Algorithmic Rulemaking Liability .

Algorithmic Rulemaking Liability in Europe

1. Meaning and Scope

Algorithmic rulemaking liability concerns legal responsibility arising when public authorities, regulators, municipalities, agencies, or other bodies use algorithms or AI to formulate, interpret, apply, recommend, prioritize, or enforce rules and regulatory standards, and the resulting algorithmic process causes unlawful or unjustified harm.

Examples include:

AI-assisted drafting of regulations;

algorithmic eligibility rules for public benefits;

automated regulatory classifications;

AI-generated administrative policies;

algorithmic allocation of permits or licences;

automated enforcement priorities;

predictive regulatory inspections;

AI-assisted tax assessments;

automated immigration rules;

algorithmic sanctions screening;

risk-based regulatory supervision;

automated public procurement criteria.

There is no single European cause of action called “algorithmic rulemaking liability.” Claims generally arise under administrative law, constitutional/fundamental-rights law, GDPR, equality law, EU institutional law, public procurement law, and principles of effective judicial protection.

The central question is:

Can a public authority lawfully delegate or rely upon algorithmic systems when creating or applying rules that affect individuals, and who is responsible when the resulting rule is unlawful, discriminatory, disproportionate, irrational, or procedurally defective?

2. Difference Between Algorithmic Rulemaking and Algorithmic Decision-Making

The distinction is important.

Algorithmic decision-making

The algorithm determines or influences an individual case.

Example:

AI decides whether Person A receives a benefit.

Algorithmic rulemaking

The algorithm determines or substantially influences the criteria applied to many people.

Example:

AI develops a risk formula that determines which categories of welfare recipients will be investigated.

Thus:

Algorithmic rulemaking

→ creates/changes criteria

→ criteria are applied repeatedly

→ many individuals are affected.

This potentially creates systemic liability rather than merely an individual error.

3. European Legal Framework

A. Rule of Law

Algorithmic rulemaking must operate within the principle that public power must have:

lawful authority;

defined limits;

procedural safeguards;

accountability;

judicial review.

An administration generally cannot obtain powers merely because an algorithm recommends them.

B. EU Charter of Fundamental Rights

Important provisions include:

Article 7 — private and family life;

Article 8 — personal-data protection;

Article 20 — equality before the law;

Article 21 — non-discrimination;

Article 41 — good administration;

Article 47 — effective remedy and fair trial;

Article 52 — limitations on fundamental rights.

C. GDPR

Where rulemaking involves personal data, relevant provisions include:

Article 5 — fairness, transparency and accuracy;

Article 6 — lawful processing;

Article 9 — special-category data;

Articles 12–15 — transparency and access;

Article 22 — automated decisions;

Articles 24–25 — accountability and privacy by design;

Article 35 — impact assessments;

Article 82 — compensation.

D. EU AI Act

The AI Act adds obligations concerning, among other matters:

risk management;

data governance;

technical documentation;

logging;

transparency;

human oversight;

accuracy;

robustness;

cybersecurity;

fundamental-rights protection;

monitoring.

For public-sector AI, these requirements may become particularly important where the system affects access to public services or exercises regulatory power.

4. Main Forms of Algorithmic Rulemaking Liability

1. Ultra vires algorithmic rulemaking

The authority uses AI to create rules beyond its statutory power.

2. Procedurally defective rulemaking

The algorithm influences rules without:

consultation;

adequate reasons;

impact assessment;

legally required procedures.

3. Discriminatory rules

The algorithm creates criteria disproportionately disadvantaging a protected group.

4. Arbitrary rulemaking

The algorithm relies on irrelevant or irrational factors.

5. Opaque rulemaking

Affected persons cannot determine why the regulatory criteria exist.

6. Privacy-invasive rulemaking

Personal data are used excessively to construct regulatory classifications.

7. Disproportionate rulemaking

A legitimate regulatory goal is pursued through unnecessarily intrusive AI methods.

8. Defective delegated rulemaking

A public authority effectively allows a private technology provider to determine substantive regulatory criteria.

