Civil Law And Uae Predictive Classification Of Legal Risk Individuals .
Civil Law and UAE: Predictive Classification of Legal Risk Individuals
1. Introduction
Predictive classification of legal risk individuals means using data, statistical models, artificial intelligence, machine learning, behavioural information, financial records, litigation history, digital activity, or other indicators to classify an individual according to an estimated level of legal, regulatory, contractual, financial, fraud, or compliance risk.
Examples include:
- assigning a person a “high-risk” fraud score;
- predicting whether an individual is likely to breach a contract;
- automated credit-risk classification;
- identifying persons considered likely to engage in fraudulent conduct;
- predicting litigation or enforcement risk;
- employee or applicant risk scoring;
- AML/KYC risk profiling;
- insurance or financial-risk profiling;
- algorithmic classification based on online behaviour.
In UAE law, this subject is particularly important because predictive classification can involve personal-data processing, profiling, automated decision-making, privacy, discrimination, civil liability, confidentiality and evidentiary issues.
A crucial distinction is:
Predicting risk is not the same as legally establishing wrongdoing.
An algorithmic classification such as “high legal risk” is a prediction or assessment. It should not automatically be treated as proof that the individual has committed an unlawful act.
2. Current UAE Legal Framework
The principal framework is the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).
The PDPL specifically addresses processing involving:
- systematic and comprehensive assessment of personal aspects;
- automated processing;
- profiling;
- legal consequences;
- serious impacts on individuals.
Where processing involves a systematic and comprehensive assessment using automated processing, including profiling, that produces legal consequences or serious impacts, the law requires a Data Protection Impact Assessment (DPIA).
This is highly relevant to predictive legal-risk classification.
Basic legal structure
| Activity | Potential legal issue |
|---|---|
| Collecting personal information | Lawful processing |
| Combining different datasets | Purpose limitation and proportionality |
| Creating a risk profile | Profiling |
| Predicting future behaviour | Accuracy and fairness |
| Assigning a risk score | Automated classification |
| Using the score to deny services | Legal/serious effect |
| Sharing the score with third parties | Disclosure and confidentiality |
| Incorrect classification | Rectification and potential liability |
| Solely automated decision | Automated decision-making safeguards |
| Processing sensitive information | Higher privacy risk |
3. Meaning of Predictive Legal-Risk Classification
The process can generally be represented as:
Personal Data → Data Analysis → Risk Model → Classification → Decision/Action
For example:
An institution collects an individual's financial behaviour, transaction history, previous disputes and other legally permissible information. An AI system assigns the individual a “high-risk” classification. The institution then imposes additional verification requirements.
The legal question is not merely whether the algorithm is technically accurate.
The court or regulator may need to examine:
- Was the data lawfully collected?
- Was the processing lawful?
- Was the purpose legitimate?
- Was profiling necessary and proportionate?
- Was the data accurate?
- Was sensitive data involved?
- Was the individual informed?
- Was the decision entirely automated?
- Was there meaningful human review?
- Did the classification produce legal or similarly serious consequences?
- Did the individual suffer damage?
- Can the controller demonstrate compliance?
4. Profiling and Predictive Classification
Profiling is particularly important because predictive systems frequently create a digital representation of an individual.
For example:
“Individual X = high probability of fraud.”
That classification may not be directly stated in the individual's original data. Instead, it is an inference generated from data.
This creates an important civil-law problem:
Raw data
“Individual made 15 transactions.”
Algorithmic inference
“Individual presents elevated fraud risk.”
Legal consequence
“Individual's account is restricted.”
The third stage is potentially much more significant legally than the first.
5. Predictive Classification Does Not Establish Liability
A fundamental civil-law principle is that liability generally requires legally relevant facts, not merely predictions.
Therefore:
Risk score ≠ proof of wrongdoing.
