PAN Lab example
Home Office IPIC
A human decides and the form only asks why not
IPIC, a Home Office algorithm, recommends migrants for immigration decisions or enforcement. Officials must justify rejecting its recommendation, not accepting it. Is their review real?
See more
IPIC, short for Identify and Prioritise Immigration Cases, is an algorithm run by the UK Home Office, the government department responsible for immigration. It recommends migrants for immigration decisions or enforcement action, such as returns from the UK, immigration bail conditions, and casework. It draws on detention, health and vulnerability, and location-monitoring data.
How it is used
On paper IPIC supports a decision rather than making it. It produces a recommendation, and a human official makes the final call. The case file calls this the standard reassurance offered for automated tools in high-stakes government settings.
The recommendations cover returns from the UK, immigration bail conditions, and casework. The casework includes cases under the EU Settlement Scheme, the scheme through which EU citizens living in the UK apply for the right to stay. The data includes detention records, health and vulnerability information, and GPS tracking imposed on people as a bail condition.
What the training materials show
The Home Office's training materials for IPIC describe how officials handle a recommendation. An official who rejects one must record a reason. An official who accepts one need record nothing. Privacy International reports that a rejected recommendation can also be changed for longer than an accepted one.
Privacy International, a civil-society group, obtained the materials after about a year of freedom of information requests. It had to complain to the UK's information regulator, the Information Commissioner's Office, before the Home Office disclosed them. It published its findings on 17 October 2024.
Who decides
The official makes the final call. Accepting a recommendation is effortless, and rejecting it is work. The case file argues that this builds a rubber-stamping incentive into the workflow, so the human review becomes a formality.
Automation bias is the pull to defer to a machine's recommendation. It is usually treated as a habit to train away. The case file argues that here the process itself makes deferring the easier path. A human makes the final decision, and that can be true and empty at once.
The pressure on the review
Privacy International points to punishing targets and casework backlogs. It asks what would stop officials rubber-stamping recommendations, since accepting takes less work than looking critically and rejecting. It quotes Jeremy Bloom, a consultant solicitor at the law firm Duncan Lewis: "IPIC recommendations are sometimes accepted by officials without any reasons given."
The sources read for this case give no rate of accepted or rejected recommendations.
Who is told
The case file says applicants are frequently not told that AI is used in their case. Privacy International says migrants are given no information about the algorithm or how it uses their data. So the person a recommendation is about cannot contest it.
The case file argues that this disables both checks that could catch an error. The official is nudged to accept, and the person is kept from objecting.
The complaint to the regulator
On 18 August 2025, Privacy International filed a complaint with the Information Commissioner's Office about IPIC and a second Home Office algorithm, the Electronic Monitoring Review Tool. The complaint alleges that the Home Office failed to carry out a lawful data protection impact assessment, which it says the law requires. That is a written assessment, made before personal data is used, of the risks to people. The complaint also alleges that the human review is inadequate.
The sources also record that IPIC is not listed in the UK government's algorithmic transparency register.
What this case does not claim
This case is not a claim that IPIC is biased. It may or may not be, and the documents do not show it. It is about a decision process designed so that the algorithm's output is the default outcome. No accuracy figures for IPIC have been published.
What this network is drawn from
This network follows the pattern the case file describes. It does not reconstruct the actual system. It shows IPIC, the officials, the case records, the GPS monitoring data, the written reason for a rejection, and the actions that follow. It also shows the two checks the case file calls for. The people being triaged are outside the network.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. A tool closes a pathway when mistakes stop passing along it. The work along it may go on.
This case has a budget of 12 units, and it starts under one pressure, Workload surges. Explore (No Targets) sets no targets. The other three levels all ask for the network's mistakes to be contained, meaning corrected rather than building on each other.
Under Service Targets Only, the targets can be met, though no single tool meets them. The cheapest combination costs 4 units: Mark AI-written records and Escalate checks. Three others cost 5 units. One is Mark AI-written records at its stronger setting, with Escalate checks. The others pair Mark AI-written records with Gate record entries, or with Assign a challenger at its stronger setting.
Every combination that meets these targets includes Mark AI-written records or Escalate checks. Without Mark AI-written records, the cheapest combinations cost 8 units, and each uses Escalate checks at its stronger setting. It is paired with Peer sharing rules and Review on schedule, with Assign a challenger and Review on schedule, or with Assign a challenger and Peer sharing rules. With Dynamics set to Off, two more combinations cost 5 units. They pair Mark AI-written records with Store less data, or with Peer sharing rules at its stronger setting.
Under Service and Safety Targets, this case is not fully addressable with the available tools, at any price. This level also asks you to close every failure pathway and to keep up with the work, among other targets. Seven pathways are open before any tool is used. The first four are Recommendation to the official, Official's accept or reject decision, Decision written to the case record, and Case data read by IPIC. The other three are Case history read by the official, Location data read by IPIC, and Accepted recommendation becomes an action.
No tool on offer closes Official's accept or reject decision or Accepted recommendation becomes an action. The second of them also keeps draining the Privacy gauge. The Work getting done gauge reads strained under every combination of tools.
Under All Governance Targets, the targets cannot be met either, for the same reasons. Money is not what stops it. No combination meets the targets at these two levels even with the budget lifted.
