Skip to content

PAN Lab example

Samagra Vedika

The match that cancels you: entity resolution as eligibility

In India's Telangana state, Samagra Vedika matches people across thirty-plus databases. A similarly-named stranger's car, matched to a household, could cancel its ration card unannounced.

See more

Samagra Vedika is a data-matching system built and run by the Department of Information Technology of Telangana, a state in India. It works out which records in thirty-plus government databases belong to the same resident, a task called entity resolution. From that merged profile it flags who qualifies for welfare, mainly ration cards, which entitle a household to subsidized food.

How it is used

The eligibility flag is the matcher's marker of whether a household qualifies. Officials had to consult it before deciding a household's eligibility.

The system was built on the 2014 Samagra Kutumba household survey, which gathered socio-economic data on roughly 30 million residents. It links records of pensions, land and houses, electricity and water connections, ration cards, and vehicle registrations. From them it builds a consolidated "360-degree profile" of each resident.

A private vendor supplied the matching engine. The case file does not name the vendor. The engine matches people on name, address, date of birth, phone number, and father's name. Its disclosed steps include a machine-learning comparison. Whether it uses other methods beyond those steps is not established. The developers reportedly had access to more than 380 million records.

It was first developed around 2016 for law-enforcement use. It was then piloted for ration eligibility and, by 2018, applied across most state welfare schemes.

What went wrong

The case file finds the core error is a false match. The matcher attributes a similarly-named third party's asset to the applicant, and the eligibility flag flips with no notice.

Bismillah Bee, a 67-year-old widow, was denied rations for more than seven years. The system had linked her late husband, a rickshaw puller, to a car owned by a similarly-named third person. Maher Bee's family's application was rejected because the family was said to own a four-wheeler, meaning a car. They were declared eligible only after a Telangana High Court ruling.

Between 2014 and 2019, Telangana cancelled more than 1.86 million existing ration cards and rejected 142,086 fresh applications without notice. Coverage reports figures against slightly different periods and baselines, such as "about 20 lakh" (2 million) cards cancelled since 2016. They agree in order of magnitude.

Who decides

Officials were formally able to override the matcher with evidence. Reporting describes officials who deferred to it instead and declined to overturn its verdict. They treated its errors as backend "technical" issues. This is automation bias: relying on an automated system instead of one's own judgment.

There is no route set down in law to contest an algorithmic exclusion. So the burden of proof falls on the excluded person. Cases are often resolved only at the High Court or the Supreme Court. Corrections won this way were not systematically added back into the matcher.

The court-ordered re-verification

In April 2022, the Supreme Court of India ordered field re-verification of about 1.9 million deleted cards. It acted on a petition by the activist SQ Masood, of the Association for Socio-Economic Empowerment of the Marginalised.

A partial re-verification re-processed 205,734 cases and approved 15,471 of them as eligible after all. That is roughly 7.5 percent wrongful rejection. It is a lower bound from an incomplete review. Reporters and petitioners argue it understates the true rate.

What each side says

The government has defended the system. It cites a self-reported 95 percent fraud-filtering "efficiency", up from 84 percent. That figure measures how well the system filters out applications the government counts as spurious, not how many people were wrongly excluded. No independent accuracy data has been published.

Amnesty International's 2024 technical investigation confirmed serious human-rights concerns. It could not complete an audit, because the system is proprietary and closed. Neither the developer nor the government released source code or accuracy data.

The law around it

Commentators set the harm against India's protections for food. The right to food is protected under Article 21, the right to life, as affirmed in People's Union for Civil Liberties v Union of India (2001). The National Food Security Act 2013 provides subsidized food to about two-thirds of India's population.

The Digital Personal Data Protection Act 2023 exempts government processing. It offers no remedy that holds an algorithm to account.

What happened next

The system was not retired after the documented errors. The same entity-resolution technology was reused to issue new ration cards in 2024 and 2025. It was combined with a November 2024 Comprehensive Family Survey and fresh field verification by revenue officials.

In October 2018, Telangana had offered the system to India's national government as a national 360-degree profiling model. That raised concerns about mass surveillance. No AI model identifier for the matching engine is documented. Its internals beyond the disclosed steps remain undisclosed.

How the case file reads it

The case file notes that a wrong match does not show up as an error. It shows up as a fact about the household, such as "this applicant owns a car". So the household has to prove the fact false, instead of appealing a miscalculation.

The case file says the leverage lies in checking each match against its source, not in making the matcher more accurate. The controls it names make a matched fact agree with its source before it can cancel a card. They are a check of each matched fact against its source, and an independent second match aimed at shared-name collisions.

The case file also sets this case against others. MiDAS, Michigan's unemployment-fraud system, removed the human reviewer, while here the reviewer was kept but deferred to the matcher. Rotterdam's welfare-fraud risk model was opened and audited for bias, while here the audit was blocked. SyRI, a Dutch welfare-fraud profiling system, was struck down before its harms were counted, while here a court ordered re-verification, not a halt.

