Artificial Intelligence Ethics in International Law
- Edmarverson A. Santos

- Jun 11
- 97 min read
Introduction
Artificial Intelligence Ethics is now a central phrase in debates about automated decision-making, biometric identification, predictive analytics, generative systems, and autonomous functions. In public international law, however, the phrase is useful only if it is tied to legal authority. Ethical language may guide conduct, but it does not by itself identify duty-bearers, establish jurisdiction, prove breach, attribute conduct, or secure remedies for affected persons.
A person harmed by an automated welfare decision, an asylum risk score, a biometric watchlist, an AI-assisted sanctions process, or a machine-supported targeting decision does not need a general promise that the system is “responsible”. The legal inquiry is more demanding. Which rule governs the conduct? Which actor controlled the system? Was the interference lawful, necessary, and proportionate? Was there discrimination? Could the person understand and challenge the decision? Was there an effective remedy?
This article treats Artificial Intelligence Ethics as a question of public international law, not as a general technology-policy debate. Its central argument is that AI ethics becomes legally serious only when translated into duties, procedures, responsibility, and remedies. Existing international law already governs many AI-related harms. The relevant fields include international human rights law, international humanitarian law, the law of state responsibility, the responsibility of international organisations, business and human rights, jurisdiction, due diligence, and the law on remedies.
AI does not create a legal vacuum. It creates new factual settings in which established legal doctrines must be applied with precision. The difficulty is not that international law has nothing to say. The difficulty is that AI systems often disturb ordinary assumptions about control, knowledge, causation, territory, and proof. A harmful result may involve a dataset collected in one state, a model trained in another, a vendor incorporated elsewhere, a public authority deploying the system domestically, and individuals who never learn that automated analysis shaped the final outcome.
The international legal order already contains tools capable of addressing these problems. The United Nations Charter affirms human rights, international cooperation, sovereign equality, and peaceful relations between states (United Nations, 1945). The International Covenant on Civil and Political Rights protects privacy, equality, expression, political participation, and procedural guarantees (United Nations, 1966a). The International Covenant on Economic, Social, and Cultural Rights protects interests affected by AI in health, education, social security, work, housing, and public services (United Nations, 1966b). International humanitarian law regulates means and methods of warfare, including new weapons and AI-enabled military systems (ICRC, 2019).
AI-specific instruments add detail but differ in legal force. UNESCO’s Recommendation on the Ethics of Artificial Intelligence offers a global framework grounded in human dignity, human rights, fairness, safety, transparency, sustainability, and oversight (UNESCO, 2021). The UN system principles for ethical AI connect AI use within the United Nations to the Charter, human rights law, privacy, data responsibility, and lifecycle assessment (United Nations System, 2022). The Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law marks a formal treaty-based development because it places AI governance within binding public law commitments for parties that ratify and implement it (Council of Europe, 2024). The EU AI Act is regional legislation rather than universal international law, yet its regulatory model may influence companies, public authorities, and legislators outside Europe because of market access and compliance pressure (European Union, 2024).
Two errors must be avoided. The first is technological exceptionalism: the claim that AI is so novel that existing international law is largely obsolete. That view is weak. International law has long applied existing rules to new weapons, industries, forms of communication, and systems of economic power. The second error is complacency: the belief that existing rules require no operational adjustment. AI can increase scale, opacity, speed, surveillance, discrimination, and cross-border harm. The rules remain relevant, but institutions must learn how to apply them to systems built through data, models, procurement contracts, infrastructure, and delegated technical authority.
This first part sets the doctrinal foundation. Section 1 explains why ethical language is insufficient and why human rights provide the strongest legal baseline for Artificial Intelligence Ethics. Section 2 examines the sources of international law on AI: treaties, custom, general principles, soft law, and normative consolidation. Later parts will examine jurisdiction, state duties, attribution, international organisations, human rights impacts, corporate responsibility, armed conflict, security, inequality, remedies, and a doctrinal test for AI ethics.
1. Ethics, Law, and International Legal Order
1.1 The limits of ethical language
AI ethics is attractive because it offers a shared vocabulary. Engineers, companies, regulators, civil society groups, and international organisations can all speak of fairness, accountability, transparency, explainability, privacy, safety, and human oversight. These principles have value. They helped expose algorithmic bias, challenge opaque decision-making, and pressure public and private actors to take AI harms seriously.
Their weakness appears when harm occurs. A statement that an AI system should be “fair” does not answer the legal questions that follow. Fairness must be measured against a legal standard. Transparency must be connected to disclosure, reasons, evidence, audit, and review. Accountability must identify the actor responsible for the breach and the institution able to grant relief. Human oversight must be real enough to alter the outcome, not merely a formal approval step added to protect the institution.
International law asks questions that ethical codes often avoid. Has a state breached an international obligation? Is the conduct attributable to a state organ, a delegated private actor, or an international organisation? Was a restriction on privacy, expression, movement, or social protection lawful and proportionate? Did the affected person receive reasons? Could the decision be challenged before an independent body? Was a remedy available in practice?
The gap between ethics and law is visible in public administration. Suppose a welfare authority uses an automated model to flag suspected fraud. The model relies on historical data, household composition, employment interruptions, address history, prior administrative contacts, and other indicators. Benefits are delayed or suspended for a group of applicants. The authority describes the system as efficient and risk-based. That description does not settle legality. The legal analysis must examine the statutory basis, discrimination, privacy, procedural fairness, disclosure, human review, proportionality, and reparation for wrongful suspension.
Migration control offers a second example. Automated tools may classify travellers, visa applicants, or asylum seekers as higher risk. The system may not expressly use race, religion, nationality, or political opinion as prohibited grounds. It may still rely on proxies that produce unequal burdens. If the person is not told that automated analysis influenced the decision, the right to challenge the result becomes hollow. The procedural injury may be as serious as the final refusal.
The same problem appears in policing. Predictive tools may direct police attention toward areas or groups already over-policed. The model then receives more data from those same areas, reinforcing the original pattern. A statistical claim of accuracy does not answer the equality question. The legal issue is not only a technical error. It is the reproduction of state coercion through a system that appears neutral while deepening existing patterns of suspicion.
Scholarly analysis has shown that many AI ethics frameworks converge around similar principles but remain weak on implementation, enforcement, institutional responsibility, and conflict between values (Jobin, Ienca and Vayena, 2019). Diya’s critique of fairness, accountability, transparency and ethics is especially relevant for international law: a framework built only on abstract ethics may lack a stable normative foundation across plural societies and may enable ethics washing when organisations use ethical language to avoid harder legal duties (Diya, 2025).
This does not mean that ethical principles should be discarded. It means they must be translated. Fairness becomes equality and non-discrimination. Transparency becomes notice, reasons, auditability, and access to evidence. Accountability becomes attribution, review, liability, and reparation. Safety becomes prevention, risk assessment, monitoring, and institutional control. Human oversight becomes legally meaningful only when the human decision-maker is trained, independent, informed, and empowered to reject the automated output.
Artificial Intelligence Ethics is legally useful when it performs that translation. It is legally weak when it remains a list of desirable values without consequences.
1.2 Competing values in global AI governance
AI ethics is often written as if global agreement already exists. That assumption is false. States disagree over surveillance, public order, data control, platform regulation, military autonomy, speech governance, encryption, national security, and the proper role of private technology companies. Corporations may prioritise innovation, scalability, trade secrecy, and market access. Civil society may prioritise dignity, non-discrimination, affected-community participation, and remedies. Communities exposed to AI systems may care less about abstract transparency than about concrete power: who designed the system, who benefits, who bears the risk, and who can object.
These disagreements shape legal outcomes. A state with broad tolerance for public surveillance may treat real-time biometric identification as a security tool. A state with stronger privacy protections may see the same system as a threat to democratic life. A company may define fairness through statistical parity. A human rights body may ask whether the system entrenches historical disadvantage. An indigenous group may object to data extraction because data carries collective meaning, even where individual consent forms exist.
Global AI systems intensify the problem. A model trained mainly on dominant languages may perform poorly for underrepresented languages. Content moderation tools may misread political speech, religious expression, satire, or conflict documentation. Automated identity systems may exclude people without stable documentation. Welfare, credit, employment, or housing models may reproduce patterns linked to poverty, race, caste, gender, disability, migration status, or colonial administration. A technical system developed in one social setting can silently export its assumptions to another.
Public international law does not require full moral consensus. It works through minimum standards, institutional procedures, cooperation, and responsibility. Human rights law is especially important because it gives disagreement a legal boundary. States may design different AI policies, but they may not ignore dignity, equality, privacy, due process, political participation, and effective remedies.
This matters because AI ethics can be captured by powerful actors. Wealthy states, major technology companies, and technical standard-setting bodies often shape the language of responsible AI. States with weaker bargaining power may import systems designed elsewhere, trained on unsuitable data, and governed through contracts that limit inspection. Marginalised communities may experience AI governance as another layer of external control. A rights-based framework does not eliminate inequality, but it gives affected persons and states a stronger vocabulary for contestation.
The UN system principles for ethical AI take the correct direction by linking AI use to the UN Charter, international human rights law, privacy, human dignity, equality, cultural diversity, data responsibility, and lifecycle assessment (United Nations System, 2022). This is stronger than a free-standing ethics code. It places AI within a legal and institutional order that already contains duties and standards of conduct.
The lifecycle approach is essential. Many rights problems are built into systems before deployment. Data may be incomplete or biased. A model may be trained for one context and used in another. A procurement contract may block disclosure. A public authority may lack the technical capacity to assess vendor claims. A human reviewer may be added late, with no real authority to depart from the machine’s recommendation. Legal review must cover design, procurement, testing, deployment, monitoring, updating, and termination.
The task for international law is not to impose a single global morality for AI. That would be unrealistic and dangerous. The better task is to identify minimum legal thresholds. Public power should not operate through secret automated systems. Rights-affecting AI should not be deployed without a legal basis, necessity, proportionality, explanation, review, and remedy. Private vendors should not become hidden governors of public decisions. Military AI must remain within the limits of humanitarian law. Institutional immunity should not produce practical impunity where AI causes harm.
1.3 Human rights as the legal baseline
Human rights law provides the strongest baseline for Artificial Intelligence Ethics because it converts moral concern into a legal structure. It identifies protected interests, duty-bearers, permissible limitations, review procedures, and remedies. It also applies to the sectors where AI is already reshaping public and private power: policing, border control, welfare, health care, education, employment, courts, taxation, sanctions screening, and public administration.
Human dignity is the starting point. AI systems can reduce individuals to risk profiles, probability scores, biometric templates, behavioural predictions, or administrative categories. Human rights law resists that reduction. A person remains a legal subject. They must be able to understand decisions that affect them, contest unlawful treatment, and obtain redress when harm occurs.
Privacy is one of the most exposed rights. AI systems depend on data collection, inference, linkage, and prediction. They may generate sensitive information that individuals never knowingly disclosed. A system can infer health status, political preference, migration risk, family relations, religious affiliation, emotional state, or economic vulnerability. Consent is often weak where the state controls access to services or where a platform dominates social and economic participation. Article 17 of the ICCPR protects individuals against unlawful or arbitrary interference with privacy, family, home, and correspondence (United Nations, 1966a). AI governance must treat inference and profiling as serious privacy questions, not only data storage issues.
Equality and non-discrimination are equally central. AI systems often learn from historical records. If those records reflect discriminatory policing, unequal access to credit, biased hiring, or exclusion from public services, the model may reproduce those patterns while appearing neutral. International human rights law is not limited to intentional prejudice. Discriminatory effects may also violate equality guarantees, especially where they reinforce vulnerability or deny equal access to protected interests (Fredman, 2016).
Freedom of expression requires a balanced approach. AI can support expression through translation, accessibility tools, information retrieval, and documentation of abuses. It can also distort public debate through recommender systems, synthetic media, automated amplification, deepfakes, and opaque moderation. Article 19 of the ICCPR protects the right to hold opinions and to seek, receive, and impart information and ideas (United Nations, 1966a). Restrictions must meet legality, legitimacy, necessity, and proportionality. AI does not weaken that test.
Procedural rights may become the central legal battlefield. Many AI harms occur through administrative systems rather than court judgments. A person may be denied a benefit, selected for investigation, delayed at a border, downgraded in a priority system, or excluded from a service. The decision may look technical or bureaucratic, but the legal consequences can be severe. Due process requires notice, reasons, access to relevant evidence, impartial review, and meaningful appeal. A decision that cannot be explained cannot be effectively challenged.
Economic and social rights prevent AI ethics from becoming too narrow. Automated systems increasingly influence health care, housing, education, labour markets, social security, and public services. They may improve delivery, identify unmet needs, and reduce administrative delay. They may also exclude persons without digital access, stable documentation, literacy, language support, or accessible interfaces. Under the ICESCR, states must pursue rights without discrimination and with attention to vulnerable groups (United Nations, 1966b). A technically efficient system that excludes the people most dependent on public services is legally suspect.
Human rights law is not a complete solution. Enforcement is uneven. International bodies can be slow. Domestic implementation varies. Powerful states often resist scrutiny. Yet human rights law offers what ethics alone lacks: doctrine, institutional practice, standards of justification, and the language of remedy. It places Artificial Intelligence Ethics inside a legal order concerned with dignity, equality, public power, and accountability.
2. Sources of International Law on AI
2.1 Treaty law and emerging AI instruments
Any serious analysis must begin with sources. Article 38(1) of the Statute of the International Court of Justice refers to international conventions, international custom, general principles of law, and subsidiary means such as judicial decisions and scholarly writings (ICJ Statute, 1945). The provision does not capture every modern form of norm production, but it remains the basic grammar of international legal authority (Aust, 2005; Klabbers, 2024).
There is still no universal AI treaty equivalent to the main human rights covenants, the Geneva Conventions, or the UN Convention on the Law of the Sea. This matters. Many AI principles are politically influential, but they do not bind states as treaty law unless adopted through binding instruments or incorporated into domestic law. A government may endorse ethical AI in a declaration while resisting enforceable limits on surveillance, military autonomy, predictive policing, or corporate responsibility.
The Council of Europe Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law is a major development because it is treaty-based (Council of Europe, 2024). Its legal importance lies in its structure. It treats AI governance as a question of human rights, democracy, and the rule of law rather than a narrow matter of product safety or industrial policy. It confirms that AI systems used by public authorities, or by private actors in contexts linked to public interests, require legality, oversight, and safeguards.
Its limits also need precision. The Convention binds only parties that ratify it and only within the scope of its obligations as implemented domestically. Its practical force will depend on national legislation, monitoring, institutional practice, judicial interpretation, and political will. It does not automatically create universal customary law. Its broader influence may still be substantial because treaties can shape expectations, guide later negotiations, and provide models for domestic reform.
The EU AI Act has a different legal character. It is regional legislation within the EU legal order, not a universal treaty. It classifies AI systems through a risk-based model, prohibits certain practices, imposes obligations on high-risk systems, and creates transparency and governance requirements (European Union, 2024). For public international law, its direct legal force is limited outside the EU. Its indirect influence may be significant. Companies seeking access to the EU market may adapt global compliance practices. Legislators elsewhere may borrow its categories. International organisations may draw on their risk language.
Existing human rights treaties remain the binding foundation for many AI-related harms. The ICCPR, ICESCR, CERD, CEDAW, CRC, CRPD, regional human rights conventions, labour instruments, and humanitarian law treaties already regulate conduct affected by AI. A facial recognition programme may raise privacy and equality issues. Automated employment screening may implicate non-discrimination and labour rights. AI-supported welfare decisions may affect social security and due process. AI-enabled weapons raise questions under humanitarian law.
Treaty interpretation allows existing obligations to meet new facts. The Vienna Convention on the Law of Treaties requires treaties to be interpreted in good faith according to the ordinary meaning of the terms in their context and in light of their object and purpose (United Nations, 1969). Human rights treaties are not confined to the technologies known at the time of adoption. Privacy is not limited to physical correspondence. Equality is not limited to explicit prejudice. Fair procedure is not limited to analogue files. The factual environment changes; the legal protection remains.
2.2 Customary international law and AI
Customary international law requires a general practice accepted as law. The International Law Commission identifies two elements: state practice and opinio juris (International Law Commission, 2018). For AI-specific rules, caution is required. Many states support broad principles such as transparency, safety, human oversight, and non-discrimination. That does not prove that they accept these principles as binding customary law in a precise legal form.
It would be premature to claim a general customary rule requiring all AI systems to be explainable, fair, transparent, or subject to human oversight. The practice is too uneven and the legal conviction too unsettled. States differ sharply on biometric surveillance, content moderation, military AI, data localisation, cyber operations, and platform control. Some regulate high-risk AI. Others prioritise innovation or security. Some deploy AI for extensive public monitoring. Others restrict comparable practices.
Custom still matters because existing customary rules apply to AI-related conduct. The prohibition on the use of force, the principle of non-intervention, sovereign equality, certain due diligence obligations, diplomatic protection, state responsibility, and core rules of humanitarian law are not suspended by machine learning. The tool is new; the legal interest may be familiar.
Humanitarian law gives a clear example. The rules of distinction, proportionality, precautions in attack, and the prohibition of weapons that are indiscriminate by nature do not depend on the absence of AI. A state cannot avoid those rules by claiming that an algorithm produced a target recommendation. A public authority cannot avoid human rights obligations by saying that a model generated the risk score. Automation changes evidence and control; it does not erase legal duty.
Custom may develop through state reactions to AI-related incidents. Relevant materials may include legislation, military manuals, official statements, diplomatic protests, litigation, treaty negotiations, procurement rules, export controls, and positions in international organisations. At present, the stronger conclusion is restrained: AI-specific custom remains limited, but AI-related conduct is already governed by established customary and treaty rules.
