Civic / Privacy / Digital Rights

The FBI Threat Screening Center AI Enhancement Initiative: Is It a Predictive “Pre-Crime” System?

Report summary

This report uses five labels to separate what the public record establishes from what remains uncertain:

Status
Research archive item
Category
Civic / Privacy / Digital Rights
Length
9,939 words
Reading time
46 minutes
Report type
evaluation

Key topics

  • Civic / Privacy / Digital Rights
  • Civic
  • Privacy
  • Digital Rights
  • AI
  • Runtime
  • Semantic Systems
  • Research Archive
  • Strategy

Research provenance

Archive status
Research archive item
Content identity
sha256:ec9e0d27bb4a3f43da46bec75097e761cf3128889c6eee2245f04aa787a3d63d

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

Source availability: 107 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

Executive assessment

Evidentiary conventions

This report uses five labels to separate what the public record establishes from what remains uncertain:

LabelMeaning
Verified factDirectly supported by an official record, court filing, statute, regulation, government report, or contemporaneous procurement notice.
Official claimA government characterization of its mission, safeguards, performance, or intended use that has not necessarily been independently validated.
Independent findingA conclusion reached by comparing multiple public records, including negative searches for follow-on procurement actions.
AllegationA claim by a litigant, advocacy organization, journalist, or other outside party that has not been conclusively established.
Reasoned inferenceA technically or legally grounded interpretation that follows from the evidence but is not expressly stated in the source documents.

Confidence ratings describe confidence in the conclusion, not confidence that the underlying program will remain unchanged after August 2, 2026.

Principal findings

Principal findingEvidence classification and confidence
The March 27, 2026 action was market research, not a contract or deployment authorization. SAM.gov identifies FBI-TSC-AIE as a Sources Sought notice, with responses due April 10. Under the Federal Acquisition Regulation, market research is used to determine whether suitable commercial products or services exist and precedes any resulting solicitation or contract.Verified fact — High confidence
The notice sought six related AI capabilities centered on knowledge retrieval, federated discovery, identifier-based reporting, synthesis, provenance, correlation, and visualization. The core language is directed principally at reducing repetitive analyst work over large, distributed datasets—not at automatically deciding that a person will commit a crime.Verified fact / independent finding — High confidence
The most controversial “predictive modeling” requirement predicts where more relevant information may be found. The operative language reportedly requires similarity, pattern, and attribute analysis to “predict where additional relevant information may be derived across federated systems.” Grammatically and technically, the target of prediction is an information location or information relationship, not future human conduct.Verified wording / independent interpretation — High confidence
No public record located through August 2, 2026 establishes a follow-on solicitation, prototype agreement, task order, contract award, selected vendor, production authorization, or operational deployment under FBI-TSC-AIE. The notice remained categorized as Sources Sought, its “Related Notice” field was blank, and the July 22 update still presented an RFI attachment rather than an award instrument.Independent negative finding — Medium-high confidence
The July 22 posting is not evidence of an award. It added an updated, larger RFI attachment—approximately 482 KB versus roughly 422 KB for the March file—but the public metadata did not expose a redline or identify a new procurement phase. The original response deadline had already passed.Verified fact / reasoned inference — High confidence that it was not an award; low confidence about the precise textual changes
The initiative fits a broader FBI strategy of all-source integration and analyst augmentation. Separate FBI Broad Agency Announcement problem sets seek AI for all-source data management, anticipatory-analysis preparation, automated reporting and alerts, knowledge management, dynamic threat modeling, open-source cross-verification, and AI governance. Those problem sets demonstrate institutional interest, but they are not proof that FBI-TSC-AIE has acquired or deployed any of those capabilities.Verified fact — High confidence
The TSC’s underlying mission has expanded beyond its original terrorism-watchlisting role. The Terrorist Screening Center was renamed the Threat Screening Center in March 2025. FBI budget materials describe a Threat Screening System containing logically separated datasets for known or suspected terrorists, certain non-terrorist national-security threat actors, and transnational organized-crime actors.Verified fact — High confidence
The NSPM-7 reference in the TSC procurement record almost certainly points to the October 2017 national-security threat-information memorandum, not the separately numbered September 2025 political-violence memorandum. The 2017 document expressly directs development of technical architectures for identity attributes and associated derogatory information and is the authority publicly linked to the Threat Screening System’s additional datasets. No public procurement document located expressly ties FBI-TSC-AIE to the 2025 memorandum.Reasoned inference — High confidence
The principal civil-liberties danger is not a demonstrated “crime prediction” model but a powerful virtual integration layer. Federated search, entity matching, similarity analysis, and automated synthesis can make distributed records function like a single investigative environment. Errors, ambiguous identities, protected activity, or weak associations can therefore be surfaced and recombined at far greater speed and scale.Reasoned inference — High confidence
Calling the documented initiative a deployed predictive “pre-crime” system is misleading. Calling it an infrastructure that could lower the technical cost of future predictive or anticipatory analysis is partly accurate. The distinction matters: related-record discovery and identity resolution are strongly supported by the documents; person-level future-conduct prediction is not.Bottom-line judgment — High confidence concerning the notice; medium confidence concerning future evolution

Concise answer

Independent finding — High confidence: FBI-TSC-AIE is best understood as an early-stage market-research initiative for an AI-assisted threat-information discovery and analyst-support layer. Its documented “prediction” requirement concerns discovering where additional information may exist across federated systems. The public record does not establish a person-risk score, an algorithmic watchlisting decision, a crime forecast, a vendor award, or an operational deployment.

Reasoned inference — Medium-high confidence: The initiative nevertheless raises serious civil-liberties questions because it would combine several capabilities—federated retrieval, identity correlation, automated synthesis, and dynamic visualization—that can transform the practical reach of existing data holdings without formally creating a new centralized database. In a threat-screening environment, that transformation can affect investigations, watchlist nominations, border encounters, immigration vetting, security clearances, or other consequential processes even when the software is nominally “decision support.”

Terms, scope, and program-status definitions

Procurement terms that must not be conflated

Verified fact: Federal procurement records distinguish sharply among market research, solicitations, awards, prototypes, and deployment. FAR Part 10 provides that agencies conduct market research to determine whether commercial products, commercial services, or nondevelopmental items can meet a need. FAR 15.201 permits exchanges with industry before proposals are received. Such exchanges can shape requirements and acquisition strategy, but they are not themselves an offer, contract, or purchase.

TermMeaning in this investigationWhat it proves
Request for informationA request for industry information, capabilities, approaches, or comments.The government is exploring the market or refining a requirement.
Sources-sought noticeMarket research aimed particularly at identifying capable sources and informing competition or set-aside decisions.Potential government interest; no obligation to buy.
SolicitationA request for quotations, bids, or proposals containing an acquisition method and instructions for competing for an award.The government has entered a formal competition, subject to cancellation.
Prototype or pilotA limited technical demonstration, test, or trial. It may arise under a contract, other transaction, cooperative agreement, existing task order, or internal development.A capability is being tested; not necessarily production-authorized.
Contract awardA legally binding procurement instrument signed by an authorized contracting officer.The government has obligated itself subject to the instrument’s terms.
Task or delivery orderAn order issued under an existing indefinite-delivery contract or governmentwide vehicle.Specific funded work has been ordered, although the public description may be generic.
Authorization to operateA cybersecurity-risk determination allowing an information system to operate under defined conditions.Security authorization—not proof that every proposed analytical use is approved.
Operational deploymentRoutine use against live mission data in an actual workflow.The capability has moved beyond research, test, or evaluation.
AI use-case inventory entryAn agency disclosure that an AI use exists at a stated lifecycle stage, subject to inventory rules and exclusions.Evidence of a recognized use case, but not necessarily a standalone contract or complete description.

