ABSTRACT
As artificial intelligence (AI) takes its place in policing, judicial systems, welfare distribution, employment, and public debate, the law has been unable to catch up and do its job of protecting the human rights of individuals. This article focuses on the relationship between the two by looking into the statutes and case law of human rights. It provides an overview of the international treaties in this area, namely, The Universal Declaration of Human Rights, The International Covenant on Civil and Political Rights, and The European Convention on Human Rights[1], and international instruments related to AI developed and implemented in the EU and at the Council of Europe, such as the European Union's Artificial Intelligence Act and the Framework Convention on Artificial Intelligence[2]. The paper analyses the key cases, including the UK case R (Bridges) v Chief Constable of South Wales Police and the US case State v Loomis, related to the application of privacy, non-discrimination, and due process issues of automated decision-making systems. The last section of the article compares the regulatory frameworks of the EU, the USA, and India providing examples of the different approaches to AI regulation. The article contends that present systems are still considerably reactive, disintegrated, and neglectful of the Global South, thus proposing a rights-by-design framework based on binding fundamental rights impact assessments, real transparency, and workable remedies. It concludes that human rights law, if modified rather than replaced, will still be the most systematic normative framework for regulating AI’s influence on human dignity and autonomy.
INTRODUCTION
1.1 The need for this investigation cannot be considered hypothetical.
The application of AI technologies is growing worldwide in areas directly influencing the rights and freedoms of people. Facial recognition systems have been used in public places without meaningful awareness on the part of the public or informed consent. In addition, legal systems are using proprietary risk-assessment algorithms for bail decisions and sentencing even though concerns regarding their transparency and the possibility of discrimination exist. Many of these systems adopt historical biases present in the data they have been trained on and thus cause discrimination. It is worth mentioning that the legitimacy of these concerns cannot be questioned. The existence of court judgments and governmental inquiries into the matter is proof of this. After these advancements, governing respectively different areas has begun in different parts of the world. To be more specific, there are two main methods used. The first one is used by the EU. The founding principle of this method implies that different countries should adopt a more complete and risk-based method of governance. As an example of this method’s application, there is the Artificial Intelligence Act (Regulation (EU) 2024/1689[3]). This law is designed in accordance with the previously agreed frameworks, such as the one stated in the Council of Europe’s convention. In general, this model implies taking measures against the occurrence of problems in advance by determining various categories of systems and knowing their risks in advance.
The second method is practiced in the USA. This model appears to be more decentralized since no single set of regulations is applied. Instead of establishing a law, the USA would prefer to rely on current legislation governing those social relations. The position of India in this changing environment is quite special. The nation has accepted digital governance and AI-based public administration rapidly; however, it has not undertaken any exclusive legislation in this area so far. The current situation involves constitutional law, regulation according to the sphere of activity, the Digital Personal Data Protection Act, 2023, and other developing policy initiatives. The decision of Justice K.S. Puttaswamy v. Union of India can be viewed as creating the above-mentioned principles in this constitution while it is claimed that there was no case involving AI. The present article indicates that different ways of regulation show that innovations in the future are still incomplete since they do not ensure human rights and liberties. This article explains how analogue regulatory models have shown us that there is room for innovation in this realm, but none of them has confidently achieved the reconciliation of technology with regard to human rights. The existent systems are reactive, fragmented, and implemented in an uneven manner, especially in Global South countries where there are hardly any institutions or regulations. Hence, the task is not only about regulation but also making sure that any design of AI is based on universal principles of dignity, equality, privacy, transparency, and other main ideas. So, the article focuses on the applicable comparative analysis of human rights which covers laws and regulations in the European Union, the United States, and India. It focuses on the way in which the conceptions of human rights are interpreted and whether these regulations can help us cope with new problematics brought by artificial intelligence.
1.2 RESEARCH QUESTIONS
- Do the international human rights instruments that already exist give us enough to work with when the decision maker is a machine rather than a person?
- How have courts actually applied the familiar doctrines, privacy, non-discrimination, due process, to AI-driven decisions, and what does that tell us about the limits of case by case adjudication?
