Skip to content

Risk Digest

How to Challenge ICE Spyware Surveillance in Court

This article maps ICE's AI-powered surveillance toolkit—including Paragon Graphite spyware, Palantir ELITE, Mobile Fortify facial recognition, and cell-site simulators—and identifies the concrete legal arguments defense counsel can use to challenge evidence obtained through these tools under the Fourth and Fifth Amendments, citing the agency's own admissions and FOIA-obtained records.

By Editorial TeamUpdated Jul 30, 2026Verified Jul 30, 2026
REPORTED — UNVERIFIED
Jurisdiction
US Federal
Court
U.S. District Court
AI tool named
Paragon Graphite, Palantir ELITE, Mobile Fortify
Ruling date
Apr 7, 2026
Source document
View primary court order ↗
Last verified
Jul 30, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

A suppression motion in an ICE spyware phone surveillance investigation usually starts in an uncomfortable place: the government presents an arrest, a device search, a face match, or a location hit as ordinary enforcement, while the defense is left to infer whether the lead came from spyware, AI targeting, a data broker, facial recognition, or a cell-site tool. The implications are not abstract. They affect what counsel can subpoena, what must be disclosed, whether probable cause was laundered through a vendor system, and whether the court is being asked to rely on an output whose limits have never been tested.

Verified as of July 30, 2026, UTC. This is a litigation-risk digest and legal research overview, not legal advice. Counsel should verify current contracts, local rules, standing, discovery orders, classified-information assertions, immigration-court standards, and any pending statutory changes before filing.

Source statusWhat the record supportsWhat it does not prove by itself
Confirmed agency admissionICE Acting Director Todd Lyons acknowledged operational use of Paragon Graphite in an April 1, 2026 letter to Congress, reported by NPR on April 7, 2026. [1]It does not establish that Graphite was used in every spyware-suspected ICE case, and ICE later told NPR in May 2026 that it had no current Paragon contract. [1]
Self-reported DHS inventory and civil-society analysisDHS reported more than 200 AI use cases, a roughly 40% increase, with ICE adding 24 new AI applications including Palantir ELITE; analysis also found more than 80% of risk-management fields empty. [2]The inventory is not a complete discovery production and should not be treated as exhaustive.
FOIA-obtained recordsFOIA records documented a Mobile Fortify double misidentification during an immigration raid and undermined ICE’s framing of app outputs as definitive. [2]One documented failure is not a statistical error rate, but it is a concrete reliability defect.
FOIA litigation record404 Media reported that its Paragon FOIA lawsuit produced only 77 heavily redacted pages out of 673 responsive pages. [3]The production proves disclosure resistance and redaction scope; it does not, by itself, prove unlawful use in a particular prosecution.
Binding Supreme Court doctrineCarpenter requires a warrant for seven or more days of historical cell-site location information. [4]The Court expressly did not resolve real-time CSLI, tower dumps, or cell-site simulators. [4]
Legal analysisLawfare/Georgetown analysis separates spyware functions into live communications interception, device-content search, and physical-space surveillance through device hardware. [5]That categorization is a framework for warrant-scope analysis, not a factual finding that ICE used each capability in a given case.
Hearing testimonyA July 15, 2026 House hearing, “The Tech Behind ICE,” included testimony from Just Futures Law, Mijente, and NIJC regarding Palantir-related funding and DHS agreements, including more than $1.8 billion in government funding since January 2025 and a $1 billion no-bid DHS agreement. [6]Hearing testimony is useful for context and discovery theory, but case-specific use still must be tied to the client’s facts.
Federal courtroom with digital surveillance streams and network diagrams above the bench and counsel tables

Start with the government’s own paper trail

The cleanest opening lever is not a white paper about spyware. It is an agency admission. Lyons’s April 1, 2026 letter matters because it moves Paragon Graphite from suspected capability to acknowledged operational use by ICE. Once that exists, a defense request for “any surveillance technology used” should not be brushed aside as speculative merely because the government prefers to describe the case as a routine arrest, search, or identity check. [1]

That does not mean counsel should allege Graphite in every case. The current contract status is disputed: ICE told NPR in May 2026 that it had no current Paragon contract. [1] The careful use of the Lyons letter is narrower and stronger. It supports discovery into whether Graphite, successor tools, shared access, tasking by another component, or derivative leads played a role in the investigation. It also supports skepticism toward declarations that speak only in present-tense contracting language while leaving past use, interagency sharing, vendor transition periods, or derivative exploitation unaddressed.

