PAN Lab example
Gladsaxe model
The screen that never ran: whole-population child scoring
A municipality builds an in-house tool to score, for every young child rather than only families already getting help, the probability that the child is living in vulnerability. Modeled on Denmark's Gladsaxe model. The twist: this system never ran. It was stopped in development, and everything that stopped it sat upstream of the model — a legal basis it never got, a whole-population data scope, and a data-security capacity it did not have.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Gladsaxe-class whole-population child screen network: 6 components and 14 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 4 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the halted-before-deployment, whole-population screening pattern documented in the Gladsaxe model case file — not a reconstruction of the actual project.
- baseline
The tool was never operationalised: this shape models a design ended in its development phase, so no live decision loop ran. The write-back and persistent-score pathways are drawn empty or nearly so to reflect the consent-gated, delete-on-decline workflow the project designed.
- baseline
The register inflow is drawn strong and privacy-sensitive because the tool was to profile every child aged 0–6, a broader reach than the benefits-gated tools it was modelled on. That whole-population scope is the shape's defining exposure.
- assumed
Human discretion was designed to remain decisive — the score was scoped to identification only, with a specialist making the assessment and deleting non-consenting cases — so the model-to-operator adoption edge is drawn low. That protective posture is what the levers here must preserve.
- baseline
The latent egress pathways to the Outside System carry the data-security-capacity exposure the case documents: a 2018 laptop theft exposed a spreadsheet with about 20,000 citizens' identification numbers — an incident separate from the project but revealing of the same capacity gap it ran under.
- baseline
One decision tree would have scored every young child, so a blind spot in it would be systematic rather than case-by-case; the model-to-model self-loop encodes that correlated reach.
- assumed
Demographics and differential harm to families are not modelled here. The documented controversy centred on surveillance, transparency and citizens' rights, and the tool never ran on live decisions, so no harm to real families from the model is implied.
What this example does not show
- This is a halted-before-deployment case: the tool was ended in its development phase and never ran on live decisions, so nothing here implies harm to real families from the model. The 2018 data breach it is associated with was a separate incident.
- The durable public image was a points system that summed weighted points per risk factor; the municipality and the peer-reviewed case study state the actual artefact was an incomplete probability-scoring decision tree, and the widely quoted point values trace to media framing of the exemption application.
- The Lab models institutional propagation, not demographics; the documented controversy centred on surveillance, transparency and citizens' rights, and no measured demographic disparity is asserted here.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
Gladsaxe's early-detection project (DTO) was a decision-tree model over about 44 risk indicators, meant to score, for every child aged 0 to 6 rather than only families already receiving help, the estimated probability that the child was living in vulnerability; per a university-run Danish public-sector AI catalogue it was to be trained on roughly 173,000 notifications the authorities received between April 2016 and December 2017, but only about 117 usable historical cases existed, and it was halted in its development phase in 2019 without ever running on live decisions, after a national media storm and an unrelated data breach that exposed about 20,000 citizens' personal identification numbers.
empirical- Academic Offentlig AI (university-run Danish public-sector AI catalogue), Gladsaxe-modellen project profile (n.d.) https://offentlig-ai.dk/projekter/gladsaxe-modellen
- Academic Kenneth Kristensen (Samfundslederskab i Skandinavien, Copenhagen Business School), Hvorfor Gladsaxemodellen fejlede: om anvendelse af algoritmer paa socialt udsatte boern (2022) https://rauli.cbs.dk/index.php/SiS/article/view/6542
- Academic Helene Friis Ratner and Kasper Elmholdt, Algorithmic constructions of risk: Anticipating uncertain futures in child protection services, Big Data and Society (2023) https://journals.sagepub.com/doi/10.1177/20539517231186120
- Academic Katarina Fast Lappalainen, Protecting Children from Maltreatment with the Help of Artificial Intelligence: A Promise or a Threat to Children's Rights?, De Lege 2021 (Uppsala University Faculty of Law) (2021) https://www.diva-portal.org/smash/record.jsf?pid=diva2:1653453
- Investigative TV 2 Kosmopol (formerly TV 2 Lorry), Computertyveri: 20.000 borgeres CPR-numre laekket (2018) https://www.tv2kosmopol.dk/gladsaxe/computertyveri-20000-borgeres-cpr-numre-laekket
A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
Where this connects
Institutional pressures in this domain
- Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
- Deadline pressure — Statutory or managerial timeliness rules reward fast approval of machine output over slow disagreement.
- Staff turnover — Experienced skepticism leaves; new staff calibrate their trust on the tool itself.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
All of them in context on the Child welfare & family services domain page.
Levers available here and the patterns behind them
- Store less data — Data minimization
- Vet connections — Connection authorization
- Require sign-off — Conformity assessment gate
- Review on schedule — Oversight cadence & retrospectives
- Assign a challenger — Structured dissent
- Keep skills sharp — Deskilling-arrest mandate
- Gate record entries — Human-in-the-loop write gating
- Upgrade model — Improve the model
- Understand the system — Understand the system
- Pause AI on alarms — Deployment circuit-breaker
Documented case histories
- Gladsaxe model
- Allegheny Family Screening Tool
- Allegheny Hello Baby
- Douglas County Decision Aide
- The score nobody sees: New York City's concealed severe-harm QA algorithm
- The audit that reached the legislature before it reached the tools: Colorado's safety and risk instruments
- Eckerd Rapid Safety Feedback: origin and spread
- Illinois Rapid Safety Feedback
- The vendor's ledger: Family-Match, the eharmony-derived adoption matcher the states kept coming back to
- ProKid (Netherlands)
- Insight Bristol / Think Family Database
- Hackney / Xantura Early Help Profiling
- Sistema Alerta Niñez (Chile)
- The map, not the score: place-based risk terrain and the records it concentrates
- The guardrail's blind side: DC's walled-off child-welfare chatbot that began writing into the case record
- US Birth Match
- Oregon Safety at Screening
- Los Angeles County Project AURA
- What Works for Children's Social Care ML pilots
- New Zealand MSD Predictive Risk Modelling