PAN Lab example
Indiana / IBM eligibility modernization
Denied for 'failure to cooperate': a privatized eligibility pipeline
Indiana outsourced welfare eligibility to an IBM-led consortium. Over a million denials followed in its first years, many for procedural 'failure to cooperate'.
See more
A consortium led by IBM and Affiliated Computer Services ran welfare eligibility for Indiana under a ten-year contract from 2006. Its system, launched in 2007, replaced caseworker relationships with call centers, document imaging, and automated timeliness rules. When a document was not matched to a case in time, the rules denied or closed the case for 'failure to cooperate'.
What happened
By 2009, more than a million Indiana residents had lost or been denied food stamps, Medicaid, or cash benefits, The Nation reports. That was a 54 percent increase in denials over the previous three years.
Many denials were for procedural 'failure to cooperate in establishing eligibility,' not for being ineligible. The phrase names a procedural category. It is not a finding that any applicant refused to cooperate.
How the denials happened
Applicants faxed millions of pages of documents to a processing center in Marion. So many disappeared that advocates called it 'the black hole in Marion,' The Nation reports.
If one page among dozens was too dark to read, damaged in transmission, or indexed to the wrong case, the application was denied. Applicants who waited on hold and then could not receive a callback were also denied for 'failure to cooperate.' This example draws the document route only.
The case file calls the automation less a model than a rigid procedural pipeline. The harm ran through the document pipeline, not through a fraud score.
The system began in a pilot area and then reached 47 more counties, The Nation reports. One set of vendor rules decided every case in the counties it reached. So a single procedural flaw repeated across the caseload instead of scattering.
Who was left to catch mistakes
Caseworkers were no longer responsible for families, The Nation reports. They became responsible for tasks assigned through a computerized queue, and applicants dealt with private call centers.
The case file reads the harm this way. When denial is the default and no one is left to resolve a document lost, unreadable, or filed to the wrong case, routine failures become mass denials.
Why it was built this way
Cost-cutting targets drove the modernization, the case file says. The error the system was built to prevent was overpayment, not wrongful denial. The case file calls that a governance choice, and usually an unexamined one.
How it ended
Governor Mitch Daniels admitted the experiment was a failure and canceled the state's contract with IBM, The Nation reports. Government Technology dates the cancellation to October 2009, about three years into the ten-year contract.
Indiana and IBM then sued each other, and the case file records years of litigation. This case does not judge who was right.
The cancellation is the one documented use of the state's power to stop the system. The sources describe no earlier halt.
Where the facts come from
The facts here come from four sources. They are Virginia Eubanks's 2018 book Automating Inequality and her article in The Nation, "Want to Cut Welfare? There's an App for That." The others are reports on the lawsuits by Government Technology and IEEE Spectrum.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network, where a mistake made by one part can be passed on to the other. A closed pathway is one that mistakes stop passing along. The work along it may go on.
This case has a budget of 12 units. Contained means the network's mistakes are corrected rather than building on each other.
Under Explore (No Targets), which sets no targets, one tool keeps the mistakes contained: Vet connections, at 3 of the 12 units. Under Service Targets Only, the same tool also meets the targets. That level asks for the automated system to be helping the work.
Vet connections allows a connection between systems only where it is explicitly approved. On this network, three steps each connect two systems with no person between them. They are the scanning of documents into the case store, the rules' reading of the case file, and the automatic closure. Vetting those connections stops mistakes passing along all three. The one rule set also repeats fewer mistakes.
Under Explore, Gate record entries with Escalate checks also keeps the mistakes contained, for 5 units. With every tool at its standard setting, every combination that meets the targets under Service Targets Only includes Vet connections. At stronger settings a few do without it. One is Escalate checks with Gate vendor updates at its stronger setting, for 5 units.
Under Service and Safety Targets and All Governance Targets, this case is not fully addressable with the available tools. Both levels ask you to close every failure pathway, among other targets.
Closing every failure pathway fits the budget. The cheapest way costs 9 of the 12 units: Gate record entries, Understand the system, and Vet connections. Understand the system costs 4 units at these levels. While it is on, Vet connections costs 2 instead of 3.
Every combination that closes every failure pathway includes all three. Vet connections and Understand the system together leave one pathway open: the rules writing determinations into the case record. With those two alone, the automated system is clearly helping the work.
Gate record entries closes that last pathway, and the system's help goes with it. No combination that closes every failure pathway leaves the automated system helping the work. The best leaves it not helping.
More money does not change that. With the budget set aside and every tool at its stronger setting, every failure pathway closes, and the automated system ends up hurting the work.
