PAN Lab example
San Jose's camera car
The rule you declare and the flow you leave open: a camera car aimed at who is sleeping outside
A city mounts cameras on a sedan and drives one district, training AI to spot potholes and trash - and, in the same pilot, RVs, lived-in vehicles, and homeless encampments. Modeled on San Jose's Road Safety Conditions Pilot (its AI object-detection initiative). The detector is accurate on infrastructure (97% on potholes) and badly inaccurate on habitation (12.5% on lived-in vehicles), and the low-precision classes are exactly the ones aimed at people. It scores no one and, in this pilot, drove no action at all: the detection-to-response loop was never wired. The written rule says the footage is not for law enforcement - but the same policy keeps a police request path to it open, and a vendor read license plates the policy said it would not. The real question is not whether to buy a sharper detector. It is whether the flows you leave feasible match the rule you declare - and whether anyone audits the gap before a low-precision guess about who is sleeping outside can turn into a sweep.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the San-Jose-detection-class vehicle-mounted object-detection pilot network: 9 components and 18 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the surveillance-adjacent object-detection pattern documented in the San Jose vehicle-mounted encampment-detection case file - not a reconstruction of the actual pilot or its vendors' models. The atlas-relevant object is the topology: a mobile computer-vision sensor with class-asymmetric accuracy (97% for potholes down to 12.5% for lived-in vehicles) aimed at a population a physical response can be taken against, whose declared authority rule and feasible data flows diverge, and whose detection-to-response loop was never wired. Any reading that implies the tool scored, ranked, or adjudicated an individual misreads it - it classified objects in street footage, and no detection drove any operational action in Phase One.
- baseline
The defining structural property is the divergence between the declared authority graph and the feasible data flows. The published data-usage protocol states the footage cannot be actively monitored for law-enforcement purposes but that 'Law enforcement may request access to previously stored footage', and requires de-identification (blurring faces, addresses, and plates) or deletion within one month; the CIO stated data was not shared with police during the pilot. Yet reporting documented, from public records, that one vendor system ran optical character recognition of license plate numbers despite the no-identification claim (the vendor did not respond to a request for comment). So the declared rule and the feasible flow differ, and the law-enforcement request path is drawn as an inactive hazard pathway, not a closed one. This is a city protocol, not a statute, and the police-request-path risk is an advocate characterization the city disputes - both positions ship.
- baseline
The two load-bearing absences are drawn as inactive pathways. First, the independent model check: no standing audit reconciled what the vendor pipeline actually extracted against its declared scope - the off-policy plate optical character recognition (OCR) was surfaced by journalists via public records, not by any routine check, and one shared pipeline runs both detector channels, so its behavior is systematic. Second, the independent peer evaluation: no independent evaluation of the low-precision detector's asymmetric-error consequences exists - the accuracy figures are self-reported by the city, the federal ITS summary only restates them, and the intended service hand-off to housing and parks never happened. These are the case's distinctive safety shape: a strongly governed pilot (a published protocol, ground-truth verification, structured engagement, aggressive deletion) whose two unmeasured surfaces are the gap between declared and feasible behavior, and the impact of aiming a low-precision detector at unhoused people.
- baseline
The safety property of this pilot is an absence, drawn as dormant model->service edges: the detection-to-response loop was never wired. No detection generated an operational dispatch in Phase One, and the auto-generation of service tickets remained a Phase Two aspiration; the high-stakes habitation loop was never wired at all before its classes were removed. The asymmetry that makes this matter is that a false positive on a 12.5%-precision lived-in-vehicle class, had it driven a response, would have fallen as a physical action (a sweep, a tow, an impound) on an unhoused person - while a false negative merely delays blight response - and the same city was contemporaneously expanding tow-and-impound authority. The decisive safeguard was a governed exit taken before any operational coupling existed: the city removed every habitation-detection use case and its March 2025 status report does not recommend implementing AI object detection in city operations at this time, with a suggestion to evaluate the removed classes separately in the future - reported here as the city's own decision.