This distinction is important. Overclaiming custom weakens the article’s credibility. A specialist analysis should not announce new customary rules merely because they are desirable. It should ask what states actually do, what they claim law requires, and how other states respond. In AI governance, much of the relevant material still belongs to soft law, treaty development, domestic regulation, institutional standards, and emerging practice.
2.3 General principles of law
General principles of law help international law reason through gaps, procedures, and common legal requirements across systems. They are not an open invitation to invent rules. Their value lies in principles recognised across domestic and international legal orders, including good faith, due process, legal certainty, equality before the law, proportionality, necessity, access to justice, and effective remedy (Cheng, 1953; Pellet, 2017).
AI governance needs these principles because many harms arise through the procedure. The affected person may not suffer visible physical injury. They may be classified, flagged, delayed, excluded, ranked, or placed under suspicion. The decision may be presented as technical, yet it can alter access to rights and opportunities. General principles help turn these harms into legal questions.
Legal certainty is central. Rights-affecting AI should not operate through hidden rules. Public authorities should not deploy secret automated systems that influence benefits, policing, border control, taxation, sanctions, or access to public services without a clear legal basis. The rule of law requires persons to know the standards that govern them. Technical opacity cannot become a substitute for legal authority.
Proportionality gives structure to disputes about surveillance, policing, migration, welfare, and security. It requires the authority to identify a lawful aim, show that the system is suitable, explain why less intrusive measures are insufficient, and justify the burden imposed on rights. This test is stricter than general ethical balancing. Efficiency and innovation are not enough.
Good faith also has practical relevance. A state should not endorse rights-based AI internationally while deploying opaque systems domestically that undermine privacy, equality, or democratic participation. Nor should a public authority hide behind vendor contracts, trade secrecy, or technical complexity. Public power remains public power even when exercised through private infrastructure.
An effective remedy is the principle that gives accountability substance. A person must have a practical route to challenge an AI-assisted decision. That route must include meaningful information, review by a competent authority, correction of error, and reparation for harm. A complaint mechanism without disclosure, expertise, independence, or remedial power is not an effective remedy.
2.4 Soft law and normative consolidation
Soft law currently dominates AI governance. UNESCO, the OECD, the UN General Assembly, the Human Rights Council, regional organisations, technical bodies, and national regulators have produced recommendations, declarations, principles, guidelines, standards, and policy frameworks. These materials vary in quality and legal relevance. None should be treated as binding merely because they use the language of rights or responsibility.
Soft law still matters. It can guide conduct before treaty law is politically possible. It can clarify expectations, shape institutional practice, influence domestic legislation, support treaty interpretation, and contribute to the gradual formation of legal standards (Shelton, 2000; Boyle and Chinkin, 2007). Its legal relevance depends on wording, adoption process, state support, institutional use, repetition, and later practice.
UNESCO’s Recommendation is significant because it was adopted within a universal organisation and links AI ethics to human dignity, human rights, sustainability, fairness, privacy, transparency, human oversight, and public awareness (UNESCO, 2021). It does not create direct treaty obligations. Its value lies in normative consolidation. It gives states and institutions a common framework for legislation, policy, procurement, education, and international cooperation.
The UN system principles for ethical AI have a narrower institutional focus but strong practical importance. They connect AI use by UN entities to the Charter, international human rights law, privacy, data responsibility, sustainability, safety, non-discrimination, and lifecycle governance (United Nations System, 2022). This is crucial because the United Nations itself may use AI in humanitarian action, migration support, peace operations, development programming, sanctions implementation, and human rights monitoring. The organisation cannot credibly promote rights-based AI while using weak safeguards in its own operations.
General Assembly resolutions and the Global Digital Compact add political authority. They do not operate as treaties. Their importance depends on their wording, breadth of support, repetition, and influence on later institutional practice. They can identify common concerns, guide cooperation, encourage domestic reform, and frame future negotiations. In a field where binding treaty-making is slow, these instruments often shape the first layer of shared expectations.
Technical standards have a different role. Standards on risk management, cybersecurity, documentation, testing, audit, data governance, and model evaluation can help operationalise legal duties. They can make vague commitments more concrete. Yet technical standards cannot replace law. A system may satisfy a technical benchmark and still violate privacy, equality, due process, or humanitarian law. Standard-setting processes may also reflect the priorities of powerful states, corporations, and technical communities.
The legal challenge is to use soft law without overstating it. A court, regulator, treaty body, or procurement authority may rely on soft law as interpretive support, evidence of emerging standards, or a benchmark for due diligence. A state may incorporate it into domestic legislation. An international organisation may adopt it as internal policy. A contract may make it binding between specific parties. In each case, legal force comes through a recognisable legal pathway.
Artificial Intelligence Ethics currently sits in this mixed normative space. Some duties are already binding because they arise from existing treaties or custom. Some are developing through AI-specific instruments. Some remain soft law. Some are technical, contractual, or institutional. A serious international law analysis must keep these categories distinct while explaining how they interact. Confusing them creates false authority. Separating them too rigidly misses how international norms develop.
3. Jurisdiction and Cross-Border AI Harm
3.1 Territorial jurisdiction and digital systems
Jurisdiction is the first practical barrier in international AI governance. AI systems rarely respect the neat territorial assumptions on which much public law was built. Data may be collected in one state, labelled in another, processed through cloud infrastructure in a third, and deployed by a public authority or company elsewhere. The person affected by the decision may never know where the relevant technical operations occurred.
Public international law does not lose relevance because technology is distributed. Territorial jurisdiction remains the basic starting point. A state may regulate conduct, persons, infrastructure, companies, and public authorities within its territory. If a welfare authority, police department, migration agency, school system, court administration, or tax office deploys AI domestically, the state’s jurisdiction is clear. The harder cases arise when the system’s design, data, or effects cross borders.
The territorial principle can still reach digital conduct where there is a substantial territorial connection. A state may regulate companies incorporated or operating within its territory. It may regulate systems placed on its market. It may impose duties on public procurement. It may require impact assessments, data safeguards, auditability, and remedies where AI affects persons within its territory. None of this requires a new jurisdictional theory. It requires applying established bases of jurisdiction to technical chains that are more complex than ordinary administrative conduct.
The Lotus principle is often invoked as a starting point for jurisdictional freedom, although it should not be overstated. The Permanent Court of International Justice held that restrictions on state action cannot simply be presumed, but the case belongs to an older legal setting and does not grant unlimited regulatory power (PCIJ, 1927). Modern jurisdiction is constrained by sovereignty, treaty obligations, human rights, immunities, comity, and the need to avoid unreasonable interference with other states’ regulatory authority.
AI sharpens the effects problem. A company may design a system outside a state, but the system may affect individuals inside that state. A platform may rank political content for users across multiple jurisdictions. A remote vendor may supply risk scoring to a border authority. A foreign spyware or biometric tool may be sold to a state that uses it against dissidents. Territorial jurisdiction based only on physical location is inadequate for these settings.
International law has long recognised that conduct may have legally relevant effects beyond the place where it begins. The effects doctrine is controversial when used too aggressively, especially in economic regulation, but it reflects a real problem: harmful conduct does not always stop at the border (Aust, 2005). For AI systems, the effects analysis must be disciplined. A state should not claim universal regulatory power merely because a digital system is globally accessible. There must be a genuine connection, such as affected persons, targeted services, market access, public deployment, infrastructure, or foreseeable rights impacts.
A practical example shows the issue. A private company incorporated abroad provides an automated fraud detection system to a domestic welfare agency. The model was trained outside the country and uses vendor-controlled infrastructure. Yet the decisions affect local residents’ access to social security. The territorial link is strong because the public authority deploys the tool inside the state’s administrative system. The state cannot treat the foreign origin of the model as a reason to avoid domestic or international obligations.
Another example concerns biometric surveillance. A state may buy facial recognition technology trained on foreign datasets and hosted on external servers. If the tool is used by domestic police to identify people at protests, the relevant human rights interference occurs within the state’s jurisdiction. The procurement chain may be international, but the exercise of public power is local. The state remains responsible for legality, necessity, proportionality, non-discrimination, and remedy.
Territorial jurisdiction is strongest when AI is used by state organs. It is more difficult where private platforms operate globally. A state may still regulate platform conduct that targets users, markets services, processes residents’ data, or shapes public debate within its territory. The legal challenge is to regulate rights-affecting conduct without creating excessive fragmentation or extraterritorial overreach.
3.2 Extraterritorial human rights duties
Extraterritorial human rights obligations are essential for AI but must be handled carefully. A weak article would simply claim that all AI harms abroad fall under the regulating state’s human rights jurisdiction. That would be too broad. A stronger analysis asks when a state exercises power, control, or authority sufficient to trigger its obligations.
Human rights bodies and courts have developed different tests. The Human Rights Committee has linked obligations under the ICCPR to persons within a state’s territory and to persons subject to its jurisdiction, including those within its power or effective control (Human Rights Committee, 2004). The International Court of Justice has accepted that human rights treaties may apply to a state’s conduct outside its territory in certain circumstances, including occupation and exercises of authority abroad (ICJ, 2004). The European Court of Human Rights has developed a cautious but significant body of case law on effective control over territory, state agent authority, and exceptional extraterritorial situations (ECtHR, 2001; ECtHR, 2011).
AI creates situations that do not fit comfortably into older categories. Remote surveillance, cyber operations, cross-border data processing, migration externalisation, and military targeting may affect individuals abroad without physical custody. The question is not only physical control. It is also whether the state’s conduct has a direct, foreseeable, and serious impact on protected rights.
The right to life offers one example. The Human Rights Committee has stated that states must respect and ensure the right to life of persons located outside their territory when such persons are affected by activities that have a direct and reasonably foreseeable impact on their right to life (Human Rights Committee, 2019). This reasoning may be relevant to AI-assisted targeting, autonomous weapons, and state cyber operations that foreseeably endanger life. It should not be extended casually to every digital effect, but it confirms that distance does not always defeat obligation.
Migration control is another important field. States increasingly cooperate with third countries, international organisations, and private vendors to manage borders before migrants reach formal territory. AI tools may assist identity checks, risk classification, movement tracking, or document verification. If a state exercises decisive influence over a process that exposes individuals to refoulement, arbitrary detention, family separation, or denial of asylum procedures, it may not avoid responsibility by placing technology, personnel, or decision points outside its border.
Surveillance exports pose a related problem. A state may authorise companies to export spyware, biometric systems, or data analytics tools to foreign authorities. Those tools may later be used against journalists, human rights defenders, opposition figures, or minority groups. Human rights law has not fully settled the extraterritorial duties of exporting states in this context. At a minimum, due diligence requires serious attention to foreseeable misuse where a state has regulatory power over the exporting actor and knowledge of the risk (UN Human Rights Council, 2011; OHCHR, 2020).
Military AI makes the issue more urgent. A state that uses AI-enabled systems abroad remains bound by the UN Charter, applicable human rights obligations, and international humanitarian law. It cannot avoid scrutiny by arguing that the relevant decision was generated through a remote system or based on data processed elsewhere. If the state selects targets, authorises force, or controls the military operation, the legal inquiry remains attached to the state’s conduct.
Extraterritoriality must not be inflated into a vague global duty to prevent all AI harm everywhere. That would be doctrinally unstable. The stronger position is narrower: where a state exercises authority, control, decisive influence, or regulatory power over conduct that directly and foreseeably affects protected rights abroad, international obligations may arise. The precise scope depends on the treaty, the right, the factual control, and the institutional setting.
3.3 Private platforms and regulatory reach
Private platforms complicate jurisdiction because they perform functions that look increasingly public. They shape speech, political visibility, access to information, commercial opportunity, identity verification, and sometimes emergency communication. They may not be state organs, but their decisions can affect rights on a scale once associated with public power.
International human rights law binds states directly. It does not bind private platforms in the same way unless incorporated through domestic law or specific legal regimes. Yet states have duties to protect individuals against human rights harms caused by private actors. That duty supports the regulation of companies operating in areas such as data protection, non-discrimination, consumer protection, labour, electoral integrity, and public safety.
The difficulty is that major platforms operate across many jurisdictions at once. A moderation decision may affect political speech in several countries. A recommender system may amplify ethnic hostility in one society while being designed and governed in another. A generative model may produce harmful content globally. A fraud detection system may be sold to public agencies in many states under similar vendor terms. Domestic regulation alone can be too weak, yet global regulation remains politically fragmented.
Powerful jurisdictions can export standards through market access. The EU AI Act, data protection rules, and platform regulations may influence companies beyond Europe because firms prefer unified compliance models. This effect is not the same as international legal validity. It is regulatory gravity. It may raise standards, but it may also allow powerful markets to set global rules without equal participation by less powerful states.
Private platforms also raise conflict-of-law problems. One state may require the removal of content that another state protects as expression. One state may demand access to user data that another treats as private. One state may classify a group as a terrorist while another sees parts of the same movement as political opposition. AI systems used for moderation, ranking, and enforcement must operate across these legal contradictions.
A rights-based approach requires states to regulate platforms without turning them into tools of censorship. It also requires companies to avoid hiding behind the complexity of global operations. Where platforms design systems that foreseeably affect expression, privacy, equality, or political participation, they should conduct human rights due diligence, document risks, consult affected groups, provide appeal mechanisms, and disclose enough information for public accountability (UN Human Rights Council, 2011; OHCHR, 2020).
Regulatory reach should be linked to genuine connections. A state has a stronger claim where the platform targets its population, processes residents’ data, maintains offices, sells advertising, contracts with public authorities, or affects elections and public services. A state has a weaker claim when it seeks to impose global content rules with little territorial connection. AI governance needs this balance because both under-regulation and overreach can damage rights.
4. State Duties Across the AI Lifecycle
4.1 Respect, protect, and fulfil
The classic human rights framework of respect, protect, and fulfil gives structure to state duties in AI governance. It is more precise than broad ethical language because it separates direct state conduct, regulation of private actors, and positive institutional measures.
The duty to respect requires the state itself not to violate rights through AI systems. A police authority should not use biometric surveillance without a lawful basis and strict necessity. A welfare department should not suspend benefits through an opaque model that denies reasons and appeal. A migration authority should not rely on risk scores that discriminate indirectly or conceal relevant evidence. A court should not use predictive tools in ways that undermine fair trial guarantees.
The duty to protect requires the state to regulate private actors that create foreseeable rights risks. This includes companies selling facial recognition tools, automated hiring systems, credit scoring models, educational proctoring software, workplace monitoring systems, content moderation infrastructure, and data brokerage services. Regulation should not be symbolic. It must include enforceable standards, supervisory capacity, investigation powers, and remedies.
The duty to fulfil requires more than preventing harm. States must build conditions that allow people to benefit from AI-compatible rights protection. This includes accessible digital services, inclusive datasets, public-interest research, legal aid, technical expertise in regulators and courts, and public education. A state that digitises public services without protecting persons with disabilities, older persons, migrants, linguistic minorities, or people without stable internet access risks turning modernization into exclusion.
AI makes these duties continuous rather than episodic. A traditional administrative rule may be adopted once and applied with modest variation. An AI system may change through updates, retraining, drift, feedback loops, or new deployment contexts. A model that was acceptable at launch may become unlawful as data changes or as use expands. State duties must track that lifecycle.
The lifecycle begins before procurement. Public authorities should ask whether AI is needed at all. Some problems are political, administrative, or resource-based, not technical. Deploying AI to detect welfare fraud while ignoring underfunding, staffing shortages, or unclear eligibility rules may intensify unfairness rather than solve it. A rights-based state should not treat AI as the default answer to administrative pressure.
The next stage is design or selection. If the state builds the system, it controls the model, data, objectives, and safeguards. If it buys the system, it must still examine the vendor’s claims. Procurement should require documentation, testing, bias evaluation, cybersecurity safeguards, data protection measures, audit rights, explainability, and termination rights. A contract that blocks the state from inspecting a rights-affecting model is incompatible with responsible public administration.
Deployment is not the end of the legal inquiry. Monitoring is essential. Error rates may differ across groups. Officials may over-rely on automated outputs. A system may be used for purposes beyond its original mandate. Data quality may deteriorate. New risks may appear after integration with other databases. The state must maintain oversight as long as the system affects rights.
4.2 Due diligence before deployment
Due diligence is the bridge between general duties and operational practice. It requires states to act with care before harm occurs, not merely to respond after violations. In international law, due diligence appears across fields, including environmental law, human rights, transboundary harm, cyber discussions, and state responsibility. The underlying idea is that a state may breach its obligations when it fails to take reasonable measures to prevent foreseeable harm within its capacity.
The Corfu Channel case remains a classic expression of the principle that a state may have duties regarding harmful activities connected to its territory or knowledge (ICJ, 1949). Environmental cases such as Pulp Mills strengthened the requirement of prior assessment where activities may cause significant harm (ICJ, 2010). AI is not environmental pollution, but the logic of prior assessment is relevant: when a state deploys or authorises a system likely to affect rights, it must examine risks before the system causes harm.
In the AI context, due diligence should begin with a rights impact assessment. This assessment should identify the purpose of the system, the legal basis, the affected rights, the groups likely to bear risk, the data sources, the possibility of bias, the role of human decision-makers, the review process, and the available remedy. It should also ask whether the same objective can be achieved by a less intrusive means.
Consultation is not optional where affected groups are identifiable. A welfare algorithm should not be designed only by data scientists and fraud units. It should consider the experience of benefit recipients, poverty organisations, equality bodies, social workers, and legal aid providers. A migration risk tool should include expertise on asylum law, non-refoulement, trauma, language barriers, and documentation gaps. A school allocation or proctoring system should consider children’s rights, disability, family circumstances, and digital inequality.
