Algorithmic Rulemaking Liability .
Algorithmic Rulemaking Liability in Europe
1. Meaning and Scope
Algorithmic rulemaking liability concerns legal responsibility arising when public authorities, regulators, municipalities, agencies, or other bodies use algorithms or AI to formulate, interpret, apply, recommend, prioritize, or enforce rules and regulatory standards, and the resulting algorithmic process causes unlawful or unjustified harm.
Examples include:
AI-assisted drafting of regulations;
algorithmic eligibility rules for public benefits;
automated regulatory classifications;
AI-generated administrative policies;
algorithmic allocation of permits or licences;
automated enforcement priorities;
predictive regulatory inspections;
AI-assisted tax assessments;
automated immigration rules;
algorithmic sanctions screening;
risk-based regulatory supervision;
automated public procurement criteria.
There is no single European cause of action called “algorithmic rulemaking liability.” Claims generally arise under administrative law, constitutional/fundamental-rights law, GDPR, equality law, EU institutional law, public procurement law, and principles of effective judicial protection.
The central question is:
Can a public authority lawfully delegate or rely upon algorithmic systems when creating or applying rules that affect individuals, and who is responsible when the resulting rule is unlawful, discriminatory, disproportionate, irrational, or procedurally defective?
2. Difference Between Algorithmic Rulemaking and Algorithmic Decision-Making
The distinction is important.
Algorithmic decision-making
The algorithm determines or influences an individual case.
Example:
AI decides whether Person A receives a benefit.
Algorithmic rulemaking
The algorithm determines or substantially influences the criteria applied to many people.
Example:
AI develops a risk formula that determines which categories of welfare recipients will be investigated.
Thus:
Algorithmic rulemaking
→ creates/changes criteria
→ criteria are applied repeatedly
→ many individuals are affected.
This potentially creates systemic liability rather than merely an individual error.
3. European Legal Framework
A. Rule of Law
Algorithmic rulemaking must operate within the principle that public power must have:
lawful authority;
defined limits;
procedural safeguards;
accountability;
judicial review.
An administration generally cannot obtain powers merely because an algorithm recommends them.
B. EU Charter of Fundamental Rights
Important provisions include:
Article 7 — private and family life;
Article 8 — personal-data protection;
Article 20 — equality before the law;
Article 21 — non-discrimination;
Article 41 — good administration;
Article 47 — effective remedy and fair trial;
Article 52 — limitations on fundamental rights.
C. GDPR
Where rulemaking involves personal data, relevant provisions include:
Article 5 — fairness, transparency and accuracy;
Article 6 — lawful processing;
Article 9 — special-category data;
Articles 12–15 — transparency and access;
Article 22 — automated decisions;
Articles 24–25 — accountability and privacy by design;
Article 35 — impact assessments;
Article 82 — compensation.
D. EU AI Act
The AI Act adds obligations concerning, among other matters:
risk management;
data governance;
technical documentation;
logging;
transparency;
human oversight;
accuracy;
robustness;
cybersecurity;
fundamental-rights protection;
monitoring.
For public-sector AI, these requirements may become particularly important where the system affects access to public services or exercises regulatory power.
4. Main Forms of Algorithmic Rulemaking Liability
1. Ultra vires algorithmic rulemaking
The authority uses AI to create rules beyond its statutory power.
2. Procedurally defective rulemaking
The algorithm influences rules without:
consultation;
adequate reasons;
impact assessment;
legally required procedures.
3. Discriminatory rules
The algorithm creates criteria disproportionately disadvantaging a protected group.
4. Arbitrary rulemaking
The algorithm relies on irrelevant or irrational factors.
5. Opaque rulemaking
Affected persons cannot determine why the regulatory criteria exist.
6. Privacy-invasive rulemaking
Personal data are used excessively to construct regulatory classifications.
7. Disproportionate rulemaking
A legitimate regulatory goal is pursued through unnecessarily intrusive AI methods.
8. Defective delegated rulemaking
A public authority effectively allows a private technology provider to determine substantive regulatory criteria.