5. Case Law

1. Kadi and Al Barakaat International Foundation v Council and Commission

Court: CJEU
Joined Cases: C-402/05 P and C-415/05 P
Year: 2008

Facts

Individuals were subjected to EU sanctions implementing international counter-terrorism measures.

They challenged the measures on fundamental-rights grounds.

Decision

The CJEU held that EU measures remain subject to fundamental-rights review even when they implement international obligations.

Principle

Public authority cannot escape fundamental-rights review merely because the underlying policy originates from another legal or political system.

Algorithmic Rulemaking Relevance

Suppose an EU or national authority uses AI to formulate sanctions criteria or risk classifications.

The authority cannot simply argue:

“The algorithm generated the classification.”

The authority remains responsible for ensuring that the regulatory framework complies with:

fundamental rights;

proportionality;

procedural fairness;

effective judicial protection.

6. Kadi v Commission

Court: CJEU
Case: C-584/10 P
Year: 2013

Facts

The case concerned continued inclusion of an individual on a sanctions list and the adequacy of the procedures available for challenging the factual basis for the listing.

Decision

The CJEU emphasized the importance of effective judicial review and the ability of the affected person to challenge the factual material supporting the measure.

Principle

A person affected by a powerful governmental classification must have a meaningful opportunity to challenge the factual basis for that classification.

Algorithmic Rulemaking Relevance

This principle is highly relevant to AI-generated regulatory classifications.

If an authority creates an algorithmic rule such as:

“Persons exceeding risk score X are subject to enhanced regulatory controls,”

affected persons may need sufficient information to challenge:

the underlying data;

the classification;

the methodology;

the application of the rule.

7. Digital Rights Ireland

Court: CJEU
Joined Cases: C-293/12 and C-594/12
Year: 2014

Facts

EU legislation required large-scale retention of telecommunications data.

The legislation was challenged because of its impact on privacy and personal-data rights.

Decision

The CJEU invalidated the Data Retention Directive because the interference with fundamental rights was insufficiently constrained and disproportionate.

Principle

Large-scale technological regulation must contain appropriate safeguards and limitations.

Algorithmic Rulemaking Relevance

AI-based regulation frequently involves:

massive datasets;

predictive analysis;

population-level profiling.

The fact that technology can process enormous quantities of information does not itself justify regulatory collection and analysis.

A rulemaking authority must examine:

necessity + proportionality + safeguards + scope.

8. Tele2 Sverige and Watson

Court: CJEU
Joined Cases: C-203/15 and C-698/15
Year: 2016

Facts

The cases concerned national telecommunications data-retention regimes.

Decision

The CJEU rejected general and indiscriminate retention of communications data as incompatible with EU law except within tightly constrained circumstances.

Principle

Technological usefulness does not automatically make a regulatory measure lawful.

Algorithmic Rulemaking Relevance

An authority might argue:

“AI needs extensive data to identify regulatory risks.”

Tele2 illustrates why such reasoning is insufficient.

The authority must still establish:

legal basis;

necessity;

proportionality;

limits;

safeguards.

9. La Quadrature du Net and Others

Court: CJEU
Joined Cases: C-511/18, C-512/18 and C-520/18
Year: 2020

Facts

The cases concerned national measures involving retention and processing of electronic communications data, including measures justified by national security and serious crime.

Decision

The CJEU examined the relationship between national-security objectives, EU law and fundamental rights.

Principle

National security does not provide an unlimited exemption from legal constraints where EU law applies.

Algorithmic Rulemaking Relevance

This is relevant to government AI systems used for:

predictive policing;

terrorism-risk assessment;

border control;

intelligence analysis;

cybersecurity regulation.

An algorithmically generated security rationale cannot itself eliminate judicial scrutiny.

10. SCHUFA Holding AG v Verbraucherzentrale Bundesverband

Court: CJEU
Case: C-634/21
Year: 2023

Facts

SCHUFA's automated credit scoring significantly influenced subsequent decisions.

Decision

The CJEU held that automated scoring may constitute automated decision-making where it effectively determines a consequential decision.

Principle

Courts must examine the real practical influence of an algorithm rather than simply the formal structure of decision-making.

Algorithmic Rulemaking Relevance

This principle can apply by analogy to regulatory systems.