Testing must be context-specific. A model may perform well in abstract accuracy tests but fail in the setting where it will be used. Facial recognition accuracy in controlled conditions does not prove lawful use in public demonstrations. A language model’s general fluency does not prove reliability for legal translation, asylum interviews, or human rights reporting. A fraud model’s detection rate does not prove that it respects equality or due process.
Documentation is part of due diligence. Public authorities should record why the system is needed, what alternatives were considered, what risks were identified, how those risks were mitigated, which officials are responsible, and how affected persons can challenge outcomes. Without documentation, later accountability becomes almost impossible.
Due diligence must also address foreseeable misuse. A database created for humanitarian assistance may later be used for migration enforcement. A biometric identity system designed for service delivery may become a surveillance tool. A predictive system built for public safety may be repurposed for political control. Rights assessment should examine function creep, not only intended use.
A one-time assessment is not enough. AI systems require ongoing monitoring because performance and use change over time. Data drift, model updates, staff behaviour, institutional incentives, and new integrations can alter rights impacts. Due diligence requires review at design, procurement, deployment, update, expansion, and termination.
4.3 Necessity and proportionality
Necessity and proportionality are central tests for rights-affecting AI. They prevent states from justifying intrusive systems through broad claims of efficiency, modernization, or security. The state must identify the aim, prove the measure is suitable, show that less intrusive alternatives are insufficient, and demonstrate that the rights burden is not excessive.
The first requirement is legality. A public authority should not deploy an AI system affecting rights without a clear legal basis. Internal policy, vendor documentation, or administrative convenience cannot substitute for law. The legal basis must be accessible and sufficiently precise. People should know when automated systems may be used, for what purpose, with what safeguards, and with what rights of challenge.
The second requirement is a legitimate aim. Public security, fraud prevention, efficient administration, health protection, and child safety may be legitimate aims in appropriate contexts. Yet the aim must be specific. A vague reference to innovation or digital transformation is insufficient. AI cannot be justified merely because it is new or cost-saving.
Suitability requires evidence that the system can actually contribute to the aim. If a predictive policing tool produces unreliable or biased outputs, it is not suitable. If an automated welfare tool generates large numbers of false positives, it may undermine the aim by punishing lawful claimants and wasting administrative resources. If a migration risk system cannot be explained, its suitability for lawful decision-making is doubtful.
Necessity requires the state to consider less intrusive alternatives. Could the objective be achieved through more staff, better training, clearer rules, targeted audits, non-AI statistical tools, or narrower data use? If the state cannot answer that question, it has not justified the system. AI should not become a shortcut for avoiding ordinary administrative reform.
Proportionality in the strict sense requires balancing the benefit against the rights burden. A biometric system used to find a specific dangerous person may raise one kind of proportionality question. Continuous biometric scanning of public space raises a much heavier burden because it affects privacy, assembly, expression, and political participation at population scale. A welfare model that saves administrative time but wrongly suspends essential income for vulnerable persons may impose a disproportionate burden.
The analysis should include group harms. AI systems can chill protest, deter benefit claims, reinforce racialised policing, exclude persons with disabilities, or make migrants less willing to approach public authorities. These harms may not appear in a narrow accuracy metric. Legal proportionality must examine social effects, not only technical performance.
Human oversight does not automatically cure disproportionality. Officials may defer to automated outputs because of workload, institutional pressure, or perceived objectivity. This is automation bias. A meaningful human reviewer must understand the system’s limits, have access to relevant information, and possess authority to reject the recommendation. A formal human signature at the end of an automated process is not enough.
Necessity and proportionality also apply to data. A state should not collect or link more data than required for a defined lawful purpose. Large-scale data accumulation creates future risks even if the initial use seems benign. Data minimisation is not only a privacy principle. It is a safeguard against function creep and institutional overreach.
4.4 Public procurement and outsourcing
Public procurement is one of the most important but least visible points of AI governance. Many public authorities do not build AI systems themselves. They buy them. Vendors may provide software, cloud services, datasets, model updates, analytics dashboards, technical support, and risk scores. The danger is that public law obligations become buried inside private contracts.
A state cannot avoid international responsibility by outsourcing public functions. If a public authority relies on a private AI system to make or support rights-affecting decisions, the state remains responsible for legality, oversight, explanation, and remedy. Procurement does not privatise the state’s human rights obligations.
This is especially important where vendors claim trade secrecy. A company may refuse to disclose model logic, training data, error rates, or validation methods. It may describe the system as proprietary. That position may protect commercial interests, but it cannot justify public opacity where rights are affected. A person denied a benefit, flagged by police, refused entry, or selected for investigation must have access to meaningful reasons. Public authorities should not buy systems they cannot explain, audit, or contest.
Procurement contracts should include rights-based conditions. These may include access to documentation, independent audit rights, data protection obligations, bias testing, cybersecurity duties, explanation requirements, incident reporting, limits on secondary use, human oversight, termination clauses, and cooperation with regulators or courts. Contracts should also prohibit vendor restrictions that prevent public authorities from meeting disclosure or remedy obligations.
Vendor dependence creates another risk. Public authorities may lack technical capacity and become dependent on private expertise. They may accept vendor claims about accuracy or fairness without independent validation. They may continue using flawed systems because termination is expensive or operationally disruptive. This dependency weakens democratic control over public power.
The problem is sharper in lower-capacity states. A government may import AI tools promoted as efficient or modern without having the regulatory, judicial, or technical infrastructure to test them. Vendor contracts may be governed by foreign law, hosted on foreign infrastructure, and written in terms that limit accountability. International cooperation should help states build procurement capacity, not merely encourage the adoption of AI systems.
Public procurement should also address purpose limitation. Systems bought for one purpose should not be repurposed without fresh legal review. A tool acquired for identity verification should not quietly become a law enforcement database. A humanitarian data system should not become a migration enforcement tool. A school safety tool should not become a general student surveillance system. Each new use requires a new legal basis and rights assessment.
Outsourcing can improve public services when properly governed. It can provide expertise, speed, and technical capacity. The legal danger lies in unaccountable delegation. The state remains the public authority. If it cannot supervise the system, explain the decision, correct the error, and provide a remedy, it should not deploy the tool.
5. Attribution and State Responsibility
5.1 AI acts and internationally wrongful conduct
The law of state responsibility is essential for Artificial Intelligence Ethics because it answers a question ethical codes often avoid: when does AI-related harm become an internationally wrongful act of a state? The starting point is simple. AI itself does not bear international responsibility. Machines do not owe treaty obligations, form legal intent, or provide reparation. Responsibility attaches to states and other legal persons through human and institutional conduct.
Under the International Law Commission’s Articles on State Responsibility, an internationally wrongful act exists when conduct consisting of an action or omission is attributable to the state and constitutes a breach of an international obligation (International Law Commission, 2001). This structure is directly applicable to AI-related harm. The fact that a system is automated does not change the two core questions: attribution and breach.
Breach depends on the primary obligation. If an AI-assisted surveillance system violates privacy, the relevant primary rule may come from human rights law. If an AI-enabled weapon is used indiscriminately, the primary rule may come from humanitarian law. If an AI-supported cyber operation violates sovereignty or the prohibition on the use of force, the primary rule may come from general international law. State responsibility supplies the secondary rules: attribution, consequences, cessation, non-repetition, and reparation.
The conduct may be an action or an omission. A state may act wrongfully by deploying a discriminatory algorithm. It may also act wrongfully by failing to regulate a private actor where it had a duty to protect against foreseeable harm. It may fail to conduct a weapons review, fail to supervise a vendor, fail to provide a remedy, or fail to prevent the foreseeable misuse of a state-controlled database.
Causation will often be contested. AI systems may produce probabilistic outputs rather than clear commands. Human officials may make final decisions based partly on automated recommendations. Vendors may blame poor deployment. Public authorities may blame flawed training data. These complexities do not defeat responsibility, but they make evidence crucial. Documentation, audit logs, procurement records, model cards, validation reports, human review notes, and appeal records may become central to proving breach.
The legal analysis should reject the “accountability gap” as an excuse. AI may create evidentiary and institutional difficulties, but it does not create a zone where responsibility disappears. If a state chooses to use a system whose operation it cannot explain or control, that choice itself may be legally relevant.
5.2 State organs using automated systems
Conduct of state organs is attributable to the state under Article 4 of the ILC Articles, whatever the organ’s function or position in the state structure (International Law Commission, 2001). This rule is crucial for AI. Courts, police, military units, intelligence services, welfare departments, border agencies, tax authorities, municipalities, and public schools remain state organs when they use automated systems.
If a police department uses facial recognition unlawfully, the state cannot say that the vendor or algorithm acted. The police decided to procure, deploy, rely on, and act upon the system. If a welfare agency suspends benefits based on an automated fraud score without reasons or appeal, the state organ made the rights-affecting decision. If a military unit uses an AI-assisted targeting system in an attack that violates humanitarian law, the conduct remains attributable to the state.
This remains true where the organ exceeds authority or violates instructions. Under Article 7 of the ILC Articles, conduct of a state organ or empowered entity remains attributable if it acts in that capacity, even if it exceeds authority or contravenes instructions (International Law Commission, 2001). This matters where officials misuse AI tools. A police officer may use a database for improper surveillance. An intelligence unit may deploy a tool beyond its mandate. A welfare official may rely on a model in cases where use is prohibited. Attribution may still arise because the actor used an official capacity.
The state may also be responsible for systemic failures. If a public authority deploys an AI tool without adequate training, review, documentation, or safeguards, responsibility is not limited to one official’s decision. The wrongful conduct may lie in the institutional design. A system that predictably produces arbitrary outcomes is not saved by the fact that no individual official intended harm.
Courts and tribunals will need to examine the relationship between automated output and human decision-making. Some systems merely assist. Others heavily determine outcomes. A risk score may be formally advisory but practically decisive because officials rarely depart from it. A public authority may claim human review while designing workflows that make disagreement unrealistic. Legal responsibility should look at actual institutional practice, not formal labels.
The duty to give reasons is especially important for state organs. A public authority cannot simply state that the system produced a score. It must explain the legal and factual basis for the decision in terms that the affected person can challenge. The more serious the rights impact, the stronger the need for explanation, disclosure, and independent review.
5.3 Private actors exercising public functions
AI governance often involves private actors performing functions close to public authority. Private companies may operate biometric databases, analyse border data, provide welfare fraud tools, manage prison technologies, support policing, run content moderation under state pressure, or supply military analytics. Attribution then becomes more complex.
Article 5 of the ILC Articles provides that the conduct of a person or entity empowered by domestic law to exercise elements of governmental authority is attributable to the state when the entity acts in that capacity (International Law Commission, 2001). This provision is directly relevant to outsourced AI systems. If a private company is legally empowered to perform a public function, its conduct may be attributable when it exercises that authority.
The key question is not whether the actor is formally private. It is whether the actor exercises governmental authority. A company that merely sells software may not fall under Article 5. A company that makes eligibility determinations, operates a public enforcement database, conducts delegated identity checks, or performs legally significant assessments on behalf of the state may be closer to the line.
Article 8 addresses conduct under the instructions, direction, or control of the state (International Law Commission, 2001). This may apply where a state directs a private technology company to carry out specific operations. The threshold is demanding. The ICJ has applied an effective control standard in the context of attribution for conduct of non-state actors (ICJ, 1986; ICJ, 2007). A looser standard would risk attributing too much private conduct to states. AI analysis must avoid that overreach.
Still, direction and control are not impossible to prove. A state may instruct a vendor to build a system for a specific enforcement purpose, define the target categories, supply the data, approve the model, direct its use, and control the outputs. In such a case, the private actor’s technical role may form part of a state-controlled operation. Attribution will depend on the facts.
There is also a separate duty to protect. Even when private conduct is not attributable to the state, the state may breach its own obligations by failing to regulate, prevent, investigate, or remedy foreseeable harm. This distinction is vital. Not every harmful act by an AI company is a state act. Yet a state may still be internationally responsible for its own failure to exercise due diligence.
A practical example can clarify the distinction. A private employer uses an automated hiring tool that discriminates against women. The conduct may not be attributable to the state. Yet the state may breach equality obligations if it has no adequate legal framework, supervisory body, complaint mechanism, or remedy for discriminatory hiring technologies. The primary wrong is then the state’s failure to protect, not the company’s conduct as such.
In public-sector outsourcing, the analysis may be stronger. If a state welfare agency adopts a vendor’s fraud detection system and uses it to suspend benefits, the final administrative decision is attributable to the state. The vendor’s role may also create contractual, domestic, or business responsibility. International responsibility attaches to the state because the public authority used the system to affect rights.
5.4 Shared responsibility and causal uncertainty
AI harms frequently involve multiple actors. A model developer builds the system. A data broker supplies training data. A cloud provider hosts the infrastructure. A public agency defines the use case. A contractor integrates the tool. Frontline officials rely on outputs. Regulators fail to supervise. Affected persons suffer the consequences. Traditional legal analysis often searches for one responsible actor, but AI supply chains may produce shared responsibility.
Shared responsibility is difficult in international law because attribution rules are actor-specific. A state is responsible for its own internationally wrongful conduct. An international organisation may be responsible for its conduct. A company may bear responsibility under domestic law, contract, regulation, or business and human rights standards. These regimes do not always align neatly.
The law of state responsibility can still address part of the problem. States may aid or assist another state in the commission of an internationally wrongful act if the conditions of Article 16 of the ILC Articles are met, including knowledge and the wrongful character of the assisted conduct (International Law Commission, 2001). In AI contexts, this may become relevant where a state knowingly supplies surveillance, cyber, or military AI capabilities to another state for unlawful use. The threshold is high, but the concept is important.
States may also incur responsibility through cooperation in internationally wrongful conduct, coercion, or failure to comply with obligations owed to the international community. These rules should be used cautiously. The stronger path will often be direct: a state is responsible for its own procurement, deployment, authorisation, failure to regulate, or failure to remedy.
Causal uncertainty is a major practical obstacle. AI systems may operate through statistical correlations that are difficult to explain. A harmful outcome may result from several interacting factors: data bias, model design, institutional reliance, poor training, lack of review, and policy pressure. Legal systems should not demand impossible proof from affected persons who lack access to the system. Burdens of proof, disclosure duties, audit logs, and presumptions may need adjustment in domestic implementation.
International law already recognises that complex causation does not always defeat responsibility. Environmental harm, armed conflict, mass surveillance, and structural discrimination often involve multiple causes. AI should be approached with the same seriousness. Where a state deploys a system that foreseeably creates a high risk of rights violations and fails to maintain safeguards, responsibility may arise even if each output cannot be fully reconstructed.
Reparation must also reflect the type of harm. Monetary compensation may be necessary but insufficient. AI-related reparation may require correction of records, deletion of unlawful data, restoration of benefits, reopening of procedures, public disclosure, institutional reform, audit, guarantees of non-repetition, and termination of the system. Where a model has affected a large group, collective remedies may be needed.
The key point is simple: automation does not dissolve responsibility. It changes the evidentiary path through which responsibility is established. States that choose to govern through AI must preserve the information needed to prove legality. If they deploy systems that cannot be audited, explained, or challenged, they create the conditions for their own responsibility.
6. International Organisations and AI
6.1 UN system use of AI
International organisations are not peripheral actors in AI governance. They collect data, coordinate humanitarian action, support development programmes, monitor human rights, advise governments, assist migration management, administer sanctions lists, and operate in conflict-affected settings. Their use of AI raises a distinct problem: international organisations often act in places where affected persons have weak access to courts, limited political voice, and little control over how their data is processed.
The United Nations system has recognised that AI may support public-interest goals but also deepen inequality and create rights risks. Its principles for ethical AI require consistency with the UN Charter, applicable international human rights law, privacy, human dignity, equality, cultural diversity, data responsibility, safety, and lifecycle assessment (United Nations System, 2022). This is important because the UN cannot credibly promote rights-based AI governance while applying lower safeguards to its own operations.
AI can assist UN bodies in several legitimate ways. Humanitarian agencies may use predictive analytics to identify food insecurity, displacement risk, or disease spread. Human rights mechanisms may use machine learning to sort large volumes of open-source material, satellite imagery, or documentation of abuses. Development agencies may use data systems to improve access to education, health, and public services. Translation tools can expand participation in multilingual settings. These uses may improve institutional capacity where human resources are limited.
The legal risk is that operational urgency can weaken safeguards. Humanitarian and development contexts often involve vulnerable populations: refugees, internally displaced persons, stateless persons, children, communities under occupation, disaster-affected groups, and persons living under authoritarian control. Data collected for assistance may later become attractive to security agencies, migration authorities, armed groups, or hostile political actors. The ethical problem is not abstract. A biometric registration system used to distribute aid may expose people to surveillance or exclusion if governance fails.
UN entities must also avoid treating AI outputs as neutral facts. A predictive model for displacement may reflect incomplete data. Satellite analysis may miss local context. A translation tool may distort testimony. A risk model may classify communities based on proxies that reproduce ethnic, religious, gender, or migration-based vulnerability. The institutional authority of the UN can give technical outputs a credibility they do not always deserve.
The lifecycle approach is essential for international organisations. Before adopting an AI tool, the organisation should establish the legal mandate, purpose, necessity, rights and risks, data safeguards, affected-community engagement, review process, and remedy route. During deployment, it should monitor errors, bias, misuse, security risk, and unexpected effects. At the end of use, it should address data deletion, archiving, transfer, and future access. A tool that is safe at collection may become dangerous if stored indefinitely.
