Skip to content

Risk Digest

How a Researcher FOIA Case Exposed ICE's Detention Algorithm

How is ICE's automated custody-scoring algorithm (RCA) documented, and why did that documentation emerge only because researchers sued under FOIA? This source-linked record traces the Casper v. DHS FOIA production, the Velesaca class-action allegations over a no-release policy, and DHS's June 2026 "Retired" status for successor Hurricane Score — flagging advocacy-sourced statistics and unverified docket details as such.

By Editorial TeamUpdated Aug 2, 2026Verified Aug 3, 2026
CONFIRMED
Jurisdiction
us-federal
Court
U.S. District Court for the District of Minnesota
AI tool named
Risk Classification Assessment (RCA), Hurricane Score
Ruling date
Jan 19, 2017
Source document
View primary court order ↗
Last verified
Aug 3, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

For this Risk Digest record, the useful starting point is source posture. The documented public account of ICE’s Risk Classification Assessment, or RCA, comes chiefly from records produced after researchers sued under FOIA in Casper v. DHS & ICE, not from a voluntary agency explanation of how the detention-scoring tool worked. Evans and Koulish identify the FOIA case as Casper v. Department of Homeland Security & U.S. Immigration and Customs Enforcement, No. 0:16-cv-00380-ADM-BRT in the District of Minnesota, filed on Feb. 16, 2016, and resolved through a stipulated settlement on Jan. 19, 2017 that produced business rules, training materials, the ATP Rules Matrix, and related RCA training records.[1] The strongest current status update on the successor tool is narrower: DHS’s ICE AI Use Case Inventory lists Hurricane Score, DHS-2408, with a status change to “Retired” in the June 2026 log.[2]

A holographic scoring grid hovering above redacted legal case documents in a records room

That distinction matters for anyone trying to trace the researcher-led legal record around ICE detention. The reliable trail does not begin with a polished product description. It begins with litigation, a settlement, and files whose names are more informative than the usual institutional summary: business rules, training materials, ATP Rules Matrix v3, and a Combined RCA Virtual University training release. Those records are the reason a reader can talk about RCA mechanics with any specificity at all.

The rest of the record is less even. The Velesaca v. Decker class-action allegations over a no-release policy are important, but they should not be treated as findings merely because they fit the produced RCA materials too neatly. The release-rate figures associated with that case come from ACLU and NYCLU advocacy materials, not from a court finding. The bond and detention figures often cited around RCA come from secondary reporting summarized by legal scholarship, not from the Casper production itself. A usable risk record keeps those labels attached.

What the Casper FOIA production made visible

Evans and Koulish’s account in “Manipulating Risk” is the spine of the public RCA record because it ties the tool’s operation to named litigation and produced materials. Their article describes RCA as a system ICE began using in the 2012–2013 period to generate custody recommendations for noncitizens in removal proceedings.[1] The records produced in the Casper settlement are not just background paperwork. They are the materials that make the decision logic legible enough to audit: business rules, officer training materials, and matrices that connected assessed risk and custody factors to recommended outcomes.[1]

The difference between “ICE used a risk tool” and “ICE’s risk tool applied these rules in this workflow” is the difference between a policy claim and a record counsel can work with. A custody-scoring tool becomes legally and operationally significant when its recommendation is placed in front of an officer, embedded in a training environment, and paired with rules that tell users what the system is supposed to produce. The Casper production matters because it moved the subject from agency self-description into documents that could be cited, compared, and challenged.

ICE Risk Classification Assessment recommendation matrix with scoring categories and recommended custody outcomes

The factors described in the RCA materials included public-safety and flight-risk inputs, with recommendations generated through a structured assessment rather than a free-form officer memo.[1] That does not make the tool neutral. It means the discretionary act was partly translated into fields, rules, and recommendations. Once that translation happened, the key questions changed: which inputs counted, how they were weighted, what outcomes were available, and how often officers treated the recommendation as practically binding.

The produced training materials are especially important because training is where a tool’s institutional meaning often becomes clearer than in a public-facing description. If a system is described externally as an assessment aid but internally taught as the ordinary route to a custody outcome, the risk profile changes. The Casper materials therefore supply more than a technical snapshot. They show the administrative environment in which RCA recommendations were expected to be generated and used.[1]

Record itemWhy it matters for risk reviewSource status
Casper v. DHS & ICE FOIA docket and settlementExplains why the RCA documents became public at allFOIA litigation record described by Evans & Koulish
Business rulesShows the rule layer behind custody recommendationsProduced after stipulated settlement
Training materials and Combined RCA Virtual University releaseShows how officers were taught to use the toolProduced after stipulated settlement
ATP Rules Matrix v3 / recommendation matrix materialsConnects scored categories to recommended custody outcomesProduced or reproduced through the RCA public-record trail
DHS ICE AI Use Case Inventory entry for Hurricane ScoreProvides a current primary-source status flag for the successor use caseDHS inventory, June 2026 log

The detention consequence is in the workflow, not the label

RCA was not a research model sitting apart from enforcement. It was used to recommend whether a person should be detained, released, or considered for bond-related custody handling within ICE’s enforcement process.[1] For the detained person, the relevant event was not the existence of a score in the abstract. It was the moment a release option, a custody recommendation, or a bond path appeared—or failed to appear—inside the officer’s workflow.

