Civil Law And Uae Machine Learning Bias Liability Attribution .

Civil Law and UAE: Machine Learning Bias Liability Attribution

1. Introduction

Machine-learning bias liability attribution concerns the legal question of who should bear civil responsibility when an AI or machine-learning system produces a discriminatory, unfair, inaccurate, or harmful outcome because of biased training data, model design, deployment choices, monitoring failures, or automated decision-making.

Examples include:

an AI recruitment system systematically rejecting applicants from a particular nationality or gender;

an automated credit-scoring system producing systematically adverse results for a particular group;

an insurance algorithm assigning discriminatory risk scores;

a facial-recognition system producing higher error rates for certain demographic groups;

an automated fraud-detection system disproportionately blocking particular customers;

an AI system used in employment, finance, insurance, healthcare, or public services producing an unlawful adverse decision.

The central legal problem is that the machine itself is normally not the legal person responsible for the damage. The law therefore has to attribute the consequences of the machine's operation to human or corporate actors such as:

the AI developer;

the data provider;

the model owner;

the deploying company;

the employer;

the operator;

the vendor;

the human decision-maker who relied on the algorithm; or

potentially several parties jointly.

UAE law does not currently create a general rule that an AI system is an independent legal person bearing civil liability merely because it made the decision. The practical approach is therefore to apply existing principles of fault, causation, damage, contractual liability, product/service responsibility, data protection, discrimination rules where applicable, and vicarious or agency liability.

The DIFC provides particularly useful guidance because its Data Protection Law expressly addresses automated decision-making and profiling, while the DIFC Courts have also issued specific guidance concerning AI-generated material and algorithmic bias.

2. Meaning of Machine-Learning Bias

Machine-learning bias occurs when the output of an algorithm systematically produces an unjustified disadvantage for particular persons or groups.

Bias can originate at different stages:

A. Data bias

The training data may contain historical discrimination or under-representation.

B. Label bias

The labels used to train the model may reflect human assumptions rather than objective reality.

C. Feature bias

Apparently neutral variables may operate as proxies for protected characteristics.

For example:

postcode may indirectly correlate with nationality or socioeconomic status;

employment history may reflect historical discrimination;

purchasing patterns may indirectly reveal sensitive characteristics.

D. Model bias

The mathematical model may systematically produce different error rates among groups.

E. Deployment bias

A technically acceptable model may become discriminatory when used in a different environment from the one for which it was designed.

F. Monitoring failure

An initially accurate system may become biased because of changing data or population behaviour.

Therefore, liability attribution should not automatically focus upon the programmer. The legally relevant question is:

Which actor had the relevant legal duty, control, knowledge, opportunity to prevent the harm, and causal connection to the discriminatory outcome?

3. UAE Civil-Law Framework

A. General civil liability

The UAE civil-law tradition generally distinguishes between:

contractual liability;

non-contractual/tort liability;

damage;

causation;

fault;

compensation; and

special statutory liability.

AI bias can potentially engage several of these simultaneously.

An injured claimant may argue that the responsible entity:

used defective data;

failed to test the algorithm;

failed to monitor discriminatory outcomes;

failed to warn users;

breached contractual obligations;

processed personal information unlawfully;

violated an applicable discrimination prohibition;

failed to exercise reasonable professional care; or

delegated an important decision to an inadequately controlled system.

The important point is that the existence of AI does not automatically eliminate ordinary civil-law principles.

4. The Attribution Problem

Machine learning creates a chain of actors:

Data provider → AI developer → model owner → vendor → deploying company → human operator → decision → affected person

A harmful outcome may therefore have multiple possible causes.

For example:

Company A purchases an AI recruitment system from Company B.
Company B trained the system using historical recruitment data supplied by Company C.
Company A deploys the system without testing its demographic error rates.
The system rejects a qualified applicant.
A human HR manager accepts the recommendation without review.

Who is liable?

