PAN Lab example
Workforce Australia Targeted Compliance Framework
The lesson not learned: automated compliance sanctioning after a scandal
A demerit-and-zone engine suspends and cancels welfare payments automatically for mutual-obligation failures — until a cancellation runs without the discretionary reasonable-excuse step the law required, and the safeguard the law mandated is never finished. Modeled on the Workforce Australia Targeted Compliance Framework. The engine is lawful in structure; the defect is what was left out, so no accuracy dial reaches it. This is the post-Robodebt system that was meant to have learned the lesson: the corrective loop existed this time — an Ombudsman, an assurance review — but it fired about ten months after the unlawfulness was flagged, and long-lived IT bugs ran undetected for years underneath. The gap the shape turns on is a live discretionary check at the point of cancellation, and a loop fast enough to trip while the error is still live.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Compliance-Framework-class automated mutual-obligation sanctioning engine network: 7 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 8 assumed · 1 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
This models the post-Robodebt automation-by-omission pattern documented in the Workforce Australia Targeted Compliance Framework case file — not a reconstruction of the actual framework or its code.
- baseline
The model-to-model self-loop encodes correlated error at scale: one deterministic ruleset applied uniformly to every case means a single wrong parameter — a long-lived IT bug — repeats identically across the caseload rather than averaging out, which is why three bugs produced nearly 1,800 incorrect penalties and a roughly five-year bug kept people in the Penalty Zone too long, rather than surfacing as scattered noise.
- assumed
The engine is drawn as a rules-based deterministic demerit-and-zone state machine, not a predictive or machine-learning risk score. The documented unlawfulness was an omission and a set of configuration defects — a legally required discretionary reasonable-excuse step (post-2022 SPROM Act) and its mandated Digital Protection Framework safeguard were never implemented, and long-lived IT bugs ran undetected — so the error lived in what was left out and mis-set, not in the model's accuracy, and no accuracy metric would have surfaced it.
- assumed
The defining absence is drawn as an inactive independent model check: no independent discretionary reasonable-excuse determination checks a cancellation before it executes. This is the exact step the April 2022 SPROM Act required and its mandated automated-decision safeguard (the Digital Protection Framework), neither of which was implemented, so cancellations executed without the human and legal check the law demanded.
- assumed
The Ombudsman-and-assurance-review step is drawn as an oversight loop that eventually worked but fired late: it found the unlawfulness and forced a pause, reinstatement and compensation, but its at-determination reconciliation starts inactive because the catch came only after roughly eighteen months undetected and about ten more months of inaction following the September 2023 legal flag. This is the deliberate counterpoint both to Robodebt and MiDAS, which had no internal corrective loop at all, and to the Medicaid unwinding, whose federal loop caught its defect fast.
- assumed
The delegate-and-appeal layer is drawn as a real but impeded and overwhelmed correction channel (a weak model-to-delegate route and slow, case-by-case manual corrections), reflecting the documented account that decisions were predominantly automated, that the required discretion was not exercised, that automatic Penalty-Zone suspensions themselves undermine the ability to challenge, and that the complaints line went 140,000-plus calls unanswered — even though review, where it happened, overturned a high rate of provider decisions.
- assumed
The Penalty-Zone-escalation node is a mediating artifact naming the mechanism's signature (five demerits within six months move a person to the Penalty Zone, where cuts of 50 or 100 percent of payment become automatic). It carries no flow of its own and does not affect the dynamics.
- assumed
The provider-compliance-event feed is marked privacy-sensitive because mutual-obligation reporting is continuous behavioral monitoring of about a million jobseekers. It is not a cross-agency data-matching dragnet, so the privacy lever here governs the intensity of that monitoring, not a data-linkage; this is why the scenario's privacy gauge starts at the low end.
- assumed
First Nations people are reported to have experienced disproportionately higher cancellation rates, but that is an external equity observation recorded outside the compliance engine's own logic and not officially disaggregated within it. This Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served jobseekers; that exposure is documented in the case file and measured outside any diagram like this one.
What this example does not show
- Two cohorts must be kept distinct and only the first is a confirmed count: the first Ombudsman report's cohort of at least 1,009 unlawfully cancelled jobseekers (a further 45 cancelled after the pause was ordered), and a far larger, still-expanding section 42AM review. For the second, the department previously published up to 9,510 unlawful cancellations or reductions, an advocacy estimate put potential exposure near 310,000, and in June 2026 Senate estimates a department official said the number was in the vicinity of that estimate but qualified that 55 to 70 percent may have legitimately lost eligibility, implying roughly 93,000 or potentially 100,000-plus. Those larger figures are ESTIMATES of POTENTIALLY unlawful cases pending case-by-case assessment, not confirmed cancellations.
- First Nations people are reported to have experienced disproportionately higher cancellation rates. The Lab models institutional workflow propagation, not demographics, and estimates no differential harm to served jobseekers; that concentration is an external equity observation recorded outside the compliance engine's own logic, documented in the case file and measured outside any diagram like this one.
- The system-scale figures (roughly 2.5 million suspension notices a year to about a million people, 200,000 to 240,000 people facing suspension threats each quarter, nearly half of all employment-service users having faced a suspension threat) derive from advocacy and analysis of departmental data; they are directionally consistent across sources but exact denominators and periods vary.
- The commissioned assurance review that helped surface the IT instability was itself found to contain fabricated citations — a non-existent court quote and non-existent academic references; the department released a corrected version and the reviewer partially refunded its fee. Its core operational findings were independently corroborated by the Ombudsman, but its citations should be treated with caution.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Public benefits & eligibility domain page.
Levers available here and the patterns behind them
- Gate record entries — Human-in-the-loop write gating
- Check with a second model — Cross-model verification
- Check copied records — Reconcile copied records
- Review on schedule — Oversight cadence & retrospectives
- Pause AI on alarms — Deployment circuit-breaker
- Vet connections — Connection authorization
- Understand the system — Understand the system
- Assign a challenger — Structured dissent
- Upgrade model — Improve the model
- Escalate checks — State-feedback vigilance
- Keep skills sharp — Deskilling-arrest mandate
Documented case histories
- Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
- Michigan MiDAS
- Robodebt (Australia)
- Indiana / IBM eligibility modernization
- Rotterdam welfare-fraud risk model
- Arkansas ARChoices / ARIA
- Netherlands childcare-benefits scandal (Toeslagenaffaire)
- SyRI (Netherlands)
- CNAF benefit-fraud risk score (France)
- Forsakringskassan VAB fraud-selection profile (Sweden)
- Udbetaling Danmark data-driven control (Denmark)
- BOSCO (Spain)
- Serbia Social Card (Socijalna karta)
- UK DWP Universal Credit Advances fraud model
- ID.me identity verification as an unemployment eligibility gate
- Medicaid unwinding: automated ex parte renewal at population scale
- INSS auto-analysis: when the productivity metric makes denial the fastest way out
- Samagra Vedika
- NYC MyCity business chatbot
- Nevada DETR generative-AI unemployment appeals
- Tennessee TennCare TEDS