- What does comparing the EU, the USA, and India actually reveal about whether comprehensive statutory regulation works better than litigation-driven governance?
1.3 OBJECTIVE AND METHODOLOGY
The aim here is not to catalogue every AI law in existence, which would be an impossible and rather dull exercise, but to test whether the existing legal toolkit is fit for purpose and to suggest, with reasonable specificity, what is lacking. The method is doctrinal, working from primary sources, statutes, treaties and judgments, and comparative, since a single-jurisdiction study risks mistaking a local quirk for a general truth. Three jurisdictions were chosen deliberately: the EU, because it has gone furthest in legislating; the US because its common-law, litigation-first tradition represents the opposite pole’ and India, because it shows what the problem looks like in a large developing democracy with a strong constitutional privacy tradition but comparatively thin AI specific legislation. Secondary sources, academic commentary and reports from UN human rights mechanisms, are used to sharpen and, where necessary, complicate the doctrinal analysis.
LEGAL PROVISIONS
2.1 HOW THE INSTRUMENTS ACTUALLY OFFER?
The vast majority of the rules and regulations of artificial intelligence have been already developed on the grounds of law that were designed long before this technology showed up. The main international human rights documents were created much prior to when algorithmic decision making, machine learning, and automated governance became part of public administration and business processes. Yet, these documents form the standard framework through which judiciary, regulators, and policymakers evaluate and measure the consequences of AI technologies on fundamental rights. In particular, Article 12 [4]of the UN Declaration of Human Rights omits any mention of automated decision-making but nevertheless provides strong protection against unlawful interference with the respect to one’s private life, family and home. The same is covered with Article 17 of the International Covenant on Civil and Political Rights[5]. Article 26 of the IPCPR establishes the principle of equality before the law and non-discrimination protection. Finally, Article 14 states that parties have the right to a fair and public trial. None of these provisions makes any direct reference to artificial intelligence or automated decision-making, but they are formulated in such a way that enables regulating the results of technological developments, not the relevant technologies.
Human rights law always aimed primarily at safeguarding people from adverse results - like arbitrary behaviour on the part of the state, discriminatory treatment, and denying somebody of procedural fairness - regardless of whether these results came from human beings or from machines.
This goal-oriented construction of the past has recently been embraced by international human rights organizations. In its 2025 submission to the Human Rights Council, The United Nations Working Group on Business and Human Rights stated that the absence of proper human rights due diligence results in the usage of AI systems generating discriminatory effects, infringing privacy rights, restricting access to public services, and negatively influencing the most vulnerable groups of people such as women, children, disabled people, and representatives of ethnic minorities. The report also points to the fact that regulatory responses to the problem are very inconsistent across jurisdictions, with particular reference to developing countries where institutional protection is weak. For this reason, United Nations supports the idea of elaborating human rights impact assessments, ensuring transparency, and employing accountability tools throughout the life cycle of AI systems instead of fixing the problems after they happen.
The ECHR is the main legal instrument at the regional level when it comes to AI-related issues. Article 8 states that everyone has the right to “respect for his private and family life”, and the European Court of Human Rights has interpreted this statement as referring to the collection of personal data by the state[6]. The emergence of technology has made article 8 relevant for problems concerning facial recognition technology, biometric monitoring, and the use of algorithms for processing data. The Charter of Fundamental Rights of the European Union helps to strengthen this protection, since it interprets the right to data protection in article 8; the right to non-discrimination in article 21; and the right to an effective remedy before an independent tribunal in article 47.
2.2 THE NEW INSTRUMENTS BUILT SPEFICALLY FOR AI
The European Union Artificial Intelligence Act, officially known as Regulation (EU) 2024/1689, was enacted on August 1, 2024, and is the first comprehensive legislation in the world that deals with artificial intelligence[7]. The act takes a different route to the normal methodology of regulating AI, by utilizing a risk-based strategy to classify AI systems into four categories, namely: unacceptable risk; high risk; limited risk; and minimal risk. AI systems with unacceptable risks (such as the use of social scoring by public authorities and some forms of real-time biometric identification of people in public areas) are generally banned with very few exceptions for law enforcement and national security[8].
