logs, device audit logs, radio traffic, call notes, database query logs, or contractor task records?

This intake is not busywork. It separates three very different evidentiary problems: an officer personally recognized the client; an officer relied on a database result but can explain the underlying record; or an officer acted on a lead generated by a system or contractor whose method, error rate, and audit trail have not been disclosed.

Map the facts against the known ICE tool categories

DHS’s AI use-case inventory, updated July 15, 2026, listed 238 AI use cases across the department, a 40% increase since July 2025. DHS designated 55 as “high-impact,” and ICE accounted for a substantial share. The same inventory classifies tools including ELITE and Mobile Fortify as “presumed high-impact but determined not high-impact.”[2] That classification is not a harmless label. If the agency treats a tool as not high-impact, counsel should not expect robust voluntary disclosure.

The inventory is also self-reported. Tech Policy Press reported that more than 80% of risk-management fields in the DHS inventory were empty, which is exactly the kind of gap that becomes meaningful when an arrest turns on a match, score, or lead that the defense cannot inspect.[3]

Risk flag in the detention factsTool category to investigateRecords counsel should try to identify
Officer used a handheld phone or tablet to scan the client’s face or documents before making a status statementMobile facial-recognition or biometric status toolDevice logs, query time, returned candidates, confidence score if any, officer training, audit trail, and policy governing use
ICE appeared at a home, workplace, airport, or route using address information the client did not recently provideAddress extraction, lead-generation software, or skip-tracing contractor dataLead packet, source fields, contractor task order, verification notes, address confidence score, and human review notes
Officer described a database “hit” or “match” without naming the databaseInteroperable immigration, criminal, biometric, or commercial database matchingDatabase name, query terms, screenshots, match criteria, candidate list, and identity-resolution steps
Government later presents the officer as having independent knowledgeAny AI-assisted lead that was laundered into officer testimonyCommunications before encounter, dispatch notes, target list, briefing packet, supervisor approval, and system-generated lead history

Mobile Fortify

Mobile Fortify is the kind of tool that should change the way counsel reads a field encounter. Reporting in 2026 described an Oregon incident in which ICE’s handheld facial-recognition app returned two different incorrect names for one woman during a field identification.[4] A coalition letter from EFF, EPIC, and other groups also described ICE’s stated position that Mobile Fortify results constitute a “definitive” determination of immigration status, and cited at least one reported incident in which ICE mistakenly determined that a U.S. citizen could be deported “based on biometric confirmation.”[5]

Those are not facts about every Mobile Fortify use. They are enough to justify targeted discovery when a field encounter included biometric scanning, a phone-based lookup, or sudden status certainty after a device query.

ELITE and address extraction

ELITE, built by Palantir, is described as a generative AI tool that extracts addresses from criminal records to build enforcement leads. 404 Media obtained a user guide showing that ICE uses the tool to identify neighborhoods for raids based on data density. The tool assigns an address confidence score, but the error rate is not disclosed.[6]

That combination should get counsel’s attention: extracted address, confidence score, no disclosed error rate, and possible raid planning. If the client was located somewhere the government should not obviously have known, the address trail matters as much as the arrest report.

The Immigration Policy Tracking Project reported a September 2025 contract for $9.2 million for access to Clearview AI’s database of more than 50 billion facial images.[7] If a case involves image comparison, social media photos, surveillance stills, or a face search that predates the detention, counsel should ask for the commercial vendor trail, not only the officer’s final report.

Skip-tracing contractors

Private skip-tracing data should be treated as evidence with a chain, not as background intelligence that vanishes after arrest. Advocacy reporting described 13 private companies awarded contracts worth up to $1.2 billion, with bonuses tied to verifying a location within 7- or 14-day windows.[8] The American Immigration Council also reported on the role of private data and location-verification systems in immigration enforcement.[9]

The contract-size figures should be cross-checked against procurement records when used in briefing. The litigation point is narrower and stronger: when the government finds a person through a private location-verification process, counsel should request the tasking record, source data, verification steps, and payment incentives that shaped the search.

Six-node workflow diagram showing client intake, tool identification, FOIA requests, preservation motion, cross-examination, and challenge checklist

Send preservation demands before the first FOIA clock runs

FOIA is slow. Deletion is not. In the first 24 to 72 hours, send preservation letters to ICE, any participating local agency, the airport authority if applicable, the employer if workplace records matter, and known contractors or vendors if their involvement is visible from the paperwork. The letter should not accuse the agency of using AI. It should preserve categories broad enough to catch it.

