**Article 14**

**Design and Development of Human-Machine Interface for Effective Oversight**

Urban Safety Analytics designed the Emergency Dispatch Prioritization Engine (EDPE) with a user interface enabling dispatch personnel to view prioritized recommendations derived from the hybrid CNN-LSTM architecture. The interface provides real-time visual summaries of geospatial inputs and temporal patterns influencing prioritization decisions. The system logs incoming data streams from geographic sensors, surveillance feeds, and time-stamped incident reports, presenting a transparent timeline of the data processed. The design intent focuses on situational awareness and operational clarity, intending to assist natural persons in overseeing the AI outputs during response operations. While the interface includes interactive elements for manual input review and acknowledgment of recommendations, no dedicated guidance or alerts address atypical data inputs or model output anomalies, reflecting a scope limited to standard operational contexts.

**Oversight Objectives in the Presence of Reasonably Foreseeable Misuse**

The system’s training incorporated publicly available sensor data and tagged incident records numbering 1.5 million samples across five years, reflecting typical urban emergencies. To address possible model risks under foreseeable use, standard validation steps included testing for performance degradation under varying sensor noise levels and temporal irregularities. However, adversarial scenarios such as sensor spoofing or extreme input distributions typical of large-scale disasters were not explicitly simulated or stress-tested systematically. Consequently, the system’s safeguards focus primarily on robustness to sensor degradation rather than intentional misuse or highly anomalous data distributions. No embedded measures target prevention or minimization of operator overreliance on outputs that could stem from such atypical conditions, acknowledging the residual risk in crisis scenarios.

**Proportionate Oversight Measures Embedded by the Provider**

At the provider-level, the EDPE incorporates fail-safes that enable dispatchers to manually override any AI prioritization decision at any time, as well as a ‘stop’ button that safely halts the model’s recommendation generation while maintaining system responsiveness and data integrity. Model outputs include confidence scores representing internal model certainty derived from historical performance metrics on similar input patterns, which are displayed alongside recommendations. These scores guide the user in assessing reliability but are not accompanied by dedicated prompts or warnings when outputs deviate significantly from typical patterns learned during training. This measure was deployed based on comprehensive evaluation metrics showing 92% accuracy on standard operational scenarios and 15% higher uncertainty signals on out-of-distribution samples, but no dynamic alert system was built to flag potentially suspect outputs in real time.

**Enabling User Understanding, Interpretation, and Intervention**

The system documentation and training materials distributed to users outline the AI model’s architecture, training data scope, known limitations, and the statistical basis of prioritization recommendations. Dispatch personnel receive instruction on interpreting the confidence indicators and understanding that these reflect probabilistic estimates, not deterministic correctness. Interactive visualizations provide breakdowns of influential factors—such as hotspot geolocations and recent incident frequencies—but do not include algorithmic explanations or anomaly detection assistance specifically flagging possible sensor spoofing or unlikely input occurrences.

Dispatchers retain full discretion to disregard or override AI outputs, supported by interface controls facilitating rapid input correction and manual priority setting. Real-time manual input checks allow users to verify sensor data plausibility, but these are user-demanded actions rather than system-enforced safeguards. The system currently does not provide embedded bias correction mechanisms triggered by abnormal input distributions or guidance to recognize automation bias risks; these responsibilities rest on the user’s situational awareness and operational judgment.

**Records of Data Processing and Justification for Special Data Use**

The EDPE processes personal data categories limited to incident metadata stripped of identifiers beyond necessary geographic and temporal markers. Any processing of special categories of personal data occurs solely within scope-defined exceptions to support bias detection and correction during iterative development cycles. The reasons for such processing, and why alternative data could not accomplish these objectives, are documented in the provider’s internal compliance files consistent with Regulations (EU) 2016/679 and (EU) 2018/1725. During deployment, no further automated special category data processing occurs without explicit operational authorization. Logs of data processing activities and model recommendations are maintained to facilitate audit trails but do not automatically generate alerts pertaining to suspicious input patterns or output anomalies.