High-risk AI systems, specifically those used in policing, migration, border control, hiring, education, health, and judicial processes are still allowed with strict regulations. All firms have to retain technical documentation, introduce sound risk control practices, ensure that training data is of high quality, put measures in place to protect civil rights, and make sure that human approval exists for these high-risk technologies. However, the most noteworthy characteristic of the AI Act is that it introduces the requirement of completing the Fundamental Rights Impact Assessment before deploying high-risk systems by authorities.
Even though the AI Act aspires to achieve quite a lot, it has faced a lot of criticism. Various civil society organisations, academics, and digital rights advocates stated throughout the legislative period that ultimately, the Regulation allows for a much wider usage of biometrics than it had been originally planned. One of the main accusations that critics level against the AI Act is that certain exemptions for law enforcement, border security, and national security undermine the rights-oriented goals of the Regulation. Thus, the gap is present between the human-centred approach to AI governance declared by the Act and the range of exemptions applicable in respect of the ongoing usage of invasive technologies.
In addition to the AI Act, the Framework Convention on Artificial Intelligence, Human Rights, Democracy and Rule of Law of the Council of Europe was opened for signing on September 5, 2024[9]. This Convention is the very first legally binding treaty that relates to artificial intelligence exclusively. However, while EU AI Act only applies to EU countries, the Convention will apply to all countries regardless whether they belong to EU or not. The idea is to make sure that no state violates fundamental human rights and does not misinterpret the rule of law while using the technology. In addition, individuals will be notified whenever they interact with AI systems but there are also lots of exceptions. One should bear in mind that national security, defence and many scientific researches will not be covered by the Treaty.
2.3 DATA PROTECTION LAWAS A STAND-IN FOR AI LAW
In places where there are no laws regarding artificial intelligence, laws regarding the protection of data have been used to control the actions of artificial intelligence. Despite the fact that protection of data processes was not meant to control artificial intelligence, it has become one of the most important laws existing in order to protect people affected by automated processes. The most suitable case in point is the General Data Protection Regulation. Article 22 of the GDPA allows individuals to be free of the effects of automated processes, because the regulation states that if automated process results in effects which have legal significance, then the individual does not have anything to worry about, if there are no exceptions given by the law[10].
Furthermore, this law also gives a possibility of getting the process questioned and described by the person affected. Although the Article and its provisions are widely discussed, this piece of legislation can be considered one of the first successful attempts to control the automated processes and make such processes responsible for their actions. India has taken a new direction with the introduction of the Digital Personal Data Protection Act, 2023, which creates a consent-based structure for regulating the processing of personal data and establishes a Data Protection Board appointed to oversee enforcement. Although the law introduces various safeguards for privacy interests and the processing of personal data, algorithmic decision making, automated profiling or discrimination resulting from the application of AI technology are not specifically addressed.
This indicates that numerous legal issues related to the use of AI technology still depend on the interpretation of the existing constitution, judicial precedents and special rules applicable to different industries, and not comprehensive legislation dealing with AI. In order to address the created gap with regulations, NITI Aayog released its Principles for Responsible AI, promoting the ideals of fairness, transparency, accountability, privacy protection, safety and inclusion. However, these principles are not binding and will have effect only in case the government and businesses voluntarily comply with them.
CASE ANALYSIS
3.1 BRIDGES v. SOUTH WALES POLICE[11]
One of the most significant merits of the ruling is that it is the first jurisdiction across the globe to successfully challenge law enforcement officials utilizing facial recognition technologies. The South Wales Police's trial conducted from 2017 to 2019 called ‘AFR Locate’ integrated facial recognition features that scanned crowds and checked them against the list of watch-listed individuals. The claimant and civil rights advocate Ed Bridges contended that his right to privacy was violated as per Article 8 of the ECHR among the data protection laws of the country.