Suppose:

AI creates a regulatory risk score → regulator formally approves the resulting classification.

If the human approval is merely automatic or mechanical, the authority may face questions concerning genuine human responsibility.

This is particularly relevant where AI generates:

regulatory risk scores;

inspection priorities;

tax-risk classifications;

benefit-fraud scores;

immigration-risk classifications.

11. Dun & Bradstreet Austria GmbH

Court: CJEU
Case: C-203/22
Year: 2025

Principle

The CJEU emphasized meaningful information concerning automated decision-making and the ability of affected individuals to understand and exercise their rights.

Algorithmic Rulemaking Relevance

When an algorithm effectively establishes or applies important regulatory classifications, merely providing a statement such as:

“The system identified you as high risk”

is unlikely to provide meaningful accountability.

The affected party may need information sufficient to challenge the relevant reasoning and data.

12. CHEZ Razpredelenie Bulgaria

Court: CJEU
Case: C-83/14
Year: 2015

Facts

An electricity company adopted a measure involving electricity meters placed at unusual heights in a particular neighbourhood, partly because of concerns about meter tampering.

The affected neighbourhood had a predominantly Roma population.

Decision

The CJEU recognized that apparently neutral measures can amount to indirect discrimination where they particularly disadvantage a protected group.

Principle

A rule does not escape discrimination law merely because it is facially neutral.

Algorithmic Rulemaking Relevance

This is particularly important for algorithmic regulation.

An algorithm may use apparently neutral variables such as:

geographic location;

income;

occupation;

educational history;

transaction patterns.

These may function as proxies for protected characteristics.

Thus:

neutral algorithmic rule ≠ automatically neutral legal effect.

13. Feryn

Court: CJEU
Case: C-54/07
Year: 2008

Facts

An employer publicly stated that it would not recruit persons of a particular ethnic background.

Principle

Discriminatory recruitment practices can be legally significant even when identifying a particular rejected applicant is difficult.

Algorithmic Rulemaking Relevance

The case is useful by analogy when algorithmic rules create systemic exclusion.

For example, an automated recruitment rule may consistently exclude a protected group.

The claimant may challenge the discriminatory structure rather than focusing exclusively on one individual decision.

14. Österreichische Post AG

Court: CJEU
Case: C-300/21
Year: 2023

Principle

The Court distinguished:

infringement;

damage;

causation.

Algorithmic Rulemaking Relevance

Suppose an algorithmically constructed public rule unlawfully processes personal information.

A compensation claim still requires appropriate proof connecting:

unlawful processing → legally recognized damage → causation.

This prevents the analysis from treating every unlawful algorithmic rule as automatically compensable.

15. Google Spain SL v AEPD

Court: CJEU
Case: C-131/12
Year: 2014

Facts

Search-engine processing associated a person's name with historical information that continued to affect the person's reputation.

Principle

Technological organization and dissemination of information can produce significant effects on individual rights.

Algorithmic Rulemaking Relevance

The case illustrates the importance of secondary effects produced by algorithmic organization of information.

A regulatory algorithm can similarly transform ordinary data into a powerful legal classification.

16. Al-Dulimi and Montana Management Inc. v Switzerland

Court: ECtHR Grand Chamber
Year: 2016

Facts

The applicants challenged sanctions associated with UN counter-terrorism measures.

Principle

Individuals must have meaningful judicial protection against measures affecting their rights, even in sensitive international-security contexts.

Algorithmic Rulemaking Relevance

If AI contributes to sanctions or security regulation, the existence of national-security or international-policy considerations does not necessarily eliminate procedural protection.

17. Big Brother Watch and Others v United Kingdom

Court: ECtHR Grand Chamber
Year: 2021

Facts

The case concerned large-scale interception and surveillance.

Decision

The Court emphasized safeguards concerning:

authorization;

selection;

retention;

examination;

use;

oversight.

Algorithmic Rulemaking Relevance

The case demonstrates that sophisticated technology requires sophisticated legal safeguards.

This is especially important when algorithms transform surveillance information into regulatory classifications.

18. Core Liability Questions

Question 1: Who created the rule?

