The U.S. proposal of December 10, 2025, to expand the collection of social media data for ESTA applicants raises questions that go beyond the technical or procedural dimension of border control. The article examines how the use of online expressions as inputs for institutional decision-making systems redefines the boundary between national security and fundamental rights. Through a dialogue between regulatory developments, research on intelligent systems, and science-fiction imaginaries, the text explores the individual and social consequences of transforming expression into evaluable data: from changes in self-perception and behavior to the alteration of social agency. The contribution proposes a non-ideological reading of the issue, acknowledging the legitimacy of security objectives while highlighting the need for transparency, proportionality, and contestability when systems based on personal data participate in decisions that affect access to fundamental experiences.
When Opinion Becomes a Border
Year
2025
Reference Lab
Innovation By Design
The U.S. Proposal on Social Media Control for ESTA and the Consequences of Using Opinion Data
On December 10, 2025, in the United States, a proposal was published that could redefine how people are assessed before crossing a border. The measure provides for an expansion of the data required from travelers applying for ESTA, including social media history from the previous five years, together with other personal data such as email addresses, phone numbers, and contact information. [1] At first glance, the proposal is presented as an extension of security checks. However, when examined more closely, it touches on a much deeper issue: what happens when thought, opinion, and individual expression become data to be analyzed in order to decide whether a person may access a country, an experience, or a portion of their life?
ESTA (Electronic System for Travel Authorization) is an electronic authorization system that allows citizens of certain countries to enter the United States without a visa for short stays of up to 90 days, for tourism or business. It was created as a simplification tool: a fast, digital alternative to the traditional visa, based on a limited set of information provided online prior to departure. The December 2025 proposal profoundly alters this logic. It is no longer merely a matter of verifying personal data, travel documents, or evident prior records, but of analyzing the applicant’s digital presence over time, including what they have written, shared, commented on, or even simply left visible on social networks. [1] This shift is crucial: the border is no longer only physical or administrative, but becomes cognitive and behavioral. The proposal, attributed to U.S. Customs and Border Protection (CBP) / the Department of Homeland Security (DHS), would introduce the scanning of social media as a “mandatory data element”: ESTA applicants would be required to provide their social media accounts from the past five years, along with the collection of additional “high-value data fields,” including email addresses from the last ten years, phone numbers from the last five years, and data and details concerning family members. [1] The proposal is not automatically in force: it is a proposal undergoing a formal process that includes a 60-day public consultation period. [2]
For those intending to enter the United States with a visa, the requirement to make one’s social media presence accessible is not a recent innovation. Since 2019, procedures for both temporary and permanent visa applications have required applicants to declare the accounts used on major digital platforms during the previous five years, with limited exceptions for specific institutional categories. From the outset, U.S. authorities clarified that applicants’ online activity is considered an integral part of the entry evaluation process, alongside other biographical elements such as employment history, travel experiences, or family ties. According to the official position, the inclusion of social media aims to strengthen national security screening without becoming a generalized obstacle to international mobility. This orientation has also been confirmed at the legal level: in 2023, a federal court decision deemed the use of information from social networks legitimate within visa issuance procedures. Challenges raised by certain civil society organizations, who warned of a potential chilling effect on the online expression of foreign artists, researchers, and cultural professionals wishing to travel to the United States, were not upheld. [3]
In contemporary digital culture, we are accustomed to considering personal data as something “technical”: name, address, phone number. Yet an increasingly significant portion of the data we produce concerns what we think, prefer, and believe. Posts, likes, comments, shared memes, prolonged silences, online relationships all of this falls within what can be defined as “expression.” It is not merely information about us; it is a manifestation of identity, often situated in context, time, irony, and contradiction. Treating these expressions as inputs for an institutional evaluation system entails a delicate shift: opinion is no longer only a right, but becomes a signal, a signal that can be interpreted, weighted, correlated, and ultimately used to make decisions with real consequences. Online expressions of thought and preference persist over time as permanent signifiers, analyzable and usable by anyone with access to them. [4–5]
In a democracy, the boundary between protecting security and safeguarding freedom of expression is always fragile. The proposal raises a question that goes beyond the specific case of the United States: to what extent can a state legitimately evaluate a person based on opinions expressed online? The issue is not (only) the presence of illegal or violent content, which can already be prosecuted today. The issue lies in the gray area where interpretation comes into play: political criticism, sarcasm, controversial positions, differing cultural contexts. When access to a fundamental service, such as entry into a country, depends on this type of analysis, a judgment on opinion is effectively introduced, even if it is never openly declared. And this is precisely the type of dynamic that democratic systems should avoid, or at the very least make extremely transparent and contestable.
Thought and Preference as Personal Data
National Security and Expression Data
However, it is necessary to avoid oversimplification. Interpreting the use of online expressions solely as a judgment on opinion risks obscuring a central element: the responsibility of states to ensure national security. Entry authorization systems such as ESTA exist precisely for this purpose to prevent concrete risks before they materialize, reducing the need for later and more invasive interventions. From this perspective, the analysis of digital behavior is not introduced as an ideological instrument, but as an attempt to fill an informational gap in a context where threats are no longer exclusively territorial, nor always visible through traditional channels. Extremist, criminal, or terrorist networks also operate online; radicalization, coordination, and propaganda often occur through public or semi-public digital platforms. Completely ignoring these traces would mean relinquishing a significant portion of the available informational landscape.
The problem, therefore, is not the existence of a security need, nor the use of data per se. The critical point emerges when tools designed to intercept risk signals are extended to forms of expression that are ambiguous, contextual, or not directly attributable to concrete threats. It is in this gap that the boundary between prevention and judgment becomes blurred. From a design and policy perspective, the issue is not whether to use expression data, but how (under what limits and with what safeguards). Targeted identification of specific, verifiable, and contextualized risk indicators is one thing; extensive and opaque use of opinions, preferences, or social networks as proxies for general trustworthiness is another. In the absence of clear criteria, expression risks being read not as a signal to be interpreted cautiously, but as an indication of potential guilt.
This is where the tension becomes structural: security requires anticipation, while democratic rights require proportionality, contestability, and the presumption of innocence. Intelligent systems amplify this tension by transforming weak signals into large-scale operational decisions. Automated analysis may reduce uncertainty, but it can also increase the risk of systemic errors, cultural bias, and out-of-context interpretations. Recognizing the legitimacy of security objectives does not mean accepting any means. On the contrary, it implies that the more powerful a system is in preventing risk, the more rigorously it must delimit what it considers relevant. Without such delimitation, prevention can slide into a form of diffuse control, where opinion is not punished as such, but becomes a permanent risk variable.
Using science fiction not as a sensational metaphor but as a tool for analyzing long-term effects, we can consider the futures depicted by science-fiction authors as representations of prevailing social fears and hopes. [6] Science fiction has often anticipated dynamics that we now recognize as concrete design and policy possibilities, not because it predicts the future deterministically, but because it makes visible latent tensions between technology, power, and society. In the case of controlling individual expression through digital data, many speculative narratives converge on a key point: when visibility becomes mandatory, expression ceases to be free and becomes performative. [6]
In the film The Circle (2017), [7] based on Dave Eggers’ novel, power is not exercised openly by the state, but by a large technology platform that progressively assumes quasi-governmental functions. In this world, total transparency is presented as a moral value and as a requirement for belonging. People are not punished for what they explicitly say, but are pressured for what they do not share. Non-exposure, silence, and opacity become suspicious signals. Expression is no longer a choice; it becomes a social duty. In the novel, more than in the film, a proto-institutional logic emerges strongly: the boundary between platform and state dissolves. Opinions, preferences, and online behaviors are used not only to personalize services, but to evaluate individual reliability. In this scenario, the absence of data equates to a lack of transparency, and lack of transparency equates to guilt. This is a crucial conceptual shift, because it introduces an idea that also recurs in real-world policies: not being visible becomes a problem. This dynamic reappears, with more explicitly political tones, in Ten Years (2015), [8] an anthology set in a near-future Hong Kong where the progressive erosion of civil liberties also passes through the control of public expression. Here there is no benevolent platform, but an authoritarian state that monitors and punishes dissent. Words, symbolic gestures, and positions become traceable and sanctionable. Expression is no longer a space for debate, but a source of risk.
In Black Mirror – Hated in the Nation, [9] the mechanism shifts again: evaluation is no longer individual and continuous, but collective and episodic. A government technological infrastructure analyzes social media activity at scale, and online hatred becomes the trigger for real and irreversible consequences. Responsibility appears distributed (“the crowd decides”) but in reality it is the infrastructure that makes the translation of expression into punishment possible. Public opinion becomes a weapon only because a system exists that collects it, amplifies it, and executes it.
This notion of expression as evidence appears even more explicitly in Little Brother [10] by Cory Doctorow. After a terrorist attack, the government uses mass surveillance of digital behavior to identify suspects and “potential enemies.” Here online activity is no longer merely a signal, but evidence. Messages, connections, and digital traces are interpreted as indicators of loyalty or threat. The novel highlights a fundamental point: when context is lost, expression easily becomes incriminating.
A further step is represented by the videogame Watch Dogs, [11] where an entire city is governed by an urban operating system that integrates personal data, social networks, consumption, and behaviors to assign risk levels and enable preventive interventions. Here there is no longer any distinction between security, governance, and service: everything converges into a single algorithmic system that classifies people. The individual is judged not only for what they say, but for what they do, buy, frequent, and traverse. It is precisely here that the discussion expands beyond social media. If today we speak of opinions, preferences, and online expression, the next question is inevitable: what happens when consumption and everyday behavior also become evaluation criteria?
In QualityLand, [12] the answer is taken to an extreme through satire: citizens are classified by an official score that determines rights, opportunities, and relationships. The score derives not only from what one says, but also from what one buys, how one behaves, and what consumption choices one makes. It is a caricature, but a structurally precise one: it shows how identity is reduced to a synthetic index, apparently objective but deeply normative. Many of these narratives draw inspiration, more or less directly, from the idea of a government social credit score, in which citizens are evaluated based on behaviors, relationships, and public expressions. Even if not tied to a specific work of fiction, this model has strongly influenced contemporary dystopian imaginaries. The fundamental difference between these scenarios and liberal democracies lies less in the tools themselves than in the degree of transparency, contestability, and proportionality.
Science fiction as a whole does not tell us that these futures are inevitable. But it does reveal a recurring trajectory: when expression, behavior, and consumption are transformed into evaluable data, power no longer needs to prohibit, it only needs to classify. And when classification determines access to fundamental experiences (traveling, participating, belonging), opinion ceases to be merely a form of freedom and becomes a condition of access. These dystopian narratives show what happens when public expression is constantly observed and evaluated: people change. The first transformation concerns self-perception. If I know that my content may be read to decide whether I am “eligible” to enter a country, I begin to ask: who am I in my data? Identity is no longer what I feel myself to be, but what a system can infer about me. A kind of distorted mirror emerges: do I recognize myself in the algorithmic representation, or do I try to correct it? The second transformation concerns behavior. Awareness of judgment generates self-censorship: I avoid certain topics, moderate my language, give up irony, delete past posts not because they are wrong, but because the risk of misinterpretation is too high. Finally, interpersonal relationships change. If my network also falls within the scope of observation, I begin to consider connections not only as social relationships, but as potential sources of reputational risk. [13]
When these mechanisms no longer affect only individuals but become systemic, the impact is social. The possibility of being judged based on online expression alters social agency (what people feel able to do, say, and claim in the public sphere). The most likely consequence is not an explosion of conflict, but its opposite: flattening. Less visible dissent, less experimentation, less expressive plurality not because society is more in agreement, but because the cost of disagreement becomes opaque and potentially high. [13]
Consequences for the Individual and for Society
Critical Nodes: When Experience Depends on Opinion
The proposal does not merely expand a set of required data; it touches on deeper issues concerning the relationship between the individual, personal information, and decision-making systems. In particular, it creates tension in how people construct and recognize their identity, how they access services and experiences, and how they are judged within increasingly automated systems.
One of the first effects concerns self-mirroring in data. When personal information is collected, processed, and returned in the form of evaluations or decisions, individuals tend to recognize themselves (or are forced to recognize themselves) in their digital representation. Identity is no longer solely an internal or relational process, but becomes something shaped through data produced and interpreted by the system. The implicit question is no longer “Who am I?” but “Who do I appear to be in my data?” In this gap, a deep tension arises: the subject may lose control over their self-narrative, while the system assumes an active role in defining what is considered acceptable, coherent, or desirable.
Closely linked to this identity dimension is the issue of consent or denial of access to services. Here, the service is not an app or digital platform, but entry into a country, the ability to travel, work, or participate in a life experience. When access is mediated by the analysis of personal data, consent ceases to be a neutral act: it becomes a condition for not being excluded. The choice is not truly free, because refusal to provide information may translate into the loss of concrete opportunities. This shifts decision-making power from the subject to the system, transforming personal information into a kind of invisible toll.
Another critical node concerns the alteration of judgment risk. Systems that process personal data, especially when supported by automated or algorithmic processes, may be unable to fully grasp context, irony, temporal change, or the ambiguities of human expression. Content may be misinterpreted, connections overestimated, patterns mistaken for intent. In such cases, the error does not remain confined within the system: it produces real effects, often disproportionate to the cause. The risk is not only that of an incorrect judgment, but of a judgment that cannot easily be understood or contested.
This dynamic directly affects quality of life. When relevant decisions are made based on interpretations of personal data, even a simple opinion can result in the loss of an opportunity: a denied trip, a postponed experience, a broken relational possibility. Daily life becomes conditioned by opaque mechanisms that operate upstream of individual choices. People do not only modify their digital behaviors; they also reorient expectations, desires, and life planning, often preemptively.
Finally, the issue of awareness and control over data emerges strongly. Who has access to the collected information? Where is it stored? For how long? With what possibilities for verification or objection? The absence of clear answers to these questions generates a loss of trust in systems and a widespread sense of exposure. This is not merely a matter of privacy in the narrow sense, but of informational asymmetry: the system “knows” a great deal about the individual, while the individual knows little about how the system functions.
Taken together, these issues show that the use of personal data is never neutral. Every choice concerning the collection, processing, and use of information contributes to redefining the boundaries of individual action and social participation. It is precisely in this space, between opportunity and consequence, that the responsibility of intelligent systems and the institutions that adopt them comes into play.
Although the proposal is American, for a European reader it is impossible not to compare it with the EU regulatory framework. The GDPR, with its principles of minimization, transparency, and purpose limitation, makes immediately evident the tensions inherent in a system that collects large quantities of expressive data for such a consequential decision. Even more delicate is the issue of artificial intelligence. It is difficult to imagine that millions of social media profiles would be analyzed manually. If automated systems are involved, well-known problems arise: bias, contextual errors, inability to understand sarcasm, cultural ambiguity, and language evolution. The European AI Act addresses precisely these risks when it refers to systems that “judge” people in high-impact contexts. Even if not directly applicable to the U.S., it clearly shows that the issue is not technological, but political and cultural.
The proposal of December 10, 2025, is still under discussion and may be modified or scaled back. But its primary value is symbolic: it makes explicit a change that is already underway. [2] The question is not only whether it is right or wrong to collect social media data. The question is more radical: do we want to live in systems in which personal expression becomes a prerequisite for access, rather than solely a right? If opinion becomes a border, then freedom of expression does not disappear; it changes form. And understanding this transformation is perhaps the true challenge of contemporary intelligent systems.
Conclusion: An Open Question
References
- [1] Federal Register Vol. 90, No. 235. 10/12/2025. Retrieved from https://www.govinfo.gov/content/pkg/FR-2025-12-10/pdf/2025-22463.pdf
- [2] S. Bhaimiya, U.S. to mandate checks of some tourists’ social media history from past 5 years. CNBC, 10/12/2025. Retrieved from https://www.cnbc.com/2025/12/10/us-to-inspect-tourists-social-media-history-from-past-5-years-.html
- [3] A. Migliorisi, Viaggi negli Usa, che cosa cambia con il controllo dei social degli ultimi 5 anni. Il Sole 24 Ore, 11/12/2025. Retrieved from https://www.ilsole24ore.com/art/viaggi-usa-che-cosa-cambia-il-controllo-social-ultimi-5-anni-AIVdZ6L
- [4] M. Pillan, L. Varisco, and M. Bertolo, Facing Digital Dystopias: A Discussion about Responsibility in the Design of Smart Products, Proceedings of the Conference on Design and Semantics of Form and Movement – Sense and Sensitivity, DeSForM 2017. InTech, Oct. 18, 2017. doi: 10.5772/intechopen.71121.
- [5] L. Varisco, Personal Interaction Design: introducing in the design process the discussion on the consequences of the use of personal information. PhD thesis, Politecnico di Milano, Milan (Italy), 2019. https://hdl.handle.net/20.500.14242/206264
[6] Shapiro A. N., The Paradox of Foreseeing the Future. 2016. Retrieved from http://www.al¬an-shapiro.com/the-paradox-of-foreseeing-the-future-by-alan-n-shapiro/ - [7] Ponsoldt, J. (Director). The Circle [Film]. 2017. Image Nation.
- [8] J. Au, K. Chow, Z. Kwok, K. Ng, and F. Wong (Directors). Ten Years [Film]. 2015.Ten Years Studio.
- [9] J. Hawes (Director). Black Mirror – Hated in the Nation [Episode]. 2016. House of Tomorrow.
- [10] C. Doctorow. Little Brother. 2008. Tom Doherty Associates.
- [11] J. Morin. Watch Dogs [Videogame]. 2014. Ubisoft.
- [12] M. Kling. QualityLand. 2017. Ullstein.
- [13] L. Varisco, Going beyond the problem of privacy: individual and social impacts of the use of personal information in connected services, 2022 https://cumulusroma2020.org/proceedings/