10 to the 23 AI logo

Domain Atlas / Public benefits & eligibility

Case fileBrazil (federal; INSS under the Ministerio da Previdencia Social, systems run by Dataprev, audited by the TCU)giant deployment

INSS auto-analysis: when the productivity metric makes denial the fastest way out

A 2024 Tribunal de Contas da Uniao (TCU) plenary audit found that INSS benefit denials were nonconforming above the maximum acceptable limit in both channels it sampled: 10.94% of automatically analyzed denials (January to May 2024) and 13.20% of manually analyzed denials (2023 sample), in Acordao 634/2025-Plenario (process TC 008.309/2024-8, session 26 March 2025). Nonconformity ('desconformidade') is a TCU audit-analysis category that includes wrongful denials but is not identical to a court-confirmed wrong-denial rate, so these are not a hard error rate; the absolute counts reported in coverage (about 920,000 automatic denials in the audited window, about 100,000 estimated wrongful, and 250,000 to 290,000 estimated unjustified manual denials) are journalistic extrapolations from the TCU percentages, not officially published counts. Neither channel uses a machine-learning or predictive risk score; 'automatic' means rules-based administrative processing and documentary-conformity analysis.[3]

What happened

Brazil's Instituto Nacional do Seguro Social (INSS) processes benefits through two coupled automation tracks fronted by one digital channel, Meu INSS, which averages around 105 million monthly accesses across more than 100 services. Track A is systemic automatic administrative concession and denial: a rules-based engine on INSS and Dataprev systems cross-checks contribution records and either grants a benefit, denies it, or routes it to manual analysis; automatic concession reached about 50% of eligible requests, short of INSS's own 55% target. Track B is Atestmed, in which the Federal Medical Expertise (Pericia Medica Federal) grants or denies temporary-incapacity benefits from uploaded medical certificates with no in-person exam. Neither track is a machine-learning or predictive risk score; "automatic" here means rules-based processing and documentary-conformity analysis.

A Tribunal de Contas da Uniao (TCU) plenary audit put numbers to the failure. In Acordao 634/2025-Plenario (process TC 008.309/2024-8, rapporteur Minister Aroldo Cedraz, session 26 March 2025), the TCU found that manually analyzed denials were 13.20% nonconforming (2023 sample) and automatically analyzed denials were 10.94% nonconforming (January to May 2024), both above the maximum acceptable limit. Nonconformity ("desconformidade") is an audit-analysis category that includes wrongful denials but is not identical to a court-confirmed wrong-denial rate. The TCU named the root cause plainly: INSS measures server productivity by the number of processes analyzed rather than the quality of the decision's justification, creating an incentive to choose denial as the fastest disposition, with no incentive for correct motivation of the denial and no effective communication with the insured. Extrapolating from the percentages, legal-press coverage estimated INSS granted about 5.964 million benefits in 2023 and denied roughly 920,000 automatically in the audited window, of which about 100,000 were estimated wrongful, alongside 250,000 to 290,000 estimated unjustified manual denials; these absolute counts are journalistic extrapolations, explicitly not officially published figures.

The Atestmed track shows a surge-then-purge dynamic. New applications for temporary-incapacity benefits rose from 4,574,827 in 2023 to 6,870,659 in 2024 (a 50.2% increase), the auxilio-doenca caseload roughly doubled from about 2 million (2022) to about 4.1 million (2025), and expenditure rose from R$27.6 billion (2022) to R$43.4 billion (2024). Then a pente-fino re-review ran from late July to December 2024: of 684,000 auxilio-doenca benefits reviewed, 356,000 were terminated (52%), saving about R$2.4 billion, and a 2025 plan targeted 802,000 permanent-disability benefits unreviewed for over two years. The maximum duration of Atestmed documentary-analysis benefits churned repeatedly: a 180-day cap under Portaria MPS/INSS 38/2023 was cut to 30 days by Medida Provisoria 1.303 (11 June 2025, later Law 15.265/2025), with benefits beyond the cap requiring an in-person or telemedicine exam, then raised to up to 90 days by Portaria Conjunta MPS/INSS no 14/2026 (23 March 2026); the "Novo Atestmed" relaunch (Portaria Conjunta MPS/INSS no 13/2026, effective 24 March 2026) is recent and its operational record is still settling.