5. Case Law
1. Kadi and Al Barakaat International Foundation v Council and Commission
Court: CJEU
Joined Cases: C-402/05 P and C-415/05 P
Year: 2008
Facts
Individuals were subjected to EU sanctions implementing international counter-terrorism measures.
They challenged the measures on fundamental-rights grounds.
Decision
The CJEU held that EU measures remain subject to fundamental-rights review even when they implement international obligations.
Principle
Public authority cannot escape fundamental-rights review merely because the underlying policy originates from another legal or political system.
Algorithmic Rulemaking Relevance
Suppose an EU or national authority uses AI to formulate sanctions criteria or risk classifications.
The authority cannot simply argue:
“The algorithm generated the classification.”
The authority remains responsible for ensuring that the regulatory framework complies with:
fundamental rights;
proportionality;
procedural fairness;
effective judicial protection.
6. Kadi v Commission
Court: CJEU
Case: C-584/10 P
Year: 2013
Facts
The case concerned continued inclusion of an individual on a sanctions list and the adequacy of the procedures available for challenging the factual basis for the listing.
Decision
The CJEU emphasized the importance of effective judicial review and the ability of the affected person to challenge the factual material supporting the measure.
Principle
A person affected by a powerful governmental classification must have a meaningful opportunity to challenge the factual basis for that classification.
Algorithmic Rulemaking Relevance
This principle is highly relevant to AI-generated regulatory classifications.
If an authority creates an algorithmic rule such as:
“Persons exceeding risk score X are subject to enhanced regulatory controls,”
affected persons may need sufficient information to challenge:
the underlying data;
the classification;
the methodology;
the application of the rule.
7. Digital Rights Ireland
Court: CJEU
Joined Cases: C-293/12 and C-594/12
Year: 2014
Facts
EU legislation required large-scale retention of telecommunications data.
The legislation was challenged because of its impact on privacy and personal-data rights.
Decision
The CJEU invalidated the Data Retention Directive because the interference with fundamental rights was insufficiently constrained and disproportionate.
Principle
Large-scale technological regulation must contain appropriate safeguards and limitations.
Algorithmic Rulemaking Relevance
AI-based regulation frequently involves:
massive datasets;
predictive analysis;
population-level profiling.
The fact that technology can process enormous quantities of information does not itself justify regulatory collection and analysis.
A rulemaking authority must examine:
necessity + proportionality + safeguards + scope.
8. Tele2 Sverige and Watson
Court: CJEU
Joined Cases: C-203/15 and C-698/15
Year: 2016
Facts
The cases concerned national telecommunications data-retention regimes.
Decision
The CJEU rejected general and indiscriminate retention of communications data as incompatible with EU law except within tightly constrained circumstances.
Principle
Technological usefulness does not automatically make a regulatory measure lawful.
Algorithmic Rulemaking Relevance
An authority might argue:
“AI needs extensive data to identify regulatory risks.”
Tele2 illustrates why such reasoning is insufficient.
The authority must still establish:
legal basis;
necessity;
proportionality;
limits;
safeguards.
9. La Quadrature du Net and Others
Court: CJEU
Joined Cases: C-511/18, C-512/18 and C-520/18
Year: 2020
Facts
The cases concerned national measures involving retention and processing of electronic communications data, including measures justified by national security and serious crime.
Decision
The CJEU examined the relationship between national-security objectives, EU law and fundamental rights.
Principle
National security does not provide an unlimited exemption from legal constraints where EU law applies.
Algorithmic Rulemaking Relevance
This is relevant to government AI systems used for:
predictive policing;
terrorism-risk assessment;
border control;
intelligence analysis;
cybersecurity regulation.
An algorithmically generated security rationale cannot itself eliminate judicial scrutiny.
10. SCHUFA Holding AG v Verbraucherzentrale Bundesverband
Court: CJEU
Case: C-634/21
Year: 2023
Facts
SCHUFA's automated credit scoring significantly influenced subsequent decisions.
Decision
The CJEU held that automated scoring may constitute automated decision-making where it effectively determines a consequential decision.
Principle
Courts must examine the real practical influence of an algorithm rather than simply the formal structure of decision-making.
Algorithmic Rulemaking Relevance
This principle can apply by analogy to regulatory systems.