Potential actors include:

Parliament;

ministry;

regulator;

municipality;

administrative agency;

public-private consortium;

AI developer;

contractor.

Responsibility depends upon the source of legal authority and the actor's role.

Question 2: Did the authority have legal power?

An algorithm cannot independently create public authority.

The first question is:

What statutory or legal provision authorizes the rule?

If no sufficient legal authority exists, the algorithmic rule may be vulnerable to judicial review.

19. Question 3: Was the Rule Properly Made?

The authority may have been required to undertake:

consultation;

impact assessment;

parliamentary procedure;

public participation;

data-protection assessment;

equality assessment;

fundamental-rights assessment.

Failure to follow mandatory procedures may make the rule unlawful.

20. Question 4: Was the Algorithm Discriminatory?

Courts may examine:

demographic outcomes;

proxy variables;

training datasets;

error rates;

disparate impact;

protected characteristics.

For example:

AI regulatory model → disproportionately identifies one ethnic community as “high risk.”

Even if ethnicity is not explicitly used, indirect discrimination may arise.

21. Question 5: Was the Rule Proportionate?

A proportionality analysis commonly asks:

Legitimate objective

What objective is being pursued?

Suitability

Can the algorithm actually advance that objective?

Necessity

Is there a less restrictive alternative?

Balancing

Do the benefits justify the rights interference?

This is particularly important for:

surveillance;

policing;

sanctions;

immigration;

welfare;

taxation.

22. Question 6: Was There Meaningful Human Responsibility?

An authority cannot necessarily avoid responsibility by saying:

“The AI recommended the rule.”

The legal question is whether officials:

understood the system;

reviewed the output;

challenged assumptions;

examined alternatives;

assessed risks;

retained actual decision-making authority.

23. Evidence in Algorithmic Rulemaking Litigation

Important evidence can include:

Algorithmic evidence

source code;

model documentation;

training-data information;

model cards;

technical specifications;

audit reports.

Administrative evidence

ministerial instructions;

regulatory memoranda;

consultation documents;

impact assessments;

meeting records;

reasons for adopting the algorithm.

Statistical evidence

disparate-impact analysis;

error rates;

demographic outcomes;

false-positive/false-negative rates.

Governance evidence

AI risk assessments;

DPIAs;

fundamental-rights impact assessments;

procurement documents;

vendor contracts;

audit records.

24. Causation

Causation can operate at several levels.

Individual claim

AI rule → individual classification → adverse decision → damage.

Systemic claim

AI model → regulatory rule → repeated application → widespread rights interference.

The second type can be particularly important because the claimant may challenge the rule itself, not merely one administrative decision.

25. Potential Defendants

Depending on the legal system and claim, possible defendants or respondents include:

government ministry;

regulatory authority;

local authority;

administrative agency;

public contractor;

AI developer;

software supplier;

data provider;

conformity-assessment or auditing body.

However, responsibility is not automatically transferred to the private AI vendor merely because the government purchased the technology.

26. Defences

Authorities may argue:

1. Statutory authorization

The rule was expressly authorized by legislation.

2. Legitimate public objective

The algorithm was necessary for:

public safety;

fraud prevention;

tax collection;

national security;

public health.

3. Human control

Officials independently assessed the algorithmic recommendation.

4. No significant effect

The algorithm merely provided information rather than determining rights.

5. No discrimination

Any statistical disparity resulted from legitimate differences rather than prohibited discrimination.

6. Proportionality

The interference was necessary and appropriately limited.

7. No causation

The claimant would have received the same outcome without the algorithm.

27. Remedies

Possible remedies include:

annulment of an unlawful administrative rule;

judicial review;

suspension of enforcement;

prohibition of algorithmic processing;

correction of data;

reconsideration by a human decision-maker;

individual reassessment;

compensation;

injunction;

regulatory investigation;

discriminatory-rule correction;

destruction or restriction of unlawfully obtained data;

new consultation or rulemaking procedure.

Where a regulation itself is invalid, the remedy may extend beyond the individual claimant and affect the entire regulatory framework.

