Civil Law And Uae Algorithmic Decision Liability Issues .

Civil Law and UAE Algorithmic Decision Liability Issues

1. Introduction

Algorithmic decision liability concerns the legal responsibility that arises when an automated or AI-assisted system makes, recommends, influences, or executes a decision that causes legally recognised harm.

In the UAE, this issue is becoming increasingly important because AI and automated systems may be used in:

  • financial services;
  • insurance;
  • healthcare;
  • employment;
  • government services;
  • regulatory enforcement;
  • consumer transactions;
  • dispute resolution;
  • legal research;
  • court administration; and
  • other high-impact decision-making.

The central civil-law question is:

When an algorithm makes or contributes to a harmful decision, who is legally responsible for the resulting damage?

The answer cannot simply be that “the AI made the decision.” AI is generally not treated as an independent legal person. Liability therefore normally has to be attributed to a developer, manufacturer, vendor, owner, operator, deployer, employer, government authority, professional, or other legally responsible person or entity, depending upon the circumstances.

The UAE's Federal Decree-Law No. 25 of 2025 promulgating the Civil Transactions Law is now the principal general civil-law framework and entered into force on 1 June 2026, replacing the 1985 Civil Transactions Law. Many of the cases discussed below predate the new Code and should therefore be understood as foundational jurisprudential authorities, rather than direct interpretations of the 2025 Code.

2. Meaning of Algorithmic Decision Liability

Algorithmic decision liability arises when an automated system contributes to a decision and that decision produces legally relevant harm.

A simplified chain is:

Data → Algorithm → Recommendation/Decision → Human or Automated Action → Harm

For liability purposes, the court may have to determine:

  1. Was the system defective?
  2. Was the data inaccurate?
  3. Was the algorithm negligently designed?
  4. Was it appropriate for the particular purpose?
  5. Was there adequate human supervision?
  6. Was the system improperly used?
  7. Was there a failure to update or monitor it?
  8. Did the algorithm cause the harm?
  9. Who controlled the system?
  10. What remedy should be granted?

3. Current UAE Legal Framework

Algorithmic liability is not governed by one single UAE statute. Instead, several legal frameworks may operate together.

A. Civil Transactions Law

The Civil Transactions Law supplies the general principles concerning:

  • obligations;
  • contracts;
  • fault;
  • causation;
  • damage;
  • compensation;
  • good faith;
  • abuse of rights; and
  • contractual interpretation.

Therefore, AI does not eliminate traditional civil-law liability principles.

B. Evidence Law

The Federal Decree-Law No. 35 of 2022 on Evidence in Civil and Commercial Transactions is highly relevant.

An algorithmic dispute may involve:

  • electronic records;
  • system logs;
  • databases;
  • electronic communications;
  • audit trails;
  • expert reports;
  • software records;
  • metadata;
  • automated decisions; and
  • digital forensic material.

The court may therefore need to determine both the authenticity and probative value of algorithmic evidence.

C. Electronic Transactions Law

Federal Decree-Law No. 46 of 2021 concerning Electronic Transactions and Trust Services provides an important legal environment for electronic transactions.

However:

Electronic validity does not automatically mean substantive legal correctness.

An automated decision can be electronically authentic but legally defective.

D. Personal Data Protection Law

Federal Decree-Law No. 45 of 2021 on Personal Data Protection is relevant where algorithms process personal information.

An AI system may create liability risks involving:

  • inaccurate personal data;
  • excessive data collection;
  • inappropriate processing;
  • inadequate security;
  • unlawful disclosure;
  • improper profiling; and
  • defective automated processing.

4. Main Categories of Algorithmic Liability

4.1 Developer Liability

A developer may potentially be responsible where an AI system contains:

  • defective architecture;
  • inadequate testing;
  • foreseeable design problems;
  • unreliable models;
  • inadequate safeguards;
  • known bias;
  • security vulnerabilities; or
  • inadequate documentation.

The key question is whether the developer breached a legally relevant duty.

4.2 Vendor Liability

A vendor may incur contractual responsibility where the supplied system:

  • fails contractual specifications;
  • produces materially unreliable results;
  • lacks promised functionality;
  • violates contractual assurances; or
  • is supplied without required safeguards.

The contractual terms become particularly important.

4.3 Deployer Liability

A company or authority that deploys an AI system may have responsibility for determining whether the system is suitable for the particular purpose.

For example:

An AI system designed for ordinary customer-service classification should not automatically be used to determine a person's legal entitlement to compensation.

Improper deployment can therefore become an independent source of liability.

5. Operator Liability

The person operating an AI system may be responsible where the harm results from:

  • incorrect inputs;
  • ignoring warnings;
  • improper configuration;
  • failure to supervise;
  • misuse;
  • failure to update the system; or
  • reliance upon clearly unreliable output.

This is especially important where the operator has the ability to override the algorithm.

6. Employer Liability

Where an employee uses an algorithm in the course of employment, questions of employer responsibility may arise.

For example:

An employee uses an AI credit assessment tool, ignores an obvious system error, and causes an unlawful commercial decision.

The legal analysis may include:

  • the employee's conduct;
  • scope of employment;
  • employer supervision;
  • contractual duties;
  • foreseeability; and
  • causation.

7. Government and Administrative Decision-Making

Algorithmic decision-making creates special problems when used by government authorities.

A government authority may use algorithms for:

  • licensing;
  • benefits;
  • regulatory enforcement;
  • inspection;
  • fraud detection;
  • immigration-related administration;
  • public services; or
  • administrative risk assessment.

A person affected by an automated decision may potentially challenge:

  • legality;
  • jurisdiction;
  • procedural fairness;
  • factual foundation;
  • discriminatory effects;
  • improper delegation;
  • failure to consider relevant facts; or
  • unreasonable reliance on an automated recommendation.

The fact that a government agency used software does not eliminate the legal requirement for lawful administrative action.

8. Judicial AI and Algorithmic Liability

The issue becomes particularly sensitive when AI assists judicial processes.

AI could potentially assist with:

  • case classification;
  • document review;
  • legal research;
  • translation;
  • transcription;
  • scheduling;
  • identifying precedents;
  • summarisation; and
  • case-management functions.

However, the final legal determination should remain attributable to the legally authorised decision-maker.

A court should not effectively delegate its judicial responsibility to an opaque commercial algorithm.

9. Case Law

There is currently limited reported UAE case law directly concerning civil liability for AI algorithms. Therefore, the cases below are important analogical and foundational authorities dealing with the principles that would be relevant to algorithmic liability.

Case 1: Federal Supreme Court Appeal No. 538 of 2016 (Civil), 18 December 2017

This case concerned interconnected contractual obligations and the importance of good faith in contractual performance.

Relevance to algorithmic liability

AI systems are normally introduced through contractual relationships.

For example:

Government/Company → AI Vendor → Software → Automated Decision

If the vendor has contractual obligations concerning accuracy, security, maintenance, or functionality, those obligations may become relevant when the system causes harm.

The case therefore supports examining the entire contractual relationship, rather than treating the algorithm as an isolated object.

Principle

Contractual obligations must be understood in accordance with their legal and contractual context, including good-faith requirements.

10. Federal Supreme Court Appeal No. 941 of 2019 (Commercial), 24 March 2020

This case is relevant to the distinction between different forms of liability and the proper legal characterisation of a claim.

Application to AI

Algorithmic harm may simultaneously raise:

  • contractual liability;
  • tort/delict liability;
  • professional responsibility;
  • product-related responsibility; or
  • employment-related responsibility.

Correct legal classification is therefore essential.

For example, where an AI vendor supplies defective software under a commercial contract, the claimant may have contractual claims.

Where an independent third party suffers damage through negligent deployment, the analysis may be different.

Principle

The court must correctly characterise the legal relationship and the source of liability rather than relying merely on the technological form of the conduct.

11. Federal Supreme Court Appeal No. 826 of 2017 (Civil), 31 December 2018

This authority is particularly relevant because algorithmic disputes frequently require specialised technical evidence.

Application

A court may need experts to determine:

  • how an algorithm operated;
  • whether data were corrupted;
  • whether a model was properly configured;
  • whether the system malfunctioned;
  • whether a technical error occurred; and
  • whether the system output was consistent with the available data.

However, technical experts do not decide the ultimate legal question.

Principle

Expert: determines/explains technical matters.

Court: determines their legal consequences.

This distinction is crucial for AI liability litigation.

12. Federal Supreme Court Appeals Nos. 1012 and 1023 of 2022 (Commercial), 17 January 2023

These authorities reinforce the distinction between legal issues and technical matters requiring expert assessment.

Relevance to algorithmic decisions

Suppose an AI vendor argues:

“The model has a 99% accuracy rate.”

The court should not automatically treat that assertion as a legal conclusion.

Technical experts may be required to investigate:

  • the methodology;
  • sample size;
  • error rate;
  • testing conditions;
  • data quality;
  • false positives;
  • false negatives; and
  • actual system performance.

The court then determines whether the technical evidence establishes breach or causation.

13. Federal Supreme Court Appeal No. 872 of 2023 (Commercial), 1 November 2023

This case involved technical examination of electronic/audio material and is particularly useful for understanding the distinction between technical authenticity and legal significance.

Application to AI

An AI-generated result may be:

  • technically genuine;
  • correctly extracted from a database; and
  • accurately recorded.

But this does not necessarily prove the legal conclusion asserted by a party.

For example:

An AI system genuinely produces a “high-risk” classification.

That does not automatically establish:

“The person is legally liable.”

The legal conclusion requires independent legal reasoning.

Principle

Technical authenticity ≠ legal proof of the ultimate proposition.

14. Federal Supreme Court Appeal No. 79 of 2020 (Civil), 17 February 2020

This authority concerns admissions and their evidentiary significance.

Relevance

AI systems increasingly generate:

  • automated emails;
  • chatbot communications;
  • automated notices;
  • machine-generated reports; and
  • system acknowledgments.

A court must determine:

  • who authorised the system;
  • who controlled it;
  • whether the communication is attributable to the person;
  • whether it accurately represents the person's intention; and
  • whether it qualifies as an admission.

Therefore:

AI-generated communication should not automatically be treated as a human admission.

15. Federal Supreme Court Appeal No. 261 of 2000 (Civil), 17 September 2000

This case dealt with older electronic communication methods and questions of reliability and attribution.

Although it predates modern AI, its reasoning remains useful by analogy.

Application to algorithmic systems

The same basic legal questions arise today:

  • Is the electronic record genuine?
  • Can it be attributed to the relevant person?
  • Has it been altered?
  • Does it accurately represent the underlying transaction?
  • What evidentiary weight should it receive?

Technology has changed substantially, but the legal necessity of authentication and attribution remains.

16. Federal Supreme Court Cassation No. 880 of 2021 (Civil), 15 November 2021

This is an important authority on compensation.

The court recognised the possibility of compensation extending to future damage and loss of opportunity, where legally established.

Relevance to algorithmic liability

An erroneous algorithmic decision could potentially cause:

  • loss of business;
  • loss of a contractual opportunity;
  • financial loss;
  • reputational damage;
  • future economic loss; or
  • other legally recognised harm.

If the claimant can establish the necessary elements of liability and causation, compensation may become available.

This makes algorithmic errors more than merely technical defects.

17. Federal Supreme Court Appeal No. 950 of 2019 (Criminal), 4 February 2020

This case involved WhatsApp-related digital evidence.

Although criminal in nature, it provides useful guidance regarding the judicial evaluation of electronic evidence.

Relevance

Algorithmic liability disputes may similarly involve:

  • WhatsApp messages;
  • system logs;
  • AI-generated reports;
  • metadata;
  • electronic records;
  • screenshots; and
  • automated communications.

Digital origin does not make evidence automatically conclusive.

The court must evaluate its reliability and relevance.

18. Federal Supreme Court Appeal No. 1001 of 2022 (Criminal), 9 May 2023

This case involved digital communications and issues of attribution and factual evaluation.

Relevance

In algorithmic disputes, the court may need to determine:

Who supplied the data?

Who operated the system?

Who authorised the output?

Who relied on the recommendation?

Who made the final decision?

These questions determine the appropriate chain of legal responsibility.

19. Case-Law Summary

CaseMain principleAlgorithmic-liability relevance
538/2016 CivilGood faith and interconnected obligationsVendor/deployer contractual responsibility
941/2019 CommercialCorrect characterisation of liabilityContract/tort/professional liability
826/2017 CivilTechnical matters and expert evidenceAI technical investigation
1012 & 1023/2022 CommercialTechnical evidence vs legal questionsAlgorithmic performance evidence
872/2023 CommercialTechnical authenticity does not equal legal meaningAI output cannot automatically establish liability
79/2020 CivilAdmissions and evidentiary attributionAutomated communications
261/2000 CivilElectronic communication and attributionDigital-system evidence
880/2021 CivilFuture damage/loss of opportunityCompensation for AI-caused harm
950/2019 CriminalEvaluation of digital evidenceAI-generated records
1001/2022 CriminalAttribution of digital communicationsIdentification of responsible actor

20. The Causation Problem

One of the most difficult issues is causation.

Suppose:

Defective algorithm → incorrect recommendation → human decision → economic loss

Who caused the loss?

Possible defendants might argue:

  • the algorithm merely made a recommendation;
  • the human made the final decision;
  • the user supplied incorrect data;
  • the claimant failed to provide information;
  • another event caused the loss.

The court must therefore identify the legally relevant causal chain.

21. Human Intervention Does Not Automatically Break Causation

The existence of a human decision-maker does not necessarily eliminate algorithmic responsibility.

For example:

AI produces a demonstrably defective recommendation → employee mechanically accepts it → claimant suffers foreseeable damage.

The human intervention may not necessarily constitute an independent intervening cause.

The precise result depends on:

  • foreseeability;
  • the nature of the human intervention;
  • the degree of reliance;
  • warnings;
  • system design;
  • professional standards; and
  • the surrounding facts.

22. Conversely, AI Does Not Automatically Cause Every Harm

A claimant must still establish causation.

For example:

An AI system contains a minor statistical error, but the claimant's loss resulted from an entirely independent contractual breach.

The existence of algorithmic imperfection alone would not necessarily establish liability.

Therefore:

Algorithmic error ≠ automatic civil liability.

23. Standard of Care

The appropriate standard may depend upon:

  • the purpose of the AI system;
  • sensitivity of the decision;
  • foreseeable risks;
  • industry standards;
  • professional obligations;
  • contractual commitments;
  • available safeguards;
  • technical complexity; and
  • severity of potential harm.

A system used to recommend restaurant advertisements should not be subject to exactly the same risk analysis as one used to influence:

  • medical decisions;
  • financial decisions;
  • government benefits;
  • legal rights; or
  • judicial processes.

The greater the potential harm, the stronger the justification for safeguards and human oversight.

24. Algorithmic Transparency

Liability becomes difficult when the system is a “black box.”

A claimant may need information concerning:

  • input data;
  • model version;
  • decision variables;
  • system logs;
  • confidence scores;
  • human interventions;
  • training methodology;
  • error rates; and
  • output history.

Without appropriate access to evidence, proving causation and fault can become extremely difficult.

This is why auditability should be treated as an important part of responsible AI deployment.

25. AI Hallucinations and Liability

Generative AI creates an additional problem.

An AI system may generate:

  • nonexistent legal authorities;
  • incorrect factual information;
  • incorrect calculations;
  • fabricated documents;
  • false summaries; or
  • inaccurate legal analysis.

If a professional relies upon such information and causes foreseeable harm, the issue becomes one of human and institutional responsibility, not simply “AI error.”

The critical question becomes:

Was reliance upon the AI output reasonable in the circumstances?

For high-risk legal decisions, independent verification is particularly important.

26. Shared Liability

An algorithmic accident may involve several actors.