For example, if an AI system gives an individual a 90% “litigation risk” score, that does not establish that the person:
- committed fraud;
- breached a contract;
- acted negligently;
- owes compensation;
- is criminally responsible.
The classification may be evidence requiring evaluation, but it should not automatically substitute for legal proof.
6. Accuracy of Predictive Classification
Accuracy becomes particularly important because predictive systems can reproduce errors from their training data.
Suppose an algorithm uses:
- previous claims;
- payment delays;
- location;
- employment information;
- online behaviour.
It may classify a person as high-risk because of correlations that do not actually demonstrate unlawful conduct.
Possible errors include:
A. False positive
A low-risk person is classified as high-risk.
B. False negative
A genuinely high-risk situation is classified as low-risk.
C. Historical bias
The model learns problematic patterns from historical data.
D. Proxy discrimination
The system does not directly use a protected characteristic but uses another variable that functions as a proxy.
E. Data-quality error
Incorrect or outdated information produces an incorrect classification.
These issues can create civil and data-protection consequences.
7. Data Protection Impact Assessment
The UAE PDPL expressly identifies automated profiling that can produce legal consequences or serious impacts as a circumstance requiring a privacy-impact assessment.
The assessment should address matters including:
- the proposed processing;
- its purpose;
- necessity;
- suitability;
- privacy risks;
- confidentiality risks;
- measures designed to reduce those risks.
Therefore, before implementing a system that automatically classifies individuals as “high legal risk,” an organisation should undertake a structured assessment.
Practical DPIA questions
- What data is being used?
- Why is it needed?
- Is every data field necessary?
- What prediction is being made?
- How reliable is the model?
- What consequences follow from the classification?
- Can the individual challenge the result?
- Is human review available?
- How is sensitive data protected?
- How long is the profile retained?
8. Automated Decision-Making
Predictive classification becomes legally more sensitive where the classification itself automatically determines an individual's treatment.
For example:
Algorithm → High Risk → Automatic rejection
is materially different from:
Algorithm → High Risk → Human review → Final decision
The second structure provides greater opportunity for:
- correction;
- explanation;
- contextual evaluation;
- human judgment;
- identification of algorithmic error.
The ADGM framework expressly recognises rights concerning decisions based solely on automated processing, including profiling, where the decision produces legal effects or similarly significant effects.
Similarly, DIFC Data Protection Law Article 38 gives a data subject the right to object to decisions based solely on automated processing, including profiling, where they produce legal or seriously impactful consequences, subject to specified exceptions and safeguards.
9. Human Review
Human review should be meaningful, not merely formal.
For example, it is weak protection if:
AI says “high risk” → employee automatically clicks “approve rejection.”
A stronger system would involve:
AI classification → explanation of relevant factors → human examination → opportunity for correction → independent decision.
The DIFC framework specifically recognises manual review in its automated decision-making safeguards.
10. Legal Risk Classification and Discrimination
Predictive classification may also create indirect discrimination.
For example, a model could use apparently neutral variables such as:
- neighbourhood;
- purchasing patterns;
- employment history;
- device information;
- communication behaviour.
These variables might nevertheless produce systematically different outcomes for particular groups.
Therefore, an organisation should distinguish:
legitimate risk differentiation
from
unlawful or unjustified discriminatory treatment.
The DIFC regime expressly includes a non-discrimination protection where data subjects exercise their data-protection rights.
11. Privacy and Personality Rights
An individual's legal-risk profile may be more intrusive than ordinary personal information.
For example:
Name + address
is ordinary identifying information.
But:
“This person is likely to commit fraud.”
is an evaluative inference concerning the person's behaviour and reputation.
The second type of information can potentially affect:
- reputation;
- employment;
- access to financial services;
- contractual opportunities;
- insurance;
- business relationships;
- regulatory treatment.
Therefore, predictive classifications should be treated as potentially significant personal-data outputs.
12. Confidentiality
Risk profiles may also contain confidential information.
