There's a moment in every structure of control when technology stops being a tool and becomes the institution itself. The turnstile at a stadium entrance used to be exactly what it looked like: a mechanism to verify you had your ticket. Someone glanced at you, the screen turned green, and you walked through. The exchange was visible, comprehensible, almost democratic in its obviousness.

That no longer exists at many entertainment venues in the United States. Now the camera measures your face before you even reach the turnstile. A model assigns a score to your facial geometry. A private company archives that data along with a risk category you never asked for and probably will never know exists. All of this happens in the seconds it takes you to walk toward the entrance, thinking about the beer you might grab before the game starts.

What's changing isn't just the technology. What's changing is who holds the power to define you before you've opened your mouth.

I recognize this pattern in other contexts. In organizations where I've worked, automated classification processes are always presented first as efficiency: shorter lines, less friction, less human error. In operational terms, some of that is true. The problem isn't the speed. It's the information that should never have been collected without explicit consent, and how efficiency erases the question of who controls the data and under what criteria.

The case that best illustrates how far this goes isn't hypothetical. Hackers extracted twenty-six million records from a major entertainment company and published them online. These weren't just names and emails. They were facial signatures, threat scores, and risk categories assigned to ordinary people who had gone to see a concert or a basketball game. That information is now available to anyone who knows where to look. The people affected had no idea it existed before the breach.

This matters because the harm isn't abstract. A facial signature isn't like a password: you can't change it or revoke it. If your facial geometry gets archived with a high-risk label by an algorithm that no one has publicly audited, that classification can follow you in ways we still don't fully understand. What happens when that data gets cross-referenced with databases held by employers, insurers, or authorities? The honest answer is that we don't know, and that uncertainty is part of the problem.

The legal dimension is where things get complicated in a way that deserves attention. Most U.S. states don't require a company to obtain consent before scanning your face in a private space. In many contexts, the practice is perfectly legal even though it's ethically questionable. Those who try to sue find themselves in a strange position: they have to improvise with negligence doctrines designed for other kinds of harm, or invoke a federal statute that, as currently written, doesn't even let them sue directly. It's like trying to fix a water leak with tools designed for electrical work.

This legal void isn't accidental. Regulatory frameworks always arrive late to technologies that generate money quickly, and facial recognition in entertainment venues is a booming business. The companies selling these models argue that they improve security by detecting people with restraining orders or violent histories. That argument carries real weight. The problem is that the same dynamic that identifies someone with a restraining order also classifies millions of people with no history whatsoever, using opaque criteria that no one can appeal.

I've seen similar patterns when analyzing algorithmic bias in judicial contexts. Automated models reproduce and amplify bias when the training data isn't neutral. The same thing happens here, with an added complication: at least judicial models receive some institutional scrutiny, however imperfect. Facial recognition systems in private stadiums don't even have that. They're a black box operated by one private company, contracted by another, applied to millions of people who never signed anything.

There are researchers who have argued for years that mass surveillance doesn't need to be run by the state to produce effects similar to those of a surveillance state. When enough everyday spaces adopt these automated classification processes, the result is a monitoring infrastructure that covers ordinary life without any authority explicitly ordering it. A distributed form of dominance that requires nothing more than private contracts and an absence of regulation.

This connects to how technological devices reshape our capacity to imagine alternatives before the question is even asked. If you normalize the idea that your face is an identity document automatically verified every time you enter a venue, you stop seeing it as a choice someone made on your behalf. It becomes part of the landscape, just like the turnstiles themselves.

From Mexico, these dynamics are observed with an added layer of concern. Whatever regulations eventually arrive in the United States will likely be exported elsewhere, for better or worse. In contexts where the rule of law is more fragile, private biometric classification processes represent qualitatively different risks. What happens when that data infrastructure lacks even the imperfect mechanisms that exist elsewhere?

I still don't have a clear answer for how to fix this. There are reasonable proposals: moratoriums on facial recognition use in mass venues until clear regulation exists, requirements for explicit consent, independent algorithm audits, and the right to know and dispute your risk score. None of them is perfect, and all face resistance from industries with concrete financial incentives to keep the legal void exactly where it is.

If the turnstile is no longer the place where your ticket gets checked but the place where you get archived forever, at what point did we collectively decide that was acceptable — and did anyone actually ask us?

Sources:

1. Electronic Frontier Foundation — Face Recognition in Entertainment Venues: What You Need to Know (eff.org)

2. Woodrow Hartzog & Evan Selinger — Facial Recognition Is the Perfect Tool for Oppression, Medium / MIT Technology Review

3. National Institute of Standards and Technology (NIST) — Face Recognition Vendor Test (FRVT): Demographic Effects (nvlpubs.nist.gov)

4. Kashmir Hill — Your Face Belongs to Us (Random House, 2023)

5. American Civil Liberties Union — The Dawn of Robot Surveillance: AI, Video Analytics, and Privacy (aclu.org)