PAN Lab example
ID.me identity verification
The gate nobody counts: an identity check in front of benefits
ID.me's facial-recognition check stood in front of pandemic unemployment claims in 25-plus states. A claimant who did not finish it was never recorded as denied.
See more
ID.me is a remote identity check run by the private company of the same name. A claimant uploads a government-ID photo and a live video selfie, and facial-recognition software compares the two. During the pandemic, state unemployment agencies placed the check in front of benefit payment, so a failed match held up the claim.
How it was used
ID.me signed its first state contract, with Florida, in June 2020. Within about a year, it held contracts with at least 25 state unemployment agencies, for nearly $45 million. It served identity checks for roughly 30 state governments and 10 federal agencies. The IRS alone spent about $86 million on licenses.
A claimant needed a smartphone or a computer with a camera. The software's pass or fail decided whether the claim went ahead. Roughly 10 to 15 percent of applicants were sent on to a live video interview with an ID.me trusted referee.
A Department of Labor Inspector General audit, reported on March 31, 2023, found that 24 of 53 state workforce agencies, 45 percent, used a facial-recognition identity contractor. They drew on 10 different vendors.
The wait for a person
House investigators found that the wait for the video interview averaged nearly 10 hours in North Dakota in April 2021. It averaged nearly 6 hours in Washington, and over 4 hours in 14 of 21 states.
New Jersey, the only state then offering an in-person alternative, averaged about 6 minutes. ID.me removed appointment scheduling, which was judged to be "hindering efficiency." The sources do not say who judged it so. It told the IRS that waits were "about 2 hours," while its own data showed averages over 4 hours across most states.
A check that records no denial
ID.me's check does not score anyone or decide eligibility. It is a fraud-control checkpoint placed in front of the claim. A claimant who does not finish an hours-long wait has not been denied. There is no decision to appeal, no reason code, and no letter.
The US Department of Labor does not collect or report how many workers are denied benefits because they could not verify their identity. Where verification comes before filing, blocked workers are not counted as denied claims at all. The National Employment Law Project, an advocacy group, documented this.
The gap here is not a bad face match. It is a denial in practice with no denial to appeal, and no count of who was lost.
Who completed verification
Oregon studied one month of regular unemployment claims sent to ID.me, 10,656 in all. By a November 2021 snapshot, 49.37 percent had completed verification. Eventually 71.06 percent did, so roughly 29 percent never completed.
Completion varied by group. It was 53.44 percent for White claimants, 41.59 percent for African American claimants, and 42.05 percent for Native Hawaiian or Pacific Islander claimants. It was 49.65 percent for English-language filers and 34.48 percent for Spanish-language filers.
Claimants aged 20 and under completed at 28.49 percent. Telephone filers completed at 38.25 percent, against 52.10 percent for internet filers. The lowest weekly benefit band completed at 39.52 percent, against 60.32 percent for the highest.
Oregon stressed that the study showed differences in completion and "did not show causation." Its outreach to 130 non-completers found that some faced a technology barrier or found the process confusing. Others had returned to work (22 percent) or had not finished by the snapshot.
Who gains and who pays
The agencies see a real, measurable benefit. Of 24 surveyed agencies, 22 (92 percent) reported that the technology reduced improper payments. Those are the agencies' own reports, not independently audited.
The cost, the wrongful lockout of eligible claimants, goes unmeasured. The case file says it falls hardest on filers with poor broadband, filers who do not speak English, younger filers, and those with the lowest benefits. Oregon's completion gaps measure friction, not errors, but the case file says they plainly show who bears the cost.
ID.me also had a reason to overstate the fraud it sells protection against. Its chief executive claimed that as much as $400 billion was lost to pandemic unemployment fraud. The Inspector General estimated $45.7 billion in potential fraud.
What changed afterward
On October 29, 2021, Oregon paused the automatic routing of all regular unemployment claims to ID.me. It did so to study disparate impacts, meaning whether the check affected groups differently. The case file calls this the one safeguard the sources show being used, and the cheapest in this area of public benefits.
After bipartisan backlash, the IRS and the Treasury dropped their mandatory facial-recognition requirement in February 2022. ID.me made facial recognition optional across government agencies. Massachusetts became the first state to follow, though there the technology had already been optional.