The UN’s own principles correctly require AI systems to avoid causing or contributing to harm and to respect, protect, and promote human rights across the system lifecycle (United Nations System, 2022). That requirement should not remain an internal policy slogan. It should shape procurement, programme design, staff training, vendor contracts, data-sharing agreements, and complaint mechanisms.
6.2 Institutional responsibility
International organisations possess legal personality where their functions require it. The International Court of Justice recognised the international personality of the United Nations in the Reparation for Injuries advisory opinion, explaining that the organisation has rights and duties under international law necessary for the performance of its functions (ICJ, 1949). That personality brings capacity, but it also raises responsibility.
The International Law Commission’s Articles on the Responsibility of International Organizations provide the basic framework. An internationally wrongful act of an international organisation exists where conduct is attributable to the organisation and breaches an international obligation binding on it (International Law Commission, 2011). The structure resembles state responsibility, but the institutional context is different. International organisations act through organs, agents, member-state cooperation, implementing partners, contractors, and field missions.
AI complicates attribution. A UN agency may procure a vendor system. A private contractor may maintain the database. A host state may provide data. A partner NGO may collect information. A peace operation may use analytics provided by another entity. If harm occurs, the affected person may face a maze of actors. The organisation may point to the contractor. The contractor may point to the data provider. The host state may point to the UN mandate. Legal analysis must identify who controlled the relevant decision and which obligation was breached.
Institutional responsibility is especially important where international organisations exercise public-like authority. They may screen individuals for assistance, administer camps, support detention alternatives, maintain beneficiary databases, coordinate returns, assist border systems, or provide technical advice that shapes domestic policy. These activities can affect rights even when the organisation does not formally govern territory.
Privileges and immunities create a further difficulty. International organisations enjoy immunities to protect their independent functions. Those immunities are not designed to create impunity. The European Court of Human Rights has linked the legitimacy of organisational immunity to the availability of reasonable alternative means of protecting rights in some contexts (ECtHR, 1999). The precise legal position varies across organisations and instruments, but the underlying accountability concern is clear.
AI increases that concern because harm may be invisible. A person may be excluded from aid because of a data error. A family may be classified as lower priority by an opaque vulnerability model. A refugee may be exposed through weak data-sharing. A community may be mischaracterised by remote analysis. If immunity blocks domestic claims and the organisation provides no internal remedy, the person may have no effective route to challenge the harm.
Institutional responsibility should require more than internal review by the same unit that deployed the system. Serious AI use by international organisations should include independent oversight, documentation, affected-person complaint procedures, data protection officers, audit capacity, and remedy mechanisms. The stronger the rights impact, the stronger the procedural safeguards must be.
Member states also matter. International organisations are not free-floating machines. They are created, funded, governed, and sometimes directed by states. Member states should not use an organisation to carry out AI-assisted conduct they could not lawfully perform themselves. Nor should they design mandates or funding arrangements that encourage data extraction, surveillance, or exclusion without safeguards. The ILC Articles recognise rules on aid, assistance, direction, control, coercion, and circumvention involving international organisations, although application depends on demanding factual and legal thresholds (International Law Commission, 2011).
The central point is that international organisations must be treated as legal actors, not only ethical coordinators. When they deploy AI, they must preserve the conditions of legality: mandate, purpose limitation, rights assessment, data security, review, explanation, and remedy.
6.3 Human rights due diligence in operations
Human rights due diligence should become the operational method for AI use by international organisations. It is not enough to rely on broad mandates, public-interest objectives, or technical vendor assurances. Due diligence requires a structured assessment of foreseeable harm and reasonable preventive action.
The first step is mandate review. An international organisation should ask whether it has the authority to collect the data, build the system, share the outputs, and act on the results. Mandate language should not be stretched simply because AI creates a new technical possibility. If the legal mandate concerns humanitarian assistance, data collected under that mandate should not be repurposed for enforcement, intelligence, or migration control without a separate legal basis and rights assessment.
The second step is affected-population analysis. Many persons interacting with international organisations cannot meaningfully refuse data collection. A refugee seeking food assistance, a displaced family registering for shelter, or a disaster-affected person requesting medical support may face practical coercion. Consent in such settings is often formal rather than free. Due diligence must account for vulnerability, dependency, language barriers, trauma, documentation gaps, and fear of authorities.
The third step is data protection. AI systems require careful control over collection, retention, access, transfer, and deletion. Sensitive humanitarian data should not become a permanent asset. Data-sharing agreements must define purpose, access rights, security measures, retention periods, and prohibitions on secondary use. Biometric data requires special caution because it cannot be replaced if compromised.
The fourth step is human review. International organisations should not make rights-affecting decisions through AI without meaningful human assessment. Human review must be trained, documented, and empowered. If staff simply accept the model output because they lack time or technical understanding, oversight is fictional.
The fifth step is the remedy. Affected persons need accessible ways to correct data, challenge classification, request explanations, and complain about harm. These mechanisms must be realistic for people with limited literacy, unstable internet access, fear of retaliation, or language barriers. A digital complaint portal alone will not be adequate in many field settings.
A final step concerns exit and transfer. International organisations often leave operations, hand systems to governments, or shift data to implementing partners. This moment is legally sensitive. A database created under international safeguards may be transferred to a state with weaker protections. AI tools used for humanitarian coordination may later support surveillance or exclusion. Responsible exit planning should be part of the original design.
Institutional immunity cannot justify weak remedies. If domestic courts are unavailable because of immunity, the organisation has a stronger duty to provide credible internal or independent mechanisms. Without such mechanisms, rights-based AI governance becomes hollow exactly where vulnerable persons most need protection.
7. Human Rights Affected by AI Systems
7.1 Dignity and human agency
Human dignity is not a decorative principle in AI governance. It protects the status of persons as legal and moral agents. AI systems threaten dignity when they reduce individuals to objects of prediction, suspicion, classification, or control without allowing them to understand, contest, or influence decisions that affect their lives.
This risk is visible in public administration. A person may be assigned a fraud risk score, a policing risk category, a migration risk profile, or an employability score. The classification may follow them across agencies. Officials may treat the score as objective. The person may never know how the label was created. Such systems can quietly alter the relationship between the individual and the authority. The person becomes a data subject in the weakest meaning of the term: a subject acted upon by data systems rather than a rights-holder capable of challenge.
Human agency requires more than keeping a human somewhere in the process. A nominal human reviewer does not protect dignity if the reviewer lacks time, training, information, or authority. Human agency requires that affected persons can understand the substance of the decision, present their case, correct errors, and receive a reasoned response.
The legal significance is practical. Dignity supports rights to personality, equality, due process, privacy, and remedy. It also limits systems that treat persons merely as instruments for administrative efficiency. A welfare agency may seek to reduce fraud. A border authority may seek to manage risk. A court may seek consistency in sentencing or bail. Those aims cannot erase the person’s right to be treated as a participant in the legal process, not merely as a variable inside a model.
Children, persons with disabilities, migrants, and detained persons require particular care. AI systems may assess behaviour, learning patterns, credibility, risk, or compliance. The danger is that institutional convenience replaces individual assessment. A child’s educational future should not be shaped by opaque proctoring or allocation tools without safeguards. A person with a disability should not be excluded because the system was designed around a narrow model of ordinary behaviour. A migrant’s credibility should not be undermined by tools unable to account for trauma, translation, or documentation loss.
Dignity also restricts manipulation. Generative AI, recommender systems, and behavioural profiling can influence choices without clear awareness. In political, commercial, or administrative contexts, manipulation may weaken autonomy by steering persons through hidden inferences. Human rights law does not prohibit all persuasion, but it does require attention to coercion, vulnerability, deception, and unequal power.
7.2 Equality and non-discrimination
AI discrimination often arises without explicit discriminatory intent. This makes it legally dangerous. A system may never mention race, sex, disability, religion, nationality, caste, age, or migration status. It may still rely on variables that operate as proxies. Address, education history, employment gaps, device use, language patterns, social networks, financial records, and prior contact with public authorities can reproduce a protected or socially vulnerable status.
International human rights law prohibits discrimination in the enjoyment of rights. The ICCPR protects equality before the law and equal protection without discrimination (United Nations, 1966a). The ICESCR requires rights to be exercised without discrimination (United Nations, 1966b). CERD, CEDAW, CRC, and CRPD deepen this framework for racial discrimination, discrimination against women, children’s rights, and disability rights (United Nations, 1965; United Nations, 1979; United Nations, 1989; United Nations, 2006).
Algorithmic discrimination can occur through biased data. If historical policing concentrated on minority neighbourhoods, predictive policing tools may direct more patrols there. More patrols produce more recorded incidents, which then confirm the model’s assumption. The system appears empirical but is partly learning the history of state attention.
It can occur through unequal error rates. A facial recognition system may misidentify some groups more often than others. A speech recognition system may perform poorly for accents, dialects, or minority languages. A hiring model may penalise career interruptions associated with pregnancy, caregiving, illness, or migration. A welfare model may treat unstable housing or irregular employment as suspicion rather than poverty.
It can also occur through exclusion by design. A digital identity system may assume stable documentation. An education platform may assume reliable internet, quiet rooms, or standard devices. A health triage system may not account for disability-related communication needs. A legal information chatbot may perform poorly in less-represented languages. These are not minor usability issues when they affect access to rights.
The legal analysis should examine effects, not only intent. Fredman’s substantive equality approach is useful here because equality requires attention to disadvantage, stigma, participation, and structural barriers, not only identical treatment (Fredman, 2016). A formally neutral model may be unlawful if it reinforces exclusion or denies equal access to protected interests.
Impact assessment should include affected groups. Technical teams may miss discriminatory effects because they do not know the social context. A model used in housing, welfare, policing, migration, or employment should be tested with attention to local patterns of inequality. Statistical review must be combined with legal and social analysis.
Non-discrimination also requires remedies. Affected persons should not bear the impossible burden of proving the internal logic of a system they cannot access. Regulators and courts may need disclosure orders, audit powers, reversed or adjusted burdens of proof, and collective complaint mechanisms. Without such tools, equality protection may fail at the evidentiary stage.
7.3 Privacy and data protection
AI intensifies privacy risks because it does not merely store information. It generates inferences. It connects data across contexts. It predicts behaviour. It can identify patterns that individuals did not disclose and could not reasonably anticipate. Privacy law focused only on collection is too narrow for AI.
Article 17 of the ICCPR protects against arbitrary or unlawful interference with privacy, family, home, or correspondence (United Nations, 1966a). The Human Rights Committee has interpreted privacy broadly, requiring legal safeguards against arbitrary interference and protection against unlawful attacks (Human Rights Committee, 1988). AI systems can interfere with privacy through surveillance, profiling, biometric identification, location tracking, communications analysis, predictive analytics, and data linkage.
Biometric systems are particularly sensitive. Facial images, fingerprints, iris scans, voiceprints, and gait patterns connect identity to the body. If compromised, they cannot be changed like a password. Biometric identification in public spaces can also affect assembly, expression, and political participation. People may avoid protests, religious gatherings, clinics, or community meetings if they believe they are being identified and recorded.
Inference is another major risk. A system may infer political views, health status, sexuality, religion, emotional state, creditworthiness, or migration intentions from ordinary data points. The person may not know that the inference exists. They may not know how it is used. They may not be able to correct it. Privacy harm then arises through prediction, not only exposure.
Data linkage creates further dangers. Information collected for one purpose may be combined with other databases and used for another. Health data may become an insurance risk. Welfare data may raise suspicion of fraud. School data may become policing intelligence. Humanitarian data may become migration enforcement. Purpose limitation is a core safeguard because data becomes more dangerous when contexts collapse.
Consent is often inadequate. Individuals may click agreement boxes without understanding the system. They may depend on a public service. They may have no realistic alternative to a dominant platform. They may face language barriers or urgency. In humanitarian and migration contexts, consent may be particularly fragile because people may fear losing assistance or protection.
Data protection should be linked to legality, necessity, proportionality, security, minimisation, access, correction, deletion, and independent supervision. The mere existence of a privacy notice is not enough. A rights-based system must limit what is collected, explain why it is needed, protect it against misuse, and delete it when the purpose ends.
AI also raises collective privacy concerns. A model trained on community data may expose patterns about a group even if individuals are anonymised. Indigenous data, minority language data, refugee databases, and community health data may carry collective meaning. International law has not fully developed a collective privacy doctrine, but human rights analysis should not ignore the group dimension of data harm.
7.4 Expression, information, and public debate
AI affects freedom of expression in contradictory ways. It can expand expression through translation, accessibility tools, content discovery, and documentation of abuses. It can also suppress, distort, or manipulate public debate through automated moderation, recommender systems, synthetic media, bot networks, and state-linked information operations.
Article 19 of the ICCPR protects the right to hold opinions without interference and the right to seek, receive, and impart information and ideas (United Nations, 1966a). Restrictions on expression must be provided by law and necessary for respect of the rights or reputations of others, national security, public order, public health, or morals. AI does not alter that structure. It changes the factual mechanisms through which speech is amplified, restricted, or manipulated.
Content moderation illustrates the difficulty. Platforms use automated tools to detect terrorism-related content, hate speech, child sexual abuse material, misinformation, copyright violations, and violent imagery. Some automation is necessary at scale. Yet automated moderation may remove lawful speech, journalistic material, satire, human rights documentation, minority language content, or evidence of war crimes. Errors may disproportionately affect communities already underrepresented in training data.
Recommender systems raise a different issue. They do not only remove content. They organise visibility. A system that prioritises engagement may amplify outrage, harassment, extremist material, or disinformation. A system that downranks political content may reduce visibility for civil society or opposition groups. The legal problem is not easily captured by traditional censorship categories because the state may not directly order removal. Still, public debate can be shaped through opaque private architecture.
Generative AI deepens the challenge. Synthetic text, images, audio, and video can produce convincing falsehoods at scale. Deepfakes may target political candidates, journalists, women, minorities, or conflict victims. Automated propaganda may distort democratic processes. Yet overbroad regulation of synthetic content can become a tool for suppressing legitimate speech. Rights-based governance must address manipulation without granting governments broad censorship powers.
Access to information is also affected. AI tools used by public authorities may help citizens understand legal rights, translate documents, or navigate procedures. If poorly designed, they may provide inaccurate information that causes missed deadlines, defective applications, or legal disadvantage. Where public bodies provide AI-based legal or administrative guidance, disclaimers cannot fully erase responsibility if the tool becomes part of the official service environment.
Human rights law requires a careful balance. States should regulate AI-enabled harms to expression, including targeted harassment, synthetic deception, and incitement, but restrictions must be lawful, necessary, proportionate, and subject to independent oversight. Platforms should provide notice, reasons, appeal, and transparency around automated moderation. Public authorities should not pressure companies into informal censorship that avoids judicial or legislative control.
7.5 Due process and fair procedure
Due process is where many AI systems will be judged. Automated decision-making often affects people through ordinary administration: benefits, immigration, taxation, education, policing, employment, sanctions screening, and public services. The decision may not look dramatic, but its consequences can be serious.
Fair procedure requires notice. A person should know when AI has materially influenced a decision affecting rights or important interests. This does not mean every minor software tool must be disclosed in detail. It means that where automated analysis shapes the outcome, the affected person should be told enough to understand the process.
Fair procedure also requires reasons. A public authority cannot simply say that a system produced a risk score. It must explain the factual and legal basis for the decision. If the model relies on categories, indicators, or evidence, the person must receive enough information to challenge errors. Black-box administration is incompatible with meaningful review.
Access to evidence is essential. If a person is denied asylum, selected for investigation, refused a public benefit, or placed on a watchlist because of automated analysis, they need access to the relevant material unless a specific and lawful limitation applies. Even in security contexts, secrecy must be controlled through independent mechanisms. Permanent reliance on undisclosed AI outputs undermines the right to challenge the decision.
Human review must be substantive. It should occur before serious harm, where possible, not only after damage has been done. The reviewer must understand the system’s limits and have the authority to change the outcome. A workflow in which the official sees only a score and a recommendation is not enough. Nor is a review meaningful if institutional pressure makes departure from the automated output rare or career-risking.
Appeal mechanisms must be independent and practical. Affected persons should not be required to prove technical flaws they cannot see. The reviewing body should have the power to order disclosure, correction, suspension, compensation, and systemic changes. In high-impact settings, regulators or courts should be able to inspect the system directly or through independent experts.
Fair trial rights raise additional concerns. AI may assist legal research, evidence review, risk assessment, sentencing analysis, bail recommendations, or case allocation. Some uses may improve efficiency. Others may undermine equality of arms, judicial independence, or reasoned adjudication. Judges should not rely on systems whose methodology cannot be tested by the parties. Criminal proceedings require especially strong safeguards because liberty and stigma are at stake.
Sanctions screening is another important area. Automated systems may identify persons or entities as potential matches on sanctions lists. False positives can restrict banking, travel, employment, or humanitarian access. Because sanctions often involve security secrecy and cross-border compliance pressure, affected persons may struggle to correct errors. AI-assisted sanctions processes need clear review and delisting pathways.
7.6 Economic and social rights
AI governance is often discussed through privacy and discrimination, but economic and social rights are equally important. AI systems are increasingly used in health care, education, housing, labour markets, social security, and public service delivery. These are not secondary legal interests. For many people, daily survival is determined.
The ICESCR requires states to take steps toward the realisation of rights to work, social security, family protection, an adequate standard of living, health, and education without discrimination (United Nations, 1966b). The Committee on Economic, Social and Cultural Rights has emphasised duties of non-discrimination, minimum essential levels, progressive realisation, and effective remedies (Committee on Economic, Social and Cultural Rights, 1990; Committee on Economic, Social and Cultural Rights, 2009).