What the available tools can and cannot address

A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. A tool closes a failure pathway when mistakes stop passing along it. The work along it goes on.

This case has a budget of 13 units. Explore (No Targets) sets no targets.

Under Service Targets Only, the targets can be met within the budget. The cheapest ways cost 5 units. Each pairs Vet connections with Peer sharing rules, Escalate checks, or Keep skills sharp. Three ways without Vet connections cost 7 units. Two use Store less data and Peer sharing rules, one with Escalate checks and one with Keep skills sharp. The third uses Review on schedule and Escalate checks, with Peer sharing rules at its stronger setting.

Under Service and Safety Targets and All Governance Targets, the targets also include closing every failure pathway. They can be met, but only just. Every combination of tools within the budget was checked. Exactly one meets them, and it costs all 13 units. It uses Understand the system, Vet connections, Store less data, Escalate checks, and Peer sharing rules.

At these two levels, Understand the system costs 4 units. While it is on, Escalate checks, Keep skills sharp, Check copied records, and Check with a second model each cost 1 unit less. Under All Governance Targets, Vet connections closes none of its pathways without Understand the system. Store less data, Peer sharing rules, and Check copied records also work less well without it.

Check copied records and Check with a second model add the two checks the case file points to. Check copied records adds the owner check before cancellation, and closes no failure pathway. Check with a second model adds the second, independent match, and closes One match logic for all. Neither is part of the one way to meet the targets at the two upper levels. Keep skills sharp, Require sign-off, Review on schedule, and Upgrade model close no failure pathway.

More checking is not always better here. All eleven tools at their standard settings cost 23 units, or 24 at the two upper levels. At their strongest settings they cost 37. Either way they close every failure pathway, yet they meet the targets at none of the three levels that set them. The added checks hold back so much of the matcher's useful work that the service targets are missed.

Stylized model of a documented deploymentPublic benefits & eligibility

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Samagra-Vedika-class entity-resolution eligibility matcher network: 6 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 3 assumed · 4 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

Show all 7 assumptions
  • assumed

    This example follows the Lab's case file on how Samagra Vedika matched records to flag eligibility. It is not a reconstruction of the actual matching engine, whose internals are undisclosed.

  • baseline

    The feature that defines this example is a check the sources do not describe. They describe no step that compared a matched asset with its true owner before the flag led to a cancellation. So the example includes two checks that a tool can add: an owner check before cancellation, and a second, independent match. The documented source of error was a false match: a similarly-named third party's asset attributed to the applicant.

  • baseline

    This example assumes one matching logic runs over roughly 30 million residents. So one flaw in matching shared or common names repeats as the same wrongful cancellation across many households, instead of averaging out. In the case of MiDAS, Michigan's unemployment-fraud system, one uniform rule set produced tens of thousands of wrongful fraud determinations, one flaw repeating at caseload scale.

  • baseline

    This example assumes officials stayed in the process but deferred to the matcher. The case file describes officials who had to consult it and could override it with evidence. Reporting says they declined to overturn it, even against contrary evidence. So the example includes their corrections. The sources say corrections came only through appeals or court cases, not through officials' routine judgment. This is automation bias: relying on an automated system instead of one's own judgment.

  • baseline

    This example includes the thirty-plus government databases, because the matcher joins their records into each resident's consolidated profile. What that joining gathers about people comes from the case file. The network does not calculate it.

  • assumed

    This example includes the consolidated 360-degree profile, because the case file describes one merged profile for each resident. No pathway in the example runs through it, so it changes nothing the example shows.

  • assumed

    This example does not show the harms to individuals, which the case file documents. A 67-year-old widow was denied rations for more than seven years after the system linked her late husband to a third party's car. A family was declared eligible only after a High Court ruling. Reporting describes those harmed as poor households who rely on rations. The example shows how errors move among the matcher, the officials, and the records, not who the people are. It estimates no difference in harm between groups of people served.

What this example does not show

Show all 2 limitations
  • This example does not show who was harmed. Reporting describes those harmed as poor households who rely on rations. The case file documents individual cases. The example shows how errors move among the matcher, the officials, and the records. It estimates no difference in harm between groups of people served. That harm is documented in the case file and measured outside the network.
  • This example does not use measured error rates. The wrongful-rejection figure, roughly 7.5 percent, comes from an incomplete, court-ordered re-verification: at least 15,471 of 205,734 re-processed cases. It is a lower bound, not a full audit. The system is proprietary, and no accuracy data has been released. So the example uses the shape of the case, not calibrated rates. The government's 95 percent "efficiency" figure is a self-reported measure of fraud filtering, not a wrongful-exclusion rate.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • Samagra Vedika, an entity-resolution system built by the Telangana government, decided welfare eligibility by matching residents across thirty-plus government databases into a consolidated profile; between 2014 and 2019 more than 1.86 million ration cards were cancelled and 142,086 fresh applications were rejected without notice. Its core error was entity-resolution false-positive matching, in which a similarly-named third party's asset was attributed to the applicant and silently flipped the eligibility flag. After the Supreme Court of India ordered field re-verification in April 2022, a partial re-verification found roughly 7.5 percent wrongful rejection (at least 15,471 approved of 205,734 re-processed cases), a lower bound from an incomplete review; the system is proprietary and closed and an independent technical audit could not be completed, with no source code or accuracy data released. The government cited a self-reported 95 percent fraud-filtering efficiency, which measures spurious-application filtering rather than the wrongful-exclusion rate.

