Two connected learning models Explore the linear model at KillChains.com

Preserved research input · KW-RPT-023

From Intelligence Nomination to Government Action: How the U.S. Terrorism-Watchlisting System Works and Where Predictive AI Could Enter It

A lifecycle reconstruction of U.S. threat screening, identity resolution, downstream action, error classes, redress, and possible entry points for predictive AI.

Digest verified 8478dd87c3ea02bc91dfea80f15a9d8f62a6d99f3dca8ca6e01755ee5897396e

From Intelligence Nomination to Government Action: How the U.S. Terrorism-Watchlisting System Works and Where Predictive AI Could Enter It

Executive findings and current terminology

The United States does not operate a single, self-executing “terrorist list” that automatically imposes the same consequence everywhere. It operates a federated watchlisting and screening enterprise in which intelligence and law-enforcement agencies nominate identities; the National Counterterrorism Center and the Federal Bureau of Investigation perform different review functions depending on whether the terrorism nexus is international or purely domestic; the FBI-administered Threat Screening Center makes the final watchlist-acceptance decision; and downstream agencies independently decide what action their own statutes and missions permit. A watchlist record can therefore trigger anything from an unnoticed database comparison, to enhanced screening, to a request that an officer telephone the Threat Screening Center, to denial of airline boarding, to additional visa or immigration scrutiny. It is not, by itself, an arrest warrant, a criminal charge, a probable-cause determination, a finding of inadmissibility, or proof that the listed person committed terrorism. citeturn6view0turn10search2turn22search6

The most important terminology changed recently:

Current official term as of August 2, 2026MeaningObsolete or potentially misleading term
Threat Screening Center, or TSCFBI-administered interagency center responsible for threat-screening identity resolution, watchlist management, encounter coordination, and related information sharingTerrorist Screening Center. The FBI formally changed the name on March 19, 2025, as the center’s mission expanded beyond terrorism
Threat Screening System, or TSSThe broader FBI-administered technical and operational environment containing logically separated datasets for different threat categoriesOften confused with the terrorism watchlist itself; also easily confused with TSA
Terrorist Screening Dataset, or TSDSThe consolidated terrorism identity dataset within TSS, commonly called the U.S. terrorist watchlistTerrorist Screening Database, or TSDB, the official name replaced in 2021
Terrorist Identities Datamart Environment, or TIDENCTC’s classified repository of identifying and derogatory information concerning persons with an international-terrorism nexusSometimes incorrectly described as the watchlist used directly by airport officers
No Fly List, Selectee List, and Expanded Selectee ListScreening designations or subsets derived from TSDS eligibility and additional criteriaThey are not separate, independent intelligence databases in the ordinary sense
DHS Watchlist Service, or WLSDHS service that receives TSC watchlist data and makes appropriate data available to DHS screening systemsThe individual DHS systems that consume its data should not themselves be called “the watchlist”
DHS Traveler Redress Inquiry Program, or DHS TRIPTSA-administered, DHS-wide intake mechanism for travel-screening complaints and watchlist-related redressIt is not a court, and it is not the entity that originally nominates most records

The renaming was substantive as well as cosmetic. The FBI announced in March 2025 that the Threat Screening Center’s mission had expanded to include certain transnational-organized-crime threats. The FBI’s fiscal-year 2027 budget submission subsequently described the Threat Screening System as containing logically separated datasets for known or suspected terrorists, certain non-terrorist military detainees, and transnational-organized-crime actors, each governed by distinct nomination criteria. The terrorism component remains the TSDS. Accordingly, a reference in a recent document to “TSS” may encompass more than terrorist watchlisting, while a reference to “TSDS” is specific to the terrorism dataset. citeturn1search0turn8view7turn14view0

As of August 26, 2024, the most recent publicly disclosed aggregate cited by the Privacy and Civil Liberties Oversight Board, the terrorism watchlist contained approximately 1.1 million persons, fewer than 6,000 of whom were U.S. persons—a category generally including citizens, nationals, and lawful permanent residents. These are persons, not necessarily one record each; aliases, identifiers, encounters, and source records can produce multiple linked data objects. The size figure also does not disclose how many people fall within No Fly, Selectee, Expanded Selectee, ordinary known-or-suspected-terrorist, or exception categories. citeturn14view0

The governing interagency policy is publicly identified as the 2023 Watchlisting Guidance, but substantial portions are not public. An informal interagency body, the Watchlisting Advisory Council, coordinates policy questions. Public FBI, GAO, and PCLOB documents describe the general standards and workflow, but they omit sensitive identifier thresholds, some subset criteria, exact matching rules, handling codes, source-weighting practices, and many quality-control metrics. The resulting public account is unusually detailed for an intelligence process, but it remains an exterior reconstruction rather than a complete operational manual. citeturn14view0turn3view0turn6view0

Principal conclusions. First, most current watchlisting is not “predictive AI.” Name matching, fingerprint comparison, facial comparison, alias resolution, and record linkage seek to determine whether two data objects refer to the same person; they do not necessarily predict future conduct. Second, prediction already exists at the policy level even without machine learning: No Fly eligibility expressly incorporates prospective threat and, in one criterion, operational capability. Third, some downstream targeting systems generate risk assessments or identify anomalies rather than merely matching identities, so they can be predictive or probabilistic even when agencies call them “analytics” or “decision support.” Fourth, the FBI’s 2026 Threat Screening Center AI Enhancement initiative could introduce similarity analysis, federated enrichment, gap detection, prioritization, and predictive modeling deeper into the lifecycle, but the public record establishes a request for information, not a deployed production system or an awarded contract. citeturn6view0turn13search1turn13search5turn16search30

Fifth, the system’s most demonstrable error problem is not reducible to one “false-positive rate.” At least three distinct errors occur: an innocent traveler can be falsely matched to somebody else’s valid record; a record can contain identifiers belonging to an innocent person; or the government can intentionally list the correct person but rely on information that is inaccurate, stale, circular, insufficient, or no longer meets the standard. Each has a different denominator and remedy. GAO’s review of roughly 20,000 U.S.-person DHS TRIP submissions from December 7, 2021, through September 30, 2023, found 289 watchlist-related matters: 21 involved misidentification, 88 resulted in removal, nine in downgrading, and 171 in no change. Those figures describe a self-selected redress population, not the accuracy of the 1.1-million-person dataset. citeturn22search3turn22search6turn4view3

Sixth, the legal landscape is fragmented by circuit, consequence, and procedural posture. The Ninth Circuit has held that the revised No Fly redress process can satisfy due process; the Fourth Circuit reversed a district-court decision that had condemned the broader watchlist’s procedures; the Supreme Court held in 2024 that government removal from No Fly does not automatically moot a challenge; and the D.C. Circuit in April 2026 upheld a TSA final order maintaining a U.S. citizen on No Fly and treated the post-redress circuit-court review mechanism as constitutionally adequate in that case. These holdings do not establish that every watchlist use is lawful, nor do they establish a general right to know whether one is on the broader TSDS. citeturn17search1turn20search2turn18search1turn19search0turn19search1

Finally, only some elements reasonably resemble “pre-crime.” Consolidating identities, correcting aliases, or notifying an officer of a potential match does not. No Fly’s prospective-danger criteria, association-based exceptions, risk scoring that estimates dangerousness, and any future AI that recommends adverse action based on predicted conduct resemble pre-crime to varying degrees because they impose or support preventive consequences before criminal adjudication. The resemblance becomes strongest when a prediction is uncertain, the consequence is severe, the evidence is secret, the affected person receives little notice, and the decision is difficult to challenge.

Architecture, datasets, and agency responsibilities

The system developed from a central post-September 11 finding: relevant identities had been dispersed across agencies and lists that were not reliably synchronized. Homeland Security Presidential Directive 6 directed the integration and use of terrorist-screening information, and the original Terrorist Screening Center began operations in 2003. The post-2009 reforms following the attempted bombing of Northwest Flight 253 further pressed agencies to review holdings, revise nomination guidance, and strengthen connections among TIDE, the consolidated watchlist, and aviation subsets. Today’s architecture preserves centralized identity consolidation while leaving intelligence ownership and operational authority distributed. citeturn6view0turn24search17turn24search18

The following map shows the publicly documented core flow. It separates the intelligence source, the watchlisting decision, the distribution mechanism, and the government action because collapsing those functions is the most common analytical error.

INTELLIGENCE OR LAW-ENFORCEMENT ORIGIN
    |
    |-- Foreign intelligence, military reporting, diplomatic reporting,
    |   border encounters, partner-government reporting, investigations,
    |   suspicious-activity reporting, biometrics, open-source leads
    |
    +---------------- International or mixed terrorism nexus ----------------+
    |                                                                        |
    v                                                                        |
Nominating agency                                                     Purely domestic nexus
    |                                                                        |
    v                                                                        v
National Counterterrorism Center (NCTC)                              FBI investigation / Sentinel
Terrorist Identities Datamart Environment (TIDE)                            |
    |                                                                        |
    | review of derogatory basis and identity data                           |
    +----------------------------------+-------------------------------------+
                                       v
                         FBI Threat Screening Center
                         Threat Screening System (TSS)
                         Terrorist Screening Dataset (TSDS)
                         - sufficiency and identity review
                         - accept, reject, modify, or remove
                         - assign eligible screening designations
                                       |
        +------------------------------+------------------------------+
        |                              |                              |
        v                              v                              v
 DHS Watchlist Service            FBI CJIS / NCIC                Other authorized
        |                         KST-related alerts              federal screening
        |                              |                         and investigative uses
  +-----+---------+                    v
  |     |         |               State, local, tribal,
  v     v         v               territorial officers
 TSA   CBP      USCIS                  |
Secure TECS/    ATLAS                  v
Flight ATS       |                 Call TSC for identity
  |     |         |                 resolution and instructions
  |     |         |
  v     v         v
Airline Border Immigration
screen  screen  benefit/credential review

STATE DEPARTMENT:
CLASS, consular systems, visa/passport screening, biometric comparisons

DOD:
DoD ABIS, Biometrically Enabled Watchlist, installation-access screening

ENCOUNTER OR ADJUDICATION:
Potential match -> identity resolution -> agency applies its own legal authority
                                    |
                                    v
                    encounter report / new intelligence / correction
                                    |
                                    +----> modification, review, removal,
                                           or further investigation

