Skip to content

PAN Lab example

Udbetaling Danmark data-driven control (Denmark)

Standing surveillance by data-linking: a welfare-fraud control suite

A Joint Data Unit links around ten national registers over millions of benefit recipients and runs up to sixty models that score them into a wonderlist of high-risk people; a human control team then works the highest-risk cases, up to the most invasive on-site checks. Modeled on Denmark's Udbetaling Danmark data-driven control. Watch where the harm begins: not at any single flag, but at the linkage itself -- half the adult population held in one suspicion apparatus -- and at a foreign-affiliation model whose threshold is relative, so it always selects some group with ties to non-EEA countries regardless of what they did. Most people it flags and opens have done nothing wrong, and the oversight that could catch that acts on complaints which opacity keeps rare -- an appeals board hears the determinations people do contest, but few learn enough about their own case to contest one.

Stylized model of a documented deploymentPublic benefits & eligibility

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Udbetaling-Danmark-class data-driven fraud-control suite network: 7 components and 15 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 5 assumed · 5 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

  • baseline

    The one documented corrective actor in this record is drawn as a wired-in reviewer: the national appeals board, which the record shows overturning a control determination - a cohabitation repayment of 12,500 Danish kroner (about 1,650 euros) built on social-media evidence. Its inbound pathway is the record, because what a recipient can appeal is the recorded determination and its repayment demand, not the wonderlist selection. The inbound stream is drawn faint because the record also documents that few flagged people learn an algorithm selected them; the outbound reversal is drawn faint rather than empty because, unlike the model-side check, this channel demonstrably fired. It is also the real referent of the correction-budget lever this org offers. The contrast with the French sibling is documented on both sides: there the score itself is not directly appealable and the scrutiny channel reached the model, here the model is unreachable and the corrective acts case by case.

  • baseline

    The manual staffing capacity is derived as low, not defaulted. The suite screens about 2.4 million recipients while the human channel opens 5,000 to 6,000 control cases a year, roughly 1,800 of them model-sourced, and the control team's filter is a paper sift (412 requested to 292 established for one documented model). That is a human tier reaching a fraction of a percent of what the models screen. Contaminated records are carried as a standing pressure on this deployment rather than an optional one, because the record documents register data of known inaccuracy - civil-registration and dwelling data - propagating into the flags.

  • assumed

    The record names the Joint Data Unit as its own actor, so it is modeled as one: the unit builds and runs the suite of up to sixty models, receives what the models surface, and recalibrates them - one organisational step removed from the control officers who act on the wonderlist. The lever over what the list becomes sits with the builders, not the actors, and drawing the unit is what makes that separation of authority visible on the board.

  • assumed

    This models the mass-data-linking fraud-control pattern documented in the Denmark Udbetaling Danmark case file -- not a reconstruction of the actual model suite, its inputs, or its weights (input weights are redacted in the record, and only four of about sixty models are documented).

  • assumed

    Peer pathways are authored on both signs: one shared model suite's systematic relative-metric skew and shared control-officer targeting habits reinforce, while a real human check survives -- the control team filters requested cases into established control cases -- so this is not a no-review structure. What starts closed is an internal precision or fairness check of the wonderlist itself.

  • baseline

    The merged-registers node carries a real, strong inflow into the model -- around ten national registers linked by the Joint Data Unit, plus foreign data via the Joint Data Unit Abroad -- so the linkage enters the dynamics, not just the picture. It is the case's defining feature: standing surveillance of benefit recipients by data-linking. What that linkage encodes as differential harm stays external (below).

  • baseline

    The retrospective-calibration loop -- past control outcomes calibrating the next wonderlist, plus control-team confirmations as ground truth, with register data of documented inaccuracy feeding the flags -- is present at baseline, reflecting the documented dynamic in which historically targeted patterns feed forward into future flags.

  • baseline

    The defining feature is an absence: no independent precision or fairness check ran on the wonderlist before outside scrutiny arrived, so the model-side check starts closed. In UDK's own 2023 figures most flagged-and-opened cases were legitimate (about 54% for Really Single; roughly 90% no further action for Model Abroad), and the scrutiny that surfaced this came from an outside investigation, not an internal check.

  • assumed

    The wonderlist is drawn as a mediating artifact on the model -> control-team pathway -- the models' question list of high-risk people. It carries no flow of its own and does not affect the dynamics.

  • assumed

    The documented harm is a design-level discrimination risk -- Model Abroad scores relative non-EEA foreign affiliation with citizenship as a direct input, and Really Single treats atypical households as suspicious -- but it could not be measured: UDK and ATP denied all requests for the demographic data needed to test the models for bias. This Lab models institutional propagation, not demographics, estimates no differential harm to served people, and encodes no disparity figure because none exists in the record. The social-scoring characterisation is contested -- Amnesty asserts it, UDK, ATP and the ministry (STAR) reject it -- and no court has ruled; the system was not suspended.