Suppose:
AI creates a regulatory risk score → regulator formally approves the resulting classification.
If the human approval is merely automatic or mechanical, the authority may face questions concerning genuine human responsibility.
This is particularly relevant where AI generates:
regulatory risk scores;
inspection priorities;
tax-risk classifications;
benefit-fraud scores;
immigration-risk classifications.
11. Dun & Bradstreet Austria GmbH
Court: CJEU
Case: C-203/22
Year: 2025
Principle
The CJEU emphasized meaningful information concerning automated decision-making and the ability of affected individuals to understand and exercise their rights.
Algorithmic Rulemaking Relevance
When an algorithm effectively establishes or applies important regulatory classifications, merely providing a statement such as:
“The system identified you as high risk”
is unlikely to provide meaningful accountability.
The affected party may need information sufficient to challenge the relevant reasoning and data.
12. CHEZ Razpredelenie Bulgaria
Court: CJEU
Case: C-83/14
Year: 2015
Facts
An electricity company adopted a measure involving electricity meters placed at unusual heights in a particular neighbourhood, partly because of concerns about meter tampering.
The affected neighbourhood had a predominantly Roma population.
Decision
The CJEU recognized that apparently neutral measures can amount to indirect discrimination where they particularly disadvantage a protected group.
Principle
A rule does not escape discrimination law merely because it is facially neutral.
Algorithmic Rulemaking Relevance
This is particularly important for algorithmic regulation.
An algorithm may use apparently neutral variables such as:
geographic location;
income;
occupation;
educational history;
transaction patterns.
These may function as proxies for protected characteristics.
Thus:
neutral algorithmic rule ≠ automatically neutral legal effect.
13. Feryn
Court: CJEU
Case: C-54/07
Year: 2008
Facts
An employer publicly stated that it would not recruit persons of a particular ethnic background.
Principle
Discriminatory recruitment practices can be legally significant even when identifying a particular rejected applicant is difficult.
Algorithmic Rulemaking Relevance
The case is useful by analogy when algorithmic rules create systemic exclusion.
For example, an automated recruitment rule may consistently exclude a protected group.
The claimant may challenge the discriminatory structure rather than focusing exclusively on one individual decision.
14. Österreichische Post AG
Court: CJEU
Case: C-300/21
Year: 2023
Principle
The Court distinguished:
infringement;
damage;
causation.
Algorithmic Rulemaking Relevance
Suppose an algorithmically constructed public rule unlawfully processes personal information.
A compensation claim still requires appropriate proof connecting:
unlawful processing → legally recognized damage → causation.
This prevents the analysis from treating every unlawful algorithmic rule as automatically compensable.
15. Google Spain SL v AEPD
Court: CJEU
Case: C-131/12
Year: 2014
Facts
Search-engine processing associated a person's name with historical information that continued to affect the person's reputation.
Principle
Technological organization and dissemination of information can produce significant effects on individual rights.
Algorithmic Rulemaking Relevance
The case illustrates the importance of secondary effects produced by algorithmic organization of information.
A regulatory algorithm can similarly transform ordinary data into a powerful legal classification.
16. Al-Dulimi and Montana Management Inc. v Switzerland
Court: ECtHR Grand Chamber
Year: 2016
Facts
The applicants challenged sanctions associated with UN counter-terrorism measures.
Principle
Individuals must have meaningful judicial protection against measures affecting their rights, even in sensitive international-security contexts.
Algorithmic Rulemaking Relevance
If AI contributes to sanctions or security regulation, the existence of national-security or international-policy considerations does not necessarily eliminate procedural protection.
17. Big Brother Watch and Others v United Kingdom
Court: ECtHR Grand Chamber
Year: 2021
Facts
The case concerned large-scale interception and surveillance.
Decision
The Court emphasized safeguards concerning:
authorization;
selection;
retention;
examination;
use;
oversight.
Algorithmic Rulemaking Relevance
The case demonstrates that sophisticated technology requires sophisticated legal safeguards.
This is especially important when algorithms transform surveillance information into regulatory classifications.
18. Core Liability Questions
Question 1: Who created the rule?
Potential actors include:
Parliament;
ministry;
regulator;
municipality;
administrative agency;
public-private consortium;
AI developer;
contractor.