In July 2023, the Department of Labor launched a public alternative. It pairs Login.gov, run by the General Services Administration, with in-person checks at the US Postal Service. A 2024 review by the Government Accountability Office found that federal agencies had leaned heavily on commercial identity vendors. It found that Login.gov had only recently added one-to-one face matching that meets the guidance of the National Institute of Standards and Technology.
ID.me and similar services still checked unemployment claims in a large share of states into 2025. In 2026, the IRS proposed allowing ID.me to keep taxpayer biometric data for up to 36 months after an account is deleted.
What this network is drawn from
This network follows the identity-check pattern in the public record of the ID.me case. It is not a reconstruction of ID.me's system, its algorithm, or any state's setup.
It shows ID.me's check, what the check receives, and the wait for a trusted referee. It also shows the referees and state staff, the verification outcome record, the face database and ID.me's scan storage, and the outside reviewers. Claimants themselves are outside the network.
What the available tools can and cannot address
Service means the useful work ID.me's check does for the agencies: confirming real claimants and stopping improper payments.
A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. Closing a pathway means mistakes stop passing along it. The work it carries goes on.
This case has a budget of 14 units. Explore (No Targets) sets no targets.
Under Service Targets Only, the targets can be met within the budget. No single tool meets them. The cheapest way costs 5 units and uses two tools: Escalate checks and Vet connections.
Escalate checks has the trusted referees and state staff check more closely when monitoring flags trouble. Here it stops mistakes passing along Failed match to a trusted referee. Vet connections lets one system read or copy another's records only where that is explicitly granted. Here it closes three pathways: Images and fraud flags to ID.me, Earlier flags send claimants back, and Facial scans kept by ID.me.
Under Service and Safety Targets, the targets can also be met. That level also asks you to close every failure pathway, among other targets. The cheapest way costs 8 units and uses three tools: Escalate checks, Store less data, and Vet connections.
Under All Governance Targets, the targets can also be met, with less room to spare. The cheapest way costs 11 units and uses four tools: Understand the system, Escalate checks, Store less data, and Vet connections. At this level, Understand the system costs 4 units and makes Vet connections 1 unit cheaper.
At that level, three tools act less strongly unless Understand the system is also in use: Check copied records, Store less data, and Vet connections. Without it, Vet connections closes none of its pathways. Other combinations of tools also meet the targets at every level that sets them.
More is not better here. Using every tool at its strongest setting closes every failure pathway and costs 33 units, more than twice the budget. It also leaves ID.me's check doing too little useful work, so it misses the targets at every level that sets them.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Identity-gate class: a facial-recognition access checkpoint in front of benefits network: 7 components and 11 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 4 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 7 assumptions
- assumed
This example follows the identity-check pattern documented in the ID.me unemployment case file. It is not a reconstruction of ID.me's system, its algorithm, or any state's setup. It shows a check placed in front of a claim. It does not show a system that scores risk or decides eligibility.
- baseline
This example treats ID.me's check as a denial in practice, though never a formal one that could be appealed. A failed match sends the claimant into a wait of hours. A claimant who does not finish is blocked without ever receiving a denial. The federal government collects no data on denials caused by failed verification. Where verification comes before filing, blocked claimants are not recorded as denied claims. That uncounted loss is this case's defining feature. So the example includes two checks that would count it, and the sources describe no one running either.
- baseline
This example treats the trusted referee interviews and the state alternatives as a real way to correct a failed match, with too little capacity. It is a real human fallback, unlike Michigan's MiDAS unemployment fraud system, which issued fraud findings without human review of the determination. But it was under-resourced. ID.me removed appointment scheduling, which was judged to be "hindering efficiency." The sources do not say who judged it so. Waits averaged nearly 10 hours in North Dakota. New Jersey, the only state then offering an in-person option, averaged about 6 minutes. That is why the example gives the referees and staff little capacity. It is also why tools that add capacity, such as Understand the system and Escalate checks, have room to help.