The DHS AI inventory performs a different function. It is not reliable because it is complete; it is useful because it is government-authored and visibly incomplete. A self-reported inventory showing more than 200 AI use cases, approximately 40% growth, 24 new ICE AI applications, Palantir ELITE, and risk-management fields left empty in more than 80% of entries gives counsel a baseline for arguing that generalized assurances are inadequate. [2] If the government’s own inventory cannot show basic risk-management information, a court should not accept an affidavit that treats automated targeting or identification as a black box outside adversarial testing.

The 404 Media FOIA production reinforces the same point from another angle. Producing 77 heavily redacted pages out of 673 responsive Paragon contract pages is not a normal evidentiary foundation; it is a record of opacity. [3] Trade-secret assertions may justify some redactions in a public-records context. They do not automatically answer a defendant’s need to know whether the government intruded into a phone, copied privileged material, intercepted communications, relied on undisclosed targeting data, or exceeded the warrant it obtained.

Lumping every system into “AI surveillance” weakens the motion. A spyware implant raises different questions than a face-matching app. A Palantir targeting platform raises different questions than a cell-site simulator. The more precise the functional category, the harder it is for the government to answer with a generic declaration that “no evidence was obtained unlawfully.”

Infographic linking ICE surveillance tools to legal levers including suppression, discovery, Franks challenges, due process, Carpenter warrant scope, and source disclosure
Technology or sourceLitigation functionImmediate demand or challenge
Paragon Graphite or comparable spywareDevice intrusion, possible communications interception, content search, or activation of device sensorsDemand warrant applications, tasking records, minimization procedures, privilege-screening protocols, audit logs, exploit scope, dates of access, and derivative-use disclosures.
Palantir ELITETargeting, lead generation, entity resolution, aggregation, raid planning, and case prioritizationDemand source datasets, query terms, analyst notes, confidence or scoring rules, audit trails, human-review records, and any role in probable-cause or reasonable-suspicion statements.
Mobile FortifyField identification and facial recognition outputDemand match images, nonmatch candidates, app version, confidence thresholds, officer instructions, human confirmation steps, error records, and impeachment material.
Historical CSLIRetrospective location trackingApply Carpenter directly when the government obtained seven or more days of historical cell-site location information without a warrant.
Real-time CSLI or cell-site simulatorsLive location tracking or device identificationForce disclosure of the tool used, legal process obtained, minimization terms, location precision, duration, and whether the court was told the technology’s real function.
Data-broker sourcingPurchased or licensed location, identity, contact, travel, or consumer-derived dataDemand contracts, source databases, query logs, retention rules, opt-out status, provenance, and whether the purchase substituted for legal process.

Graphite is not one warrant problem

The easy mistake is to treat spyware as a single search. The harder and more useful question is what the implant was authorized to do. Lawfare/Georgetown’s categorization is valuable here because it separates spyware capabilities into live communications interception, device-content search, and physical-space surveillance through device hardware. [5] Each category points to a different authorization problem.

  • Live communications interception: If the tool captured communications as they occurred, counsel should ask what statutory interception authority the government relied on, what minimization applied, which accounts or applications were covered, and whether privileged or third-party communications were captured.
  • Device-content search: If the tool searched stored files, messages, photos, location history, tokens, app databases, or credentials, the Rule 41 and particularity questions become central. The warrant should say what could be searched, for what offense, during what period, and with what limits on copying and later review.
  • Physical-space surveillance: If the tool activated or exploited a phone’s microphone, camera, or other sensors, counsel should resist any affidavit that describes the event merely as a “device search.” The practical effect may be surveillance of rooms, conversations, bystanders, and attorney-client settings.

