Skip to content

PAN Lab example

Udbetaling Danmark data-driven control (Denmark)

Standing surveillance by data-linking: a welfare-fraud control suite

Udbetaling Danmark's fraud-control models score Danish benefit recipients on data from about ten linked national registers. A control team decides which flagged cases to investigate.

See more

Udbetaling Danmark (UDK), Denmark's welfare-payments agency, has a fraud-control suite that used up to sixty models as of 2019. A Joint Data Unit links data on millions of residents from about ten national registers and from foreign authorities. The models score benefit recipients into a "wonderlist" of statistically high-risk people for a control team to filter.

Who runs it

UDK was set up in 2012 to centralise municipal welfare payments. They include child allowance, pensions, housing benefit, unemployment, maternity pay, and sick pay.

ATP (Arbejdsmarkedets Tillaegspension), a quasi-public body, administers the fraud control on UDK's behalf. ATP has private firms, including the IT supplier NNIT, build some of the models. In the case file's reading, that split between public and private is part of the accountability critique.

In 2021 UDK paid about 241 billion Danish kroner (about 32.3 billion euros) to roughly 2.4 million recipients. That is on the order of half of Denmark's adult population.

How it is used

The Joint Data Unit links the registers and builds and runs the models. The models output the wonderlist, a question list of statistically high-risk people.

UDK's HOK register unit, its control team, and municipal control units filter those requested cases into established control cases before investigating. The investigations can go up to the most invasive checks. Human controllers, not the models, make the final decision between fraud and honest error.

The control team handles about 5,000 to 6,000 cases a year, about 1,800 of them from the models. The rest come from tips, which Danish law requires be processed. As of 2019, 90 of Denmark's 93 municipal control teams used social-media data in fraud checks.

What the documented models do

Amnesty International obtained redacted documentation on four of the models, with input weights and many inputs withheld. Three carry outcome figures for 2023.

Really Single looks for statistically atypical households among people who receive single-person supplements. Model Abroad scores the relative strength of a recipient's ties to countries outside the European Economic Area (EEA). Citizenship is a direct input. It prioritises people with "medium and high" ties, so in the case file's reading it always selects some such group, whatever anyone did. The third model checks for fictitious employment and parental-leave income.

What UDK's own figures show

In UDK's own 2023 figures, Really Single produced 412 requested cases, 292 control cases, and 135 cases with money owed. UDK confirmed that in 54% of the cases its unit opened, the recipient's claim was legitimate.

Model Abroad produced 511 requested cases, 351 control cases, and 36 with money owed. Roughly nine in ten ended with no further action. The fictitious-employment control produced 491, 207, and 72.

Money owed here covers both deliberate fraud and honest error, because UDK does not separate them. So these are not fraud rates. In each model, most opened cases found no money owed.

Where the harm begins

In the case file's reading, the harm begins before any single flag, at the linkage itself. Recipients on the order of half of Denmark's adults are held inside one system of suspicion.

Model Abroad adds a relative threshold. In the case file's reading, it always selects some group with ties to non-EEA countries, whatever they did. In UDK's own 2023 figures for three models, most opened cases found no money owed.

Who can check it

Datatilsynet, Denmark's data protection authority, told Amnesty it can generally act only on complaints. It said impact assessments are the controller's own duty. Flagged people rarely learn an algorithm selected them, so complaints are rare.

The Ministry of Employment and its agency STAR said their oversight covers efficiency and fraud-prevention goals. They said they cannot instruct UDK on how it handles cases.

The National Appeals Board hears appeals against individual determinations. It overturned a repayment order of 12,500 Danish kroner (about 1,650 euros) built on a Facebook-based cohabitation finding.

In the 2024-25 session, the Minister of Employment forwarded the UDK board's account of the data-driven control to the Folketinget's Digitalisation and IT committee. The sources record no regulator-ordered halt.

What each side says

Amnesty International launched its report "Coded Injustice" on 13 November 2024, after more than two years of research. Its document index is dated 12 November. It calls the system mass surveillance and argues it works as social scoring, which the EU AI Act prohibits. It calls for a ban.

Amnesty argues the design carries a risk of discrimination. UDK and ATP denied all requests for the demographic data needed to test the models for bias. They said they do not hold it. So no disparity figure exists in the sources.

UDK rejected the social-scoring assessment, insisting that human caseworkers always review flagged cases. STAR rejected the oversight findings in writing on 1 November 2024. UDK rejected the discrimination-by-design finding without further explanation. No court has ruled, and the system was not suspended.

In their own words

Amnesty researcher Hellen Mukiri-Smith said the mass surveillance risks "targeting the very people it was meant to protect."

One person Amnesty interviewed described life under the system: "It is like sitting at the end of the gun. We are always afraid."

What this network is drawn from

This network is drawn from the public record, not from UDK's own system. It follows the case file's pattern of fraud control by linking data. Only four of about sixty models, as of 2019, are documented, and input weights were withheld.

The recipients who are investigated are outside the network. The burden of being investigated is documented in the case file.

What the available tools can and cannot address

Service means the useful work the models do for the control team: pointing it to cases worth checking.