AI may improve economic and social rights when used carefully. It can help identify health risks, allocate resources, translate services, detect unmet needs, reduce administrative delay, and support inclusive education. A health system may use AI to improve diagnostics. A social protection agency may use data analysis to identify eligible persons who are not receiving benefits. An education authority may use assistive tools for learners with disabilities. These uses should not be dismissed.
The risk is exclusion through automation. A social security system may wrongly flag vulnerable persons as fraudulent. A health triage tool may underdiagnose groups underrepresented in training data. A housing allocation system may reproduce segregation. An automated hiring tool may screen out older workers, disabled applicants, pregnant women, migrants, or persons with non-linear employment histories. An education platform may punish students who lack stable internet or quiet study spaces.
Digital access is a rights issue. If public services become AI-mediated and digital-only, persons without devices, connectivity, literacy, documentation, or accessible interfaces may be excluded. The state cannot satisfy economic and social rights by creating technically advanced systems that vulnerable groups cannot use. Accessibility must be part of design, not a later correction.
Resource constraints do not excuse careless automation. States may use technology to improve efficiency, but austerity cannot justify systems that arbitrarily deny essential support. Where AI is used to allocate scarce resources, the criteria must be lawful, transparent, non-discriminatory, and reviewable. A person denied health care, housing support, education access, or social protection must be able to understand and challenge the basis of the decision.
Economic and social rights also require attention to labour. AI-driven workplace monitoring, algorithmic management, automated scheduling, productivity scoring, and hiring systems can affect dignity, privacy, equality, freedom of association, and just conditions of work. International labour standards and human rights law should be read together in this field. The employer may be private, but the state has a duty to regulate workplace systems that foreseeably harm rights.
AI policy should not focus only on preventing abuse. It should also ask how AI can support rights fulfilment. Public-interest AI may assist health systems, climate adaptation, disability inclusion, language access, disaster response, and education. The legal condition is that deployment must be participatory, accountable, and rights-compatible. Innovation is valuable only when it strengthens, rather than weakens, legal protection.
8. Business Responsibility and AI Supply Chains
8.1 The UN Guiding Principles and AI
Private companies are central to AI. They build models, collect data, host infrastructure, sell analytics, moderate content, provide cloud services, design chips, operate platforms, and supply public authorities. Public international law traditionally binds states, but AI governance cannot be serious without addressing corporate responsibility.
The UN Guiding Principles on Business and Human Rights provide the main international framework. They rest on three pillars: the state's duty to protect human rights, the corporate responsibility to respect human rights, and access to remedy (UN Human Rights Council, 2011). The corporate responsibility to respect means that companies should avoid infringing on human rights and address adverse impacts with which they are involved.
The UN Guiding Principles are not a treaty. They do not create direct international legal obligations for companies in the same way human rights treaties bind states. Their authority comes through broad institutional acceptance, domestic incorporation, litigation, regulation, investor expectations, procurement rules, and corporate due diligence practice. For AI, they provide a practical framework because they focus on risk, leverage, business relationships, and remedies.
AI companies often frame responsibility in terms of product safety or acceptable use. That is too narrow. A model may be safe in a technical sense but harmful in a human rights sense. A surveillance tool may function as intended and still support repression. A language model may produce fluent content and still expose users to legal misinformation. A risk scoring system may be profitable and still discriminatory.
Human rights due diligence under the UN Guiding Principles requires companies to identify, prevent, mitigate, and account for how they address human rights impacts (UN Human Rights Council, 2011). For AI, this should cover the full lifecycle: data collection, labelling, model design, testing, deployment, updates, monitoring, downstream use, and termination. It should also cover business relationships, including customers, governments, vendors, data providers, and cloud partners.
Companies should pay particular attention to high-risk customers and contexts. Supplying biometric surveillance to an authority with a record of repression is not the same as supplying accessibility tools to a school system. Providing predictive analytics to law enforcement requires different safeguards than providing grammar correction software. Context matters because the same technical capability can support legitimate administration or serious rights abuse.
The corporate responsibility to respect also includes remedy. If a company causes or contributes to harm, it should provide or cooperate in remediation. If the harm is directly linked to its products or services through a business relationship, it should use leverage to prevent or mitigate the harm. A company cannot treat misuse as unforeseeable where the use case, customer, or political context made the risk obvious.
8.2 Developers, deployers, and leverage
AI supply chains involve different actors with different capacities. A serious legal analysis should not speak of “AI companies” as if all actors play the same role. Responsibility depends on function, knowledge, control, and leverage.
Developers create models, tools, or infrastructure. They may control training data, architecture, safety testing, documentation, and update cycles. They may not control every downstream use, especially for general-purpose systems. Yet they can foresee categories of risk, restrict certain uses, provide documentation, test for harms, monitor abuse, and design safeguards.
Deployers apply AI systems in concrete settings. A bank uses a credit model. A school uses proctoring software. A police department uses facial recognition. A hospital uses diagnostic support. A welfare agency uses fraud scoring. Deployers often understand the operational context better than developers. They control the purpose, affected population, human review, local safeguards, and remedy route.
Data brokers and data providers influence the system before deployment. They collect, clean, aggregate, and sell data. Their practices may determine whether the system rests on lawful, accurate, representative, and rights-respecting information. Poor data governance can create harm even if the model is technically sophisticated.
Cloud providers and infrastructure companies may not design the final application, but they can hold leverage where their services enable high-risk systems. Their responsibility depends on knowledge, contractual power, technical control, and the severity of the risk. A cloud provider need not monitor every ordinary customer as if it were a regulator, but it should not ignore credible evidence that its infrastructure supports serious human rights abuse.
Public-sector clients are especially important. When companies sell AI to governments, the risk profile changes. Tools used in policing, border control, welfare, taxation, education, surveillance, detention, or military operations can affect rights directly. Vendors should expect higher documentation, audit, explanation, and contractual safeguards in public-sector deployments.
Leverage is central under the UN Guiding Principles. A company may not control a government customer, but it may have contractual rights, technical update power, termination clauses, training obligations, or the ability to suspend services. The company should use that leverage where serious human rights risks arise. If leverage is absent, it should consider increasing leverage or ending the relationship in severe cases (UN Human Rights Council, 2011).
General-purpose AI creates harder questions. Developers may not know every downstream application. Still, they can identify foreseeable categories of misuse: fraud, impersonation, disinformation, cyber abuse, harassment, unlawful surveillance, biological or chemical risk, and discrimination. The broader the system’s capability and distribution, the stronger the need for staged release, monitoring, use restrictions, documentation, and incident response.
Responsibility should track capacity. A small application developer does not have the same resources as a major platform or foundation model provider. Yet limited resources do not excuse reckless deployment in high-risk settings. A company that cannot test, explain, or monitor a system should not sell it for rights-affecting use.
8.3 Corporate due diligence
Corporate AI due diligence should begin before design choices are locked in. Many harms arise because companies optimise for speed, engagement, cost reduction, or predictive power without asking which rights may be affected. A late-stage ethics review rarely fixes a system built on the wrong assumptions.
The first element is a human rights impact assessment. Companies should identify affected rights, vulnerable groups, foreseeable misuse, severity of harm, and the institutional context of deployment. The assessment should not be a generic checklist. A hiring tool, a border analytics system, a medical diagnostic tool, and a content recommender raise different legal risks.
The second element is data governance. Companies should assess data provenance, legality of collection, representativeness, quality, labelling conditions, privacy risk, and group harm. Data scraped or purchased at scale may carry legal and ethical defects. Labour conditions in data labelling also matter. Workers who review violent, sexual, or traumatic material may face psychological harm and should receive protection.
The third element is testing. Pre-deployment testing should include bias evaluation, robustness, security, explainability, misuse potential, and context-specific performance. Testing should not be limited to average accuracy. It should examine subgroup error rates, worst-case scenarios, and real-world use. Independent evaluation is especially important for high-risk systems.
The fourth element is stakeholder engagement. Affected communities, workers, public-interest groups, technical experts, equality bodies, and domain specialists can identify risks that internal teams miss. Consultation should not be performative. It should influence design, deployment, and safeguards.
The fifth element is documentation. Companies should provide deployers and regulators with information about system's purpose, limitations, data, testing, appropriate use, prohibited use, monitoring, and known risks. Documentation does not require full public disclosure of every technical detail, but it must be meaningful enough to support legal compliance.
The sixth element is monitoring after deployment. AI systems can fail after launch because context changes, users adapt, data drifts, or the system is repurposed. Companies should maintain incident reporting, abuse detection, update controls, and channels for affected persons or public authorities to raise concerns.
The seventh element is remediation. Where the company causes or contributes to harm, remediation may include correction, compensation, service suspension, model withdrawal, deletion of data, public explanation, technical repair, or cooperation with independent investigations. Remedy should not be reduced to customer support.
Corporate due diligence must also address the business model. Some harms arise not because one model is flawed but because the business incentive rewards surveillance, addiction, manipulation, or discriminatory targeting. Engagement optimisation can amplify harmful content. Advertising models can encourage intrusive profiling. Labour platforms can use algorithmic management to intensify control over workers. A narrow technical audit will not solve a rights problem built into the revenue structure.
8.4 Trade secrecy and accountability
Trade secrecy is one of the most common barriers to AI accountability. Companies may argue that model architecture, training data, weights, decision logic, or validation methods are proprietary. Intellectual property and trade secrets deserve legal protection in appropriate settings. They do not justify complete opacity where rights are affected.
The issue is not that every source code file must be public. The issue is that affected persons, regulators, courts, auditors, and public authorities need enough information to assess legality. A person denied a public benefit cannot challenge the decision if the decisive factors are hidden. A regulator cannot assess discrimination if error rates are unavailable. A court cannot review proportionality if the state cannot explain how the system works.
Different levels of disclosure may be appropriate. Public transparency may include system purpose, use context, rights impact assessment, general logic, safeguards, and complaint routes. Regulator disclosure may include technical documentation, testing results, data information, and audit logs. Court-supervised disclosure may protect commercial confidentiality while allowing parties to challenge evidence. Independent auditors may inspect sensitive material under confidentiality obligations.
Trade secrecy is especially weak as a defence where a company sells to public authorities. Public power must remain reviewable. A vendor that wants to provide rights-affecting systems to the government should accept stronger disclosure and audit duties. If the vendor refuses, the public authority should not procure the system.
Opacity also affects procurement. Public agencies may become dependent on systems they do not understand. They may accept vendor accuracy claims without independent validation. They may be unable to explain decisions to affected persons. They may find it costly to terminate contracts. Rights-based procurement should address these risks before adoption.
There is a broader democratic concern. AI systems used in policing, welfare, migration, education, and courts can shape public authority. If their logic is shielded entirely by private law, democratic oversight is weakened. Public functions cannot be governed through secret technical systems controlled by vendors.
Accountability does not require hostility to innovation. It requires conditions under which innovation can be trusted because it is contestable. Companies that build high-risk AI systems should expect documentation, audit, impact assessment, and remedy obligations. Secrecy may protect legitimate commercial interests, but it cannot become a licence to govern people without explanation.
9. AI in Human Rights Practice
9.1 Monitoring and evidence gathering
AI is not only a source of human rights risk. It can also support human rights protection. International organisations, NGOs, journalists, prosecutors, and investigators increasingly use digital tools to collect, sort, translate, compare, and analyse large volumes of material. Satellite imagery, open-source videos, social media posts, audio files, battlefield images, refugee movement data, and environmental records may all help document violations.
The value is practical. Human rights investigators often face a scarcity of time, language capacity, security access, and field presence. AI-assisted tools can identify damaged villages, detect mass graves, compare before-and-after satellite images, track forced displacement, classify large datasets, and translate victim testimony. Dulka shows how AI has already been used in human rights work, including satellite-based analysis of village destruction, displacement forecasting, media monitoring, deforestation tracking, and analysis of online abuse against women (Dulka, 2023).
This can strengthen accountability. Atrocity crimes and systematic human rights violations often leave scattered traces. A village burned in one district, a convoy movement in another, a set of online threats, a pattern of arrests, and a sudden displacement flow may look disconnected when viewed separately. AI can help identify patterns that deserve human investigation. It can support early warning and help investigators allocate limited resources.
The legal value of AI-assisted evidence depends on reliability. A model that detects destroyed buildings is not a witness. It is an analytical tool. Its output must be verified, contextualised, and connected to other evidence. A satellite image may show destruction, but not always the perpetrator, intent, timing, or legal classification. A social media classifier may identify hate speech patterns, but legal analysis still requires context, speaker identity, audience, intent, likelihood of harm, and the applicable legal threshold.
AI should assist legal judgment, not replace it. Human rights law and international criminal law depend on standards of proof, attribution, intent, causation, and protected status. These cannot be reduced to pattern recognition. A model may help identify a possible attack on civilians, but lawyers and investigators must still assess distinction, proportionality, command structures, witness testimony, and the chain connecting conduct to responsible actors.
AI also changes the scale of documentation. Large-scale analysis can reveal patterns invisible to manual review. At the same time, scale can create false confidence. A large dataset may be incomplete, biased toward digitally visible populations, or shaped by platform access. Communities with low connectivity, restricted internet, or fear of online posting may disappear from the evidence. A sophisticated model trained on incomplete data can produce a polished but distorted picture.
The best approach is triangulation. AI-assisted findings should be checked against independent sources: witness interviews, forensic analysis, satellite metadata, official documents, field reports, intercepted communications where lawfully obtained, medical records, and expert assessment. The more serious the allegation, the stronger the corroboration required.
9.2 Verification and evidentiary reliability
Verification is the central safeguard for AI in human rights practice. Digital evidence can be powerful, but it is vulnerable to manipulation, misclassification, missing context, and overinterpretation. Generative AI deepens the problem because synthetic images, audio, and video may be created at low cost and distributed rapidly.
Authentication should begin with provenance. Investigators need to know where the material came from, who collected it, when it was captured, how it was stored, and how it was altered, if at all. Metadata may help, but metadata can be missing, stripped, or manipulated. Platform timestamps may not correspond to the time of the original event. Reposted material may be mistaken for new evidence.
Chain of custody matters. If AI-assisted evidence may later support litigation, sanctions, asylum decisions, or international criminal proceedings, investigators must preserve the path of the evidence. Each transfer, storage decision, analytical step, and modification should be recorded. A court or tribunal will need to understand not only the final output but the process that produced it.
Methodology must also be disclosed to the extent compatible with security and witness protection. A human rights report that relies on AI-assisted image classification should explain the tool, the criteria, the validation method, the error limits, and the role of human review. If the method cannot be explained, its weight should be limited. Technical sophistication is not a substitute for evidentiary transparency.
False positives can harm people. A system may wrongly identify a village as destroyed, a person as a combatant, an account as extremist, or a video as fabricated. In public reporting, such errors can damage credibility and expose individuals to retaliation. In legal proceedings, they may affect liberty, asylum, sanctions, or reputation. Verification protects both accuracy and fairness.
False negatives also matter. AI may fail to identify violations where data is scarce, images are poor, languages are underrepresented, or perpetrators deliberately avoid digital traces. A model’s silence should not be read as the absence of harm. Human rights violations often occur in places where documentation is hardest.
Human review should be specialised. It is not enough for a general user to inspect AI outputs casually. Investigators need expertise in the region, conflict dynamics, language, legal classification, digital forensics, and the limits of the tool. A model may detect a building, but only contextual expertise can assess whether it was a school, military site, hospital, shelter, or civilian home.
The evidentiary lesson is direct. AI can improve human rights practice when it is used as a disciplined investigative aid. It can damage accountability when outputs are treated as legal conclusions.
9.3 Reporting and institutional credibility
Human rights reporting depends on credibility. Reports by UN bodies, commissions of inquiry, NGOs, national human rights institutions, journalists, and academic teams may influence sanctions, asylum decisions, litigation, diplomatic pressure, and public memory. AI can support reporting, but it can also weaken trust if used carelessly.
AI-assisted drafting creates obvious risks. A generative system may summarise documents, translate testimony, identify themes, or propose report structures. These functions can save time. They can also introduce errors, fabricate sources, flatten nuance, or alter the meaning of testimony. A human rights report that includes inaccurate AI-generated material can harm victims and damage institutional authority.
The problem is sharper where reports concern contested facts. States accused of violations often attack methodology. If an institution cannot explain how AI was used, how outputs were verified, and how errors were corrected, it gives hostile actors an easy line of attack. Credibility requires transparency about process, not only confidence in conclusions.
AI may also influence prioritisation. If a monitoring body uses automated tools to identify urgent cases, those tools may shape which violations receive attention. Digitally visible abuses may rise in priority. Abuses affecting offline communities may receive less attention. This can distort institutional focus. The legal and moral importance of a violation should not depend on how easily it can be detected by a model.
Translation tools need special caution. They can expand access across languages, which is valuable in international practice. Yet testimony about torture, sexual violence, displacement, persecution, or political opinion may depend on nuance. A mistranslation can change the meaning. Human review by qualified translators remains essential for sensitive material.
AI can help protect staff. Human rights workers who review violent images, torture videos, sexual abuse material, and hate campaigns may suffer psychological harm. AI can filter, prioritise, blur, or cluster material to reduce direct exposure. Dulka notes that AI may help mitigate trauma exposure for human rights workers reviewing large volumes of distressing content (Dulka, 2023). This is a legitimate institutional benefit, provided it does not weaken verification.