For suppression, the first target is the warrant record: application, affidavit, attachments, incorporated protocols, sealing orders, returns, inventories, and any later expansions. The second target is execution: tasking logs, access times, file paths, captures, selectors, filters, minimization, and analyst review. If the government refuses to identify the capability, counsel can argue that the court cannot assess particularity, overbreadth, probable cause, minimization, privilege intrusion, or fruit-of-the-poisonous-tree issues from a vendor label withheld behind trade-secret language.

The 404 Media production gives this argument a practical evidentiary hook. The public record already shows broad Paragon redactions and limited production from a much larger responsive universe. [3] In criminal discovery, that history supports a narrower but sharper request: not “disclose all source code,” but “disclose the operational facts needed to determine whether the search in this case stayed inside the warrant.”

Questions that should not be left to a vendor declaration

  • Was the client’s device infected, accessed, queried, or tasked?
  • Was the intrusion zero-click, link-based, credential-based, cloud-based, or performed through another device or account?
  • What data categories were collected, and what categories were technically available?
  • Were live communications, stored content, location data, contacts, authentication tokens, microphone captures, or camera captures collected?
  • What minimization and privilege procedures were in place before collection began?
  • Were derivative leads used to obtain later warrants, conduct surveillance, stop a person, question a witness, or execute a raid?
  • Were any materials deleted, quarantined, filtered, or withheld from the prosecution team?

Palantir ELITE belongs in the targeting record, not just the background file

Palantir ELITE is significant because it appears in the DHS AI inventory as part of ICE’s expanding AI use, not because the inventory proves what happened in a particular arrest. [2] In litigation, ELITE should be treated as targeting and aggregation infrastructure unless the government proves it had no role in the case. That means the relevant question is not only whether ELITE produced trial evidence. It is whether ELITE helped decide whom to investigate, where to raid, which address to treat as current, which identity link to accept, or which facts to place in an affidavit.

That distinction matters for Franks-style challenges. If an affidavit states that agents identified a person through “database checks,” “law-enforcement records,” or “investigative analysis,” but omits that the database chain included automated entity resolution, stale commercial data, contested immigration records, or a vendor-generated association, the omission may be material. Counsel does not need to prove algorithmic error at the outset. The first demand is for the data path.

Affidavit phraseWhat counsel should test
“Database checks confirmed the target’s address.”Which databases, what date ranges, what confidence indicators, what conflicting addresses, and whether a commercial or AI-aggregated source supplied the address.
“Agents identified associates of the target.”Whether entity resolution connected people through shared phone numbers, addresses, vehicles, family relationships, social-media data, utility records, travel records, or inferred links.
“The target was selected for enforcement based on investigative priorities.”Whether an AI prioritization, risk score, list, dashboard, or ELITE query shaped selection.
“Analysts corroborated the information.”Who reviewed it, what they reviewed, whether contradictory records existed, and whether human review meant independent verification or merely clicking through a generated result.

The July 15, 2026 House hearing adds scale to the inquiry. Testimony described more than $1.8 billion in government funding to Palantir since January 2025, including a $1 billion no-bid DHS agreement. [6] Scale is not illegality. But in discovery practice it undercuts the suggestion that a major ICE targeting platform is too peripheral to disclose when the case began with a raid list, address match, or identity association.

This is also where civil-rights and immigration counsel may need a broader factual record than criminal defense counsel. A single prosecution might focus on probable cause and suppression. A pattern case may focus on whether targeting systems concentrated enforcement on protected groups, registry populations, workplaces, neighborhoods, or humanitarian-relief cohorts. For surveillance-targeting context, the Haitian TPS risk registry analysis at ICE AI surveillance risks for Haitian TPS holders is a useful companion route, but a motion still needs case-specific proof of how the client was selected.