A financial institution, employer, insurer, platform or regulator might generate an internal classification that should not automatically be disclosed to unrelated parties.
The legal problem becomes more serious where a risk profile is:
- sold;
- shared with affiliates;
- transferred internationally;
- supplied to another institution;
- used for marketing;
- used for automated exclusion.
The controller therefore needs to examine both the lawfulness of the original processing and the lawfulness of subsequent disclosure.
13. Civil Liability for Incorrect Classification
Suppose:
An AI system incorrectly classifies an individual as a high-risk fraud subject.
The individual loses a business opportunity.
Possible questions include:
- Was the classification generated through unlawful processing?
- Was inaccurate data used?
- Was there negligence?
- Was there a breach of statutory duty?
- Was the classification disclosed to another party?
- Was actual damage suffered?
- Is there causation between the classification and damage?
- Can the organisation establish lawful justification?
Civil liability cannot simply be presumed from the existence of an algorithmic error.
The claimant ordinarily needs to establish the relevant elements of the applicable cause of action, including legally recognisable damage and causal connection.
14. Evidentiary Problems
Predictive systems create difficult evidentiary questions.
A claimant may ask:
“Why was I classified as high risk?”
The organisation may respond:
“The model generated the result.”
That is unlikely to resolve the legal issue by itself.
Potential evidence includes:
- source datasets;
- model documentation;
- decision logs;
- audit trails;
- model version;
- input variables;
- output score;
- human-review records;
- expert reports;
- system architecture;
- security records.
Thus, algorithmic transparency and evidentiary traceability become increasingly important.
15. Case Laws
Important qualification
Direct UAE reported appellate case law specifically deciding the legality of AI-generated predictive legal-risk classifications remains limited. The following authorities therefore include UAE/DIFC/ADGM decisions and closely related technology, privacy, data-protection and evidence authorities.
They should not be presented as though every case directly decided AI profiling.
Case 1 — Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse
[2020] DIFC CFI 051 & CFI 085
This is one of the most important UAE free-zone data-protection authorities.
The dispute concerned a subject-access request involving information held by the DFSA during regulatory proceedings.
The DIFC Court considered questions concerning:
- personal data;
- access rights;
- regulatory investigations;
- confidentiality;
- limitations on disclosure.
The judgment examined what constitutes personal data and the relationship between access rights and regulatory functions.
Relevance
For predictive-risk systems, it demonstrates that an individual's rights concerning information must be considered alongside:
- regulatory functions;
- confidentiality;
- third-party interests;
- the nature of the information requested.
A predictive risk profile therefore cannot simply be treated as ordinary administrative information without considering applicable data-protection rules.
Case 2 — Health Bay Investment in Healthcare Enterprises & Development LLC v Dr Kamal Akkach
[2021] DIFC CFI 087
This DIFC dispute is relevant to the protection and treatment of information in a professional and commercial environment.
Principle
Confidential and personal information may acquire legal significance beyond the physical document or database in which it is stored.
Relevance to predictive classification
Where a risk system uses professional, employment or other sensitive information, the organisation must consider:
- confidentiality;
- lawful use;
- purpose;
- access;
- disclosure.
The case is therefore useful as a related UAE free-zone authority concerning information-related civil obligations, although it is not a direct automated-profiling decision.
Case 3 — Barclays Bank PLC v Bavaguthu Raghuram Shetty
[2020] DIFC CFI 061
This case concerned electronic evidence and the evidentiary treatment of digitally generated material.
Principle
Electronic information can become central evidence in civil litigation, but questions of authenticity, reliability and evidentiary weight remain important.
Relevance
Predictive classification disputes may depend upon:
- algorithmic records;
- electronic communications;
- databases;
- transaction histories;
- system logs.
The case illustrates why a party relying upon an automated classification should be able to establish the provenance and reliability of the underlying electronic evidence.
