Civil Law And Uae Machine-Learning Bias And Legal Responsibility

Civil Law and UAE: Machine-Learning Bias and Legal Responsibility

1. Introduction

Machine-learning bias arises when an AI or machine-learning system produces systematically distorted, unfair, inaccurate, or unequal outcomes because of problems in its:

  • training data;
  • data selection;
  • model design;
  • variables or proxies;
  • algorithmic optimisation;
  • deployment environment; or
  • human supervision.

In UAE civil law, the central legal question is not simply whether an algorithm is “biased.” The more important question is:

Who is legally responsible when a biased machine-learning system causes legally recognisable harm?

This creates an attribution problem because the machine itself is generally not treated as an independent civil person. Responsibility may instead have to be connected to the developer, provider, owner, controller, operator, employer, user, or other legally responsible person/entity, depending on the facts, applicable legislation, contract, and causation.

The issue is especially important after the new Federal Decree-Law No. 25 of 2025 promulgating the Civil Transactions Law, which entered into force on 1 June 2026 and repealed the 1985 Civil Transactions Law.

2. Meaning of Machine-Learning Bias

Machine-learning bias occurs when the operation of a model systematically produces results that are inaccurate or disadvantageous for particular persons or groups.

Simple example

A company uses an AI recruitment system.

Historical hiring data shows that applicants with certain characteristics were more frequently selected.

The model learns those historical patterns.

It subsequently gives lower scores to otherwise qualified applicants because it has learned correlations from the historical data.

The legal problem may arise at several levels:

biased data → biased model → biased prediction → human reliance → adverse decision → damage

The fact that the final decision was made by a human does not necessarily eliminate questions concerning the design or deployment of the system.

3. UAE Legal Framework

There is currently no single comprehensive UAE federal civil-liability statute specifically titled “AI Bias Liability.”

Instead, responsibility can arise through several legal frameworks.

Main sources include:

  1. Federal Decree-Law No. 25 of 2025 — Civil Transactions Law
  2. Federal Decree-Law No. 45 of 2021 — Personal Data Protection Law
  3. contractual obligations;
  4. sector-specific regulation;
  5. consumer-protection rules;
  6. employment legislation;
  7. evidence and procedural law;
  8. DIFC/ADGM legislation where applicable.

The UAE Personal Data Protection Law is particularly important because it expressly regulates automated processing and profiling.

4. Personal Data Protection Law and Algorithmic Bias

Federal Decree-Law No. 45 of 2021 contains unusually relevant provisions.

Article 13

A data subject has a right to receive information including decisions made based on automated processing, including profiling.

Article 18

The data subject has a right to object to decisions resulting from automated processing, including profiling, particularly where the decision has legal impact or adversely affects the person.

The law also provides exceptions and requires human involvement in reviewing automated-processing decisions upon the data subject's request in the circumstances specified by the provision.

This is highly relevant to machine-learning bias.

For example:

AI credit scoring

→ automated profiling

→ low credit score

→ loan refused

→ financial consequence

The legal analysis cannot stop at:

“The computer gave the applicant a low score.”

The relevant questions include:

  • What personal data was used?
  • Was the data accurate?
  • Was profiling involved?
  • Was the decision automated?
  • Did it have legal or serious adverse consequences?
  • Was there a valid legal basis?
  • Was human review available where required?
  • Did the organisation take appropriate safeguards?

5. Civil Liability Under the New UAE Civil Transactions Law

The new Civil Transactions Law is now the principal federal civil-law framework.

Federal Decree-Law No. 25 of 2025 entered into force on 1 June 2026.

The new law retains the basic civil-liability architecture based around:

harmful conduct → damage → causation → compensation

Article 271 is particularly interesting for AI-related physical or mechanical systems. It provides liability for a person controlling things requiring special care to prevent harm or mechanical machinery, subject to the statutory exception for harm that could not be prevented and other special provisions.

This could become relevant to:

  • autonomous vehicles;
  • industrial robots;
  • AI-controlled machinery;
  • automated security systems;
  • AI-enabled medical devices;
  • intelligent building systems.

However, an important qualification is necessary:

It should not automatically be assumed that every software-only AI system falls within Article 271.

The classification of the particular technology and the applicable special legislation would matter.

