In 2018, it was revealed that the European Union was funding the development and testing of a machine learning tool that read facial expressions and assigned them values of truthfulness. It was called iBorderCtrl, and it was piloted at border-control posts in Hungary, Greece, and Latvia under the claim that it worked as a lie detection system. This egregious product of the EU’s security-industrial policy became the paradigmatic case that, in the middle of the drafting of a new regulation for Artificial Intelligence, drew legal and policy scholars to the problem of machine learning systems in the EU’s migration apparatus.
Yet they arrived with the same universalizing toolkit used to sell AI: the problems of governing the lives of migrants became one of complex and opaque algorithms, of bias in model design and of violations of migrants’ privacy. The intricate dynamics of a mobility regime built over the last thirty years to restrict the movement of racialized communities and make their life difficult were quietly reduced to yet another case of the risks of algorithmic tools.
The intricate dynamics of a mobility regime built over the last thirty years to restrict the movement of racialized communities and make their life difficult were quietly reduced to yet another case of the risks of algorithmic tools.
In my mapping of 92 studies on AI and migration in the EU (2016–2025), 25 cited iBorderCtrl as an example.[1] iBorderCtrl became a stand-in for everything wrong with border control. It did not matter that its testing was minimal or that it was never operationally deployed for anything. Yet in elevating this crude, barely-tested system into a symbol, scholars missed something more significant: the everyday machinery of suspicion that predates and surrounds it. The analysis concealed the deep power relations and institutional apparatus that produce migrant precarity. The problem of injustice became one of transparency, data protection, and compliance. In other words, the political problem was converted into a technical one.
Do not misunderstand me. iBorderCtrl is indeed an example of the disregard for the dignity of non-citizens, of the EU’s determination to build a national security industry, criminalization of migrants, and of the institutional opacity that allows such experiments to take place. But scholars and digital-rights organizations arrived late and elevated iBorderCtrl into a symbol for everything wrong with AI and migration. Another hammer looking for a nail.
In this piece, I draw a more complex picture. I show how the “AI in migration” framing hides unequal power relations by treating every migration process as identical (a lie detector in Greece analyzed alongside asylum tools in Germany) and by treating “AI” as a general technology with generic risks. The political problem of migrant justice requires a different lens.
The new nail, or how the technological reading misses the complexity of the migration system
For many analysts, “AI”, whatever that means in this context, is arriving to replace human decisions in the migration and asylum system, and with it, we are losing the humaneness of the encounter. But look at the history of migration management in Europe and a different picture emerges. There was a dehumanizing regime before. The system was built, over more than seventy years, precisely to strip people of it: to turn human beings into visa applicants, migrants, temporary workers, residents, and refugees, each category defined by a systematic deprivation of rights.
That regime has a colonial genealogy. Imperial powers once moved colonized subjects freely to meet labor demands. Decolonization reversed this. From the 1950s, former imperial powers restricted the movement of former colonial subjects while favoring settler families. After the Nazi era, explicit racial references disappeared from law, only to reappear coded through terms like “family ties” and “economic utility”. Thus, the former imperial powers legalized the breaking of their colonial ties. Within a few years, colonized subjects in the metropole had become foreigners and their movements were subjected to heavy controls.
The EU’s common visa policy in the 1990s translated these postcolonial distinctions into supranational law. A list of third countries requiring visas was assembled by aggregating member states’ existing restrictions. From that moment, the everyday movement of Moroccans back and forth to Spain was made illegal. Scholars have shown this list maps neatly onto racial hierarchies: wealthy, white-majority states enjoy visa-free movement, while predominantly non-white countries face strict restrictions.
Scholars have shown this list maps neatly onto racial hierarchies: wealthy, white-majority states enjoy visa-free movement, while predominantly non-white countries face strict restrictions.
Building that regime required more than law. It required offices, bureaucratic posts, and, most relevant here, infrastructures and databases capable of severing the EU from its own history: limiting the movement of the formerly colonized while keeping resources and labor flowing. It also required an organizational disposition, and that disposition rests on two constructions.
The first is criminalization. Aided by the war on terror, racialized migrants became framed as permanent security risks. Once cast as a potential threat, any data can be used against them, and they fall outside ordinary legal protections. Whole law-enforcement systems treat particular nationalities and religions as latent terrorist risks to be managed preemptively.
The second is a culture of suspicion. Ethnographers describe this as routine institutional practice: migrants’ accounts are presumptively doubtful, testimony is distrusted, and documents are privileged over what applicants say. A misspelled name or uncertain answer can be inscribed as a “contradiction,” then travel between officials as settled fact.
The filtering begins long before Europe. The visa is the first filter: a lengthy, expensive process administered with enormous discretion. Family reunification is also restricted in many countries according to where a partner comes from.
The heaviest weight falls on those who reach Europe without access to the mobility infrastructure and claim asylum.