    empirical
    • Advocacy Amnesty International, Use of Entity Resolution in India: Shining a light on how new forms of automation can deny people access to welfare (2024) https://www.amnesty.org/en/latest/research/2024/04/entity-resolution-in-indias-welfare-digitalization/
    • Investigative Tapasya, Kumar Sambhav and Divij Joshi, How an algorithm denied food to thousands of poor in India's Telangana (Al Jazeera, with The Reporters' Collective and the Pulitzer Center AI Accountability Network) (2024) https://www.aljazeera.com/economy/2024/1/24/how-an-algorithm-denied-food-to-thousands-of-poor-in-indias-telangana
    • Academic Tushar V Sharma, Algorithmic Welfare Exclusion and the Right to Food in India: Lessons from Samagra Vedika (Oxford Human Rights Hub, University of Oxford) (2026) https://ohrh.law.ox.ac.uk/algorithmic-welfare-exclusion-and-the-right-to-food-in-india-lessons-from-samagra-vedika/
    • Trade press Sumit Jha, Telangana employs same tech to issue new ration cards that deleted 20 lakh names (The South First) (2024) https://thesouthfirst.com/telangana/telangana-employs-same-tech-to-issue-new-ration-cards-that-deleted-20-lakh-names/
    • Investigative Kumar Sambhav, Exclusive: Telangana offered its own 360 degree citizen tracking system to the Modi government (The Reporters' Collective; originally HuffPost India) (2020) https://www.reporters-collective.in/stories/exclusive-telangana-offered-its-own-360-degree-citizen-tracking-system-to-modi-govt
    • Investigative Pulitzer Center AI Accountability Network, How an algorithm denied food to thousands of poor in India's Telangana (2024) https://pulitzercenter.org/stories/how-algorithm-denied-food-thousands-poor-indias-telangana
  • A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.

    empirical
    • Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
    • Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold
  • Under Samagra Vedika, exclusions were silent and there was no statutory route to contest an algorithmic decision, so the burden of proof fell on the excluded person: reporting describes officials who, though formally able to override the algorithm with evidence, deferred to it and declined to overturn its verdict, treating errors as backend technical issues. Documented individual harms include a 67-year-old widow denied rations for more than seven years after the system linked her deceased husband to a car owned by a similarly-named third person, and a family rejected for allegedly owning a four-wheeler that was declared eligible only after a Telangana High Court ruling. Corrections came through individual litigation and did not systematically feed back into the model, and the same entity-resolution technology was reused to issue new ration cards in 2024-2025.

    empirical
    • Investigative Tapasya, Kumar Sambhav and Divij Joshi, How an algorithm denied food to thousands of poor in India's Telangana (Al Jazeera, with The Reporters' Collective and the Pulitzer Center AI Accountability Network) (2024) https://www.aljazeera.com/economy/2024/1/24/how-an-algorithm-denied-food-to-thousands-of-poor-in-indias-telangana
    • Investigative The Reporters' Collective, A poor woman is declared rich; a living man dead. Their food and pension stopped by government (2024) https://www.reporters-collective.in/twitter-threads/a-poor-woman-is-declared-rich-a-living-man-dead-their-food-and-pension-stopped-by-government
    • Academic Tushar V Sharma, Algorithmic Welfare Exclusion and the Right to Food in India: Lessons from Samagra Vedika (Oxford Human Rights Hub, University of Oxford) (2026) https://ohrh.law.ox.ac.uk/algorithmic-welfare-exclusion-and-the-right-to-food-in-india-lessons-from-samagra-vedika/
    • Advocacy Amnesty International, Use of Entity Resolution in India: Shining a light on how new forms of automation can deny people access to welfare (2024) https://www.amnesty.org/en/latest/research/2024/04/entity-resolution-in-indias-welfare-digitalization/
    • Trade press Sumit Jha, Telangana employs same tech to issue new ration cards that deleted 20 lakh names (The South First) (2024) https://thesouthfirst.com/telangana/telangana-employs-same-tech-to-issue-new-ration-cards-that-deleted-20-lakh-names/

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Public benefits & eligibility domain page.

Levers available here and the patterns behind them

Documented case histories