  • All records identifying the basis for the stop, detention, arrest, transfer, or custody decision.
  • All database queries, biometric queries, facial-recognition searches, image searches, address searches, and identity-resolution queries concerning the client.
  • All screenshots, returned candidate lists, match results, confidence scores, status determinations, audit logs, and device logs.
  • All communications transmitting a lead, target packet, address, photograph, route, employer information, flight assignment, worksite information, or location verification.
  • All records reflecting use of Mobile Fortify, ELITE, Clearview AI, Palantir systems, skip-tracing vendors, commercial data brokers, or other automated tools in connection with the client.
  • All policies, training materials, standard operating procedures, and supervisor approvals governing the tool used.
  • All body-worn camera footage, fixed-site video, airport surveillance footage, radio traffic, CAD logs, incident reports, and chain-of-custody records.

If the detention occurred at an airport, add the airport police department, airport authority, relevant terminal security office, and employer security or operations unit. Airport surveillance systems often operate on retention schedules that do not care that immigration counsel is still waiting for an A-file.

Build the FOIA requests around events, tools, and audit trails

A generic A-file request will not reliably surface AI involvement. File it, but do not stop there. The better FOIA set has three lanes: the client-specific enforcement file, tool-specific records connected to the incident, and procurement or policy records that explain what the system was supposed to do.

FOIA lane one: client-specific enforcement records

Ask for the A-file and the enforcement file, but use language that forces the agency to search beyond conventional forms. The request should identify the client by all known names, A-number if known, date of birth, country of birth, detention date, location, employer if relevant, and all known agencies present.

Sample FOIA language:

Please produce all records concerning the identification, targeting, location, stop, detention, arrest, custody classification, transfer, or removal processing of [CLIENT NAME] on or about [DATE] at [LOCATION]. This request includes, but is not limited to, arrest reports, officer notes, supervisor approvals, target packets, lead-generation records, lookout records, database query results, biometric query results, facial-recognition searches, address searches, screenshots, returned candidate lists, confidence scores, audit logs, device logs, dispatch records, radio communications, emails, text messages, Teams or chat messages, and records received from contractors, vendors, other federal agencies, state agencies, local agencies, airport authorities, or employers.

FOIA lane two: named AI or data tools

Once intake facts suggest a tool category, name it. If the officer used a handheld device, ask about Mobile Fortify and any biometric or facial-recognition applications available on that device. If the case involves a home or workplace address that appears sourced rather than volunteered, ask about ELITE, Palantir systems, commercial data brokers, skip-tracing vendors, and address-verification products. If there was photo comparison, ask about Clearview AI and other face-search tools.

Sample tool-specific language:

Please produce all records reflecting whether Mobile Fortify, ELITE, Clearview AI, Palantir tools, skip-tracing contractors, commercial data brokers, facial-recognition systems, biometric databases, address-extraction tools, machine-learning scoring systems, or automated identity-resolution tools were used, queried, consulted, or relied upon in connection with [CLIENT NAME], [A-NUMBER], or the events of [DATE] at [LOCATION].

For each tool or system, please produce the query, input data, uploaded image or document if any, returned result, candidate list, score, confidence value, status determination, user ID, query timestamp, audit log, error message, override record, human review note, and any communication transmitting the result.

FOIA lane three: policies, contracts, and validation records

The client-specific file may show a result without explaining the system. That is not enough for litigation. A separate request should seek records that explain the tool’s function, limits, and human-review requirements.

Sample policy-and-validation language:

Please produce records sufficient to show the purpose, approved use, training requirements, validation testing, error rates, false-positive rates, false-negative rates, demographic performance testing, audit procedures, access controls, retention rules, human-review requirements, and limitations of any automated, algorithmic, machine-learning, generative AI, facial-recognition, biometric, address-extraction, or identity-resolution tool used in connection with [CLIENT NAME] or the events of [DATE].

This request includes user guides, standard operating procedures, privacy impact assessments, contracts, statements of work, task orders, vendor manuals, training decks, validation reports, red-team reports, incident reports, complaint records, and records of known misidentifications or erroneous outputs.