Case 4 — Gate MENA DMCC v Tabarak Investment Capital Ltd
[2023] DIFC CA 002
This litigation concerned complex digital-asset and technological evidence.
Principle
Digital disputes require careful examination of technical evidence, attribution and the factual circumstances surrounding electronic transactions.
Relevance
Predictive legal-risk systems similarly depend upon technical evidence.
For example, if an organisation claims:
“The algorithm classified the individual because of these transactions,”
the court may need to determine:
- whether the transactions actually occurred;
- whether the data was correctly attributed;
- whether the system correctly interpreted it;
- whether the resulting inference is justified.
The case is therefore relevant to the evidentiary architecture surrounding algorithmic classification, rather than being a direct profiling precedent.
Case 5 — NMC Healthcare Ltd & Others v Dubai Islamic Bank PJSC & Others
ADGM proceedings
NMC-related litigation generated extensive disputes concerning electronic information, financial records, digital evidence and investigation-related material.
Principle
Large-scale commercial disputes may require sophisticated treatment of electronic information and evidence.
Relevance
Predictive legal-risk systems frequently operate on large datasets.
Therefore, litigation concerning an automated classification may require examination of:
- databases;
- transaction records;
- communications;
- system-generated information;
- expert evidence.
The case is useful as an ADGM comparative authority for the evidentiary problems arising in technologically complex disputes.
Case 6 — NMC Healthcare Ltd & Others v Shetty & Others
[2025] ADGM CFI 0007
This later NMC-related litigation provides another important illustration of the treatment of complex electronic and financial evidence in ADGM proceedings.
Relevance
Where a predictive classification depends upon thousands or millions of individual data points, the claimant may need to establish not merely the existence of a computer-generated result but:
- the underlying data;
- the processing methodology;
- the reliability of the process;
- the connection between the output and the disputed decision.
Thus, automated classification should remain open to evidentiary scrutiny.
Case 7 — Dubai Court of Cassation, Criminal Cassation No. 536 of 2024
This UAE criminal authority concerned invasion of privacy through computer networks or information-technology tools.
The court considered the elements of digital privacy infringement and recognised that unlawful privacy intrusion can occur through technological means. Contemporary commentary on the judgment reports that the court treated general criminal intent as sufficient in the relevant circumstances.
Relevance
Although this is criminal rather than civil and does not concern AI profiling directly, it demonstrates the UAE judiciary's recognition of privacy interests in digital environments.
For predictive classification, unauthorised acquisition or use of information can therefore create legal consequences independently of whether the information is processed by a human or an algorithm.
Case 8 — Dubai Court of Cassation, Civil Cassation No. 611 of 2025
This technology-related civil authority is relevant to the distinction between:
- wrongful technological conduct;
- proof of damage;
- amount of compensation.
Principle
Establishing wrongful technological conduct does not automatically establish every item of financial damage claimed.
Relevance
This is particularly important for predictive classification.
Suppose:
An organisation unlawfully processes an individual's data and generates an incorrect risk profile.
The claimant would still need to establish the legally relevant damage and causal relationship required by the applicable civil claim.
Thus:
Unlawful processing ≠ automatic entitlement to every claimed loss.
16. DIFC Automated-Profiling Framework
The DIFC provides particularly useful UAE free-zone guidance for this subject.
Article 38 of the DIFC Data Protection Law recognises a data subject's right to object to a decision based solely on automated processing, including profiling, when it produces legal or seriously impactful consequences, and provides for manual review subject to defined exceptions.
The framework also places restrictions on solely automated decisions involving special categories of personal data.
This makes the DIFC framework highly relevant to questions involving:
- automated credit scoring;
- fraud-risk classification;
- employment screening;
- insurance profiling;
- financial-risk scoring;
- compliance classifications.
17. ADGM Approach
The ADGM Data Protection Regulations similarly recognise rights concerning automated individual decision-making and profiling.
