Example campaigns
3 links
Graph · Strategy
01 · In focus
The structured facts the source records about Empirical audit and expose of deployed AI systems, the count of declared adjacencies in the corpus, and the federation map zoomed on this node and its neighbours.
strategy
↑15 declared connections
02 · Connections
Split by direction. Direct links are the ones Empirical audit and expose of deployed AI systems’s source record names; inferred backlinks are records elsewhere in the corpus that point at this entity.
15 links
Other records that name this entity.
3 links
12 links
03 · Background
Body prose as it appears in movement-graph’s published markdown for this entity. Links to other corpus entities resolve to their graph page; links to deeper repo paths are kept as text so the page does not invent a route.
Run a quantitative test on a deployed AI system — face recognition, credit scoring, content moderation, generative model behaviour — and publish the disparity numbers as an attributable, citable record. The audit is engineered so the result is hard to dispute: a stratified sample, a clear metric, a methodology section other researchers can replicate. The publication is timed for press coverage and routed at journalists, regulators, and the deploying organisation in parallel.
An organisation chooses this strategy because deployed AI systems are evidence-poor by default — the operator controls disclosure, and aggregated statistics from impact reports do not survive contact with a serious sample. A reproducible audit converts a movement claim ("this system is biased") into a citation other actors can carry: into legislation, into court filings, into a procurement officer's decision not to buy. Once a number is in the public record, every later defence of the system has to argue against it.
The trade-off is the cost of doing the science well — bad audits poison the well — and the structural problem that auditing is easier to fund than fixing: a movement can accumulate empirical exposures faster than the political and legal apparatus around it can convert them into outcomes.
Empirical audit is the most-adopted strategy in the corpus — twelve named adopters spanning the Algorithmic Justice League, the Norwegian Consumer Council, AlgorithmWatch, the DAIR Institute, the Citizen Lab, Amnesty International, Big Brother Watch, the American Civil Liberties Union, and Pollicy on the org side; the AJL–Georgetown Safe Face Pledge, the NCC "Out of Control" campaign, and the AlgorithmWatch OpenSCHUFA campaign on the campaign side — and the four effects: above are typical of what the strategy returns to the movement: an industry exit here, a six-figure GDPR fine through five years of appeals, a credit-scoring system's anomalies on the parliamentary record, a United-States export-control listing of a commercial-spyware vendor.
The strategy is good, with a high ceiling and a hard wall.
Strong on its primary claim — that an empirical examination of a deployed AI system converts a movement complaint into a citation other actors can carry. Gender Shades's 34.7 per cent error rate is the single most-cited audit number in the corpus and appears in legislative text (the EU AI Act's biometric-recognition provisions), in court filings (the American Civil Liberties Union's Williams v. Detroit Police Department wrongful-arrest action, the first United States wrongful-arrest lawsuit tied to facial-recognition error), in an IBM Chief Executive Officer's letter to the United States Congress, and in the Coded Bias documentary's public narrative. The OpenSCHUFA methodology — citizens-as-data-donors invoking statutory subject-access rights, with civil-society and journalist partners analysing the donated records — became the working template for AlgorithmWatch's DataSkop election-cycle audits of YouTube (2021 German federal election) and TikTok (2023), and has been independently adopted by adjacent European civil-society organisations working on consumer-credit, recommender-system, and public-sector automated-decision-making accountability. The Citizen Lab forensic protocol on Pegasus is the global civil-society standard for commercial-spyware attribution and is what produced the United States Entity-List listing in the first place.
Weaker on its secondary claim — that empirical evidence converts into binding outcomes on a useful timescale. The audit-to-outcome conversion-ratio is decade-scale at best (Gender Shades February 2018 → IBM exit June 2020 → no durable rule change) and zero at worst (OpenSCHUFA November 2018 → no statutory disclosure of SCHUFA's algorithm, no primary legislation on credit-scoring transparency, seven years on). The IBM / Amazon / Microsoft 2020 moratoria — the strategy's flagship corporate-behavior chain — required a global racial-justice mobilisation to fire and did not produce durable rule changes; Amazon's "one-year" Rekognition moratorium was quietly extended without a hard policy commitment, Microsoft kept its non-police facial-recognition product lines, and IBM exited a market in which it had limited share to begin with. The strategy returns evidence faster than the legal-and-political apparatus around it can convert that evidence into binding outcomes, which is how a movement that has built more audit infrastructure than any prior accountability movement has so far won fewer durable algorithmic constraints than it has audit findings.
The deepest structural problem is the methodology arms race. An audit depends on a research-access surface — the deployed system has to be testable, scrapable, requestable, or forensically analysable. That surface is closing across the board: Meta cut off the New York University Ad Observatory researchers's platform access in August 2021 and forced the shutdown of their participatory-ad-tracking tool; AlgorithmWatch's Instagram-newsfeed monitoring project was shut down by Facebook on terms-of-service grounds in July 2021; X (formerly Twitter) terminated free academic API access in February 2023; and the EU AI Act's trade-secret carveouts protect provider models from the very methodologies the Act's fundamental-rights impact assessment requirement implicitly contemplates. The strategy works best where the access surface is open (mobile-app traffic capture; statutory subject-access disclosures; on-device forensics on visible spyware) and degrades toward unusable where the platform can close that surface (recommendation-system internals; closed-weights frontier models; on-device classifiers behind hardware enclaves). An adopter that plans an audit cycle five years out cannot assume the access conditions of today still apply, and the audit-led arm of the movement is increasingly building its work product on a foundation the targets can revoke.