The map is deliberately non-linear at the bottom. Encounters can generate new identifiers, resolve an alias, disassociate an innocent traveler, corroborate or undermine the original intelligence, prompt an investigation, or trigger a nomination modification. The Threat Screening Center operates continuously to resolve potential matches, but the encountering agency—not TSC—normally decides whether it has legal authority to search, detain, deny a benefit, refuse boarding, revoke a document, or open an investigation. citeturn6view0turn2view2turn4view4

Agency-responsibility matrix

OrganizationCurrent principal systems or datasetsWatchlisting responsibilityScreening or action responsibilityImportant limits
FBI Threat Screening CenterThreat Screening System; Terrorist Screening Dataset; encounter-management records; NCIC exportsFinal arbiter of TSDS inclusion or rejection; identity resolution; quality control; modification and removal; screening designations; redress review supportConfirms or rejects potential matches and coordinates operational responseDoes not itself supply every underlying intelligence report and generally does not confer independent search, arrest, immigration, or passport authority
FBI operational divisions and field officesSentinel and investigative files; domestic-terrorism case informationSole direct nominator for purely domestic-terrorism identities; may nominate international-nexus identities through NCTC; must correct or retract source informationMay investigate under FBI authorities and respond to encountersWatchlisting is not a substitute for investigative predication, probable cause, or a warrant
National Counterterrorism CenterTerrorist Identities Datamart EnvironmentCentral repository and review point for international-terrorism identities and derogatory information; transmits eligible identity information to TSCSupports intelligence analysis rather than ordinary front-line screeningTIDE is not the same as TSDS and is not generally the record directly displayed to local police
Office of the Director of National IntelligenceIntelligence-community governance structures; NCTC is within ODNICoordinates intelligence-community policy and oversightNo routine airport or roadside enforcement roleOperational authorities remain with component agencies
DHS headquarters and Office of Strategy, Policy, and PlansDHS Watchlist Service and departmental governanceParticipates in interagency policy; WLS distributes appropriate data to componentsCoordinates DHS-wide screening and redress policyWLS is a distribution service, not a separate substantive nomination standard
Transportation Security AdministrationSecure Flight; Cleared List and redress-related records; credential-vetting systemsCan originate relevant intelligence but is principally a screening consumerCompares passenger and covered non-traveler data; prevents No Fly boarding; directs enhanced Selectee screening; administers DHS TRIP and No Fly administrative appealA Secure Flight flag is not proof of TSDS status; random and rules-based screening also produce extra screening
Customs and Border ProtectionTECS platform; Automated Targeting System; Advance Passenger Information and passenger-name records; Traveler Verification Service; WLS feedsCan collect information and submit or support nominations through appropriate channelsBorder inspection, targeting, secondary referral, admissibility processing, traveler identity verificationATS risk results and watchlist matches are leads; CBP must use its separate border, customs, and immigration authorities
Department of StateConsular Lookout and Support System; Consular Consolidated Database; Integrated Biometric System; passport and visa recordsDiplomatic posts and headquarters can originate terrorism reporting and nomination informationVisa adjudication and revocation; passport adjudication; biometric comparison; diplomatic reportingTSDS status is an input, not a universal automatic visa or passport disposition; the governing immigration and passport authorities still apply
U.S. Citizenship and Immigration ServicesATLAS; Fraud Detection and National Security systems; USCIS ELIS; WLS accessCan develop and refer derogatory informationAutomated checks, rule-based screening, fraud and national-security referral, immigration-benefit adjudicationATLAS alerts do not themselves decide statutory eligibility; adjudicators and specialized officers apply immigration law
DHS Office of Biometric Identity ManagementAutomated Biometric Identification System, known as IDENT; Homeland Advanced Recognition Technology, or HART, modernizationSupplies identity-resolution capability rather than substantive terrorist nomination criteriaBiometric storage, search, and identity verification for DHS and partnersPublic documents through 2025 described HART as replacing IDENT, but did not establish that every operational function had migrated by August 2, 2026
Department of DefenseDepartment of Defense Automated Biometric Identification System; Biometrically Enabled Watchlist; military and installation-access systemsMilitary intelligence and operational components can originate identities and biometrics; information may flow to NCTC/TSC where eligibleBattlefield and installation-access identity screening; force protectionThe DoD Biometrically Enabled Watchlist is not identical to TSDS; military detainee and other TSS categories are logically separate
FBI Criminal Justice Information Services DivisionNational Crime Information Center, including the Known or Suspected Terrorist-related file and alertsTSC is the only entity authorized to enter and maintain the relevant NCIC watchlist recordsMakes alerts available to authorized criminal-justice usersNCIC alert handling codes are operational instructions, not arrest warrants
State, local, tribal, and territorial law enforcementState interfaces to NCIC; local records systemsUsually cannot directly place a person in TSDS; may generate reports or referrals that federal nominators assessEncounter individuals, review alerts, contact TSC, use independent state or federal legal authorityOfficers are instructed not to disclose watchlist status; a hit alone does not create unlimited detention or search power
Fusion centersHomeland Security Information Network, eGuardian or suspicious-activity-reporting channels, regional systemsCollect, assess, and route information that may support federal nominations; respond to TSC requests for informationDisseminate threat information and support local-federal coordinationFusion-center reporting is not automatically sufficient for watchlisting; suspicious-activity reporting alone is publicly described as insufficient
Other federal usersBackground-investigation, clearance, firearms, explosives, credential, and facility-access systemsMay nominate through authorized channelsUse eligible watchlist data as one screening inputEach consequence depends on a distinct statute, regulation, adjudicative standard, or security authority

The matrix reflects the current TSC and TSDS terminology and the division between international nominations through NCTC and purely domestic nominations through the FBI. FBI public guidance expressly identifies State visa and passport screening, CBP international-travel screening, TSA passenger screening, USCIS immigration screening, DoD base-access screening, FBI investigations, and state and local law-enforcement support as principal uses. citeturn6view0turn10search2turn22search6

NCTC and TIDE. TIDE contains classified identifying and derogatory information for identities associated with international terrorism. It can include names, aliases, dates and places of birth, travel-document information, photographs, fingerprints, other biometrics, and links to the source reporting. NCTC evaluates international-terrorism nominations before transmitting appropriate identity information to TSC. The sensitive intelligence generally remains in TIDE or the originating agency’s holdings; TSDS itself is described as an unclassified but sensitive identity dataset rather than the central repository for all classified source reporting. citeturn6view0turn14view0turn22search6

FBI and purely domestic terrorism. For a person whose alleged terrorism nexus is purely domestic—meaning there is no foreign-intelligence, counterintelligence, or international-terrorism link—the FBI is the sole nominating agency and sends the nomination directly to TSC. The public process presupposes an FBI counterterrorism investigation or other authorized FBI predicate. If the FBI later concludes that the person lacks a terrorism nexus, it is expected to close the relevant investigation where appropriate and request removal through the same watchlisting channels. citeturn22search6turn6view0

DHS Watchlist Service. WLS was created to receive the consolidated watchlist feed from TSC and distribute appropriate data to DHS components. It reduces the need for each DHS component to build an independent direct ingest. USCIS, CBP, TSA, and other authorized users can consume data through WLS while maintaining their own mission systems, matching methods, case records, and legal decision processes. A record’s replication in WLS-connected systems also means that correction is operationally more complex than changing a single row at TSC: downstream caches, override records, cleared lists, encounter histories, and adjudicative files may require separate synchronization or annotation. citeturn15search0turn15search4turn22search1

TSA and Secure Flight. Secure Flight receives passenger data and compares it with continuously updated watchlist and related screening data before boarding. The program is intended to prevent No Fly persons from boarding and to identify Selectee persons for enhanced screening. It also screens certain non-traveling populations connected with aviation. TSA’s systems can produce screening results for reasons unrelated to TSDS, including random selection, identity-data problems, other security rules, credential concerns, or behavior-related restrictions. Thus, “SSSS” markings, failure to print a boarding pass, or referral to an airline desk are not reliable proof of watchlist status. citeturn16search0turn15search9turn15search15turn10search2

CBP, TECS, and ATS. TECS is CBP’s principal law-enforcement and border-processing platform. The Automated Targeting System is officially described as a decision-support tool that compares traveler, cargo, and conveyance information against law-enforcement, intelligence, and other enforcement data. ATS can perform rules-based targeting and risk assessment in addition to literal identity matching. At a port of entry, a TSDS-related signal can lead to secondary inspection and TSC contact, but CBP’s actual inspection, search, admissibility, seizure, or detention decision derives from border, immigration, customs, or criminal authority rather than from the watchlist standard alone. citeturn15search8turn16search26turn16search30

State Department. State’s Consular Lookout and Support System supports visa and passport lookout functions, while its consular data environment and Integrated Biometric System support biographic and facial comparisons. GAO has reported that State compares visa and passport applicant photographs against terrorist-watchlist photographs. A match can inform a visa denial, revocation, advisory opinion, passport review, or referral, but the legal disposition must still be grounded in immigration or passport law. The broader watchlist is therefore neither identical to CLASS nor an automatic passport-revocation list. citeturn22search0turn22search9turn22search10turn22search6

USCIS and ATLAS. ATLAS is both an automated-check service and a rule-based screening platform. It checks immigration-related identities and events, generates alerts, and routes matters to Fraud Detection and National Security personnel or background-check officers when potentially relevant information arises. The system can perform event-based rescreening after an application was filed, which is important because watchlist or derogatory information may change during a long-pending immigration case. An ATLAS alert is a triage mechanism; the benefit decision remains governed by the Immigration and Nationality Act, regulations, evidentiary rules, and the relevant burden of proof. citeturn16search2turn16search14turn16search18

DOD biometrics. DoD ABIS stores biometric records, and the Biometrically Enabled Watchlist links certain biometric identities to force-protection or national-security information. DoD’s inspector general has described ABIS records linked with the BEWL and has examined whether military components properly submitted or used biometric records. These systems can contribute highly discriminating identifiers to terrorism identity resolution, but a BEWL entry is not necessarily a TSDS record and should not be represented as one. citeturn22search2

NCIC, local police, and fusion centers. TSC exports an appropriate subset into NCIC, where authorized officers can receive handling-code alerts during ordinary queries. The current NCIC privacy assessment states that TSC alone may enter and maintain the relevant records. GAO reported in 2026 that terrorist-watchlist alerts use three principal handling codes, with sensitive details omitted publicly. Officers are generally expected to compare available identifiers and telephone TSC, which performs additional identity resolution and supplies instructions or information. The alert does not itself authorize arrest. Fusion centers can provide local intelligence, route suspicious-activity reporting, and answer TSC requests, but public watchlisting guidance states that suspicious-activity reporting alone does not satisfy the nomination standard. citeturn24search7turn2view2turn4view4turn22search8

Lifecycle, standards, and consequences

A watchlist record has a longer lifecycle than “nominate, list, encounter.” It begins with source collection and ends, if at all, with removal from active screening—not necessarily destruction of the underlying intelligence, encounter history, nomination package, or archived identity record.

