The Private Sector is Incrementally Normalizing the Biometric Scanning Architecture for the Government to Arrogate

Posted on July 4, 2026

As reported in ZeroHedge, facial recognition and other biometric authentication is increasingly and stealthily being deployed by private companies to their widely used apps and services. Major tech companies are leading the way in requiring users to submit biometric data for certain critical functionality of their applications, while still stating in their policies that surrendering such data is optional.

The piece starts by claiming that facial scanning is now a prerequisite on Facebook for performing account recovery for select accounts, or even to open certain posts. More than merely a selfie photo, the “facial scanning” required in these cases is essentially a video of the front and sides of one’s head, so that parent company Meta can review the user’s full facial geometry. The stated reason for the measure is to prevent fraudulent account access, and the company maintains in its policies that the biometric data is discarded after use.

However, it is difficult to take the tech behemoth at its word given Facebook’s historically cavalier attitude toward respecting the privacy of users’ faces. It is well-established that Facebook has enough facial data from users to identify them even when they aren’t tagged. Moreover, the application’s ethics is dubious, as it also manipulated users’ moods without telling them in the name of “science”.

Another example the article cites is Uber, which it says also allegedly started requiring users to submit not only selfies for facial recognition, but photos of one’s driver’s license—even to hail rides. Uber concedes that it uses these identifiers for preventing multi-account access for drivers, and extends them as an optional feature for riders. However, the reporting claims that some riders have stated they are being made to submit this identifying data merely to use the app for basic transportation. To whatever extent it is implementing this mechanism, Uber has established itself as yet another private player with the means to associate faces with identities without needing to obtain third-party data.

These two applications are far from the only places in which Americans might now expect to be subject to facial analysis. Other private entities that are beginning to make facial recognition commonplace include banks (often through mobile apps) and telecommunications companies (such as for the purpose of SIM card replacement). Even airports practically require passengers to give up biometric data simply to avail themselves of air travel.

As the writeup aptly points out, age verification laws are accelerating the integration of facial recognition into ever more areas of life. Some US states are now enforcing age restrictions on social media—in California’s case, all end-user devices that can connect to the Internet will have to check users’ ages. One compliance mechanism some of these laws rely on is facial recognition which, by identifying you, can thereby validate that you are of the requisite age to use a service. But facial recognition is far from foolproof.There are still cases of misidentification, with higher error rates for nonwhite people. On top of that, it is arguably of questionable utility, as the less sophisticated implementations can be duped by laughable circumvention techniques.

In the larger context of the development of technology, this continues an ongoing shift away from an open, anonymous Web. Early in the Web’s life, even if a site required a username and password, it typically did not attempt to tether that username to a real identity. If surfing the Web is a virtual analog to cruising down city streets, between enforcing user identification online with biometrics and AI-equipped surveillance camera networks (such as such as Flock), it seems that anonymity is being gradually eliminated from each. Once Internet usage is tied to identity, then user activity can be managed.

CCDBR has noted the perils of the “third-party doctrine” begotten by Smith v. Maryland many timesBy way of the legal principle, the government can obtain records on users with far less than a search warrant on the supposed grounds that users reasonably understood that they forfeit that data as a function of using some service. If these various private entities, via their apps, can all identify users, then the government—the issuer of the very IDs that many of them employ to verify user identity in the first place—becomes the pivot point that can correlate all one’s activities across services. From there, what won’t the government be able to know about any American’s private life?

All of this, as the article also rightly underscores, is happening without any change in the laws.Because service providers are increasingly concluding that, in their estimation, biometric collection and user identification improves service and reduces abuse, it redounds to any government agency which can simply request the data.The fact that the corporate players leading the trend toward biometric identification are also the titans of their respective industries also makes it as challenging for users to opt out as it would be if it was a law.

Would users be willing to flee Meta’s constellation of platforms, YouTube, and TikTok if they were all to begin identifying users by their faces, if their friends and family were unwilling to follow suit? Would depositors be willing to bank only in person, or withdraw all their money, if their bank pushed facial recognition on them? After strangling the taxi industry, could passengers, practically speaking, go back to taxis if they didn’t want to give Uber a scan of their faces?

This is where regulations like Illinois’s trailblazing Biometric Information Privacy Act (BIPA) are indispensable. While it does not prohibit companies from collecting biometric data from users, it does stipulate strict disclosure on what the information will be used for, and severely limit what they are allowed to do with it. The logical continuation is to push for guardrails around government requests for data in private hands. The time to reverse the trend is now, before people get too inured to any app that wants a copy of their face to have it.

You can read the full piece from ZeroHedge here.

Donate

Volunteer