Responsibility depends upon the source of legal authority and the actor's role.
Question 2: Did the authority have legal power?
An algorithm cannot independently create public authority.
The first question is:
What statutory or legal provision authorizes the rule?
If no sufficient legal authority exists, the algorithmic rule may be vulnerable to judicial review.
19. Question 3: Was the Rule Properly Made?
The authority may have been required to undertake:
consultation;
impact assessment;
parliamentary procedure;
public participation;
data-protection assessment;
equality assessment;
fundamental-rights assessment.
Failure to follow mandatory procedures may make the rule unlawful.
20. Question 4: Was the Algorithm Discriminatory?
Courts may examine:
demographic outcomes;
proxy variables;
training datasets;
error rates;
disparate impact;
protected characteristics.
For example:
AI regulatory model → disproportionately identifies one ethnic community as “high risk.”
Even if ethnicity is not explicitly used, indirect discrimination may arise.
21. Question 5: Was the Rule Proportionate?
A proportionality analysis commonly asks:
Legitimate objective
What objective is being pursued?
Suitability
Can the algorithm actually advance that objective?
Necessity
Is there a less restrictive alternative?
Balancing
Do the benefits justify the rights interference?
This is particularly important for:
surveillance;
policing;
sanctions;
immigration;
welfare;
taxation.
22. Question 6: Was There Meaningful Human Responsibility?
An authority cannot necessarily avoid responsibility by saying:
“The AI recommended the rule.”
The legal question is whether officials:
understood the system;
reviewed the output;
challenged assumptions;
examined alternatives;
assessed risks;
retained actual decision-making authority.
23. Evidence in Algorithmic Rulemaking Litigation
Important evidence can include:
Algorithmic evidence
source code;
model documentation;
training-data information;
model cards;
technical specifications;
audit reports.
Administrative evidence
ministerial instructions;
regulatory memoranda;
consultation documents;
impact assessments;
meeting records;
reasons for adopting the algorithm.
Statistical evidence
disparate-impact analysis;
error rates;
demographic outcomes;
false-positive/false-negative rates.
Governance evidence
AI risk assessments;
DPIAs;
fundamental-rights impact assessments;
procurement documents;
vendor contracts;
audit records.
24. Causation
Causation can operate at several levels.
Individual claim
AI rule → individual classification → adverse decision → damage.
Systemic claim
AI model → regulatory rule → repeated application → widespread rights interference.
The second type can be particularly important because the claimant may challenge the rule itself, not merely one administrative decision.
25. Potential Defendants
Depending on the legal system and claim, possible defendants or respondents include:
government ministry;
regulatory authority;
local authority;
administrative agency;
public contractor;
AI developer;
software supplier;
data provider;
conformity-assessment or auditing body.
However, responsibility is not automatically transferred to the private AI vendor merely because the government purchased the technology.
26. Defences
Authorities may argue:
1. Statutory authorization
The rule was expressly authorized by legislation.
2. Legitimate public objective
The algorithm was necessary for:
public safety;
fraud prevention;
tax collection;
national security;
public health.
3. Human control
Officials independently assessed the algorithmic recommendation.
4. No significant effect
The algorithm merely provided information rather than determining rights.
5. No discrimination
Any statistical disparity resulted from legitimate differences rather than prohibited discrimination.
6. Proportionality
The interference was necessary and appropriately limited.
7. No causation
The claimant would have received the same outcome without the algorithm.
27. Remedies
Possible remedies include:
annulment of an unlawful administrative rule;
judicial review;
suspension of enforcement;
prohibition of algorithmic processing;
correction of data;
reconsideration by a human decision-maker;
individual reassessment;
compensation;
injunction;
regulatory investigation;
discriminatory-rule correction;
destruction or restriction of unlawfully obtained data;
new consultation or rulemaking procedure.
Where a regulation itself is invalid, the remedy may extend beyond the individual claimant and affect the entire regulatory framework.