Origin of intelligence. A potential identity may originate in a foreign-intelligence report, FBI investigation, military or battlefield collection, diplomatic cable, border encounter, visa interview, partner-government report, financial or communications intelligence, open-source information, suspicious-activity report, biometric collection, or information supplied by another subject or source. Reliability at this stage varies. Raw intelligence can include uncorroborated allegations, partial names, uncertain transliterations, source judgments, and inferential links. The critical legal and analytical distinction is that information may lawfully exist in an intelligence or investigative holding without yet satisfying the criteria for TSDS inclusion. citeturn6view0turn14view0turn22search6

Nomination. Only authorized government agencies can nominate. For an international or mixed nexus, the nominating agency submits information to NCTC for TIDE processing. For a purely domestic nexus, the FBI submits directly to TSC. The nomination should identify the subject, explain the terrorism nexus, supply the underlying derogatory basis, and provide enough identifiers for screening. Race, ethnicity, national origin, religion, and First Amendment-protected beliefs or activities may not be the sole basis, and guesses, hunches, or suspicious-activity reporting alone are insufficient. citeturn6view0turn10search2

NCTC or FBI sufficiency review. NCTC assesses international nominations for consistency with the governing criteria and TIDE requirements. The FBI conducts the corresponding substantive review for domestic nominations. Review is not limited to whether some negative statement exists; reviewers are expected to consider the totality of available information, including aggravating and mitigating information and rational inferences. The public record does not disclose a numerical source-reliability score, a mandatory corroboration count, or a universal rule excluding hearsay. citeturn6view0turn14view0

Identity resolution. Reviewers must decide whether the derogatory information concerns a sufficiently identifiable person and whether the identifiers belong together. Names, aliases, dates of birth, places of birth, nationality, passport numbers, photographs, fingerprints, iris data, travel patterns, addresses, and relational information can all contribute. This stage may merge aliases into one identity, separate two people who share a name, or identify that an innocent person’s passport number was mistakenly attached to someone else’s record. The minimum identifier combinations vary by screening subset and are partly classified or sensitive. citeturn6view0turn22search6

TSC acceptance or rejection. TSC independently checks whether the substantive nomination criterion and identifier-sufficiency requirement are met. It may accept, reject, return for clarification, or later modify the record. TSC is the final arbiter for both international and domestic terrorism nominations. Rejection at any stage is required when the record does not meet the governing criteria, although public reports do not disclose comprehensive acceptance, rejection, or return rates. citeturn22search6turn6view0

Designation within the screening architecture. A TSDS-eligible person may be assigned No Fly, Selectee, Expanded Selectee, or ordinary known-or-suspected-terrorist treatment. Some associated or connected persons who do not satisfy reasonable suspicion may be included as Watchlist Exceptions for limited immigration, visa, credentialing, or benefit-screening purposes. The exception category is important because it demonstrates that not every identity exported from the terrorism watchlisting enterprise is based on a finding that the person is themselves reasonably suspected of terrorism. citeturn22search6turn3view0

Quality control and dissemination. Once accepted, the record is subject to formatting, identifier checks, subset assignment, and dissemination rules. Relevant portions are sent to DHS WLS, NCIC, State, Defense, and other authorized systems according to purpose and handling restrictions. TSC reports that it audits records, reviews available information after potential-match encounters, and periodically revisits policy. Nominating agencies remain responsible for correcting or retracting information they own. Public documents also describe special review mechanisms for U.S.-person records, including a six-month timer or biannual review, although PCLOB and GAO have questioned whether those reviews are consistently completed, documented, and monitored. citeturn6view0turn14view0turn3view1

Screening encounter. A screening system produces a potential match, not necessarily a confirmed identity. The encounter may occur in person, electronically, before travel, at a border, during a visa or benefit adjudication, at a military installation, or during an NCIC query. The screening organization compares the person’s data with the candidate record. Where required, it contacts TSC, which performs additional identity resolution and determines whether the person is a positive match, a negative match, or unresolved. citeturn6view0turn2view2

Operational action. After a confirmed match, the encountering agency applies its own authority. TSA can prevent boarding when the person is confirmed as No Fly or direct enhanced screening for Selectee treatment. CBP can conduct border inspection and take immigration or customs action. State can evaluate visa or passport consequences. USCIS can refer or adjudicate an immigration case. An FBI field office can investigate or seek judicial process. A local officer can take action supported by traffic, criminal, protective, or other lawful grounds. The watchlist result informs the decision but generally does not replace the separate legal threshold. citeturn10search2turn22search6turn6view0

Modification. New intelligence, corrected identifiers, biometric confirmation, an encounter report, a change in association, source recantation, investigative closure, death, duplicate detection, or redress submission can result in modification. A person may remain in TSDS while moving between No Fly, Selectee, Expanded Selectee, and ordinary treatment. An innocent traveler may receive a cleared-list or override record without any change to the actual watchlisted person’s record. These are operationally different corrections. citeturn22search6turn6view0

Periodic review. Review is distributed among the nominator, NCTC or FBI, and TSC. Public materials say agencies must reassess records and act on new exculpatory or refuting information, but “periodic” does not necessarily mean a full de novo reconsideration of every source at short fixed intervals. PCLOB recommended clearer definitions of currency, retroactive review when standards change, stronger purging practices for U.S.-person data, and metrics showing whether reviewers actually considered mitigating information. GAO separately recommended timelines and monitoring for TIDE and TSDS modifications and removals. citeturn14view0turn3view1

Redress-triggered review. A DHS TRIP complaint can cause TSC to determine whether the complainant is a match, solicit updated or exculpatory information from relevant agencies, and decide whether to maintain, modify, downgrade, or remove a record. For a U.S. citizen or lawful permanent resident denied boarding because of No Fly, the enhanced process can disclose status and an unclassified summary of reasons, invite a response, obtain a TSC recommendation, and culminate in a TSA Administrator final order. citeturn6view0turn19search0turn22search6

Removal. Removal is appropriate when the criteria are no longer met, including because new information refutes or discredits the original basis or changed circumstances eliminate the relevant nexus. Removal from one subset is not necessarily complete TSDS removal; a No Fly downgrade can leave the person subject to Selectee or another designation. Conversely, an override or cleared-list entry for an innocent traveler generally leaves the actual subject’s watchlist record intact. citeturn6view0turn22search6

Retention after removal. Removal from active dissemination does not mean erasure. The FBI’s published Terrorist Screening Records System notice, using legacy TSDB terminology, states that active watchlist records are retained for 99 years and inactive or archived records for 50 years. Nomination files, source intelligence, FBI investigative records, TIDE holdings, screening transactions, encounter-management records, DHS TRIP files, litigation records, and local police records can be governed by separate schedules and exemptions. The old SORN may not describe every current TSS component, but it demonstrates that archival retention is intentionally much longer than active listing. citeturn24search1turn24search2turn24search4

Table of legal standards and consequences

Stage or functionPublicly stated standardTemporal orientationWhat it authorizes or supports
Raw intelligence collectionAgency-specific intelligence, investigative, border, military, diplomatic, or reporting authorityPast, present, future, or unknownRetention and analysis in source systems; does not by itself establish watchlist eligibility
Known or suspected terrorist nominationArticulable intelligence or information that, under the totality of circumstances and rational inferences, creates reasonable suspicion that the person is engaged, has been engaged, or intends to engage in terrorism, preparation, aid, or furtheranceExpressly combines past, present, and intended future conductEligibility for ordinary TSDS inclusion, subject to identifier sufficiency
Identifier sufficiencyEnough biographic or biometric information to allow screeners to match or disassociate a person; exact combinations vary by subsetIdentity-focused, not dangerousness-focusedDetermines whether the intelligence can be operationalized in screening
Watchlist ExceptionConnection or association with known or suspected terrorists under criteria that do not require the ordinary reasonable-suspicion standardOften relational; may imply present or future screening relevanceLimited export for immigration, visa, credential, benefit, and other approved functions
No FlyOrdinary reasonable suspicion plus one of the additional threat criteria: terrorism concerning aircraft; a domestic-terrorism threat to the homeland; an international-terrorism threat to a U.S. facility abroad or associated personnel; or a threat of violent terrorism combined with operational capabilityStrongly prospective, though based on historical and current evidenceProhibition on boarding flights arriving in, departing from, or overflying the United States
SelecteeOrdinary reasonable suspicion plus an additional sensitive criterion not publicly disclosedUnknown combination; likely preventiveEnhanced airport screening and possible Federal Air Marshal coverage
Expanded SelecteeOrdinary reasonable suspicion; further details are sensitivePreventive screeningSimilar enhanced screening and possible flight-security measures
Potential computer matchAlgorithmic or rules-based similarity thresholdIdentity probabilityReferral for human or TSC resolution; not a determination of terrorism
TSC positive-match resolutionSufficient congruence between encountered person and watchlist identity under undisclosed matching proceduresIdentity determinationConfirms that the person encountered corresponds to the record; does not independently establish authority to arrest
Border secondary screeningCBP targeting, watchlist, document, intelligence, random, or other referral criteria; action governed by border and immigration authorityMixedInspection, questioning, document review, biometric checks, and potentially immigration or customs action
Visa decisionApplicable Immigration and Nationality Act grounds, including terrorism-related inadmissibility where relevant; consular and revocation authoritiesPast, present, association, support, and anticipated activity depending on statutory provisionDenial, revocation, advisory review, or additional processing
Passport decisionPassport statutes and regulations; national-security information can inform adjudicationMixedDenial, limitation, or revocation where an independent passport-law ground is satisfied
USCIS benefit decisionBenefit-specific eligibility, admissibility, good-moral-character, security, and evidentiary rulesMixedReferral, interview, hold, request for evidence, denial, or other adjudicative action
InvestigationAgency investigative guidelines and statutory jurisdiction; intrusive steps may require reasonable suspicion, probable cause, court orders, or warrantsPast, present, and future threatCollection and investigative activity; watchlist status is a lead, not automatic predication for every technique
Arrest or criminal searchProbable cause and any warrant or exigency requirementsSuspected completed or ongoing offenseArrest or search; TSDS status alone is not a warrant
RemovalRecord no longer meets the applicable substantive or identifier criteriaCurrent reassessment of all relevant periodsEnd or reduction of active screening designation
No Fly administrative appealTSA Administrator reviews the complete redress file, including the person’s response and TSC recommendationCurrent threat eligibilityFinal agency order maintain­ing, downgrading, or removing No Fly status; reviewable under 49 U.S.C. § 46110

