In the summer of 2019 I sat at a kitchen table in someone else's country and told a friend he was being paranoid.
He was working through the DS-160 — the U.S. nonimmigrant visa application — and had reached the box that was new that year, asking for every social media handle he had used in the previous five years. He wanted to delete his Twitter account before answering. Not because there was anything in it — because there were seven years of it, he could not remember all of it, and he disliked the idea of a stranger meeting a version of him assembled from his worst jokes.
I made the confident argument. The form asks for handles, I said, not opinions. Nobody is going to read a decade of your timeline — consulates are drowning as it is. And deleting looks worse than posting. Answer honestly, you'll be fine.
He deleted it anyway. He got the visa. For years I filed that under "I was right and he was lucky."
I was not right. I won the argument in the room and have been losing it ever since, one announcement at a time — and the one that settled it took effect on March 30 of this year.
What changed on March 30 — and what has been true since 2019
The five-year list of handles is not new. Almost every headline about this implied that it was — and I nearly wrote one of them.
Since May 2019 the State Department has collected social media identifiers from nearly all foreigners applying for visas — some 15 million travelers a year, by the Brennan Center's count at the time — requiring applicants to register with the government all social media handles used in the preceding five years, as the Knight First Amendment Institute describes it. That box has been on the form for seven years; my friend answered its first edition.
What changed is the reading, and the openness.
In June 2025 the Department told student and exchange applicants — F, M and J — to set every profile to "public," on the framing that a U.S. visa is a privilege, not a right. In December it moved to expand its online presence review to all H-1B and H-4 applicants. Then, effective March 30, 2026, a further set of applicants "regardless of age" must also now change their privacy settings to "public" on all platforms: fiancé(e)s (K-1, K-2, K-3); domestic workers (A-3, C-3, G-5); trainees (H-3 and H-4); cultural and religious visitors (Q, R-1, R-2); and — read that one twice — "Informant, Witness, and Victims of Crimes" (S, T and U).
Immigration analysts at Boundless counted it as the third — and largest — to date, adding fourteen categories, and noted something that has stayed quiet: "No official guidance specifies an end date for keeping profiles public." Not a rule with a duration — an instruction with no finish line, and practitioners advising visibility until a decision arrives.
Two consequences get merged constantly. Omitting social media information on the form, the announcement says, "could lead to visa denial and ineligibility for future visas" — note the could. Failing to make a profile public is not described anywhere I could find as a standalone ground for refusal.
Everything hinges on one word, and the word is "public"
Handing your handles to a consular officer is a disclosure to a government. Setting your profiles to public is a disclosure to everyone.
The Electronic Frontier Foundation put it plainly: making private accounts public exposes troves of sensitive information to the entire internet, not just the U.S. government — identity thieves, foreign governments, current and prospective employers, anyone who looks. An applicant from a country with an unhappy security service is told, as a condition of attending a daughter's graduation, to open the archive to that service too. And the archive does not close afterward: the handles are saved indefinitely in government databases, the Brennan Center notes. A handle is a key, handed to a filing system that never forgets.
The behavioral effect arrived immediately, and needed no machine. Students interviewed by the Christian Science Monitor described deleting accounts and rewriting themselves; one Nigerian student said it felt like someone is watching my every move. Researchers writing in The Conversation argue the directive turns social media feeds into political documents — a strange thing to do to a photo album.
The standard your posts are read against
The Bureau of Consular Affairs has said for years that every visa decision is a national security decision affecting individual Americans. That sentence sits on the archived 2017–2021 State Department site — written during the first Trump administration — and I quote it precisely because it is old. The slogan is not the new thing. The machinery underneath it is.
Internal guidance reported by Time directed officers to identify applicants who bear hostile attitudes towards our citizens, culture, government, institutions, or founding principles, and to weigh whether the posts undermine their credibility. Separately — a different agency, different job — U.S. Citizenship and Immigration Services said in August 2025 that anti-American activity would be an overwhelmingly negative factor in benefit adjudications inside the country.
Now hold that against what happens when the answer is no. In Department of State v. Muñoz (2024), the Supreme Court concluded that a U.S. citizen and her noncitizen spouse had no access to judicial review of a consular officer's denial of an immigrant visa. In fairness, the American Immigration Council advisory that says so exists to argue Muñoz is not the end of consular accountability: review is narrow, not zero. And Doc Society v. Blinken, the direct challenge to the handle requirement, never reached the merits — the D.C. Circuit held on June 27, 2025 that the plaintiffs lacked standing, and the case was voluntarily dismissed that December. No court has said the requirement is constitutional. None has said it isn't.
