Skip to content

PAN Lab example

ID.me identity verification

The gate nobody counts: an identity check in front of benefits

A facial-recognition identity check sits in front of an unemployment claim: match a live selfie to a government-ID photo, pass and the claim proceeds, fail and you drop into a video-interview queue that in some states ran about ten hours. Modeled on the ID.me facial-recognition identity check used to gate pandemic-era unemployment claims. What makes this shape distinctive is that it is not scoring or judging anyone: it is a checkpoint, and the people it turns away are never recorded as denied. Where verification comes before filing, a blocked worker is not a rejected claim — just someone who never appears. The gap here is not a bad model; it is a de facto denial with no denial to appeal and no count of who was lost.

Stylized model of a documented deploymentPublic benefits & eligibility

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Identity-gate class: a facial-recognition access checkpoint in front of benefits network: 7 components and 11 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 4 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    This models the identity-verification access pattern documented in the ID.me unemployment-insurance case file -- an identity gate placed in front of the claim -- not a reconstruction of the actual vendor system, its algorithm, or any state's configuration. It is deliberately not a risk-scoring or adjudication model.

  • baseline

    The gate functions as a de facto eligibility denial rather than a formal, appealable determination: a failed match routes the claimant into an hours-long queue, and abandonment before completion blocks the claim without ever producing a denial that could be appealed. That the blocked are never counted -- the federal system collects no denial-by-verification-failure data, and pre-filing blocks are not recorded as denied claims -- is this shape's defining feature, drawn as the two latent check pathways.

  • baseline

    The trusted-referee video interview and the state agency alternatives (mail, phone, in-person) are drawn as a genuine but capacity-starved correction channel: real enough that this is not a MiDAS-style removal of the human, but deliberately under-resourced -- appointment scheduling was removed, queues ran up to about 10 hours, and only New Jersey offered an in-person option that cut the wait to minutes. That is why manualCapacity is low and why capacity levers (correction-budget, vigilance) have room to bite.

  • baseline

    The biometric data-leaving pathways -- the one-to-many database search and the vendor's retention of facial scans beyond agency control -- reflect the documented record: the vendor admitted one-to-many matching after emphasizing one-to-one, most audited contracts did not specify matching type, data storage or biometric-data destruction, and a 2026 proposal would retain scans up to 36 months after account deletion. They are drawn privacy-sensitive so vendor-gate, data-minimization and connection-auth have clear targets.

  • assumed

    The oversight node is drawn as ex-post and external (the Inspector General audit, two House investigations, a federal civil-rights complaint), not a live internal control. It arrived after the queues and lockouts, and its main recommendations were promised as guidance rather than wired into a standing check -- which is why the corrective work in this shape is opening the two latent accounting checks, not the audit that already happened.

  • assumed

    The trusted-referee queue is drawn as a mediating worklist on the gate-to-staff pathway; it carries no flow of its own and does not affect the dynamics. It is present to name where the multi-hour wait lives.

  • assumed

    The documented completion differentials by race, language, age, income and filing method are a friction proxy, not a measured wrongful-denial rate: Oregon's own study stated it showed differences in completion and did not show causation, and non-completion mixes truly blocked eligible claimants with people who returned to work and fraudsters using stolen identities. This Lab models institutional access friction, not demographics, and estimates no differential harm to served claimants; those completion gaps are documented in the case file and measured outside any diagram like this one.

What this example does not show

  • The documented completion differentials by race, language, age, income and filing method (from Oregon's one-month study, n=10,656) are a friction proxy, not a measured wrongful-denial or false-reject rate: the Oregon Employment Department stated its study showed differences in completion and did not show causation, and non-completion mixes truly blocked eligible claimants with people who had returned to work and fraudsters using stolen identities. Treat completion gaps as an upper bound on friction, never as a measured error rate.
  • The scale figures are ranges from different sources measuring different things (at least 25 state UI agencies for nearly $45M; roughly 30 state governments; 27 agencies contracting at some point), and true denial, trusted-referee resolution, and appeal-outcome volumes are largely unavailable because the federal system does not collect denial-by-verification-failure data. That gap is a documented finding here, not a zero.
  • The documented harm is access friction that falls unevenly, plus a biometric-privacy exposure. The Lab models institutional access dynamics, not demographics, and estimates no differential harm to served claimants; those disparities and the individual harms in the civil-rights complaint are documented in the case file and measured outside any diagram like this one. Per project rules no specific algorithm or model is named; NIST's bias findings describe the technology class, not a named system.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • During the pandemic unemployment surge, a private facial-recognition identity check operated as a de facto eligibility gate for unemployment benefits in at least 25 U.S. state workforce agencies, with a live 'trusted referee' interview queue that House investigators documented averaging nearly 10 hours in North Dakota and over 4 hours in 14 of 21 states, versus about 6 minutes in New Jersey where an in-person option existed. Oregon's own one-month study (n=10,656 routed) recorded verification-completion differences by group -- for example 41.59% for African American and 34.48% for Spanish-language claimants versus 53.44% for White claimants -- but stated the study showed differences in completion and did not show causation, so these are a friction proxy, not a measured wrongful-denial rate. The U.S. Department of Labor does not collect or report the number of workers blocked for inability to verify identity, and where verification precedes filing those workers are not counted as denied claims at all, so the scale of any wrongful lockout is undocumented.