The ordinary known-or-suspected-terrorist definition is not purely retrospective. It reaches a person reasonably suspected to have engaged, be engaging, or intend to engage in terrorism-related conduct. No Fly adds a more specific prospective-threat judgment. Watchlist Exceptions, by contrast, can operate on association or connection without ordinary reasonable suspicion that the associated person is themselves a terrorist actor. citeturn6view0turn22search6

Distinguishing watchlisting, screening, investigation, and prediction

ConceptQuestion answeredTypical outputWhat it is not
WatchlistingDoes available information and identity data satisfy policy criteria for inclusion in TSDS or a related designation?Accepted, rejected, modified, removed, or assigned subsetA criminal conviction or universal command to take action
ScreeningDoes this traveler, applicant, worker, visitor, or encountered person match a listed or otherwise relevant identity, and what screening instruction applies?No match, possible match, positive match, secondary screening, deny boarding, referNecessarily an investigation into an offense
InvestigationIs there a factual and legal basis to collect evidence about a person, group, event, or offense using investigative authorities?Leads, interviews, process, surveillance, case opening or closureAutomatically authorized by a watchlist hit
Identity prediction or probabilistic matchingHow likely is it that two imperfect records concern the same person?Similarity score, candidate list, confidence levelPrediction that the person will commit terrorism
Threat or behavior predictionHow likely is an uncertain future event, conduct, or dangerous outcome?Risk score, threat class, prioritized target, forecastMere name matching
Collection recommendationWhere is missing or corroborating information most likely to be found, or what collection would reduce uncertainty?Suggested database, source, query, or investigative stepNecessarily a prediction of guilt, though it may shape who is investigated

This distinction is essential to any assessment of AI. A model that transliterates an Arabic name, compares fingerprints, or merges duplicate records is performing identity resolution. A model that estimates the likelihood that a person will conduct a violent act is predicting behavior. A model that predicts which database is likely to contain an omitted passport number predicts information location, not terrorism—unless the system converts that result into a dangerousness score.

Screening, errors, and statistical performance

Different consequences from the same underlying dataset

The broader terrorism watchlist. Ordinary TSDS inclusion makes identity information available for authorized screening and investigative purposes. Most listed people are not on No Fly and can travel by air, although they may face secondary screening, border questioning, visa effects, benefit review, credential consequences, or law-enforcement attention. The FBI emphasizes that the vast majority of passengers subjected to extra airport screening are not watchlisted. citeturn10search2turn22search6

No Fly. No Fly is the most severe routine travel consequence. A confirmed person is prohibited from boarding a covered flight arriving in, departing from, or transiting U.S. airspace. The criterion is not merely “the person is in TSDS”; it adds an assessment of aviation, homeland, overseas-facility, or operational violent-terrorism threat. citeturn6view0turn19search0

Selectee and Expanded Selectee. These functions permit travel but impose enhanced security screening. Possible consequences include more intensive person and property screening, inability to obtain a boarding pass remotely, additional identity checks, and possible Federal Air Marshal coverage. The additional Selectee criterion is withheld as sensitive; Expanded Selectee publicly requires ordinary reasonable suspicion but can lead to similar screening. citeturn22search6

Border screening. CBP can receive watchlist, law-enforcement, immigration, document, targeting-rule, or anomaly-based referrals. A U.S. citizen generally cannot be denied entry to the United States, but can be delayed and inspected; a lawful permanent resident may face different immigration questions depending on travel and statutory status; a noncitizen applicant for admission can be found inadmissible under the INA. A TSDS match can inform the process, but it is not synonymous with a formal inadmissibility finding. citeturn16search30turn22search6

Visa screening. Visa applicants are screened through State systems and relevant interagency checks. Terrorism-related inadmissibility provisions can reach participation, support, solicitation, membership, endorsement, or association defined by statute, and visa revocation can occur under separate authority. Watchlist information may be highly influential, but the consular decision and any later admissibility decision have their own legal framework. citeturn22search0turn22search6

Passport consequences. GAO identifies passport issuance as a federal service informed by the watchlist, and State uses biometric and lookout systems in passport adjudication. Public sources do not establish a rule that every TSDS entry automatically causes denial or revocation. Rather, watchlist information can trigger review and support action where passport statutes and regulations authorize it. Treating “on TSDS” and “passport revoked” as equivalent would overstate the public evidence. citeturn22search6turn22search9

USCIS and naturalization. For lawful permanent residents and other applicants, watchlist information may generate enhanced review, an FDNS referral, delay, an interview, requests for evidence, or denial if the underlying facts establish a statutory ground. GAO identifies naturalization denial and entry-related consequences as examples affecting some lawful permanent residents. The substantive decision must nevertheless rest on immigration law and evidence, not merely the existence of a secret flag. citeturn22search6turn16search2

NCIC distribution. TSC enters and maintains the relevant NCIC records. An officer’s query may return a handling code directing caution, identity checks, and TSC contact. A local officer should not tell the person that the alert is a watchlist hit. The officer may enforce an independent warrant, criminal law, traffic law, or safety authority, but the alert is not itself a warrant or blanket command to detain. citeturn24search7turn2view2turn22search6

Investigative use. A TSDS encounter can provide a lead, reveal travel or associates, prompt a field-office notification, or corroborate an existing investigation. Conversely, investigation can generate the nomination. This feedback loop creates value but also raises the danger of circular validation: an encounter caused by the watchlist can be written up as new derogatory information and then cited as support for continuing the watchlist record unless reviewers distinguish independent evidence from consequences created by the listing itself.

The error taxonomy

False identity match. The person being screened is not the watchlisted person, but shared or similar identifiers trigger a candidate match. Common names, shared dates of birth, missing middle names, inconsistent name order, truncated fields, reused passport numbers, transliteration variants, and low-quality photographs increase the risk. A redress control number, TSA Cleared List entry, or CBP override can help future systems distinguish the innocent traveler. citeturn22search6

Contaminated watchlist record. The subject may be legitimately watchlisted, but the record contains an identifier belonging to an innocent person. This can happen through data-entry error, source confusion, mistaken alias linkage, document fraud, or poor entity resolution. Merely clearing the innocent traveler at TSA does not necessarily repair the source record across TIDE, TSDS, State, CBP, and local holdings; the incorrect identifier must be removed or disassociated upstream. GAO expressly identified mistaken insertion of an innocent traveler’s identifiers into a known-or-suspected-terrorist record as a distinct error category. citeturn22search6

Erroneous nomination of the correct person. The government knows exactly whom it listed, but the derogatory basis may be false, misinterpreted, too weak, constitutionally impermissible, or derived from a source whose reliability was overstated. This is not “misidentification.” It is a substantive eligibility dispute.

Initially valid but stale listing. The available information may have met the standard when nominated, but later developments undermine it. An association ends; a source recants; an investigation closes; a suspected alias proves unrelated; a foreign partner corrects its report; or policy changes. Data-aging controls must therefore evaluate continuing relevance, not merely whether a record was once valid. citeturn6view0turn14view0

False negative. A person who meets the criteria may not be identified because the government lacks a name, the alias is unknown, transliteration differs, the biometrics are absent, the record is delayed, a source agency fails to nominate, or matching thresholds are set too narrowly. Overly aggressive deduplication can merge separate people; overly cautious matching can miss an alias. The public system emphasizes false-positive burdens because they generate visible complaints, but false negatives are the principal security rationale for broad data sharing and probabilistic matching.

Association error. Relationship information can be accurate but misleading. Two people may share a household, mosque, workplace, telephone number, flight, financial transaction, social-media connection, or family tie for benign reasons. The key analytical questions are whether the association is direct or inferred, current or historical, voluntary or incidental, and independently corroborated. Watchlist Exceptions heighten this concern because they permit consequences for some connected persons who do not satisfy ordinary reasonable suspicion. citeturn22search6

Transliteration and name-order error. Names written in Arabic, Cyrillic, Chinese, Persian, Urdu, Pashto, and other scripts can have multiple valid Romanizations. Patronymics, compound surnames, honorifics, particles, and naming conventions may be split differently across passports and databases. A system optimized for recall can generate many candidates; one optimized for exact spelling can miss genuine matches. Transliteration software reduces inconsistency but can also create false confidence that linguistically plausible variants identify the same person.

Circular reporting. A watchlist alert prompts questioning; the questioning creates an encounter report; another agency receives the report without seeing that the encounter was generated by the original watchlist record; and the report is cited as fresh corroboration. Similar loops can occur when multiple intelligence reports reproduce one original partner allegation. Provenance and source-lineage controls are therefore essential: five reports are not five independent sources if all derive from one unverified report.

Confirmation bias. Once a reviewer sees that a person is watchlisted, ambiguous travel, contacts, or behavior may be interpreted as confirming suspicion. Mitigating facts can receive less attention than derogatory ones. Separating identity-resolution review from substantive threat review, requiring explicit treatment of exculpatory evidence, and showing reviewers source independence can reduce this bias.

Automation bias. A high match score, system-generated risk label, or AI summary can be treated as authoritative even when important fields conflict. Humans may defer because they assume the model considered more data, or because overruling it requires extra documentation. Conversely, reviewers may ignore valid alerts after repeated false positives. Both overreliance and alert fatigue are automation failures.

