top of page

From the ‘Worst of the Worst’ to the Easiest To Arrest: How AI Is Powering Immigration Enforcement

  • 2 hours ago
  • 3 min read

Aug 14, 2026


From the ‘Worst of the Worst’ to the Easiest To Arrest: How AI Is Powering Immigration Enforcement

Shifted gears to a more targeted immigration enforcement approach that depends heavily on machine learning to arrest those already in the system. (Image via Canva)

 

Rather than the “worst of the worst” that Trump promised to target on his 2024 campaign trail, immigration authorities are increasingly using AI-driven surveillance tools to find and arrest whoever is easiest to catch.

A strategy described by Trump “border czar” Tom Homan as one of “shock and awe” saw masked immigration agents swarm entire cities nationwide, shoot at least 23 people and kill six since last year, including three U.S. citizens. But the Department of Homeland Security (DHS) has recently shifted gears, opting for a quieter, more targeted approach that depends heavily on machine learning to arrest those already in the system, sometimes warrantlessly

More than 6 million immigrants with temporary protections are potentially exposed, including those with Temporary Protected Status, DACA recipients and people with pending asylum cases or humanitarian parole.

AI agents help DHS cost-effectively identify these immigrants and locate what internal ICE documents deem “target-rich” environments, like immigrant enclaves, where arrests will yield the largest haul of detainees. 

DHS does this by first gaining access, through questionably legal means, to confidential personal data from federal sources including the IRSstate Medicaid rolls and SNAP records. It then layers that onto its own administrative records from immigrants’ U.S. Citizenship and Immigration Services (USCIS) filings. 

But raw data alone isn’t especially useful; the bulk of DHS spending on immigrant surveillance is instead on aggregating this data to show how to locate millions of potential targets through analyses of patterns in individual behavior.

While DHS spent $228.6 million on data purchase contracts since January 2021, for instance, it has spent $622.8 million on data analytics.

While DHS enforcement strategy still relies heavily on human intelligence from 287(g) partnerships with local law enforcement, it is increasingly enhanced by constantly evolving surveillance tools. Immigration-related AI use cases at DHS rose 36% by January 2026 over 2024 levels, according to the American Immigration Council.

But a series of third-party system hacks by frontier AI models at OpenAI, Meta and Anthropic — the same kind of AI agent that the Trump administration now uses for immigration enforcement — raises the question of how much control AI owners have over even their own tools.

Last July, a test version of OpenAI’s ChatGPT software, running without its usual safety guardrails as part of a worst-case capability test, used a previously unknown vulnerability to access the internet and breach the infrastructure of AI startup platform Hugging Face while seeking answers for a benchmark test.

Hugging Face’s chief security officer noted that over five days, the company’s agent took 17,000 steps before it successfully invaded and mapped the data in the startup’s AI lab.

OpenAI called the attack “unprecedented,” saying the software went to “extreme lengths” to find ways to “cheat.”

Meta disclosed its own incident last August when a model breached an unidentified company’s systems during a security test. In this case, no guardrails were removed; the third-party tester said “the exact same” bug had let the model access the internet the prior week, when Anthropic’s models used it to hack three other organizations’ systems.   

The OpenAI, Meta and Anthropic incidents show that once these systems’ explicit guardrails come off, they may become not just tools in the surveillance dragnet but semi-autonomous actors that pursue their owners’ broad goals past the rules created to contain them — a dynamic with direct bearing on the Trump administration’s mass deportation campaign

It’s not clear that our legal system is prepared to respond to AI-driven misuse of confidential personal data, no matter the guardrails in place; under this administration, that readiness can’t be taken for granted. 

AI’s tendency to learn on the job suggests that, as with Trump administration officials, the AI systems now used in federal immigration enforcement will adapt to what the administration rewards, meaning less weight given to legal compliance over time.

Characterizing lawfully present immigrants as “criminals” or “invaders,” for example, can erode an AI surveillance tool’s respect for their individual rights. 

Human actors may be no more reliable: The immigration agent who killed Colombian immigrant Johan Sebastian Duran Guerrero in Maine had a record of disturbing behavior before joining Immigration and Customs Enforcement (ICE), and may have been unable or unwilling to self-correct. 

Nor does this surveillance dragnet end with immigrants.

These data tools, funded by taxpayer dollars reaching $310 million in 2025 and as much as $513 million this year, are already being deployed against U.S. citizens

Trump issued an executive order last June directing the Department of War, DHS and other agencies to take “expeditious action” to secure federal data systems against malicious intrusion. 

The order says nothing about preventing the government from turning those same tools against U.S. households, or about who gets to determine when these tools have been misused.

 

Comments


bottom of page