**Article 14**

### Design and Development of Human-Machine Interface Tools to Support Effective Oversight

The Guardian Signal Controller (GSC) integrates multimodal AI components—namely Convolutional Neural Networks (CNNs) for spatial feature extraction from high-definition video feeds and Random Forest classifiers for decision-level classification—operating in real time within urban intersections. The provider’s design choices prioritized deterministic and interpretable outputs to facilitate human oversight, aligning with the system’s role in safety-critical traffic signal control.

The user interface (UI) presented to operators within municipal traffic control centers displays detected traffic anomalies and predicted accident risks via concise event flags accompanied by confidence scores and annotated video snippets. The interface includes live sensor data overlays to enable situational context for flagged events. Operators receive textual summaries indicating system confidence intervals ranging from 65% to 95%, generated through ensemble metrics combining CNN and Random Forest outputs.

However, design documentation and version control logs confirm that no interactive prompts or confirmation requests are embedded in the UI to encourage operator validation of flagged events or system-generated warnings. The architecture provides manual override controls permitting operators to alter signal timings directly. The interface includes a “stop” button mechanism that safely halts AI-driven signal optimization and reverts to predefined fallback modes, permitting human-initiated intervention at any time.

The decision to exclude mandatory validation prompts was documented in the risk assessment as a trade-off favoring uninterrupted real-time responsiveness, given the latency-sensitive application context. This design rationale was supported by user feedback from operational pilots emphasizing minimal interruption burdens on highly experienced traffic controllers.

### Measures to Minimize Risks Arising from System Use and Potential Misuse

The Guardian Signal Controller was subjected to extensive pre-deployment testing involving a combined dataset of 1.2 million video frames and synchronized sensor readings collected from 15 urban intersections over a 24-month period. This dataset included annotated occurrences of anomalies such as near-collisions, pedestrian conflicts, and red-light infractions verified by human experts.

During development, robustness tests under simulated adverse conditions included low lighting, inclement weather, and sensor noise, with a validation accuracy maintained at 89% (±3%). Adversarial stress tests examining environmental occlusion and ambiguous traffic patterns informed the deployment of the Random Forest classifier layer to compensate for CNN uncertainty on borderline cases.

While these measures focused on optimizing model reliability and reducing false negatives critical for safety, the system’s operational safeguards do not encompass procedural training or embedded simulations for operators addressing ambiguous or conflicting AI outputs. The provider’s risk analysis documentation acknowledges that users may experience uncertainty in interpreting outputs with confidence scores below 70%, but no formalized guidance or simulation scenarios demonstrating human operator responses to such cases are included in the training materials.

### Provider-Integrated and User-Dependent Oversight Components

Before market placement, the provider’s compliance strategy implemented several technical oversight measures intrinsic to the GSC system. These include:

- Continuous real-time monitoring of AI confidence metrics with integrated logging of anomaly detection rates and operator interventions, enabling retrospective audit and model tuning.
- A secure, role-based UI ensuring that only authorized personnel can override system outputs or initiate emergency halts, tracked via comprehensive audit trails.
- Fail-safe logic that automatically engages preset traffic signal schemes under detection or communication failures, ensuring conservative operation during AI unavailability.

Measures designated for deployer implementation—such as comprehensive operator training programs, operational guidelines specifying handling of conflicting signals, and internal workflows for multi-operator verification—are recommended but not enforced or facilitated by the provider. Correspondingly, the provider’s documentation clearly delineates this separation of responsibilities, avoiding prescriptive mandates on deployer procedures.

### Enabling Operators’ Understanding and Monitoring Capabilities

The system’s delivered technical documentation package provides detailed explanations of the AI components’ capabilities and limitations. This includes:

- Model architecture outlines describing the CNN’s feature extraction role and the Random Forest’s algorithmic rationale for enhancing resilience under uncertainty.
- Descriptions of known failure modes and environmental conditions that degrade detection performance.
- Examples of typical output scenarios, including expected false positive and false negative rates categorized by event type and time of day.

These materials aim to facilitate operators’ comprehension sufficient to monitor system behavior effectively. The live interface highlights confidence scores and displays associated video segments to support visual verification. Nonetheless, there is no embedded mechanism or alerting feature to caution operators about the potential for automation bias or to encourage critical scrutiny of automated outputs during operational use. Consequently, operators rely primarily on baseline training and their professional experience to identify system anomalies or erroneous outputs without proactive provider-driven prompts.

### Features Supporting Operator Intervention and System Halt

The Guardian Signal Controller interface provides operators with a dedicated emergency “stop” control that instantly halts AI-driven traffic signal optimization algorithms. Activating this control reverts the intersection to preconfigured fixed-time traffic signal plans designed to comply with safety regulations. The interface logs the timestamp and operator credentials associated with such interventions, enabling traceability.

Additionally, manual override controls permit limited adjustment of green-light durations and phase sequences at intersections. These controls require explicit operator input actions for changes to take effect and provide immediate feedback on current signal states to avoid inadvertent command execution. The design balances the need for rapid emergency responses with safeguarding against accidental or unauthorized overrides.

### Records of Processing Activities and Rationale for Special Data Use

The Guardian Signal Controller processes video and sensor data that do not include biometric identifiers and avoids special categories of personal data as defined under relevant EU regulations. Data processing records maintained pursuant to Articles 5 and 30 of Regulation (EU) 2016/679 document that all data collected for bias detection and model calibration exclude sensitive personal data, circumventing the need for processing justifications under special data categories.

Where rare exceptions arise—for instance, anonymized pedestrian posture data to improve detection in low-light conditions—the provider’s records detail why anonymization and alternative data sources could not achieve equivalent bias mitigation. These justifications are logged and periodically reviewed to ensure strict necessity and proportionality, in accordance with data protection obligations.