An expanding standard, a permanent corpus, and almost no way to ask why.
Now let me argue against my own headline
The strongest objection comes from someone who has sat on the other side of the glass. Peter Van Buren, a former Foreign Service officer, wrote in The American Conservative that the expansion of the social media check is more for show than impact at this point. His argument is logistics, not ideology: officers have minutes per applicant, not hours. "Artificial intelligence may someday be the answer, but not today," he wrote — the check stays useful as a targeted follow-up once something else has raised a flag, but "it is impractical on a mass scale under current circumstances."
I think he is largely right about today. So let me be honest about how thin the tooling record is.
Axios reports that State, with the Justice Department and DHS, launched a "Catch and Revoke" initiative that would use AI to review student visa holders' social media — reporting about a plan, not a published policy, and aimed at people already here rather than at new applicants. The Brennan Center calls it "AI-enabled." In October 2025, three labor unions and EFF sued State and Homeland Security; the lawsuit argues the program uses "AI and other automated technologies" to punish disfavored viewpoints — allegations in a complaint, not findings. The Department answered that the United States is under no obligation to allow foreign aliens to come to our country, commit acts of hate or incite violence.
Does any of it work? Nobody can tell you. The last serious audit is nine years old: in February 2017 the DHS inspector general reported that the department's social media screening pilots lack criteria for measuring performance. Read that carefully — it does not say the pilots failed. It says nobody built a way to know. The program has grown by orders of magnitude since, with no public measurement of whether it works.
So where does that leave me? The Brennan Center's researchers concede Van Buren's premise and take it somewhere worse. Tracking every digital move of tens of millions of people would demand surveillance infrastructure bigger than anything that currently exists, they write, and scoring beliefs is "poorly defined, highly subjective, and empirically error-prone." Then the line that reorganized my thinking: a system doesn't need to watch everyone to control them — it only needs people to think it can.
That is the honest version of my thesis. Not that a machine currently scores your tone — that the collection is universal, the retention indefinite, the standard now reaches attitudes, the profiles have been ordered open — and the reading capability is the only missing piece, and the cheapest to buy.
North of the border, the automation points the other way
The comparison that nags at me sits four hours north of Detroit. Canada has been automating its visa processing for longer, and far more openly, than the United States has — and aimed it the other way.
Start with collection. Canadian screening is risk-based and multi-step: the Canada Border Services Agency runs in-depth open source checks — the government's own example is "media and social media presence" — during comprehensive screening, on files referred to it. Not every application goes through every step, and an inadmissibility recommendation "must meet the legal threshold of reasonable grounds to believe." A referral and a threshold, not a universal form field. Canadian practitioners write that as of 2026, Immigration, Refugees and Citizenship Canada does not generally require you to list all of your social media handles in a standard application, though publicly visible material may still be compared against what you declared — and "does not generally" is doing work there.
Now the automation, which is the surprising part. IRCC has triaged overseas temporary resident visa applications with advanced analytics since 2018 — China and India first, everywhere else from January 2022 — and by the department's own Question Period briefing note, those models sort incoming files and automatically approve the eligibility portion of certain straightforward applications. No IRCC system, the note says, can refuse an application or recommend a refusal; the models exist "never to automatically refuse applicants." That is the department's account of itself, not an audit — but the design intent is on the record.
Canada automates the yes. The American argument is about automating the no. Once you see that asymmetry you cannot unsee it.
There is also a paperwork regime the United States has no match for. Under the Treasury Board's Directive on Automated Decision-Making, a federal institution must publish an algorithmic impact assessment prior to the production of any automated decision system — and the definition reaches any technology that assists human judgment, not only one that replaces it. You can download IRCC's Algorithmic Impact Assessment for the triage system today, alongside a 2018 peer review the page itself concedes "does not cover all considerations related to the Directive."
Which is where I stop flattering Canada.
Publishing it has not made the system legible to the people inside it. University of Toronto researchers, in a June 2026 preprint, found that applicants lack the interpretive resources to make sense of their outcomes. New Canadian Media found the same gap from the practitioner side: the sorting happens before a human officer ever opens the file, and Yameena Ansari, managing lawyer at Ansari Law, told them there is no formal mechanism to challenge a triage classification. IRCC's answer there was that its tools are "primarily rules-based" and do not make or alter decisions. The courts have blessed the practice too: as immigration lawyer Steven Meurrens notes, the Federal Court held in 2024 that algorithmic processing is not in of itself a breach of procedural fairness. Canada's safeguards are administrative, not judicial.
And Canada is tightening, not loosening: the Canadian Civil Liberties Association warns that Bill C-2 might broaden information-sharing with the United States, alongside powers to share sensitive immigration data and demand customer information without judicial approval. Those are advocacy characterizations of a bill, not enacted law — but anyone holding Canada up as a sanctuary should read them first. The difference is not virtue; it is where the automation points, and how much of it gets written down.
Just imagine your file in 2031
Picture a renewal interview five years out.
The handles you surrendered in 2026 are still on file — kept indefinitely — along with everything you have added since. The officer does not scroll. The officer opens a summary, generated and tidy, that renders eleven years of your posting in four sentences and attaches a disposition. Nobody in the room wrote those sentences, and nobody can fully explain them. But they are in the file, and the file is what the next officer reads.
You are refused, and told essentially nothing about why. You never learn that the summary flagged a reply you left on a friend's post, in a language the model handles poorly, during an election week at home.
Then the second-order effects, likelier and more depressing than the dystopian ones. A service industry appears — feed hygiene consultancies, pre-application audits, a going rate to comb eleven years of you for anything that reads badly against a standard nobody has published. And the trap closes, because a scrubbed feed is itself a signal: an account from a country in political crisis containing nothing but recipes and airport photos looks, to any pattern-matcher, exactly like someone who cleaned up.
And the quiet version, requiring no new technology: a generation of capable people never says anything in public about its own government, in its own language, because a consulate is in the reading audience.
What the researchers and the lawyers keep landing on
What strikes me is how little the concern tracks ideology: the critique of the machinery comes from the civil-liberties left, the critique of its competence from a conservative former diplomat, and both are describing the same object.
Scholars at the Knight First Amendment Institute and the Brennan Center argued years ago that this is not only a foreigner's problem: conditioning the ability of foreign documentary filmmakers to travel here on surveillance of their accounts burdens the Americans who wanted to hear from them. Your speech is on the other end of that conversation.
The pushback is getting more institutional, too. On February 9, 2026, the Brennan Center, the Knight Institute and the Electronic Privacy Information Center submitted a comment urging the Department of Homeland Security to abandon a proposal to collect social media identifiers from the roughly 14.5 million foreign travelers a year who use the visa-waiver system — a different and much larger population.
And from the legal academy, the most useful idea here is also the dullest. Writing in the Columbia Law Review, Jake Stuebner proposes amending the Immigration and Nationality Act so consular officers must give factual and timely explanations for visa denials. Not a ban on vetting. Not a right of appeal. A reason. Every automation nightmare above shrinks the moment somebody has to write down why.
So what do you actually do with this?
(I am not your lawyer, and for anything consequential you should have one.)
List every handle, including the dead ones — and do not panic-delete. The form covers platforms used in the last five years, you certify your answers are true and correct, and the government's own language is that an omission could lead to denial and future ineligibility. A forgotten account is a worse problem than an embarrassing one, and scrubbing one you already declared creates its own credibility problem.
Before you switch anything to public, do a personal-data pass, not a political one. Old posts leak home addresses, employers, children's schools and travel dates to the entire internet, not just a consulate. Lock down what identifies you physically before you open what identifies you politically.
Ask when you can close it again, and expect no clean answer. There is no published end date — decide with your lawyer, and write down the date you decided. The review itself may also result in delays in appointments.
If you are American, stop treating this as somebody else's file. The person who cannot come is your in-law, your collaborator, your conference speaker — and the federal comment dockets civil society files into are open to you too.
What I should have told him
Seven years on, the honest answer at that kitchen table was not "you're being paranoid." It was: I don't know, and neither does anyone else, and that is the actual problem.
He was not paranoid. He was early.
What I got wrong was assuming surveillance must be real to work. It doesn't. The corpus is universal, the retention permanent, the standard now reaches attitudes, the profiles have been ordered open — and the reading capability is the only missing component, the one that gets cheaper every year while removing the others takes political will.
Which is why the fix is neither glamorous nor technological. It is Canada's boring paperwork, roughly: publish the impact assessment before the system runs, aim the automation at approving straightforward files rather than refusing ambiguous ones, keep a referral threshold instead of a universal dragnet — and make somebody write down the reason. Those are procurement rules and administrative law. Any government could adopt them next year; ours could.
I lost that argument in 2019 because I could not imagine anyone bothering to read all of it. The lesson, as I see it, is that "nobody would bother" was never a safeguard. It was a temporary shortage of capacity, and shortages end.
The HAIA Foundation works the unglamorous end of this — the rules deciding how automated systems get to read us, and who has to explain the answer afterward. If that is your kind of thing, subscribe — and forward this to whoever in your family is filling in a form this month.




