Dispatches from the fault lines



Part 3: When the Machines Start Talking

This is Part 3 of “What Lies Beneath”, a five-part public service “thriller” series following Scott* while exploring the concept of administrative truth: what it is, how it works, where it breaks down, and what better-designed systems could look like for people and public servants. Read the intro here.

In Part 1 we explored how a person’s ground truth, personal data and administrative truth aren’t one and the same, and why it is useful to make conceptual distinctions. Part 2 showed the layered complexity of not only chopped up data across many systems, but also how from a (Canadian) state’s perspective, there isn’t a shared understanding of what it means to be human, or what it means to be an unemployed human, or a disabled human. Part 3 looks into what it means for human-state interactions when public institutions increasingly digitize and automate public administrations at speed, without addressing underlying challenges, for example when enabling pro-active public service delivery through AI.

Larry Stockett, the president of Micronet Inc., a company specializing in automation, in his office in 1979 (Dave Taylor / AP).

While waiting for his federal Employment Insurance (EI) to come through, Scott* also applied for provincial income assistance where he lives, British Columbia. Unbeknownst to him, his income assistance application was flagged. An invisible-to-him automated validation process compared his declared household composition against records held in connected provincial databases and found a discrepancy. The system saw a single adult male applicant claiming to support two dependents part-time. Yet the records it queried showed a marriage that had not been formally dissolved in provincial systems. The household income calculation ran against the two-adult assumption and put the file on hold. 

So six weeks into his unemployment journey, Scott receives an automated letter asking him to provide additional documentation on his provincial assistance application. The letter does not tell him what the discrepancy was exactly. It also does not tell him which system had flagged it, or what that system believed about him, or which eligibility criteria he did not meet. It told him to call a phone number instead.

He called the number four times. The complex selection menu had him deterred, and he missed a few call-backs because you know… life’s busy. Finally he reached a human agent he could talk to.

*Scott is a fictional character in a speculative fiction story to illustrate the concept of administrative truth. His story returns at the beginning and end of every chapter and serves as a vignette to tell a bigger story. It is set in a not so distant, imperfect future, where (mostly invisible) computers – not humans – handle public service delivery.

* * *


The Administrative Untruth in Action

First, it’s good to mention that the specific failure in Scott’s case is automated validation working as designed. It compared Scott’s declared household composition against the administrative truth held in provincial systems and found a discrepancy. Scott himself was totally being truthful, yet from the system’s perspective, something was wrong.

Yet, what the system (in this context read: computers) could not know is that the discrepancy was not in Scott’s declaration. It was in its own record. The marriage that the provincial system still shows as active ended twelve months ago. That record is an administrative untruth: a formally captured fact that was accurate once, became inaccurate when Scott’s divorce was finalised, and was never corrected because no system was responsible for detecting the change. Yet, it is operative and used for a service decision.

The administrative untruth was a predictable consequence of a design in which life events — including legal ones like divorce — do not automatically propagate to the records that rely on them. Scott’s divorce changed his ground truth. It changed nothing in provincial administrative systems, because nobody told them, and they had no mechanism to ask.

What makes this particularly significant in an automated environment is that the administrative untruth did not just sit inertly in one system. It was used as an input to an automated process in another. The system queried it, treated it as reliable, and acted on it. The untruth was propagated and given operational consequence without a human checking whether it was still true.

That brings us to the next important thing to notice.

When the Machines Start Talking

For most of the history of public administration, administrative truth was held and acted on by people. For Scott’s type of public service (benefits), the service flow somewhat read like this:

  • a person submitted a form, or a caseworker compiled a file and submitted it on their behalf
  • a public service adjudicator reviewed and made a determination
  • a notification was sent out: you are denied or granted a service
  • a clerk updated a record and put it in a physical file cabinet

Of course these adjudicating “behind the scenes” street-level, human bureaucrats (Lipsky, 1980) made mistakes, exercised bias and applied rules unevenly. They may have been subjective in applying policy human-by-human (for better or worse), but they were also something else: accountable. You could appeal to their supervisor. You could ask them, face to face in a government office, why they decided what they decided. There was a visible human whose judgment was locatable, traceable and thus queryable.

As administrative systems become more digitized and automated, and governments work towards digital and pro-active service delivery in zero-click, AI-driven governments, humans move further away from decision-making. The decision becomes the output of a different kind of service process: machine readable law, data flowing between systems, rules encoded in software, and eligibility computed rather than humanly judged.

One could say: that’s great. It’s more fair, speedy and less subjective. But is it? When Scott’s application was flagged, the letter he received asked him to respond to a discrepancy he himself could not see, produced by a process he did not know existed, based on data he did not know was being queried in the back-end. The appeal process itself was originally designed for a world where a human made a decision and was accountable for it. It asks: was the policy applied correctly? It doesn’t ask: was the data accurate and visible? Was the integration between systems working as intended? Was the rule encoded in software actually the rule the policy intended?

Those are quite different questions, but no existing appeal process in the Canadian system is yet designed to investigate these questions well as we move deeper into a digital age of government. What are the design gaps at play?

