Domain Atlas / Public benefits & eligibility
CNAF benefit-fraud risk score (France)
Work with this case in the PAN Lab ↗
France's family-benefits fund (CNAF) computes a monthly benefit-fraud suspicion score, on a 0-to-1 scale, for every benefit-receiving household — analysing the data of about 32 million people and producing more than 13 million scores each month, close to half of France's population; the highest scores route households into fraud controls, up to the most invasive on-site checks. An analysis by Le Monde and Lighthouse Reports of an extracted production model (a logistic regression of about 33 variables) found that markers of economic vulnerability raised the score: a stable-income family averaged about 0.33, while a person working while receiving the disability allowance (AAH) averaged about 0.66. The model's target was an overpayment (indu) above a threshold, which is frequently unintentional administrative error rather than proven intentional fraud, and the score itself is not disclosed to the person and cannot be appealed directly. CNAF disputed the discrimination framing, describing the tool as a neutral decision-aid that only prioritises which files to check; a coalition that grew to 25 organisations challenged the model before the Conseil d'État, and as of this writing no court had ruled.[6]
What happened
France's family-benefits fund, the Caisse Nationale des Allocations Familiales (CNAF), runs an in-house benefit-fraud risk-scoring model — the "datamining" score — over its entire benefits database. Every benefit-receiving household is assigned a monthly suspicion score on a 0-to-1 scale: roughly 13 million scores, computed from the data of about 32 million people, close to half of France's population. The highest scores route households into CAF fraud controls (contrôles), up to the most invasive on-site investigations, where controllers can question household composition, examine bank records, and visit the home. The score is officially a decision-aid that only prioritises which files to check; human controllers, not the score, make the final fraud-versus-error determination, and the score is not disclosed to the person and cannot be appealed directly — a beneficiary can contest only the resulting control decision or the overpayment-recovery demand.
The system has roots in a late-2000s local experiment in Bordeaux, generalised nationally amid mid-2000s anti-fraud policy, and ran through successive production versions (circa 2010, 2014, 2018, and a redesigned "2025" model). In 2023, Le Monde and Lighthouse Reports obtained earlier model versions through French freedom-of-information law (via the CADA, after CNAF resistance) and reverse-analysed the 2014 model: a logistic regression of about 33 variables, with per-variable coefficients ranging from -0.81 to +0.89, producing raw scores from -12.89 to +9.83 that a sigmoid maps to a 0-to-1 probability. The model was trained to predict overpayments (indus) of at least €600 per month lasting at least six months, using CNAF's annual random-audit survey as ground truth — so its target is legally an overpayment, which is frequently unintentional administrative or declaratory error rather than proven intentional fraud. On the model's own arithmetic, markers of economic vulnerability raised the score: low income, unemployment, receiving the RSA minimum-income benefit, a high rent-to-income ratio, low web-connection frequency, a recent separation or house move, declaratory errors, single-parent status, and — in the pre-2025 model — working while receiving the disability allowance (AAH), which critics called "the height of cynicism." An illustrative stable-income family averaged about 0.33, while a person working while receiving AAH averaged about 0.66.
Reporting on the model's effects found that since 2019 it flagged more than 700,000 investigations, and that of flagged households about 35% ultimately had to repay (averaging around €821), while about 17% were found to be owed money by CNAF — against a roughly 15% repayment baseline from random-audit controls. Roughly seven of every ten people investigated were flagged by the algorithm. Investigators noted the analysis could not compute false-positive rates by protected group, because outcome data broken down by protected category was not available. In October 2025, CNAF's own internal statistics department (DSER) circulated a simulation study, reported by Le Monde and La Quadrature du Net, finding that RSA recipients were about 13% of beneficiaries but 39 to 41% of the highest-scoring 5%, that single mothers were about 14% of beneficiaries but 37 to 40% of that top bracket, and that households including a foreign national scored higher even after the nationality variable was removed — a proxy-discrimination pattern. The full study is not public.