- assumed
The privacy surface is real and is drawn on the feed, the read, the write, and the egress. The collection is covert street surveillance of homes, vehicles, faces, and plates in an unhoused-heavy district, with no individual notification and no opt-out from being captured. It is mitigated by aggressive one-month de-identification or deletion and by the eventual removal of the habitation classes, but a vendor's off-policy plate optical character recognition (OCR) made identification feasible, a law-enforcement request path to the stored footage is preserved, and pilot data and San-Jose-trained vendor models flow outward through the GovAI Coalition, the San Jose State University sharing preparation, and the vendors' continued marketing. data-minimization and connection-auth are the closers on the extraction and the egress; the one place minimization was not applied (the retained, off-policy plate OCR) is exactly what they would address.
- assumed
Served people - unhoused residents, and any enforcement or outreach action taken toward them - are not in the dynamics; this Lab reads institutional propagation only. Because the response loop was never closed, there are no false-positive consequence data on unhoused people and no counts of police requests, so the enforcement-adjacent response layer is a governance and scenario structure, never computed here. The per-class accuracy figures (97% to 12.5%) are the city's own staff-ground-truthed statistics, not an independent audit; the vendor roster differs across sources (the Guardian named five participants, the city report lists four), and the first-in-US framing is attributed to city officials and national housing advocates, not asserted. A detection on this map is an institutional signal, never a person.
What this example does not show
- Served people - unhoused residents, and any enforcement or outreach action taken toward them - are not modeled here; the Lab reads institutional propagation only. Because the detection-to-response loop was never wired, there are no false-positive consequence data on unhoused people and no counts of police requests under the protocol; the enforcement-adjacent response layer is a governance and scenario structure, never computed here. The harm surface is a low-precision surveillance sensor whose declared authority rule and feasible data flows diverge - never an individual determination.
- The per-class accuracy figures (97% for potholes and 88% for trash down to 70% for RVs and 12.5% for lived-in vehicles) are the city's own staff-ground-truthed statistics, not an independent audit, and they shift between measurement moments (a March 2024 official interview gave 70 to 75% for RVs and 10 to 15% for lived-in cars against a 70% goal; the final report gave 70% RV and 12.5% lived-in vehicle). Note the 70% RV figure detects RVs, not habitation - the system could not distinguish a lived-in RV from an empty one - so effective habitation-detection accuracy is lower than the headline. A safe-looking baseline is a property of this model, not a safety promise for any real deployment.
- Purpose and the police-request-path risk are contested and both positions ship. The city framed the pilot as proactive service delivery and stated data was not shared with police during the pilot; advocates set it against contemporaneous encampment sweeps, a no-return zone, and a mayoral tow-and-impound push, and treated the preserved request path and eventual data flow as the operative risk. The no-law-enforcement-use clause is city protocol language, not a statute. The vendor's license-plate optical character recognition (OCR) against the no-identification claim is reported from public records and was uncontested by the vendor (who did not respond to a request for comment); it is carried as reported, not adjudicated.
- This is an object-detection and evaluation pilot, not a risk-scoring, generative, or determination system, and no detection drove any operational action in Phase One; any reading that implies individual scoring or case adjudication misreads it. The first-in-US framing is attributed to city officials and national housing advocates rather than asserted, the vendor roster differs across sources (the Guardian named five participants, the city report lists four), and the removal of the habitation classes and the non-recommendation are reported as the city's own decisions - with a stated suggestion to evaluate the removed classes separately in the future, a documented residual revival pathway alongside the retained trash class and the coalition and vendor scaling channel.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
San Jose's vehicle-mounted computer-vision pilot, described by city officials and national housing advocates as the first US experiment training AI to recognize tents and lived-in vehicles, reported sharply class-asymmetric accuracy in the city's own staff-ground-truthed evaluation — 97% for potholes and 88% for trash, but only 70% for RVs (unable to distinguish a lived-in RV from an empty one) and 12.5% for lived-in vehicles, with a March 2024 official interview bracketing the habitation figures at 70–75% for RVs and 10–15% for lived-in cars against a 70% goal; no detection ever generated an operational dispatch, and after investigative exposure and structured engagement the city removed every habitation-detection use case, its March 2025 status report declining to recommend implementing AI object detection in city operations at this time.