    empirical
    • Government U.S. House Committee on Oversight and Reform, Chairs Clyburn, Maloney Release Evidence Facial Recognition Company ID.me Downplayed Excessive Wait Times for Americans Seeking Unemployment Relief Funds (2022) https://oversightdemocrats.house.gov/news/press-releases/chairs-maloney-clyburn-release-evidence-facial-recognition-company-idme
    • Government evaluation State of Oregon Employment Department, Potential Disparate Impacts of ID.me for Unemployment Insurance Claimants in Oregon (Anonymized) (2022) https://www.oregon.gov/employ/NewsAndMedia/Documents/2022-02-Potential-ID.Me-Disparate-Impacts-FINAL.pdf
    • Advocacy National Employment Law Project, Identity Verification (Unemployment Insurance Policy Hub, Policy Advocacy Brief) (2023) https://www.nelp.org/app/uploads/2023/11/ID-Verification-11-2023.pdf
    • Government evaluation U.S. Department of Labor, Office of Inspector General, Alert Memorandum: ETA and States Need to Ensure the Use of Identity Verification Service Contractors Results in Equitable Access to UI Benefits and Secure Biometric Data (Report No. 19-23-005-03-315) (2023) https://www.oig.dol.gov/public/reports/oa/2023/19-23-005-03-315.pdf
  • A U.S. Department of Labor Inspector General audit (March 31, 2023) found that among 24 state workforce agencies using a facial-recognition identity contractor, 18 of 24 (75%) contracts did not specify one-to-one versus one-to-many matching, 15 of 24 (63%) did not address data storage, and 13 of 24 (54%) did not address destruction of the collected biometric data, while 22 of 24 (92%) agencies reported the technology reduced improper payments -- the operator-side benefit that sustained adoption even as the wrongful-lockout cost went unmeasured. The vendor initially represented it used only one-to-one matching and later acknowledged one-to-many matching against a database; after bipartisan backlash the IRS and Treasury dropped the mandatory facial-recognition requirement in February 2022 and the vendor made it optional across agencies, though the service remained in use for unemployment identity verification in a large share of states, and a 2026 IRS proposal would allow it to retain taxpayer biometric data up to 36 months after account deletion. The reported improper-payment reductions are agency self-reports, not independently audited.

    empirical
    • Government evaluation U.S. Department of Labor, Office of Inspector General, Alert Memorandum: ETA and States Need to Ensure the Use of Identity Verification Service Contractors Results in Equitable Access to UI Benefits and Secure Biometric Data (Report No. 19-23-005-03-315) (2023) https://www.oig.dol.gov/public/reports/oa/2023/19-23-005-03-315.pdf
    • Advocacy American Civil Liberties Union (Jay Stanley and Olga Akselrod), Three Key Problems with the Government's Use of a Flawed Facial Recognition Service (2022) https://www.aclu.org/news/privacy-technology/three-key-problems-with-the-governments-use-of-a-flawed-facial-recognition-service
    • Advocacy Electronic Frontier Foundation, Victory ID.me to Drop Facial Recognition Requirement for Government Services (2022) https://www.eff.org/deeplinks/2022/02/victory-irs-wont-require-facial-recognition-idme
    • Trade press Biometric Update, IRS proposal could turn taxpayer facial verification into long-term fraud database (2026) https://www.biometricupdate.com/202605/irs-proposal-could-turn-taxpayer-facial-verification-into-long-term-fraud-database

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Public benefits & eligibility domain page.

Levers available here and the patterns behind them

Documented case histories