ADGM guidance gives examples such as:
- automated recruitment assessments;
- automated credit decisions;
- financial-product recommendations based on consumer profiling.
It explains that an automated decision may have a significant effect where it influences whether an individual is considered for employment or affects financial products or pricing available to that person.
The ADGM framework therefore illustrates a broader UAE regulatory trend:
The greater the legal or significant effect of automated classification, the stronger the need for safeguards.
18. Federal UAE and Free-Zone Distinction
It is important not to merge all UAE regimes.
| Jurisdiction | Principal framework |
|---|---|
| UAE mainland | Federal PDPL and other federal laws |
| DIFC | DIFC Data Protection Law No. 5 of 2020 |
| ADGM | ADGM Data Protection Regulations 2021 |
| Federal courts | Federal/mainland legislation |
| DIFC Courts | DIFC legislation |
| ADGM Courts | ADGM legislation |
Therefore, a DIFC judgment should not automatically be described as a Federal UAE Court of Cassation precedent.
19. Civil-Law Elements of a Claim
Where predictive classification causes an alleged civil wrong, the claimant may need to establish:
1. Protected interest
There must be a legally protected interest, such as privacy, confidentiality, contractual rights or economic interests.
2. Unlawful conduct
The processing or use of information must fall outside the relevant legal permission or contractual/statutory authority.
3. Damage
The claimant must establish legally recognised damage where the cause of action requires it.
4. Causation
The claimant must connect the unlawful classification to the damage.
5. Attribution
The responsible controller, processor or other actor must be identified.
6. Quantum
The amount of compensation must be properly established.
20. Predictive Legal Risk and Contract Law
Risk classification can also arise during contractual relationships.
For example:
A bank uses predictive scoring to decide whether to continue providing a service.
Or:
A company uses an employee-risk model to determine whether to renew an employment-related arrangement.
The legal analysis may involve:
- contractual terms;
- good faith;
- data-protection obligations;
- confidentiality;
- statutory duties;
- non-discrimination;
- legitimate business purposes.
A contractual clause does not necessarily eliminate mandatory data-protection obligations.
21. Predictive Classification in Employment
Consider an employer using AI to classify employees:
| Classification | Possible consequence |
|---|---|
| Low risk | Normal employment |
| Medium risk | Additional supervision |
| High risk | Investigation |
| Very high risk | Termination recommendation |
The greatest legal danger occurs when:
AI classification automatically produces an employment consequence.
The employer should therefore consider:
- accuracy;
- transparency;
- human review;
- legitimate purpose;
- proportionality;
- employment-law requirements;
- privacy;
- discrimination;
- record keeping.
An algorithmic prediction should not automatically replace the legally required assessment of the actual facts.
22. Predictive Classification in Banking and Fintech
This is one of the most important applications.
A financial institution may create a risk profile based on:
- transaction behaviour;
- account activity;
- payment history;
- customer information;
- geographic information;
- unusual transaction patterns.
Some risk classification may be legally required for AML/KYC purposes.
However:
Regulatory compliance does not mean that every automated classification is automatically lawful.
The controller still needs to examine applicable data-protection requirements and appropriate safeguards.
23. Predictive Classification and Fraud Detection
Fraud-detection systems can be beneficial because they allow organisations to identify unusual behaviour quickly.
However, they create a difficult civil-law balance:
Fraud prevention
versus
individual rights.
For example:
An algorithm identifies an individual's transactions as suspicious.
The organisation may investigate.
But:
“Suspicious” does not necessarily mean “fraudulent.”
The distinction is legally significant.
24. Algorithmic Explainability
A predictive classification system should ideally be capable of explaining:
- what information was used;
- what factors were significant;
- what the classification means;
- what level of confidence exists;
- what limitations exist;
- whether a human reviewed it.
This is especially important where the output affects an individual's legal or economic position.
DIFC Courts' current privacy policy itself recognises rights concerning decisions based solely on automated processing and states that the Courts do not ordinarily rely solely on automated decision-making for personal-data processing.
