Immigration & asylum AI
Immigration and asylum are among the highest-stakes decisions a state makes about a person — asylum, removal, detention — so the reliability of any AI signal and the weight it is given matter more here than almost anywhere, and the person affected is typically least able to see or contest the AI. Two patterns anchor the governance. In credibility assessment, a federal asylum agency uses dialect-recognition AI to estimate an applicant's origin from a speech sample; the tool is imprecise (government-reported recognition around 80 percent for one language, and linguists judge separating some varieties close to hopeless) and the agency's own caseworkers call it a rough compass, too imprecise to resolve hard cases. Used honestly as one clue among several it is defensible; the documented risk is that an imprecise output acquires more authority than its accuracy supports, in a determination where the state's tool is set against the applicant's own account. In enforcement triage, an algorithm identifies and recommends people for immigration actions, and a design detail uncovered through freedom-of-information litigation makes the governance concrete: officials had to justify rejecting a recommendation but not accepting one — an asymmetric override that builds a rubber-stamping incentive into the workflow, so the human in the loop is nominal rather than real. Running under both is a severed correction loop on the applicant's side: applicants are frequently not told AI is used, so the person with the most at stake and the most knowledge of the truth cannot contest the signal used to decide their case. The Lab networks model only the deploying government body — its model or triage tool, the caseworkers and officers who act on its outputs, and its case records; the applicants being decided sit outside the dynamics, no asylum or enforcement outcome is computed on any diagram, and reliability, override-design, and disclosure findings are recorded external facts (reports, fieldwork, FOI disclosures), never adjudications of any individual case.
Use cases
What AI is doing here
Origin & credibility assessment
PredictiveAI that estimates an asylum applicant's origin from signals like speech — used as one input into a credibility determination, where the tool is imprecise (a rough compass, in caseworkers' words) and the documented risk is that an inaccurate output acquires more authority than its reliability supports, against the applicant's own account.
Immigration enforcement triage
PredictiveAlgorithmic identification and prioritisation of people for immigration actions (returns, bail, casework) — where an asymmetric override design (officials must justify rejecting a recommendation but not accepting one) can build a rubber-stamping incentive into the workflow, making the human in the loop nominal rather than real.
Asylum decision support & translation
GenerativeGenerative and translation tools supporting asylum casework — summarising evidence, translating interviews — in the highest-stakes setting, where an error can propagate into a determination and applicants are frequently not told AI is used, severing the correction loop on the side that holds the truth.
Case files
What has gone wrong and right
Documented deployments, presented as model organizations calibrated to the evidence, with full citations.
A rough compass in the hardest place to be wrong
Germany (a federal asylum agency's dialect-recognition tool in the asylum procedure)Germany's federal asylum agency, the BAMF, uses dialect-recognition AI to estimate an applicant's country or region of origin from a speech sample, as one input into the credibility assessment of their claimed origin. The tool is imprecise — government-reported recognition around 80 percent for one language, and linguists judge separating some closely related varieties close to hopeless — and the agency's own caseworkers describe it as only a rough compass, too imprecise to resolve the hard cases, with outputs that are clues rather than determinations. Used honestly as one clue among several it is defensible; the documented risk is that an imprecise output acquires more authority than its accuracy supports, in a determination where the state's tool is set against the applicant's own account of who they are. Running under it is a severed correction loop: the applicant, who knows their own origin and has the most at stake, is often unable to see or contest the estimate.
Explore this deployment in the PAN Lab →The human who must justify only 'no'
United Kingdom (a government immigration-enforcement triage algorithm; documented via FOI litigation)The UK Home Office's immigration-enforcement triage algorithm, IPIC (Identify and Prioritise Immigration Cases), identifies and recommends people for enforcement actions — returns, bail conditions, casework — drawing on sensitive data including detention, health, vulnerability, and location-monitoring records. Uncovered through roughly a year of freedom-of-information litigation, its training materials show an asymmetric override: officials must record a justification for rejecting a recommendation but not for accepting one. That builds a rubber-stamping incentive into the workflow — accepting the algorithm is frictionless, overriding it requires work — so the human in the loop is nominal rather than a real check. It is the corpus's clearest documented instance of automation bias engineered into an agency workflow, and it runs alongside a severed correction loop: applicants are frequently not told AI is used, so the person it is about cannot contest it either.
Explore this deployment in the PAN Lab →System map
Who is in the system and what pushes on it
Who is in the system
- Frontline workers. Caseworkers, screeners, eligibility staff — the operator network whose judgment the system augments or erodes.
- Agency leadership. Owns procurement, policy, and the authority map; answers for the system publicly.
- Served people & families. Those the decisions land on. Deliberately outside the PAN dynamics — their outcomes are measured, never simulated.
- Regulators & oversight bodies. Boards, auditors, data-protection officers, inspectorates — external correction capacity.
- Courts & commissions. The heaviest, slowest actors — who end most of the failures documented in this Atlas.
- Advocates & community organizations. Surface harms institutions do not see; historically the earliest accurate signal.
Dominant pressures
- Reviewer bottleneck. One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Austerity & recovery incentives. Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Vendor opacity. The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift. The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
- Compliance over substance. Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
Governance
Questions leaders should be asking
- 1. A dialect or origin signal is imprecise (roughly a fifth of cases wrong for one language, some varieties near-impossible to separate) and its own caseworkers call it a rough compass — so does that documented imprecision actually bound the weight it carries, or can 'the software indicates this origin' harden into a credibility finding the accuracy cannot support?
- 2. An enforcement-triage tool was found to require officials to justify rejecting its recommendation but not accepting one — so is the human in the loop a real check, or has an asymmetric override built a rubber-stamping incentive into the workflow that makes nominal oversight hollow?
- 3. Applicants are frequently not told AI is used in their case — so is the correction loop severed on exactly the side that holds the truth, cutting out the person with the most at stake and the most knowledge of their own origin from contesting the signal used to decide it?
- 4. These are among the highest-stakes decisions a state makes about a person — so is the reliability of the AI signal, and the applicant's ability to see and contest it, being held to a standard that matches the stakes, or is a tool defensible only as 'one input' being allowed to carry weight it cannot support?
For the actions behind these questions, see the Practice Library.
Seeing your organization in this domain? Mapping its actual pathways, pressures, and correction capacity is engagement work.
Work With 1023AI