PAN Lab example
Gladsaxe model
The screen that never ran: whole-population child scoring
Gladsaxe, a Danish municipality, built a model to score every young child for vulnerability. It was stopped in development and never ran on live cases.
See more
The Gladsaxe model was a decision tree that Gladsaxe Municipality, a Copenhagen suburb in Denmark, built in house. A decision tree reaches an estimate through a series of questions about a case. This one was to estimate, for every child aged 0 to 6, the probability that the child was living in vulnerability.
Why Gladsaxe built it
Gladsaxe is a municipality of about 70,000 people on the edge of Copenhagen. In 2016 its family department found that children in distress were typically first identified around age 8 to 12. A case review showed different municipal departments had each noted earlier warning signs. Those signs were never connected into one picture.
The project's formal name was Dataunderstoettet Tidlig Opsporing af udsatte boern, or DTO. That means, roughly, data-supported early detection of vulnerable children. The case file calls it an early-detection project.
How it was meant to work
The model was built around about 44 risk indicators, drawn from about nine municipal data sources. It was to score every child aged 0 to 6, not only families already receiving help.
When a child's estimated probability rose above a set level, the model was to flag the case. A specialist adviser was to make a first assessment. The adviser could reject the case and delete it, or ask the family's consent for a full assessment. Without consent, the case was to be deleted.
The municipality meant the model only to identify cases. It was not to make casework decisions, in whole or in part.
What stopped it
The project first sought legal cover as a free-municipality project, which can allow exemptions from current law. In December 2017 the Ministry of Economy and Interior refused the exemption. The municipality then hoped for a legal basis in the new Data Protection Act. The Act, passed in May 2018, did not provide one.
The project became tangled in national debates over the government's "ghetto" package and over GDPR, the European Union's data protection rules. The package set special measures for neighbourhoods classed as "ghettos". It cited Gladsaxe's application as inspiration. In March 2018 a media storm compared it to surveillance states, among them East Germany.
In December 2018 four laptops were stolen from the city hall. One held a spreadsheet with about 20,000 citizens' personal identification numbers. The case file calls the theft unrelated to the project, but the media linked the two.
On 14 December 2018, in response, Liberal Alliance, a party in the governing coalition, withdrew its support. The project was put on hold in January 2019 and ended in its development phase that year. It never ran on live decisions.
What the case study found
A 2022 case study by Kenneth Kristensen found a "decoupled" chain of governance. Councillors had approved the project's purpose. They were not close enough to its method to explain or defend it when the media storm hit.
The case study found the municipality had the staff and skills to run the project. Professional organisations were brought in late, and citizens not at all.
What each side said
The municipality said the model was neither a points system nor mass surveillance, but a targeted use of data. The Danish Association of Social Workers feared the model would flag many families with no real cause for concern. It warned that would spend resources on the wrong families and worry many families without reason.
The case file's reading
Most cases in this collection turn on what a deployed system did. The case file reads Gladsaxe as a case about what a system was never permitted to do. Its decisive controls all sat ahead of the model itself: legal authorization, deployment sign-off, the scope of its data, and data-security capacity.
The municipality had a part-time data-protection officer, against an estimated need of ten to seventeen. The case file concludes that legitimacy, legal basis, and security capacity are controls in their own right. A failure of any one of them can stop a tool long before its accuracy is tested.
The double ethics
The case file calls Gladsaxe its clearest case of "double ethics". The case file's concern about profiling every young child has to be weighed against a documented cost. Warning signs left unconnected had kept vulnerable children unseen until age eight or later.
Gladsaxe's municipal director at the time used the phrase in a public debate in 2019. The case study reports the director's point: there are ethical questions in using the municipality's data about citizens, and also in not using it.
Where the facts come from
The facts here come from Offentlig AI, a university-run catalogue of AI in Danish public services, and Kristensen's 2022 case study. Other sources are a 2023 article by Helene Friis Ratner and Kasper Elmholdt, a 2021 Uppsala University law article by Katarina Fast Lappalainen, and Danish news reporting.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network, where a mistake made by one part can be passed on to the other. A pathway is closed when mistakes stop passing along it. The work along it can go on.
This case has a budget of 12 units. Explore (No Targets) sets no targets. There, any one tool except Require sign-off keeps mistakes contained: corrected rather than building on one another.
Under Service Targets Only, the targets can be met. That level also asks for the model to be helping the advisers' work. Vet connections alone meets them, for 3 units. Within the budget, 40 different sets of tools meet them, and every one includes Vet connections.
Under Service and Safety Targets, the targets can be met. That level adds closing every failure pathway, and it asks that the service not be strained. The cheapest combination costs 7 of the 12 units: Vet connections with Understand the system, which costs 4 units at this level.
Four sets of tools meet these targets, and each includes both of those tools. The other three add Require sign-off, Upgrade model, or both.
Under All Governance Targets, the targets are not fully addressable with the available tools. That level asks for the model to be clearly helping the work. No combination that keeps mistakes contained and closes every failure pathway does that. The best leaves the model helping, but not clearly.
More money does not change that. Every tool at its strongest setting at once costs 31 units, far over the budget. It closes every failure pathway, but the model then helps the work far less. It meets the targets at none of the three levels that set them.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Gladsaxe-class whole-population child screen network: 6 components and 14 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 4 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 7 assumptions
- assumed
This example follows the pattern the Gladsaxe model case file documents: a whole-population screen stopped before it ever ran. It does not rebuild the actual project.