28. Comparative Case Table
| Case | Court | Main Principle | Algorithmic Rulemaking Relevance |
|---|---|---|---|
| Kadi, C-402/05 P & C-415/05 P | CJEU | Fundamental-rights review of EU measures | AI-assisted sanctions/regulation |
| Kadi, C-584/10 P | CJEU | Effective judicial review | Challenging algorithmic classifications |
| Digital Rights Ireland, C-293/12 & C-594/12 | CJEU | Proportionality of mass data regulation | Large-scale AI regulation |
| Tele2 Sverige, C-203/15 & C-698/15 | CJEU | Limits on indiscriminate data retention | AI surveillance |
| La Quadrature du Net | CJEU | Security powers remain legally constrained | Predictive policing/intelligence |
| SCHUFA, C-634/21 | CJEU | Effective automated decision-making | AI-generated regulatory risk scores |
| Dun & Bradstreet, C-203/22 | CJEU | Meaningful information about automated logic | Transparency and challenge |
| CHEZ, C-83/14 | CJEU | Indirect discrimination | Algorithmic discriminatory rules |
| Feryn, C-54/07 | CJEU | Structural discrimination | Systemic algorithmic exclusion |
| Österreichische Post, C-300/21 | CJEU | Damage and causation | Compensation |
| Al-Dulimi | ECtHR GC | Effective judicial scrutiny | Algorithmic sanctions |
| Big Brother Watch | ECtHR GC | Surveillance safeguards | AI surveillance regulation |
29. Algorithmic Rulemaking Liability Test
A useful European legal framework can be summarized as:
Step 1 — Authority
Did the public body possess legal authority to create or apply the rule?
Step 2 — Procedure
Were all mandatory rulemaking procedures followed?
Step 3 — Data
Was the underlying data lawfully obtained and sufficiently accurate?
Step 4 — Algorithm
Was the algorithm appropriate, reliable and adequately validated?
Step 5 — Equality
Does the rule directly or indirectly discriminate?
Step 6 — Proportionality
Is the interference necessary and proportionate?
Step 7 — Transparency
Can affected persons understand and challenge the rule?
Step 8 — Human responsibility
Did public officials exercise genuine judgment?
Step 9 — Accountability
Can responsibility be attributed to identifiable institutions and officials?
Step 10 — Remedy
Is there an effective means of judicial or administrative challenge?
30. Algorithmic Rulemaking and the Rule of Law
The deepest concern is that AI may gradually transform policy choices into apparently objective technical outputs.
For example:
Political choice: “Which people should receive enhanced regulatory scrutiny?”
becomes:
Technical question: “Who has an AI risk score above 0.82?”
The mathematical appearance of the second question does not make the underlying choice legally neutral.
The authority still has to justify:
why the threshold exists;
why the variables were selected;
why particular risks are prioritized;
whether less intrusive methods exist;
whether particular groups are disproportionately affected;
who is accountable for the resulting consequences.
31. Conclusion
Algorithmic rulemaking liability is fundamentally about controlling the exercise of public power through computational systems. European law does not permit an authority to convert a legally contestable policy decision into an unquestionable technological output merely by placing an algorithm between the government and the citizen.
The strongest authorities include Kadi, Kadi II, Digital Rights Ireland, Tele2 Sverige, La Quadrature du Net, SCHUFA, Dun & Bradstreet, CHEZ, Feryn, Österreichische Post, Al-Dulimi, and Big Brother Watch.
Together, these cases support several important propositions:
Algorithmic regulation remains subject to the rule of law.
Public authorities remain responsible for fundamental-rights compliance when they use AI.
Technological efficiency does not eliminate proportionality requirements.
Apparently neutral algorithmic rules can produce unlawful indirect discrimination.
Large-scale data processing requires particularly strong safeguards.
Individuals need meaningful avenues to challenge consequential classifications.
Nominal human involvement does not necessarily cure excessive algorithmic influence.
International security or public-policy objectives do not automatically eliminate judicial review.
Where unlawful processing causes damage, causation and compensation must be separately assessed.
Private technology providers do not automatically become the sole bearers of responsibility merely because they supplied the algorithm.
The central principle is:
An algorithm may assist European rulemaking, but it cannot become a substitute for lawful authority, reasoned public decision-making, proportionality, equality, fundamental-rights protection and effective judicial review.

comments