Error and redress statistics

MeasureNumeratorDenominatorResultLimitation
U.S.-person DHS TRIP inquiries found watchlist-related, Dec. 7, 2021–Sept. 30, 2023289Roughly 20,0001.5%Self-selected complainants; excludes people who did not complain or whose problem was not recognized
Watchlist-related inquiries with no change17128959.2%“No change” does not independently prove the listing or match was correct
Watchlist-related inquiries resulting in removal8828930.4%Removal can reflect changed circumstances or new information, not necessarily original error
Watchlist-related inquiries involving misidentification212897.3%Measures identified false matches in this complaint population, not system-wide match specificity
Watchlist-related inquiries resulting in downgrade92893.1%A downgrade can leave substantial screening consequences
Enhanced No Fly requests for additional reasons during the GAO period9Not all No Fly persons; only eligible requesters in the reviewed periodNot a population rateEight were still active at the data cutoff; one was downgraded
Administrative No Fly appeals in the GAO period1Eligible persons who reached the appeal stageNot a population rateThe one reviewed appeal closed without removal
2022 complainants who said they believed they were watchlisted and were actually matched93702.4%Belief-based subgroup; not all DHS TRIP complaints
Approximate share of all DHS TRIP complaints associated with the watchlist, reported by PCLOBAll complaints in the referenced dataAbout 2%Timeframe and categorization differ from GAO’s U.S.-person sample
Persons in TSDS as of Aug. 26, 2024About 1.1 millionGlobal listed populationDoes not reveal record count, aliases, subsets, or error rate
U.S. persons in TSDS as of Aug. 26, 2024Fewer than 6,000About 1.1 million personsUnder about 0.55%Approximate, date-specific, and no subset breakdown
TSC record reviews described in a 2021 briefingAbout 1,200 per dayAbout 438,000 annualized if constantWorkload indicatorNot an acceptance or error rate and may not reflect 2026 operations
TSC outreach events to nonfederal users, FY 2019–202443Six fiscal yearsAbout 7.2 per yearEvents varied in audience and scope
Interview groups unfamiliar with current or recent TSC outreach2326 groups representing 55 agencies88.5%Qualitative sample, not a nationally representative survey
Interview groups unaware of current reference materials242692.3%Same sampling limitation
Interview groups believing not all officers were prepared to handle encounters132650%Respondent judgment, not an encounter-error audit

The DHS TRIP figures are the best recent public outcome data, but they cannot support a general statement such as “30 percent of watchlist records are wrong.” The 88 removals were 30 percent of 289 watchlist-related U.S.-person complaints, not 30 percent of TSDS, not 30 percent of U.S.-person records, and not 30 percent of all encounters. A removal can mean the original listing was erroneous, that new exculpatory information became available, that an association ended, or that the record no longer met a current standard. citeturn22search3turn22search6turn4view3

PCLOB’s 2022 comparison illustrates the opposite denominator problem: of 370 complainants who believed they were watchlisted, only nine actually were. That does not establish that screening was benign; many people experience repeated secondary screening for other reasons. It does establish that personal inference from airport treatment is an unreliable measure of TSDS status. citeturn14view0

GAO’s 2026 examination of state, local, tribal, and territorial use found significant training and outreach gaps. Twenty-three of 26 interview groups were unfamiliar with current or recent TSC outreach, 24 were unaware of current reference materials, and half believed not all officers were prepared to handle a potential encounter. TSC conducted 43 relevant outreach events over fiscal years 2019 through 2024, only four of which were categorized as direct state or local events; others were conducted through fusion centers, associations, training forums, or professional events. These figures do not prove that officers mishandled a particular encounter, but they identify a control weakness at the point where a sensitive alert can affect a roadside interaction. citeturn2view2turn4view5

The base-rate problem

Even a highly accurate system can produce more false than true alerts when the predicted condition is rare. Positive predictive value is:

\[ PPV=\frac{\text{sensitivity}\times\text{prevalence}} {\text{sensitivity}\times\text{prevalence}+ (1-\text{specificity})\times(1-\text{prevalence})} \]

For watchlisting, “prevalence” must be defined carefully. It could mean the proportion of all screened travelers who are truly the listed identity, the proportion who genuinely meet a future-danger criterion, or the proportion of candidates in an already enriched intelligence pool who are relevant. Those are radically different populations.

The following calculations are illustrative, not estimates of actual government performance:

Hypothetical populationPrevalenceSensitivitySpecificityTrue positives per 1,000,000False positives per 1,000,000Positive predictive value
Rare event, moderate high-quality matcher0.01%90%99%909,9990.89%
Higher-risk screened pool0.1%90%99%9009,9908.26%
Enriched referral pool1%90%99%9,0009,90047.62%
Rare event, very high specificity0.01%95%99.9%95about 1,0008.68%
Higher-risk pool, very high specificity0.1%95%99.9%950about 99948.74%
Rare event, exceptional specificity0.01%99%99.99%99about 10049.75%

The lesson is not that screening cannot work. It is that specificity and population selection dominate performance in rare-event settings. A loose algorithm used on every traveler can create overwhelming false-alert volume. The same algorithm used only after exact passport, date-of-birth, and biometric agreement can have much higher predictive value. Multi-stage screening—broad candidate generation followed by exact document and biometric resolution—is therefore statistically preferable to treating a single fuzzy-name score as dispositive.

The base-rate problem is even more severe for future dangerousness than for identity matching. Identity matching can be anchored by fingerprints or document numbers. A prediction that a person will commit a terrorist attack concerns an extraordinarily rare event, lacks an immediately observable ground truth for most negative cases, and can be distorted because intervention prevents the predicted event. A system may look successful because listed people did not attack, when the non-event could mean either prevention or an incorrect prediction. Valid evaluation must therefore use outcomes other than “no attack occurred,” including blinded case review, source-quality measures, false-alert burdens, removal rates, calibration, and counterfactual analysis.

Algorithms, automated decision support, and the 2026 AI initiative

What is already automated

Name matching. Secure Flight, border systems, State systems, immigration systems, NCIC interfaces, and TSC identity-resolution tools compare names and other biographic fields. Matching can include exact comparisons, phonetic similarity, edit distance, transliteration variants, reordered name components, alias tables, and weighted field agreement. This is automated identity matching, not predictive policing, unless a separate model uses the match to forecast conduct. Secure Flight publicly describes rapid comparison of passenger information with continuously updated watchlists. citeturn15search9turn16search0

Biometric matching. Facial recognition, fingerprint matching, and other biometric comparisons are probabilistic identification technologies. State has used its Integrated Biometric System to compare visa and passport applicant photographs with watchlist photographs. CBP’s Traveler Verification Service and related facial-recognition capabilities verify travelers against travel-document galleries. DoD ABIS supports biometric search and watchlist linkage, while DHS IDENT—and its HART modernization—supports department-wide biometric identity services. These tools predict identity correspondence, not future terrorism. citeturn22search9turn23search1turn22search2turn16search6

Entity resolution. Entity-resolution systems merge or separate records using combinations of biographic, biometric, travel, communications, and relational identifiers. They can identify that “Mohamed A. Hassan,” “Muhammad Hassan,” and a fingerprint record probably concern one person, or that two people with the same name are distinct. Because entity resolution changes which information is attributed to whom, an error can propagate farther than an ordinary one-time match.

Rule-based screening and prioritization. USCIS ATLAS is publicly described as both an automated-check service and a rule-based screening platform. ATS compares traveler and cargo data against intelligence and enforcement information and is officially classified as decision support. Rule-based systems are algorithms even when they do not use machine learning. A rule that routes every record with a specified combination of travel, document, and intelligence attributes to secondary review performs risk classification. citeturn16search2turn16search30

Risk assessment and anomaly detection. ATS has long gone beyond literal watchlist matching by applying targeting rules and identifying higher-risk transactions or travelers for officer review. Anomaly detection asks whether conduct deviates from a learned or expected pattern; risk assessment estimates relevance or threat based on multiple factors. These functions can become predictive when they estimate an uncertain security outcome, even if the agency labels the output “targeting,” “triage,” or “risk assessment.” citeturn16search26turn16search30

Link analysis. Intelligence and law-enforcement analysts use relational data to identify associations among people, communications, travel, documents, addresses, organizations, and events. Public watchlisting documents confirm that connected and associated persons can receive screening treatment, but they disclose little about the production algorithms. The public evidence supports the existence of analytic relationship assessment; it does not disclose a current universal machine-learning model that autonomously decides which social links establish watchlist eligibility. citeturn14view0turn22search6

Derogatory-information discovery. Automated checks can search newly received records against existing identities, notify reviewers that a new report concerns a listed person, or identify a potentially relevant record in another system. Event-based USCIS screening and federated watchlist distribution are examples of continuous or recurring discovery rather than one-time adjudication. citeturn16search2turn16search18

Data quality and deduplication. Automated systems can flag impossible dates, conflicting nationalities, expired documents, duplicate identities, missing mandatory fields, or biometrics linked to multiple biographic identities. Such tools improve accuracy but can also delete meaningful distinctions or merge records incorrectly.

The DHS AI inventory is expressly limited to unclassified and non-sensitive use cases. Its CBP, TSA, and USCIS pages disclose facial recognition and other AI-supported activities, but absence from the inventory does not prove that no classified or sensitive analytic system exists. Likewise, a system can be algorithmic without falling within an agency’s administrative definition of “AI.” citeturn23search4turn23search10turn23search1turn23search12turn23search18

Functional inventory

Requested capabilityPublicly established present usePredictive in the relevant sense?Principal risk
Name and biometric matchingWidespread across Secure Flight, State, CBP, DHS biometrics, DoD, and TSC-supported screeningPredicts identity correspondence, not future misconductDemographic performance variation, poor image quality, transliteration, common names
Entity resolutionNecessary to TSC, TIDE, State, DHS, and DoD identity managementUsually not future-event predictionWrongly merging innocent and suspect identities
Link analysisUsed in intelligence analysis and association assessment; details partly nonpublicCan be descriptive or predictive depending on outputGuilt by association, incidental contacts, network amplification
Record prioritizationRules and risk tools route cases, travelers, and records for reviewOften predictive of relevance, workload, or riskLow-priority exculpatory records may never receive review
Anomaly detectionUsed in targeting and security analyticsYes, when estimating abnormality as a proxy for threatNormal cultural, travel, or economic variation treated as suspicious
Derogatory-information discoveryAutomated checks and rescreening find new potentially relevant informationUsually predicts relevance or likely linkage, not necessarily dangerousnessCircular reporting and context loss
Risk classificationATS and other screening systems classify or prioritize risk; No Fly policy itself is prospectiveYes when output estimates threat or adverse outcomeBase-rate error, opacity, proxy discrimination
Recommendation of additional collectionExisting analysts and systems identify gaps; 2026 RFI expressly seeks automated gap analysis and enrichmentPredicts where useful information may be found; may indirectly predict investigative valueSelf-reinforcing surveillance and one-sided collection