Disclosure should be proportionate. Institutions need not reveal details that endanger witnesses, sources, or investigative methods. They should still provide enough information for readers to assess reliability. A short methodology section explaining AI use, human review, verification, and limitations may be necessary where AI materially influenced findings.
Human rights institutions should adopt internal rules on AI-assisted reporting. These rules should cover permissible uses, prohibited uses, source verification, citation control, translation review, data security, witness protection, recordkeeping, and accountability for errors. Informal experimentation is not acceptable where reports may affect rights, reputations, sanctions, or criminal investigations.
9.4 Protection of victims and investigators
AI can expose the very people human rights work is meant to protect. Victims, witnesses, activists, journalists, humanitarian workers, and investigators may be identified through data linkage, facial recognition, voice recognition, geolocation, metadata, or careless publication. Protection must be built into AI-assisted human rights work.
Witness safety is the first concern. A video uploaded to document abuse may reveal faces, locations, licence plates, voices, family links, or community affiliations. AI tools can make identification easier. A hostile government or armed group may use facial recognition to identify protesters, detainees, or witnesses. Publication decisions must account for this risk.
Anonymisation is not always enough. Data that appears anonymised may be re-identified when combined with other datasets. A unique movement pattern, rare dialect, medical condition, or family structure may reveal identity. AI increases re-identification risk because it can detect patterns humans might miss. Sensitive human rights data should be minimised, secured, and shared only under strict controls.
Victims should not lose agency over their own stories. AI-assisted documentation can turn testimony into data points. This may be useful for pattern analysis, but it risks detaching evidence from lived experience. Informed participation, trauma-sensitive methods, and respect for witness preferences remain essential.
Investigators also need protection. Digital human rights work can expose investigators to hacking, doxing, harassment, surveillance, and psychological trauma. AI tools may help manage volume, but they also create new attack surfaces. Secure systems, access controls, staff training, and incident response are part of the legal and ethical infrastructure.
Data retention is a neglected issue. Human rights organisations may keep archives for future accountability. Long retention can be valuable where prosecutions occur years later. It can also endanger victims if systems are breached or political conditions change. Retention decisions should balance accountability, consent, security, and foreseeable misuse.
Humanitarian and human rights databases should not be repurposed casually. Information collected to support victims should not become an intelligence resource, migration control tool, or political database. Purpose limitation is central to trust. If communities believe that documentation exposes them to future harm, they may stop cooperating with investigators.
AI can strengthen protection only when it is used with restraint. Tools that blur faces, detect identifying information, manage access, and reduce staff exposure can be valuable. Tools that expand surveillance, centralise sensitive data, or enable uncontrolled sharing can be dangerous. The difference lies in governance.
10. Armed Conflict and Autonomous Systems
10.1 AI under humanitarian law
AI-enabled military systems are governed by existing international humanitarian law. There is no legal gap simply because a weapon or decision-support system uses machine learning, sensor fusion, autonomy, or predictive analytics. The core rules remain distinction, proportionality, precautions in attack, military necessity, humanity, and the prohibition of weapons that are indiscriminate by nature (ICRC, 2019; Sassòli, 2019).
The first legal question is classification. AI may be used in weapons, targeting support, intelligence analysis, logistics, surveillance, cyber operations, air defence, naval systems, drones, and command-and-control. Not every military AI system is an autonomous weapon. A legal analysis must identify what the system does, where human judgment enters, what effects it produces, and which legal rules apply.
Distinction requires parties to distinguish between civilians and combatants and between civilian objects and military objectives. AI systems may assist with classification, but classification is not merely a technical task. It depends on context, behaviour, intelligence, reliability, legal status, and uncertainty. A model may identify a vehicle, movement pattern, heat signature, or object type. It cannot, by itself, resolve all legal questions about targetability.
Proportionality requires an assessment of expected incidental civilian harm in relation to the concrete and direct military advantage anticipated. This assessment is normative and contextual. AI may help estimate blast radius, civilian presence, or pattern of life. It cannot replace the commander’s legal judgment. A system that produces a numerical risk score may conceal assumptions about civilian life, uncertainty, and acceptable harm.
Precautions require feasible steps to verify targets, choose means and methods with a view to avoiding or minimising civilian harm, and cancel or suspend attacks where it becomes apparent that the target is not lawful or the expected harm is excessive. AI can support precautions by improving surveillance and analysis. It can also weaken precautions if speed, automation bias, or poor data quality lead humans to accept recommendations too quickly.
The Martens Clause remains relevant. It refers to the principles of humanity and the dictates of public conscience where specific rules are absent (Additional Protocol I, 1977). It does not create a simple answer to every autonomous weapons question. It does remind states that legality is not exhausted by technical compliance where weapons raise fundamental concerns about human control, dignity, and civilian protection.
AI-enabled warfare also raises accountability problems. If an attack violates humanitarian law, responsibility cannot be assigned to the machine. The legal inquiry must examine commanders, operators, programmers, where relevant, weapons reviewers, procurement authorities, and the state. The challenge is proof of knowledge, foreseeability, control, and causation, not the disappearance of law.
10.2 Human judgment in targeting
The debate over autonomous weapons is often framed around “meaningful human control”. The phrase is not itself a settled treaty rule, but it captures a core legal and ethical concern: life-and-death decisions should not be delegated to systems that humans cannot understand, supervise, or constrain.
Human judgment matters because targeting is not only about detection. It requires legal classification, assessment of uncertainty, civilian harm estimation, proportionality reasoning, and the ability to cancel or suspend an attack. A system may identify a pattern associated with hostile activity, but a human must understand the basis, limits, and operational context before relying on it.
Autonomy can appear in different parts of the targeting cycle. A system may select targets, prioritise them, recommend force, track movement, engage automatically, or defend against incoming threats. The legal risk differs across these functions. Defensive systems operating in narrow environments may be easier to review than systems that search for human targets across populated areas.
Speed is a major pressure. Military actors may seek AI systems because conflicts unfold quickly, especially in air defence, cyber operations, swarming drones, and electronic warfare. Speed can support protection in some contexts. It can also compress human judgment until review becomes symbolic. A human who has only seconds to approve a machine recommendation may not exercise meaningful control.
Opacity is another problem. Some machine learning systems cannot provide reasons in a form that operators can understand. If the operator cannot know why the system classified a person, vehicle, signal, or structure as a target, reliance becomes legally dangerous. Unexplainable systems may be especially problematic where civilian harm is foreseeable.
Environment matters. A system used in an isolated maritime zone differs from one used in a dense urban area. A system designed to intercept incoming missiles differs from one designed to identify persons based on behaviour. Human control requirements should be stricter where targets are human beings, civilians are nearby, or the environment is unpredictable.
Training and doctrine are part of human judgment. Operators must know the system’s capabilities, limits, error rates, data dependencies, and authorised conditions of use. Commanders must understand how automation affects target selection and civilian harm assessment. Legal advisers must be involved before and during deployment where risks are high.
The legal issue is not autonomy in the abstract. It is the quality of control over the use of force. A weapon system that allows commanders to define narrow targets, geographic limits, time limits, abort conditions, and operational constraints may pose different risks from a system that searches broadly and adapts unpredictably. Human judgment must be assessed in relation to design, deployment, and actual use.
10.3 Article 36 weapons review
Article 36 of Additional Protocol I requires each state party, in the study, development, acquisition, or adoption of a new weapon, means, or method of warfare, to determine whether its employment would be prohibited by international law in some or all circumstances (Additional Protocol I, 1977). This obligation is central to AI-enabled military systems.
Weapons review is not a paperwork exercise. It requires legal, technical, and operational assessment before deployment. For AI systems, the review should examine data, model behaviour, reliability, predictability, explainability, cybersecurity, human-machine interaction, operational environment, update processes, and failure modes. A conventional review method may be insufficient where the system learns, adapts, or changes through software updates.
The timing of the review matters. AI systems may evolve after initial approval. A model may be retrained. Sensors may be added. Software may be updated. The deployment context may change. A system approved for one environment may be unlawful or unreliable in another. Article 36 review should be repeated or reopened when material changes occur.
Review must examine foreseeable use, not only intended use. A vendor or military developer may describe ideal conditions. Legal advisers must ask how the system may perform under stress, degraded data, adversarial manipulation, communication loss, civilian proximity, weather interference, or operator misunderstanding. A system that is lawful only under narrow conditions must have technical and operational constraints that keep use within those conditions.
Cybersecurity is part of weapons review. AI-enabled systems may be vulnerable to spoofing, data poisoning, adversarial examples, hacking, sensor manipulation, or communication disruption. A compromised system may misidentify targets or behave unpredictably. If such risks are foreseeable and unmanaged, legality is doubtful.
The human-machine interface must also be reviewed. If the system presents outputs in a way that encourages over-reliance, hides uncertainty, or pressures rapid approval, the design affects legal compliance. Interfaces should communicate confidence, uncertainty, data gaps, and legal constraints in a way operators can understand.
States not party to Additional Protocol I may still have strong reasons to conduct weapons reviews as a matter of responsible practice and customary compliance with IHL obligations. The review process helps states meet duties under distinction, proportionality, precautions, and weapons law. For AI systems, failure to review may become evidence of negligent or reckless deployment.
Transparency about weapons review is politically sensitive, but complete secrecy is undesirable. States can publish review policies, general criteria, and institutional procedures without revealing classified details. Public confidence in AI military governance requires at least some information about how legality is assessed.
10.4 Accountability for battlefield harm
AI-enabled warfare does not eliminate legal accountability. It complicates the evidence. When harm occurs, investigators must determine which actors designed, approved, deployed, supervised, and used the system. They must identify what was foreseeable, what was known, what controls existed, and how the system behaved.
State responsibility may arise where an AI-enabled attack breaches international humanitarian law and the conduct is attributable to the state. This includes attacks by armed forces, state organs, or actors whose conduct is otherwise attributable under international law. The state may owe cessation, assurances of non-repetition, and reparation depending on the circumstances (International Law Commission, 2001).
Individual criminal responsibility may arise where the legal threshold for war crimes, crimes against humanity, or genocide is met. AI does not change the need to prove the required mental element and conduct. It may affect how knowledge and intent are shown. Commanders who knowingly deploy unreliable systems in civilian areas, ignore warnings, or fail to supervise may face scrutiny under established doctrines, including command responsibility where the legal elements are satisfied (Rome Statute, 1998).
Command responsibility requires careful application. A commander is not criminally responsible merely because a complex system produced harm. The analysis must examine effective control, knowledge or reason to know, failure to prevent or repress, and the link to crimes committed by subordinates. AI can make these questions harder, but not irrelevant.
Procurement and review officials may also be important. If a state acquires a system without adequate legal review, ignores known limitations, or deploys it outside approved conditions, responsibility may extend beyond the battlefield operator. The chain of responsibility may include those who authorised use despite foreseeable legal risks.
Manufacturers are usually addressed through domestic law, contract, export control, and business responsibility rather than direct international criminal law. Yet their role should not be ignored. A company that markets a system for unlawful use, conceals known defects, or continues support after credible evidence of serious abuse may face domestic liability, sanctions, exclusion from procurement, or claims under emerging mandatory due diligence regimes.
Evidence preservation is critical. Military AI systems should keep logs of inputs, outputs, confidence levels, operator actions, overrides, data sources, updates, and communications. Without such records, after-action review becomes weak. A state that deploys systems without audit trails makes accountability more difficult and may undermine its own ability to prove lawful conduct.
The accountability question should not be framed as a machine problem. It is an institutional design problem. States that use AI in warfare must build systems that preserve human judgment, legal review, traceability, and investigation. If they cannot do so, they should not deploy the system in contexts where civilian life and protected persons are at serious risk.
11. AI, Security, and International Peace
11.1 Cyber operations and AI escalation
AI can intensify cyber operations by increasing speed, scale, targeting, deception, and adaptability. It may assist vulnerability discovery, phishing, malware development, intrusion detection, automated exploitation, social engineering, and command disruption. It may also strengthen defence through anomaly detection, system monitoring, and rapid response. The legal issue is not AI as such, but the way AI changes the risk of escalation and miscalculation.
Public international law already applies to state conduct in cyberspace. Relevant principles include sovereignty, non-intervention, the prohibition on the use of force, peaceful settlement of disputes, due diligence debates, human rights, and international humanitarian law during armed conflict (Schmitt, 2017; United Nations General Assembly, 2021). AI does not replace these rules. It may make their application more factually difficult.
Attribution is a major challenge. AI-enabled cyber operations can be routed through multiple states, private infrastructure, compromised devices, and automated agents. A state harmed by a cyber operation may struggle to identify the responsible actor quickly. If states respond before the evidence is reliable, the escalation risk rises. AI may increase this danger by accelerating both attack and response cycles.
The threshold between hostile activity and use of force remains fact-dependent. Cyber operations that cause physical damage, injury, or severe disruption may raise questions under Article 2(4) of the UN Charter (United Nations, 1945). AI may enable operations against power grids, hospitals, financial systems, transport networks, satellites, or military command systems. Legal analysis must assess scale, effects, intent, where relevant, and context.
Non-intervention is also important. AI-enabled operations may target elections, public institutions, political parties, media ecosystems, or social movements. Coercive interference in matters reserved to a state may violate the principle of non-intervention. Disinformation alone does not automatically meet that threshold. Coordinated AI-enabled manipulation linked to coercive pressure, cyber intrusion, or state control may raise stronger concerns.
Due diligence in cyberspace remains contested in its precise scope. Still, states are under increasing pressure to prevent their territory or infrastructure from being used for serious, harmful cyber operations where they have the knowledge and capacity to act. AI may increase the need for monitoring and response, but it may also make prevention harder. The standard should remain one of reasonable measures, not strict liability.
Human rights apply to cyber operations. AI-enabled surveillance, hacking, doxing, and information manipulation may affect privacy, expression, association, political participation, and access to services. National security cannot operate as a blank cheque. Measures must be lawful, necessary, proportionate, and subject to oversight.
11.2 Disinformation and political self-determination
Generative AI has made synthetic political manipulation cheaper and faster. Text, images, audio, and video can be produced at scale and targeted to specific audiences. Automated networks can amplify false narratives, impersonate real persons, and flood public debate. The threat is not only false information. It is the erosion of the conditions under which people can participate meaningfully in political life.
International law protects political participation and self-determination. Article 25 of the ICCPR protects the right to take part in public affairs, vote, be elected, and access public service (United Nations, 1966a). Common Article 1 of the ICCPR and ICESCR recognises the right of peoples to self-determination (United Nations, 1966a; United Nations, 1966b). AI-enabled influence operations may affect these interests when they distort electoral processes, intimidate voters, or manipulate public debate through deception.
Not all disinformation is an international law violation. Political speech includes error, exaggeration, propaganda, and hostile messaging. A rights-based approach must avoid giving governments broad censorship authority. The legal concern becomes stronger where foreign state-linked operations use deception, automation, cyber intrusion, impersonation, data theft, or targeted manipulation to interfere with democratic processes.
Synthetic media targeting women, minorities, journalists, and opposition figures also affects equality and participation. Deepfake sexual abuse, fabricated criminal evidence, and automated harassment can drive people out of public life. The harm is not only reputational. It can silence political participation and reinforce structural exclusion.
Platform responsibility is central. Recommender systems and advertising tools can amplify AI-generated manipulation. Companies should assess election-related risks, label synthetic content where appropriate, preserve political advertising records, provide researcher access under safeguards, and cooperate with independent oversight. These measures should protect expression rather than suppress lawful dissent.
State responses must satisfy legality and proportionality. Criminal bans on vague categories of “false information” can be abused against journalists and opponents. More rights-compatible measures include transparency rules, platform accountability, media literacy, independent electoral oversight, rapid correction mechanisms, protection for journalists, and targeted action against coordinated inauthentic behaviour.
Political self-determination also has an external dimension. Foreign AI-enabled influence operations may be part of broader coercive strategies. When combined with cyber attacks, funding manipulation, threats, or pressure on institutions, disinformation can contribute to unlawful interference. The legal assessment must examine the full pattern of conduct.
AI makes democratic resilience a public international law issue. States have duties to protect political rights within their jurisdiction. They also have duties to respect the political independence of other states. The same technology can be used to support civic participation or to degrade it. The difference lies in transparency, accountability, and respect for political agency.
11.3 Dual-use technology and export controls
AI is a dual-use technology. The same capability can serve health care, disaster response, education, logistics, military targeting, surveillance, cyber operations, or repression. This makes governance difficult. A broad ban would harm beneficial uses. A permissive approach would ignore foreseeable abuse.
Export controls are one legal tool. States may restrict the transfer of certain technologies where there is a serious risk of military misuse, internal repression, surveillance abuse, or human rights violations. Traditional export control systems were built around weapons, dual-use goods, encryption, cyber tools, and sensitive materials. AI challenges these systems because software, models, expertise, data, and cloud access may cross borders without ordinary shipment.
Human rights due diligence should inform export decisions. A state authorising export of facial recognition, spyware, predictive policing tools, biometric databases, or military AI should assess the end user, human rights record, legal safeguards, risk of diversion, and potential impact on vulnerable groups. A licence should not be granted where serious misuse is foreseeable, and safeguards are inadequate.
Corporate actors also have responsibilities. A company should not rely only on formal legality where the risk of abuse is obvious. Selling surveillance analytics to authorities known for persecuting dissidents, minorities, or journalists creates a foreseeable human rights risk. Contract clauses prohibiting misuse are weak if monitoring and enforcement are absent.
Military AI raises additional concerns. Decision-support tools, autonomous functions, targeting analytics, drone swarms, cyber capabilities, and command systems may alter regional balances and crisis stability. The UN Charter framework on force remains applicable, but arms control and confidence-building measures may be needed to reduce miscalculation. Transparency, testing norms, communication channels, and limits on certain systems may support international peace.
The risk of proliferation to non-state actors is serious. AI tools can assist drone navigation, target recognition, cyber intrusion, propaganda, and weapons adaptation. Non-state armed groups and criminal organisations may use commercial systems in harmful ways. States should address this through export controls, platform governance, criminal law, procurement standards, and international cooperation.
Controls must be carefully designed. Overbroad restrictions can block development, research, humanitarian innovation, and access for lower-capacity states. They may also concentrate AI power in wealthy states and major corporations. Rights-based export governance should target high-risk uses and users rather than suppress general technological capacity.
Technology transfer and safeguards should be discussed together. States in the Global South should not be told simply to accept restrictions while remaining dependent on foreign infrastructure. International cooperation should support lawful, rights-compatible AI capacity, including public-interest systems, regulatory expertise, and independent oversight.
The dual-use character of AI confirms the article’s core thesis. Ethical language is not enough. Governance requires legal classification, risk assessment, licensing, oversight, responsibility, and remedy. The same tool can protect rights or violate them. International law must focus on use, control, context, and foreseeable harm.
12. Inequality, Development, and Digital Sovereignty
12.1 Data colonialism and dependency
Artificial Intelligence Ethics cannot be credible if it ignores global inequality. AI systems are often designed, financed, trained, hosted, and governed by actors based in technologically powerful states. Many lower-capacity states import cloud infrastructure, digital identity tools, biometric systems, platform services, surveillance equipment, educational software, and public-sector analytics without equal bargaining power. This creates a problem of legal dependence as well as technical dependence.
The language of ethics may conceal this imbalance. A system may be described as fair, safe, and efficient by the vendor that built it. The receiving state may lack the technical capacity to test those claims. Public agencies may lack lawyers and engineers able to examine model behaviour, data provenance, security risks, contract terms, and human rights impacts. The result is a governance structure in which the state remains legally responsible for public decisions while private foreign actors control essential technical knowledge.
Data colonialism describes a related concern: the extraction of data, behavioural patterns, social knowledge, and economic value from populations that have little control over how the information is used (Couldry and Mejias, 2019). The term should not be used loosely. It is strongest where data extraction reproduces older patterns of unequal power, external control, and economic dependence. In AI governance, this can occur when populations become sources of training data, experimental markets, or surveillance subjects without meaningful participation.
The problem is not only commercial. Development programmes may promote digital systems as neutral modernization. Digital identity, welfare analytics, biometric registration, and predictive social-policy tools may improve service delivery. They may also create permanent infrastructures of monitoring. If the state lacks strong data protection, judicial review, procurement capacity, and cybersecurity, public-interest technology can become a system of control.
Language inequality is another form of dependency. Large AI models perform better in dominant languages because those languages are better represented in training data. Underrepresented languages may receive lower-quality translation, weaker moderation, poorer legal information, and less reliable public-service tools. This affects access to justice, education, health care, political participation, and cultural life. A global AI system that cannot understand a community’s language cannot claim equal accessibility.
Infrastructure dependency also affects sovereignty. A state may rely on foreign cloud providers for public databases, health systems, tax administration, education platforms, or security tools. If access, pricing, updates, or compliance terms are controlled abroad, the state’s ability to regulate public power is weakened. Sovereignty here is not an abstract symbol. It concerns the practical ability to audit, secure, explain, and control systems used in governance.
Digital sovereignty should not be misunderstood as isolation. No state can build every AI component alone. International cooperation, open standards, shared research, and cross-border infrastructure are necessary. The legal issue is whether states can preserve democratic control, rights protection, and regulatory autonomy while participating in global technological systems.
A rights-based approach to AI and development must ask who controls data, who sets standards, who profits, who bears risk, and who can challenge harm. Artificial Intelligence Ethics that ignore these questions become a polished language for unequal technological adoption.
12.2 Language, culture, and exclusion
AI systems often carry hidden cultural assumptions. They may reflect the social norms, legal categories, behavioural patterns, and linguistic structures of the environments in which they were trained. When exported into different societies, those assumptions may distort decisions.
Human rights law offers a better baseline than abstract ethics because it combines universality with attention to context. Universal rights do not require an identical administrative design everywhere. They require dignity, equality, participation, privacy, due process, and remedies to be protected in real conditions. Local context matters because harm is experienced through language, culture, disability, gender, migration status, poverty, race, caste, religion, and political vulnerability.
Indigenous data governance illustrates the point. Some communities understand data not only as individual information but as collective knowledge tied to identity, land, ancestry, and self-determination. A standard consent form may not address these collective interests. International law increasingly recognises indigenous peoples’ rights to culture, participation, lands, resources, and self-determination, including through the United Nations Declaration on the Rights of Indigenous Peoples (United Nations General Assembly, 2007). AI governance should not treat indigenous data as an ordinary extractive resource.
Disability rights also require more than neutral design. The Convention on the Rights of Persons with Disabilities requires accessibility, equality, reasonable accommodation, and respect for autonomy (United Nations, 2006). AI tools used in education, employment, public services, and health care may discriminate if they treat atypical speech, movement, learning patterns, or communication styles as risk, deception, low productivity, or non-compliance. Equal treatment may require adapting the system, not forcing persons to conform to the model.
Cultural and religious contexts may also affect AI moderation and public administration. Automated content systems may misread religious language, political symbolism, minority dialects, or historical references. A platform may remove documentation of atrocities because violent images match prohibited-content rules. A legal chatbot may mistranslate family, inheritance, or asylum terms. In these cases, the problem is not only a technical error. It is a legal exclusion through cultural misunderstanding.
AI systems used in migration and asylum require particular caution. Applicants may speak through interpreters, lack documents, suffer trauma, or explain persecution through cultural concepts unfamiliar to officials. Automated credibility tools, language analysis, or risk scoring may misclassify such applicants. Non-refoulement, fair procedure, and dignity require individual assessment. AI cannot be allowed to turn complexity into suspicion.
Participation is the safeguard most often missing. Affected communities should have a role before high-risk systems are adopted. Consultation should not be limited to experts, vendors, and state agencies. It should include those likely to be classified, monitored, excluded, or scored. Participation improves accuracy, but its deeper legal value lies in democratic legitimacy and respect for agency.
12.3 Capacity-building and technology transfer
International cooperation is a legal and practical necessity. The UN Charter includes international cooperation among the purposes of the United Nations (United Nations, 1945). Human rights treaties also recognise cooperation in realising rights, especially economic and social rights (United Nations, 1966b). AI governance should be read against that background.
Capacity-building must go beyond training officials to buy technology. States need independent regulators, judicial expertise, data protection authorities, procurement specialists, cybersecurity capacity, public-interest technologists, and civil society oversight. A state that imports AI tools without these safeguards may increase risk while appearing modern.
Technology transfer should not mean dumping systems into weaker regulatory environments. Responsible transfer requires documentation, local testing, language adaptation, accessibility, data protection, independent audit, and contractual rights to inspect and terminate. A system suitable for one jurisdiction may be unsafe in another because the data, institutions, rights protections, and social conditions differ.
International organisations can help, but they must avoid vendor-driven development. Public-interest AI capacity should not be shaped primarily by companies seeking new markets. Assistance should support legal infrastructure, open knowledge, local research, rights-based procurement, and community participation. Otherwise, capacity-building becomes market expansion under a humanitarian vocabulary.
Regional cooperation may be useful. States can share model procurement clauses, data protection standards, audit methods, judicial training materials, and public-sector risk assessment tools. Smaller states may have more bargaining power when they coordinate. Common standards can also reduce dependence on vendor-defined ethics.
Funding is a legal issue because rights protection costs money. A state cannot build meaningful AI oversight with declarations alone. Regulators need technical staff. Courts need expert assistance. Public defenders need access to evidence. Data protection authorities need enforcement powers. Civil society needs resources to scrutinise systems. Without material capacity, Artificial Intelligence Ethics remains an elite discourse detached from affected populations.
Development should also include the right not to automate. Some public problems require staff, housing, health care, legal aid, education, social work, or anti-corruption reform. AI may assist these functions, but it should not be used to disguise political choices about underfunding. A rights-based state must ask whether technology solves the problem or merely makes scarcity more efficient.
13. Remedies and Enforcement
13.1 Explainability as a condition of remedy
A remedy is impossible when the affected person cannot understand the basis of the decision. Explainability is not only a technical preference. It is a legal condition for due process, equality, privacy, and access to justice.
The level of explanation should depend on the seriousness of the impact. A low-risk recommendation tool may require limited disclosure. A system affecting liberty, asylum, welfare, policing, education, health care, employment, or sanctions requires a stronger explanation. The person should know that AI was used, what role it played, which main factors influenced the outcome, what evidence was relied on, and how the decision can be challenged.
Explanation must be useful to the person, not only to engineers. A mathematical description of model architecture may be unintelligible. A vague statement that “risk indicators were considered” is useless. A rights-compatible explanation should connect the system’s output to the facts of the case in ordinary language, while allowing deeper technical review by regulators, courts, or independent experts where needed.
Trade secrecy cannot defeat a remedy. Commercial confidentiality may justify controlled disclosure, protective orders, regulator-only access, or independent audits. It cannot justify a system in which no one outside the vendor can assess legality. Public authorities should not deploy rights-affecting systems if they cannot explain them.
Explainability also supports institutional learning. If a system produces wrongful decisions, explanations, and audit records allow correction. Without them, errors become invisible. Affected persons may suffer individually, while the same defect continues to harm others.
13.2 Human review and contestability
Human review is often presented as the safeguard that makes AI lawful. That claim is weak unless the review is real. A human who merely approves an automated result without understanding it does not provide legal protection. A human who lacks the authority to change the outcome is a procedural ornament.
Meaningful review requires independence, competence, time, access to information, and power. The reviewer must be able to question the output, inspect relevant evidence, consider the person’s explanation, and depart from the automated recommendation. The review should be documented so that later bodies can understand how the decision was made.
Contestability is broader than review. It means the affected person can challenge the decision in practice. They must receive notice, reasons, access to relevant information, assistance where needed, and a forum capable of granting relief. Contestability fails when the process is too technical, too expensive, too slow, or too opaque.
Vulnerable groups may need additional support. Migrants, children, persons with disabilities, welfare recipients, detained persons, and persons with limited literacy may not be able to challenge AI-assisted decisions through ordinary digital forms. Effective contestation may require legal aid, interpretation, accessible formats, community support, and offline procedures.
Automated systems also require collective contestability. Some harms are systemic. A model may discriminate against a group, chill protest, misclassify a community, or produce widespread false suspicion. Individual appeals may fix isolated cases while leaving the system intact. Regulators, equality bodies, ombuds institutions, national human rights institutions, and civil society organisations need standing or authority to challenge systemic defects.
A legally serious review system must include suspension powers. If an AI system creates serious rights risks, the reviewing authority should be able to pause its use, order an audit, require disclosure, mandate correction, or prohibit deployment. A remedy that only compensates after harm may be inadequate where the system continues to affect thousands of people.
13.3 Judicial and administrative remedies
Courts are essential but not sufficient. AI-related harms often require speed, technical expertise, and systemic investigation. A person wrongly denied welfare cannot wait years for a final judgment. A person falsely matched on a sanctions list may need urgent correction. A discriminatory hiring tool may affect many applicants who never learn why they were rejected.
Administrative remedies can be more accessible if properly designed. Data protection authorities can investigate processing, order deletion, impose fines, and require compliance. Equality bodies can examine discriminatory effects. Ombuds institutions can investigate maladministration. Sector regulators can supervise health, finance, education, labour, and communications. Procurement bodies can review public contracts. National human rights institutions can address systemic risks.
Each route has limits. Data protection authorities may focus on privacy and miss broader due process or equality harms. Equality bodies may lack technical expertise. Ombuds institutions may issue recommendations without binding force. Courts may struggle with technical secrecy. Sector regulators may be captured by industry. A strong system requires coordination among institutions.
International remedies remain limited. Treaty bodies may consider individual communications where states have accepted procedures. Regional human rights courts may provide stronger enforcement in some systems. Special procedures can investigate and report. International organisations may create internal complaint mechanisms. None of these routes can replace domestic remedies. Most AI harms will need effective national implementation.
Procedural tools are crucial. Courts and regulators need powers to order disclosure, appoint independent experts, access source material under confidentiality, inspect audit logs, review procurement contracts, and require statistical evidence. Without such powers, AI litigation may fail because the affected person cannot prove what the system did.
Standing rules matter. Many affected persons will not know they were harmed. Others may lack resources. Collective actions, public interest litigation, complaints by civil society, and regulatory investigations can address this gap. AI systems often produce group harms that individual litigation cannot capture.
Remedies should address urgency. Interim measures may be necessary to stop deportation, restore benefits, prevent data transfer, suspend surveillance, or halt deployment during review. Waiting for final adjudication may make the remedy meaningless.
13.4 Reparation for AI-related harm
Reparation must match the harm. The law of state responsibility recognises cessation, assurances of non-repetition, restitution, compensation, and satisfaction (International Law Commission, 2001). Human rights law also requires effective remedies adapted to the violation (United Nations General Assembly, 2005). AI-related harm may require both individual and systemic forms of repair.
Restitution may include restoring benefits, reopening an asylum procedure, removing a person from a watchlist, correcting an administrative record, reversing an automated exclusion, or reinstating access to a service. Where the harm is procedural, a new decision by a lawful process may be necessary.
Compensation may be required for financial loss, emotional distress, reputational harm, unlawful detention, denial of services, or other injury. Quantifying AI-related harm can be difficult, especially where a person lost an opportunity rather than a guaranteed benefit. Courts and administrative bodies should avoid treating technical complexity as a reason to deny compensation.
Correction and deletion are often central. If unlawful data, false inferences, or discriminatory scores remain in a system, harm may continue. A person may be repeatedly flagged, investigated, or excluded. Remedy should include correction of records, deletion of unlawfully processed data, and notification to entities that received the wrong information.
Satisfaction may include acknowledgment, apology, public explanation, publication of findings, or clarification that a person was wrongly classified. This matters where AI systems create suspicion or stigma. A false fraud label, security classification, or risk score may damage dignity and reputation even after the immediate decision is reversed.
Guarantees of non-repetition are essential for systemic AI harms. They may require suspension of the system, redesign, independent audit, staff training, procurement reform, new legislation, stronger regulator powers, public reporting, or termination of vendor contracts. If a system harmed many people, individual remedies alone are inadequate.
Collective remedies may be needed where a tool affected a group. A discriminatory policing model, welfare fraud system, or biometric surveillance programme may harm communities, not only individuals. Remedies may require community consultation, public disclosure, institutional reform, and monitoring.
Reparation should also address the evidentiary imbalance. Where a state or company failed to keep logs, blocked disclosure, or deployed an unexplainable system, it should not benefit from the resulting uncertainty. Domestic law may need presumptions, burden-shifting, or adverse inferences where the responsible actor controlled the evidence.
Also Read
14. A Doctrinal Test for Artificial Intelligence Ethics
14.1 Legal basis
The first test is legal basis. A rights-affecting AI system must be authorised by law. Internal guidelines, vendor contracts, procurement documents, or administrative preferences are not enough where the system affects privacy, liberty, equality, expression, social benefits, migration status, education, health care, employment, or access to justice.
The legal basis must be accessible and precise. Individuals should know the circumstances in which AI may be used, the purposes allowed, the data categories processed, the safeguards required, the role of human decision-makers, the available review, and the remedy. Secret AI governance is incompatible with the rule of law.
Legal basis also requires institutional competence. The authority using AI must have the power to use it for the stated purpose. A database collected for education should not become a policing tool without lawful authorisation. A humanitarian registration system should not become migration enforcement infrastructure through informal data-sharing. Purpose limits must be legally enforceable.
For private actors, legal basis operates differently but remains important. Companies need lawful grounds for data processing, non-discriminatory practices, consumer protection compliance, sectoral authorisation where relevant, and respect for domestic legislation implementing human rights duties. Public authorities using private systems must ensure that the legal basis covers the whole deployment, not only the final human decision.
14.2 Legitimate aim
The second test is legitimate aim. A state or institution must identify the specific lawful purpose of the AI system. Vague references to innovation, efficiency, digital transformation, or security are insufficient. The aim must be concrete enough to allow review.
Fraud prevention, public safety, health protection, administrative accuracy, child protection, and resource allocation may be legitimate aims in appropriate settings. Yet legitimacy is not automatic. A system designed to suppress dissent, monitor lawful protest, discriminate against minorities, manipulate voters, or avoid legal obligations has no legitimate rights-based aim.
The aim must also match the system. A broad surveillance tool cannot be justified by a narrow public-order claim if it collects data on an entire population. A welfare fraud model cannot be justified by efficiency if it is mainly used to reduce expenditure by deterring lawful claims. A migration tool cannot be justified by border management if it obstructs access to asylum or increases refoulement risk.
Legitimate aim analysis should expose hidden purposes. Public authorities may describe a system as administrative while using it for enforcement. Platforms may describe recommender systems as user experience while optimising for engagement and advertising revenue. Companies may describe monitoring tools as productivity systems while enabling intrusive worker control. Legal review should examine actual function, not marketing language.
14.3 Necessity
The third test is necessity. Even where the aim is legitimate, the institution must show that AI is needed. It must ask whether the same objective can be achieved through less intrusive, less discriminatory, or more transparent means.
Necessity is where many systems fail. Public bodies may adopt AI because it appears modern, cheaper, or politically attractive. Yet the underlying problem may be poor staffing, unclear rules, lack of training, weak administration, or underfunded services. AI may automate a defective process rather than improve it.