25. Right to Challenge
A meaningful legal-risk classification system should permit an affected individual, where applicable, to:
- know that profiling occurred;
- access relevant personal information;
- correct inaccurate data;
- object where a legal right exists;
- request human review where applicable;
- challenge an adverse consequence;
- seek appropriate legal remedies.
This is particularly important because algorithmic predictions may contain errors that are difficult for the individual to discover independently.
26. Data Minimisation
An organisation should avoid collecting unlimited information simply because AI can process it.
For example, if fraud-risk assessment requires:
- transaction data,
it does not automatically follow that the organisation should collect:
- unrelated social-media activity;
- unrelated personal communications;
- unnecessary location history.
The principle is:
More data does not automatically mean better or more lawful prediction.
27. Special/Sensitive Personal Data
Predictive classification becomes substantially more sensitive where the system uses information concerning matters such as:
- health;
- biometrics;
- genetic information;
- other protected categories.
The UAE PDPL specifically treats large-scale sensitive-data processing and systematic automated assessment as matters requiring heightened privacy-risk analysis.
The DIFC framework also places additional safeguards around automated decisions involving special categories of personal data.
28. Algorithmic Bias
Suppose historical data shows that a particular category of customers was investigated more frequently.
An AI trained on that historical data may learn:
“Members of this category = high risk.”
This can create a feedback loop:
Historical enforcement → biased dataset → algorithmic classification → increased monitoring → more historical data → reinforced classification
This is sometimes called algorithmic feedback bias.
From a civil-law perspective, the relevant questions include:
- Was the processing lawful?
- Was the classification accurate?
- Was it discriminatory?
- Was the decision proportionate?
- Was there human review?
- Did it cause legally recognisable damage?
29. Predictive Classification and Reputation
A risk classification may affect an individual's reputation even when it is never publicly disclosed.
For example:
Internal database: “High-risk customer.”
If the classification is then shared externally:
“High-risk person — do not deal with him.”
the potential legal consequences can increase significantly.
The legal analysis may then involve:
- data protection;
- confidentiality;
- defamation/privacy principles where applicable;
- contractual obligations;
- civil liability.
30. Responsibility of AI Vendors
An important question is:
Who is responsible when a third-party AI system produces the incorrect classification?
Possible actors include:
- data controller;
- processor;
- software provider;
- AI developer;
- data broker;
- financial institution;
- employer;
- insurer.
The contractual allocation of responsibility is relevant, but mandatory legal obligations cannot necessarily be avoided simply by outsourcing the processing.
31. Evidentiary Chain
A strong legal framework should maintain an evidence chain:
Source Data → Processing → Model Version → Risk Score → Human Review → Final Decision → Consequence
If one stage cannot be reconstructed, proving the legality or reliability of the decision may become difficult.
This is particularly important in litigation.
32. Example
Facts
A UAE fintech company uses AI to classify customers.
Customer A receives a “high legal-risk” score because:
- several transactions were unusual;
- the customer had previous payment disputes;
- the algorithm identified behavioural similarities with previously flagged accounts.
The system automatically freezes the account.
Legal questions
The court could ask:
- Was the information lawfully processed?
- Was profiling involved?
- Was the profiling sufficiently justified?
- Did it have a legal or serious effect?
- Was a DPIA required?
- Was the customer informed?
- Was there human review?
- Was the information accurate?
- Was the classification based on sensitive data?
- Was the freeze legally justified?
- Was damage suffered?
- Was the damage caused by the classification?
The key point is:
The existence of a sophisticated algorithm does not remove the need for ordinary legal analysis.
33. Practical Compliance Framework
A UAE organisation using predictive legal-risk classification should consider the following:
Step 1 — Define purpose
Clearly identify why the prediction is being made.
Step 2 — Identify data
Determine exactly which personal data is being processed.
