RAND's Warning on Biometric and Digital ID Systems

A new report from RAND is putting fresh weight behind a concern privacy advocates have raised for years: identity systems built for one purpose rarely stay confined to that purpose. According to the report, security agencies adopting biometric identification, digital identity, and AI systems should be required to justify the need for the technology before acquiring it in the first place.

That may sound like a basic bureaucratic safeguard, but its absence is exactly the problem RAND is highlighting. Once an agency has facial recognition, fingerprint databases, or digital ID infrastructure in place, the systems tend to get pulled into uses well beyond their original justification. RAND's core argument is that biometric digital ID surveillance risks aren't hypothetical edge cases. They are a predictable outcome of how these tools get adopted and expanded once they exist.

From Verification Tool to Targeting Tool

The pattern RAND describes is straightforward. A biometric or digital ID system gets introduced to solve a narrow problem: verifying a traveler's identity, confirming eligibility for a service, or checking someone's age. But the underlying infrastructure, the databases, the matching algorithms, the collection points, doesn't disappear once that narrow task is done. It becomes a standing capability that other parts of government, or other agencies entirely, can tap into.

This is how identification systems become targeting systems. A database built to confirm who someone is can just as easily be used to track where someone has been, who they associate with, or whether they match a watchlist. RAND's call for agencies to justify need before acquisition is essentially an attempt to slow that drift before it happens, by forcing a conversation about scope and limits at the point of adoption rather than after the system is already entrenched and difficult to unwind.

Digital ID and Age Verification Are Already Normalizing This Infrastructure

What makes RAND's report notable isn't just its warning about security agencies abroad. It lands at a moment when similar infrastructure is being built inside the United States, often under a far less controversial banner: protecting children online.

Age verification laws and proposals increasingly require platforms or governments to confirm a user's age, and confirming age in practice means confirming identity. A CGO research paper on age verification has already raised the question of what happens to the identity data these systems collect once the immediate child-safety justification has been satisfied. The paper argues that the rush to pass these laws often skips over exactly the kind of scrutiny RAND says should be mandatory before any identity system gets built at all.

The same dynamic shows up in legislative proposals like the KIDS Act. As one analysis explains, the bill is pitched as a child-safety measure but functions as a surveillance system that would apply to the entire population, not just minors. Age checks require verifying everyone, which means the infrastructure ends up covering adults too. That is the repurposing problem RAND describes, just playing out domestically through child-safety framing rather than national security framing.

What This Means For You

Most people will never interact directly with the kind of security agency systems RAND's report focuses on. But the underlying lesson applies broadly: any system that collects biometric or identity data for one stated purpose can be redirected toward another purpose later, often without the person whose data it is ever being told. Age verification systems, digital ID programs, and biometric login tools all carry this same structural risk, regardless of how benign the original pitch sounds.

This doesn't mean every digital ID or age verification proposal is secretly a surveillance program. It means the burden of proof should sit with the agency or company proposing the system, not with the public trying to anticipate how the data might be used five years down the line.

What Policymakers and Citizens Should Demand

RAND's recommendation, that agencies justify need before acquiring biometric or digital ID technology, is a reasonable floor, not a ceiling. Policymakers evaluating any new identity system, whether framed around security, child safety, or convenience, should ask what specific problem the system solves, who else will have access to the data it collects, and what happens to that data once the original task is complete. Privacy-conscious citizens can push for the same questions to be asked publicly before these systems are deployed, not after they've already become permanent infrastructure.

The throughline connecting RAND's report to domestic age verification debates is simple: once an identity system exists, its use tends to expand. Demanding justification up front, and clear limits on secondary use, is one of the few tools available to stop biometric digital ID surveillance risks from becoming reality rather than warning.