The heaviest weight falls on those who reach Europe without access to the mobility infrastructure and claim asylum. Against them, institutions mobilize the full apparatus: they foreclose the regular routes, from planes to paperwork; they pay third countries to intercept people, make remaining routes dangerous, immobilize arrivals at first application, and fast-track rejection for anyone not from a recognized war zone. Those who remain are pushed into the illegal labor market, extracting cheap goods for lower wages than Europeans, denied civil rights, waiting for regularization.
This is the crucial point. Automation does not arrive to disturb a humane system. It arrives to fit one already organized around suspicion, documentary proof, standardization, and speed, an environment increasingly reshaped by managerial reforms that demand more decisions with fewer resources. Algorithmic tools are attractive precisely because they extend what these institutions already do: they generate externalized traces, standardize suspicion, and let a doubtful inference move more easily across files, interviews, and borders.
The hammer, or what the technology is doing with migrants in the EU
Having traced the EU’s migration systems, we can see that AI did not arrive to disturb a pristine apparatus. It entered a space organized around the precarization of racialized migrants. In my literature review, texts grouped heterogeneous systems under a common “AI” umbrella with no attention to their specific technical characteristics. They clustered around biometrics, data extraction, forecasting tools, iBorderCtrl, and border surveillance. Most analyses examined multiple technologies across multiple jurisdictions simultaneously. Only 35 of the 92 sources focus on a specific technology in one or two jurisdictions.

Figure 1: Technologies discussed in the reviewed literature
The first problem with this abstraction is technological: it stops us seeing what these tools are actually doing. By treating “AI in migration” as a single, coherent object, the literature obscures the fact that these systems are embedded in highly diverse institutional agendas and serve different, sometimes conflicting, objectives. To resist this hype, Tucker proposes four principles: give technical detail about specific technologies; name barriers to understanding created by corporate secrecy; identify the companies building these systems; and assign responsibility to human actors rather than to “the technology” itself.
Working from these principles, I catalogued 62 claimed uses of artificial intelligence, mapping each to its technological system, its administrative function, and its target migrant category.[2] One finding stands out: the primary targets are asylum applicants. Once disaggregated, many systems lumped together as “AI” look less like a single technological domain than like administrative instruments through which migration governance operationalizes suspicion, categorization, and exclusion under the language of efficiency, neutrality, and legality.
Take the most-discussed technology in the literature: biometrics, and facial recognition in particular. The standard critique is that these tools fail more often on darker skin. That is true and important, but it flattens what the technology actually does, because the same facial recognition capability is deployed toward radically different ends:
- to open e-gates for “trusted travelers”;
- to support law enforcement investigations that, in Germany and the Netherlands, draw on facial templates of foreigners;
- to check whether an asylum applicant previously entered by an irregular route, or lodged an earlier claim elsewhere;
- to bind an asylum case file to a facial template;
- to surveil accommodation centres in Greece, logging residents’ every movement;
- to run entry–exit controls for non-EU visitors;
- and to police the comings and goings of asylum applicants in accommodation centers in the Netherlands and Greece.
One technology, many purposes. But automation changes something deeper than purpose: it changes scale. What was once constrained by human bottlenecks (officials manually reviewing files, conducting interviews, making discretionary decisions one by one) can now process thousands of cases with minimal intervention. Predictive analytics reaches backward (intercepting people before travel) and sideways (across borders and databases). This is not a new logic; it is an old logic operating at unprecedented speed and reach.
Disaggregating the corpus this way exposes a stark asymmetry in how these tools are distributed across migrant categories (Figure 2). Applicants for study, naturalization, labor, or residence largely encounter administrative-processing tools, systems designed to accelerate cases where approval is the default and human attention is triggered only by an anomaly. Asylum applicants encounter something else entirely. They absorb the full weight of security screening, surveillance, and predictive tooling.

Figure 2: Types of administrative processes using algorithmic tools and migrant categorizations
The catalog of what is done to them is worth reading in full, because its accumulation is the point. Forecasting tools try to anticipate where and who will attempt to reach Europe, licensing preemptive action and stoking catastrophic fantasies of mass migration. Tools are built to detect people before they reach the border, so that external authorities can be asked to stop them: AI-equipped drones that spot humans, social media monitoring that alerts border police to possible movements, predictive analytics that model likely routes. Biometric systems fix an applicant’s claim and their challenge to the border regime onto their body. Automated tools scan the documents submitted in support of an asylum case. Others decide where to allocate applicants, according to the needs of local governments. The contents of a private phone are extracted and automatically mined for signs of “national security risks”, or for clues to a country of origin, an identity, a reason for fleeing. A speech recording is used to predict a country of origin through an imagined correlation between database dialects and a person’s pronunciation. A surname is matched to a probable origin. Case files are filtered through tools that group similar cases for officials. And the recorded testimony in which someone recounts the atrocities that forced them to leave is analyzed for traces of a possible “national security concern.”
