Skip to content

PAN Lab example

Home Office IPIC

A human decides and the form only asks why not

IPIC (Identify and Prioritise Immigration Cases) is an enforcement-triage algorithm that recommends people for immigration actions — returns, bail, casework — from sensitive detention, health, and location data, with a human official making the final call. It is modeled on a deployment where freedom-of-information (FOI) litigation surfaced a one-sided override: officials must record a reason to reject a recommendation but none to accept one. That builds automation bias — the pull to defer to the machine — into the workflow by design: accepting is effortless, disagreeing is work, so the human review is only a formality. Applicants are often not told AI is used, so they cannot challenge it. Watch whether the review is genuinely a check, and whether the person it is about can answer it.

Stylized model of a documented deploymentImmigration & asylum AI

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Enforcement-triage-class where oversight is hollow by design network: 7 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • assumed

    Three documented parts of this deployment shape the model. First, the rejection-justification step is drawn as a form, not a culture, because that is what the disclosed training material shows: officials must record a reason to reject a recommendation but none to accept one, so the two options cost different amounts of work before anyone has looked at the case. Second, the location feed is a live input — a record of where a person went, generated by nothing more deliberate than living somewhere, read for what it might imply. Third, an accepted recommendation flows straight from the record into an action — a removal, a bail condition, a casework step against a named person — with nothing reconciling it against the file first. Three checks are therefore switched off on the same decision: rejecting is made costly, the affected person is kept from knowing, and nothing reviews the action before it lands. The workload the disclosed material describes — more cases than the human review can genuinely absorb — is what makes the easy, deferential path the one that gets taken.

  • baseline

    This models the enforcement-triage pattern documented in the case file — not a reconstruction of the actual system. An immigration-enforcement triage algorithm recommends people for actions (returns, bail, casework) from sensitive detention, health, vulnerability, and location-monitoring data. Roughly a year of freedom-of-information (FOI) litigation surfaced a one-sided override: officials must record a justification to reject a recommendation but not to accept one. The override design and the disclosure gap are recorded findings from that litigation and civil-society analysis, entered as such — not judgments about any individual case.

  • baseline

    The one-sided override builds automation bias into the process by design: accepting the recommendation is effortless, rejecting it takes work, so deference becomes the rule rather than a tendency. The claim that a human makes the final decision can be true and empty at the same time — the clearest documented case in this collection of automation bias built into an agency workflow. A genuinely even-handed review — one that makes the official as free and as prompted to reject as to accept — is the check this design leaves switched off. Whether oversight is real is a property of how the process is designed, not of the org chart.

  • assumed

    The other switched-off check is disclosure to the affected person: applicants are frequently not told AI is used, so the one party who could challenge a wrong recommendation — the person it is about — cannot. With the official nudged to accept and the applicant kept from objecting, both checks that could catch an error are off at once. Disclosure to the affected person is not a courtesy but a load-bearing correction, often the last one standing when the internal review has been designed toward deference. This is not a claim that the model is biased — only that the process is designed toward deference.

  • assumed

    No enforcement outcome and no individual's case is modeled here. This Lab reads institutional propagation only, and the people being triaged are boundary-only. The override design uncovered through freedom-of-information (FOI) litigation, the sensitive-data inputs, and the non-disclosure to applicants live in the case file, and are never computed from anything in this diagram.

What this example does not show

  • No enforcement outcome and no individual's case is modeled. The Lab reads institutional propagation only; the people being triaged are boundary-only, and the freedom-of-information (FOI)-disclosed override design, the sensitive-data inputs, and the non-disclosure to applicants live in the case file, never computed on this diagram.
  • The override design and the disclosure gap are recorded findings from freedom-of-information (FOI) litigation and civil-society analysis entered as such, not adjudications of any individual case, and nothing here is a claim that the model is biased — only that the process is designed toward deference; the symmetric review and the applicant's ability to contest are drawn as two latent checks.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • A government's immigration-enforcement triage algorithm identifies and recommends people for enforcement actions — returns, bail conditions, casework — drawing on sensitive data including detention, health, vulnerability, and location-monitoring records. Uncovered through roughly a year of freedom-of-information litigation, its training materials show an asymmetric override design: officials must record a justification for rejecting a recommendation but not for accepting one. That design builds a rubber-stamping incentive into the workflow — accepting the algorithm is frictionless, overriding it requires work — so the human in the loop is nominal rather than a real check. It is the corpus's clearest documented instance of automation bias engineered into an agency workflow, in one of the highest-stakes enforcement settings a state operates.

    empirical
    • Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://privacyinternational.org/news-analysis/5452/automating-hostile-environment-uncovering-secretive-home-office-algorithm-heart
    • Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://www.whatdotheyknow.com/request/identify_and_prioritise_immigrat_3
  • The lesson the case carries is that nominal human oversight is not real oversight. An asymmetric override — where accepting the algorithm's recommendation is frictionless and rejecting it requires a recorded justification — engineers automation bias into the process by making deference the path of least resistance, so the claim that a human makes the final decision can be true and empty at once. Two governable surfaces follow. Whether the review is genuinely symmetric: the official as free and as prompted to reject as to accept, so an error is as likely to be caught as waved through. And whether the affected person is told the AI is used and can contest it: applicants are frequently not told, which severs the correction on the side that could challenge the recommendation, so the one check that survives the asymmetric override — the person it is about — is cut out too.

    empirical
    • Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://privacyinternational.org/press-release/5640/privacy-international-issues-complaint-uk-regulator-regarding-deployment-two
    • Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://www.whatdotheyknow.com/request/identify_and_prioritise_immigrat_3

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).

All of them in context on the Immigration & asylum AI domain page.

Levers available here and the patterns behind them

Documented case histories