Mobile Fortify gives courts a concrete failure mode

Facial recognition challenges often fail when they stay at the level of generalized skepticism. Mobile Fortify’s documented double misidentification is more useful because it gives counsel a concrete failure mode: a woman was misidentified during an immigration raid, and the FOIA record contradicted ICE’s framing of app results as definitive. [2] That is not an error-rate study. It is still enough to make reliability, officer training, output language, and downstream reliance fair subjects for discovery.

The strongest Mobile Fortify argument is usually not that every app result is inadmissible. It is that the government must disclose how the result was generated and how it was used. If the match justified detention, questioning, transport, phone seizure, consent pressure, or a later warrant, then the app is not a harmless administrative aid. It is part of the evidentiary chain.

  • Request the probe image, gallery images, candidate list, confidence score or ranking, timestamp, app version, and device identifier.
  • Request officer instructions describing whether a result may be called “definitive,” “possible,” “investigative,” or “not an identification.”
  • Request records of false positives, corrected identifications, user complaints, training materials, and vendor or agency warnings.
  • Compare the face-match timeline with the claimed basis for the stop, detention, arrest, search, or consent.
  • Ask whether the officer had independent grounds before the app output or whether the output created the encounter.

The due process argument is strongest when the app output changed the person’s legal position and the government then insulated the output from testing. A field identification that triggers detention is different from a lead that agents independently corroborate before taking coercive action. Counsel should make that distinction explicit, because it affects prejudice.

A related enforcement-risk example appears in the Southwest flight attendant ICE AI enforcement case, where the practical concern is not whether an automated system is impressive, but whether a person can reconstruct the chain of machine output, human reliance, and official action after the government has already labeled the case routine.

Cell-site tools: Carpenter is strong, but not complete

Carpenter is the firmest anchor for historical cell-site location information. The Supreme Court held that the government generally needs a warrant to obtain seven or more days of historical CSLI. [4] If ICE or another agency obtained that volume of historical cell-site data without a warrant and used it to locate, identify, or build the case against the client, Carpenter belongs near the front of the suppression motion.

But Carpenter should not be overstated. The Court expressly declined to decide real-time CSLI, tower dumps, and other techniques, and it did not resolve cell-site simulators. [4] That reservation leaves room for argument; it does not supply a settled holding. Counsel should therefore separate three questions: historical records acquired from a carrier, real-time carrier-assisted tracking, and active use of a simulator or comparable device to locate or identify phones.

Location methodStronger argumentRecord needed
Seven or more days of historical CSLICarpenter warrant requirement.Carrier orders, warrants, returns, date range, number of days, and derivative use.
Shorter historical CSLIFact-dependent Fourth Amendment argument based on precision, aggregation, and use.Time span, location precision, frequency of points, and whether combined with other databases.
Real-time CSLIReserved Carpenter issue; argue warrant need based on live tracking and intrusion.Legal process, duration, refresh rate, minimization, and emergency assertions.
Cell-site simulatorReserved issue; challenge secrecy, misdescription, overcollection, and lack of particularity.Application language, device model or capability, target identifiers, bystander collection, deletion protocols, and whether the court was told a simulator would be used.

The practical discovery point is simple: do not accept “location information” as a complete description. A tower dump, a ping, historical CSLI, GPS from a seized phone, a commercial location feed, and a simulator deployment create different Fourth Amendment records. They also create different third-party exposure, minimization, and bystander-collection issues.

For a fuller Fourth Amendment framework around Carpenter and Chatrie-style reasoning, the analysis of autonomous police drones and the Fourth Amendment is useful, especially where location tools are combined with persistent observation or automated sorting.

Data-broker sourcing is where the purchase record becomes the warrant record

Data-broker evidence often enters a case disguised as a lead: a current address, a workplace, a phone number, a travel pattern, a device location, or a household association. The constitutional problem is that the government may treat purchase or licensing as a substitute for legal process. The first litigation move is to force the government to say whether it obtained the information directly from a provider under legal process, from a commercial broker, from a law-enforcement fusion system, from another agency, or from an AI platform ingesting several of those sources.