This is what the abstraction hides. Not “AI,” but a machinery of suspicion pointed, with remarkable consistency, at the people least able to contest it.
How the reading misplaces harm
Having traced the complexity of both the migration system and the technologies deployed within it, we can now see precisely how the paradigmatic reading, from legal scholars and some civil society organizations, misplaces the harm. It does so in three characteristic ways.

Figure 3: Dominant risk narratives
Privacy: Most of this literature treats the use of AI as, at bottom, a privacy violation. The violation is real. But to read a regime built to constrain the lives of migrants simply as a privacy problem is to miss the most important point. The harm is not the violation of privacy as such; it is what that violation produces, what classification emerges, which proxy is assigned, which representation is made standard, and which logic the system then acts upon. Framed as privacy, the harm becomes impossible to locate: we can no longer see where it actually happens, or how.
Opacity: A second common reading holds that algorithms are so complex they obscure their own logic. But the idea that opacity is something new, introduced by technology, into a regime already ordered by suspicion and discretion, is close to absurd. Migrants must navigate legal jargon, incomplete explanations, and inaccessible records, while even frontline officials struggle to interpret constantly changing regulations. Your visa was refused because the official believed you would not return. Your asylum claim was rejected because your story lacked credibility. You were turned back at the airport because you would “probably” overstay. What was the reasoning? We rarely know exactly; the discretion is vast, and these are not hypotheticals but the experiences of millions. To imagine AI introduces opacity into such a system is to misunderstand it. What AI actually changes is how representations and classifications are built: how legible the system becomes to those it judges, how racial ideology looks automatic and objective, and how standardized decision-making is manufactured. That is what we need to research.
Technical limitations: The third reading is now standard: the problem of low-quality databases used to automate decisions, of flawed algorithmic design, of tools with biased tendencies applied to migrants. But as we have seen, migration control is organized around suspicion and anticipation. The threshold for what counts as an actionable data point is extraordinarily low, and speculation reigns. Almost any fragment of data can become a free-floating proxy for criminalization and suspicion. As noted earlier, a misspelled name or uncertain answer becomes a “contradiction” that travels across officials as settled fact. The problem, then, is not the technology. It is the institutions, infrastructures, and databases whose very design produces illegalization and criminalization, and in which speculation is the law and its absurd conclusions become legal.
Conclusion, or what this reading costs us
None of this means that privacy, opacity, or data quality do not matter. It means that when they become the whole story, they do a specific and damaging kind of work: they depoliticize.
By locating harm in a faulty model, a leaky database, or an opaque algorithm, the dominant reading converts a political problem into a technical one. The question stops being why this regime exists, and who it is built to exclude, and becomes: how do we make the tools fairer, more accurate, more transparent, more compliant? But a more accurate suspicion machine is still a suspicion machine. A transparent tool for illegalizing racialized movement still illegalizes it. Optimize these systems, and you do not dismantle the regime; you make it run more smoothly.
But a more accurate suspicion machine is still a suspicion machine. A transparent tool for illegalizing racialized movement still illegalizes it.
This is how the technical hides the political. It lets institutions built to precaritize and exclude present themselves as neutral administrations that have merely been disrupted by a risky new technology, and now only need better safeguards to be put right. And it quietly relocates responsibility onto the very people the system targets — asylum seekers who must prove they are not lying, not dangerous, not fraudulent — rather than onto the institutions doing the targeting.
Return, finally, to iBorderCtrl. Nearly one-third of the literature invoked a lie detector that was barely tested and never operationally deployed. It was easy to condemn precisely because it was so crude, so obviously pseudoscientific. But the danger was not only the cartoonish machine that reads faces for lies. It is the quiet, simple systems growing inside the migration system while doing exactly what the regime has always done: sorting the world’s racialized populations into those who may move and those who must be stopped. If we keep our eyes on the extraordinary tool, we will miss the machinery working, and that machinery was never about the technology at all.
[1] The corpus was constructed through searches in Scopus, Web of Science, and Academic Search Complete, supplemented by Google Scholar and backward/forward citation tracing. Search terms were organized into three concept clusters: (1) migrant categories, such as refugee, asylum, and migration; (2) automated technologies, such as artificial intelligence, algorithms, automated decision-making, machine learning, risk assessment, and profiling; and (3) geographic scope, such as Europe, European Union, and Schengen. Related terms were combined within each cluster using OR, while the three clusters were combined with AND, so that retrieved sources had to include at least one term from each cluster. The corpus was then expanded with grey literature, especially reports by human rights organizations and research institutes, to ensure a richer basis for tracing policy-facing debates and documented uses of algorithmic systems that may not yet be extensively discussed in peer-reviewed scholarship.
[2] This mapping depended heavily on the work of Derya Ozkul, but also collected cases from other mentions of technology in the corpus analyzed.