A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. Closing a pathway means mistakes stop passing along it. The work it carries goes on.

This case has a budget of 13 units. Explore (No Targets) sets no targets.

Under Service Targets Only, the targets can be met. The cheapest way costs 3 units and uses one tool, Vet connections. The next cheapest routes cost 6 units and use three tools. One is Escalate checks, Mark AI-written records, and Gate vendor updates. Another is Assign a challenger, Review on schedule, and Escalate checks.

More tools are not always better here. With every tool at its strongest setting, ignoring the budget, the models' service falls below the target.

Under Service and Safety Targets and All Governance Targets, the targets are not fully addressable with the available tools. Those levels require closing every failure pathway. Even with every tool at its strongest setting, one stays open: “Unit builds and recalibrates the models”. No tool offered here acts on it. That combination also cuts the models' service below the target.

Understand the system costs 3 units under Explore and Service Targets Only, and 4 under the two higher levels. Its stronger setting costs 6. Every other tool costs the same at every level. Choosing Understand the system makes four other tools cheaper, as its reading describes.

Stylized model of a documented deploymentPublic benefits & eligibility

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Udbetaling-Danmark-class data-driven fraud-control suite network: 7 components and 15 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 5 assumed · 5 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

Show all 10 assumptions
  • baseline

    This example draws one body that the sources show correcting the control work: the National Appeals Board. It overturned a repayment order of 12,500 Danish kroner, about 1,650 euros. The order was built on a Facebook-based cohabitation finding. The example assumes a recipient appeals the recorded determination and its repayment demand, not the models' selection. The sources describe no way to appeal a selection. The example assumes few determinations are appealed, because flagged people rarely learn an algorithm selected them. It treats the board's review as a check that works, because it has overturned a determination. On this network, the Understand the system tool acts on the pathway into the board. The French family-benefits case shares that. It differs because the operator's own internal study examined the score. Here the models stay out of reach, and correction happens one case at a time.

  • baseline

    This example assumes the control team has little capacity for its workload. The models score about 2.4 million recipients, in 2021 figures. The control team handles 5,000 to 6,000 cases a year, about 1,800 of them from the models. For Really Single in 2023, 412 requested cases became 292 control cases. So human checking reaches a fraction of a percent of the people the models score. Contaminated records are a pressure on this case from the start, not an optional one. The sources record that the models use register data of known inaccuracy, such as civil-registration and dwelling data, when they flag people.

  • assumed

    The sources name the Joint Data Unit as its own actor, so this example draws it separately. The unit builds and runs the suite of up to sixty models, as of 2019. It sees how they perform and recalibrates them. It is separate from the control officers who act on the wonderlist. So the power over what the list becomes lies with the builders, not with the officers. Drawing the unit makes that split of authority visible.

  • assumed

    This example follows the data-linking fraud-control pattern in the Udbetaling Danmark case file. It does not rebuild the actual models, their inputs, or their weights. Input weights are withheld in the documentation, and only four of about sixty models, as of 2019, are documented.

  • assumed

    This example draws two ways mistakes spread between parts of the same kind. One shared suite applies its relative targeting to everyone, and control officers pass targeting habits to one another. It also draws a real human check: the control team filters requested cases into control cases. So this is not a case without human review. The sources describe no check of the wonderlist's own precision or fairness before Amnesty's outside investigation.

  • baseline

    The linked registers are drawn as a real input to the models. About ten national registers are linked by the Joint Data Unit, plus foreign data from the Joint Data Unit Abroad. So the linkage affects how mistakes move in this example, not just the picture. It is the case's defining feature: standing surveillance of benefit recipients by linking data. What that linkage means as unequal harm stays outside this example.

  • baseline

    This example includes the loop the sources describe. Past control outcomes recalibrate the next wonderlist, and the cases the control team confirms shape the next calibration. The models also use register data of documented inaccuracy when they flag people. So patterns of who was targeted before shape future flags.

  • baseline

    The case's defining gap is a check nobody ran: an independent test of the wonderlist's precision or fairness before outside scrutiny arrived. In UDK's own 2023 figures, most control cases opened from the three models with figures found no money owed. For Really Single, UDK confirmed that in 54% of the cases its unit opened, the recipient's claim was legitimate. For Model Abroad, roughly 90% ended with no further action. That came to light through Amnesty's outside investigation, not an internal check.

  • assumed

    The wonderlist is drawn between the models and the control team as the models' question list of people they rate as high-risk. It has no pathway of its own and does not change how mistakes move in this example.

  • assumed

    The documented harm is a risk of discrimination built into the design. Model Abroad scores relative non-EEA foreign affiliation, with citizenship as a direct input. Really Single treats atypical households as suspicious. The risk could not be measured: UDK and ATP denied all requests for the demographic data needed to test the models for bias. This example shows how mistakes move through the institution, not who is harmed. It estimates no unequal harm to recipients and holds no disparity figure, because the sources contain none. Amnesty calls the system social scoring. UDK, ATP, and the ministry agency STAR reject that. No court has ruled, and the system was not suspended.