For example:

Developer

creates defective model

Vendor

supplies system

Authority/company

deploys system

Employee

relies on output

Claimant

suffers loss

The legal system may therefore have to determine whether responsibility lies with one actor or whether multiple legally relevant acts contributed to the harm.

27. Contractual Allocation of AI Risk

AI contracts should ideally address:

  • accuracy;
  • permitted uses;
  • prohibited uses;
  • data quality;
  • cybersecurity;
  • audit rights;
  • incident notification;
  • model changes;
  • human oversight;
  • indemnification;
  • insurance;
  • liability caps;
  • regulatory compliance; and
  • termination rights.

However, a contractual allocation of risk does not necessarily eliminate liability toward third parties or override mandatory legal rules.

28. Algorithmic Liability in Courts

For judicial AI, an appropriate model should be:

AI

Assists with:

  • search;
  • classification;
  • summarisation;
  • transcription;
  • translation;
  • document organisation.

Human judge/decision-maker

Determines:

  • facts;
  • law;
  • credibility;
  • evidence;
  • legal reasoning;
  • final judgment.

This separation protects judicial independence and procedural fairness.

29. Recommended UAE Algorithmic Liability Framework

A practical framework can be divided into six stages.

Stage 1 — Identification

Identify:

  • system;
  • developer;
  • vendor;
  • deployer;
  • operator;
  • decision-maker.

Stage 2 — Technical investigation

Examine:

  • data;
  • algorithm;
  • system logs;
  • model version;
  • error rate;
  • cybersecurity;
  • human intervention.

Stage 3 — Legal duty

Determine:

  • contractual duty;
  • statutory duty;
  • professional duty;
  • duty of care;
  • data-protection obligation.

Stage 4 — Causation

Establish:

system defect → decision → harm.

Stage 5 — Damage

Determine:

  • actual financial loss;
  • future loss;
  • loss of opportunity;
  • property damage;
  • other legally recognised damage.

Stage 6 — Remedy

Possible remedies include:

  • correction;
  • reconsideration;
  • injunction;
  • contractual relief;
  • compensation;
  • restoration of rights; or
  • other appropriate judicial relief.

30. Key Principles

The emerging UAE approach to algorithmic decision liability can be summarised as follows:

Principle 1

AI is generally a tool, not an independent legal person.

Principle 2

Responsibility must ultimately be attributed to a legally responsible person or entity.

Principle 3

Technical complexity does not eliminate civil liability.

Principle 4

Electronic evidence must be authenticated and evaluated.

Principle 5

Expert evidence may explain the algorithm, but the court decides the legal consequences.

Principle 6

Human oversight is especially important for high-impact decisions.

Principle 7

Algorithmic error alone does not establish liability; causation and legally recognised damage must be established.

Principle 8

A genuine electronic record does not automatically prove the legal conclusion drawn from it.

Principle 9

Contractual allocation of AI risks is important but does not necessarily eliminate statutory or third-party liability.

Principle 10

The greater the potential impact on legal rights, the stronger the need for transparency, auditability, and meaningful human review.

31. Conclusion

UAE algorithmic decision liability is fundamentally an extension of traditional civil-law principles into an automated environment.

The technology may be new, but the legal questions remain familiar:

Who owed the duty?
Was the duty breached?
Was the algorithm defective or improperly used?
Who controlled it?
Did the decision cause the harm?
Was the harm foreseeable?
What damage occurred?
What remedy is available?

The UAE's current civil-law framework, together with the Evidence Law, Electronic Transactions Law, and Personal Data Protection Law, provides the legal infrastructure for addressing these questions.

The cited UAE Supreme Court authorities concerning good faith, legal characterisation, expert evidence, technical evidence, electronic communications, attribution, causation, and compensation provide important foundations even though they were not themselves decided as modern AI-liability cases.

The most appropriate approach is therefore a human-attribution model: algorithms can assist or influence decisions, but legal responsibility remains with the persons and entities that design, supply, deploy, operate, supervise, or ultimately rely upon the system. This ensures that technological automation does not create a “liability gap” in UAE civil law.

LEAVE A COMMENT