Step 3 — Establish legal basis
Identify the applicable lawful basis.
Step 4 — Conduct risk assessment
Determine whether profiling or automated decision-making creates significant risks.
Step 5 — Conduct DPIA where required
Particularly where automated profiling produces legal or serious impacts.
Step 6 — Test accuracy
Regularly evaluate false positives and false negatives.
Step 7 — Test bias
Examine whether apparently neutral variables produce discriminatory outcomes.
Step 8 — Provide safeguards
Implement human review and challenge mechanisms where required.
Step 9 — Maintain audit trails
Record data, model versions and decisions.
Step 10 — Control disclosure
Restrict access to risk profiles.
Step 11 — Review vendors
Ensure AI providers meet applicable contractual and legal requirements.
Step 12 — Provide remediation
Correct inaccurate classifications and address unlawful consequences.
34. Important Legal Principles
The subject can be reduced to the following principles:
Principle 1
Prediction is not proof.
Principle 2
Profiling is a form of personal-data processing.
Principle 3
Legal or serious consequences require stronger safeguards.
Principle 4
Human review is important where automated decisions materially affect individuals.
Principle 5
Accuracy matters because incorrect data can produce incorrect legal classifications.
Principle 6
Sensitive data creates heightened risks.
Principle 7
Risk classification must have a legitimate and sufficiently defined purpose.
Principle 8
Algorithmic processing does not eliminate civil liability.
Principle 9
A controller cannot automatically escape responsibility by outsourcing AI processing.
Principle 10
DIFC and ADGM automated-decision rules should be distinguished from the federal mainland regime.
35. Case-Law Summary
| Case | Jurisdiction | Main relevance |
|---|---|---|
| DFSA v Commissioner of Data Protection & Waterhouse [2020] | DIFC | Personal-data access, regulatory information, confidentiality |
| Health Bay v Dr Kamal Akkach [2021] | DIFC | Confidential/professional information |
| Barclays Bank v Shetty [2020] | DIFC | Electronic evidence |
| Gate MENA v Tabarak [2023] | DIFC | Digital evidence and technological attribution |
| NMC Healthcare v Dubai Islamic Bank | ADGM | Complex electronic/financial evidence |
| NMC Healthcare v Shetty [2025] | ADGM | Digital and financial evidence |
| Dubai Cassation 536/2024 | UAE | Digital privacy/invasion of privacy |
| Dubai Cassation 611/2025 | UAE | Technology-related conduct and proof of damage |
These authorities demonstrate the surrounding legal principles; they should not be cited as though UAE courts have already developed a large body of direct precedent specifically on AI-based predictive legal-risk scoring.
36. Exam-Oriented Formula
Predictive Legal-Risk Classification
Personal Data + Profiling + Prediction + Automated Processing + Legal/Serious Effect + Safeguards = Legal Analysis
For civil liability:
Unlawful Processing + Protected Interest + Damage + Causation + Attribution = Potential Civil Liability
And the most important distinction is:
Risk classification ≠ proof of liability.
37. Conclusion
Predictive classification of legal-risk individuals represents a major intersection between UAE civil law, personal-data protection, artificial intelligence, privacy, evidence and civil liability.
The UAE framework increasingly recognises that automated processing can have serious consequences for individuals. The federal PDPL specifically identifies systematic automated assessment and profiling that produces legal or serious impacts as high-risk processing requiring appropriate privacy-risk assessment.
The DIFC and ADGM regimes provide even more explicit treatment of automated decision-making and profiling, including rights concerning significant automated decisions and human review.
The central civil-law principle is therefore:
An algorithm may predict legal risk, but the prediction itself should not be confused with legally established wrongdoing.
For UAE legal analysis, the proper approach is to examine lawfulness of data processing, accuracy, proportionality, profiling, automated decision-making, human review, confidentiality, discrimination, evidence, damage and causation separately.

comments