The 2026 Threat Screening Center AI Enhancement initiative

On March 27, 2026, the FBI posted a sources-sought notice titled Threat Screening Center AI Enhancement, Notice ID FBI-TSC-AIE. Responses were due April 10, and the notice was later updated on July 22 and marked inactive. A sources-sought notice is market research: it asks industry what capabilities exist and how they might be supplied. It is not evidence that the FBI awarded a contract, trained a production model, or authorized AI to make watchlisting decisions. citeturn13search1turn13search2

Public procurement mirrors and reporting describing the notice’s inaccessible or difficult-to-retrieve attachments identify the desired capabilities as an AI-enabled knowledge base; federated search with summarization and source attribution; identifier-driven reporting; natural-language querying across datasets; dynamic visualization; data enrichment and gap analysis; retention of citations and data lineage; and predictive modeling using enhanced data. Because the official SAM.gov page confirms the initiative but the most granular feature descriptions come from secondary procurement reproductions, those technical details should be treated as a public reconstruction rather than a complete official specification. citeturn13search4turn13search5turn13search6

One reported requirement would compare new data for similarity, pattern alignment, and attribute correlation with existing records to predict where additional relevant information may be found across federated systems. That wording does not necessarily describe a model predicting who will attack. It may describe a model predicting which database, record family, identifier, or relationship is most likely to fill an intelligence gap. It would become behavioral prediction if similarity or correlation were converted into a score estimating terrorism propensity, future violence, or operational capability. citeturn11view0turn12search0

The initiative could affect each lifecycle stage as follows:

Lifecycle stagePlausible AI-enabled changePotential benefitPrincipal legal or technical danger
Intelligence intakeExtract names, aliases, dates, documents, locations, and relationships from reports; translate and normalize textFaster exploitation of high-volume reportingHallucinated entities, translation errors, loss of uncertainty qualifiers
Nomination draftingGenerate summaries, identify allegedly relevant derogatory passages, populate formsReduced clerical delay and more consistent packagesModel-generated narrative can make weak evidence appear coherent
Sufficiency reviewCheck required fields, compare evidence with policy criteria, flag missing corroborationFewer incomplete nominationsCriteria encoded incorrectly; reviewers defer to a compliance score
Identity resolutionCross-lingual entity resolution, graph-based alias linking, multimodal biometric-biographic comparisonBetter disambiguation and fewer duplicate recordsCatastrophic merge of innocent and suspect identities
Inclusion or rejectionRank nominations by apparent evidentiary strength or similarity to accepted casesFocus scarce expert reviewHistorical bias becomes a template; similarity substitutes for individualized suspicion
Quality controlDetect conflicting fields, stale sources, circular citations, duplicate reporting, unsupported associationsDirectly addresses known accuracy problemsModels may flag only machine-readable inconsistencies and miss substantive unreliability
DisseminationTailor fields and handling instructions to recipient missionData minimization and fewer irrelevant alertsIncorrect routing expands consequences or withholds needed exculpatory context
Encounter handlingSummarize record, rank matching identifiers, recommend disambiguating questionsFaster resolution and shorter detentionAutomation bias; generated summary omits mitigating facts
ModificationDetect new information inconsistent with the record or suggest changed subset eligibilityMore timely correctionAsymmetric design may search for new derogatory data more aggressively than exculpatory data
Periodic reviewPrioritize aged, low-confidence, association-based, or uncorroborated recordsMakes meaningful review feasible at scaleLow-priority records can persist indefinitely without human reconsideration
RedressCompare complainant submissions with source records and identify factual conflictsFaster resolution and clearer issue listsSecret automated credibility scoring; submission used to discover new derogatory leads
RemovalRecommend removal where current evidence no longer satisfies criteriaReduces stale listingsHumans may resist AI-recommended removal more than AI-recommended retention
Collection recommendationIdentify missing fields and databases likely to contain relevant evidenceMore targeted collectionCreates an escalating loop in which uncertainty always justifies more surveillance
Threat assessmentEstimate likelihood of aviation, homeland, facility, or violent-terrorism threatPotentially more consistent No Fly reviewThis is the clearest path to algorithmic pre-crime and the most severe base-rate problem

The most defensible use is procedural and quality oriented: extraction, translation assistance, duplicate detection, source-lineage analysis, contradiction detection, stale-record identification, and balanced presentation of derogatory and mitigating information. The least defensible use is an opaque model whose score materially establishes reasonable suspicion, association, future threat, or operational capability.

Technical safeguards necessary before deployment

Any high-impact deployment should maintain the original source beside every generated statement; preserve report-level caveats and source reliability; show which facts are independent and which derive from the same origin; separate observed facts from analyst inference and model inference; record every model version and prompt; permit reproducible reruns; measure error by language, name structure, nationality, sex, age, image quality, and record completeness; and force reviewers to state an independent rationale when adopting an adverse recommendation.

A model should never be allowed to “launder” uncertainty. “Source could not verify whether the traveler met X” must not become “traveler likely met X.” Summarization must preserve negation, temporal qualifiers, alternative explanations, and confidence labels. Natural-language interfaces also require strict access controls because an apparently simple question can retrieve, combine, or infer information the user was not authorized to see in one place.

Evaluation must distinguish at least four tasks: candidate generation, identity confirmation, substantive nomination eligibility, and future-threat prediction. Reporting one overall “accuracy” number would be meaningless. Candidate generation should emphasize recall but be followed by strict resolution. Identity confirmation should report false-match and false-nonmatch rates. Nomination support should be tested against blinded expert review. Threat prediction should be assessed for calibration, positive predictive value, subgroup error, temporal drift, and whether it adds value over transparent rules.

The RFI’s stated interest in traceable lineage and source attribution is therefore important. Properly implemented, those features could make human decision-making more auditable than current fragmented searches. Improperly implemented, an AI knowledge base could aggregate so much information and generate such persuasive narratives that nominal human review becomes ceremonial.

Redress, oversight, and case law

DHS TRIP

DHS TRIP is the primary administrative intake mechanism for travelers who experience repeated secondary screening, denial of boarding, border delays, inability to print boarding passes, or related travel difficulties. A complainant supplies identity documents and details of the incident and receives a redress control number. TSA, CBP, TSC, and other components review the matter according to the type of screening problem. A control number helps systems distinguish the traveler but is not a certificate that the traveler has been removed from every government record. citeturn22search6turn6view0

For ordinary inquiries, the government generally neither confirms nor denies broader TSDS status. It may state that records were reviewed and any necessary corrections made. If the person was merely confused with a listed individual, TSA can add the person to its Cleared List and CBP can create an override record. These mitigations reduce repeated false matches but can leave the underlying listed person’s record untouched. citeturn22search6

A U.S. citizen or lawful permanent resident denied boarding because of No Fly receives greater process. The government can confirm No Fly status and provide an unclassified summary of reasons to the extent possible without unacceptable national-security or law-enforcement harm. The person may submit a response. TSC reassesses the record and, if it recommends continued listing, the TSA Administrator issues a final order. That order is reviewable directly in a federal court of appeals under 49 U.S.C. § 46110. citeturn6view0turn19search0

The process’s strengths are that it can force interagency review, correct identity errors without litigation, disclose at least some reasons in the most severe travel cases, and produce a reviewable final order. Its weaknesses are delay, limited disclosure, lack of an independent adjudicator, government control over the record, absence of ordinary discovery and cross-examination, and sharply reduced process for people subject only to Selectee, border, visa, passport, credential, or broader TSDS effects.

FOIA, Privacy Act, congressional assistance, and internal review

A person can file Freedom of Information Act requests with FBI, DHS, TSA, CBP, State, or other involved agencies. In practice, terrorism-watchlist records are frequently withheld under exemptions protecting classified information, law-enforcement techniques, intelligence sources and methods, personal privacy, and ongoing investigations. The Privacy Act contains access and amendment mechanisms, but many relevant systems have exemptions. GAO concluded that FOIA and similar requests generally do not produce disclosure or change in watchlist status. citeturn22search6

A member of Congress can make an inquiry, contact DHS TRIP or TSC, request a briefing, or seek help resolving a constituent’s case. Congressional assistance may accelerate attention but does not create a separate evidentiary hearing or compel disclosure of classified reasons. CBP and TSA ombudsman offices can resolve program-specific complaints, while agency inspectors general and civil-rights offices can investigate systemic misconduct. GAO found that these channels usually redirect the person to DHS TRIP when the issue is watchlist-related. citeturn22search6

Litigation itself can trigger renewed agency review. GAO reported an informal TSC Redress Office practice under which relevant agencies are asked, with a short deadline, to provide updates that might affect a litigant’s status. This can produce removal, but it also creates a mootness dispute if the government changes status after suit without conceding error. citeturn22search6turn18search1