The court of appeal agreed with the submissions, however, the attached reasoning was rather exceptional. The legally recognized document does not clearly state the face recognizer to be disproportionate, which clearly contradicts its own acceptance of the fact that the interference with Article 8 of Bridges may actually be proportionate. The court contested the legal framework which lacked a clarity regarding the discretion of officers over the persons on the watch list and the deployment of the technology which was simply unapproved by any laws. Furthermore, the court found the data protection assessment worrisome as it concluded that Article 8 is not applicable to the present case.
3.2 STATE v. LOOMIS: DUE PROCESS AGAINST A BLACK BOX [12]
The situation in America, on the other hand, is quite different. The Supreme Court of Wisconsin had to rule on case number State v Loomis, 2016 WI 68, 881 N.W.2d 749, where it was necessary to decide if the COMPAS risk score may be used for sentencing without infringing judges' due process rights. Eric Loomis was sentenced in connection with a drive-by shooting he was involved in, but since COMPAS is based on a trade secret and nothing could be said of its accuracy, Mr. Loomis could not receive an individualized sentence, and the software's functioning involves discrimination based on gender.
The Supreme Court of Wisconsin ruled in favour of the sentence appealing against it. Courts were allowed to continue using COMPAS with clear limitations set as to its use.
The Court argued that since Loomis utilized his own questionnaire and other public records, he had sufficient opportunity to examine the basis underlying the data as long as the weighting of the algorithm remains concealed. The US Supreme Court refused to hear any further appeals regarding the case, hence Loomis is still the leading case for the time being, although it is only technically binding Wisconsin.
I find Loomis rather less compelling than Bridges, and I think this is worth putting plainly: the Wisconsin courts seemed to think a warning label is equivalent to a remedy. Just being warned that a tool might be biased against you is not the same as being able to verify its actual performance in your case. A number of commentators pursue the same line of reasoning, making the case that the court’s use of language of caution instead of informative; simply establishes a criterion easy for the state to meet and quite weak for the defendant.
COMPARATIVE PERSPECTITIVE
1. THE EUROPEAN UNION
On paper, the EU’s strategy is the most ambitious since it is based on a singular regulation applying in all member states and organized according to levels of risk in accordance with the Charter of Fundamental Rights while also underpinned by the GDPR and soon to be complemented by the treaty of the Council of Europe[13]. One of its advantages is that obligations are enforced even before the system is put in place, along with penalties. Meanwhile, it has its shortcomings, identified by civil society as well as the EU Fundamental Rights Agency itself, which boils down to the fact that the exemptions for law enforcement and migration are so vast that they can encompass most activities that the Act aims to ban, while the criteria for defining “high-risk” are rather unspecific, which means that there are opportunities for further discussions.
2. THE UNITED STATES
There is no equivalent law at the national level in the United States. Instead, AI governance consists of a network of laws that rely on sector-specific regulations (employment discrimination law, credit reporting rules), inconsistent state regulations, and lawsuits like Loomis. This system merits responsiveness since courts can address problems as they arise, but it is fundamentally reactive. Unlike the FRIA in the EU, there is no obligation to conduct any risk assessments before deploying an algorithm; legal recourse is only available after the harm is done and there is someone who has the capability of pursuing legal action.
3. INDIA
India is in a different position. The Supreme Court's historic ruling in Justice K S Puttaswamy (Retd) v Union of India [14]recognised privacy as a fundamental right under the Constitution at such an early time that the government had no time to take legislative action. The Digital Personal Data Protection Act, 2023 [15]has since made it possible to implement a system of data protection based on consent, and even though a Data Protection Board [16]has been established, the new legislation is silent on issues of algorithmic bias and automated decision-making processes.
DISCUSSION
During the course of my research, three key points emerged. Firstly, while there have been signs of progress, the existing human rights frameworks have not been proven ineffective; instead, they have not been enforced adequately. The principles of non-interference, equality, right to fair hearing, and right to appeal have been included in the texts of the law, but it would not be easy to enforce them.
There is a loophole in the enforcement process as the working group on business [17]and human rights pointed out. Secondly, to my surprise, so far courts have been more concerned about procedures than results. Bridges requested legal clarity while Loomis asked for notification about the tool. However, none of the courts required the parties to demonstrate that they had used an accurate and unbiased tool. This is challenging, because the system developed according to the best practices of law could still have some bias.
Exemptions applied to national security, law enforcement and research are evident from every instrument analysed in this study starting from AI act and ending with the framework convention. This is a pattern and point to the fact that state security interests have been granted priority over the interests of individuals, including in such areas as police activities, migration and counter-terrorism where the UN Special Rapporteurs expressed their utmost concerns. The Special Rapporteur has actually stated that predictive analytics must never be the basis for a prosecution or detention decision, which is quite alarming when one regards lack of safeguards from the point of view of UN experts.
CONCLUSION
In summary, after analyzing this specific material, we can conclude that artificial intelligence itself does not need human rights law to be reinvented but rather the correct application of this law to a new type of decision-makers. Both Bridges and Loomis demonstrate that old doctrines legality and proportionality in one part of the Atlantic and due process in another, can still cover algorithmic damage. At the same time, they also illustrate the limit of what procedural remedies can do if the system was not tested and does not actually provide fair decisions. The comparison of the EU, the USA, and India illustrates that no jurisdiction has reached the solution: the EU’s statute has security exemptions undermining its effectiveness; the American model is reactive and imperfect, while India has a strong constitutional background but lacks the adequate legislation.
Reference
[1] ICCPR, arts 14 and 26.
[2] Universal Declaration of Human Rights, UNGA Res 217 A (III) art 12; International Covenant on Civil and Political Rights (ICCPR) 999 UNTS 171, art 17.
[3] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI) (2024) Oj L1689; Council of Europe, Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law, CETS No. 225.
[4] UN Human Rights Council, working group on the issue of Human Rights and Transnational Corporation and Other Business Entertainment
[5] Convention for the Protection of Human Rights and Fundamental Freedoms (European Convention on Human Rights) ETS No 5 (1950) art 8; Charter of Fundamental Rights of the European Union (2012) Oj C326/391, arts 8, 21 and 47.
[6] Regulation (EU) 2024/1689, in particular the prohibited-practices provisions and the high-risk obligations, including the Fundamental Rights Impact Assessment requirement; see European Commission, “AI Act Enters into Force” (1 August 2024).
[7]Amnesty International EU Office, ‘EU’s AI Act Fails to Set Gold Standard for Human Rights’ (April 2024); European Network of National Human Rights Institutions (ENNHRI), ‘European Regulatory Frameworks on AI’ (2025).
[8] Council of Europe, Framework Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law, CETS No. 225 (2024).
[9] Regulation (EU) 2016/679 (General Data Protection Regulation) (2016) Oj L119/1, art 22.
[10] Digital Personal Data Protection Act 2023 (India), Act no. 22 of 2023; NITI Aayog, Priniciples for Responsible AI (Government of India, February 2021); Access Partnership, ‘The key Policy Frameworks Governing AI in India’ (2025).
[11] R (Bridges) v. Chief Constable of South Wales Police (2020) EWCA Civ 1058; see also the first-instance decision, R (Bridges) v. Chief Constable of South Wales Police (2019) EWHC 2341.
[12] State v. Loomis, 2016 WI 68, 881 N.W.2d 749 (Wis 2016).
[13] EU Agency for Fundamental Rights, Assessing High-Risk Artificial Intelligence: Fundamental Rights Risks (December 2025); Amnesty International EU Office (n 7).
[14] Justice K. S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1.
[15] Digital Personal Data Protection Act 2023 (India)
[16] UN Human Rights Council, Working Group Report (n 4).
[17] UN Special Rapporteur on the Promotion and Protection of Human Rights and Fundamental Freedoms while Countering terrorism, Position Paper on the Human Rights Impacts of Using Artificial Intelligence in Countering Terrorism (OHCHR, December 2025).