6. Attribution: The Central Problem

Machine-learning systems create a chain of actors.

Example

A bank purchases an AI credit-scoring system.

The system was:

  • designed by Company A;
  • trained using data supplied by Company B;
  • hosted by Company C;
  • configured by the bank;
  • operated by employees;
  • used to make credit decisions.

The customer suffers loss.

Who is responsible?

Potentially relevant actors include:

ActorPossible responsibility
AI developerDesign/model defect
Data providerInaccurate or unlawfully obtained data
AI vendorContractual/service obligations
Deploying companyNegligent implementation
OperatorImproper use
EmployerEmployee conduct
Data controllerData-protection obligations
Human decision-makerFailure to review or correct obvious error
AI system itselfGenerally not treated as an independent civil person

The court would need to identify the legally relevant duty and connect the breach to the damage.

7. Types of Machine-Learning Bias

A. Data bias

Training data is incomplete or historically distorted.

Example

A fraud-detection system is trained primarily on one type of customer profile.

It performs poorly on another population.

B. Selection bias

The data used to train the model is not representative of the population on which the system is deployed.

C. Measurement bias

The system uses an inaccurate proxy for the characteristic it intends to measure.

D. Historical bias

The model reproduces patterns that existed historically but should not be treated as legally or socially appropriate today.

E. Proxy discrimination

The model does not directly use a sensitive characteristic but uses another variable strongly correlated with it.

F. Feedback-loop bias

The model's earlier decisions create new data that reinforces the same pattern.

Example:

AI identifies certain transactions as “high risk.”

More transactions involving those customers are investigated.

The resulting investigation data is fed back into the model.

The model becomes even more likely to classify those customers as high risk.

8. Case Law: Important Qualification

There is not yet a mature body of UAE reported case law specifically deciding civil liability for machine-learning bias.

Therefore, it would be misleading to present ordinary UAE/DIFC cases as though courts had already established a comprehensive AI-bias doctrine.

The following cases are useful because they establish principles concerning:

  • AI-generated material;
  • data protection;
  • fairness;
  • bias;
  • human review;
  • causation;
  • legal responsibility; and
  • procedural safeguards.

9. Case 1 — Klesta Eshja & Hair Creators Salon LLC v Salah Masri & Others, CFI 066/2024

This is one of the most directly relevant recent UAE judicial decisions concerning AI-generated legal material.

In March 2026, the DIFC Court recorded that certain amended defences had been prepared substantially with AI assistance and contained false references and misleading material. The Court had ordered the defences struck out and subsequently awarded costs connected with the resulting applications.

Importance

The case demonstrates an important principle:

The use of AI does not transfer legal responsibility from the human party to the machine.

The litigants remained responsible for material placed before the Court.

Relevance to machine-learning bias

If a company uses an AI system to make a commercial or legal decision, it cannot necessarily argue:

“The algorithm made the decision, therefore nobody is responsible.”

Human and corporate accountability remains relevant.

10. Case 2 — Stelian Gheorghe v BSA Ahmad Bin Hezeem & Associates LLP & Jimmy Haoula, CFI 045/2025

In this 2025 DIFC proceeding, the Court noted allegations that portions of the claim form and evidence may have been AI-generated and contained errors. The Court observed that errors of law have no place in witness evidence filed by lawyers.

The case ultimately concerned an arbitration clause and the Court stayed proceedings in favour of arbitration.

Relevance

The case demonstrates that:

AI assistance → does not eliminate professional/legal responsibility.

For machine-learning systems, this supports the principle that organisations deploying technology must consider:

  • verification;
  • supervision;
  • professional standards;
  • contractual obligations; and
  • consequences of relying upon erroneous output.

11. Case 3 — Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse, CFI 051/2018 & CFI 085/2018

This DIFC case involved access to personal data and the interaction between regulatory investigations and data-protection rights.

The Court considered the statutory framework governing data access and the circumstances in which disclosure could be restricted.

Relevance to machine-learning bias

Machine-learning models frequently depend on enormous quantities of personal information.

Therefore, a bias claim may involve two distinct legal questions:

  1. Was the resulting decision discriminatory or inaccurate?
  2. Was the underlying personal data lawfully processed and adequately protected?

A claimant may therefore need to analyse both substantive harm and data governance.

12. Case 4 — Asif Hakim Adil v Frontline Development Partners Ltd, CFI 015/2014

The DIFC Court considered the principle of apparent judicial or tribunal bias and referred to the familiar test concerning whether a fair-minded and informed observer would conclude that there was a real possibility of bias.

Relevance

Although this was not an AI case, the conceptual importance is substantial.

Machine-learning systems can exhibit systematic bias without any conscious intention.

Thus, an AI-bias analysis should distinguish:

Intentional bias

A person deliberately programs discriminatory treatment.

Statistical/model bias

The system produces systematically unequal results because of data or model structure.

Human automation bias

A human decision-maker blindly accepts the machine's output.

Civil responsibility does not necessarily require proof that the algorithm “intended” to discriminate.

The legal question may instead concern duty, breach, harm and causation.

13. Case 5 — KPMG LLP v Dubai Financial Services Authority, CFI 008/2022

The DIFC Court considered judicial review issues concerning regulatory decision-making and examined principles including legality, rationality and procedural fairness.

Relevance

Suppose an AI system is used by a regulated organisation to determine:

  • risk;
  • compliance;
  • fraud;
  • customer classification.

The fact that an algorithm produced the classification does not eliminate the need for the institution to comply with applicable legal requirements.

The principle can be expressed as:

Automated reasoning does not create immunity from regulatory or legal duties.

14. Case 6 — Ledger v Leeor, CA 013/2022

The DIFC Court of Appeal considered an urgent ex parte application and the procedural requirements surrounding interim relief. The appeal was dismissed.

Relevance

The case is useful for the broader principle that courts retain control over the legal process even where urgent technological or commercial circumstances exist.

In AI disputes, procedural safeguards remain important.

An algorithm should not be treated as possessing independent procedural authority simply because it can produce a rapid recommendation.

15. Case 7 — Oheo Bank v Parker, CA 006/2025

This 2026 DIFC Court of Appeal decision is particularly important for the relationship between automated decision-making and procedural fairness.

The Court stated that the relevant inquiry includes whether there was “real unfairness or real practical injustice” and held that a party had been deprived of a reasonable opportunity to address a claim that emerged during the arbitration. The Court also emphasised that adequate reasons are a function of due process.

Relevance to machine-learning bias

Imagine that an algorithm identifies a person as:

“High fraud risk.”

The affected person must potentially be able to challenge:

  • the underlying data;
  • the classification;
  • the assumptions;
  • the relevant evidence;
  • the methodology.

An opaque model that prevents meaningful challenge creates a serious fairness issue.

16. Case 8 — IDBI Bank Ltd v Amira C Foods International DMCC, CA 014/2019

The DIFC Court of Appeal considered a substantial damages dispute involving contractual breach and the assessment of losses.

Relevance

Machine-learning bias claims ultimately require more than proof that an algorithm behaved unfairly.

The claimant normally needs to establish the legally relevant:

harm + causation + loss

For example:

AI credit model

incorrect classification

loan refusal

business opportunity lost

financial damage

The claimant still needs to establish the causal connection between the wrongful conduct and the recoverable loss.

17. DIFC AI Guidance and Bias

The DIFC Courts' Practical Guidance Note No. 2 of 2023 is particularly important.

It expressly identifies:

  • misleading or incorrect AI-generated information;
  • data-protection risks;
  • transparency;
  • accuracy;
  • reliability;
  • potential biases;
  • limitations of training data;
  • algorithmic limitations; and
  • over-reliance on AI.

It also states that AI should assist rather than replace integral human decision-making.

This is not a general federal AI-liability statute, but it provides a useful judicial framework for understanding the UAE approach to responsible AI use in litigation.

18. The DIFC Digital Economy Court

The DIFC framework goes further than merely recognising AI as a litigation tool.

Part 58 expressly identifies claims involving:

  • artificial intelligence;
  • AI-controlled devices;
  • complex databases;
  • blockchain;
  • digital assets;
  • fintech; and
  • other digital-economy technologies.

It also permits AI-driven or decision-tree smart forms for certain digital-economy claims.

This is important because it demonstrates that the UAE judicial environment is moving toward institutionalised digital dispute resolution, while maintaining court supervision.

19. Who Can Be Legally Responsible for Machine-Learning Bias?

A. Developer

Potential responsibility may arise if the developer:

  • knowingly creates a defective model;
  • fails to correct a known defect;
  • uses defective training data;
  • violates contractual specifications;
  • breaches an applicable duty.

B. AI Vendor

A vendor may face contractual responsibility if the product does not satisfy contractual representations or agreed specifications.

C. Data Provider

Responsibility may arise where inaccurate or unlawfully processed data is supplied and that data materially contributes to the harm.

D. Deploying Company

This is often the most important practical actor.

The company decides:

  • whether to purchase the system;
  • how to configure it;
  • what data to feed into it;
  • whether to test it;
  • whether to monitor it;
  • whether humans review outputs.

E. Human Decision-Maker

A human may potentially be responsible where the person:

  • ignores obvious errors;
  • fails to investigate suspicious results;
  • blindly relies on the system;
  • fails to perform required review.

20. The Causation Problem

Causation is often the hardest issue.

Consider:

Developer error

biased model

company uses model

employee relies on output

customer denied financing

business suffers loss.

Which event legally caused the damage?

There may be multiple contributing causes.

The court may need to examine:

  • model defect;
  • data defect;
  • deployment;
  • human conduct;
  • customer's own conduct;
  • intervening events.

The new Civil Transactions Law links compensation to legally recognised damage and lost profit where the loss is a natural consequence of the harmful act.

21. Multiple Responsible Parties

AI systems make multi-party responsibility particularly important.

Suppose:

  • Data Provider = 20% contribution
  • Model Developer = 30%
  • Deploying Bank = 40%
  • Human Operator = 10%

The court would need to determine responsibility according to the applicable civil-liability rules and facts.

This is different from traditional negligence where identifying one physical actor may be relatively straightforward.

AI creates a distributed causation chain.

22. Contractual Liability

Many AI relationships are contractual.

Example:

Company A purchases an AI recruitment system from Company B.

The contract promises:

  • accuracy;
  • regulatory compliance;
  • testing;
  • explainability;
  • security.

The system systematically rejects qualified candidates because of a model defect.

The claimant may potentially pursue contractual remedies depending upon:

  • contractual warranties;
  • service levels;
  • limitation clauses;
  • indemnities;
  • representations;
  • applicable law;
  • causation;
  • proof of loss.

Therefore, AI bias can produce contractual liability even where tort liability is difficult to establish.

23. Data Protection Liability

Machine-learning bias often begins with personal data.

The UAE PDPL imposes obligations concerning personal-data processing and security.

Article 18 specifically addresses automated processing and profiling.

Article 20 also addresses appropriate technical and organisational measures and impact-assessment requirements for certain high-risk processing involving automated assessment/profiling.

Therefore:

AI governance = model governance + data governance

24. Algorithmic Bias and Privacy

Bias and privacy can overlap.

For example, an AI system may infer:

  • financial status;
  • behaviour;
  • reliability;
  • preferences;
  • risk;
  • location;
  • other personal characteristics.

Even if the system does not directly use a sensitive variable, it may infer a characteristic from other information.

This makes data minimisation, accuracy and appropriate processing safeguards important.

25. Bias in Different UAE Sectors

Banking

AI credit scoring may produce:

  • loan denial;
  • higher interest;
  • reduced credit limits.

Potential issues:

  • inaccurate data;
  • profiling;
  • contractual obligations;
  • regulatory duties;
  • causation.

Insurance

Machine learning may determine:

  • premium;
  • risk category;
  • claim suspicion.

Potential issue:

Does the model rely on unreliable proxies?

Employment

AI recruitment may:

  • rank candidates;
  • reject applications;
  • recommend promotions.

Potential issues include:

  • inaccurate data;
  • discriminatory outcomes;
  • employment-law requirements;
  • privacy;
  • contractual duties.

Healthcare

AI may:

  • diagnose;
  • prioritise patients;
  • recommend treatment.

Bias could create serious physical damage.

The legal consequences may involve:

  • professional negligence;
  • medical regulation;
  • product/service liability;
  • civil compensation.

Autonomous vehicles

Bias may affect:

  • pedestrian detection;
  • object classification;
  • route selection.

Here Article 271's provisions concerning controlled things and mechanical machinery could potentially become relevant depending upon the facts and classification of the system.

26. Machine Bias vs Human Bias

An important legal distinction is:

Human bias

A person intentionally or negligently makes a biased decision.

Machine bias

The system produces a biased result because of its data or architecture.

Human-machine bias

The human relies excessively on a biased algorithm.

The third category may be especially important.

A company may argue:

“We did not discriminate; our algorithm did.”

But legal responsibility may focus on who deployed, controlled and relied upon the system, rather than whether the computer possessed discriminatory intent.

27. The Automation-Bias Problem

Human decision-makers can become psychologically dependent on algorithmic recommendations.

Example:

AI says:

“Fraud probability: 96%.”

The employee accepts the recommendation without checking the underlying evidence.

Later, the classification is proven wrong.

The legal issue is not simply:

“Was the AI wrong?”

It becomes:

“Was it reasonable and legally compliant for the human decision-maker to rely on the AI output without meaningful verification?”

This is a much stronger civil-liability question.

28. Explainability as a Liability Issue

Explainability is important because it affects proof.

Suppose:

AI rejects applicant.

The company cannot explain:

  • what variables mattered;
  • which data was used;
  • how the score was calculated;
  • why comparable applicants received different outcomes.

This can make it difficult for the affected person to establish:

  • error;
  • bias;
  • causation;
  • breach.

Accordingly, AI governance should preserve audit trails and decision logs.

29. Evidence and Burden of Proof

An AI-bias dispute may require:

  • training-data records;
  • model documentation;
  • validation reports;
  • model-version history;
  • audit logs;
  • performance statistics;
  • error rates;
  • human-review records;
  • vendor contracts;
  • system specifications;
  • impact assessments.

The DIFC AI guidance expressly emphasises verification of AI-generated material and understanding limitations in training data, algorithms and potential bias.

30. A Practical Responsibility Matrix

ProblemPotential responsible party
Defective training dataData provider / controller
Defective algorithmDeveloper / vendor
Poor configurationDeploying organisation
Failure to testDeploying organisation
Failure to monitorDeploying organisation
Failure to reviewHuman decision-maker / organisation
Unlawful personal-data processingController / processor as applicable
False AI-generated court materialParty/legal practitioner responsible for filing
Physical harm from AI machineryController/operator and other legally responsible actors
Contractual AI failureContracting party/vendor depending on breach

This is not automatic liability. Each category requires analysis of the applicable law, duty, facts and causal connection.

31. Defences and Limiting Factors

A defendant may argue:

1. No duty

There was no applicable legal or contractual duty.

2. No breach

The system complied with the agreed specifications and applicable requirements.

3. No causation

The alleged bias did not cause the claimant's loss.

4. Intervening cause

Another event caused the damage.

5. Inaccurate claimant data

The decision was based on information supplied by the claimant.

6. Contractual allocation of risk

The parties allocated particular AI risks contractually, subject to mandatory law.

7. Statutory exception

A data-protection exception or other applicable statutory provision may apply.

32. The “Black Box” Problem

The most difficult cases may involve a model that even its developer cannot fully explain.

Suppose:

Input → Neural network → Output

but the internal reasoning is difficult to reconstruct.

The legal problem becomes:

How can a claimant prove negligence or causation without understanding the system?

This creates pressure for:

  • explainability;
  • auditability;
  • disclosure;
  • expert evidence;
  • model documentation;
  • independent testing.

33. Recommended UAE AI Liability Framework

A responsible organisation should maintain:

Before deployment

  • data-quality assessment;
  • bias testing;
  • legal compliance assessment;
  • privacy impact assessment;
  • model validation;
  • contractual allocation of responsibility.

During deployment

  • human oversight;
  • monitoring;
  • error detection;
  • audit logs;
  • incident management.

After an adverse decision

  • explain the relevant process;
  • permit legally required review;
  • investigate complaints;
  • correct inaccurate data;
  • preserve evidence.

34. Six Core Legal Questions for a UAE Court

When faced with an alleged machine-learning bias claim, the court could conceptually ask:

Question 1

Was there a legally protected or recognised interest?