Case-law chronology and current precedential status

DateCaseIssue and holdingPresent status through August 2, 2026
2008–2012Ibrahim v. Department of Homeland Security, 538 F.3d 1250 and 669 F.3d 983 (9th Cir.)Established jurisdictional and standing principles for a noncitizen former U.S. student with substantial voluntary U.S. connections challenging erroneous watchlisting effectsBinding Ninth Circuit precedent on the issues decided; highly fact-specific
2014Ibrahim v. DHS, 62 F. Supp. 3d 909 (N.D. Cal.)After trial, found that an FBI agent’s mistaken nomination handling caused erroneous No Fly treatment and ordered correction of interconnected recordsInfluential district-court merits judgment, not nationwide appellate precedent; later Ninth Circuit litigation concerned relief and attorney fees rather than reversing the core factual finding
2014Latif v. Holder, 28 F. Supp. 3d 1134 (D. Or.)Held the then-existing No Fly redress process constitutionally inadequate because affected U.S. persons lacked meaningful notice and opportunity to respondAddressed the pre-2015 process; its practical force was superseded by revised procedures later upheld in Kashem
2015Mokdad v. Lynch, 804 F.3d 807 (6th Cir.)Held that district court could hear a direct challenge to TSC’s placement decision; TSA was necessary for some procedural claimsBinding Sixth Circuit jurisdictional precedent
2017Mokdad v. SessionsAffirmed mootness after a declaration that the plaintiff was not and would not be placed on No Fly based on current informationStill circuit precedent, but the Supreme Court’s later Fikre decision imposes a more demanding voluntary-cessation analysis where recurrence remains reasonably possible
2019Kashem v. Barr, 941 F.3d 358 (9th Cir.)Rejected vagueness and procedural-due-process challenges to revised No Fly criteria and redress procedures; accepted disclosure limits and ex parte treatment of sensitive informationBinding Ninth Circuit precedent; principal appellate approval of enhanced No Fly redress
2019–2021Elhady v. Kable, 391 F. Supp. 3d 562, reversed, 993 F.3d 208 (4th Cir.)District court held broader watchlist procedures inadequate; Fourth Circuit reversed, finding plaintiffs had not established deprivation of a protected liberty interest and rejecting stigma-plus theories based on intergovernmental disseminationThe Fourth Circuit reversal is controlling within that circuit; the district court’s contrary merits judgment is no longer authoritative
2020Tanzin v. Tanvir, 592 U.S. 43Held that the Religious Freedom Restoration Act permits appropriate monetary relief against federal officers in their individual capacities; underlying plaintiffs alleged No Fly placement for refusing to become informantsUnanimous Supreme Court precedent on RFRA remedies, not a ruling that the alleged listing conduct occurred or that watchlisting generally violates RFRA
2021Jibril v. Mayorkas, 20 F.4th 804 (D.C. Cir.)Held that alleged repeated Selectee-style airport burdens and concrete plans to travel could establish Article III injury for standingBinding D.C. Circuit standing precedent; did not finally adjudicate watchlist merits
2022–2024Fikre v. FBI / FBI v. Fikre, 35 F.4th 762; 601 U.S. 234Supreme Court unanimously held that removal from No Fly and a promise limited to “currently available information” did not satisfy the government’s burden to show the challenged conduct could not reasonably recurBinding nationwide mootness precedent; the Court did not decide the due-process merits and expressly did not require disclosure of classified information as a universal condition of mootness
2026Khalid v. TSA, D.C. Cir. No. 23-1150Upheld a TSA Administrator final order maintaining No Fly status; rejected substantive-due-process and procedural challenges and reviewed sensitive material through the statutory appellate processBinding D.C. Circuit precedent as of April 14, 2026
2026Khalid v. Blanche, D.C. Cir. No. 24-5091Held that a separate district-court challenge to broader watchlist status lacked redressability while an active TSA No Fly final order independently imposed the same travel injury; emphasized § 46110’s exclusive-review structureBinding D.C. Circuit jurisdiction and standing precedent; creates a difficult sequencing problem for simultaneous TSDS and No Fly challenges

Ibrahim. The Ibrahim litigation is the clearest public example of a concrete nomination error. The Ninth Circuit allowed the challenge to proceed despite the plaintiff’s foreign location and visa complications, and the district court found after trial that an agent had mistakenly handled the watchlist nomination. The case also demonstrates the practical entanglement of No Fly, Selectee, CLASS, border systems, and other downstream records: correcting one designation did not automatically correct every derivative effect. The government invoked secrecy interests during the litigation, but the court was able to decide the case on a limited factual record rather than dismiss it wholesale. citeturn17search9turn17search3turn17search6

Latif and Kashem. Latif held that the old DHS TRIP process provided insufficient notice and opportunity to challenge No Fly placement. The government revised the process, adding status confirmation and an unclassified statement of reasons for eligible U.S. persons. In Kashem, the Ninth Circuit held that the revised process satisfied due process, giving substantial weight to aviation-security interests, limits on disclosure, and the availability of court-of-appeals review. Kashem is therefore the governing Ninth Circuit precedent, while Latif remains historically important for explaining why enhanced redress exists. citeturn17search12turn17search1

Elhady. The district court concluded that the broader watchlist’s consequences and lack of notice violated procedural due process. The Fourth Circuit reversed. It held that routine delays and burdens at borders and airports did not deprive the plaintiffs of a historically recognized liberty interest in the manner required, and that intragovernmental or law-enforcement dissemination did not constitute public disclosure for a stigma-plus claim. Rehearing was denied, and later Fourth Circuit decisions continue to cite Elhady as controlling. citeturn20search2turn20search21turn20search4

Tanzin. The Supreme Court’s holding was remedial: RFRA’s authorization of “appropriate relief” includes damages against federal officers in their individual capacities. The Court accepted the allegations—that agents used No Fly placement to pressure Muslim men to become informants—for purposes of deciding the legal remedy. It did not adjudicate the truth of those allegations. The case nevertheless matters because damages can remain available after removal moots injunctive relief, subject to immunity and merits defenses. citeturn21search0

Jibril. The D.C. Circuit recognized that repeated airport screening burdens can establish injury in fact when plaintiffs have concrete travel plans. This is significant because the government generally does not confirm Selectee status, making standing otherwise difficult. Jibril does not establish a constitutional entitlement to Selectee notice or removal, but it rejects the proposition that enhanced screening is always too minor or speculative to enter federal court. citeturn18search6turn21search6

Fikre and mootness. The government removed Fikre from No Fly and declared that he would not be relisted based on currently available information. The Supreme Court held that this was insufficient to moot the case because it did not establish that the alleged conduct could not reasonably recur, including if the same conduct were evaluated again. Justice Alito, joined by Justice Kavanaugh, emphasized that the ruling did not require classified disclosure to the plaintiff or court in every case. Fikre is a procedural victory for reviewability, not a ruling that Fikre’s original placement was unconstitutional. citeturn18search1turn18search4turn18search17

Khalid in 2026. The D.C. Circuit reviewed a TSA final order maintaining a U.S. citizen on No Fly after enhanced redress. It concluded that there is no fundamental substantive-due-process right to travel specifically by air where other modes remain theoretically available, accepted the administrative procedures, and sustained the order under the applicable review framework. In the parallel case, it held that a district-court order concerning broader TSDS status could not redress the travel injury while the TSA order independently maintained No Fly status. Together, the decisions strengthen § 46110 review but can prevent a district court from separately adjudicating the antecedent TSC watchlist decision while an active No Fly order stands. citeturn19search0turn19search1

State secrets, classified evidence, and disclosure

Watchlist litigation operates at the intersection of the state-secrets privilege, classified-information protection, law-enforcement privilege, statutory review records, and ordinary due process. These doctrines are distinct. A court can uphold a privilege over particular evidence without dismissing the whole action; it can review material ex parte or in camera; it can require an unclassified summary; or it can conclude that the plaintiff cannot establish a claim without protected evidence.

The current appellate trend accepts substantial secrecy. Kashem approved procedures that withhold information where disclosure would harm national security or law enforcement. Khalid involved nonpublic TSC recommendations and sensitive record material. Fikre’s concurrence expressly cautioned that the mootness holding did not create a general requirement to disclose classified grounds. Ibrahim shows that a court can sometimes identify a bureaucratic error without exposing the full intelligence basis. citeturn17search1turn19search0turn18search17turn17search3

The central due-process dispute is therefore not “complete disclosure versus complete secrecy.” It is how to provide enough notice to permit a meaningful response while protecting genuinely sensitive sources and methods. Possible intermediates include unclassified factual summaries, security-cleared special counsel, judicial access to complete source records, admissions or denials of specific factual propositions, and disclosure of the criteria and non-sensitive evidence without revealing collection methods.

Steelman analysis, reforms, and pre-crime determination

The strongest case for the system

The system’s strongest justification is institutional rather than algorithmic. Before consolidation, agencies could possess separate fragments—a name in a diplomatic cable, a fingerprint from a military encounter, a visa application, and an FBI lead—without realizing they concerned the same person. TSDS, TIDE, WLS, Secure Flight, State systems, and NCIC allow agencies to connect those fragments and make the result available at the point of decision. HSPD-6’s central premise—that identity information should not remain trapped in organizational silos after September 11—remains compelling. citeturn6view0turn24search17

Preventive screening also addresses harms for which waiting for probable cause may be irrational. Aviation attacks can produce catastrophic and irreversible loss. A person can present a security threat without evidence sufficient for criminal prosecution, especially where intelligence comes from foreign partners, disrupted plots, protected sources, or conduct outside U.S. jurisdiction. A reasonable-suspicion standard, additional No Fly threat criteria, identity-sufficiency requirements, multi-agency review, and restricted dissemination can be defended as calibrated administrative risk management rather than punishment. citeturn6view0turn17search1

The system contains more safeguards than the phrase “secret blacklist” suggests. Only government agencies can nominate; constitutionally protected activity and protected characteristics may not be the sole basis; NCTC or FBI reviews precede TSC acceptance; TSC can reject nominations; identifiers must be sufficient for screening; agencies must modify or retract inaccurate information; records receive audits and encounter-triggered review; U.S.-person records receive special treatment; and enhanced No Fly redress provides notice, response, a final TSA order, and judicial review. citeturn6view0turn10search2turn14view0

A federated model can also prevent overreach. TSC identifies and coordinates, but the screen­ing agency must apply separate authority. A local officer does not receive an arrest warrant merely because NCIC produces an alert. State cannot lawfully deny a passport solely because a database says “watchlisted” if passport law supplies no ground. USCIS must adjudicate the immigration benefit under the INA. This separation creates multiple opportunities to reject an unjustified consequence.

Finally, secrecy can protect legitimate operational interests. Revealing that an intelligence service supplied an alias, that the government can link a specific communications identifier, or that a person is not under scrutiny can compromise sources, enable evasion, and expose officers or partners. Broad public confirmation or denial could let a group test which operatives are known by sending them through screening points. The Fourth and Ninth Circuits have credited these concerns. citeturn17search1turn20search2

The strongest case against the system

The counterargument begins with the severity and diffusion of consequences. A single, secret identity determination can propagate into aviation, border, visa, passport, immigration, credential, clearance, military-access, firearms, and police systems. The affected person may never learn which source caused the problem, which agency owns it, whether the person is actually listed, or whether a cleared-list notation merely masks rather than corrects the error. The institutional separation that protects against automatic action also makes responsibility difficult to locate.

The substantive threshold is low relative to the consequences. Reasonable suspicion is below probable cause and can rely on rational inferences. Watchlist Exceptions permit some screening effects without ordinary reasonable suspicion, based on connection or association. No Fly adds a future-threat judgment but still does not require criminal charge or conviction. A person may therefore suffer a major mobility restriction on the basis of secret, partly inferential, and potentially untested intelligence.

The system is structurally vulnerable to one-sided evidence. Intelligence collection is designed to discover threats, not to build a balanced adjudicative record. A source report enters the file because it is suspicious; absence of corroboration can motivate more collection rather than exoneration; and an encounter generated by the listing can create further reporting. Unless reviewers deliberately search for disconfirmation, the record can become an accumulating dossier in which quantity is mistaken for independent corroboration.