That is why the officer-deviation figures, though secondary, are worth preserving with a label. NYU’s Journal of Intellectual Property and Entertainment Law article, summarizing reporting by The Intercept and The Verge, states that ICE officers deviated from RCA recommendations less than 1% of the time.[3] The same secondary account reports that immigration judges granted bond in roughly 40% of cases and that people detained before a hearing experienced a median detention period of about 80 days.[3] Those figures should not be converted into court findings. They should be read as reported indicators of how little room may have existed between a tool recommendation and a person’s confinement trajectory.

The judge-comparison number is also easy to misuse. A reported 40% bond-grant rate by judges does not prove that RCA caused different detention outcomes in every comparable case. It does, however, sharpen the operational question: if a field-office workflow rarely moves away from the automated recommendation, then the contents of the matrix and the available recommendation categories become more than technical documentation. They become the practical boundary of release consideration inside that workflow.

The Velesaca no-release allegations

The Velesaca v. Decker class action belongs after the RCA mechanics because its significance depends on the tool’s release function. In March 2020, the ACLU announced a NYCLU lawsuit alleging that ICE’s New York City office had adopted a secret no-release policy and that the office effectively stopped releasing people after arrest.[4] The docket number should be re-verified through PACER or a live NYCLU source before publication in any litigation table; the available research trail does not support asserting it here.

A branching custody workflow diagram with one release path severed by a redaction bar

The ACLU press release reported that the New York ICE office released approximately 47% of people arrested from 2013 through June 2017, then released approximately 3% from June 2017 through September 2019.[4] That is advocacy-organization data, not a judicial finding. It is still material because the alleged timing and direction of the change match the precise risk issue raised by the RCA documents: whether the release branch in a custody-assessment process remained meaningfully available.

A clean version of the claim is therefore narrower than many summaries make it. The record supports saying that plaintiffs and advocacy organizations alleged a no-release policy and reported a sharp drop in release rates in the New York office. It does not support saying, without further court-confirmed findings, that the litigation proved RCA itself caused that drop. The tool may be central to the allegation; the allegation is not the same thing as an adjudicated fact.

Hurricane Score’s June 2026 status is a status flag, not a full answer

The current primary-source update is DHS’s own ICE AI Use Case Inventory entry for Hurricane Score, DHS-2408. In the June 2026 log of changes, DHS lists the Hurricane Score use case as “Retired.”[2] That is the status a risk record can cite as of Q3 2026, provided it is rechecked at publication against the live inventory.

The retirement label should not do more work than the inventory entry does. It does not erase the RCA record, resolve the Velesaca allegations, or establish that custody-scoring risk has disappeared from immigration enforcement. It says that this named successor use case, Hurricane Score, is listed by DHS as retired in the June 2026 inventory log.[2] For legal-risk purposes, that is a valuable freshness signal and a poor substitute for a methodology record.

The more durable lesson from RCA is procedural. A custody-scoring system may be operationally powerful long before the public can see the rule logic, matrices, or training deck. In this instance, the public methodology record exists because researchers brought a FOIA case and obtained production through settlement. If a later tool is described as retired, replaced, or updated, the next useful question is not whether the name changed. It is whether the rule materials, training instructions, recommendation categories, and officer-use patterns are available in a form that can be tested.

Risk conclusion as of Q3 2026

The safest reading is limited but firm. RCA is a leading U.S. example of an enforcement algorithm whose public methodology is FOIA-produced rather than agency-published. The Casper record supplies the strongest documentation: the docket, the settlement posture, the business rules, the training materials, and the matrices that show how custody recommendations were structured.[1] The Velesaca no-release theory and release-rate collapse should be described as class-action allegations and ACLU/NYCLU-reported figures, not court findings.[4] The less-than-1% officer-deviation figure, the roughly 40% judge bond-grant comparison, and the approximately 80-day median pre-hearing detention figure should be labeled as secondary reporting.[3] Hurricane Score can be cited as retired only by tying that statement to DHS’s June 2026 inventory status and rechecking the live page before publication.[2]

References

  1. Manipulating Risk: Immigration Detention through Automation — Evans & Koulish, 24 Lewis & Clark L. Rev. 789.
  2. DHS AI Use Case Inventory (ICE) — Department of Homeland Security, June 2026.
  3. Litigating Government Use of Risk Assessment Tools — NYU Journal of Intellectual Property and Entertainment Law.
  4. NYCLU Lawsuit: ICE Office in NYC Has Secret No-Release Policy — ACLU, March 2, 2020.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →