Civil Law And Uae Algorithmic Accountability In Governance .

Civil Law and UAE Algorithmic Accountability in Governance

1. Introduction

Algorithmic accountability in governance means that when UAE government authorities use algorithms, artificial intelligence (AI), automated decision-making, predictive systems, or data-driven tools, there must be identifiable responsibility for how those systems are designed, operated, supervised, and used.

In civil-law terms, the central question is:

Who is legally responsible when an algorithm used by a public authority produces an unlawful, discriminatory, erroneous, or harmful outcome?

The UAE does not presently have one comprehensive federal statute called an “Algorithmic Accountability Act.” Instead, accountability is derived from several overlapping areas of law, including:

  • the UAE Constitution;
  • the Civil Transactions Law;
  • administrative law and judicial review;
  • evidence law;
  • personal-data protection;
  • electronic transactions and trust services;
  • sector-specific regulation;
  • government AI policies and ethical frameworks;
  • DIFC/ADGM rules where those jurisdictions are involved.

A particularly important development is the Federal Decree-Law No. 25 of 2025 promulgating the new Civil Transactions Law, which came into force on 1 June 2026. Therefore, current UAE civil-liability analysis should distinguish the new law from older cases decided under the repealed 1985 Civil Transactions Law.

2. Meaning of Algorithmic Accountability

Algorithmic accountability involves several connected duties.

A. Identification of responsibility

A government body cannot normally avoid responsibility simply by saying:

“The computer made the decision.”

The legal responsibility generally remains with the authority, institution, official, contractor, or other legally responsible actor.

B. Human oversight

Important governmental decisions should have meaningful human supervision, particularly where the algorithm affects:

  • licences;
  • permits;
  • benefits;
  • immigration status;
  • taxation;
  • enforcement;
  • public services;
  • property;
  • employment;
  • healthcare;
  • judicial or quasi-judicial decisions.

C. Accuracy

Government algorithms must use reliable data and appropriate methodology.

D. Transparency

Affected persons should, subject to legitimate confidentiality and security restrictions, be able to understand the legal basis and material reasons for an adverse governmental decision.

E. Non-discrimination

Algorithmic decision-making should not reproduce unlawful discrimination through biased data, proxies, or system design.

F. Auditability

There should be records sufficient to determine:

  • what data were used;
  • which model or rule was applied;
  • who authorised deployment;
  • what version of the system operated;
  • whether a human reviewed the output;
  • why the final governmental decision was made.

3. Constitutional Foundation

Algorithmic governance must operate consistently with fundamental constitutional principles.

Article 25 — Equality

The UAE Constitution establishes equality before the law and prohibits distinctions among citizens based on matters such as origin, nationality, faith and social status.

Consequently, an algorithm that systematically produces legally impermissible unequal treatment could raise constitutional and administrative-law concerns.

Article 41 — Right to Complain

Individuals have the right to complain to competent authorities, including judicial authorities, concerning violations of rights and freedoms.

This is particularly important for automated government decisions because an affected person must have a meaningful mechanism to challenge an algorithmically influenced decision.

Article 94 — Justice and Judicial Independence

Justice is the basis of government, and judges are independent and subject only to law and conscience.

An algorithm therefore cannot replace the legal responsibility of the competent judicial authority merely because technology was used to assist the decision-making process.

4. Civil Liability for Algorithmic Government Decisions

A useful civil-law framework can be expressed as:

Algorithmic conduct → unlawful/faulty governmental conduct → damage → causation → liability → remedy

The principal questions are:

  1. Was there an unlawful or negligent act?
  2. Was the algorithm reasonably designed and supervised?
  3. Was inaccurate or unlawfully obtained data used?
  4. Was the person given appropriate procedural protection?
  5. Did the algorithm materially contribute to the decision?
  6. Did the decision cause legally compensable damage?
  7. Was the damage foreseeable and sufficiently connected to the conduct?

Under civil-law reasoning, the fact that technology was used does not automatically create a new category of liability. Rather, traditional principles are applied to technologically sophisticated conduct.

5. Government Contractor and Algorithm Vendor Liability

Algorithmic government systems are frequently developed by private technology companies.

This creates a chain of accountability:

Government authority → procurement decision → vendor → software/model → data → algorithmic output → official decision → citizen harm

A government body generally cannot assume that outsourcing eliminates its legal responsibilities.

For example, suppose a government authority contracts with a technology company to develop an automated fraud-detection system.

The system wrongly identifies a citizen as fraudulent and automatically suspends a benefit.

Potential questions include:

  • Did the authority properly test the system?
  • Did the vendor disclose known limitations?
  • Was the training data appropriate?
  • Was the false-positive rate acceptable?
  • Was there human review?
  • Was the affected person notified?
  • Was there an appeal mechanism?
  • Did the authority blindly rely upon the vendor?

The contractual relationship between government and vendor does not necessarily determine the citizen's rights.

6. Algorithmic Transparency

Transparency does not necessarily mean publishing the source code.

There can be several levels of transparency:

LevelMeaning
BasicInforming the person that automated technology was used
ProceduralExplaining the legal and administrative process
Reason-givingExplaining the material reasons for the decision
TechnicalExplaining relevant model/data characteristics
AuditAllowing authorised examination of the system
Full disclosureExceptional disclosure of source code or proprietary technical material

UAE law must balance transparency against:

  • national security;
  • cybersecurity;
  • confidential government information;
  • trade secrets;
  • personal-data protection;
  • third-party privacy.

Thus, algorithmic accountability does not necessarily require unrestricted disclosure of algorithms.

7. Human Oversight

Human oversight is particularly important for high-impact decisions.

Consider three situations:

Low-risk

An algorithm sorts applications into administrative queues.

Human review may be minimal.

Medium-risk

An algorithm identifies applications requiring further investigation.

A human officer should assess the result before adverse action.

High-risk

An algorithm determines whether a person should lose a governmental entitlement.

A meaningful human review and appeal mechanism become particularly important.

The important distinction is between:

human-in-the-loop

and

human rubber-stamping.

A person who simply approves every algorithmic recommendation without reviewing it may not provide genuine accountability.

8. Data Protection and Algorithmic Governance

Algorithmic systems frequently process large quantities of personal information.

Relevant issues include:

  • lawful processing;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • security;
  • access rights;
  • correction;
  • retention;
  • cross-border transfers;
  • automated profiling.

The UAE's federal personal-data framework therefore forms an important part of algorithmic accountability.

An algorithm cannot become legally legitimate merely because its output is statistically accurate if the underlying data were unlawfully collected or processed.

9. Automated Decisions and Civil Evidence

The Federal Decree-Law No. 35 of 2022 on Evidence in Civil and Commercial Transactions is important where a dispute concerns algorithmic decision-making.

Electronic records, system logs, digital communications and other electronic evidence may become relevant to proving:

  • what the algorithm did;
  • what data it received;
  • what output it generated;
  • whether a human intervened;
  • when the decision was made;
  • whether the system malfunctioned.

Therefore, government bodies using algorithms should maintain reliable audit trails.

An authority that cannot reconstruct how an automated decision was reached may face serious evidentiary difficulties in litigation.

10. Algorithmic Bias

Algorithmic bias may arise in several ways.

Historical-data bias

The training data may reproduce historical inequalities.

Selection bias

Certain groups may be inadequately represented.

Proxy discrimination

The system may use apparently neutral variables that indirectly correlate with protected characteristics.

Automation bias

Officials may give excessive weight to computer-generated recommendations.

Feedback-loop bias

An algorithm may repeatedly direct enforcement toward an area or group, producing more data suggesting that the group requires enforcement.

Civil-law accountability therefore requires examining not merely the mathematical model but the entire decision-making ecosystem.

11. Abuse of Rights and Algorithmic Governance

The UAE's civil-law doctrine of abuse of rights is also potentially relevant.

Under the former Civil Transactions Law, Article 106 recognised circumstances in which exercise of a right becomes unlawful, including:

  • intention to cause harm;
  • pursuing an unlawful interest;
  • disproportion between benefit and harm;
  • exceeding customary limits.

The new Civil Transactions Law continues the modernised approach to lawful and abusive exercise of rights.

This doctrine could become relevant where a governmental power is technically lawful but exercised through an algorithm in a manner that produces an unjustifiable or disproportionate result.

12. Case Laws

Because UAE reported jurisprudence specifically concerning government algorithms is still limited, the following cases should be divided into direct AI/technology authorities and analogous civil/administrative authorities.

Case 1 — Arabyads Holding Ltd v Gulrez Alam Marghoob Alam

[2025] ADGMCFI 0032

This is one of the most important recent UAE AI-related decisions.

A UAE law firm submitted legal material containing numerous false or incorrectly cited authorities. The proceedings examined the use of AI-assisted legal research.

The ADGM Court emphasised that professional responsibility remains with the human lawyers. AI-assisted research does not transfer responsibility to the machine.

Principle

A person cannot escape legal responsibility by attributing an error to artificial intelligence.

Relevance to government algorithms

The same principle is highly relevant to public administration.

A government authority cannot simply argue:

“The algorithm produced the result.”

The authority must maintain appropriate verification and supervision.

13. Case 2 — Stelian Gheorghe v BSA Ahmad Bin Hezeem & Associates LLP & Jimmy Haoula

[2025] DIFC CFI 045

The DIFC Court considered proceedings containing material alleged to have been partly generated or assisted by AI.

The case demonstrated the importance of accuracy in pleadings and evidence.

The Court made clear that legal submissions and evidence must satisfy procedural and professional requirements regardless of whether technology was used in their preparation.

Principle

AI-generated material does not receive automatic credibility merely because it is technologically produced.

Relevance

For algorithmic governance, this supports the proposition that:

  • AI outputs require verification;
  • human responsibility remains essential;
  • technological assistance does not eliminate procedural duties.

14. Case 3 — Aegis Resources DMCC v Union Bank of India (DIFC Branch)

[2020] DIFC CFI 004

This case involved electronic communications and cyber fraud.

Fraudulent payment instructions were communicated after a customer's email system was compromised. The Court considered responsibility surrounding the electronic transaction and the circumstances in which the bank acted on the instructions.

Principle

Electronic systems do not eliminate ordinary legal duties.

Relevance

The case is useful by analogy for algorithmic governance because it demonstrates that courts can examine:

  • technological systems;
  • electronic instructions;
  • security failures;
  • causation;
  • allocation of loss.

An automated governmental system would similarly need to be examined in terms of its technical operation and the human decisions surrounding it.

15. Case 4 — International Electro-Mechanical Services Co LLC v Emirates Speciality Hospital FZ-LLC

[2020] DIFC CFI 114

The DIFC Court considered actual, implied and apparent authority.

The Court recognised that authority can arise from circumstances and conduct rather than merely from an express written authorisation.

Relevance to AI

Suppose an AI system is authorised to communicate with citizens or enter transactions on behalf of a governmental entity.

The legal question becomes:

Did the government authority actually authorise the system, and what limits existed on that authority?

An AI system cannot ordinarily create unlimited authority merely because it technically performs an action.

16. Case 5 — Currency Matters Middle East v Michael Page International Ltd

[2018] DIFC CFI 039

The case concerned apparent authority arising from corporate conduct, including communications and conduct associated with senior management.

Principle

Third parties may rely upon an appearance of authority where the principal's conduct reasonably creates that appearance.

Algorithmic relevance

This becomes significant where a government AI system communicates externally.

If an official governmental platform appears to make an authoritative decision, questions may arise concerning:

  • authority;
  • reliance;
  • representation;
  • legitimate expectations;
  • responsibility for the communication.

17. Case 6 — Khaled Salem Musabeh Humad Al Mheiri v John Cameron

[2025] DIFC CA 008

The DIFC Court of Appeal considered principles governing apparent authority.

The analysis emphasised the importance of:

  • conduct of the principal;
  • reasonable belief;
  • authority;
  • good faith.

Relevance to algorithmic governance

An automated governmental platform may create a representation to a citizen.

For example, if a government portal officially informs someone that a licence has been approved, the legal consequences cannot automatically be avoided simply by saying that an AI system generated the notification.

The precise legal effect would depend on the statutory framework and authority of the system.

18. Case 7 — Dubai Court of Cassation, Civil Cassation Nos. 158/2006 and 179/2006

This case concerned the abuse of rights doctrine.

The Court examined the use of a legal right in circumstances producing unlawful harm and applied the principles contained in Article 106 of the former Civil Transactions Law.

Principle

A formally existing right may be exercised unlawfully when the statutory conditions for abuse are established.

Algorithmic relevance

Government agencies may possess legitimate regulatory powers, but algorithmic implementation must not convert a lawful power into disproportionate or abusive administration.

19. Case 8 — Dubai Court of Cassation, Commercial Cassation No. 1070/2022

The Court examined the right to complain, report wrongdoing and resort to judicial authorities.

The exercise of such rights is legitimate, but they can potentially be abused where exercised maliciously or in bad faith.

Algorithmic relevance

This principle can be extended by analogy to automated enforcement systems.

A government agency may legitimately use:

  • fraud detection;
  • compliance monitoring;
  • risk scoring;
  • automated investigations.

But the existence of a legitimate enforcement power does not necessarily justify every method of exercising it.

20. Case 9 — Dubai Court of Cassation, Commercial Cassation No. 467/2025

The Court again examined abuse of rights under the UAE civil-law framework.

The analysis focused on the recognised criteria for determining when the exercise of a right becomes unlawful and emphasised the importance of evidence and factual assessment.

Relevance

For algorithmic administration, the court may need to examine:

  • the purpose of the governmental measure;
  • proportionality;
  • harm;
  • the legitimacy of the governmental interest;
  • the manner in which the power was exercised.

An algorithmic output should therefore not automatically be treated as conclusive proof that the government's action was lawful.

21. Case 10 — UAE Federal Supreme Court, Civil Appeal No. 867/2025

The Federal Supreme Court emphasised the importance of properly addressing a decisive substantive defence.

Failure to consider a material defence can constitute a fundamental defect in reasoning and affect the right of defence.

Algorithmic relevance

This is particularly important when an administrative authority relies on automated systems.

Suppose a citizen demonstrates that:

  • the database contains incorrect information;
  • the algorithm used obsolete information;
  • the person belongs to an exempt category;
  • the system misclassified the person.

A genuine review mechanism should address those substantive objections rather than merely repeat the automated result.

22. Algorithmic Accountability and Administrative Decisions

Algorithmic governance can be analysed through five stages.

Stage 1 — Algorithm design

The authority should determine:

  • purpose;
  • legal authority;
  • risks;
  • affected groups;
  • data sources;
  • expected error rate.

Stage 2 — Deployment

Before deployment:

  • testing;
  • cybersecurity assessment;
  • bias testing;
  • validation;
  • human oversight arrangements;
  • documentation.

Stage 3 — Decision

The system produces a recommendation or decision.

Stage 4 — Human review

An authorised official should determine whether the output can lawfully be acted upon.

Stage 5 — Challenge

The affected person should have an appropriate mechanism for:

  • explanation;
  • correction;
  • reconsideration;
  • appeal;
  • judicial review;
  • compensation where legally available.

23. Algorithmic Accountability and AI Judicial Systems

This issue is particularly sensitive.

AI may assist courts with:

  • document classification;
  • case management;
  • research;
  • translation;
  • scheduling;
  • precedent retrieval;
  • evidence organisation;
  • transcription.

But there is a fundamental distinction between:

AI-assisted adjudication

and

AI-controlled adjudication.

The former can support judges.

The latter creates difficult questions concerning:

  • judicial independence;
  • procedural fairness;
  • reasoning;
  • transparency;
  • right to be heard;
  • appeal;
  • responsibility;
  • constitutional legitimacy.

The UAE's emerging judicial-AI initiatives therefore make human supervision and validation especially important.

24. DIFC's Special Position

The DIFC is particularly relevant because its Digital Economy Court framework expressly addresses technology disputes, including matters involving:

  • AI;
  • digital assets;
  • blockchain;
  • cloud computing;
  • digital data;
  • automated dispute resolution;
  • robotics;
  • cyber-physical systems.

The DIFC Courts have also issued guidance concerning generative AI in proceedings.

This does not automatically apply to every UAE government decision, because DIFC law and courts are distinct from the onshore UAE federal/emirate court system.

Nevertheless, DIFC jurisprudence can provide persuasive comparative guidance on technologically sophisticated disputes.

25. ADGM and Algorithmic Accountability

ADGM provides another important UAE common-law jurisdiction.

Its significance comes from:

  • English common-law principles;
  • strong commercial jurisprudence;
  • sophisticated financial regulation;
  • technology-focused disputes;
  • judicial attention to professional responsibility.

Arabyads is especially significant because it demonstrates that sophisticated technology does not eliminate professional accountability.

This principle is highly transferable to public-sector AI governance.

26. Government Procurement and Vendor Accountability

A strong UAE algorithmic-accountability model should require government contracts with AI vendors to address:

  1. accuracy;
  2. cybersecurity;
  3. data protection;
  4. audit rights;
  5. documentation;
  6. model updates;
  7. incident reporting;
  8. bias testing;
  9. explainability;
  10. liability allocation;
  11. intellectual property;
  12. subcontracting;
  13. termination;
  14. data deletion;
  15. regulatory cooperation.

Without these provisions, accountability can become unclear when an algorithm causes harm.

27. Causation in Algorithmic Harm

Causation can be complex.

Suppose:

Incorrect database → algorithmic classification → human approval → adverse decision → financial loss

Who caused the damage?

A court may need to determine whether:

  • the data error;
  • algorithm design;
  • vendor negligence;
  • government deployment;
  • human approval;
  • claimant's conduct

was the legally relevant cause.

This makes algorithmic cases different from simple negligence cases because responsibility may be distributed across several actors.

28. Algorithmic Errors and Compensation

Possible forms of harm include:

Economic harm

  • loss of benefits;
  • loss of business;
  • additional costs;
  • property loss;
  • lost income.

Non-economic harm

  • reputational injury;
  • dignity;
  • emotional distress;
  • interference with personal rights.

Procedural harm

  • denial of a fair opportunity to challenge the decision;
  • failure to consider relevant evidence;
  • unlawful delay.

The availability and amount of compensation depend on the applicable substantive and procedural law.

29. Remedies

Depending on the circumstances, potential remedies may include:

  • annulment or setting aside of an unlawful administrative decision;
  • reconsideration;
  • correction of personal data;
  • injunction;
  • declaratory relief;
  • restoration of a benefit or entitlement;
  • damages;
  • correction of an official record;
  • procedural relief;
  • disciplinary or regulatory action;
  • contractual remedies against a technology provider.

The appropriate remedy depends heavily on whether the dispute is an administrative-law dispute, civil claim, regulatory proceeding, employment dispute, consumer matter, or DIFC/ADGM proceeding.

30. Proposed UAE Algorithmic Accountability Framework

A comprehensive governance model could contain the following principles:

PrincipleRequirement
LegalityAlgorithm must have a lawful governmental basis
Purpose limitationSystem used only for authorised purposes
AccuracyReliable data and validated models
FairnessTesting for discriminatory outcomes
TransparencyAppropriate explanation of material decisions
Human oversightCompetent official remains responsible
AuditabilityComplete decision records
PrivacyLawful processing of personal data
SecurityProtection against manipulation
ProportionalityAutomated measures should not be excessive
ContestabilityAffected person can challenge results
AccountabilityIdentifiable person/entity responsible
Vendor governanceContracts allocate technical and legal duties
Continuous monitoringSystems reviewed after deployment

31. Major Legal Challenges

1. Black-box algorithms

A decision-maker may not understand why the algorithm produced a particular result.

2. Multiple responsible actors

Responsibility can be divided between government, vendor, data provider and official.

3. Rapid technological change

Legal rules can become outdated faster than traditional legislation.

4. Confidentiality

Security and trade-secret concerns may restrict disclosure.

5. Bias

Apparently neutral systems can produce discriminatory outcomes.

6. Automation bias

Officials may over-trust computer-generated recommendations.

7. Evidence

It may be difficult to reconstruct historical algorithmic decisions.

8. Cross-border systems

Cloud providers and AI models may operate outside the UAE.

9. Model updates

An AI model may change after the original governmental decision.

10. Responsibility gap

Without clear governance, every actor may blame another actor.

32. Relationship Between Civil Law and Algorithmic Accountability

The most important conceptual point is that AI does not eliminate civil-law principles.

Traditional concepts remain relevant:

Good faith

Reasonableness

Abuse of rights

Fault

Damage

Causation

Compensation

The technological system changes the factual environment, but the legal principles continue to perform their regulatory function.

33. Summary of the Case Laws

CaseMain principleAlgorithmic relevance
Arabyads Holding Ltd v Gulrez Alam Marghoob Alam [2025] ADGMCFI 0032AI-assisted work requires human verificationDirect AI accountability
Stelian Gheorghe v BSA Ahmad Bin Hezeem [2025] DIFC CFI 045AI-generated/assisted material remains subject to procedural standardsDirect AI/procedural accountability
Aegis Resources DMCC v Union Bank of India [2020] DIFC CFI 004Electronic systems and cyber fraud do not eliminate legal dutiesElectronic-system accountability
International Electro-Mechanical Services v Emirates Speciality Hospital [2020] DIFC CFI 114Actual, implied and apparent authorityAI-agent authority
Currency Matters Middle East v Michael Page [2018] DIFC CFI 039Apparent authority can arise from conductGovernment digital representations
Khaled Salem Al Mheiri v John Cameron [2025] DIFC CA 008Principal's conduct can create apparent authorityAutomated government communications
Dubai Cassation 158/2006 & 179/2006Abuse of rights creates liabilityAbuse through automated administration
Dubai Cassation 1070/2022Legitimate rights can be abused through bad faithAutomated enforcement
Dubai Cassation 467/2025Abuse-of-rights criteria and evidentiary assessmentProportionality of algorithmic decisions
UAE Federal Supreme Court Civil Appeal 867/2025Material defences must be properly consideredRight to challenge automated decisions

34. Conclusion

UAE algorithmic accountability in governance is best understood as an extension of established civil-law, constitutional, administrative, evidence, data-protection and professional-responsibility principles into an AI-driven environment.

The central rule should be:

Technology may assist governmental decision-making, but it cannot become a legal shield against accountability.

An algorithm is not normally an independent legal person capable of bearing governmental responsibility. The legally responsible authority must therefore ensure that the system is lawful, accurate, proportionate, secure, reviewable and appropriately supervised.

The developing UAE approach can be summarised as:

Lawful authority + reliable data + responsible algorithm + human oversight + transparency + right to challenge + auditability + effective remedy = algorithmic accountability.

The Arabyads decision is particularly significant because it demonstrates the emerging UAE judicial attitude that the use of AI does not displace human professional responsibility. The other UAE and DIFC authorities reinforce the related principles of electronic-system responsibility, authority, good faith, procedural fairness and abuse of rights.

Because UAE-specific reported case law on government algorithmic decision-making itself remains limited, the strongest present legal methodology is to combine the emerging AI authorities with established civil-law and administrative principles. This is likely to become increasingly important as UAE governmental bodies expand the use of AI and automated decision systems.

LEAVE A COMMENT