The downstream consequences are not transparent enough to measure. The government publishes no current global false-match rate, false-negative rate, subset population, nomination rejection rate, average duration, source-quality distribution, demographic error rate, or number of people retained solely through association criteria. DHS TRIP data are useful but self-selected. The public cannot determine whether 88 removals among 289 watchlist-related complaints reflects effective correction or a system that required burdensome complaints to repair stale records. citeturn22search6turn14view0

Redress remains asymmetrical. The government sees the full record; the person usually sees little or nothing. Even enhanced No Fly disclosure can omit evidence. The reviewing TSC is part of the same enterprise that maintained the record, and the TSA Administrator receives TSC’s nonpublic recommendation. Court review may rely on an ex parte record, while broader TSDS claims can face standing, privilege, jurisdiction, mootness, and redressability barriers. Khalid’s 2026 decisions illustrate how an active TSA order can prevent separate district-court review of the antecedent watchlist status. citeturn19search0turn19search1

The system’s expansion beyond terrorism creates mission-creep risk. The 2025 renaming and TSS architecture now encompass separate transnational-organized-crime and military-detainee datasets. Logical separation is a safeguard, but shared infrastructure, personnel, analytics, and dissemination channels can normalize broader preventive listing. The question is no longer only whether terrorism identities should be consolidated, but which categories of suspected threat actors can be subjected to watchlist-like treatment without ordinary adjudication. citeturn1search0turn8view7

AI can intensify each weakness. A model trained on historical nominations learns the biases of prior source selection and association practices. A generated summary can hide contradictions. Similarity to previously listed people can be mistaken for independent suspicion. Automated prioritization can leave low-ranked exculpatory reviews untouched. Natural-language interfaces can make massive data fusion effortless, while source details disappear behind a fluent answer. A human signature at the end does not ensure meaningful human judgment.

Reform options

Improve nomenclature and public reporting. The FBI should publish an annual TSDS transparency report using current TSC, TSS, and TSDS terminology. It should disclose, at minimum, total persons; U.S.-person totals; subset counts in ranges where exact numbers are sensitive; annual nominations, rejections, removals, downgrades, and modifications; median duration; redress times; misidentification outcomes; and the number of records maintained under exception criteria. PCLOB has recommended stronger recurring transparency, and GAO has identified major oversight gaps. citeturn14view0turn3view1

Create denominator-aware accuracy metrics. Agencies should separately measure false candidate matches, false confirmed matches, contaminated identifiers, substantively unsupported listings, stale listings, and false negatives. Reports should state the population and denominator. “Twenty-one misidentifications” is meaningful only with the 289 watchlist-related complaint denominator and the limitation that complainants are self-selected.

Audit source independence and circularity. Every material fact should have machine-readable lineage to its originating report. Systems should show when several reports derive from one source, when an encounter was caused by the watchlist itself, and when an association was inferred rather than observed. Reviewers should be prohibited from counting derivative reporting as independent corroboration.

Make exculpatory review mandatory. Nomination, periodic review, and redress forms should contain a required section identifying mitigating information, contrary evidence, alternative explanations, source reliability problems, and investigative closures. Supervisors should reject packages that merely state “none known” without documenting the search performed.

Time-limit weak and association-based records. Records relying principally on association, low-confidence identity data, or one uncorroborated source should expire unless affirmatively renewed after de novo review. More serious, biometrically confirmed records could have longer review intervals. “No new information” should not automatically equal “continue indefinitely.”

Strengthen identifier controls. High-consequence designations should require stronger identifier combinations than low-level analytic holdings. No Fly confirmation should ordinarily require document, date-of-birth, biometric, or similarly discriminating agreement before boarding denial, with an emergency escalation path for incomplete identities. Common-name-only matching should never produce a final adverse action.

Propagate corrections. TSC should operate an auditable correction protocol that identifies every downstream recipient, acknowledges receipt, verifies update completion, and distinguishes deletion, archival restriction, cleared-list mitigation, and substantive removal. The person should receive a non-sensitive statement identifying which classes of systems were corrected.

Improve local encounter training. TSC and CJIS should provide current scenario-based training, quick-reference materials, and periodic testing for dispatchers and officers. Given GAO’s finding that 24 of 26 interview groups lacked awareness of current materials, relying on passive distribution is inadequate. citeturn2view2turn4view5

Build AI first for auditing, not adverse scoring. Initial AI deployment should focus on duplicate detection, transliteration review, source-lineage analysis, contradiction detection, stale-record identification, and redress triage. Models should not establish reasonable suspicion, association, No Fly threat, or operational capability until Congress or binding public rules specify permissible inputs, validation requirements, and review rights.

Require model cards and decision logs. For every high-impact model, agencies should document purpose, prohibited uses, training data, validation population, subgroup error, calibration, known limitations, human-review requirements, and change history. Each affected decision should preserve the model version, input fields, output, explanation, reviewer action, and independent rationale.

Ban protected-class and proxy shortcuts. Existing policy bars race, ethnicity, national origin, religion, and protected beliefs as sole bases. AI rules should go further by testing proxy effects and preventing those characteristics from materially driving a risk score absent a narrowly tailored and legally authorized reason. Removing an explicit field is insufficient when language, location, family ties, or religious activity functions as a proxy.

Adopt adversarial validation. Independent teams should attempt to trigger false matches using common names, transliteration variants, corrupted documents, shared addresses, low-quality images, and adversarially selected records. Red-team findings should be supplied to inspectors general, PCLOB, GAO, and appropriate congressional committees.

Create an independent administrative adjudicator. No Fly and other severe consequences could be reviewed by a security-cleared administrative judge or independent board outside TSC and the screening component. The adjudicator should have access to the complete record, authority to compel correction across agencies, and responsibility to produce an unclassified explanation.

Expand notice beyond No Fly. Repeated Selectee treatment, sustained border consequences, passport action, denial of a major immigration benefit, loss of a federal credential, or other materially adverse action attributable to TSDS should trigger notice that watchlist information materially contributed, subject to tailored delay where disclosure would threaten an active investigation.

Use security-cleared special counsel where necessary. In cases involving highly classified evidence, a vetted advocate could test source reliability, challenge circular reporting, and present exculpatory arguments without disclosing protected material to the claimant. This is not equivalent to ordinary open litigation, but it is more adversarial than one-sided ex parte review.

Make the burden explicit. The government should bear the burden of establishing continued eligibility when a person presents a plausible factual rebuttal, when a record exceeds a specified age, or when the principal source has been discredited. A claimant should not have to disprove undisclosed allegations.

Provide judicially reviewable notice and appeal. Congress could create a unified cause of action permitting review of TSC status and downstream consequences in one proceeding, resolving the jurisdictional fragmentation between district-court challenges and § 46110 petitions. Courts should be authorized to review the full record, order cross-system correction, retain jurisdiction after voluntary removal, and award fees where the government cannot substantially justify the listing.

Clarify remedies and retention. Removal orders should specify whether active TSDS status, subset designations, downstream flags, and erroneous identifiers must be deleted, blocked, or annotated. Archival retention may remain appropriate for accountability and intelligence history, but archived records should not silently re-enter active screening without a fresh eligibility determination.

Final determination: which elements resemble “pre-crime”

“Pre-crime” is not a legal term with one settled threshold. For this report, an element reasonably resembles pre-crime when government imposes or materially supports an adverse preventive consequence because it estimates that a person may engage in future harmful conduct, before criminal adjudication, particularly when the estimate is secret and difficult to contest.

Elements that do not reasonably resemble pre-crime by themselves include maintaining accurate names and biometrics; translating and transliterating identifiers; merging genuine duplicate records; separating innocent people with common names; comparing a passport photograph with a stored image; transmitting an existing record to an authorized screener; detecting data-quality conflicts; or notifying an officer that an encountered person may match a record. These are identity, records-management, or communication functions.

Elements that are preventive but only weakly resemble pre-crime include visa, border, facility-access, and credential screening based on established statutory disqualifications or documented past conduct. They act before a new offense occurs, but many administrative screening regimes have always been preventive. The resemblance increases when the underlying ground is an undisclosed forecast rather than a defined legal disqualification.

Ordinary TSDS known-or-suspected-terrorist eligibility moderately resembles pre-crime because the definition expressly includes a person who “intends to engage” in terrorism. Yet it also reaches suspected past and present involvement and requires articulable information and reasonable suspicion. A record based on evidence of completed material support is less pre-crime-like than one based principally on inferred future intent.

Watchlist Exceptions based on association can strongly resemble pre-crime where an individual who is not reasonably suspected of terrorism receives adverse screening because a relationship is thought to create future risk. The resemblance depends on the consequence. Loss of expedited screening is minor; repeated border detention, denial of a credential, or immigration consequences are much more significant.

No Fly is the clearest existing pre-crime analogue. Its additional criteria ask whether a person poses specified future terrorism threats and, in one category, is operationally capable of violent terrorism. The government prevents air travel before prosecution or proof beyond a reasonable doubt. The system’s defenders accurately characterize this as preventive aviation security; its critics accurately observe that it is a severe restraint based partly on predicted dangerousness.

ATS-style risk assessment and anomaly detection resemble pre-crime when they estimate threat rather than merely find a known record. A targeting rule that says “this passport is reported stolen” is factual screening. A model that says “this combination of travel and associations predicts elevated terrorism risk” is predictive. The label “decision support” does not alter the function.

The 2026 AI initiative is not yet proven to be a pre-crime system. The official record establishes market research for AI enhancement, while public descriptions emphasize federated search, summarization, lineage, data enrichment, gap analysis, similarity, pattern alignment, and predictive modeling. Predicting where additional relevant information may exist is not the same as predicting a terrorist act. The initiative would cross the pre-crime line if model outputs materially determine that a person intends terrorism, poses a future aviation or homeland threat, is operationally capable, or deserves adverse screening because of similarity to prior cases. citeturn13search1turn13search5turn11view0

The decisive governance question is therefore not whether the enterprise “uses AI.” It already uses extensive automation, probabilistic matching, risk tools, and decision support. The decisive questions are what uncertainty the system predicts, what consequence follows, what independent evidence is required, whether the person can understand and challenge the result, and whether an accountable official genuinely re-evaluates the evidence.

On the public evidence through August 2, 2026, the United States terrorism-watchlisting enterprise is best understood as a hybrid. Its core is an identity-resolution and information-sharing system. Around that core sit administrative screening regimes with distinct legal powers. Within those regimes, No Fly, association-based exceptions, some targeting analytics, and any future AI-driven dangerousness scoring have genuine pre-crime characteristics. The system is not wholly pre-crime, but neither is “mere matching” an adequate description of its most consequential and prospective functions.