- baseline
The model never ran on live cases. It was ended in its development phase, so this example shows the design, not a system that made real decisions. The design deleted a case when an adviser rejected it or the family declined consent. So this example assumes little is written back into the case records, and no score is kept for each family.
- baseline
This example treats the register data as the case's defining exposure, and marks it as sensitive. The model was to profile every child aged 0 to 6. That is a broader reach than the earlier tools it was modeled on, which scored only families receiving benefits.
- assumed
The design kept human judgment decisive. The model was to identify cases only, and a specialist adviser was to assess each one and delete it if the family did not consent. So this example assumes the flag weighs little in what advisers decide. Any tool used here should keep that judgment independent.
- baseline
The two routes to the Outside System stand for the data-security gap the case documents. In 2018 a stolen laptop held a spreadsheet with about 20,000 citizens' personal identification numbers. That theft was separate from the project. This example treats it as a sign of the same gap in the municipality's security capacity.
- baseline
One decision tree would have scored every young child. So a flaw in it would repeat across every case instead of averaging out. The link from the model back to itself stands for that shared reach.
- assumed
This example does not model demographics or unequal harm to families. The documented controversy centred on surveillance, transparency, and citizens' rights. The model never ran on live decisions, so no harm to real families from it is implied.
What this example does not show
Show all 3 limitations
- This model was stopped in development and never ran on live decisions. So nothing here implies harm to real families from the model. The 2018 data breach the media linked to it was a separate incident.
- The lasting public image is a points system that added up weighted points for each risk factor. The municipality and the peer-reviewed case study say the real model was an unfinished decision tree that was to estimate a probability. The widely quoted point values trace to media framing of the exemption application.
- This example shows how mistakes move through the institution, not who is affected. The documented controversy centred on surveillance, transparency, and citizens' rights. No measured difference between groups of families is claimed here.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
Gladsaxe's early-detection project (DTO) was a decision-tree model over about 44 risk indicators, meant to score, for every child aged 0 to 6 rather than only families already receiving help, the estimated probability that the child was living in vulnerability; per a university-run Danish public-sector AI catalogue it was to be trained on roughly 173,000 notifications the authorities received between April 2016 and December 2017, but only about 117 usable historical cases existed, and it was halted in its development phase in 2019 without ever running on live decisions, after a national media storm and an unrelated data breach that exposed about 20,000 citizens' personal identification numbers.
empirical- Academic Offentlig AI (university-run Danish public-sector AI catalogue), Gladsaxe-modellen project profile (n.d.) https://offentlig-ai.dk/projekter/gladsaxe-modellen
- Academic Kenneth Kristensen (Samfundslederskab i Skandinavien, Copenhagen Business School), Hvorfor Gladsaxemodellen fejlede: om anvendelse af algoritmer paa socialt udsatte boern (2022) https://rauli.cbs.dk/index.php/SiS/article/view/6542
- Academic Helene Friis Ratner and Kasper Elmholdt, Algorithmic constructions of risk: Anticipating uncertain futures in child protection services, Big Data and Society (2023) https://journals.sagepub.com/doi/10.1177/20539517231186120
- Academic Katarina Fast Lappalainen, Protecting Children from Maltreatment with the Help of Artificial Intelligence: A Promise or a Threat to Children's Rights?, De Lege 2021 (Uppsala University Faculty of Law) (2021) https://www.diva-portal.org/smash/record.jsf?pid=diva2:1653453
- Investigative TV 2 Kosmopol (formerly TV 2 Lorry), Computertyveri: 20.000 borgeres CPR-numre laekket (2018) https://www.tv2kosmopol.dk/gladsaxe/computertyveri-20000-borgeres-cpr-numre-laekket
A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
Where this connects
Institutional pressures in this domain
- Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
- Deadline pressure — Statutory or managerial timeliness rules reward fast approval of machine output over slow disagreement.
- Staff turnover — Experienced skepticism leaves; new staff calibrate their trust on the tool itself.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
All of them in context on the Child welfare & family services domain page.
Levers available here and the patterns behind them
- Store less data — Data minimization
- Vet connections — Connection authorization
- Require sign-off — Conformity assessment gate
- Review on schedule — Oversight cadence & retrospectives
- Assign a challenger — Structured dissent
- Keep skills sharp — Deskilling-arrest mandate
- Gate record entries — Human-in-the-loop write gating
- Upgrade model — Improve the model
- Understand the system — Understand the system
- Pause AI on alarms — Deployment circuit-breaker
Documented case histories
- Gladsaxe model
- Allegheny Family Screening Tool
- Allegheny Hello Baby
- Douglas County Decision Aide
- The score nobody sees: New York City's concealed severe-harm QA algorithm
- The audit that reached the legislature before it reached the tools: Colorado's safety and risk instruments
- Eckerd Rapid Safety Feedback: origin and spread
- Illinois Rapid Safety Feedback
- The vendor's ledger: Family-Match, the eharmony-derived adoption matcher the states kept coming back to
- ProKid (Netherlands)
- Insight Bristol / Think Family Database
- Hackney / Xantura Early Help Profiling
- Sistema Alerta Niñez (Chile)
- The map, not the score: place-based risk terrain and the records it concentrates
- The guardrail's blind side: DC's walled-off child-welfare chatbot that began writing into the case record
- US Birth Match
- Oregon Safety at Screening
- Los Angeles County Project AURA
- What Works for Children's Social Care ML pilots
- New Zealand MSD Predictive Risk Modelling