The Interplay of AI, International Law and Human Rights in the Digital Age : Author: Palak Khatri

International human rights law was built to bind states to their borders; AI operates across all of them. Three concrete examples illustrate this mismatch: the CNIL’s 2021 fine against Clearview AI, which fell outside any binding international regime; the 2020 SyRI case, in which the Hague District Court struck down an algorithmic welfare-fraud system under the European Convention on Human Rights; and the Aadhaar judgment, in which the Indian Supreme Court upheld a similar biometric system under a proportionality test.

ARTICLE

Palak Khatri

9/13/2026

Abstract

International human rights law was built to bind states to their borders; AI operates across all of them. Three concrete examples illustrate this mismatch: the CNIL’s 2021 fine against Clearview AI, which fell outside any binding international regime; the 2020 SyRI case, in which the Hague District Court struck down an algorithmic welfare-fraud system under the European Convention on Human Rights; and the Aadhaar judgment, in which the Indian Supreme Court upheld a similar biometric system under a proportionality test. A comparison of these rulings reveals the inconsistent results obtained by courts applying decades-old privacy and equality provisions to AI systems, precisely because there is no binding international standard governing the technology, a gap unfulfilled by non-binding instruments such as UNESCO’s 2021 Recommendation on the Ethics of Artificial Intelligence. The article argues that to fill this gap, binding procedures, like mandatory algorithmic transparency, should be linked to an existing enforcement mechanism rather than voluntary declarations to be interpreted by domestic courts.

Keywords: Artificial Intelligence, Privacy, International Law, Human Rights, Algorithmic Transparency, Soft Law, Proportionality

An Introduction to the Legal Gap

In late 2021, France’s data protection authority, the CNIL, fined a US-based technology company, ‘Clearview AI’ €20 million for the unconsented extraction of billions of images from public sources using an AI-driven facial recognition system. This violation fell outside the reach of binding international regulations. The imperilled right was privacy, codified under Article 12 of the UDHR. International law sits at the nexus of AI systems designed to transcend geopolitical borders, and human rights defined to be universal. However, only domestic laws are equipped to penalize AI-related abuses that cross those borders, leaving protection reliant on jurisdiction rather than the universality international law promises.

The threats posed to human rights by AI are structured by two factors: opacity and scale. Article 12 is reinforced by Article 17 of the ICCPR, shielding individuals from ‘arbitrary interference’ with privacy. These rules envisioned a world of discrete, traceable acts of surveillance, not a machine-learning model making millions of deductions from scraped data with no attributable actor. In either scenario, AI not only makes it difficult to safeguard a right, but negates the human actor on which international law was built, compelling courts and regulators to stretch these provisions to govern a technology they were never drafted to cover.

Two Courts, Two Answers

This misalignment unfolded specifically in the 2020 SyRI case, where the Hague District Court assessed an automated system deployed by the Dutch government to counter welfare fund fraud by linking separate databases which ended up identifying individuals as high-risk, mostly in low-income areas. A coalition of civil society groups challenged this system under Article 8 of the ECHR, arguing that the government’s lack of transparency left the flagged individuals with no way of knowing why they had been targeted. The court ruled that if the government interferes with privacy, its methods must be clear enough so that the individual can defend themselves. Since it wasn’t, the court struck this system down for disregarding basic human rights. The panel held that preventing welfare fraud was legitimate, but doing it through a hidden algorithmic process broke the legal equilibrium. This is the same pattern as in the Clearview case wherein a domestic authority, instead of an international one, ends up as the only actor able to respond.

Setting this against India’s K.S. Puttaswamy (Aadhaar-5J.) v. Union of India, the Supreme Court upheld the core structure of the biometric identification scheme while invalidating the mandatory linkage to private entities like bank accounts. The Aadhaar system, like SyRI, was an algorithmic platform which handled biometric matching, verification and validation across the UIDAI database. However, where the Dutch Court treated ambiguity as prejudicial, the Indian apex court affirmed the state’s justification of delivering targeted welfare to over a billion people as a valid objective proportionate enough to pass the three-fold privacy test established in the 2017 K.S. Puttaswamy judgement as long as the linkage to private sector remained non-mandatory. Two structurally similar systems, same legal tests, but two opposite rulings proving that no consistent global standard yet exists for the regulation of AI’s human rights impact.

This divergence is exactly what international soft-law instruments intended to correct, and precisely what they fell short on, since none of them bind states that adopt them. The UNESCO Recommendation on the Ethics of Artificial Intelligence was unanimously adopted in November 2021 by all 193 member states during UNESCO’s 41st General Conference. It calls for transparency, proportionality and human supervision that resonates with both SyRI and Aadhaar rulings, but only as a recommendation and not a treaty. It creates no obligation that states can be held to. A more effective approach is not another recommendation, but rather a binding treaty with minimum procedural standards. Instead of leaving each domestic court to find such solutions alone, rules like mandatory algorithmic transparency and the right to explanation should be enforceable the way GDPR’s provisions are, by attaching them to the UN Human Rights Committee’s mandate to protect privacy under Article 17 of the ICCPR.

Conclusion

Artificial intelligence did not create new human rights; it created new ways of infringing the ones we already have, across the jurisdictions international law was never built to reach. The SyRI and Aadhaar rulings highlight how domestic courts provide different answers to the same question. Whether the world ever lands on a single, global standard doesn’t come down to what domestic courts decide. It depends on whether states are willing to join hands. This willingness is not hypothetical; on 15 May 2026, the European Union ratified the Council of Europe’s Framework Convention on Artificial Intelligence, making it the first binding international AI treaty. Whether these protections extend beyond European borders, and whether the world joins them, will decide if Clearview, SyRI and Aadhaar remain isolated rulings or the last warnings of their kind.

References:

· K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1.

· K.S. Puttaswamy (Aadhaar-5J.) v. Union of India, (2019) 1 SCC 1.

· NJCM v. Netherlands (SyRI), C/09/550982/HA ZA 18-388, ECLI:NL:RBDHA:2020:1878 (Dist. Ct. The Hague, Feb. 5, 2020).

· Universal Declaration of Human Rights, G.A. Res. 217 (III) A, U.N. Doc. A/RES/217(III) (Dec. 10, 1948).

· International Covenant on Civil and Political Rights, Dec. 16, 1966, 999 U.N.T.S. 171.

· Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, Sept. 5, 2024, C.E.T.S. No. 225.