Potentially:

B for defective development;

C for defective or unlawfully supplied data;

A for negligent deployment or failure to supervise;

the human decision-maker where personal fault is established; and

more than one actor where their conduct contributed to the same damage.

Thus, machine-learning bias is fundamentally an attribution problem rather than simply a technology problem.

5. Role of Human Agency

A machine-learning model normally does not have an independent legal personality.

Consequently, civil liability is ordinarily attributed through human or corporate legal persons.

This produces an important principle:

Autonomous technological operation does not necessarily mean autonomous legal responsibility.

The more important questions are:

Who designed the system?

Who selected the training data?

Who determined the objective?

Who selected the model?

Who deployed it?

Who had the ability to test it?

Who knew or ought to have known about discriminatory outcomes?

Who had contractual responsibility?

Who made the final decision?

Who could reasonably have prevented the harm?

6. Data Protection as a Route to Liability

Data protection law is particularly important because machine-learning systems frequently depend upon extensive personal data.

The DIFC Data Protection Law No. 5 of 2020 contains an especially important provision concerning automated individual decision-making, including profiling.

A data subject has a right to object to a decision based solely on automated processing, including profiling, where it produces legal or similarly serious consequences, and may require manual review, subject to specified exceptions.

This is highly relevant to algorithmic bias.

For example:

A financial institution's AI system automatically rejects an applicant's credit request.

If the decision is based exclusively on automated processing and falls within the statutory conditions, the affected person may have a right to seek human review.

Therefore, the legal issue is not limited to whether the algorithm was statistically biased. It can also concern whether the organization unlawfully allowed an automated process to determine an individual's legal or seriously significant position.

7. Case Law

Case 1 — Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse

[2018] DIFC CFI 051 and CFI 085

This is an important DIFC data-protection authority.

The dispute concerned a data subject's access rights and the obligations imposed upon a data controller under the DIFC Data Protection Law. The Court examined statutory rights concerning access to personal data and the operation of data-processing obligations.

Relevance to machine-learning bias

Machine-learning models frequently depend upon personal data.

Therefore, where an algorithm produces a harmful or discriminatory result, the claimant may need to establish:

what data was processed;

where the data originated;

how it was used;

what categories of information were involved;

whether the processing complied with applicable law; and

whether the affected individual possessed statutory rights concerning that processing.

Principle

Data-processing legality can become an important component of algorithmic-liability attribution.

The case does not itself concern machine-learning bias, but it provides a useful foundation for analysing the legal relationship between automated processing and data-subject rights.

8. Case 2 — Marwan Ahmad Lutfi v DIFC Authority

[2012] DIFC CFI 003

This case concerned alleged employment discrimination under the DIFC employment regime.

The Court considered the statutory concept of discrimination and the requirement that the treatment complained of be connected with a protected characteristic. The Court emphasized the evidentiary importance of determining what inference should properly be drawn from the primary facts.

Relevance to AI bias

Suppose an AI recruitment system rejects candidates disproportionately belonging to a particular protected group.

Statistical disparity alone may not necessarily establish every element of a discrimination claim. The claimant would need to connect:

algorithmic output → disadvantage → protected characteristic → legally relevant causal connection.

This makes evidence about:

training data;

model variables;

model outputs;

comparator groups;

error rates; and

human intervention

potentially important.

Principle

A discriminatory outcome must be legally connected to the protected characteristic or relevant statutory ground; technological complexity does not eliminate the requirement of causation.

9. Case 3 — Hana Al Herz v DIFC Authority

[2013] DIFC CA 004

The DIFC Court of Appeal considered allegations of employment discrimination.

The Court examined whether the termination was actually because of the protected characteristic or whether another explanation accounted for the employer's conduct. The Court ultimately concluded on the facts that the necessary discriminatory causal connection had not been established.

Relevance to machine learning

This authority demonstrates why causal attribution is critical.

Consider:

An AI system disproportionately rejects applicants from a particular nationality.

That fact does not automatically establish that nationality caused the rejection.