Design Gaps at Play

Here I introduce three gaps we could design for in better ways, but there may be more. 

The Legibility Gap

Foucault’s concept of “biopower” describes how public institutions produce knowledge about populations to classify, categorise, and act on those classifications in ways that shape what people can do and who they can be (Foucault, 2008). Administrative truth systems are one of the primary sites where this happens. A record does not just describe Scott. It constitutes him, in the eyes of the state, as a particular kind of subject: employed or unemployed, married or single, eligible or ineligible, immigrant or citizen, able-bodied or disabled, imprisoned or free. Based on this administrative picture, it depicts whether a person is deserving of something, for example to receive public service benefits, to be set free from imprisonment, or to be allowed to enter a country.

When that constitution happens through opaque, automated systems, the process becomes illegible to the person it constitutes. Scott cannot see what the provincial system believes about him. He cannot see which data points triggered the flag. He cannot see which system provided which input, or when that input was last updated. He receives a notice without access to the reasoning that produced it.

Virginia Eubanks (2018), in her investigation of automated systems in welfare, housing, and child services in the United States, found this pattern consistently with people who are most affected by automated administrative decisions yet are the least able to contest them, because the systems are (intentionally or not) opaque by design. Hence this is why Virginia Eubanks calls the systems she studied “digital poorhouses”: automated infrastructures that concentrate the management of vulnerability in opaque ways while distributing the costs and consequences downward onto the people least equipped to bear them, often deepening structural inequality.

In democracies, opacity is often an unintended, side effect of complexity, of systems built by multiple actors over multiple years with no single person who understands or sees the whole anymore. The effect on the person experiencing the complexity is similar: they are subject to a decision but cannot see it clearly enough to challenge it. The effect is of illegible states is not innocent: it creates a power imbalance between the citizen and the state.

The Contestation Gap

When Scott does reach a human caseworker on the phone, he enters a process designed for a different kind of decision.

Administrative law in Canada establishes procedural rights for people subject to government decisions. People have the right to know their own files, the right to be heard, the right to a decision with reasoning. But these rights were developed in a context where decisions were made by humans applying policy to facts with human judgement. They are poorly equipped for a context where decisions emerge from the interaction of automated systems acting on data of uncertain origin and accuracy.  

The caseworker can see that a flag was raised on Scott’s file. They cannot easily see which system generated it, what data it queried, or whether that data was current. They can override the flag if Scott provides additional documentation, however they have no power or agency to fix the underlying record that caused it.

danah boyd and Kate Crawford identified this problem at the level of big data systems: the categories and classifications produced by algorithmic analysis appear objective because they are computational, but they embed the assumptions of the people who designed them (boyd & Crawford, 2012). The validation rule that treated a marriage record in one provincial database as more authoritative than Scott’s self-declared household composition through his application forms, reflects a powerful design choice. That choice is now invisible inside the output. Without traceability, contestation is guesswork and accountability is practically impossible.  

The Accountability Gap

Who is responsible when the automated system delays Scott’s application based on a record that has been inaccurate for a year?

The institution that runs the system will say the system correctly identified a data discrepancy and appropriately requested clarification. The system that provided the marriage record will say its data was accurate as of the last update. The policy team will say the validation rule correctly implements the household composition policy. And nobody is accountable for the fact that Scott’s divorce — a legal fact that is twelve months old — never propagated to the systems that now govern his access to support during a crisis.

This is what happens when the governance of administrative truth has not kept pace with the automation of administrative decisions. The bureaucratic accountability structures we have were designed for a world where humans made decisions. In that world, accountability attaches to a person, who makes a judgment in the moment. In a world where decisions emerge from systems, accountability becomes diffuse. It is spread across data owners, designers, system integrators, policy teams, and digital system vendors in ways that make it practically unlocatable.

Effectively, the accountability over public administration decisions moves inside the digital infrastructure leading to a new “division of labour”, argue Widlak and Peeters (2025). In this new world, an “infrastructure-level bureaucracy” carries the consequences for data itself, organizations, and citizens. As the 2021 collapse of the Dutch government demonstrated, large-scale failures in data-driven “infrastructure-level” (instead of street-level) public administrations can ultimately become matters of political accountability. Following an investigation into a decade-long childcare benefits scandal—in which tens of thousands of predominantly low-income families were wrongly accused of fraud, often because of racial profiling or minor administrative errors—the government resigned. In the end, responsibility for such systemic failures rested with the Prime Minister, but not after a lot of societal damage was already done, and long after people were able to organize themselves to set up a law suit against the state.

The Emerging Frontiers: System-Inferred Signals and AI

Why is it becoming increasingly important to design for these gaps? There are a few new technological development that make all of this more urgent.

First, the next generation of administrative systems that aim to enable pro-active public service delivery is moving toward inferring facts about people from patterns in existing data, before people have reported anything. Patterns in tax filings, benefit claims, and social service interactions can be used to infer that something has changed or will happen in a person’s life before any human has reported that change. Jurisdictions like Finland are already experimenting with this.