Do not assume ICE is the only FOIA target. Depending on the facts, send requests to CBP, USCIS, TSA, the airport authority, local police, state fusion centers, and any agency named in the arrest paperwork. Where a private contractor appears, use procurement records, state public-records laws, subpoenas where available, and targeted discovery to reach what FOIA may not.

Government data systems separated from a defense attorney desk by a translucent wall with a FOIA document passing through

Use motion practice to turn suspicion into a disclosure issue

Immigration proceedings do not give counsel the same discovery tools available in ordinary civil litigation. That makes the early record more important, not less. The motion should tie the requested AI or data records to a contested issue: identity, alienage, removability, custody, bond, credibility, location of arrest, legality of stop, reliability of government evidence, or the ability to cross-examine the witness who claims knowledge.

The motion should be explicit about the gap. The government should not be permitted to present an officer’s conclusion as independent knowledge if the officer relied on an undisclosed facial-recognition return, address score, commercial data lead, or contractor verification. That is not a theoretical AI objection. It is a confrontation and reliability problem in the administrative record.

  • Move for production of records underlying the stop, identification, location, or status determination.
  • Move to compel disclosure of database names, tool names, query logs, screenshots, scores, candidate lists, and human-review notes.
  • Move to suppress or exclude evidence if the government cannot establish how the identification or lead was generated and reviewed.
  • Move for a continuance where FOIA, preservation responses, or agency disclosures remain pending and the missing records are material.
  • Object to testimony that presents a machine-generated or contractor-generated lead as personal officer knowledge.
  • Request an adverse inference or evidentiary limitation if relevant logs, footage, or query records were not preserved after notice.

Direct precedent on AI-generated evidence in ICE enforcement remains limited. But the due-process argument does not require a court to understand every model architecture. It requires a record showing that a government witness relied on an undisclosed system whose output affected a material decision and whose reliability cannot be tested without disclosure.

There is also a broader court-compliance concern. Tech Policy Press reported that, in January 2026, a Minnesota federal judge documented 96 ICE court-order violations across 74 cases.[3] That finding does not prove noncompliance in any individual AI-evidence dispute. It does support a practical litigation posture: do not rely on informal assurances when the issue is preservation, disclosure, or the existence of records.

Cross-examine the human witness about the machine-shaped path

Most AI disputes in immigration court will not arrive with a vendor engineer on the stand. They will arrive through an officer who says the client was identified, located, or confirmed. Cross-examination has to reconstruct the path from lead to arrest.

Identity and biometric questions

  • Before you approached the person, did you have a photograph, name, A-number, address, employer, flight assignment, or target packet?
  • Who supplied that information?
  • Did you or anyone else use a phone, tablet, camera, biometric reader, or facial-recognition application?
  • What system was used, and what training did you receive on it?
  • Did the system return one result or multiple candidates?
  • Was there a confidence score, ranking, warning, or limitation on the result?
  • Did you save the result, screenshot it, or record the query number?
  • What independent steps did you take before treating the result as accurate?

Address and targeting questions

  • How did you obtain the address or location where the client was found?
  • Was the address extracted from another record, purchased from a vendor, supplied by a contractor, or generated by a lead system?
  • Did the address record include a confidence score, date, source field, or verification status?
  • Did the system show prior addresses, relatives, vehicles, employers, or phone numbers?
  • Did anyone verify the address in person before the operation?
  • Were there incentives, deadlines, or tasking requirements for quick location verification?
  • Is the lead packet in the record before the court?

Status and removability questions

  • When did you first determine the client’s immigration status?
  • What database or record did you rely on?
  • Did the database show pending asylum, work authorization, parole, prior applications, or pending relief?
  • Did any automated tool summarize, classify, or flag the person’s status?
  • Did you review the underlying immigration file or only the returned status screen?
  • If the result was wrong, how would you know?

That last question is not rhetorical. If the officer cannot identify the tool, cannot explain what the score means, cannot say whether the system produces false positives, and cannot produce the returned candidates or query log, the court has a reliability problem. The problem belongs in the record before it becomes an appeal issue.