A claimant may need to investigate whether:

nationality was directly used;

nationality operated through a proxy;

historical data encoded discriminatory patterns;

another variable produced the result;

the model's error rate was responsible; or

the human decision-maker independently caused the adverse outcome.

Principle

An adverse result and a protected characteristic are not necessarily enough; the legally relevant causal relationship must be established.

10. Case 4 — Mr Shiraz Mahmood v Standard Chartered Bank DIFC

[2021] DIFC CFI 044

This case is particularly relevant to algorithmic discrimination because it discusses causation, comparators, evidential inference, employer responsibility, and vicarious liability.

The Court explained that discriminatory treatment must be connected with a prohibited ground and that merely showing detrimental treatment is insufficient. The judgment also considered the evidentiary difficulty of proving discrimination and the drawing of inferences from primary facts.

The Court further considered the employer's vicarious liability under Article 54 of the applicable DIFC Employment Law.

Application to machine learning

Imagine that:

an employer uses an AI hiring system that disproportionately rejects women.

There are several possible attribution questions:

Employer liability

The employer selected and deployed the system.

Vendor liability

The vendor developed the model.

Data liability

A third party supplied biased training data.

Human decision-maker liability

The HR manager knowingly relied on an obviously discriminatory recommendation.

The case's treatment of causation and evidentiary inference provides a useful framework for analysing these questions.

Principle

Algorithmic disparity must be connected to the legally relevant discriminatory ground, while evidence can be used to establish the causal relationship.

11. Case 5 — Marwan Lutfi v DIFC Authority

[2013] DIFC CA 003

The Court of Appeal considered whether an employment termination was discriminatory and emphasized the importance of identifying the actual reason for the employer's action.

The Court found that the claimant had not established that the termination occurred because of marital status.

AI significance

This authority helps distinguish:

automated correlation

from

legally relevant causation.

An algorithm may identify correlations that are statistically significant but legally irrelevant.

For example:

A model discovers that applicants from a particular area have historically lower retention rates.

The model may therefore disadvantage applicants from that area.

But the legal question remains:

Was the resulting disadvantage caused by a legally prohibited characteristic, an unlawful data-processing practice, negligent deployment, or some other legally actionable conduct?

Principle

Statistical correlation is not automatically equivalent to legal causation.

12. Case 6 — Haya Spa LLC v Harper Real Estate / Hasan Real Estate

[2016] DIFC SCT 150

The Court considered negligence and vicarious liability in relation to the conduct of an authorized employee/agent.

The Court proceeded on the basis that the relevant conduct of the authorized agent could give rise to vicarious liability and also considered negligence under the DIFC Law of Obligations.

Relevance to machine learning

This provides a useful analogy for AI systems.

Where a company uses an automated system as part of its business operations, the claimant may argue that the company cannot avoid responsibility merely because the immediate harmful action was generated by technology.

The stronger legal inquiry is:

Was the system being used in the company's business?

Who controlled the deployment?

Who selected the system?

Was there negligent supervision?

Was the company aware of risks?

Could the company have prevented the harm?

Principle

Delegating an operational function does not necessarily eliminate the principal's responsibility for legally attributable conduct.

However, this should not be overstated: an AI system is not literally an employee or legal agent merely because a company uses it.

13. Case 7 — Abraaj Investment Management Ltd v KPMG Lower Gulf Ltd

[2021] DIFC CFI 041

This case is particularly useful for the concept of attribution.

The Court considered arguments involving corporate conduct, employee and agent conduct, vicarious liability, and the rules governing attribution. The judgment discusses the distinction between wrongdoing attributable to a company itself and liability arising from the conduct of employees or agents.

AI relevance

AI systems introduce a similar attribution problem.

Suppose:

the developer created the model;

the customer configured it;

the employee activated it;

the algorithm produced the discriminatory result.

The law must determine which conduct legally belongs to which actor.

Principle

Attribution is an independent legal inquiry and cannot be resolved merely by identifying the immediate physical or technological cause of an event.

This is highly important for machine-learning liability.

14. Case 8 — The Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse

[2020] DIFC CFI 051/2018 and CFI 085/2018

The Court again addressed data-protection rights and the relationship between the regulator, data controller and data subject. The proceedings arose under the DIFC Data Protection Law and involved statutory rights relating to personal-data access.

AI significance

Machine-learning accountability often requires access to information.

Without sufficient information concerning:

the data used;

processing purposes;

categories of information;

model inputs;

relevant automated processing;

an affected person may face serious evidentiary difficulties.

Consequently, data-access and transparency rights can indirectly assist civil claims involving algorithmic discrimination.

Principle

Data transparency can be an essential evidentiary foundation for establishing algorithmic responsibility.

15. Case 9 — Mr Shiraz Mahmood and the Evidentiary Problem of AI Discrimination

The reasoning in Mahmood v Standard Chartered Bank DIFC is particularly useful because discrimination claims may rarely have direct evidence of discriminatory intention.

The Court recognized the importance of drawing proper inferences from primary facts while maintaining the statutory burden of proof.

This becomes even more important with machine learning.

A claimant may not know:

what features the model uses;

whether proxies exist;

how weights are assigned;

how training data was selected;

why a particular score was produced.

Therefore, algorithmic bias litigation can require technical evidence from:

data scientists;

software engineers;

forensic experts;

statisticians;

auditors;

cybersecurity experts; and

data-protection specialists.

16. DIFC Courts' AI Guidance

The DIFC Courts have gone further than merely applying conventional legal principles.

Their Practical Guidance Note No. 2 of 2023 addresses the use of large language models and generative AI in court proceedings.

The Guidance requires transparency concerning AI-generated material and specifically identifies potential limitations and biases associated with AI systems. It also instructs users to evaluate reliability by considering training data, algorithms and potential bias or inaccuracies.

The Guidance also emphasizes that AI should assist rather than replace the human decision-making required in legal proceedings.

This is significant for liability attribution because it demonstrates an institutional principle:

AI outputs should remain subject to human verification and responsibility.

17. 2026 DIFC AI Litigation — Alarabi Investments Ltd v Cron AI Ltd

A more recent development is:

Alarabi Investments Limited v Cron AI Ltd, CFI 030/2025 (DIFC CFI, 26 June 2026).

The dispute concerned procedural issues surrounding a default judgment and an application to set it aside. The Court dealt with the AI-related company under ordinary procedural rules.

The case is not a machine-learning bias decision.

Nevertheless, it illustrates an important institutional point:

An AI-related company remains subject to ordinary judicial procedure and does not obtain a separate legal status merely because its business concerns AI.

Accordingly, ordinary principles of jurisdiction, pleadings, evidence, liability and remedies remain relevant.

18. Who Can Be Liable for Machine-Learning Bias?

A. AI Developer

The developer may potentially be responsible where the harmful outcome results from:

defective architecture;

inadequate testing;

known discriminatory training data;

failure to correct known bias;

inadequate safeguards;

defective documentation.

The claimant would ordinarily still need to establish the applicable legal duty, breach, causation and damage.

B. Data Provider

Liability may arise where the supplied dataset was:

unlawfully obtained;

materially inaccurate;

misleading;

deliberately manipulated;

improperly labelled; or

known to contain serious discriminatory distortions.

C. Deploying Company

The deploying organization may be particularly important because it controls the real-world use of the system.

Potential failures include:

no bias testing;

inappropriate use case;

failure to monitor outcomes;

excessive reliance upon automated recommendations;

failure to provide human review;

ignoring known model limitations.

D. Employer

Where an AI system is used for:

recruitment;

promotion;

dismissal;

performance evaluation;

compensation;

the employer may remain legally responsible for its employment decisions.

The fact that an algorithm generated the recommendation does not automatically transfer responsibility to the software vendor.

E. Human Decision-Maker

A human decision-maker may potentially incur responsibility where the person:

knowingly relied upon discriminatory outputs;

ignored obvious warning signs;

manipulated the algorithm;

deliberately selected discriminatory parameters; or

failed to perform a legally required review.

19. Joint Liability and Multiple Causation

Machine-learning bias may involve multiple contributing causes.

Example:

Developer supplies a poorly tested model.
Employer deploys it without testing.
HR manager receives a warning that the model disadvantages women.
HR manager nevertheless follows the automated recommendation.

Here there may be three potentially relevant forms of conduct:

defective development;

negligent deployment; and

knowing human reliance.

The court would need to determine:

which conduct caused the damage;

whether each actor owed a relevant duty;

whether the harm was foreseeable;

whether liability is joint or several under the applicable law;

whether contribution can be sought between responsible parties.

20. Bias and Negligence

A useful negligence structure is:

Duty

Did the defendant owe a legally recognized duty to the claimant?

Breach

Did the defendant fail to exercise the legally required degree of care?

Causation

Did the failure cause the discriminatory or harmful outcome?

Damage

Did the claimant suffer legally compensable loss?

Remoteness

Was the resulting damage sufficiently connected with the wrongful conduct?

For AI systems, breach may potentially include:

failure to test;

failure to audit;

inadequate documentation;

failure to monitor;

failure to provide human review;

failure to correct known bias.

21. Contractual Attribution

AI bias may also constitute a contractual issue.

For example, an AI vendor may promise:

compliance with applicable law;

non-discriminatory operation;

specified accuracy levels;

auditability;

explainability;

data security;

regulatory compliance.

If those contractual promises are breached, the dispute may primarily become a contractual liability claim.

The contract may therefore become extremely important in determining:

allocation of responsibility;

indemnities;

warranties;

limitation clauses;

audit rights;

testing obligations;

termination rights;

insurance requirements.

22. Consumer Protection Dimension

Where an AI system is embedded in consumer-facing products or services, UAE consumer-protection legislation may become relevant.

For example:

automated pricing;

financial services;

insurance;

online marketplaces;

recommendation systems;

consumer credit;

automated customer profiling.

A company should not assume that the algorithm itself absorbs liability.

The relevant legal person remains the business providing the product or service.

23. Explainability and Attribution

Explainability is especially important in bias cases.

Suppose an applicant asks:

"Why was my application rejected?"

The company responds:

"The algorithm rejected you."

That answer does not necessarily resolve legal responsibility.

The important questions are:

What data did the algorithm consider?

What factors influenced the decision?

Were protected characteristics used?

Were proxy variables used?

Was the result statistically unusual?

Was there human review?

Was the model validated?

Was the model appropriate for the decision?

The DIFC Courts' AI guidance expressly emphasizes evaluating training data, algorithms and potential biases when assessing AI-generated material.

24. Burden of Proof

Machine-learning bias presents a significant evidentiary problem.

The affected individual normally does not possess:

source code;

training datasets;

model weights;

validation reports;

internal audit reports;

model cards;

deployment records.

The defendant may possess all of them.

Accordingly, litigation may involve:

disclosure;

expert evidence;

statistical evidence;

data-access rights;

audit records;

internal correspondence;

model documentation.

The reasoning in Mahmood v Standard Chartered Bank is useful because it demonstrates the importance of drawing legitimate inferences from primary facts in discrimination litigation while respecting the applicable burden of proof.

25. Statistical Evidence

Algorithmic discrimination may be demonstrated through statistical evidence.

For example:

GroupApplicationsRejections
Group A10,00030%
Group B10,00052%

The difference may justify investigation.

However:

statistical disparity ≠ automatic legal liability.

The court may still need to establish:

whether the disparity is statistically significant;

whether the relevant group difference is causally connected to a protected characteristic;

whether the model used a legitimate variable;

whether the disparity resulted from data quality;

whether another variable explains the result;

whether the applicable law prohibits the resulting treatment.