Question 2

Was there a legal or contractual duty?

Question 3

Was the AI system defective, improperly used, or unlawfully operated?

Question 4

Who controlled or was responsible for the relevant system?

Question 5

Did the system's operation cause the claimant's legally recognised damage?

Question 6

What compensation or other remedy is legally available?

35. Important Distinction: Bias Does Not Automatically Equal Liability

This is crucial for an examination answer.

Bias ≠ automatic civil liability.

A claimant generally needs to establish the elements required by the applicable legal route.

For example:

A model produces statistically unequal outcomes.

That alone does not necessarily prove:

  • unlawful conduct;
  • breach of duty;
  • legally compensable damage;
  • causation.

The court must examine the specific legal framework.

36. Case-Law Summary

CaseRelevance
Klesta Eshja & Hair Creators Salon LLC v Salah Masri & Others, CFI 066/2024AI-generated material containing false references; human parties remained responsible; pleadings struck out
Stelian Gheorghe v BSA Ahmad Bin Hezeem & Associates LLP, CFI 045/2025Court considered alleged AI-generated errors and maintained professional/legal responsibility
DFSA v Commissioner of Data Protection & Anna Waterhouse, CFI 051/2018 & CFI 085/2018Data access, privacy and regulatory decision-making
Asif Hakim Adil v Frontline Development Partners Ltd, CFI 015/2014Legal concept of apparent bias
KPMG LLP v DFSA, CFI 008/2022Legality, rationality and fairness in regulated decision-making
Ledger v Leeor, CA 013/2022Procedural control and fairness in urgent adjudication
Oheo Bank v Parker, CA 006/2025Real unfairness, practical injustice, opportunity to present case and adequate reasons
IDBI Bank v Amira C Foods, CA 014/2019Damages, causation and assessment of loss

Important: These cases should not be cited as though they establish a specific UAE doctrine of “machine-learning bias liability.” The direct AI cases are still limited. They provide analogical principles concerning data protection, bias, procedural fairness, AI-generated material, professional responsibility and damages.

37. Exam-Oriented Revision Points

Machine-learning bias in UAE civil law

  1. AI is generally a tool, not an independent civil person.
  2. Liability must therefore normally be attributed to a legally responsible human or legal entity.
  3. The new Civil Transactions Law applies from 1 June 2026
  4. Article 271 may be relevant to AI-controlled mechanical machinery depending on the facts. 
  5. The PDPL regulates automated processing and profiling.
  6. Article 18 provides an objection right concerning certain automated decisions and provides for human review upon request in specified circumstances. 
  7. Bias can originate from data, model design, deployment or human reliance.
  8. Causation is critical.
  9. Contractual liability may coexist with tort/data-protection liability.
  10. AI does not eliminate human or corporate accountability.
  11. DIFC Courts expressly recognise AI-related disputes within the Digital Economy Court framework. 
  12. DIFC judicial guidance stresses transparency, verification, bias awareness and avoidance of excessive AI reliance. 

38. Conclusion

Machine-learning bias and legal responsibility in UAE civil law represent an emerging area rather than a fully developed independent doctrine.

The central legal problem is attribution.

An AI system may generate the biased output, but the legal system must determine:

Who designed it? Who supplied the data? Who controlled it? Who deployed it? Who relied upon it? What duty existed? What harm occurred? And did the system's operation legally cause that harm?

The UAE's current framework provides several important building blocks:

Civil Transactions Law → harm, responsibility, causation and compensation.

Personal Data Protection Law → automated processing, profiling, information rights and human review safeguards.

DIFC jurisprudence → procedural fairness, bias principles, accountability, adequate reasons and consequences of unreliable AI-generated material.

DIFC Digital Economy Court → institutional recognition of AI-related disputes.

The emerging principle can therefore be summarised as:

Machine-learning bias does not transfer legal responsibility to the machine. The law must trace the technology back through data, design, control, deployment and human decision-making to identify the legally responsible person or entity and establish duty, breach, causation and damage.

That makes algorithmic accountability a developing component of UAE civil-law responsibility, particularly where AI decisions affect financial, contractual, employment, consumer, privacy or property interests.

LEAVE A COMMENT