PAN Lab example
SyRI (Netherlands)
Struck down before the harm was counted: a secret welfare-fraud dragnet
A secret model links records across many government databases and flags people for fraud investigation, and the flags land in a two-year register that other agencies re-read and re-link — but the people flagged are never told, so they cannot see or contest a flag. Modeled on the Netherlands' SyRI. Watch where the control comes from: not from measuring who was wrongly flagged, but from the transparency and privacy defect an outside authority could see before any of that harm was counted.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the SyRI-class cross-database risk-flagging engine network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 4 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the secret cross-database risk-flagging pattern documented in the SyRI case file — not a reconstruction of the actual model or its undisclosed indicators.
- assumed
Peer pathways are authored on both signs: shared suspicion heuristics and one secret indicator set's systematic skew reinforce, while the operator-side ministry pre-screen — the documented false-positive filter — is a present but light inhibiting check.
- baseline
The register loop — notifications written into a two-year register, re-linked into agency files, and re-read on re-investigation — is present at baseline, reflecting the case documentation's account of a two-year register held with no subject-facing correction.
- assumed
The ministry pre-screen node carries a real, lighter review pathway of its own — the documented operator-side screening of notifications for false positives before release — so it enters the dynamics rather than sitting on a pathway. That it screened some false positives does not mean the person flagged could see or contest the notification.
- baseline
The defining feature is an absence: there was no subject-facing correction channel, so the record-side reconciliation edge starts closed at baseline. The court found no duty to notify data subjects, so a flagged person generally could not know about, access, or contest a notification.
- baseline
The cross-database-linkage node carries a real inflow into the model — pseudonymised records linked across many government databases — so it enters the dynamics. What that linkage reached (data collected for other purposes, up to special-category data) and whom it targeted are documented in the case file, not computed here.
- assumed
SyRI was deployed in specific low-income, high-migrant neighbourhoods, a targeting the court flagged as risking discrimination and stigmatisation. This Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served people; that targeting and the individual harms are documented in the case file and measured outside any diagram like this one.
What this example does not show
- SyRI was deployed in specific low-income, high-migrant neighbourhoods, a targeting the court flagged as risking discrimination and stigmatisation. The Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served people; that targeting and the individual harms are documented in the case file and measured outside any diagram like this one.
- The false-positive and zero-fraud figures reached the record through litigation pleadings and press, not an independent government audit; the Lab uses the case's shape, not calibrated rates.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
The District Court of The Hague found that the SyRI framework provided no duty to notify people that their data had been processed or that a risk report had been filed, so a flagged person generally could not know about, access, or contest the notification; notifications were retained in a register for up to two years. The court held that a risk notification carried significant effect for the person even though it lacked formal legal effect, and it faulted the scheme for a lack of transparency and for breaching data-minimisation and purpose-limitation principles.
empirical- Government District Court of The Hague, NJCM and FNV v. The State of the Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 (English translation; Dutch original ECLI:NL:RBDHA:2020:865) (2020) https://www.escr-net.org/caselaw/2020/nederlands-juristen-comite-voor-mensenrechten-et-al-v-netherlands-eclinlrbdha20201878/
- Academic van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257
On 5 February 2020 the District Court of The Hague ruled that the legislation authorising SyRI, the Dutch state's secret cross-database welfare-fraud risk-profiling system, violated Article 8 of the European Convention on Human Rights, and it ordered the system's use stopped; the State did not appeal. The ruling is widely described as one of the first times a court anywhere halted a digital welfare-fraud technology on human-rights grounds. Across its two executed neighbourhood projects SyRI was reported to have produced no confirmed fraud cases, and in one municipality 62 of 113 risk notifications were reported to be false positives.
empirical- Government District Court of The Hague, NJCM and FNV v. The State of the Netherlands (SyRI), ECLI:NL:RBDHA:2020:1878 (English translation; Dutch original ECLI:NL:RBDHA:2020:865) (2020) https://www.escr-net.org/caselaw/2020/nederlands-juristen-comite-voor-mensenrechten-et-al-v-netherlands-eclinlrbdha20201878/
- Academic van Bekkum, Marvin and Zuiderveen Borgesius, Frederik, Digital welfare fraud detection and the Dutch SyRI judgment, European Journal of Social Security 23(4):323-340 (2021) https://journals.sagepub.com/doi/10.1177/13882627211031257
- Government UN Office of the High Commissioner for Human Rights, Landmark ruling by Dutch court stops government attempts to spy on the poor - UN expert (2020) https://www.ohchr.org/en/press-releases/2020/02/landmark-ruling-dutch-court-stops-government-attempts-spy-poor-un-expert
- Investigative AlgorithmWatch, How Dutch activists got an invasive fraud detection algorithm banned (Automating Society Report 2020: Netherlands) (2020) https://algorithmwatch.org/en/syri-netherlands-algorithm/
- Trade press PONT Data&Privacy (privacy-web.nl), SyRI: Algorithm that identifies citizens as high fraud risk (2019) https://privacy-web.nl/en/artikelen/syri-algoritme-dat-burgers-aanmerkt-als-hoog-frauderisico/
- Advocacy Public Interest Litigation Project (PILP-NJCM), System Risk Indication (SyRI) - dossier (2020) https://pilp.nu/en/dossier/system-risk-indication-syri/
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Public benefits & eligibility domain page.
Levers available here and the patterns behind them
- Require sign-off — Conformity assessment gate
- Mark AI-written records — Provenance labeling
- Store less data — Data minimization
- Check copied records — Reconcile copied records
- Vet connections — Connection authorization
- Understand the system — Understand the system
- Review on schedule — Oversight cadence & retrospectives
- Assign a challenger — Structured dissent
- Upgrade model — Improve the model
- Peer sharing rules — Peer-edge governance
- Escalate checks — State-feedback vigilance
Documented case histories
- SyRI (Netherlands)
- Michigan MiDAS
- Robodebt (Australia)
- Indiana / IBM eligibility modernization
- Rotterdam welfare-fraud risk model
- Arkansas ARChoices / ARIA
- Netherlands childcare-benefits scandal (Toeslagenaffaire)
- CNAF benefit-fraud risk score (France)
- Forsakringskassan VAB fraud-selection profile (Sweden)
- Udbetaling Danmark data-driven control (Denmark)
- BOSCO (Spain)
- Serbia Social Card (Socijalna karta)
- UK DWP Universal Credit Advances fraud model
- ID.me identity verification as an unemployment eligibility gate
- Medicaid unwinding: automated ex parte renewal at population scale
- INSS auto-analysis: when the productivity metric makes denial the fastest way out
- Samagra Vedika
- Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
- NYC MyCity business chatbot
- Nevada DETR generative-AI unemployment appeals
- Tennessee TennCare TEDS