Did Congress fix the problems with Section 702 when it last reauthorized the law?
In 2024, Congress passed the Reforming Intelligence and Securing America Act (RISAA), a bill authored by longtime opponents of Section 702 reform in an attempt to stave off more meaningful changes. While RISAA included some modest reforms relating to backdoor searches, none of them solved the fundamental problem: Section 702 grants the government warrantless access to Americans’ private communications. In any event, most of these reforms merely codified changes to internal agency procedures that the FBI had previously implemented and that had already proven to be insufficient to stop abuse.
As unambitious as RISAA’s requirements were, it emerged within months that the FBI was systematically violating them. In August 2024, Department of Justice overseers discovered that the FBI had been quietly using a querying tool that allowed users to access Americans’ communications without adhering to the procedures in RISAA designed to prevent abuse, such as obtaining attorney or supervisory approval for backdoor searches, recording the reasons for conducting them, and subjecting them to internal audits. It took months for the DOJ to shut down this tool.
This systemic violation of multiple provisions of RISAA, on its own, makes clear that RISAA did not solve the FBI’s compliance problems. It also undermines the claim that RISAA produced a steep decline in the number of backdoor searches the FBI conducts. Those making this claim have pointed to the government’s reported statistics for 2024 and 2025. But because the FBI did not track or count the number of queries performed using this particular querying tool, the reported data for 2024 and 2025 is incomplete, and the total number of queries performed during those years remains unknown. And because the Department of Justice did not audit these queries, we simply do not know the extent or nature of any violations that might have occurred during this period.
How do the current administration’s actions impact concerns about backdoor searches?
The current system of Section 702 oversight relies almost entirely on executive branch self-policing to prevent, detect, and report abuses. Although Congress and the FISA Court also oversee surveillance activities under Section 702, they do not conduct their own audits. They are thus wholly dependent on the DOJ and other agencies that receive Section 702 data to conduct rigorous audits of their own backdoor searches and to report the results promptly, fully, and accurately.
Yet this administration has gutted the main internal oversight mechanisms for Section 702. It dismantled the FBI’s Office of Internal Auditing, established in 2020 to improve compliance with Section 702. It fired all three Democratic appointees on the five-member Privacy and Civil Liberties Oversight Board, thus undermining both its effectiveness and its independence. And it has apparently cowed the DOJ’s Office of the Inspector General into inactivity. Moreover, dozens of courts across the country have admonished the DOJ for providing inaccurate, incomplete, or misleading information. In short, there is little reason to expect the robust internal oversight and faithful reporting that are necessary to deter abuse of Section 702.
What can be done to protect Americans from warrantless government spying?
Bipartisan sponsors have introduced bills in both the Senate and the House of Representatives that would reauthorize Section 702 with reforms to protect Americans’ privacy, including a requirement that the government obtain a warrant or FISA Title I order to access the content of Americans’ communications collected under Section 702. The warrant requirement proposals all include reasonable exceptions designed to accommodate legitimate security needs. For example, no court order would be required in an emergency, if the subject of the search provided consent (e.g., where the purpose of the search is to identify potential victims), or where the search is designed to identify the targets of a cyberattack.
Under current reform proposals, the court order requirement kicks in only when the government seeks to access the contents of a communication. In other words, the government may check first to see whether a particular American’s information actually appears within the Section 702-collected data before applying for a court order. This would ensure that any additional burden on the courts is manageable, and it would allow the government to use U.S. person queries without a court order to rule out particular Americans’ involvement in the activities under investigation.
This commonsense solution has had broad bipartisan support for years. It has been passed twice in the House, and in 2024, it was defeated in the House by a single vote. Polling shows that 76 percent of Americans support a court order requirement for backdoor searches.
Would a warrant requirement harm national security?
The national security value of backdoor searches is modest at best and would not be undermined by a warrant requirement. The government has provided multiple examples in which surveillance of foreign targets under Section 702 provided key information about cyberattacks, espionage, and fentanyl trafficking. By contrast, it has cited very few examples in which backdoor searches have been useful.
After a thorough review of all the relevant classified and unclassified information, the Privacy and Civil Liberties Oversight Board found in its 2023 report that “there was little justification provided to the Board on the relative value of the close to 5 million [U.S. person queries] conducted by the FBI from 2019 to 2022.” In the handful of instances in which backdoor searches did add value, it appeared that the government could have obtained a warrant, gotten the consent of the subject of the search, or invoked the emergency exception — a point confirmed by the chair of the board. A warrant requirement with reasonable exceptions would protect Americans’ rights while preserving the core national security value of Section 702: surveillance of foreign targets.
What happens if Congress doesn’t reauthorize Section 702 by April 20?
Although the statute will expire on April 20, Section 702 surveillance operates under yearlong certifications approved by the FISA Court. The law makes clear that these certifications remain valid until their expiration date, even if the underlying statute expires. Based on the date of the last publicly available certification, the government was scheduled to renew its certifications in March of this year, which would lock in Section 702 surveillance authority until March 2027. Those renewal proceedings have not yet been declassified.
Some supporters of a straight reauthorization have nonetheless expressed concerns that companies that provide communications services might refuse to turn over targets’ communications to the government if the underlying law has expired. However, companies do not choose whether to assist the government with Section 702 surveillance. They are served with directives, and if they fail to comply with a valid directive, they face fines of $250,000 per day. The FISA Court can compel compliance, as it did in 2008 when a company refused to cooperate during a brief lapse in the statutory authority.
Congress has ample time to consider and pass reforms. Failure to do so would deny Americans long-overdue protections and facilitate continued warrantless domestic spying by the executive branch.