Skip to content

PAN Lab example

Cleveland State remote proctoring

A camera in the bedroom and a flag that lands by skin tone

A university requires students to pan their webcam around their home before an online exam; proctoring software then flags suspected cheating. Modeled on a deployment where a federal court held the room scan an unreasonable search, and peer-reviewed measurement found more flags for darker-skinned and Black students with no more actual cheating. The integrity problem is real; the surveillance is not a free default. So watch the two costs the tool's flag count hides: the rights cost of a camera in a home, and a burden of suspicion distributed by skin tone.

Stylized model of a documented deploymentEducation AI

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Proctoring-surveillance-class with two established costs network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    Two things are drawn that the template folded away. The pre-exam sweep of the room is its own inbound source, because it is what the ruling was about: it is not watching an exam, it is collecting whatever is in a room before the exam starts, and it is the only input here taken from somewhere the institution has no other claim on. And the external function is split in two, because two very different things exist. The internal proportionality review could have run before any exam and did not, so it stays empty. The court did run, and is drawn present, at a low level - a real check that returned a real answer. Holding both is the point: the check that worked was reachable only by a student willing to litigate, arrived years later, and reaches one practice at one institution. A modest workload against very limited capacity for an exam cohort against instructors reviewing flags alongside teaching.

  • baseline

    This models the proctoring-surveillance pattern documented in the case file - not a reconstruction of the actual system. A public university required a pre-exam webcam room scan of students' homes and used remote-proctoring software to flag suspected cheating. A federal court held the room scan an unreasonable Fourth Amendment search (a decided ruling, so its holding is drawn as the finding it is), and peer-reviewed measurement found more face-detection failures, red flags, and higher priority scores for darker-skinned and Black students with no corresponding difference in actual cheating.

  • baseline

    The two costs are independently established and drawn as the two latent checks. The demographic burden is the empty independent model check: the flag-rate-by-group audit that would surface the disparity before flags become accusations - the disparity is a recorded external peer-reviewed finding, never computed here, and a flag is an accusation the student must answer, so a disparate flag rate with equal innocence is a disparate burden of suspicion. The disparity's visual source rides the privacy-sensitive record-to-model feed.

  • assumed

    The rights cost is the empty oversight check: the proportionality review weighing the invasiveness of the surveillance (a room scan of a home) against the integrity problem, and whether a less invasive means would do. A court supplied this after the fact, holding the room scan an unreasonable search - so surveillance-based integrity AI is not a free default; it is a decision with a rights dimension a court can rule on regardless of the integrity goal, and the proportionality is owed before the surveillance is imposed. The home-scan recording is drawn privacy-sensitive on both the model-to-record and record-to-model pathways.

  • assumed

    No student outcome is modeled here. This Lab reads institutional propagation only, and the students being watched are boundary-only. The room-scan ruling, the demographic flag disparity, and the proportionality question live in the case file, and are never computed from anything in this diagram.

What this example does not show

  • No student outcome is modeled. The Lab reads institutional propagation only; the students being watched are boundary-only, and the room-scan ruling, the demographic flag disparity, and the proportionality question live in the case file, never computed on this diagram.
  • The ruling is a decided federal decision, so its holding (the room scan was an unreasonable search) is stated as the finding it is; the demographic flag disparity is a peer-reviewed measurement drawn as a recorded external finding, not a computed harm, and the flag-rate-by-group audit and the proportionality review are drawn as two latent checks.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • A public university required students to pan their webcam around their home before an online exam, using remote-proctoring software that flags suspected cheating from the video. A federal court held that the pre-exam room scan was an unreasonable search under the Fourth Amendment — a first-of-its-kind ruling that a routine proctoring practice violated a student's constitutional rights in their own home. Separately, peer-reviewed measurement of automated proctoring found the software produced more face-detection failures, more red flags, and higher priority scores for darker-skinned and Black students, with no corresponding difference in actual cheating. The deployment is the education domain's clearest case of surveillance-based integrity AI whose costs — a rights violation and a demographic burden of suspicion — are each independently established.

    empirical
    • Regulatory Ogletree v. Cleveland State University, No. 1:21-cv-00500 (N.D. Ohio, August 22, 2022); via Higher Ed Dive and Future of Privacy Forum analyses. https://fpf.org/blog/federal-court-deems-universitys-use-of-room-scans-within-the-home-unconstitutional/
    • Peer-reviewed Yoder-Himes, D.R., Asif, A., Kinney, K., et al. (2022). Racial, skin tone, and sex disparities in automated proctoring software. Frontiers in Education, 7, 881449. https://doi.org/10.3389/feduc.2022.881449 https://www.frontiersin.org/journals/education/articles/10.3389/feduc.2022.881449/full
  • The lesson the case carries is that surveillance-based integrity AI is not a free default: it carries a rights cost that can be independently adjudicated and a demographic burden that can be measured, and both are owed a reckoning before the surveillance is imposed, not after a court or an audit finds the harm. A room scan of a student's home was held to be an unreasonable search, so the surveillance has a rights dimension a court can rule on regardless of the integrity goal. And because the software flags darker-skinned and Black students more often with no more actual cheating, and a flag is an accusation the student must answer, a disparate flag rate is a disparate burden of suspicion. The governable surfaces are the proportionality of the surveillance to the integrity problem it is trying to solve, and the measured flag rate by group.

    empirical
    • Peer-reviewed Yoder-Himes, D.R., Asif, A., Kinney, K., et al. (2022). Racial, skin tone, and sex disparities in automated proctoring software. Frontiers in Education, 7, 881449. https://doi.org/10.3389/feduc.2022.881449 https://www.frontiersin.org/journals/education/articles/10.3389/feduc.2022.881449/full
    • Regulatory Ogletree v. Cleveland State University, No. 1:21-cv-00500 (N.D. Ohio, August 22, 2022); via Higher Ed Dive and Future of Privacy Forum analyses. https://fpf.org/blog/federal-court-deems-universitys-use-of-room-scans-within-the-home-unconstitutional/

Where this connects

Institutional pressures in this domain

  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.

All of them in context on the Education AI domain page.

Levers available here and the patterns behind them

Documented case histories