The correction side is slow and external. Denials that are not resolved through the 30-day administrative recurso flow to the Federal Justice: the CNJ recorded 5,109,076 pending previdenciario lawsuits as of 31 October 2024, with pending cases averaging about 746 days to resolution and a conciliation rate near 24.84% (CNJ "Justica em Numeros" data), and the INSS widely reported as the single largest litigant in Brazilian justice. A fast automated or manual denial is thus reversed only after a roughly two-year judicial wait, so each error persists as harm for years. The digital-only front door compounds the exclusion: a 2024 functional-literacy index (Inaf) found about 48% of Brazilians aged 50 to 64 performed poorly on digital-competency tests, yet key contests were routed only through the Meu INSS app with the 135 phone line as fallback, so some applicants never complete the intake at all, a denial-by-attrition invisible to the denial statistics. (The most-cited figure for that digital-only channel, R$6.3 billion in disputed deductions, belongs to a separate unauthorized-deductions scandal and is noted here only for the digital-exclusion point, not as part of the benefit-analysis channel.) In a 2026 follow-up the TCU turned to the mirror-image error: automatic concession that omits discrepancy notices, so beneficiaries entitled to a higher benefit are silently underpaid, and it set a 180-day deadline for INSS, Dataprev and the Ministry to change the automatic-concession system so the insured are notified of discrepancies. Both automated tracks remain in production and expanding under TCU-ordered reform.

The sociotechnical reading

The other automated-benefits failures in this Atlas fail in ways you can point at: MiDAS issued tens of thousands of false fraud determinations at a documented error rate; Robodebt raised debts on an averaging method a Royal Commission found unlawful; the Medicaid unwinding carried one wrong setting, the unit of determination, that a working federal loop eventually caught. This case's defect is subtler and, in a sense, has no defect at all. The automatic engine is not a fraud score, is not accused of illegality, and is not, in the ordinary sense, inaccurate. What the TCU audited was not the engine but the metric behind it: server productivity is counted as the number of processes analyzed, not the quality of the decision, and under that metric denial is the fastest way to clear a case. That is the case's first lesson, and it is distinct from every other in the domain: when automation is deployed to drain a backlog, it inherits whatever the throughput metric rewards, and a metric that rewards speed over correctness turns queue management into a denial machine by incentive rather than by design. No accuracy dial reaches this, because there is no misclassification to measure; the leverage points are the metric itself and a live merit check on the denial at the point it is made. The TCU said as much when it named the absent conditions: no incentive for correct motivation of the denial, no effective communication with the insured, and no participation by the insured in the automatic decision.

The second lesson is the shape of the correction, and it is the exact inverse of the Medicaid unwinding's hopeful loop. There, honest throughput telemetry let a working monitor catch a silent error within months. Here the productivity metric is not honest telemetry that catches the harm; it is the harm's cause, and the oversight that exists arrives on the wrong clock. This is a two-speed system: a denial is fast and cheap to produce, while its reversal runs through an administrative recurso and then a judicial channel where pending cases average about 746 days. The external audit that measured the nonconformity, the TCU, sampled decisions after they had already persisted in the record and driven benefit cutoffs. So error here is not a spike that a loop trips on; it is a durable stock that accumulates for years while correction crawls, with a five-million-case court backlog as the visible sediment. The productive governance moves follow directly, and none of them is an accuracy fix: break the metric's grip by opening a real quality and peer challenge to a denial before it stands; install an independent merit re-check and a discrepancy notice so the insured can participate in the decision that affects them; reconcile a denial against the person's own record before it becomes a cutoff and years of litigation; and pull the audit rhythm toward the point of decision so a nonconforming denial is caught while it is still contestable. The Atlas's office-cultures pattern (the same model behaves very differently under different incentive regimes), its two-speed-correction pattern, and its provenance-and-notice patterns all converge on a case where the dangerous thing was never the model. It was the number the institution chose to optimize.

