Civil Law And Uae Platform Responsibility For Algorithmic Harm .
Civil Law and UAE: Platform Responsibility for Algorithmic Harm
1. Introduction
Platform responsibility for algorithmic harm concerns the civil liability of a digital platform when an algorithm used by that platform causes legally recognised harm.
Examples include:
- an algorithm wrongly suspending a seller;
- discriminatory ranking or recommendation;
- automated rejection of a financial application;
- incorrect fraud detection;
- wrongful account termination;
- algorithmic price or market manipulation;
- inaccurate automated profiling;
- disclosure or misuse of personal data;
- an AI system producing harmful or misleading information;
- an automated platform decision causing financial or reputational loss.
The central legal question is:
When an algorithm causes harm, can the platform be legally responsible even though no human employee directly made the harmful decision?
Under UAE civil-law principles, the answer may be yes, depending on the source of the duty, the platform's conduct or omission, the damage, causation, contractual relationship and applicable statutory rules.
There is presently no single UAE federal statute creating a comprehensive, standalone civil-liability regime for “algorithmic harm.” The issue is instead addressed through the interaction of civil liability, contract law, data protection, consumer protection, electronic transactions and technology-specific regulation.
The current UAE framework is particularly significant because the new Civil Transactions Law applies from 1 June 2026 and contains general rules on harmful acts, causation, multiple wrongdoers and compensation.
2. Meaning of Algorithmic Harm
An algorithm is a set of computational instructions used to process information and produce an output.
A platform may use algorithms for:
- ranking;
- recommendation;
- advertising;
- credit assessment;
- fraud detection;
- identity verification;
- content moderation;
- seller evaluation;
- pricing;
- risk scoring;
- account suspension;
- search results.
Algorithmic harm occurs when the operation, design, training, deployment, supervision or output of such a system causes legally compensable loss or infringement.
A simple model is:
Platform → Algorithm → Decision → Harm → Causation → Potential Liability
3. Important UAE Legal Principle
The most important point is that the algorithm is generally a technological instrument, not an independent legal person.
Therefore, the legal investigation normally moves toward:
- the platform operator;
- software developer;
- data controller;
- service provider;
- employer;
- contractor;
- supplier;
- human decision-maker; or
- another legally responsible person.
The fact that a decision was automated does not automatically eliminate the legal responsibility of the person or entity controlling the system.
4. Current Civil Transactions Law
The current UAE Civil Transactions Law contains the general civil-liability framework applicable to harmful conduct.
The law recognises liability where harm is caused and provides rules dealing with causation, external causes, multiple responsible persons and compensation.
Article 249 — External Cause
A person may escape compensation where they establish that the harm resulted from an external cause beyond their control, including:
- force majeure;
- sudden accident;
- act of a third party; or
- act of the injured person,
unless the law or agreement provides otherwise.
This provision creates an important issue for algorithmic disputes:
Can a platform genuinely demonstrate that an algorithmic error was an external event beyond its control?
That will depend upon the facts.
5. Multiple Persons Responsible for Algorithmic Harm
Article 253 of the current Civil Transactions Law provides that where multiple persons are responsible for harm, liability may be allocated according to their respective contribution, while the court may also determine equal or joint-and-several liability. It also permits reduction where the injured party contributed to or aggravated the harm.
This is particularly useful for complex AI systems.
For example:
Data provider + software developer + platform operator + human reviewer
may all have different roles.
The court may therefore need to determine:
- who supplied the defective data;
- who designed the model;
- who deployed it;
- who failed to supervise it;
- who made the final decision; and
- whose conduct caused the damage.
6. Compensation for Algorithmic Harm
Article 255 provides that compensation is assessed according to the loss suffered and lost profit where such loss is the natural consequence of the harmful act.
Article 254 also recognises moral harm, including infringement affecting reputation, honour, social standing or financial status.
Therefore, algorithmic harm can potentially involve:
Economic loss
- lost income;
- lost business;
- transaction losses;
- additional expenses;
- lost customers.