A welfare authority should ask whether targeted human review, better guidance, increased staffing, or narrower statistical checks would prevent fraud without mass suspicion. A police force should ask whether ordinary investigation, community-based methods, or judicially authorised surveillance would meet the need without predictive profiling. A school should ask whether human assessment or accessible support would work better than intrusive proctoring.
Data necessity is part of the test. The institution must justify each major category of data. Collecting more data because it may improve prediction is not enough. Data that is unnecessary for the lawful purpose should not be processed. This protects privacy and reduces function creep.
Necessity must be reassessed over time. A system may be adopted during emergency conditions but continue after the emergency ends. A temporary tool may become permanent infrastructure. A model designed for one problem may be expanded to new purposes. Each expansion requires fresh necessity analysis.
14.4 Proportionality
The fourth test is proportionality. The expected benefit must be weighed against the right burden. This requires more than a technical risk score. It requires legal judgment about the seriousness, scale, duration, reversibility, and distribution of harm.
Proportionality should consider individual harm. A false fraud flag may suspend income needed for food or rent. A false security match may block travel or banking. A wrong educational classification may affect a child’s future. A mistaken police prediction may expose a person to coercive attention.
It should also consider group harm. A system may disproportionately burden racial minorities, migrants, poor communities, persons with disabilities, political dissidents, or linguistic minorities. Group harm may persist even where each decision appears defensible in isolation.
Chilling effects must be included. Biometric surveillance may deter protest. Online monitoring may deter expression. Welfare analytics may deter lawful claims. Migration data-sharing may deter people from seeking protection or health care. These effects are difficult to quantify but legally significant.
Proportionality must also examine institutional consequences. Some systems normalise automated suspicion, expand surveillance infrastructures, or shift discretion to private vendors. A tool may seem useful in one case but dangerous as a model of governance. Public law must consider these longer-term effects.
Mitigation measures can reduce harm, but do not always save a system. Human review, audits, transparency notices, or appeal rights may be insufficient where the system is inherently disproportionate. Some uses should be prohibited because the rights burden is too high or because meaningful control is impossible.
14.5 Accountability
The fifth test is accountability. No AI system affecting rights should be deployed without documentation, auditability, human responsibility, independent review, and remedy. Accountability is the point at which Artificial Intelligence Ethics becomes law.
Documentation should show purpose, legal basis, data sources, design choices, testing, limitations, safeguards, responsible officials, monitoring results, incidents, and review outcomes. If the institution cannot document the system, it cannot prove legality.
Auditability requires access by competent bodies. Internal audits may help, but high-risk systems need independent scrutiny. Regulators, courts, national human rights institutions, data protection authorities, equality bodies, or authorised auditors should be able to inspect relevant evidence.
Responsibility must be assigned before harm occurs. Institutions should identify who approves the system, who monitors it, who handles complaints, who can suspend use, and who is legally accountable. Diffuse responsibility is a design failure.
Remedy must be practical. Affected persons should have notice, reasons, access to evidence, human review, appeal, correction, deletion, compensation where appropriate, and protection against retaliation. Systemic harms require systemic remedies.
The test can be expressed in a simple sequence:
Test | Core question | Legal consequence |
Legal basis | Is the system clearly authorised by law? | No lawful basis means no deployment. |
Legitimate aim | Is the purpose specific and lawful? | Vague aims cannot justify rights interference. |
Necessity | Is AI needed, or is a less intrusive method available? | Unnecessary systems should be rejected. |
Proportionality | Do benefits justify the rights burden? | Excessive harm makes use unlawful. |
Accountability | Can the system be explained, audited, challenged, and remedied? | No accountability means no rights-compatible use. |
This test does not solve every dispute. It gives lawyers, judges, regulators, public authorities, international organisations, companies, and civil society a disciplined framework. It prevents AI ethics from drifting into slogans and forces analysis into legal form.
Conclusion
Artificial Intelligence Ethics in international law should not be treated as a separate moral field detached from legal doctrine. Its value depends on translation. Ethical ideas such as fairness, transparency, safety, accountability, and human oversight become legally meaningful only when connected to sources, jurisdiction, duties, attribution, responsibility, remedies, and institutional control.
The article has argued that AI does not create a legal vacuum. Existing international law already applies to many AI-related harms. Human rights law governs privacy, equality, expression, due process, political participation, and economic and social rights. International humanitarian law governs AI-enabled weapons and targeting systems. The law of state responsibility governs attribution, breach, cessation, and reparation. The responsibility of international organisations is relevant where UN bodies and other institutions use AI in field operations. Business and human rights standards guide corporate conduct across AI supply chains.
The challenge is operational. AI systems disturb ordinary assumptions about territory, control, causation, knowledge, and proof. A harmful decision may emerge through data collected in one state, infrastructure hosted in another, software built by a private vendor, and public authority exercised elsewhere. Affected persons may not know that AI shaped the outcome. Legal systems must respond with stronger disclosure, auditability, impact assessment, procurement control, human review, and remedies.
Soft law has an important role, but it must be used honestly. UNESCO principles, UN system guidance, General Assembly resolutions, technical standards, and institutional frameworks can shape expectations and support future law. They do not replace binding obligations. The Council of Europe AI Convention and the EU AI Act show a movement toward more formal governance, but global AI law remains fragmented. In this setting, existing human rights and responsibility doctrines provide the most stable legal foundation.
A serious approach must also address inequality. AI governance cannot be credible if it is written only by powerful states, corporations, and technical bodies. Data extraction, language exclusion, infrastructure dependency, weak procurement capacity, and limited regulatory expertise can turn AI into another mechanism of global hierarchy. Rights-based AI requires participation, capacity-building, technology transfer, local testing, and respect for communities affected by deployment.
The doctrinal test proposed here is deliberately strict: legal basis, legitimate aim, necessity, proportionality, and accountability. A system that fails any of these elements should not be deployed in rights-affecting contexts. This test does not reject innovation. It rejects unaccountable power. AI can support human rights monitoring, public services, accessibility, health care, disaster response, and legal research. It can also deepen surveillance, discrimination, exclusion, manipulation, and violence. International law must judge AI by use, context, control, and harm.
The future of Artificial Intelligence Ethics will not be decided by principles alone. It will be decided by whether individuals and communities can challenge harmful systems, whether states can control the technologies they deploy, whether companies can be held to account for foreseeable harm, and whether international institutions apply to themselves the standards they promote to others. Without enforceable accountability, AI ethics remains rhetoric. With a legal structure, it can become part of a serious international law response to technological power.
References
Additional Protocol I (1977) Protocol Additional to the Geneva Conventions of 12 August 1949, and relating to the Protection of Victims of International Armed Conflicts [online]. Available at: https://ihl-databases.icrc.org/en/ihl-treaties/api-1977 (Accessed: 1 June 2026).
Aust, A. (2005) Handbook of International Law. Cambridge: Cambridge University Press.
Boyle, A. and Chinkin, C. (2007) The Making of International Law. Oxford: Oxford University Press.
Cheng, B. (1953) General Principles of Law as Applied by International Courts and Tribunals. London: Stevens & Sons.
Committee on Economic, Social and Cultural Rights (1990) General Comment No. 3: The Nature of States Parties’ Obligations [online]. Available at: https://docs.un.org/en/E/1991/23(SUPP) (Accessed: 1 June 2026).
Committee on Economic, Social and Cultural Rights (2009) General Comment No. 20: Non-discrimination in Economic, Social and Cultural Rights [online]. Available at: https://docs.un.org/en/E/C.12/GC/20 (Accessed: 2 June 2026).
Council of Europe (2024) Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law [online]. Available at: https://www.coe.int/en/web/artificial-intelligence/the-framework-convention-on-artificial-intelligence (Accessed: 2 June 2026).
Couldry, N. and Mejias, U.A. (2019) The Costs of Connection: How Data Is Colonizing Human Life and Appropriating It for Capitalism. Stanford: Stanford University Press.
Diya, S.R. (2025) Applying International Human Rights Principles for AI Governance [online]. Available at: https://www.cigionline.org/publications/applying-international-human-rights-principles-for-ai-governance/ (Accessed: 2 June 2026).
Dulka, A. (2023) ‘The use of artificial intelligence in international human rights law’, Stanford Technology Law Review, 26(2), pp. 316–365. Available at: https://law.stanford.edu/publications/the-use-of-artificial-intelligence-in-international-human-rights-law/ (Accessed: 2 June 2026).
European Court of Human Rights (1999) Waite and Kennedy v Germany, Application no. 26083/94 [online]. Available at: https://hudoc.echr.coe.int/eng?i=001-58912 (Accessed: 3 June 2026).
European Court of Human Rights (2001) Banković and Others v Belgium and Others, Application no. 52207/99 [online]. Available at: https://hudoc.echr.coe.int/eng?i=001-22099 (Accessed: 3 June 2026).
European Court of Human Rights (2011) Al-Skeini and Others v United Kingdom, Application no. 55721/07 [online]. Available at: https://hudoc.echr.coe.int/eng?i=001-105606 (Accessed: 3 June 2026).
European Union (2024) Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence [online]. Available at: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (Accessed: 4 June 2026).
Fredman, S. (2016) ‘Substantive equality revisited’, International Journal of Constitutional Law, 14(3), pp. 712–738.
Human Rights Committee (1988) General Comment No. 16: Article 17, Right to Privacy [online]. Available at: https://www.refworld.org/legal/general/hrc/1988/en/27539 (Accessed: 4 June 2026).
Human Rights Committee (2004) General Comment No. 31: The Nature of the General Legal Obligation Imposed on States Parties to the Covenant [online]. Available at: https://docs.un.org/en/CCPR/C/21/Rev.1/Add.13 (Accessed: 4 June 2026).
Human Rights Committee (2019) General Comment No. 36: Article 6, Right to Life [online]. Available at: https://docs.un.org/en/CCPR/C/GC/36 (Accessed: 4 June 2026).
International Committee of the Red Cross (2019) Artificial Intelligence and Machine Learning in Armed Conflict: A Human-Centred Approach [online]. Available at: https://www.icrc.org/en/document/artificial-intelligence-and-machine-learning-armed-conflict-human-centred-approach (Accessed: 4 June 2026).
International Court of Justice (1949a) Corfu Channel Case, United Kingdom v Albania, Merits, Judgment [online]. Available at: https://www.icj-cij.org/case/1 (Accessed: 4 June 2026).
International Court of Justice (1949b) Reparation for Injuries Suffered in the Service of the United Nations, Advisory Opinion [online]. Available at: https://www.icj-cij.org/case/4 (Accessed: 4 June 2026).
International Court of Justice (1986) Military and Paramilitary Activities in and against Nicaragua, Nicaragua v United States of America, Merits, Judgment [online]. Available at: https://www.icj-cij.org/case/70 (Accessed: 4 June 2026).
International Court of Justice (2004) Legal Consequences of the Construction of a Wall in the Occupied Palestinian Territory, Advisory Opinion [online]. Available at: https://www.icj-cij.org/case/131 (Accessed: 4 June 2026).
International Court of Justice (2007) Application of the Convention on the Prevention and Punishment of the Crime of Genocide, Bosnia and Herzegovina v Serbia and Montenegro, Judgment [online]. Available at: https://www.icj-cij.org/case/91 (Accessed: 4 June 2026).
International Court of Justice (2010) Pulp Mills on the River Uruguay, Argentina v Uruguay, Judgment [online]. Available at: https://www.icj-cij.org/case/135 (Accessed: 5 June 2026).
International Law Commission (2001) Articles on Responsibility of States for Internationally Wrongful Acts [online]. Available at: https://legal.un.org/ilc/texts/instruments/english/draft_articles/9_6_2001.pdf (Accessed: 5 June 2026).
International Law Commission (2011) Articles on the Responsibility of International Organizations [online]. Available at: https://legal.un.org/ilc/texts/instruments/english/draft_articles/9_11_2011.pdf (Accessed: 5 June 2026).
International Law Commission (2018) Draft Conclusions on Identification of Customary International Law [online]. Available at: https://legal.un.org/ilc/texts/instruments/english/commentaries/1_13_2018.pdf (Accessed: 5 June 2026).
Jobin, A., Ienca, M. and Vayena, E. (2019) ‘The global landscape of AI ethics guidelines’, Nature Machine Intelligence, 1, pp. 389–399.
Klabbers, J. (2024) International Law. 4th edn. Cambridge: Cambridge University Press.
OHCHR (2020) An Introduction to the UN Guiding Principles in the Age of Technology [online]. Available at: https://www.ohchr.org/en/documents/tools-and-resources/introduction-un-guiding-principles-age-technology (Accessed: 5 June 2026).
Pellet, A. and Müller, D. (2019) ‘Article 38’, in Zimmermann, A., Tams, C.J., Oellers-Frahm, K. and Tomuschat, C. (eds.) The Statute of the International Court of Justice: A Commentary. 3rd edn. Oxford: Oxford University Press, pp. 819–977.
Permanent Court of International Justice (1927) The Case of the S.S. Lotus, France v Turkey, Judgment [online]. Available at: https://www.icj-cij.org/sites/default/files/permanent-court-of-international-justice/serie_A/A_10/30_Lotus_Arret.pdf (Accessed: 5 June 2026).
Rome Statute (1998) Rome Statute of the International Criminal Court [online]. Available at: https://www.icc-cpi.int/sites/default/files/2024-05/Rome-Statute-eng.pdf (Accessed: 5 June 2026).
Sassòli, M. (2019) International Humanitarian Law: Rules, Controversies, and Solutions to Problems Arising in Warfare. Cheltenham: Edward Elgar.
Schmitt, M.N. (ed.) (2017) Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations. Cambridge: Cambridge University Press.
Shelton, D. (ed.) (2000) Commitment and Compliance: The Role of Non-binding Norms in the International Legal System. Oxford: Oxford University Press.
UNESCO (2021) Recommendation on the Ethics of Artificial Intelligence [online]. Available at: https://www.unesco.org/en/artificial-intelligence/recommendation-ethics (Accessed: 6 June 2026).
United Nations (1945) Charter of the United Nations and Statute of the International Court of Justice [online]. Available at: https://www.un.org/en/about-us/un-charter/full-text (Accessed: 6 June 2026).
United Nations (1965) International Convention on the Elimination of All Forms of Racial Discrimination [online]. Available at: https://www.ohchr.org/en/instruments-mechanisms/instruments/international-convention-elimination-all-forms-racial (Accessed: 6 June 2026).
United Nations (1966a) International Covenant on Civil and Political Rights [online]. Available at: https://www.ohchr.org/en/instruments-mechanisms/instruments/international-covenant-civil-and-political-rights (Accessed: 6 June 2026).
United Nations (1966b) International Covenant on Economic, Social and Cultural Rights [online]. Available at: https://www.ohchr.org/en/instruments-mechanisms/instruments/international-covenant-economic-social-and-cultural-rights (Accessed: 6 June 2026).
United Nations (1969) Vienna Convention on the Law of Treaties [online]. Available at: https://legal.un.org/ilc/texts/instruments/english/conventions/1_1_1969.pdf (Accessed: 6 June 2026).
United Nations (1979) Convention on the Elimination of All Forms of Discrimination against Women [online]. Available at: https://www.ohchr.org/en/instruments-mechanisms/instruments/convention-elimination-all-forms-discrimination-against-women (Accessed: 6 June 2026).
United Nations (1989) Convention on the Rights of the Child [online]. Available at: https://www.ohchr.org/en/instruments-mechanisms/instruments/convention-rights-child (Accessed: 6 June 2026).
United Nations (2006) Convention on the Rights of Persons with Disabilities [online]. Available at: https://www.ohchr.org/en/instruments-mechanisms/instruments/convention-rights-persons-disabilities (Accessed: 6 June 2026).
United Nations General Assembly (2005) Basic Principles and Guidelines on the Right to a Remedy and Reparation for Victims of Gross Violations of International Human Rights Law and Serious Violations of International Humanitarian Law [online]. Available at: https://docs.un.org/en/A/RES/60/147 (Accessed: 10 June 2026).
United Nations General Assembly (2007) United Nations Declaration on the Rights of Indigenous Peoples [online]. Available at: https://docs.un.org/en/A/RES/61/295 (Accessed: 10 June 2026).
United Nations General Assembly (2021) Report of the Group of Governmental Experts on Advancing Responsible State Behaviour in Cyberspace in the Context of International Security [online]. Available at: https://docs.un.org/en/A/76/135 (Accessed: 10 June 2026).
United Nations General Assembly (2024a) Seizing the Opportunities of Safe, Secure and Trustworthy Artificial Intelligence Systems for Sustainable Development, A/RES/78/265 [online]. Available at: https://docs.un.org/en/A/RES/78/265 (Accessed: 10 June 2026).
United Nations General Assembly (2024b) The Pact for the Future, Global Digital Compact and Declaration on Future Generations, A/RES/79/1 [online]. Available at: https://docs.un.org/en/A/RES/79/1 (Accessed: 10 June 2026).
United Nations Human Rights Council (2011) Guiding Principles on Business and Human Rights: Implementing the United Nations “Protect, Respect and Remedy” Framework [online]. Available at: https://www.ohchr.org/documents/publications/guidingprinciplesbusinesshr_en.pdf (Accessed: 10 June 2026).
United Nations System (2022) Principles for the Ethical Use of Artificial Intelligence in the United Nations System [online]. Available at: https://unsceb.org/principles-ethical-use-artificial-intelligence-united-nations-system (Accessed: 10 June 2026).


