Independent finding — High confidence: FBI-TSC-AIE reached only the first two categories in the public record: an RFI embodied in a sources-sought notice. The record does not support collapsing that status into “the FBI bought predictive AI,” “the FBI built a prototype,” or “the system is live.”

Technical terms

AI-enabled knowledge management means using language models, semantic indexes, search engines, or knowledge graphs to retrieve and synthesize information from policies, directives, standard operating procedures, and prior analytical products. A credible implementation would preserve document versions, effective dates, access restrictions, and links to authoritative source text.

Federated search means querying multiple repositories through connectors or application interfaces while leaving records in their source systems. The federation layer may combine results, but source repositories retain their own storage, permissions, and records-management responsibilities. It is therefore distinct from copying all records into one warehouse.

Entity resolution is the process of deciding whether records refer to the same real-world person, organization, device, account, address, document, or other entity. Exact identifiers—such as fingerprints or a unique document number—can be highly discriminating. Names, dates of birth, transliterations, telephone numbers, addresses, or co-occurrence patterns require probabilistic or rule-based matching and can produce both missed matches and false matches.

Identifier resolution is narrower. It asks what other records correspond to a supplied identifier or set of identifiers. It need not determine a person’s identity from scratch, although aggregating multiple weak identifiers can become functional identity resolution.

Similarity analysis finds records that are close according to selected features, embeddings, text patterns, graph relationships, time, geography, or other attributes. Similarity does not by itself establish identity, culpability, intent, or future conduct.

Data lineage records where data came from, how it was transformed, which version was used, what model or query acted on it, and how an output was produced. Lineage is broader than a citation: a citation points to a source; lineage should preserve the processing chain.

Predictive modeling is an umbrella term. A model may predict equipment failure, document relevance, the repository likely to contain another record, business costs, threat-group capability, or a person’s future conduct. The word “predictive” therefore does not establish that an application predicts crime.

Dynamic threat models are structured analytical representations that update as evidence changes. The FBI’s separate BAA describes weighted models using adversary capability, doctrine, influence, historical behavior, and stated intent. That is closer to prospective threat analysis than the TSC RFI’s information-discovery prediction, but even the BAA does not necessarily call for an individual criminal-propensity score.

Scope and limitations

Independent finding: The research examined the two publicly indexed SAM versions, public attachment descriptions and mirrors, exact-title and exact-identifier searches for follow-on actions, FBI and DOJ budget and AI materials, the FBI’s enterprise BAA, TSC transparency and privacy records, PCLOB and DOJ Inspector General reports, presidential directives, procurement rules, and judicial decisions.

Limitation — Medium confidence: The public SAM interface exposed the existence, names, sizes, dates, and public status of both attachments, while third-party procurement mirrors exposed substantial extracted text. A publicly accessible government redline explaining the differences between the March and July PDFs was not located. Accordingly, this report does not claim that every formatting or wording change between those files has been reconstructed.

Limitation — High confidence: Negative procurement findings cannot exclude a classified procurement, an order under a broadly described existing vehicle, work funded under a different identifier, internal government development, or a later action not yet indexed. They establish only that no publicly attributable follow-on was found by the research cutoff.

Documentary record and chronology

The institutional history

Period or dateDevelopmentEvidentiary assessment
Before September 2001Nine federal agencies maintained twelve separate terrorism-related watchlists. Information-sharing restrictions made cross-agency integration difficult, a deficiency later associated with the government’s failure to connect pre-attack information.Verified fact
September 2001The attacks prompted a reorganization of terrorism-information integration, watchlisting, and screening. The 9/11 Commission later recommended a more unified screening system.Verified fact
May 2003The Terrorist Threat Integration Center was created; it later became part of the National Counterterrorism Center. TIDE developed as the central repository of international-terrorism identity information.Verified fact
September 2003HSPD-6 directed the Attorney General to establish an organization consolidating the government’s terrorism-screening approach and to maintain thorough, accurate, and current information on persons known or appropriately suspected of terrorism-related conduct. The TSC was created pursuant to that framework.Verified fact
August 2004HSPD-11 called for comprehensive, coordinated terrorist-related screening while safeguarding legal rights, civil liberties, and information privacy.Verified fact
December 2004The Intelligence Reform and Terrorism Prevention Act formalized NCTC-related responsibilities and broader post-9/11 information-integration reforms.Verified fact
October 2005Executive Order 13388 directed agencies possessing or acquiring terrorism information to provide access to agencies with counterterrorism functions, subject to exceptions and legal constraints.Verified fact
January 2007An addendum to the TSC interagency memorandum clarified “terrorist identifiers,” including photographs, fingerprints, and other biometric data.Verified fact
December 2009–2010The attempted Northwest Airlines bombing exposed weaknesses in nomination and information-integration practices. Interagency Watchlisting Guidance was formalized in 2010.Verified fact
October 2017The original NSPM-7—Integration, Sharing, and Use of National Security Threat Actor Information to Protect Americans—directed development of technical architectures and policy frameworks for identity attributes and associated information concerning multiple categories of evaluated threat actors.Verified fact
2017–2022The government developed the broader Threat Screening System. PCLOB records explain that the Terrorist Screening Dataset sits within the TSS and that TSS contains additional, logically separated national-security datasets associated with the 2017 NSPM-7 framework.Verified fact
2021The term Terrorist Screening Dataset replaced the former Terrorist Screening Database terminology in public descriptions.Verified fact
2023Updated interagency Watchlisting Guidance governed nominations, removals, mitigating information, and data integrity. Much of the detailed guidance remained classified or controlled.Verified fact
February 2024The FBI issued a new publicly referenced version of its Domestic Investigations and Operations Guide. DOJ OIG materials confirm that the DIOG governs FBI criminal, national-security, and foreign-intelligence investigative activities.Verified fact
April 2024The FBI published an updated watchlisting transparency document describing TSDS inputs, nomination processes, identity information, encounter support, and privacy/civil-rights reviews.Verified fact / official claim
August 2024PCLOB reported that the terrorist watchlist contained approximately 1.1 million persons, fewer than 6,000 of whom were U.S. persons.Verified fact based on TSC reporting to PCLOB
December 2024DOJ OIG found the FBI in the early stages of AI integration. It had a Chief AI Officer, an AI governance board, an AI Ethics Council, an AI policy, and an inventory process, but faced data-architecture, workforce, funding, vendor-transparency, and independent-testing challenges.Verified independent oversight finding
January 2025PCLOB issued its Terrorist Watchlist report, recommending stronger data-integrity metrics, reviews and purging of U.S.-person records, transparency reporting, and improved redress.Verified independent oversight finding
March 2025The FBI renamed the Terrorist Screening Center as the Threat Screening Center, stating that its mission had expanded to additional national-security threats, including transnational organized crime.Verified fact / official explanation
April 2025OMB issued M-25-21 on federal AI use and M-25-22 on AI acquisition. The former requires risk practices for high-impact AI; the latter emphasizes performance, competition, interoperability, data portability, and vendor dependency, while excluding Intelligence Community elements from its requirements.Verified fact
September 2025A second presidential memorandum numbered NSPM-7 directed a domestic political-violence strategy. It is distinct from the 2017 NSPM-7 that established the national-security threat-actor information-integration framework.Verified fact
January 2026DOJ updated its public 2025 AI inventory. The inventory uses lifecycle categories such as predeployment, pilot, deployed, and retired, but no entry publicly identified itself as FBI-TSC-AIE.Verified fact / independent inventory finding
March 27, 2026The FBI posted FBI-TSC-AIE as a Sources Sought notice with an RFI attachment and an April 10 response deadline.Verified fact
April 10, 2026Industry responses were due. The notice did not become a public solicitation or award at the deadline.Verified fact
April 25, 2026SAM metadata marked the original notice inactive.Verified fact
May 2026The White House’s counterterrorism strategy called for identifying actors and plots before they occur and mapping threat groups and their ties. That strategy supplies broader policy context but does not identify FBI-TSC-AIE as an implementing system.Official policy claim / independent limitation
July 22, 2026SAM posted an updated RFI attachment under the same notice identifier. The opportunity remained a Sources Sought action rather than an award notice.Verified fact
August 2, 2026No publicly attributable solicitation, prototype agreement, task order, award, vendor selection, production authorization, or operational deployment was located under the notice title or identifier.Independent negative finding — Medium-high confidence

The two different NSPM-7 documents

The duplicate numbering is unusually important.

Verified fact: The October 2017 NSPM-7 defines “national security threat actor information” as identity attributes and associated information about individuals, organizations, groups, or networks assessed to threaten U.S. safety, security, or national interests. It directs DOJ, DHS, ODNI, and partner agencies to create technical architectures and corresponding policy frameworks for integration, sharing, and use. It also requires safeguards where an application may deny a benefit or protected interest.

Verified fact: The September 2025 NSPM-7 addresses domestic terrorism and organized political violence. It directs Joint Terrorism Task Forces to investigate and disrupt specified criminal networks and instructs the Attorney General to identify behaviors, fact patterns, recurrent motivations, and other indicia for preventing potential violent activity.

Independent finding — High confidence: The TSC’s publicly documented Threat Screening System predates the 2025 memorandum and is explicitly traced by PCLOB to the 2017 NSPM-7. The AIE notice’s pairing of HSPD-6 and NSPM-7 therefore most naturally refers to HSPD-6 plus the 2017 integration directive.

Reasoned inference — Medium confidence: The 2025 memorandum and the 2026 counterterrorism strategy still matter as environmental context. A technical layer capable of cross-domain association and identifier enrichment could potentially support investigations initiated under those policies. But potential compatibility is not evidence of actual integration, authorization, targeting criteria, or deployment.

Procurement record and actual program status

What the government requested

Verified fact: The notice states that the TSC has a national-security mission to consolidate the federal approach to terrorism and national-security threat screening. It describes a need to automate time-intensive, repeatable manual work involving large data volumes across multiple domains. It also refers to gap analysis and querying external systems for enrichment.

The documented capability areas are:

CapabilityPublicly described requirementTechnical meaning
AI-enabled knowledge baseIngest and index standard operating procedures, directives, and policies; permit natural-language questions; return current answers with citations.A retrieval and generation layer over authoritative internal guidance, likely requiring version awareness and retrieval-augmented generation rather than an unconstrained chatbot.
Federated search and summarizationSearch multiple repositories without consolidating all records; summarize responsive information; redirect users to source material; preserve lineage.Query orchestration across heterogeneous systems, with permissions enforced at each source and results combined at query time.
Identifier-driven reportsUse identifiers to query federated sources, produce reports at configurable intervals, and preserve a citation for each data element.Automated enrichment and dossier assembly around supplied identifiers, potentially including exact and fuzzy matching.
Natural-language querying and synthesisPermit natural-language questions over enterprise datasets and synthesize results with citations and traceability.Translate user intent into structured or semantic queries, retrieve authorized records, and generate an evidence-linked response.
Similarity, pattern, correlation, and “predictive” discoveryOn ingestion of new data, compare similarity, pattern alignment, and attributes against existing records to identify where additional relevant information may be found across federated systems.Record linkage, nearest-neighbor search, graph traversal, association analysis, or a learned relevance model. The predicted variable is apparently the likely existence or location of further information.
Dynamic visualizationLet analysts explore and display relationships dynamically while preserving source traceability.Interactive graphs, timelines, tables, geospatial displays, relationship maps, or drill-down views tied to underlying records.

Verified fact based on publicly extracted attachment text: Responses were to be unclassified and focused on vendor capability, corporate identifiers, business status, available contract vehicles, technical approach, and relevant experience. Public procurement mirrors report a limit of approximately 25 pages and an expectation that an eventual solution conform to FBI AI ethical standards and receive AI Ethics Council review.

Independent finding — High confidence: The RFI did not publicly disclose an appropriated amount, estimated contract value, period of performance, evaluation factors for award, production quantities, service-level agreement, model-performance threshold, or implementation schedule. Commercial websites’ dollar estimates and “odds of award” are algorithmic estimates, not government commitments.

Procurement-document matrix

Record soughtPublicly located recordWhat it establishesStatus and confidence
Original SAM noticeMarch 27, 2026 SAM entry, FBI-TSC-AIE, Sources Sought.Official notice identifier, agency, notice type, dates, contact, and attachment.Located — High
Original attachment“TSC RFI for AI Enhancement Services Final.pdf,” approximately 421.65 KB.Initial RFI and capability description.Located/indexed — High
Response deadlineApril 10, 2026, 3 p.m. Eastern.End of requested industry-response period.Located — High
July updateJuly 22 SAM posting under same notice identifier.Continued or revised market-research record, not a new award.Located — High
Updated attachment“UPDATE 7.22TSC RFI for AI Enhancement Services Final.pdf,” approximately 482 KB.A revised RFI file exists.Located/indexed — High
Official redline or change logNone located.Exact March-to-July textual changes cannot be reliably enumerated.Not located — Medium
Public questions and answersNo separately indexed Q&A document located.No public evidence of formal answers to vendor questions.Not located — Medium
Procurement forecast line itemNo forecast entry specifically naming FBI-TSC-AIE located.No publicly identified planned solicitation date, value, or acquisition vehicle.Not located — Medium
Formal solicitationNo RFP, RFQ, invitation for bids, or solicitation number linked to FBI-TSC-AIE located.Market research had not publicly advanced to formal competition.Not located — Medium-high
Prototype agreement or pilot noticeNo attributable prototype, other-transaction, cooperative agreement, or pilot notice located.No public evidence of a TSC-AIE prototype.Not located — Medium
Contract or task-order awardNo award linked by title, notice identifier, or related-notice field located.No publicly verified vendor selection or funded production work.Not located — Medium-high
Awarded vendorNone supported by reliable public records.Prospective vendors should not be inferred from market presence or prior FBI work.None identified — High
Budget justification lineFY2027 FBI materials describe TSC operations and the Threat Screening System, but no named TSC-AIE line or separately identified appropriation was located.General mission funding does not establish funding for this RFI.General funding only — High
DOJ AI inventory entryNo entry publicly named FBI-TSC-AIE or Threat Screening Center AI Enhancement.No inventory confirmation of this initiative as a pilot or deployed use case. The inventory predates the notice and may aggregate or withhold sensitive uses.Not identified — Medium
FBI BAA awardThe separate enterprise BAA remains open through May 16, 2027 and permits, but does not require, multiple R&D awards.The BAA is an adjacent acquisition channel, not a TSC-AIE award.Separate action — High
Privacy impact assessmentNo public PIA specifically naming TSC-AIE located. Existing TSC/TSS privacy records cover broader systems.Whether a new or amended assessment has been prepared is unknown.Not located — Medium
AI Ethics Council decisionNo public decision or approval specifically naming TSC-AIE located.Governance review cannot be presumed from the RFI’s stated expectation.Not located — Medium-high
Congressional referenceNo hearing, report, or member letter specifically naming FBI-TSC-AIE located. Broader TSC, watchlisting, and FBI AI oversight materials exist.Congress has addressed the surrounding programs but not publicly this notice by name.Direct reference not located — Medium

Why the FBI requested it

Official claim: The operational justification is volume and analyst workload. The TSC says personnel perform repeatable, time-intensive work across multiple data domains and require better automation for gap analysis, retrieval, enrichment, and presentation.

Independent finding: That rationale matches three documented FBI-wide problems. First, the Bureau’s BAA identifies unstructured-data triage, all-source integration, automated reporting, knowledge management, and alerting as enterprise needs. Second, DOJ OIG found that modernization of data architecture and IT infrastructure was a barrier to AI adoption. Third, the TSC’s expansion from one terrorism dataset to multiple logically separated threat datasets increases the burden of locating relevant information while respecting distinct access and policy rules.

Reasoned inference — High confidence: A federated approach is attractive because it promises cross-system discovery without a wholesale physical merger. It can preserve source ownership, classification boundaries, records schedules, and system-specific access controls—if the federation layer enforces them correctly.

Reasoned inference — High confidence: It can also create a functional merger. An analyst who once had to search six systems independently may receive a single synthesized relationship map in seconds. The absence of a central copy therefore does not eliminate aggregation, inference, or mission-creep risks.

Deployment status

Bottom-line status finding:

As of August 2, 2026, the highest publicly verified stage is “market research / sources sought.”

No public evidence establishes:

  • a procurement competition;
  • technical evaluation or down-select;
  • a prototype or pilot;
  • live-data testing;
  • an awarded vendor;
  • a funded task order;
  • an authorization to operate;
  • AI Ethics Council approval;
  • operational use in nomination, screening, encounter management, or investigation;
  • or an automated adverse decision.

Confidence: High that the notice itself is only market research; medium-high that no public follow-on existed or was attributable by the cutoff; low regarding nonpublic or differently titled activity.

Technical architecture, functions, and data lifecycle

A likely architecture

The following diagram is a reasoned architecture, not a disclosed FBI system design. It reflects the minimum components needed to perform the public requirements while retaining provenance and access controls.

                     AUTHORITATIVE SOURCE ENVIRONMENTS
       ┌───────────────────────────────────────────────────────┐
       │ Threat-screening datasets │ Case systems │ Policies  │
       │ Encounter records         │ Partner repositories     │
       │ Other authorized enterprise or external systems      │
       └───────────────┬───────────────────────────────────────┘
                       │
             Source-specific connectors
      authentication • authorization • classification checks
                       │
       ┌───────────────▼───────────────────────────────────────┐
       │ FEDERATION AND DATA-GOVERNANCE GATEWAY               │
       │ query routing • schemas • purpose controls • logging │
       │ records restrictions • source/version identifiers    │
       └───────────────┬───────────────────────────────────────┘
                       │
        ┌──────────────▼──────────────┐
        │ RETRIEVAL AND INDEX LAYER   │
        │ keyword • semantic • graph  │
        │ metadata • document chunks  │
        └──────────────┬──────────────┘
                       │
       ┌───────────────▼───────────────────────────────────────┐
       │ ENTITY / IDENTIFIER RESOLUTION                       │
       │ exact matches • fuzzy names • biometrics references │
       │ aliases • devices/accounts • confidence estimates   │
       └───────────────┬───────────────────────────────────────┘
                       │
       ┌───────────────▼───────────────────────────────────────┐
       │ ENRICHMENT AND ANALYTIC LAYER                        │
       │ similarity • pattern alignment • attribute links    │
       │ gap detection • likely-source prediction            │
       └───────────────┬───────────────────────────────────────┘
                       │
       ┌───────────────▼───────────────────────────────────────┐
       │ SYNTHESIS / KNOWLEDGE LAYER                          │
       │ natural-language interface • summaries • reports    │
       │ citations • lineage • uncertainty • policy answers  │
       └───────────────┬───────────────────────────────────────┘
                       │
       ┌───────────────▼───────────────────────────────────────┐
       │ ANALYST WORKSPACE                                    │
       │ tables • graphs • timelines • maps • source drill-in│
       │ accept/reject/correct • escalation • dissemination  │
       └───────────────┬───────────────────────────────────────┘
                       │
       ┌───────────────▼───────────────────────────────────────┐
       │ GOVERNANCE AND ASSURANCE                             │
       │ immutable logs • QA • model/version registry        │
       │ drift tests • access review • incident response     │
       │ retention/correction/deletion workflows             │
       └───────────────────────────────────────────────────────┘

Verified fact: Public records identify TIDE and FBI Sentinel as upstream sources of international and purely domestic terrorism information, respectively, for the terrorism-watchlisting environment. The TSDS contains identifiers exported from those environments, and certain watchlist information is exported to NCIC for law-enforcement screening. The TSC also manages encounters and notification of relevant stakeholders.

Important limitation — High confidence: The AIE notice does not publicly name TIDE, Sentinel, TSDS, NCIC, a financial dataset, social-media collection, location records, or any other specific operational repository as an intended connection. The systems above are verified components of the broader TSC ecosystem, not confirmed AIE integrations.

Capability analysis

AI-enabled knowledge management

Verified fact: The RFI calls for ingestion and indexing of standard operating procedures, directives, and policies, natural-language querying, and answers with citations.

Technical assessment: This is a classic retrieval-augmented knowledge application. A robust system would first identify authoritative documents, split and index them with metadata, retrieve passages responsive to a question, and generate an answer constrained by those passages. The system should show document title, version, effective date, paragraph, classification, and whether superseding guidance exists.

Risk: A policy assistant can confidently cite an obsolete directive or merge rules that apply to different datasets. Version control is therefore not an administrative convenience; it is a legal-control requirement.

Function supported: Policy retrieval, not identity resolution or person-risk prediction.

Federated search and summarization

Verified fact: The desired search spans multiple repositories without requiring consolidation and is expected to provide summaries, source redirection, and lineage.

Technical assessment: A query broker would determine which repositories the user is authorized and justified to search, translate the request into each repository’s schema or API, normalize results, and return them in a common format. Semantic retrieval could discover conceptually related records even when exact keywords differ.

Risk: The federation layer can accidentally become the most privileged component in the environment. If it possesses broad service credentials or caches restricted data, compromise of that layer could defeat source-level segmentation.

Function supported: Related-record discovery strongly; identity resolution only if matching logic is added.

Entity and identifier resolution

Verified fact: The RFI includes identifier-driven querying and reporting. TSC’s documented operational mission separately includes identity resolution and determining whether a screened person is a positive match to a watchlist record.

Technical assessment: Exact identifier resolution can join records on a passport number, fingerprint reference, or system identifier. Probabilistic resolution scores whether records with variations—such as transliterated names, partial birth dates, reused addresses, or shared devices—refer to the same entity.

A defensible implementation should return:

  • the attributes compared;
  • match and non-match evidence;
  • confidence calibrated on relevant populations;
  • known collision rates;
  • alternative candidate identities;
  • and a rule prohibiting weak contextual similarity from being presented as a confirmed identity.

Risk: In threat screening, false consolidation can be more damaging than an ordinary search error because the resulting composite may falsely appear to contain corroboration from multiple systems.

Function supported: Identity resolution moderately to strongly, depending on implementation; no inherent prediction of future conduct.

Source attribution and citation retention

Verified fact: Citation retention, source redirection, traceability, and data lineage appear repeatedly in the public requirement descriptions.

Technical assessment: Every output proposition should retain a machine-readable provenance object: source-system identifier, record identifier, field or passage, retrieval time, record version, transformation history, model version, and confidence. A citation that merely opens a document is insufficient if the summary combined or transformed multiple fields.

Risk: Lineage can break when outputs are copied into a separate intelligence product, exported to a partner, manually rephrased, or used as a feature in another model. Provenance must travel with the data.

Function supported: Accountability across all functions; not itself a threat assessment.

Natural-language querying

Verified fact: Both the knowledge-base and enterprise-data requirements contemplate natural-language questions.

Technical assessment: The language interface may translate a question into database queries, semantic-search requests, or graph traversals. It can reduce the need for analysts to know every source schema, but it also conceals query construction.

A safe interface should display:

  • the systems queried;
  • the interpreted search terms and filters;
  • exclusions caused by access restrictions;
  • whether the answer is complete or partial;
  • the date range and entity constraints;
  • and the distinction between retrieved facts and generated synthesis.

Risk: A vague question such as “show people connected to X” can silently encode a broad relationship rule. Query transparency is therefore as important as model explainability.

Similarity, pattern alignment, and attribute correlation

Verified wording: The RFI’s controversial analytic function is triggered when new data is ingested and compares it with existing records through similarity, pattern alignment, and attribute correlation. Its stated objective is to predict where additional relevant information may exist across federated systems.

Technical assessment: This could be implemented through:

  • semantic nearest-neighbor search;
  • fuzzy record linkage;
  • graph link prediction;
  • co-occurrence analysis;
  • rules based on shared attributes;
  • clustering;
  • or a classifier predicting which repository or record class is likely to contain another relevant item.

These techniques can be valuable for finding a second record about the same passport, organization, account, communication identifier, location, event, or modus operandi. They can also produce guilt-by-association effects when a shared attribute is common or socially structured.

Function supported: Related-record discovery strongly and identity resolution potentially. It does not, on its stated terms, predict a future act.

Predictive modeling with traceable lineage

Independent finding — High confidence: The heading “Predictive Modeling Using Enhanced Data with Traceable Lineage” is broader than the operative description. The operative description narrows the prediction target to where further relevant information may be derived.

Reasoned inference: The model may assign a probability such as “repository B is likely to contain a related record” or “this new item aligns with cluster C.” That is predictive in the machine-learning sense but is materially different from “this person is likely to commit violence.”

Unresolved risk: A discovery score could later be reused as a threat feature. For example, the number of systems in which related information is found might be treated as evidence of risk even if the count reflects duplicate reporting or biased collection. The RFI does not publicly describe feature-use restrictions preventing such repurposing.

Dynamic visualization

Verified fact: The final capability is dynamic visualization with traceability to sources.

Technical assessment: The likely outputs include relationship graphs, timelines, geographic views, matrices, and interactive report dashboards. Visualization can help analysts understand sequence and structure, but its design can imply conclusions. A thick edge, central node, red icon, or cluster placement can communicate “importance” or “risk” even when the underlying metric is merely frequency or data availability.

The four functions that must be separated

FunctionQuestion answeredEvidence in TSC-AIE recordAssessment
Finding related records“What other records, documents, or systems may contain information relevant to this identifier, topic, or event?”Federated search, semantic retrieval, identifier-driven reporting, similarity analysis, gap analysis, enrichment, source prediction.Strongly supported — High confidence
Resolving identity“Do these records refer to the same person or entity?”Identifier-driven search and attribute correlation; TSC’s independent mission includes identity resolution.Supported, but detailed matching requirements are undisclosed — Medium-high confidence
Assessing an existing threat“Given available evidence, does this person, organization, event, or network meet an established threat or watchlisting criterion?”The TSC mission is threat screening, and better information could inform analysts. The RFI does not publicly specify nomination criteria, threat scores, automated recommendations, or an adjudicative model.Indirectly supported as analyst context — Medium confidence
Predicting future human conduct“How likely is this person to commit a future violent, terrorist, or criminal act?”No public requirement for a person-level probability, behavioral-risk score, recidivism model, crime forecast, or automated watchlisting recommendation.Not supported by the procurement text — High confidence

Comparison with conventional search and genuine person-risk prediction

DimensionConventional database searchDocumented TSC-AIE conceptGenuine person-risk prediction
Primary inputKeywords, exact fields, structured filtersNatural language, identifiers, documents, embeddings, cross-source attributesHistorical person-level outcomes and predictive features
Primary outputMatching recordsRelated records, summaries, citations, reports, likely data sources, visual relationshipsProbability or category of future behavior
Typical model targetRelevance to queryRelevance, relationship, identity, repository likelihoodFuture violence, offending, travel, radicalization, or other conduct
Role of identity resolutionOptionalPotentially centralUsually required to create longitudinal person histories
Need for labeled outcomesNoNot necessarilyYes, unless using an unvalidated proxy
Base-rate problemLimited to retrieval precisionPresent if results are interpreted as threat signalsSevere for rare events such as terrorism
Potential adverse consequenceMissed or overbroad search resultsAnalyst suspicion, enrichment, dissemination, watchlisting supportDirect risk classification or intervention
Human reviewReviews recordsExpected but details not publicMay be nominal or substantive, depending on system
Best descriptionInformation retrievalAI-enhanced investigative and screening supportPredictive behavioral analytics

Illustrative analysis, not an FBI performance estimate: Suppose one future offender exists among 100,000 people. Even a hypothetical model with 90 percent sensitivity and 99 percent specificity would identify roughly one true positive while falsely flagging about 1,000 non-offenders. The positive predictive value would be approximately one-tenth of one percent. This base-rate problem is why predicting extremely rare human conduct is categorically harder than finding related documents.

Likely data lifecycle

Collection. Data originates under the legal authority of source agencies or systems. The AIE notice does not create new collection authority. The broader TSC environment receives nominated identities and associated information from NCTC/TIDE, FBI systems, screening partners, and encounter processes.

Ingestion or query-time access. The solution may index selected metadata or document content, or it may query records in place. A hybrid design is likely: policy documents and embeddings may be centrally indexed, while sensitive operational records remain federated.

Entity matching. Identifiers and attributes are normalized, aliases and transliterations compared, and possible matches ranked. Exact biometrics and unique numbers should be treated differently from shared addresses, names, or behavioral similarities.

Enrichment. The system queries additional authorized sources, aligns patterns, identifies gaps, and assembles candidate relationships. An enrichment result should remain labeled as a lead unless independently confirmed.

Model inference. Retrieval ranking, similarity scores, record-link probabilities, summaries, and likely-source predictions are produced. Model and prompt versions should be logged.

Analyst review. An analyst checks underlying records, confirms or rejects matches, considers mitigating information, and determines whether the output is suitable for dissemination or action. The RFI does not publicly define mandatory review depth or prohibited reliance.

Dissemination. Confirmed or caveated information may be shared within the FBI or with authorized screening, law-enforcement, intelligence, or international partners. The TSC’s existing role includes near-real-time encounter support and information sharing.

Retention. Source records remain subject to their governing SORNs and schedules. FBI public materials describe long retention periods for TSC records, including periods extending to decades for active, inactive, and encounter records. That does not establish the schedule for new AIE logs, caches, embeddings, or generated reports, which would require records classification.

Correction. Corrections must propagate from authoritative sources to indexes, cached summaries, entity clusters, visualizations, and derived reports. Correcting only the source while preserving a stale vector index or generated dossier would leave the substantive error in circulation.

Deletion or purge. Removal from a source dataset should trigger deletion or invalidation of derived features, links, cached text, and model-accessible copies unless another lawful recordkeeping requirement applies. PCLOB has specifically urged stronger review and purging of U.S.-person watchlist records.

Governing authorities, AI governance, and oversight

Authority or mechanismRelevant rule or functionConstraint or unresolved issue
HSPD-6Directs consolidation of terrorism-screening information concerning persons known or appropriately suspected of terrorism-related conduct and requires thorough, accurate, and current information.Must be implemented consistently with the Constitution and applicable law. It does not independently authorize every method of collecting or using data.
HSPD-11Calls for comprehensive, coordinated terrorist-related screening.Expressly recognizes legal rights, civil liberties, and information privacy.
2017 NSPM-7Directs technical architectures and policy frameworks for integrating identity attributes and associated national-security threat information.Requires privacy, civil-rights, civil-liberties, and protected-interest safeguards, particularly where use may deny a benefit or protected interest.
2025 NSPM-7Directs a federal strategy concerning domestic terrorism and organized political violence and calls for analysis of behaviors, patterns, motivations, and indicia.No public record ties TSC-AIE to this memorandum. Its view-based language and breadth create substantial First Amendment concerns if operational criteria reach protected advocacy or association.
Attorney General’s Guidelines for Domestic FBI OperationsEstablish authorized-purpose, predication, technique, and First Amendment restrictions for domestic FBI activity. Public guidance states information may not be collected or maintained solely to monitor First Amendment-protected activity.AI correlation does not relax predication or authorized-purpose rules. Analysts cannot convert protected speech into investigative justification merely because a model finds similarity.
FBI DIOG, February 2024Implements the Attorney General’s Guidelines for criminal, national-security, and foreign-intelligence investigative activity.Public redactions and classified supplements limit external assessment of how AI-assisted queries map to investigative stages and techniques.
Privacy Act of 1974Requires that agency records about individuals in a system of records be relevant and necessary to an authorized purpose and imposes accuracy, access, amendment, accounting, notice, and disclosure rules, subject to exemptions.Law-enforcement and national-security systems often invoke exemptions. Derived associations, embeddings, confidence scores, and generated summaries may be difficult for subjects to discover and contest.
E-Government Act, Section 208Requires PIAs for new or substantially changed IT involving identifiable information. DOJ policy extends PIA review to national-security systems even though the statute’s requirement does not apply to them in the same way.No TSC-AIE-specific public PIA was located. Classified or sensitive portions may lawfully be withheld, but the absence of a public document limits accountability.
TSC/TSS and related SORNsExisting records notices describe categories, purposes, routine uses, retention, and exemptions for threat-screening and NCIC-related records.A new analytic layer may require amendment if it materially changes categories, purposes, routine uses, or retrieval practices. Whether FBI considers it merely a tool over existing systems is unknown.
OMB M-25-21Requires agencies to govern AI, maintain inventories, identify high-impact AI, implement minimum risk practices, monitor performance, and cease uses that cannot be adequately mitigated.Applicability to national-security and Intelligence Community activities contains scope complexities; internal FBI and ODNI rules may be the more direct controls for some uses.
OMB M-25-22Governs AI acquisition, emphasizing competition, fit-for-purpose performance, interoperability, portability, and avoidance of vendor lock-in.The memorandum expressly excludes Intelligence Community elements. The FBI’s mixed law-enforcement and IC status makes activity-specific legal analysis necessary.
FBI AI Ethics Council and AI policyOIG reports that the Council reviews purpose, benefits, risks, privacy, monitoring, and ethical compliance and that FBI policy requires governance of AI capabilities.No public TSC-AIE review decision exists. OIG identified potential review backlogs, vendor-opacity problems, and limited independent testing.
ODNI AI ethics frameworkApplies ethical principles to Intelligence Community AI, including lawful, responsible, equitable, traceable, reliable, and governable use. The FBI says its process is designed around those principles.Principles require operational metrics, enforcement, and documentation; a statement of conformity is not validation.
NIST AI Risk Management FrameworkIdentifies validity, reliability, safety, security, resilience, accountability, transparency, explainability, privacy enhancement, and management of harmful bias as trustworthy-AI characteristics.The framework is primarily a risk-management framework, not a substitute for legal authority, judicial review, or enforceable individual rights.
PCLOBConducted a multi-year watchlist review and issued seven recommendations on integrity, mitigating information, U.S.-person review, transparency, and redress.PCLOB reported that important unclassified details were withheld from its public report and provided separately to Congress.
DOJ Inspector GeneralAudits FBI AI governance, congressional compliance, technology integration, and program management. OIG found both progress and material barriers.OIG reported that a congressionally required FBI AI report due in June 2023 remained incomplete as of its audit and was still described as outstanding in FY2025 materials.
GAO and CongressGAO and congressional committees have repeatedly examined watchlist management, screening vulnerabilities, redress, accuracy, and effects on Americans. PCLOB relied extensively on those records.No public hearing or report located had evaluated FBI-TSC-AIE itself by August 2, 2026.

First Amendment

Verified legal constraint: The Attorney General’s Guidelines and DIOG framework require a legitimate law-enforcement or national-security purpose and prohibit investigative activity based solely on protected First Amendment expression.

Reasoned legal assessment: The highest-risk feature is attribute and association correlation. Political speech, religious attendance, journalism, protest participation, charitable giving, or membership can be analytically correlated with a threat record without being unlawful. A system may technically be “finding a pattern” while legally surfacing constitutionally protected activity. The control must operate at feature selection, query authorization, output labeling, and downstream use—not merely at final adjudication.

Verified contextual fact: The 2025 NSPM-7 explicitly identifies recurrent motivations and ideological indicia while also invoking criminal activity. Civil-liberties organizations allege that the memorandum could chill dissent or enable viewpoint-based investigations. Those critiques are serious but do not prove that TSC-AIE processes political-activity data.

Fourth Amendment

Reasoned legal assessment: The RFI creates no collection authority. Whether a federated query implicates the Fourth Amendment depends primarily on how the source data was acquired, the user’s authority to access it, the sensitivity and comprehensiveness of the aggregated result, and whether the query constitutes a new search under governing doctrine.

A tool querying lawfully maintained government records is not automatically unconstitutional. Yet aggregation can change practical privacy consequences. A cross-system reconstruction of a person’s movements, communications, financial associations, travel, and social network can be substantially more revealing than any one record. The constitutional analysis should therefore consider both the legality of each source and the qualitative effect of comprehensive aggregation.

Fifth Amendment and redress

Verified fact: Watchlisting and No Fly List litigation shows that due-process questions turn on the consequence imposed, the adequacy of notice and redress, access to reasons, classified evidence, and the risk of erroneous deprivation. In FBI v. Fikre, the Supreme Court held that removing a plaintiff from the No Fly List and offering a limited assurance did not automatically moot his challenge.

Verified fact: PCLOB found that persons contesting watchlist effects face difficulties because they generally cannot access the classified information underlying a nomination. It recommended improved redress and greater transparency.

Reasoned legal assessment: An internal discovery tool may not itself deprive anyone of liberty or property. Due process becomes acute when its output materially contributes to a watchlist nomination, travel restriction, immigration action, security decision, referral, detention, investigation, or other adverse government action. At that point, provenance and correction are constitutional safeguards, not merely model-quality features.

Equal-protection principles

Reasoned legal assessment: The Fifth Amendment’s equal-protection component constrains intentional federal discrimination. A model can produce disparate effects without an express protected-class field because names, language, geography, religious institutions, travel, family relationships, or nationality operate as proxies. Statistical disparity alone does not always establish a constitutional violation, but it can reveal defects relevant to statutory obligations, internal policy, evidentiary reliability, and intentional-design inquiries.

A meaningful assessment would test false-positive and false-negative rates across language and transliteration groups, national origins, citizenship categories, sex, age, disability where relevant, and other legally or operationally significant populations. It would also test whether particular communities are more heavily represented because of collection patterns rather than true differences in threat prevalence.

Privacy and records governance

Verified fact: Section 208 PIAs are intended to explain how identifiable information is collected, stored, protected, shared, and managed. DOJ policy states that PIAs should be completed before operation, testing, or piloting and extends review to national-security systems.

Independent finding — Medium-high confidence: No public TSC-AIE-specific PIA, Privacy Threshold Analysis, modified SORN, records schedule, or public AI impact assessment was located. That absence is consistent with an initiative that had not progressed beyond market research, but it leaves the intended governance architecture unknown.

Reasoned inference: New record types could include prompts, queries, retrieved passages, generated summaries, embeddings, entity clusters, analyst corrections, match-confidence values, visualizations, and audit logs. Each requires an authoritative determination of whether it is a temporary work product, a federal record, part of an existing system of records, or a new record category.

Accuracy, bias, privacy, and security risk assessment

Risk register

RiskMechanismPotential consequenceNecessary controlsResidual rating
False identity matchCommon names, transliteration, incomplete birth data, shared identifiers, or over-weighted contextual attributes merge different people.Innocent person inherits derogatory information or encounter history.Attribute-level explanation; calibrated thresholds; biometric confirmation where lawful; alternative candidates; mandatory analyst verification.Critical
Missed identity matchVariant spellings, aliases, data-entry errors, or disconnected systems prevent linkage.Relevant threat information is not surfaced.Multilingual normalization; recall testing; human search fallback; structured uncertainty.High
Source error propagationAn inaccurate source record is repeated, summarized, and cited across reports.Error appears corroborated merely because it is reproduced in multiple outputs.Single-source deduplication; source-quality metadata; correction propagation; distinguish independent corroboration from duplication.Critical
Generated-summary errorA language model invents, omits, conflates, or overstates source content.Analyst relies on a false factual narrative despite apparent citations.Evidence-bounded generation; sentence-level citations; contradiction checks; direct-source review before action.Critical
Stale policy adviceKnowledge base retrieves superseded guidance or mixes rules applying to different datasets.Unlawful query, retention, nomination, or dissemination.Effective-date logic; authoritative version registry; supersession alerts; legal-owner approval.High
Association inflationShared locations, organizations, devices, or acquaintances are presented as meaningful links.Guilt by association; expansion from subject to community or network.Relationship-type labels; prevalence-adjusted significance; minimum-evidence rules; protected-activity filters.Critical
Base-rate failureRare-event prediction generates many more false positives than true positives.Large investigative burden and disproportionate impact on innocent people.Do not convert discovery scores into conduct-risk scores; publish calibration and precision; narrow operational use.Critical if behavioral prediction is introduced
Feedback loopAnalyst actions triggered by model outputs create more records about flagged people, which make them appear more connected in future searches.Self-reinforcing suspicion and biased data growth.Separate model-generated leads from independent evidence; audit outcome feedback; prohibit unreviewed retraining on enforcement outcomes.Critical
Automation biasAnalysts defer to fluent summaries, high scores, or compelling network graphics.Human review becomes nominal rather than corrective.Require source opening; uncertainty display; structured dissent; measure override and error-detection behavior.High
Model driftData, language, adversary behavior, source schemas, or model versions change.Performance degrades silently; bias or missed matches increase.Continuous monitoring; population-specific benchmarks; rollback; model registry and change control.High
Mission creepA retrieval capability is reused for nomination, targeting, political-violence analysis, immigration vetting, or personnel screening.Use beyond the purpose evaluated by privacy and ethics reviewers.Purpose-binding; separate approvals; use-case-specific access roles; new PIA/AIEC review for material changes.Critical
Cross-domain access leakageFederation broker returns data a user could not lawfully or operationally access directly.Exposure of classified, sealed, grand-jury, intelligence-source, or partner-restricted information.Attribute-based access control; source-enforced authorization; need-to-know and purpose checks; no privilege escalation.Critical
Inference leakageSummary reveals the existence or substance of restricted information without exposing the source document.Classification or source-method compromise.Output classification review; inference controls; compartment-aware generation; derivative-classification rules.Critical
Prompt injectionRetrieved documents contain instructions or adversarial text that manipulate the language model.Data exfiltration, altered queries, concealed sources, or misleading summaries.Treat retrieved text as data, not instructions; content isolation; tool allowlists; adversarial testing.High
Data poisoningFalse or manipulated records are inserted into source systems or open-source feeds.Correlations and entity profiles are intentionally distorted.Source authentication; anomaly detection; provenance; corroboration; poisoning exercises.High
Vendor opacityProprietary models, undocumented updates, or inaccessible training and testing details prevent validation.FBI cannot verify performance, bias, security, or legal compliance.Audit rights; model cards; version notice; reproducible evaluation; government-controlled logs; escrow or portability.High
Vendor lock-inProprietary embeddings, schemas, or orchestration make migration costly.Long-term dependence and inability to preserve records or reproduce old outputs.Open formats and APIs; exportable indexes and lineage; transition assistance; model substitution testing.Medium-high
Inadequate audit loggingQueries, source access, model versions, or analyst actions are not fully recorded.Misuse or error cannot be reconstructed.Immutable, tamper-evident logs; independent review; purpose code; retention proportional to oversight needs.Critical
Correction failureA corrected source does not update caches, embeddings, reports, or downstream partner copies.Erroneous suspicion persists after nominal correction.Dependency graph; invalidation notices; partner correction protocol; periodic derived-data reconciliation.Critical
Deletion inconsistencySource record is purged but derived representations remain.Continued processing of data no longer authorized or accurate.Cryptographic deletion where feasible; index rebuild; deletion attestations; records-officer review.High

Verified oversight context: PCLOB has already identified accuracy, mitigating-information, review, purge, transparency, and redress as areas needing improvement in the conventional watchlisting system. It recommended six-month TSC review of U.S.-person records, continued vetting of source reliability, and prompt removal where criteria are no longer met.

Verified oversight context: DOJ OIG independently found that the FBI faces data-architecture modernization problems, vendor-transparency limitations, a lack of independent testing options, and a potentially burdensome AI ethics-review pipeline.

Reasoned inference: An AIE system can reduce some existing risks. Better source attribution may expose contradictions; federated retrieval may find mitigating records; automated review may identify stale entries; and improved identity resolution may reduce name-based false matches. Whether it improves or worsens accuracy depends on measured performance and how analysts use the output.

Security classification and access controls

Verified fact: The separate FBI enterprise BAA anticipates that work may involve unclassified, classified, and potentially SCI-access environments; contractor access to FBI networks can require Top Secret eligibility and, depending on systems, SCI access.

Reasoned inference: The operational AIE environment would likely require multi-level handling even if industry capability statements were unclassified. The hardest problem is not merely storing classified data. It is ensuring that generated text, relationship edges, and even “no result” responses do not reveal restricted facts.

A minimum control set would include:

  • source-side authorization rather than reliance on a universal service account;
  • separate indexes or cryptographic namespaces by classification and compartment;
  • purpose- and case-based access restrictions;
  • immutable query and dissemination logs;
  • model, prompt, and connector versioning;
  • controls against exporting restricted snippets into lower-level reports;
  • and independent red-team testing for inference leakage.

Human override

Independent finding: Public summaries emphasize citations, traceability, and ethics review but do not specify a binding human-override rule, required source verification, minimum analyst grade, dual review, or categories of decision for which AI output cannot be used.

Reasoned inference: “Human in the loop” is not a sufficient safeguard unless the human has authority, time, access to the underlying evidence, training to challenge the system, and a documented obligation to record disagreements. An analyst who must process hundreds of machine-generated leads may become a rubber stamp.

Competing interpretations and civil-liberties judgment

The strongest government case

Official claim: TSC operates in a high-volume, time-sensitive environment where missed links can have grave consequences. Its 24-hour center supports positive-match determinations, encounters, notifications, and information sharing across law-enforcement, homeland-security, intelligence, and international partners.

The strongest government argument is therefore:

First, post-9/11 failures were failures of fragmented information. Separate holdings, incompatible formats, and inability to connect identifiers can prevent analysts from seeing that multiple agencies possess pieces of the same threat picture. The central purpose of HSPD-6 and the 2017 NSPM-7 is lawful, accurate, timely integration.

Second, the proposed system is primarily an evidence-finding tool. Federated search, natural-language access, citation retention, and source lineage can make analysts more efficient without authorizing new surveillance or creating an autonomous decision-maker.

Third, federation can be more privacy-protective than bulk consolidation. Records can remain in source systems, with local permissions and ownership, while an authorized analyst receives only responsive results.