28. Comparative Case Table

CaseCourtMain PrincipleAlgorithmic Rulemaking Relevance
Kadi, C-402/05 P & C-415/05 PCJEUFundamental-rights review of EU measuresAI-assisted sanctions/regulation
Kadi, C-584/10 PCJEUEffective judicial reviewChallenging algorithmic classifications
Digital Rights Ireland, C-293/12 & C-594/12CJEUProportionality of mass data regulationLarge-scale AI regulation
Tele2 Sverige, C-203/15 & C-698/15CJEULimits on indiscriminate data retentionAI surveillance
La Quadrature du NetCJEUSecurity powers remain legally constrainedPredictive policing/intelligence
SCHUFA, C-634/21CJEUEffective automated decision-makingAI-generated regulatory risk scores
Dun & Bradstreet, C-203/22CJEUMeaningful information about automated logicTransparency and challenge
CHEZ, C-83/14CJEUIndirect discriminationAlgorithmic discriminatory rules
Feryn, C-54/07CJEUStructural discriminationSystemic algorithmic exclusion
Österreichische Post, C-300/21CJEUDamage and causationCompensation
Al-DulimiECtHR GCEffective judicial scrutinyAlgorithmic sanctions
Big Brother WatchECtHR GCSurveillance safeguardsAI surveillance regulation

29. Algorithmic Rulemaking Liability Test

A useful European legal framework can be summarized as:

Step 1 — Authority

Did the public body possess legal authority to create or apply the rule?

Step 2 — Procedure

Were all mandatory rulemaking procedures followed?

Step 3 — Data

Was the underlying data lawfully obtained and sufficiently accurate?

Step 4 — Algorithm

Was the algorithm appropriate, reliable and adequately validated?

Step 5 — Equality

Does the rule directly or indirectly discriminate?

Step 6 — Proportionality

Is the interference necessary and proportionate?

Step 7 — Transparency

Can affected persons understand and challenge the rule?

Step 8 — Human responsibility

Did public officials exercise genuine judgment?

Step 9 — Accountability

Can responsibility be attributed to identifiable institutions and officials?

Step 10 — Remedy

Is there an effective means of judicial or administrative challenge?

30. Algorithmic Rulemaking and the Rule of Law

The deepest concern is that AI may gradually transform policy choices into apparently objective technical outputs.

For example:

Political choice: “Which people should receive enhanced regulatory scrutiny?”

becomes:

Technical question: “Who has an AI risk score above 0.82?”

The mathematical appearance of the second question does not make the underlying choice legally neutral.

The authority still has to justify:

why the threshold exists;

why the variables were selected;

why particular risks are prioritized;

whether less intrusive methods exist;

whether particular groups are disproportionately affected;

who is accountable for the resulting consequences.

31. Conclusion

Algorithmic rulemaking liability is fundamentally about controlling the exercise of public power through computational systems. European law does not permit an authority to convert a legally contestable policy decision into an unquestionable technological output merely by placing an algorithm between the government and the citizen.

The strongest authorities include Kadi, Kadi II, Digital Rights Ireland, Tele2 Sverige, La Quadrature du Net, SCHUFA, Dun & Bradstreet, CHEZ, Feryn, Österreichische Post, Al-Dulimi, and Big Brother Watch.

Together, these cases support several important propositions:

Algorithmic regulation remains subject to the rule of law.

Public authorities remain responsible for fundamental-rights compliance when they use AI.

Technological efficiency does not eliminate proportionality requirements.

Apparently neutral algorithmic rules can produce unlawful indirect discrimination.

Large-scale data processing requires particularly strong safeguards.

Individuals need meaningful avenues to challenge consequential classifications.

Nominal human involvement does not necessarily cure excessive algorithmic influence.

International security or public-policy objectives do not automatically eliminate judicial review.

Where unlawful processing causes damage, causation and compensation must be separately assessed.

Private technology providers do not automatically become the sole bearers of responsibility merely because they supplied the algorithm.

The central principle is:

An algorithm may assist European rulemaking, but it cannot become a substitute for lawful authority, reasoned public decision-making, proportionality, equality, fundamental-rights protection and effective judicial review.

LEAVE A COMMENT