What this example does not show

Show all 2 limitations
  • The documented harm is a risk of discrimination built into the design, and it could not be measured. Model Abroad scores relative non-EEA “foreign affiliation”, with citizenship as a direct input. Really Single treats atypical households as suspicious. UDK and ATP denied all requests for the demographic data needed to test the models. This example shows how mistakes move through the institution, not who is harmed. It estimates no unequal harm to recipients, and the sources hold no disparity figure. Amnesty calls the system mass surveillance and social scoring under the EU AI Act. UDK, ATP, and the ministry agency STAR reject that. No court has ruled, and the system was not suspended.
  • The 2023 control figures are UDK's own and cover three of about sixty models, as of 2019. UDK calls their outcome “revenue”, meaning money found to be owed. It counts deliberate fraud and honest error together, because UDK does not separate them. So they are not fraud rates, and this example uses the case's shape, not its rates. The recipients who are investigated are not drawn in this network. The burden of being investigated is documented in the case file, outside this example.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • Udbetaling Danmark's 'Joint Data Unit' merges and links the personal data of millions of residents from around ten national registers -- civil registration (CPR), buildings and dwellings (BBR), business, income, tax (R75), health, VAT, cash and sickness benefits, education grants, and the motor-vehicle register -- alongside a 'Joint Data Unit Abroad' that pulls data from foreign authorities; in 2021 UDK paid about DKK 241 billion to roughly 2.4 million recipients. Amnesty International documents this as mass surveillance and argues the design carries a discrimination risk: 'Model Abroad' scores a relative strength of ties to non-EEA countries with citizenship as a direct input, and 'Really Single' treats statistically atypical households as suspicious. That harm is a design-level risk rather than a measured outcome, because UDK and ATP denied all requests for the demographic data needed to test the models for bias, so no disparate-impact figure exists in the record. Oversight is thin: the Danish Data Protection Authority (Datatilsynet) can generally act only on complaints (GDPR Art. 57) with no proactive power, and because flagged people rarely learn an algorithm selected them, complaints are rare. UDK rejects the discrimination-by-design and social-scoring findings; no court has ruled.

    empirical
    • Investigative Amnesty International (Algorithmic Accountability Lab), Coded Injustice: Surveillance and Discrimination in Denmark's Automated Welfare State (index EUR 18/8709/2024) (2024) https://www.amnesty.org/en/documents/eur18/8709/2024/en/
    • Advocacy Amnesty International Danmark, Danmark: Algoritmer masseovervaager og diskriminerer udsatte grupper i jagten paa svindel (Denmark: Algorithms mass-surveil and discriminate against vulnerable groups in the hunt for fraud) (2024) https://amnesty.dk/danmark-algoritmer-masseovervaager-og-diskriminerer-udsatte-grupper-i-jagten-paa-svindel/
    • Trade press BABL AI, Denmark's Automated Welfare System Under Fire for Surveillance and Discrimination (2024) https://babl.ai/denmarks-automated-welfare-system-under-fire-for-surveillance-and-discrimination/
  • Denmark's Udbetaling Danmark (UDK), administered by ATP, runs a data-driven welfare-fraud operation that as of 2019 used up to about 60 AI and machine-learning models to score benefit recipients into a 'wonderlist' of high-risk people, which a human control team filters into control cases for investigation. In UDK's own 2023 control statistics (three documented models), the 'Model Abroad' foreign-affiliation model sent 511 cases for control but recovered money in only 36 -- about 7%, with roughly nine in ten resulting in no further action -- and UDK confirmed that 54% of the 'Really Single' household-outlier cases its unit opened were in fact legitimate. Those 'revenue' outcomes conflate deliberate fraud with honest error, which UDK does not separate, so they are not pure fraud rates. Amnesty International characterised the system as mass surveillance and prohibited social scoring under the EU AI Act; UDK, ATP, and the ministry (STAR) rejected that characterisation, the system was not suspended, and as of this writing no court had ruled.

    empirical
    • Investigative Amnesty International (Algorithmic Accountability Lab), Coded Injustice: Surveillance and Discrimination in Denmark's Automated Welfare State (index EUR 18/8709/2024) (2024) https://www.amnesty.org/en/documents/eur18/8709/2024/en/
    • Investigative Amnesty International, Denmark: AI-powered welfare system fuels mass surveillance and risks discriminating against marginalized groups - report (2024) https://www.amnesty.org/en/latest/news/2024/11/denmark-ai-powered-welfare-system-fuels-mass-surveillance-and-risks-discriminating-against-marginalized-groups-report/
    • Trade press Fortune (Europe), Denmark's renowned safety net turns into a political battleground as AI and algorithms target welfare recipients (2024) https://fortune.com/europe/2024/11/13/denmark-renowned-safety-net-turns-into-a-political-battleground-ai-algorithms-target-welfare-recipients
    • Trade press BABL AI, Denmark's Automated Welfare System Under Fire for Surveillance and Discrimination (2024) https://babl.ai/denmarks-automated-welfare-system-under-fire-for-surveillance-and-discrimination/

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Public benefits & eligibility domain page.

Levers available here and the patterns behind them

Documented case histories