More is not better here. Using every tool at its strongest setting costs 30 units, well over the budget of 12. It contains the mistakes, but the same two pathways stay open and the work stays strained. It meets the targets at none of the three levels that set them. Under Service Targets Only, the benefit IPIC brings to the work then falls below what the targets ask.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Enforcement-triage-class where oversight is hollow by design network: 7 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 5 assumptions
- assumed
Three documented parts of this deployment shape the network. First, the written reason for a rejection is drawn as a step on a form, because the disclosed training materials show it. Officials must record a reason to reject a recommendation but none to accept one. So the two choices cost different amounts of work before anyone looks at the case. Second, location data from electronic monitoring is drawn as its own input, apart from the case records. Third, an accepted recommendation becomes a return, a bail condition, or a casework step. The sources describe no check of that action against the case file first. So the network shows three gaps around each decision: rejecting costs more work, the person is not told, and the sources describe no review of the action. Privacy International points to punishing targets and casework backlogs. The network assumes this workload makes the easy, deferring path the one officials take.
- baseline
This network follows the enforcement triage pattern the case file describes. It does not reconstruct the actual system. IPIC recommends people for returns, bail conditions, and casework. It draws on detention, health and vulnerability, and location-monitoring data. About a year of freedom of information requests, escalated to the UK's information regulator, uncovered the one-sided rule on reasons. The rule and the gap in telling applicants are findings from those requests and from Privacy International's analysis. They are not judgments about any individual case.
- baseline
The one-sided rule makes accepting a recommendation effortless and rejecting it work. The case file argues that this makes deferring the rule rather than a tendency. So the claim that a human makes the final decision can be true and empty at once. The case file calls this the clearest documented case, among those collected here, of automation bias built into an agency's workflow. Automation bias is the pull to defer to a machine's recommendation. The network includes a review that asks as much of accepting as of rejecting, as a check this design does not provide. Whether oversight is real depends on how the process is designed, not on the organization chart.
- assumed
The second check this design does not provide is telling the affected person. The case file says applicants are frequently not told that AI is used. So the person a recommendation is about cannot challenge it. With the official nudged to accept and the person kept from objecting, both checks that could catch an error are off at once. The case file argues that telling the person is not a courtesy. It is often the last correction left when the internal review is designed toward deference. This is not a claim that IPIC is biased, only that the process is designed toward deference.
- assumed
The network models no enforcement outcome and no individual's case. It shows how mistakes pass between the parts of the Home Office's triage process. The people being triaged are outside the network. The rule on reasons, the sensitive data IPIC draws on, and the gap in telling applicants are recorded in the case file. None of them is computed from this network.
What this example does not show
Show all 2 limitations
- This example does not show any enforcement outcome or any individual's case. It shows how mistakes pass between the parts of the Home Office's triage process. The people being triaged are outside the network. The one-sided rule on reasons, the sensitive data IPIC draws on, and the gap in telling applicants are recorded in the case file, not computed here.
- This example does not show a measured rate of rubber-stamping, or any measure of IPIC's accuracy. The rule on reasons and the gap in telling applicants are findings from freedom of information requests and Privacy International's analysis. They are not rulings on any individual case. Nothing here claims that IPIC is biased, only that the process is designed toward deference. The network includes the even-handed review and the affected person's ability to contest as two checks this design does not provide.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
A government's immigration-enforcement triage algorithm identifies and recommends people for enforcement actions — returns, bail conditions, casework — drawing on sensitive data including detention, health, vulnerability, and location-monitoring records. Uncovered through roughly a year of freedom-of-information litigation, its training materials show an asymmetric override design: officials must record a justification for rejecting a recommendation but not for accepting one. That design builds a rubber-stamping incentive into the workflow — accepting the algorithm is frictionless, overriding it requires work — so the human in the loop is nominal rather than a real check. It is the corpus's clearest documented instance of automation bias engineered into an agency workflow, in one of the highest-stakes enforcement settings a state operates.
empirical- Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://privacyinternational.org/news-analysis/5452/automating-hostile-environment-uncovering-secretive-home-office-algorithm-heart
- Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://www.whatdotheyknow.com/request/identify_and_prioritise_immigrat_3
The lesson the case carries is that nominal human oversight is not real oversight. An asymmetric override — where accepting the algorithm's recommendation is frictionless and rejecting it requires a recorded justification — engineers automation bias into the process by making deference the path of least resistance, so the claim that a human makes the final decision can be true and empty at once. Two governable surfaces follow. Whether the review is genuinely symmetric: the official as free and as prompted to reject as to accept, so an error is as likely to be caught as waved through. And whether the affected person is told the AI is used and can contest it: applicants are frequently not told, which severs the correction on the side that could challenge the recommendation, so the one check that survives the asymmetric override — the person it is about — is cut out too.
empirical- Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://privacyinternational.org/press-release/5640/privacy-international-issues-complaint-uk-regulator-regarding-deployment-two
- Advocacy Privacy International (2024, October 17). Automating the hostile environment: uncovering the secretive Home Office algorithm at the heart of immigration enforcement (IPIC); with the 2025 ICO complaint and the primary FOI trail. https://www.whatdotheyknow.com/request/identify_and_prioritise_immigrat_3
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
All of them in context on the Immigration & asylum AI domain page.
Levers available here and the patterns behind them
- Assign a challenger — Structured dissent
- Gate record entries — Human-in-the-loop write gating
- Mark AI-written records — Provenance labeling
- Peer sharing rules — Peer-edge governance
- Review on schedule — Oversight cadence & retrospectives
- Store less data — Data minimization
- Escalate checks — State-feedback vigilance
- Upgrade model — Improve the model