Moral/reputational loss
- wrongful fraud classification;
- reputational damage;
- unlawful disclosure;
- harmful automated profiling.
7. Data Protection and Automated Decision-Making
The UAE Personal Data Protection Law is especially important.
Federal Decree-Law No. 45 of 2021 expressly addresses automated processing and profiling.
Article 18 gives the data subject the right to object to decisions resulting from automated processing, including profiling, particularly where such decisions have legal consequences or adversely affect the individual.
This is one of the most important statutory protections concerning algorithmic decision-making in the UAE.
Thus:
Automated processing
→ adverse decision
→ data-subject rights
→ potential legal dispute
The platform's responsibility may therefore arise not only under general civil liability but also under data-protection obligations.
8. Consumer Protection
Federal Law No. 15 of 2020 on Consumer Protection applies to consumer relationships and contains specific provisions concerning e-commerce.
Article 25 requires e-commerce providers registered in the UAE to provide consumers and competent authorities with information concerning matters including:
- identity and legal status;
- address;
- licensing authority;
- commodity/service information;
- contracting terms;
- payment;
- warranty.
This can become relevant where an algorithm materially affects:
- product recommendations;
- pricing;
- transaction processing;
- consumer access;
- payment;
- product information.
The platform's technological architecture does not eliminate consumer-law obligations.
9. Digital Economy Court
The UAE's DIFC Courts have created a specialist Digital Economy Court.
Its jurisdictional framework expressly includes claims involving:
- artificial intelligence;
- digital assets;
- substantial databases;
- cloud data;
- e-commerce;
- online intermediaries;
- digital payment platforms;
- marketplaces;
- automatic dispute-resolution systems;
- blockchain;
- cyber-physical systems; and
- connected technology.
This is significant because it demonstrates that UAE-based judicial institutions expressly anticipate litigation concerning AI and complex digital systems.
The DIFC Courts also have a Technology and Construction Division dealing with technologically complex disputes, including disputes involving artificial intelligence and connected cars.
10. Elements of Platform Liability for Algorithmic Harm
A useful legal framework consists of six questions.
10.1 Was there a legal duty?
The duty might arise from:
- contract;
- tort/civil liability;
- data-protection legislation;
- consumer legislation;
- professional obligations;
- regulatory requirements.
10.2 What did the platform do or fail to do?
Possible conduct includes:
- deploying defective software;
- using inaccurate data;
- failing to test an algorithm;
- failing to monitor bias;
- failing to update the system;
- failing to provide human review;
- failing to correct known errors;
- relying blindly on automated outputs.
10.3 Was there actual damage?
The claimant must establish legally relevant harm.
Examples:
AED 100,000 lost revenue
or
loss of business opportunity
or
reputational injury
or
unlawful interference with personal data.
10.4 Did the algorithm cause the damage?
Causation is critical.
It is not enough to say:
“The algorithm was involved.”
The claimant generally needs to establish a sufficiently direct causal connection between the relevant conduct and the harm.
10.5 Was the harm foreseeable or legally attributable?
The court may consider:
- system design;
- known risks;
- warnings;
- testing;
- human supervision;
- industry standards;
- contractual obligations;
- statutory requirements.
10.6 Is there a defence?
Potential arguments may include:
- external cause;
- force majeure;
- third-party interference;
- claimant's own conduct;
- contractual allocation of risk;
- absence of causation;
- absence of damage.
Article 249 specifically recognises certain external causes.
11. Case Law
Case 1: Larmag Holding B.V. v First Abu Dhabi Bank PJSC & Others [2019] DIFC CFI 054
This case is important for understanding the UAE civil-law concept of harm.
The DIFC Court discussed the UAE Civil Code framework, including the principle historically contained in Article 282 that a person causing harm may be liable even where the actor is not a person of discretion.
The judgment explained the basic structure of UAE civil liability as involving:
harmful conduct → damage → causal relationship.
Relevance to algorithms
The algorithm itself should not be treated as a mysterious intervening event.