Fourth, citations and lineage may improve accountability. Conventional manual work can involve copied text, spreadsheets, and undocumented search paths. A properly engineered system can preserve exactly which records produced a conclusion and make review reproducible.

Fifth, the same tools can surface mitigating information. Similarity analysis need not only find derogatory links. It can locate exculpatory records, identity conflicts, duplicate reports, outdated nominations, or evidence that two similar names belong to different people. PCLOB has specifically urged greater consideration of mitigating information.

Sixth, human analysts remain responsible. The public requirement does not call for automatic watchlisting, detention, investigation opening, or criminal prediction. FBI governance structures and AI Ethics Council review offer mechanisms—at least in principle—to prevent inappropriate use.

Seventh, delaying modernization has risks. Legacy search and manual review can produce missed information, inconsistent citations, slow encounter resolution, and unreviewable analyst work. Accuracy and civil liberties can be harmed by false negatives and poor identity resolution as well as false positives.

The strongest civil-liberties critique

The strongest critique does not depend on claiming that the FBI has already deployed science-fiction “pre-crime.”

First, a virtual superdatabase can be as consequential as a physical one. Federated architecture allows simultaneous discovery across repositories while avoiding the political and legal visibility of formally merging them. An analyst may experience a seamless all-source environment even though each source remains nominally separate.

Second, correlation can turn ordinary associations into investigative suspicion. Shared institutions, travel routes, neighborhoods, family ties, language, devices, charities, religious communities, or protest activity can generate dense relationship graphs without proving unlawful intent. In a threat-screening context, a visual or statistical association may acquire an aura of national-security significance.

Third, the broader mission has expanded. TSC began as a terrorism-screening center but now manages additional threat categories and transnational organized-crime information. The 2017 NSPM-7 annex identifying threat categories is not public, limiting democratic understanding of the full universe of persons or organizations subject to screening architecture.

Fourth, political context matters. The 2025 NSPM-7 and 2026 counterterrorism strategy advocate identifying ideological and organizational networks before violence occurs. Although no record links TSC-AIE to those policies, deploying a broad correlation platform in that environment creates a plausible mission-creep pathway.

Fifth, errors can become self-validating. Once an erroneous identity or weak association leads to more screening, interviews, referrals, or records, future searches find more data about the person. The system may interpret the volume of government attention as independent evidence of relevance.

Sixth, secrecy impedes correction. Individuals often do not know which data, criteria, or associations affected them. PCLOB noted the difficulty of contesting classified watchlisting information and the lack of current TSC transparency reporting.

Seventh, citations do not guarantee truth. An output can accurately cite an erroneous record, duplicate allegation, unreliable source, or legally impermissible item. Provenance answers “where did this come from?” It does not answer “is it true, fair, relevant, or lawful to use?”

Eighth, no public governance artifact is specific to the initiative. No TSC-AIE PIA, impact assessment, AI Ethics Council decision, performance protocol, bias evaluation, access-control design, retention schedule, or redress mechanism was located.

Ninth, market research can still shape institutional direction. An RFI does not deploy technology, but it tells industry which capabilities the government values and can establish a path toward acquisition. Oversight that waits until a classified system is operational may arrive too late to alter its architecture.

Unanswered questions

AddresseeQuestion
FBI contracting officeOne: What substantive changes were made between the March 27 and July 22 RFI attachments, and why was the updated file posted after the response deadline?
FBI contracting officeTwo: Was the response period reopened, and were all prospective sources given equal notice and opportunity to address the revised requirements?
FBI contracting officeThree: How many responses were received, and what business-size, technical, and contract-vehicle characteristics did the market research reveal?
FBI contracting officeFour: Has the FBI decided to cancel, defer, compete, sole-source, prototype, or place the work under an existing contract vehicle?
FBI contracting officeFive: Has any request for proposals, task-order request, BAA call, other-transaction solicitation, or internal development effort been issued under a different title or identifier?
TSC leadershipSix: Which 2017 NSPM-7 threat-actor categories and Threat Screening System datasets are within the contemplated scope?
TSC leadershipSeven: Does the phrase “external systems” include only FBI systems, or also partner-agency, commercial, open-source, international, financial, travel, communications, location, or social-media information?
TSC leadershipEight: Will the tool support watchlist nomination, nomination review, encounter resolution, redress, transnational-organized-crime screening, domestic-terrorism work, or all of these?
TSC leadershipNine: Can a similarity, correlation, or retrieval score ever be used as evidence of threat status, or only as a lead to underlying records?
TSC leadershipTen: Is any person-level future-conduct, violence-risk, radicalization-risk, or recidivism score contemplated now or in a planned phase?
FBI Chief AI Officer and AI Ethics CouncilEleven: Has an AI use case been submitted for ethics review, and what lifecycle stage, risk classification, and prohibited uses were assigned?
FBI Chief AI Officer and AI Ethics CouncilTwelve: What independent test data, error metrics, population-specific performance measures, and red-team exercises will be required before pilot or deployment?
FBI privacy and civil-liberties officialsThirteen: Has a Privacy Threshold Analysis, PIA, civil-liberties impact review, SORN analysis, or records-schedule determination begun?
FBI privacy and civil-liberties officialsFourteen: How will corrections and removals propagate to embeddings, entity clusters, cached summaries, analyst products, and partner disseminations?
FBI security officialsFifteen: How will the federation layer prevent cross-compartment leakage, inference disclosure, overprivileged service accounts, prompt injection, and poisoned source data?
Prospective vendorsSixteen: Will vendors disclose training sources, model architecture, evaluation limitations, update schedules, subcontractors, and government audit rights?
Prospective vendorsSeventeen: Can every generated proposition be reproduced after a model update, and can the government export all data, indexes, lineage, and logs without proprietary lock-in?
DOJ Inspector GeneralEighteen: Will OIG review whether the FBI’s AI congressional-reporting obligations, ethics process, and independent-testing deficiencies were resolved before TSC-related deployment?
GAO and CongressNineteen: Will oversight distinguish information-retrieval models from person-risk prediction and require notice before one is repurposed into the other?
Congress and PCLOBTwenty: Should legislation require public impact summaries, periodic accuracy reporting, protected-activity audits, correction propagation, and an appeal mechanism when AI-derived information contributes to consequential screening?

Bottom-line judgment

Judgment: “Pre-crime” is a misleading description of FBI-TSC-AIE as documented through August 2, 2026.

High-confidence basis:

  1. The only verified procurement stage is a sources-sought RFI.
  2. No public award, prototype, task order, or deployment is established.
  3. The documented predictive requirement concerns locating further relevant information across federated systems.
  4. No public requirement calls for forecasting a person’s future crime, violence, radicalization, or terrorism.
  5. No automated adverse-decision authority is specified.

Partly accurate caution: The label captures a legitimate concern about the direction in which the surrounding architecture could evolve. The FBI separately seeks anticipatory-analysis preparation, alerts, weighted dynamic threat models, and broad all-source correlation. TSC operates in an environment where information can contribute to highly consequential screening and investigative decisions. A federated discovery layer would make person-centered aggregation and network analysis faster and more comprehensive.

Independent conclusion — High confidence: The most accurate present description is:

An unawarded market-research initiative for AI-assisted knowledge management, federated threat-information discovery, identity and identifier correlation, source-linked synthesis, and visualization.

Reasoned future-risk conclusion — Medium confidence: It could become part of a predictive threat-assessment environment if later requirements add person-level scoring, behavioral forecasting, automated alerts tied to individuals, or operational recommendations. None of those additions should be inferred from the present notice. They should trigger a new and public legal, privacy, procurement, accuracy, bias, and civil-liberties review.

Final status: Market research, not “pre-crime”; potentially enabling infrastructure, not proven predictive policing; serious oversight questions, but no verified operational system or selected vendor.