Counsel should be careful with statutory arguments here. The status of the Fourth Amendment Is Not For Sale Act in the 119th Congress requires current verification before any filing treats it as enacted law or controlling authority. The safer constitutional argument does not depend on that bill. It asks whether the government acquired data that, under Carpenter’s reasoning or ordinary warrant principles, should not be insulated from judicial review merely because the government bought access rather than served a warrant.

  • Demand the broker or platform name, contract, purchase order, statement of work, user guide, data dictionary, and permitted-use terms.
  • Demand the query logs: who searched, when, using what identifiers, and for what investigative purpose.
  • Demand provenance: original data source, collection method, date range, update frequency, retention period, and opt-out or consent representations.
  • Demand conflict records: stale addresses, competing identities, failed matches, suppressed candidates, and analyst notes rejecting alternatives.
  • Tie the broker record to a consequence: stop, detention, search, questioning, raid location, warrant paragraph, or removal filing.

Discovery should track authorization, data path, reliability, and use

The most useful discovery requests are not the broadest ones. Courts are more likely to engage when the request is tied to an element the judge must decide: probable cause, particularity, standing, voluntariness, reliability, material omission, prejudice, or derivative use. A motion that asks for “all AI records” gives the government room to object. A motion that asks for “the source and audit trail for the address assertion in paragraph 14 of the warrant affidavit” is harder to wave away.

Litigation issueTargeted request
SuppressionIdentify every surveillance tool, database, broker feed, AI system, facial recognition app, cell-site process, or spyware capability used before the search, stop, arrest, or warrant.
Franks-style challengeProduce source records and analyst notes for each affidavit statement derived from automated matching, database aggregation, location tools, or vendor systems.
Rule 41 or ECPA warrant scopeProduce the warrant application, technical protocol, minimization terms, execution logs, returns, inventories, and any post-search filtering or expansion approvals.
Reliability and due processProduce error records, misidentification reports, confidence thresholds, training materials, version history, and human-review documentation.
Brady/Giglio-type impeachmentProduce known false positives, corrected identifications, vendor warnings, audit failures, analyst discipline, and contradictory records affecting identification or location.
Derivative evidenceIdentify every later warrant, interview, detention, search, database query, or raid step that relied on the disputed output.

The evidentiary foundation should be equally concrete. Who operated the system? What training did that person have? What input did they enter? What output appeared? What warnings appeared with it? Was the output saved? Was a confidence measure displayed? Did a human confirm it independently? Did the human know the original source? Did the government preserve the nonmatches and alternatives? Those questions turn a black box into a chain of custody problem.

Suppression theories by constitutional pressure point

Fourth Amendment arguments are strongest when the tool invaded a protected space, gathered location data at Carpenter scale, exceeded a warrant, or supplied probable cause through concealed facts. Fifth Amendment and due process arguments become stronger when the government uses an automated or vendor-generated output in a way the person cannot meaningfully test, especially if the output caused detention, interrogation, identification, or removal consequences.

Pressure pointBest-fit argumentCommon weakness
Spyware device intrusionThe search exceeded the warrant, lacked particularity, intercepted communications without proper authority, captured privileged material, or became physical-space surveillance without adequate authorization.Counsel must connect the tool to the client’s device or derivative evidence.
AI-generated targetingThe affidavit omitted material source information, relied on stale or unreliable data, or concealed automated association and scoring.A targeting lead may not be suppressible unless it affected probable cause, a seizure, or derivative evidence.
Facial recognitionThe identification was unreliable, mischaracterized as definitive, or used to justify detention without adequate corroboration.General criticism of facial recognition is usually not enough without case-specific reliance.
Historical CSLICarpenter requires a warrant for seven or more days of historical CSLI.Shorter periods and non-CSLI location sources require more fact-specific argument.
Real-time location or simulator useThe government conducted live tracking or active device identification without adequate warrant disclosure, minimization, or particularity.Supreme Court doctrine remains reserved rather than settled.
Data-broker acquisitionThe government purchased access to sensitive data that should require judicial process, then used it as an investigative substitute for a warrant.The law is still developing, and the motion needs a precise acquisition record.

