OIG report: US officials working on Login.gov, used by dozens of sites, rejected facial recognition to verify users due to algorithmic bias, breaking NIST rules
Khari Johnson / Wired : Tweets: @tobywalsh Tweets: Toby Walsh / @tobywalsh : Is this really true? WIRED claims federal security guidelines require that a person's identity must be confirmable using a biometric such as fingerprint or face recognition. https://www.wired.com/...
Context & Ripple Effects
The arc here runs from NIST's Facial Recognition Vendor Test program, which Wired's earlier reporting showed shapes what US agencies and businesses buy even as its test corpus drew fire for using images of immigrants, visa applicants, and others without consent, to GSA's October 2023 plan to bring facial recognition into Login.gov in 2024 with an opt-out alternative. The OIG report reveals the middle of that story: the people building the system initially refused the biometric requirement on bias grounds.
That refusal matters because NIST's identity-assurance rules treat biometric confirmation as a requirement, not an option — putting the operators of a service used by dozens of federal sites directly at odds with the standards body that governs them. By late 2024 GSA had resolved the standoff in the other direction, giving agencies access to its IAL2-compliant selfie-versus-photo-ID matching, making the OIG finding a record of why the decision was contested.
First-order effects
- Login.gov officials are exposed to a formal compliance finding for deviating from NIST's digital-identity guidelines, while agencies relying on the service faced a period where user verification could not be completed biometrically.
Second-order effects
- Vendors selling facial recognition into government now have a documented procurement blocker — algorithmic bias — that they must clear before NIST-conformant deployments proceed, raising the bar beyond raw accuracy scores.
Third-order effects
- If federal identity standards keep mandating biometrics while operators resist on bias grounds, the pressure lands on NIST to reconcile its assurance requirements with equity evidence, effectively making civil-rights review part of security certification.
The trend: Federal identity infrastructure is becoming the proving ground where algorithmic-bias objections collide with mandated biometric verification, forcing standards bodies to weigh fairness alongside security.