RAND urges strict oversight as security biometrics enable discriminatory surveillance

RAND warns security biometrics, digital ID can become tools for targeting

Security agencies that deploy biometric identification, digital identity platforms, and AI systems without first proving necessity risk building surveillance infrastructure that targets vulnerable populations, according to a new RAND Europe report.

The findings land amid accelerating adoption of these tools across policing, border control, and national security functions. Governments worldwide now face pressure to modernize identity verification while guarding against discrimination, opaque decision-making, and misuse.

The five-month study, backed by the UK Foreign, Commonwealth & Development Office, involved 13 expert interviews, a literature review, and an internal workshop. Researchers identified nine emerging technology areas, from drones and blockchain to augmented reality and satellite imagery. Yet the most urgent conclusions center on biometrics, digital ID, AI decision support, and large-scale data systems working together.

RAND highlights biometric capabilities expanding well beyond fingerprints and facial scans. Voice recognition, gait analysis, typing patterns, and swipe behavior now function as identifying markers. Law enforcement increasingly favors multimodal systems that combine several traits, including AI-assisted facial recognition capable of processing low-resolution images or partially obscured faces.

The report flags documented higher misidentification rates for women, Black people, and ethnic minorities in facial recognition systems. It also raises consent concerns, noting that people required to submit biometrics for essential services may not understand how their data gets used. Refugees and other marginalized groups face particular vulnerability. In fragile states, weak cybersecurity makes biometric databases prime targets for breaches and surveillance overreach.

Digital identity presents a similar paradox. Ukraine’s Diia app demonstrated how state-controlled platforms can deliver critical services during wartime. Yet concentrating sensitive personal data within a single system creates risk if governance fails or foreign vendors control underlying infrastructure.

RAND dismisses the notion that keeping a “human in the loop” adequately guards against AI failures. Automation bias leads operators to trust algorithmic outputs even when evidence contradicts them. The report recommends layered oversight instead, including data provenance tracking, access logs, bias testing, and trained personnel empowered to challenge machine decisions.

The path forward, according to RAND, demands pre-acquisition assessments covering purpose, local conditions, data ownership, and misuse potential. Independent auditing and enforceable consequences for abuse matter as much as technical accuracy.