- baseline
The two pathways out to the face database and ID.me's scan storage follow the documented record. One is ID.me's one-to-many search of a database, which it acknowledged after first saying it used only one-to-one matching. The other is ID.me's storage of facial scans. Most audited contracts did not specify the matching type, and most did not address data storage or destroying the biometric data. In 2026, the IRS proposed letting ID.me keep taxpayer biometric data up to 36 months after an account is deleted. Both pathways are marked as handling sensitive personal data. So Gate vendor updates, Store less data, and Vet connections each have a clear target.
- assumed
This example treats the outside reviewers as coming after the fact and from outside, not as a live internal control. They are the Inspector General's audit, two House investigations, and a federal civil rights complaint. They came after the queues and lockouts. The Employment and Training Administration accepted the audit's three recommendations, and the sources do not show them turned into a standing check. So the corrective work in this example is adding the two checks that would count the blocked, not repeating an audit that already happened.
- assumed
This example shows the trusted referee video queue as its own part, between ID.me's check and the referees and staff. It marks where the wait of hours happens. It does not change how mistakes pass between the other parts.
- assumed
The completion gaps by race, language, age, income, and filing method measure friction, not wrongful denials. Oregon's own study said it showed differences in completion and did not show causation. Not finishing mixes blocked eligible claimants with people who had returned to work, and with fraudsters using stolen identities. This example follows how errors move between parts of the deployment, not who the claimants are. It does not estimate how harm differs between groups of claimants. The completion gaps are documented in the case file and measured outside this example.
What this example does not show
Show all 3 limitations
- The completion gaps by race, language, age, income, and filing method come from Oregon's one-month study of 10,656 claims sent to ID.me. They measure friction, not a wrongful-denial or false-rejection rate. The Oregon Employment Department said its study showed differences in completion and did not show causation. Not finishing mixes blocked eligible claimants with people who had returned to work, and with fraudsters using stolen identities. Read the gaps as an upper bound on friction, never as a measured error rate.
- The scale figures are ranges from different sources that measure different things. They are at least 25 state unemployment agencies for nearly $45 million, roughly 30 state governments, and 27 agencies that contracted at some point. The numbers of true denials, trusted referee resolutions, and appeal outcomes are largely unavailable. The federal government does not collect data on denials caused by failed verification. That gap is a finding of this case, not a zero.
- The documented harm is friction that falls unevenly, plus a risk to claimants' biometric privacy. This example follows how errors move between parts of the deployment, not who the claimants are. It does not estimate how harm differs between groups of claimants. Those gaps and the individual harms in the civil rights complaint are documented in the case file. Nothing in this example computes them. This example names no specific face-matching algorithm. The findings of the National Institute of Standards and Technology on bias describe facial recognition in general, not a named system.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
During the pandemic unemployment surge, a private facial-recognition identity check operated as a de facto eligibility gate for unemployment benefits in at least 25 U.S. state workforce agencies, with a live 'trusted referee' interview queue that House investigators documented averaging nearly 10 hours in North Dakota and over 4 hours in 14 of 21 states, versus about 6 minutes in New Jersey where an in-person option existed. Oregon's own one-month study (n=10,656 routed) recorded verification-completion differences by group -- for example 41.59% for African American and 34.48% for Spanish-language claimants versus 53.44% for White claimants -- but stated the study showed differences in completion and did not show causation, so these are a friction proxy, not a measured wrongful-denial rate. The U.S. Department of Labor does not collect or report the number of workers blocked for inability to verify identity, and where verification precedes filing those workers are not counted as denied claims at all, so the scale of any wrongful lockout is undocumented.