26. Proxy Discrimination

One of the most difficult AI issues is proxy discrimination.

The model may not explicitly use:

gender

but may use:

occupation;

purchasing behaviour;

geographical information;

employment history;

education;

language;

device information.

A proxy can nevertheless reproduce a protected characteristic's effect.

Therefore, simply saying:

"The algorithm never used gender"

may not completely resolve a bias claim.

The legal analysis should examine the actual operation and causal effect of the model.

27. Human-in-the-Loop Liability

Human review can significantly affect attribution.

There are three broad situations:

Situation 1 — Fully automated

AI makes the decision without meaningful human intervention.

Attribution may focus heavily on:

controller;

operator;

developer;

applicable automated-decision rules.

Situation 2 — AI recommendation + human review

The AI recommends an outcome and a human makes the final decision.

Liability may depend upon whether the human review was:

genuine;

informed;

independent; or

merely rubber-stamping.

Situation 3 — AI as analytical tool

The human decision-maker independently assesses the evidence.

In such a case, the algorithm may be only one evidentiary input.

This distinction can materially affect causation.

28. Vendor Contracts and Allocation of Risk

Businesses using machine-learning systems should consider contractual allocation of:

bias-testing obligations;

audit rights;

cybersecurity;

data quality;

regulatory compliance;

explainability;

human-review requirements;

incident reporting;

indemnification;

insurance;

limitation of liability.

However, contractual allocation between commercial parties does not necessarily eliminate liability owed to an injured third party where mandatory law applies.

29. Vicarious Liability and AI

Traditional vicarious liability normally assumes an employee or agent.

AI is different.

An algorithm is not automatically:

an employee;

an agent;

a legal representative;

a legal person.

Therefore, the safer legal approach is:

Attribute the relevant human or corporate conduct surrounding the AI rather than treating the AI itself as the legal defendant.

The reasoning concerning vicarious liability and attribution in Haya Spa and Abraaj provides useful analogies for this problem.

30. Product Liability Theory

A machine-learning system embedded into a physical product can create another possible route.

Examples:

autonomous vehicle;

medical device;

biometric device;

automated industrial machine.

The claimant may argue that the product or system was defective.

The legal analysis would then examine:

defect;

foreseeable use;

warnings;

safety;

causation;

damage.

The fact that the defect is software-based rather than mechanical does not necessarily prevent ordinary civil-law principles from becoming relevant.

31. AI Bias and Professional Negligence

Professional users of AI may have enhanced duties.

Examples:

banks;

insurers;

hospitals;

lawyers;

auditors;

financial institutions;

regulated entities.

A professional organization may be expected to understand the limitations of a system it deploys.

The DIFC Courts' AI guidance provides a useful illustration of this principle: practitioners are expected to verify AI-generated material and understand the limitations of training data, algorithms and possible bias.

32. AI Bias in Employment

Employment is one of the clearest areas of risk.

AI may be used for:

recruitment;

CV screening;

promotion;

performance scoring;

employee monitoring;

termination decisions.

The DIFC Employment Law jurisprudence demonstrates that discrimination depends upon the relevant protected characteristic and causation.

Mahmood v Standard Chartered Bank DIFC is particularly useful because it addresses causal connection, comparators, evidential inference and employer responsibility.

Therefore:

An employer cannot necessarily avoid employment-law responsibility merely by outsourcing the decision to an algorithm.

33. AI Bias in Financial Services

Financial institutions may employ machine learning for:

credit scoring;

anti-fraud systems;

AML monitoring;

customer-risk classification;

insurance underwriting.

Bias can result in:

account closures;

loan refusals;

enhanced scrutiny;

pricing differences;

transaction blocking.

The legal analysis may involve a combination of:

contract;

financial regulation;

data protection;

consumer law;

negligence;

discrimination law where applicable.

34. AI Bias and Damages

If liability is established, damages depend upon the applicable cause of action and proof of loss.

Potential consequences may include:

financial loss;

lost employment opportunity;

lost contractual opportunity;

additional costs;

reputational injury where legally compensable;

other legally recognized non-economic harm.

The claimant must nevertheless establish a legally compensable loss and causal connection.

A statistical bias finding alone does not automatically establish the amount of damages.

35. Defences

Potential defences may include:

A. No causal connection

The defendant may argue that the algorithm was not the actual cause of the decision.

B. Independent human decision

A human may have independently rejected the claimant.

C. Legitimate non-discriminatory factor

The defendant may establish that another legitimate factor caused the outcome.

D. Lack of damage

The claimant may fail to establish legally compensable loss.

E. Contractual limitation

A limitation clause may be relevant between contracting parties, subject to mandatory law.

F. Compliance with applicable law

The defendant may establish that the processing or automated decision was authorized under applicable legislation.

G. Third-party fault

The defendant may argue that defective data or software supplied by another party caused the harm.

36. Regulatory Compliance Is Not Always the End of the Analysis

An important distinction is:

Regulatory compliance

versus

civil liability.

A company may comply with one regulatory requirement while still facing a contractual or tort claim if another legal duty has been breached.

Similarly, the existence of a vendor's contractual warranty does not necessarily mean that the end user has no claim against the deploying organization.

37. Practical Attribution Matrix

ActorPossible source of responsibilityTypical question
DeveloperNegligence/contract/product responsibilityWas the model defectively designed?
Data providerData-related responsibilityWas the training data inaccurate or unlawfully supplied?
VendorContract/service liabilityDid the system meet contractual specifications?
Deploying companyNegligence/contract/regulationWas deployment reasonable and lawful?
EmployerEmployment law/civil liabilityDid AI produce discriminatory employment treatment?
Human decision-makerPersonal faultDid the person knowingly rely on a biased output?
ControllerData protectionWas automated processing lawful?
Multiple actorsJoint/concurrent responsibilityDid several failures combine to produce the damage?

38. Six Core Legal Tests for UAE AI-Bias Liability

A court considering a machine-learning bias dispute could conceptually examine:

Test 1 — Duty

Who owed the relevant legal duty?

Test 2 — Control

Who controlled the relevant AI system?

Test 3 — Knowledge

Who knew or should reasonably have known about the bias?

Test 4 — Causation

Did the bias materially contribute to the claimant's harm?

Test 5 — Preventability

Could the defendant reasonably have prevented or corrected the discriminatory outcome?

Test 6 — Damage

What legally compensable harm resulted?

These tests help prevent the simplistic conclusion that "the AI did it, therefore nobody is responsible."

39. Importance of Auditability

AI systems should ideally maintain:

version history;

training-data records;

testing records;

bias assessments;

model-performance statistics;

human-review records;

decision logs;

explanations of material model changes.

These records can become important evidence in litigation.

Without them, a defendant may face difficulty demonstrating how a decision was produced or whether reasonable safeguards existed.

40. Central Legal Principle

The emerging UAE position can be summarized as follows:

Machine-learning autonomy does not automatically create legal autonomy.

The machine may generate the immediate output, but civil liability generally requires identification of a legally responsible person or entity.

Thus:

AI output → human/corporate attribution → legal duty → breach/fault → causation → damage → remedy

rather than:

AI output → AI itself becomes liable.

41. Relationship Between AI Bias and Human Responsibility

The most significant legal question is therefore not:

"Was the machine biased?"

It is:

"Which legally responsible actor failed to prevent, detect, correct, or appropriately respond to the bias?"

That distinction is crucial.

A model can contain statistical bias without producing legally actionable damage.

Conversely, a company may potentially incur responsibility where:

the model's bias was foreseeable;

the company knew of the risk;

the company failed to test it;

the company failed to monitor it;

the company ignored warnings;

the model was used for an inappropriate purpose; or

the company relied blindly upon an automated recommendation.

42. Overall Legal Position in the UAE

As of 2026, UAE law does not appear to have developed a comprehensive, reported body of judicial precedent specifically establishing a standalone tort of "machine-learning bias."

The legal framework is therefore assembled from existing doctrines.

The most relevant areas are:

civil liability;

contractual liability;

negligence;

causation;

discrimination law where applicable;

data protection;

automated decision-making;

consumer protection;

professional duties;

agency and vicarious liability;

product/service responsibility; and

evidentiary principles.

The DIFC is especially significant because its Data Protection Law expressly addresses automated decision-making and profiling, and the DIFC Courts have issued guidance expressly requiring attention to AI limitations and potential bias.

43. Case-Law Revision List

For examination or quick revision, remember these authorities:

Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse [2018] DIFC CFI 051/085
— data protection, access rights and automated data processing.

Marwan Ahmad Lutfi v DIFC Authority [2012] DIFC CFI 003
— discrimination, protected characteristics and causal inference.

Hana Al Herz v DIFC Authority [2013] DIFC CA 004
— discriminatory causation and determining the real reason for adverse treatment.

Marwan Lutfi v DIFC Authority [2013] DIFC CA 003
— causation and discrimination under DIFC employment law.

Shiraz Mahmood v Standard Chartered Bank DIFC [2021] DIFC CFI 044
— discrimination, causation, evidence and employer/vicarious liability.

Haya Spa LLC v Harper Real Estate / Hasan Real Estate [2016] DIFC SCT 150
— negligence, agency and vicarious liability.

Abraaj Investment Management Ltd v KPMG Lower Gulf Ltd [2021] DIFC CFI 041
— corporate attribution, employee/agent conduct and responsibility.

Alarabi Investments Ltd v Cron AI Ltd [2026] DIFC CFI 030/2025
— AI-related company remaining subject to ordinary judicial procedure.

These cases should be described as analogical authorities, not as decisions that have already established a general UAE doctrine of machine-learning bias liability.

44. Conclusion

Machine-learning bias liability attribution in UAE civil law is primarily an exercise in applying established legal principles to new technology.

The AI system itself ordinarily does not become the legal bearer of civil responsibility merely because it generated an autonomous output.

The court is more likely to investigate:

who designed the system;

who supplied the data;

who controlled deployment;

who owed the relevant legal duty;

whether the system was appropriately tested;

whether bias was foreseeable;

whether the organization knew or should have known about it;

whether meaningful human review existed;

whether the biased output caused legally recognizable harm; and

which actor should legally bear the resulting loss.

The DIFC framework is particularly significant because it combines data-protection rights concerning automated decisions with judicial guidance emphasizing transparency, verification, human judgment and awareness of algorithmic bias.

Accordingly, the emerging principle can be expressed as:

Machine-learning systems may generate decisions autonomously, but legal responsibility remains capable of being attributed to the human or corporate actors who design, supply, control, deploy, supervise, or knowingly rely upon those systems.

Quick Exam Points

AI is generally not treated as an independent civil-law person merely because it makes autonomous decisions.

Bias can originate in data, labels, features, model architecture or deployment.

Liability requires a legally relevant duty and causal connection.

Statistical disparity does not automatically equal legal discrimination.

Human review can materially affect attribution.

Data-protection law is particularly important for automated profiling.

DIFC Data Protection Law recognizes rights concerning certain solely automated decisions.

The DIFC Courts' AI guidance emphasizes transparency and consideration of AI limitations and bias.

Developer, vendor and deploying organization may have different legal responsibilities.

Several actors may potentially contribute to the same damage.

Mahmood v Standard Chartered Bank DIFC is particularly useful for discrimination, causation and evidentiary inference.

Abraaj v KPMG is useful for attribution analysis.

Haya Spa is useful for negligence and vicarious liability.

There is currently no comprehensive reported UAE case law establishing a standalone doctrine specifically called "machine-learning bias liability."

Existing civil, contractual, employment and data-protection doctrines therefore remain central.

LEAVE A COMMENT