In principle, this could be beneficial. A system that detects early signs of distress (ie. map of an active wildfire + persons address + persons income = potential need for support) and connects a person with available support preventatively before they reach a financial crisis point. In practice, the governance and privacy questions are serious and largely unanswered. Who decides what patterns constitute a meaningful signal? Who validates the inference before it becomes an administrative truth? What happens when the inference is wrong? And does the person whose life is being inferred about know this is happening? Jurisdictions experimenting with pro-active service delivery need serious governance and guardrails in place.

The other, not-so-distant-future development is the possibility for citizens and governments to maintain a a “digital twin”: a continuously updated AI-powered model of what different governments know about a person, aggregated across systems, capable of anticipating needs and coordinating responses before anyone has to ask.

Technically, a digital twin of Scott could have caught the inconsistency between his federal filing and his provincial income assistance record before it caused him harm. It would have shown him which programs were relevant the moment his layoff was recorded. But the socio-anthropological implications of a digital twin for the citizen-state relationship are vast and largely not understood. If Scott cannot see, contest, or exit his digital twin, yet it governs what he receives and is denied, then it takes the power asymmetry already embedded in administrative truth systems and amplifies it into a single, comprehensive, continuously updated model. And when the twin inherits an administrative untruth, as it will, the error scales across every program simultaneously rather than staying contained in one.

As with all newly introduced technology, it becomes a question of who owns Scott’s life and the meaning of it: the State, big tech, or Scott?

To Conclude: The Missing Human

Let’s conclude Part 3 of this series. Ofcourse, efficiency gains of automation and digitization are very attractive, because information can flow much faster. The speed imperative (looking at the recently published “Velocity White Papers” from the Alberta Government) acts like a shiny diamond to governments.

One could say that this kind of way of working is more fair, better traceable, and less subjective. Though if we look at Scott’s story, we can see how technology can make state processes more opaque, and thus imminently more powerful. And if these systems are not built or designed with public value, transparency and good governance in mind, the consequences when something goes wrong can be far more severe, further eroding citizens’ trust in government.

Therefore, I would argue for getting some other things fundamentally “right” first (ie. design for accountability, contestability, agency, legibility) before we build ferocious and velocious technology on top. One such thing is a corrective mechanism for administrative untruths. I believe it is a basic requirement for any pro-active, digitized service delivery system that uses administrative data to make consequential decisions. There should always be a designed pathway for detecting, reporting, and resolving records that have become inaccurate. Manish Srivastava, who writes about digital governance infrastructure, believes that for a public administration decision to be truly accountable, it should also be possible to identify which rule was applied, in which version, against which data, at the time the decision was made (Srivastava, 2026).

Yet, I can’t help but note that in every failure mode described in this series, the same absence appears. There is no designated human whose job it is to know what the administrative system as a whole believes about Scott. To be accountable for whether that belief is accurate and to answer to Scott when it is wrong. There usually is a technical (product) owner for the system. There is a policy owner for the program, an owner of the service and a data custodian for the authoritative data. But none of these roles carries the specific accountability of saying: “I am responsible for what this system believes about this person as a whole, and I will answer for it”. 

Filling this governance gap requires thinking, designing and deciding about where human judgement lives, and what this could look like in an increasingly automated, futuristic administrative world.

Part 4 turns toward what better design could make possible: building systems where the journey from life event to administrative truth is legible, contestable, portable and anchored to a human who can be held to account.

* * *

Back to Scott

Scott feels defeated and withdrawn. He hasn’t received payment in a while and his finances are getting tighter. Wasn’t this provincial application for assistance supposed to patch this gap?

The person he talked to on the phone was nice enough, but told him that he is responsible himself for fixing the truth in the system. She can’t file the divorce papers for him because the administrative truth lives in a different Ministry than hers.

Scott browses to the right website, uploads his divorce paperwork from a year ago, closes his computer, and calls it day. A bad day, that is.

References

boyd, d., & Crawford, K. (2012). Critical questions for big data: Provocations for a cultural, technological, and scholarly phenomenon. Information, Communication & Society, 15.

Eubanks, V. (2018). Automating inequality: How high-tech tools profile, police, and punish the poor.

Foucault, M. (2008). The birth of biopolitics: Lectures at the Collège de France, 1978–1979.

Lipsky, M. (1980). Street-level bureaucracy: Dilemmas of the individual in public services.

Srivastava, M. (2026). The minimum digital kernel of an unbundled state. Digital Statecraft.

Widlak, A. & R. Peeters (2025). A theory of the infrastructure-level bureaucracy: Understanding the consequences of data-exchange for procedural justice, organizational decision-making, and data itself. In: Government Information Quarterly, Volume 42, Issue 2.

What’s next

Here’s what’s coming next.

Part 4 looks at what better design could make possible, such as a “receipt” of administrative truth, informed navigation within a jurisdiction and portable truths across jurisdictions. It wouldn’t necessarily require digitizing the entire service. It would require governing the records that already exist, and where applicable, digitise those well in consistent ways. 

Part 5 makes the governance argument. Because the real challenge lies in who holds power over administrative truth, and what obligations come with that power.