The strategy is bad as the lone arm. An adopter that runs only the audit arm — without the strategic litigation that converts the finding into legal precedent, without the coalition lobbying that converts the finding into statutory text, without the counter-narrative framing that converts the finding into a public political stake — produces an archive of empirical exposures that the AI industry can absorb into its own "responsible AI" governance vocabulary at zero binding cost. The frontier-model providers now publish audit numbers in their model cards as a product-trust signal; the audit-and-expose finding becomes the audit-and-incorporate finding when no downstream arm of the movement is positioned to carry the audit into a binding constraint. The strategy is genuinely powerful at the supply end of the evidentiary chain; whether the movement converts it on the demand end is the open question this strategy cannot answer alone.
The strategy sits structurally upstream in the movement's evidentiary chain — it produces the citation other arms carry — and has dense feeds into several downstream strategies. It feeds strategic litigation against algorithmic state decisions as its primary onward channel: Gender Shades's bias documentation is the substrate for the American Civil Liberties Union's Williams v. Detroit Police Department wrongful-arrest filing, Worker Info Exchange's Managed by Bots audit is the substrate for the Amsterdam Court of Appeal's 4 April 2023 ruling on Uber and Ola, and the Citizen Lab Pegasus-attribution dossier is the substrate for the Pegasus Project's civil and criminal filings in France, India, Mexico, and El Salvador.
It feeds coalition lobbying of binding regional regulation as the empirical input the lobbying arm cites: the Norwegian Consumer Council's "Out of Control" report directly anchored its own June 2021 "Time to Ban Surveillance-Based Advertising" open letter co-signed by 60-plus organisations including BEUC and EDRi and addressed to EU Digital Services Act trilogue negotiators and to United States federal policymakers; the Gender Shades line was carried into the EU AI Act's biometric-recognition provisions by the European Digital Rights coalition; AlgorithmWatch's recommender-system audit work on TikTok and YouTube was carried into the same Act's Article 26 platform-risk-assessment provisions.
It feeds counter-narrative framing as the number that anchors the narrative: AJL's 34.7 per cent error rate became the Coded Bias documentary's central image and the "your face is not your password" framing the Algorithmic Justice League carried into TSA opt-out organising; OpenSCHUFA's "black box" framing became the German credit-scoring debate's vocabulary; Worker Info Exchange's algorithmic-management findings reframed the gig-driver debate from "flexibility" to "managed by bots".
It is paired with survivor-led testimony as evidence as the complementary public-facing register. The audit produces the number, the survivor produces the face the number attaches to, and the pair travel as a single story. Robert Williams of Detroit is the named survivor whose wrongful arrest the Gender Shades number quantifies in the public imagination; Daniel Motaung is the named survivor whose Sama working conditions Worker Info Exchange and Foxglove's investigative work make legible as exploitation rather than employment; the Mexican human-rights defenders whose phones the Citizen Lab forensically attributed to Pegasus are the named survivors whose targeting the Entity-List designation indirectly addresses. An audit without a survivor is a statistic; a survivor without an audit is an anecdote; the pair is what travels.
It feeds organise the workers in the AI supply chain by supplying the working-conditions evidentiary substrate the organising arm uses but cannot itself produce: TIME's January 2023 investigation into Sama's Kenyan content-moderation workforce that built ChatGPT's safety layer, Privacy International's long-read on gig-economy algorithmic management, Worker Info Exchange's Managed by Bots report on seven major gig platforms, and the Data Workers' Inquiry at the Weizenbaum-Institut für die vernetzte Gesellschaft and the Distributed AI Research Institute are all audit-form outputs that supplied the Nairobi content-moderator union and the Amsterdam gig-driver litigation with the empirical findings the worker-organising form needed but could not produce from inside its own labour-side mechanics. The empirical-audit arm and the worker-organising arm are operationally distinct populations (researchers in research institutions and workers in supply-chain jobs) but run a single evidentiary loop on the same target.
It parallels parallel community research institution — the audit-as-knowledge-form expressed institutionally rather than as a single campaign. The Distributed AI Research Institute was founded on the premise that the audit-as-knowledge-form requires an institutional vehicle independent of frontier-AI corporations and Big-Tech-funded academic labs; its existence is the empirical-audit strategy crystallised into a standing organisation rather than a one-off campaign. AlgorithmWatch's working model since OpenSCHUFA is the same logic at a different scale.
The strongest competing strategy is the AI industry's own counter-strategy: the audit-incorporation gambit. Where civil-society audits expose disparate impact in a deployed model, the model's provider responds by publishing its own audit numbers — model cards, system cards, responsible-AI scorecards — that absorb the finding into a product-trust narrative the provider controls. This is happening at the frontier today: every major frontier-model provider publishes "fairness benchmarks" in its model-card releases and treats the publication itself as evidence of accountability. The strategy's most consequential structural threat is not platform opposition but platform co-option — the audit form succeeding so completely that its targets adopt the form themselves and use it to defang the external accountability claim. The empirical-audit arm of the movement has not yet found a stable answer to the question of what an external audit is supposed to prove once the target is publishing one too.
Source: entities/strategies/strat-empirical-audit-and-expose.md — movement-graph pin 5d136ad.