PAN Lab example
Indiana / IBM eligibility modernization
Denied for 'failure to cooperate': a privatized eligibility pipeline
A statewide benefits system is handed to a private consortium — call centers and document imaging replace local caseworkers, and a timeliness clock closes any case whose paperwork is not matched in time, for 'failure to cooperate'. Modeled on Indiana's IBM/ACS eligibility modernization. The harm runs through the document pipeline, not a fraud score: ordinary paperwork friction becomes mass denial once the human who used to absorb it is gone, and for years the only actor who could stop it was the contract itself.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Indiana-class privatized eligibility pipeline network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 4 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the privatized, procedural eligibility-pipeline pattern documented in the Indiana / IBM eligibility-modernization case file — not a reconstruction of the actual system.
- baseline
The defining mechanism is a default-deny on ambiguity: the case documentation describes over a million denials in the program's early years, many for procedural 'failure to cooperate' rather than substantive ineligibility. The record-to-denial pathway is drawn strong, and the reconciliation check that would catch a document lost in imaging is drawn on the map but runs dry at baseline.
- baseline
Human capacity to absorb documentation friction was removed: named local caseworkers were replaced by a remote call-center and document-processing workforce with little authority to reverse a determination. The model-to-operator adoption pathway is drawn thin and the operator correction loop weak, so ordinary documentation friction becomes adverse action rather than being resolved in a relationship.
- baseline
One vendor rule set applied uniformly across the state means a single procedural flaw produces correlated mass denial rather than scattered error; the model-to-model self-loop encodes that correlated reach — an authored emphasis, not a measured rate.
- baseline
The state-vendor contract node's defining documented action was a one-time terminal governance event — the 2009 contract cancellation and ensuing litigation — not a continuous oversight loop. Its outbound stop authority is drawn on the map but dormant at baseline, so a pre-committed halt or standing review lever can turn a crisis-driven cancellation into a governed control. The merits of the litigation are recorded in the case file, not adjudicated here.
- assumed
Centralized imaging of sensitive applicant paperwork by a private vendor is drawn as a privacy-sensitive intake edge, but the documented harm channel here is procedural denial, not data misuse or third-party disclosure; nothing here implies a documented breach.
- assumed
The people denied — low-income, elderly, and disabled applicants and families — are not modeled here. This Lab models institutional propagation, not demographics, and estimates no differential harm to served people; that harm is documented in the case file and measured outside any diagram like this one.
What this example does not show
- The 'failure to cooperate' framing describes the procedural denial category documented in the sources, not a finding about any individual applicant's conduct; the modeled default-deny is the system's behavior, not a claim that applicants did not cooperate.
- The litigation between Indiana and its vendor is recorded in the case file as a terminal event, not adjudicated here; the contract-cancellation node models the stop authority's shape, not the merits of that dispute.
- The people denied — low-income, elderly, and disabled applicants and families — are not modeled here. The Lab models institutional propagation, not demographics, and estimates no differential harm to served people; that harm is documented in the case file and measured outside any diagram like this one.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
Indiana's privatized eligibility modernization produced over a million denials in its early years — many procedural rather than substantive — before the state canceled the contract and litigated with its vendor.
empirical- Investigative Eubanks, Automating Inequality (2018); The Nation, Want to Cut Welfare? There's an App for That https://www.thenation.com/article/archive/want-cut-welfare-theres-app/
- Investigative Government Technology, IBM and Indiana Suing Each Other https://www.govtech.com/health/ibm-and-indiana-suing-each-other.html
- Investigative IEEE Spectrum, Indiana and IBM Sue Each Other Over Failed Outsourcing Contract https://spectrum.ieee.org/indiana-and-ibm-sue-each-other-over-failed-outsourcing-contract
A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Public benefits & eligibility domain page.
Levers available here and the patterns behind them
- Gate record entries — Human-in-the-loop write gating
- Check copied records — Reconcile copied records
- Understand the system — Understand the system
- Escalate checks — State-feedback vigilance
- Gate vendor updates — Vendor quality gate
- Pause AI on alarms — Deployment circuit-breaker
- Require sign-off — Conformity assessment gate
- Review on schedule — Oversight cadence & retrospectives
- Vet connections — Connection authorization
- Assign a challenger — Structured dissent
- Upgrade model — Improve the model
Documented case histories
- Indiana / IBM eligibility modernization
- Michigan MiDAS
- Robodebt (Australia)
- Rotterdam welfare-fraud risk model
- Arkansas ARChoices / ARIA
- Netherlands childcare-benefits scandal (Toeslagenaffaire)
- SyRI (Netherlands)
- CNAF benefit-fraud risk score (France)
- Forsakringskassan VAB fraud-selection profile (Sweden)
- Udbetaling Danmark data-driven control (Denmark)
- BOSCO (Spain)
- Serbia Social Card (Socijalna karta)
- UK DWP Universal Credit Advances fraud model
- ID.me identity verification as an unemployment eligibility gate
- Medicaid unwinding: automated ex parte renewal at population scale
- INSS auto-analysis: when the productivity metric makes denial the fastest way out
- Samagra Vedika
- Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
- NYC MyCity business chatbot
- Nevada DETR generative-AI unemployment appeals
- Tennessee TennCare TEDS