Do not overread USCIS automation evidence, but do not ignore it

USCIS automation evidence is useful context, not direct proof of ICE enforcement practice. A Cozen O’Connor alert described USCIS tools such as ELIS Evidence Classifier and Verification Match Model, reported higher RFE and denial rates, and stated that EB-2 NIW denial rates reached nearly 40% with AI mis-tagging cited as a contributor.[10] The same alert reported that more than 1,200 international students lost status through automated database terminations, prompting nationwide litigation.[10]

Those examples do not show that ICE used AI in a particular arrest. They do show why immigration lawyers should be careful when a government system converts a partial database record into a consequence. In enforcement, the consequence is not just a request for evidence or a denial notice. It can be handcuffs, transfer, bond denial, or removal pressure before the underlying data has been tested.

Who bears the burden when the government used an undisclosed tool?

Counsel should expect the government to argue that the respondent must show prejudice or unreliability. That is hard to do when the tool name, query, returned result, and error profile are withheld. The answer is to separate burdens.

  • The client can identify facts suggesting tool use: device scan, unexplained match, address lead, contractor trace, or officer testimony that depends on a database result.
  • The government should identify the source of the evidence it offers: officer observation, agency database, biometric search, commercial vendor, contractor lead, or automated scoring system.
  • If the government relies on the output, it should produce enough information for the respondent to test reliability: what was queried, what came back, what warnings applied, what human review occurred, and whether contrary candidates or data existed.
  • If the government refuses or cannot produce those records, counsel should ask the court to limit the testimony, continue the case, compel production, or give reduced weight to the evidence.

The practical objective is not to make the immigration judge adjudicate AI policy. It is to prevent a one-way evidence rule where the government benefits from automated systems while the detained person is told to disprove a system they are not allowed to see.

Deployable challenge checklist

  1. Lock the timeline: first contact, first scan, first status statement, first custody decision, and every agency or contractor that appeared in the chain.
  2. Collect fragile evidence from the family and employer: screenshots, texts, call logs, badges, work schedules, airport notices, incident reports, and video-retention information.
  3. Send preservation letters to ICE, participating agencies, airport or employer entities, and any identified contractor or vendor.
  4. File a broad A-file and enforcement-file FOIA request, but add explicit language covering biometric queries, facial-recognition searches, address extraction, lead packets, contractor records, screenshots, scores, and audit logs.
  5. File tool-specific FOIA requests when facts point to Mobile Fortify, ELITE, Clearview AI, Palantir systems, skip-tracing contractors, commercial data brokers, or other automated identity tools.
  6. Request policies and validation records: user guides, training materials, error rates, false-positive rates, demographic testing, audit rules, retention rules, and human-review requirements.
  7. Move early for disclosure, continuance, suppression, exclusion, or evidentiary limits if the government’s evidence depends on an undisclosed tool or database result.
  8. Cross-examine the officer on the path from lead to arrest: who supplied the information, what system was queried, what result returned, what human review occurred, and what was preserved.
  9. Object when the government repackages a machine-generated or contractor-generated lead as an officer’s personal knowledge.
  10. Keep the caveat in the record: suspected AI involvement is not proof of AI use. The workflow is designed to surface and test the issue, not to assume the answer.

DHS self-classification and incomplete disclosure fields make passive reliance on agency transparency a bad litigation plan. In a detention case, counsel has to create the disclosure record: preserve the evidence, name the possible tools, request the logs, force the witness to explain the chain, and keep the court focused on reliability. This workflow can surface and challenge AI involvement. It cannot establish AI use where the record does not support it, and it does not replace matter-specific legal judgment.

References

  1. Southwest flight attendant detained by ICE while working at Nashville airport, ABC News, July 2026, link
  2. DHS AI Use Case Inventory: ICE, Department of Homeland Security, updated July 15, 2026, link
  3. DHS AI inventory coverage and ICE court-order violation reporting, Tech Policy Press, February 2026, link
  4. ICE facial recognition app misidentified a woman as two different people, 404 Media, January 2026, link
  5. Coalition letter concerning ICE Mobile Fortify, Electronic Frontier Foundation, November 2025, link
  6. ICE use of Palantir ELITE address-extraction tool, 404 Media, link
  7. Clearview AI contract tracking entry, Immigration Policy Tracking Project, September 2025, link
  8. ICE skip-tracing contractor analysis, Jeelani Law Firm, April 2026, link
  9. Private data and location verification in immigration enforcement, American Immigration Council, December 2025, link
  10. USCIS AI tools, RFE and denial rate analysis, Cozen O’Connor, April 2026, link

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →