Photo by Albert Stoynov on Unsplash
Remember when Face ID felt like the future? You'd hold your phone up, it would scan your face in a fraction of a second, and you'd feel like you were living in a spy movie. That was the pitch: biometrics as convenience, as security, as a frictionless upgrade to your digital life.
That pitch aged badly.
Because while you were unlocking your phone with your face, an entirely different ecosystem of biometric technology was being built around you — in stores, on city streets, inside office buildings, and embedded in apps you use every single day. And unlike Face ID, most of it wasn't asking for your permission.
Beyond Face Unlock: The Biometric Stack You Don't See
Facial recognition is the one people know about. It's visible enough to have sparked actual legislative fights — Illinois's BIPA law, the temporary bans in cities like San Francisco and Portland. But facial recognition is just the most obvious layer of a much deeper biometric surveillance stack.
Gait analysis — the identification of individuals by the specific way they walk — is operational in several major US retail chains and casino environments. Unlike facial recognition, it doesn't require you to look at a camera. It works from behind, from the side, even in low light. Carnegie Mellon researchers demonstrated gait-based identification at distances exceeding 150 feet back in 2020. The commercial deployments since then have been considerably less publicized.
Behavioral biometrics are arguably more invasive because they're nearly invisible. This category covers the way you type (keystroke dynamics), how you hold your phone (grip pressure, orientation), how you scroll (speed, hesitation patterns), and even how your mouse moves across a screen. Companies like BioCatch and NeuroID sell behavioral biometric platforms to banks and financial institutions — ostensibly for fraud detection, which is a legitimate use case. But the data profiles being built are extraordinarily detailed, and the line between fraud detection and behavioral surveillance is thinner than their marketing suggests.
And then there's emotion detection — AI systems that analyze micro-expressions, voice pitch, and eye movement to infer psychological states. This technology is being used in job interview screening platforms (HireVue faced significant backlash and dropped the feature in 2021, but competitors remain active), in call center monitoring, and in some educational technology platforms that claim to measure student engagement.
The Cases That Should Have Made Bigger Headlines
A few real-world deployments deserve more attention than they got.
In 2022, Clearview AI — the facial recognition company that scraped billions of photos from social media without consent — was found to have been used by hundreds of US law enforcement agencies, many of which had never disclosed the practice to the public or to local oversight bodies. The company settled with the ACLU and agreed to restrict sales to law enforcement under certain conditions. But its database, and databases like it, still exist.
Madison Square Garden Entertainment made national news in late 2022 when it emerged that the company was using facial recognition to identify and ban attorneys who were involved in litigation against any of its venues — including lawyers who had purchased tickets for unrelated events. The technology was effectively being used as a legal intimidation tool.
On the retail side, a 2023 report from the Government Accountability Office found that several major US retailers — including grocery chains — were running facial recognition pilots without any posted customer notification. Some of these programs were quietly discontinued after the report's publication. Others were not.
The Data Problem Nobody's Solving
Here's the part that doesn't get talked about enough: biometric data is categorically different from other personal data.
If your password is compromised, you change your password. If your credit card number leaks, you get a new card. But your face doesn't change. Your gait doesn't change. Your typing rhythm doesn't change. Once that data is out — whether through a breach, a sale, or a subpoena — the exposure is permanent. There is no reset.
And the data is absolutely getting out. In 2021, a Brazilian facial recognition company called Antheus Tecnologia exposed a database containing over 2.3 million biometric records, including actual fingerprint data. Similar incidents have occurred with smaller vendors in the US whose names never made it past the security trade press.
The legal framework in the US is, to put it charitably, a patchwork. Illinois, Texas, Washington, and a handful of other states have biometric privacy laws with actual enforcement mechanisms. The majority of states have nothing. Federal legislation — the proposed National Biometric Information Privacy Act — has been introduced and stalled multiple times without advancing.
What You're Actually Agreeing To
Most consumers have a vague sense that apps collect data. Few understand the specific scope of biometric data collection buried in terms of service.
Fitness apps collect biometric data. Period tracking apps collect biometric data. Social media platforms with photo tagging features collect facial geometry. Voice assistant devices collect voiceprint data. Many of these data points are shared with third-party analytics partners under clauses that are technically disclosed but practically unreadable.
The FTC has taken some enforcement action — notably against companies that collected children's biometric data — but the agency's resources relative to the scale of the industry are not a fair match.
The Uncomfortable Truth About Convenience
None of this means biometric technology is inherently evil. Fingerprint scanners on phones are genuinely more secure than four-digit PINs. Behavioral biometrics do catch real fraud. Facial recognition has helped identify missing persons and solve violent crimes.
The problem isn't the technology. It's the almost complete absence of meaningful consent, the lack of federal data minimization requirements, and the commercial incentive to collect as much as possible and figure out the ethics later.
Your body is generating a continuous stream of uniquely identifying data. Right now, in the US, there are very few laws governing who can collect it, how long they can keep it, who they can sell it to, or what happens when it leaks.
That's not a technology problem. That's a policy failure — and it's one that's accumulating interest by the day.