On 15-16 October 2024, fifteen organisations led by La Quadrature du Net — among them Amnesty International France, the Ligue des droits de l'Homme, Gisti, APF France handicap, the Syndicat des avocats de France, and Collectif Changer de Cap — filed a challenge before the Conseil d'État seeking to strike down the algorithm on data-protection (GDPR) and non-discrimination grounds. In October 2025 the Défenseur des droits (the French ombudsperson) filed observations finding that "a presumption of indirect discrimination appears established," because the differential treatment rests on beneficiaries' particular economic vulnerability, and that the tool appears to over-control the most precarious populations. In January 2026, ten further organisations — including the CGT and Solidaires unions, European Digital Rights, AlgorithmWatch, the Panoptykon Foundation, the European Network Against Racism, and the Mouvement des mères isolées — joined the case, bringing the coalition to 25 organisations demanding a ban; the written phase closed at the end of January 2026, a public hearing was expected in spring 2026, and observers anticipated a possible referral to the Court of Justice of the EU under GDPR case law on automated scoring. As of this writing no court had ruled.
The model challenged in the 2024 suit — the 2018 version — ran until January 2026 and had been withheld from the 2023 investigation; CNAF published its source code only on 15 January 2026, alongside a redesigned "2025" model that entered production the same month. The 2025 model removed the AAH-while-working, nationality, housing-type, and behavioural variables, but critics say it still over-targets the same groups, retaining triggers such as receiving three or more benefits, receiving over €200 per month in allocations, low income (0.6 to 1.5 times the minimum wage), and RSA entry and exit events; its disproportion is so far projected from DSER simulations, not yet measured in live production. CNAF disputes the discrimination framing throughout, describing the tool as a neutral decision-aid that targets significant and repeated overpayments, with one CNAF director arguing it was "the opposite of discrimination" because no one can explain why a given file is targeted. No AI model identifier is documented in the record.
The sociotechnical reading
CNAF is the Atlas's targets-the-vulnerable-by-design case. Its defining feature is not an absent human or a hidden model but the content of the score itself: the variables that raise fraud suspicion are the very markers of the population a safety net exists to serve. Low income, receiving the disability allowance, single parenthood, a recent separation or move — on the model's own extracted arithmetic these push a household up the ranking, so being vulnerable is, mechanically, being suspected. That is a double penalty, and it is sharpened by what the model actually predicts: not proven fraud but "overpayment" (indu), a threshold that ordinary administrative or declaratory error crosses far more often than deliberate wrongdoing. A system optimised against overpayment, over-concentrated on the precarious, will find plenty of error there and read it back as risk.
The self-reinforcing loop is the engine. The score is retrained on the outcomes of past controls and the annual random-audit survey, so groups historically over-controlled feed forward into future high scores; a skew in who gets checked rides straight back into who the model suspects next. This is the pathway the Lab's connection-authorization and challenger levers are aimed at, and why a better-calibrated classifier is the decoy here: refining a score that trains on its own targeting leaves the loop intact.
The case also inverts its nearest neighbour. Where the Netherlands' SyRI was struck down because it was secret — invisibility as the harm, halted before the wrongful flags were counted — CNAF is the opposite transparency story. Its exact formula was forced open through freedom-of-information law, the disproportion is demonstrable on the model's own coefficients, and it was later corroborated by the operator's own internal DSER study — and yet the system kept running, the litigation is still pending, and a redesigned model reproduces the same disproportion by its own simulation. Rotterdam's control came from an outside audit that pried a model open and suspended it; CNAF was pried open too, and did not stop. The map's lesson is that visibility is necessary but not sufficient: proving a score targets the vulnerable, even on its own arithmetic and even to the operator's own satisfaction, does not by itself dislodge it. What the framework flags as the missing control is an internal fairness check with teeth — the audit the design never ran on itself — plus governance of the retraining loop and minimization at the input, where the double penalty begins. And because human controllers do make the final call, the deference question matters: a decision-aid becomes a verdict exactly when the rank is treated as the answer. The contested framing is part of the record and is kept in it here: regulators and a large civil-society coalition assert discrimination, the ombudsperson found a presumption of it, CNAF disputes the characterisation, and no court has yet ruled.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.