What this example does not show

  • The documented harm is a design-level discrimination RISK -- relative non-EEA “foreign affiliation” scoring with citizenship as a direct input, and atypical households treated as suspicious -- that could not be measured, because UDK and ATP denied all requests for the demographic data needed to test the models. The Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served people; no disparity figure exists in the record. Amnesty characterises the system as mass surveillance and social scoring under the EU AI Act; UDK, ATP and the ministry (STAR) reject that characterisation; no court has ruled and the system was not suspended.
  • The 2023 control figures are UDK's own, cover only three of about sixty models, and their “revenue” outcome conflates deliberate fraud with honest error (UDK does not split them), so they are not pure fraud rates; the Lab uses the case's shape, not calibrated rates. Affected recipients are not represented on this diagram -- the burden of being investigated is documented in the case file and measured outside any diagram like this one.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • Udbetaling Danmark's 'Joint Data Unit' merges and links the personal data of millions of residents from around ten national registers -- civil registration (CPR), buildings and dwellings (BBR), business, income, tax (R75), health, VAT, cash and sickness benefits, education grants, and the motor-vehicle register -- alongside a 'Joint Data Unit Abroad' that pulls data from foreign authorities; in 2021 UDK paid about DKK 241 billion to roughly 2.4 million recipients. Amnesty International documents this as mass surveillance and argues the design carries a discrimination risk: 'Model Abroad' scores a relative strength of ties to non-EEA countries with citizenship as a direct input, and 'Really Single' treats statistically atypical households as suspicious. That harm is a design-level risk rather than a measured outcome, because UDK and ATP denied all requests for the demographic data needed to test the models for bias, so no disparate-impact figure exists in the record. Oversight is thin: the Danish Data Protection Authority (Datatilsynet) can generally act only on complaints (GDPR Art. 57) with no proactive power, and because flagged people rarely learn an algorithm selected them, complaints are rare. UDK rejects the discrimination-by-design and social-scoring findings; no court has ruled.

    empirical
    • Investigative Amnesty International (Algorithmic Accountability Lab), Coded Injustice: Surveillance and Discrimination in Denmark's Automated Welfare State (index EUR 18/8709/2024) (2024) https://www.amnesty.org/en/documents/eur18/8709/2024/en/
    • Advocacy Amnesty International Danmark, Danmark: Algoritmer masseovervaager og diskriminerer udsatte grupper i jagten paa svindel (Denmark: Algorithms mass-surveil and discriminate against vulnerable groups in the hunt for fraud) (2024) https://amnesty.dk/danmark-algoritmer-masseovervaager-og-diskriminerer-udsatte-grupper-i-jagten-paa-svindel/
    • Trade press BABL AI, Denmark's Automated Welfare System Under Fire for Surveillance and Discrimination (2024) https://babl.ai/denmarks-automated-welfare-system-under-fire-for-surveillance-and-discrimination/
  • Denmark's Udbetaling Danmark (UDK), administered by ATP, runs a data-driven welfare-fraud operation that as of 2019 used up to about 60 AI and machine-learning models to score benefit recipients into a 'wonderlist' of high-risk people, which a human control team filters into control cases for investigation. In UDK's own 2023 control statistics (three documented models), the 'Model Abroad' foreign-affiliation model sent 511 cases for control but recovered money in only 36 -- about 7%, with roughly nine in ten resulting in no further action -- and UDK confirmed that 54% of the 'Really Single' household-outlier cases its unit opened were in fact legitimate. Those 'revenue' outcomes conflate deliberate fraud with honest error, which UDK does not separate, so they are not pure fraud rates. Amnesty International characterised the system as mass surveillance and prohibited social scoring under the EU AI Act; UDK, ATP, and the ministry (STAR) rejected that characterisation, the system was not suspended, and as of this writing no court had ruled.

    empirical
    • Investigative Amnesty International (Algorithmic Accountability Lab), Coded Injustice: Surveillance and Discrimination in Denmark's Automated Welfare State (index EUR 18/8709/2024) (2024) https://www.amnesty.org/en/documents/eur18/8709/2024/en/
    • Investigative Amnesty International, Denmark: AI-powered welfare system fuels mass surveillance and risks discriminating against marginalized groups - report (2024) https://www.amnesty.org/en/latest/news/2024/11/denmark-ai-powered-welfare-system-fuels-mass-surveillance-and-risks-discriminating-against-marginalized-groups-report/
    • Trade press Fortune (Europe), Denmark's renowned safety net turns into a political battleground as AI and algorithms target welfare recipients (2024) https://fortune.com/europe/2024/11/13/denmark-renowned-safety-net-turns-into-a-political-battleground-ai-algorithms-target-welfare-recipients
    • Trade press BABL AI, Denmark's Automated Welfare System Under Fire for Surveillance and Discrimination (2024) https://babl.ai/denmarks-automated-welfare-system-under-fire-for-surveillance-and-discrimination/

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Public benefits & eligibility domain page.

Levers available here and the patterns behind them

Documented case histories