empirical- Investigative Feathers, Revealed: a California city is training AI to spot homeless encampments (The Guardian, 2024) https://www.theguardian.com/technology/2024/mar/25/san-jose-homelessness-ai-detection
- Government City of San Jose Information Technology Department, Road Safety Conditions Pilot - AI Object Detection Initiative Status Report (March 20, 2025, with council memo of April 1, 2025) (2025) https://www.sanjoseca.gov/home/showpublisheddocument/119937
- Government evaluation US Department of Transportation ITS Knowledge Resources, Road Safety Conditions Pilot in California Using Computer Vision and Artificial Intelligence Reported 97 Percent Accuracy in Pothole Detection (Benefit Summary 2025-B02015) (2025) https://www.itskrs.its.dot.gov/2025-b02015
The pilot's published data-usage protocol declares that the footage cannot be actively monitored for law-enforcement purposes while preserving a police request path to it — verbatim, 'Law enforcement may request access to previously stored footage. Law enforcement is not actively monitoring any data collected' — and requires de-identification or deletion within one month; the CIO stated data was not shared with police during the pilot, yet public-records reporting documented that one vendor's system ran optical character recognition of license plate numbers despite the city's no-identification claim, so the declared authority rule and the feasible data flows diverged, a gap surfaced by journalists rather than by any standing audit, and the no-law-enforcement-use clause is city protocol language rather than statute.
empirical- Investigative Feathers, Revealed: a California city is training AI to spot homeless encampments (The Guardian, 2024) https://www.theguardian.com/technology/2024/mar/25/san-jose-homelessness-ai-detection
- Government City of San Jose Information Technology Department (Digital Privacy Program), Data Usage Protocol - Road Safety Detection Pilot (December 2023, updated April 2024) (2024) https://www.sanjoseca.gov/your-government/departments-offices/information-technology/digital-privacy/data-usage-policies-public-comment
- Trade press Varian, San Jose Is Using AI to Detect Homeless Camps. Will It Work? (Governing, Bay Area News Group, 2024) https://www.governing.com/urban/san-jose-is-using-ai-to-detect-homeless-camps-will-it-work
Where this connects
Institutional pressures in this domain
- Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
All of them in context on the Housing & homelessness services domain page.
Levers available here and the patterns behind them
- Vet connections — Connection authorization
- Store less data — Data minimization
- Mark AI-written records — Provenance labeling
- Check with a second model — Cross-model verification
- Review on schedule — Oversight cadence & retrospectives
- Escalate checks — State-feedback vigilance
- Keep skills sharp — Deskilling-arrest mandate
- Peer sharing rules — Peer-edge governance
- Pause AI on alarms — Deployment circuit-breaker
- Keep prompts neutral — Framing and mirroring reduction
- Gate record entries — Human-in-the-loop write gating
- Upgrade model — Improve the model
Documented case histories
- San Jose's camera car: a low-precision detector aimed at who is sleeping outside
- Allegheny Housing Assessment
- VI-SPDAT
- LA's coordinated-entry triage revision: the fix that needed fixing
- LA County Homelessness Prevention Unit
- Santa Clara County Homelessness Prevention System
- Homebase Risk Assessment Questionnaire
- Xantura OneView (predictive homelessness flagging)
- London's Strategic Insights Tool: one linked memory of rough sleeping read by every borough
- CHAI (chronic-homelessness prediction)
- Calgary Drop-In Centre: interpretable screening a shelter's own staff choose to check
- Imagine LA Benefit Navigator copilot
- SafeRent Tenant Screening Score
- CrimSAFE criminal-record tenant screening
- One engine, many rivals: a shared rent-setting model and the record it writes back