That is a finding about the deployment, not a gap in your approach. Here the system's help and its harm run through the same entry in the case record.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Indiana-class privatized eligibility pipeline network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 4 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 7 assumptions
- assumed
This example follows the pattern of the Indiana eligibility system run by an IBM-led consortium, as its case file documents. It does not rebuild the real system.
- baseline
The system here denies by default when a document is not matched in time. The case file records over a million denials in the early years, many for procedural 'failure to cooperate' rather than ineligibility. The sources describe no check of whether a document arrived before a case was closed. The tool Check copied records adds one, which here compares each closure with the documents received.
- baseline
The system replaced caseworkers' relationships with families with call centers and a queue of tasks. Workers had little power to reverse a determination. So a document lost, unreadable, or filed to the wrong case becomes a denial, instead of being resolved by someone who knows the family.
- baseline
One set of vendor rules decides every case in the counties it reached. So a single procedural flaw produces denials across the caseload at once, instead of scattered errors. That emphasis is this example's own reading, not a measured figure.
- baseline
The state used its contract once to stop the system, by canceling it in 2009, not as a standing review. Indiana and IBM then sued each other. The sources describe no standing power to halt the system before then. The tool Assign a challenger adds one, which here puts the state's power to halt into regular use. This example does not judge the lawsuits.
- assumed
A private vendor scanned and stored applicants' sensitive paperwork, so that step is marked as touching private data. The harm the sources document is denial, not misuse or disclosure of data. Nothing here implies a breach.
- assumed
The people denied, including low-income, elderly, and disabled applicants and families, are not shown in this example. It shows how mistakes move between the system, staff, and records. It estimates no difference in harm between groups of people. The case file documents that harm.
What this example does not show
Show all 3 limitations
- 'Failure to cooperate' names the procedural denial category in the sources. It is not a finding about any applicant's conduct. The automatic denial here is the system's behavior, not a claim that applicants did not cooperate.
- Indiana and IBM sued each other after the cancellation, and the case file records that litigation. This example does not judge it. The contract part of the network shows the state's power to stop the system, not who was right.
- The people denied, including low-income, elderly, and disabled applicants and families, are not shown in this example. It shows how mistakes move between the system, staff, and records, and estimates no difference in harm between groups. The case file documents that harm.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
Indiana's privatized eligibility modernization produced over a million denials in its early years — many procedural rather than substantive — before the state canceled the contract and litigated with its vendor.
empirical- Investigative Eubanks, Automating Inequality (2018); The Nation, Want to Cut Welfare? There's an App for That https://www.thenation.com/article/archive/want-cut-welfare-theres-app/
- Investigative Government Technology, IBM and Indiana Suing Each Other https://www.govtech.com/health/ibm-and-indiana-suing-each-other.html
- Investigative IEEE Spectrum, Indiana and IBM Sue Each Other Over Failed Outsourcing Contract https://spectrum.ieee.org/indiana-and-ibm-sue-each-other-over-failed-outsourcing-contract
A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.
empirical- Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
- Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
All of them in context on the Public benefits & eligibility domain page.
Levers available here and the patterns behind them
- Gate record entries — Human-in-the-loop write gating
- Check copied records — Reconcile copied records
- Understand the system — Understand the system
- Escalate checks — State-feedback vigilance
- Gate vendor updates — Vendor quality gate
- Pause AI on alarms — Deployment circuit-breaker
- Require sign-off — Conformity assessment gate
- Review on schedule — Oversight cadence & retrospectives
- Vet connections — Connection authorization
- Assign a challenger — Structured dissent
- Upgrade model — Improve the model
Documented case histories
- Indiana / IBM eligibility modernization
- Michigan MiDAS
- Robodebt (Australia)
- Rotterdam welfare-fraud risk model
- Arkansas ARChoices / ARIA
- Netherlands childcare-benefits scandal (Toeslagenaffaire)
- SyRI (Netherlands)
- CNAF benefit-fraud risk score (France)
- Forsakringskassan VAB fraud-selection profile (Sweden)
- Udbetaling Danmark data-driven control (Denmark)
- BOSCO (Spain)
- Serbia Social Card (Socijalna karta)
- UK DWP Universal Credit Advances fraud model
- ID.me identity verification as an unemployment eligibility gate
- Medicaid unwinding: automated ex parte renewal at population scale
- INSS auto-analysis: when the productivity metric makes denial the fastest way out
- Samagra Vedika
- Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
- NYC MyCity business chatbot
- Nevada DETR generative-AI unemployment appeals
- Tennessee TennCare TEDS