The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.

Grounding sources for this case

The same sources that ground this model organization in the PAN library: evaluations, government documents, investigative reporting, and advocacy documentation, each labeled by tier.

observatoriodepoliticafiscal2026GroundingAcademicSave

Observatorio de Politica Fiscal FGV IBRE, A Chamativa Evolucao das Concessoes de Beneficios no INSS e o Atestmed (Rogerio Nagamine Costanzi) (2026) https://observatorio-politica-fiscal.ibre.fgv.br/politica-economica/outros/chamativa-evolucao-das-concessoes-de-beneficios-no-inss-e-o-atestmed

https://observatorio-politica-fiscal.ibre.fgv.br/politica-economica/outros/chamativa-evolucao-das-concessoes-de-beneficios-no-inss-e-o-atestmed

Grounds: model org: brazil_inss_automation

conexaotrabalhoportaldaindus2025GroundingTrade pressSave

Conexao Trabalho Portal da Industria CNI, Medida Provisoria limita prazo de duracao de beneficios concedidos por analise documental (2025) https://conexaotrabalho.portaldaindustria.com.br/noticias/detalhe/previdencia/ageral/medida-provisoria-limita-prazo-de-duracao-de-beneficios-concedidos-por-analise-documental/

https://conexaotrabalho.portaldaindustria.com.br/noticias/detalhe/previdencia/ageral/medida-provisoria-limita-prazo-de-duracao-de-beneficios-concedidos-por-analise-documental/

Grounds: model org: brazil_inss_automation

Seeing your organization in this case file?

The histories here are documented after the harm. Mapping a live deployment's pathways and pressures, before the incident report, is engagement work: intake, diagnosis, prescription, and monitoring, with every limitation stated.

Sources & Evidence

Claims made on this page and what supports them. The full registry lives in Evidence.

EmpiricalA 2024 Tribunal de Contas da Uniao (TCU) plenary audit found that INSS benefit denials were nonconforming abov…

A 2024 Tribunal de Contas da Uniao (TCU) plenary audit found that INSS benefit denials were nonconforming above the maximum acceptable limit in both channels it sampled: 10.94% of automatically analyzed denials (January to May 2024) and 13.20% of manually analyzed denials (2023 sample), in Acordao 634/2025-Plenario (process TC 008.309/2024-8, session 26 March 2025). Nonconformity ('desconformidade') is a TCU audit-analysis category that includes wrongful denials but is not identical to a court-confirmed wrong-denial rate, so these are not a hard error rate; the absolute counts reported in coverage (about 920,000 automatic denials in the audited window, about 100,000 estimated wrongful, and 250,000 to 290,000 estimated unjustified manual denials) are journalistic extrapolations from the TCU percentages, not officially published counts. Neither channel uses a machine-learning or predictive risk score; 'automatic' means rules-based administrative processing and documentary-conformity analysis.

EmpiricalThe TCU root-cause finding was that INSS measures server productivity by the number of processes analyzed rath…

The TCU root-cause finding was that INSS measures server productivity by the number of processes analyzed rather than the quality of the decision's justification, creating an incentive to choose denial as the fastest disposition, with no incentive for correct motivation of the denial and no effective communication with the insured. The correction channel is slow and external: the CNJ recorded 5,109,076 pending previdenciario lawsuits as of 31 October 2024, and CNJ 'Justica em Numeros' data put the average pending-case duration at about 746 days with a conciliation rate near 24.84%, so a fast automated or manual denial is reversed only after a roughly two-year judicial wait. The 5.1-million-case backlog and the 746-day duration are CNJ caseload figures and cannot be mechanically attributed to automated denials specifically, because the public data do not link an individual court reversal to the channel that produced the denial.