The court can examine:
- the platform's conduct;
- the system's operation;
- the resulting damage; and
- causation.
The case therefore provides an important conceptual bridge between traditional UAE civil liability and algorithmic harm.
Case 2: Graciela Limited v Giacobbe [2014] DIFC CFI 027
This case concerned deliberate interference with the proper functioning of an IT system.
The claimant alleged wrongful interference with its IT system under DIFC law. The case demonstrates that interference with digital systems can generate legally actionable disputes rather than being treated merely as a technical problem.
Relevance to algorithmic responsibility
The case supports the proposition that courts can analyse technological conduct using established legal concepts.
For example:
technical interference → legal wrong → damage → remedy.
The same approach can be adapted to an algorithm that causes unlawful interference or damage.
Case 3: Linux v Lizeth [2022] DIFC SCT 237
The dispute concerned a software-development agreement for an e-commerce and restaurant-management platform.
The claimant alleged that the defendant supplied a copied third-party platform instead of developing the promised original platform and claimed losses involving vendors, partnerships and income. It also alleged copyright and data-security consequences.
Principle
Technology-related contractual obligations can be treated as ordinary legally enforceable obligations.
Relevance
This is important because platform responsibility may arise through contractual breach, independently of tort.
If a platform operator promises:
- particular functionality;
- security;
- data protection;
- accuracy; or
- system performance,
failure of the system may create contractual consequences depending on the agreement.
Case 4: DIFC Investments Ltd v Dubai Islamic Bank [2022] DIFC CFI 024
The case involved complex commercial obligations and the court's determination of liability arising from the relevant contractual structure.
Although it was not an AI-liability case, it demonstrates an important principle for technology disputes:
Courts analyse the actual legal relationship and contractual obligations rather than simply the technological environment surrounding the dispute.
Relevance
A platform defendant therefore cannot necessarily rely upon the complexity of its algorithm to avoid contractual responsibility.
The court can ask:
- What did the platform promise?
- What did the contract require?
- What actually happened?
- What loss followed?
Case 5: Stelian Gheorghe v BSA Ahmad Bin Hezeem & Associates LLP & Jimmy Haoula [2025] DIFC CFI 045
This case concerned allegations that pleadings and evidence had been partly generated using AI.
The DIFC Court considered the alleged AI-generated errors in the procedural context and ultimately stayed the proceedings in favour of arbitration pursuant to the parties' arbitration agreement.
Principle
The use of AI does not itself determine the underlying legal consequences.
The court continues to examine:
- legal obligations;
- procedural rules;
- evidence;
- contractual arrangements; and
- jurisdiction/arbitration.
Relevance
This supports a central proposition for algorithmic-harm cases:
AI involvement does not replace ordinary legal responsibility analysis.
Case 6: Klesta Eshja & Hair Creators Salon LLC v Salah Masri & Others [2025] DIFC CFI 066/2024
This is a particularly useful recent UAE digital-law authority.
The defendants' amended defences had been prepared substantially with AI assistance and contained false references and misleading material. The court struck out the amended defences and subsequently dealt with the resulting costs consequences.
Principle
The court does not treat AI-generated output as inherently reliable.
Human parties remain responsible for material submitted to the court.
Relevance to platform liability
The analogy is important:
AI output → human/platform reliance → harmful consequence
The existence of an automated system does not necessarily transfer responsibility away from the human or legal entity controlling its use.
Case 7: Mintil v Mester [2023] DIFC SCT 029
This case involved employment-related issues, including data-protection questions concerning an employee card.
The court considered the employer's reliance on data-protection provisions and examined whether the employer had properly explained its position to the employee.
Relevance
The case illustrates an important broader principle:
Technological or data-related powers must still operate within legally recognisable obligations and procedures.
For platforms, this is particularly relevant where automated systems make decisions affecting users.
12. Important Qualification About the Case Law
There is currently a significant distinction between algorithmic-liability theory and reported UAE judicial decisions directly imposing damages on a platform because an algorithm itself caused harm.
The cases above should therefore not be described as six UAE judgments that have already established a general “algorithmic harm” doctrine.
Instead:
- Larmag provides the general UAE civil-liability foundation;
- Graciela demonstrates judicial treatment of technological interference;
- Linux demonstrates technology-related contractual responsibility;
- DIFC Investments illustrates analysis of underlying contractual liability;
- Stelian Gheorghe demonstrates judicial treatment of AI-generated material;
- Klesta Eshja demonstrates consequences of unreliable AI-generated material;
- Mintil provides a related data-protection/technology context.
This distinction is important for accurate legal research.
13. Platform Liability for Algorithmic Bias
Suppose a marketplace algorithm systematically ranks one category of sellers lower because its training data contains historical distortions.
Potential issues include:
1. Data problem
Was the underlying data inaccurate or improperly processed?
2. Design problem
Was the algorithm designed in a reasonably appropriate manner?
3. Monitoring problem
Did the platform know, or should it have detected, the harmful pattern?
4. Governance problem
Was there a human review mechanism?
5. Causation problem
Did the algorithm actually cause the seller's financial loss?
6. Damage problem
Can the claimant establish actual loss?
The case would therefore require more than simply proving that an algorithm was biased.
14. Algorithmic Fraud Detection
Consider a banking or payment platform.
The system automatically classifies a customer as “high risk.”
The account is frozen.
The customer loses AED 500,000 in business transactions.
Possible legal questions include:
- Was the account restriction contractually authorised?
- Was the customer's data lawfully processed?
- Was automated profiling involved?
- Did the customer have a right to object?
- Was the decision inaccurate?
- Was there human review?
- Was there a contractual or statutory duty to investigate?
- Was the loss caused by the platform?
- Did the customer contribute to the loss?
- Was the restriction justified by law or regulation?
The Personal Data Protection Law's provisions concerning objections to automated processing can become particularly relevant.
15. Algorithmic Account Suspension
A platform may automatically suspend a merchant because its system identifies “fraud.”
The merchant then loses access to customers.
The platform may argue:
“The algorithm made the decision.”
That statement does not necessarily resolve the civil-liability question.
The court could instead investigate:
Platform design
↓
Training/data quality
↓
Risk threshold
↓
Human supervision
↓
Decision
↓
Notice/appeal
↓
Economic loss
↓
Causation
This is the appropriate legal chain.
16. Duty to Monitor Algorithms
A particularly important emerging issue is whether platforms have a continuing duty to monitor their algorithms.
A strong factual case for responsibility may arise where:
- the platform knew of repeated errors;
- complaints were received;
- the problem was technically identifiable;
- the platform failed to investigate;
- the algorithm continued operating;
- foreseeable harm followed.
This can transform the issue from:
“The algorithm made a mistake”
into:
“The platform failed to exercise appropriate control over a system it deployed and operated.”
That distinction is highly significant.
17. Human Oversight
Human oversight becomes especially important where algorithmic decisions have serious consequences.
Examples include:
- account termination;
- financial exclusion;
- employment decisions;
- insurance decisions;
- healthcare decisions;
- reputational classifications.
A platform that retains meaningful human review may be able to identify and correct errors before substantial harm occurs.
The absence of any meaningful review may become relevant to the assessment of responsibility, depending upon the applicable duty.
18. Explainability and Evidence
A claimant may face a difficult problem:
“The platform says the algorithm caused the decision, but I do not know how the algorithm reached it.”
This creates an evidentiary challenge.
Useful evidence may include:
- model documentation;
- system logs;
- input data;
- output data;
- audit trails;
- decision timestamps;
- version history;
- human-review records;
- error reports;
- complaints;
- testing records;
- risk assessments.
The DIFC Digital Economy Court framework specifically contemplates production and presentation of digital data, models and other digital information in technology disputes.
19. Algorithmic Harm and Causation
Causation can be the most difficult element.
Suppose:
Algorithmic decision → account suspension → business loss
The platform may argue:
“The claimant would have lost the business anyway.”
The claimant therefore needs to establish the causal connection between the algorithmic decision and the loss.
Article 255's focus on loss and lost profit as a natural consequence of the harmful act is relevant to this analysis.
20. Multiple Actors
Modern AI platforms may involve:
Data provider
↓
Model developer
↓
Cloud provider
↓
Platform operator
↓
Business customer
↓
End user
An algorithmic injury may therefore involve several potential actors.
Article 253's rules concerning multiple responsible persons are particularly useful because the court can examine each actor's contribution to the harm.
21. Contractual Limitation of Liability
Platforms frequently include provisions such as:
- limitation of liability;
- exclusion of indirect loss;
- disclaimers;
- “as available” clauses;
- automated-decision disclaimers.
Their effectiveness must be assessed under the applicable law.
A platform cannot assume that a contractual disclaimer automatically eliminates every statutory or civil-law obligation.
The current Civil Transactions Law's rules concerning adhesion contracts and unfair conditions are especially important in standard-form platform agreements.
22. Algorithmic Harm and Consumer Platforms
Consider an e-commerce platform.
The recommendation algorithm repeatedly promotes a defective product because it maximises sales.
Thousands of consumers purchase it.
The resulting questions could involve:
- product liability;
- consumer protection;
- platform obligations;
- misleading information;
- contractual obligations;
- causation.
The Consumer Protection Law specifically regulates e-commerce providers and requires information concerning goods/services and contractual arrangements.
23. Data Harm and Algorithmic Harm
These two concepts frequently overlap.
Algorithmic harm
The algorithm produces an unfair or incorrect result.
Data harm
Personal data is:
- improperly processed;
- disclosed;
- misused;
- inaccurately profiled;
- retained or transferred contrary to applicable requirements.
A single incident may involve both.
For example:
Incorrect personal data → algorithmic risk score → account closure → financial loss.
The claimant may therefore have both:
- data-protection issues; and
- civil-compensation issues.
24. Defences Available to Platforms
A platform may potentially rely upon:
A. External cause
The harm resulted from an external event beyond the platform's control. Article 249 is relevant.
B. Third-party conduct
A third party manipulated the algorithm or supplied malicious data.
C. User contribution
The user's conduct contributed to the loss.
D. Lack of causation
The platform may establish that its algorithm did not actually cause the claimed damage.
E. Lack of legally recognised damage
A claimant may have difficulty proving compensable loss.
F. Contractual allocation
The parties may have allocated certain risks contractually, subject to mandatory law and applicable restrictions.
25. Platform Responsibility Model
A useful model for UAE civil-law analysis is:
Level 1 — Design
Was the algorithm appropriately designed?
Level 2 — Data
Was accurate and lawfully processed data used?
Level 3 — Deployment
Was the algorithm deployed for an appropriate purpose?
Level 4 — Monitoring
Was its performance monitored?
Level 5 — Intervention
Was human intervention available when necessary?
Level 6 — Harm
Did the system produce legally recognised damage?
Level 7 — Causation
Did the platform's system cause that damage?
Level 8 — Remedy
What compensation or corrective measure is appropriate?
26. Role of the DIFC Digital Economy Court
The development of the DIFC Digital Economy Court is particularly important for future algorithmic-liability disputes.
Its rules expressly identify:
- AI;
- databases;
- digital platforms;
- e-commerce;
- online intermediaries;
- digital payments;
- automated dispute resolution;
- blockchain; and
- other digital technologies
as matters capable of falling within the Digital Economy Court framework.
This indicates that UAE judicial infrastructure is adapting to disputes where the technology itself becomes central to the legal controversy.
27. Practical Example
Facts
A UAE delivery platform uses AI to allocate delivery jobs.
The algorithm consistently assigns fewer high-value deliveries to one group of drivers because of an error in historical training data.
A driver loses AED 80,000 in expected earnings.
Legal analysis
1. Platform relationship:
Was the driver contractually connected to the platform?
2. Algorithm:
What algorithm made the allocation?
3. Data:
What data trained the system?
4. Error:
Was the output inaccurate or discriminatory?
5. Notice:
Did the platform know about the problem?
6. Monitoring:
Was the system audited?
7. Causation:
Did the algorithm cause the driver's loss?
8. Damage:
Can AED 80,000 be established as legally recoverable loss?
9. Defences:
Was the error caused by a third party or external event?
10. Remedy:
Could compensation or another corrective remedy be appropriate?
This demonstrates why algorithmic liability is not simply a question of whether “AI was wrong.”
28. Key Difference: Algorithmic Error vs Algorithmic Negligence
This distinction is useful in examinations.
Algorithmic error
The system produces an incorrect result.
Example:
A fraud algorithm incorrectly flags a legitimate transaction.
Algorithmic negligence/responsibility
The platform may have failed to:
- test;
- supervise;
- update;
- audit;
- correct;
- monitor; or
- appropriately deploy
the system.
Thus:
An algorithmic mistake does not automatically establish platform liability; the legal analysis must establish the relevant duty, damage and causation.
29. Case-Law Revision Table
| Case | Relevance to algorithmic harm |
|---|---|
| Larmag Holding B.V. v First Abu Dhabi Bank [2019] DIFC CFI 054 | UAE civil-law harm requires analysis of harmful conduct, damage and causation. |
| Graciela Ltd v Giacobbe [2014] DIFC CFI 027 | Technological interference can give rise to legally actionable disputes. |
| Linux v Lizeth [2022] DIFC SCT 237 | Technology/platform development obligations can create contractual liability. |
| DIFC Investments Ltd v Dubai Islamic Bank [2022] DIFC CFI 024 | Courts examine underlying contractual obligations rather than treating technology as an independent legal actor. |
| Stelian Gheorghe v BSA Ahmad Bin Hezeem [2025] DIFC CFI 045 | AI-generated material does not displace ordinary legal and procedural responsibility. |
| Klesta Eshja v Salah Masri [2025] DIFC CFI 066/2024 | Courts can impose procedural consequences where AI-generated material is unreliable or misleading. |
| Mintil v Mester [2023] DIFC SCT 029 | Data-protection and technology-related obligations remain subject to legal scrutiny. |
Important: these cases are not all direct “algorithmic harm” decisions. They are UAE/DIFC authorities illustrating the legal principles most relevant to future platform-algorithm liability.
30. Exam-Ready Framework
For an exam answer, use:
Algorithmic Harm
→ Identify platform
→ Identify algorithm
→ Identify duty
→ Identify conduct/omission
→ Establish damage
→ Establish causation
→ Consider data-protection obligations
→ Consider consumer protection
→ Consider contractual terms
→ Consider multiple responsible actors
→ Consider defences
→ Determine compensation/remedy.
31. Conclusion
Platform responsibility for algorithmic harm is an emerging area of UAE civil law rather than a completely separate established branch of liability.
The current legal framework allows the problem to be analysed through existing principles:
- harmful acts;
- causation;
- damage;
- multiple wrongdoers;
- contractual obligations;
- good faith;
- data-protection rights;
- consumer protection;
- electronic transactions; and
- judicial remedies.
The UAE Personal Data Protection Law is particularly significant because it expressly gives individuals rights concerning adverse decisions resulting from automated processing and profiling.
At the judicial level, the DIFC's Digital Economy Court expressly accommodates disputes involving AI, digital platforms, databases, e-commerce, automated dispute resolution and related technologies, demonstrating institutional recognition of the emerging category of digital disputes.
Final formula
Algorithm + Platform Control + Legal Duty + Harm + Causation = Potential Platform Responsibility
The decisive issue is therefore not simply “Did the algorithm make the mistake?” but:
“Who legally controlled, deployed, supervised or benefited from the system, what duty applied, what harm occurred, and is there a legally sufficient causal connection between the platform's conduct and that harm?

comments