empirical- Government U.S. House Committee on Oversight and Reform, Chairs Clyburn, Maloney Release Evidence Facial Recognition Company ID.me Downplayed Excessive Wait Times for Americans Seeking Unemployment Relief Funds (2022) https://oversightdemocrats.house.gov/news/press-releases/chairs-maloney-clyburn-release-evidence-facial-recognition-company-idme
- Government evaluation State of Oregon Employment Department, Potential Disparate Impacts of ID.me for Unemployment Insurance Claimants in Oregon (Anonymized) (2022) https://www.oregon.gov/employ/NewsAndMedia/Documents/2022-02-Potential-ID.Me-Disparate-Impacts-FINAL.pdf
- Advocacy National Employment Law Project, Identity Verification (Unemployment Insurance Policy Hub, Policy Advocacy Brief) (2023) https://www.nelp.org/app/uploads/2023/11/ID-Verification-11-2023.pdf
- Government evaluation U.S. Department of Labor, Office of Inspector General, Alert Memorandum: ETA and States Need to Ensure the Use of Identity Verification Service Contractors Results in Equitable Access to UI Benefits and Secure Biometric Data (Report No. 19-23-005-03-315) (2023) https://www.oig.dol.gov/public/reports/oa/2023/19-23-005-03-315.pdf
A U.S. Department of Labor Inspector General audit (March 31, 2023) found that among 24 state workforce agencies using a facial-recognition identity contractor, 18 of 24 (75%) contracts did not specify one-to-one versus one-to-many matching, 15 of 24 (63%) did not address data storage, and 13 of 24 (54%) did not address destruction of the collected biometric data, while 22 of 24 (92%) agencies reported the technology reduced improper payments -- the operator-side benefit that sustained adoption even as the wrongful-lockout cost went unmeasured. The vendor initially represented it used only one-to-one matching and later acknowledged one-to-many matching against a database; after bipartisan backlash the IRS and Treasury dropped the mandatory facial-recognition requirement in February 2022 and the vendor made it optional across agencies, though the service remained in use for unemployment identity verification in a large share of states, and a 2026 IRS proposal would allow it to retain taxpayer biometric data up to 36 months after account deletion. The reported improper-payment reductions are agency self-reports, not independently audited.
empirical- Government evaluation U.S. Department of Labor, Office of Inspector General, Alert Memorandum: ETA and States Need to Ensure the Use of Identity Verification Service Contractors Results in Equitable Access to UI Benefits and Secure Biometric Data (Report No. 19-23-005-03-315) (2023) https://www.oig.dol.gov/public/reports/oa/2023/19-23-005-03-315.pdf
- Advocacy American Civil Liberties Union (Jay Stanley and Olga Akselrod), Three Key Problems with the Government's Use of a Flawed Facial Recognition Service (2022) https://www.aclu.org/news/privacy-technology/three-key-problems-with-the-governments-use-of-a-flawed-facial-recognition-service
- Advocacy Electronic Frontier Foundation, Victory ID.me to Drop Facial Recognition Requirement for Government Services (2022) https://www.eff.org/deeplinks/2022/02/victory-irs-wont-require-facial-recognition-idme
- Trade press Biometric Update, IRS proposal could turn taxpayer facial verification into long-term fraud database (2026) https://www.biometricupdate.com/202605/irs-proposal-could-turn-taxpayer-facial-verification-into-long-term-fraud-database
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Public benefits & eligibility domain page.
Levers available here and the patterns behind them
- Pause AI on alarms — Deployment circuit-breaker
- Understand the system — Understand the system
- Assign a challenger — Structured dissent
- Check copied records — Reconcile copied records
- Gate vendor updates — Vendor quality gate
- Store less data — Data minimization
- Vet connections — Connection authorization
- Review on schedule — Oversight cadence & retrospectives
- Escalate checks — State-feedback vigilance
- Upgrade model — Improve the model
Documented case histories
- ID.me identity verification as an unemployment eligibility gate
- Michigan MiDAS
- Robodebt (Australia)
- Indiana / IBM eligibility modernization
- Rotterdam welfare-fraud risk model
- Arkansas ARChoices / ARIA
- Netherlands childcare-benefits scandal (Toeslagenaffaire)
- SyRI (Netherlands)
- CNAF benefit-fraud risk score (France)
- Forsakringskassan VAB fraud-selection profile (Sweden)
- Udbetaling Danmark data-driven control (Denmark)
- BOSCO (Spain)
- Serbia Social Card (Socijalna karta)
- UK DWP Universal Credit Advances fraud model
- Medicaid unwinding: automated ex parte renewal at population scale
- INSS auto-analysis: when the productivity metric makes denial the fastest way out
- Samagra Vedika
- Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
- NYC MyCity business chatbot
- Nevada DETR generative-AI unemployment appeals
- Tennessee TennCare TEDS