One recurring government response is that the disputed system produced only a lead. That answer should trigger a derivative-use inquiry, not end it. If the lead caused officers to choose an address, stop a car, question a person, seize a phone, seek a warrant, or enter a workplace, the defense is entitled to test whether the lead was lawfully obtained and accurately described. A lead can be the first domino.

Immigration proceedings require a narrower suppression strategy

Removal proceedings do not import criminal suppression doctrine wholesale. The evidentiary standard is lower, and suppression that might be viable in a criminal case may fail in immigration court unless counsel can show an egregious violation, fundamental unfairness, or unreliability serious enough to undermine the proceeding. That distinction should be addressed directly rather than hidden in a Fourth Amendment brief drafted for a different forum.

The practical strategy in immigration court is often layered: move to suppress where the violation is egregious, move to terminate where government conduct infected the case, object to unreliable records, demand the basis for identity and location assertions, seek subpoenas where available, and use FOIA aggressively to reconstruct the acquisition path. Mobile Fortify’s documented misidentification is especially relevant here because it goes to reliability as well as legality. [2]

Counsel should also distinguish identity from evidence. The government may argue that identity itself is not suppressible. That does not make every document, statement, phone extraction, database return, or location record admissible. The question is what the government obtained after the disputed surveillance step and whether that material is reliable, fairly obtained, and properly connected to the respondent.

What a court can be asked to order

The remedy should match the record. If counsel has only a government inventory entry, the first order may be disclosure. If counsel has an affidavit omission, the request may be a Franks hearing. If counsel has warrant overbreadth or unauthorized execution, suppression may be appropriate. If counsel has a reliability defect, the request may be exclusion, an evidentiary hearing, impeachment material, or limits on how the government may characterize the output.

  • Order the government to identify whether spyware, ELITE, Mobile Fortify, a cell-site simulator, real-time CSLI, historical CSLI, or broker data was used in the investigation.
  • Order production of warrant materials, tasking logs, audit trails, query records, source datasets, minimization protocols, and derivative-use records under protective order if necessary.
  • Hold an evidentiary hearing on whether the government’s affidavit omitted material facts about automated targeting, vendor data, location tracking, or facial recognition reliance.
  • Suppress evidence obtained through an unauthorized device intrusion, overbroad search, warrantless Carpenter-scale historical CSLI acquisition, or materially misleading warrant application.
  • Exclude or limit testimony that describes a facial recognition or AI output as definitive when the record supports only an investigative lead.
  • Require the government to disclose known misidentifications, contradictory records, confidence limits, and vendor warnings before relying on the output.

Protective orders may solve some legitimate security and trade-secret concerns. They should not be allowed to erase the adversarial function. A court can restrict dissemination while still requiring the government to disclose what tool was used, what it did, what legal authority allowed it, what data it collected, what limits applied, and how the output affected the case.

The record is the lever

ICE’s surveillance stack is not unchallengeable because it is technical, classified-adjacent, or vendor-mediated. The agency’s own records now give counsel usable starting points: an admitted operational spyware capability, a self-reported AI inventory with visible gaps, a disclosed ELITE entry, a documented Mobile Fortify misidentification, a heavily redacted Paragon FOIA production, and unresolved doctrine around real-time location tools.

The strongest motions will not try to prove every surveillance abuse at once. They will force the government to identify the tool, the warrant or authorization, the data path, the reliability record, and the role the output played in targeting or evidence collection. That is where the procedural fog becomes litigable.

References

  1. ICE acknowledges it is using powerful spyware, NPR, April 7, 2026
  2. DHS AI Surveillance Arsenal Grows as Agency Defies Courts, Tech Policy Press
  3. Paragon FOIA lawsuit records on ICE Graphite contract pages, 404 Media
  4. Carpenter v. United States, Supreme Court of the United States, June 22, 2018
  5. Spyware capability analysis categorizing live communications interception, device-content search, and physical-space surveillance, Lawfare / Georgetown
  6. The Tech Behind ICE, U.S. House hearing, July 15, 2026

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →