Due Diligence in the Age of Government-Deployed AI

by | Jul 21, 2026

author profile picture

About Sofia Olofsson

Sofia Olofsson is an independent researcher working at the intersection of international human rights law, artificial intelligence governance, and digital cooperation. Her writing has appeared in the Oxford Human Rights Hub, the Harvard International Law Journal, Tech Policy Press, UNESCO, and IOPScience. She holds a Master of Public Administration from Cornell University and an MSc in Security Studies from University College London. || The views expressed are solely those of the author and do not reflect the positions of the United Nations or any affiliated organization.

As artificial intelligence systems are increasingly embedded into government decision-making – from welfare eligibility checks to automated risk assessments – states face a familiar human rights question in a novel context: what does due diligence require when the instruments of power are opaque, adaptive technologies rather than traditional administrative processes? This piece examines that question from the perspective of independent legal analysis.

Due diligence in international human rights law refers to the proactive obligation of states to take reasonable steps to prevent, investigate, punish, and remedy human rights violations – including those arising from the state’s own systems or through third parties acting under its authority. In the context of government-deployed AI, this encompasses identifying foreseeable rights risks prior to deployment, building institutional capacity to monitor algorithmic outcomes, and ensuring accessible mechanisms for remedy. The concept originates in Velásquez Rodríguez v Honduras (IACtHR, 1988) and has since been developed through subsequent UN treaty body jurisprudence and scholarly development.

Under international human rights law, states have a duty to respect, protect and fulfil the rights enshrined in treaties such as the International Covenant on Civil and Political Rights (ICCPR) and the International Covenant on Economic, Social and Cultural Rights (ICESCR). These obligations are not passive: they require states to take reasonable measures to prevent foreseeable harm to rights holders [8]. This analysis draws in particular on three soft law instruments: the UN Guiding Principles on Business and Human Rights (2011); the UNESCO Recommendation on the Ethics of Artificial Intelligence (2021); and the Council of Europe Framework Convention on Artificial Intelligence and Human Rights (2024). While not binding per se, these instruments provide authoritative interpretive guidance on how existing treaty obligations apply in algorithmic governance contexts.

Under established international human rights law, states bear an affirmative obligation to assess human rights impacts of their actions and adopt measures to address risks. These obligations persist regardless of whether the state develops the technology itself or relies on private vendors. Responsibility cannot be deferred on the basis of third-party involvement – a robust due diligence framework must be in place. More specifically, the obligations derive from: (1) Article 2(1) ICCPR – the general obligation to respect and ensure rights without discrimination; (2) Article 2(1) ICESCR – the obligation to take progressive steps toward full realization of rights; and (3) Principle 1 of the UN Guiding Principles on Business and Human Rights, which affirms that states must protect against human rights abuses by third parties, including private vendors, operating within their jurisdiction.

AI systems pose distinctive challenges for due diligence precisely because they are often non-transparent and adaptive. Traditional administrative instruments can be evaluated against statutory criteria. AI models, by contrast, can change behaviour based on data inputs. These features do not exempt states from their duties; on the contrary, the complexity of the system increases the diligence required. If a state deploys an algorithmic eligibility tool without the capacity to assess how it functions, it places itself at risk of violating core human rights obligations.

Consider the obligation to guard against discrimination. Article 2(1) of the ICCPR requires states to ensure that rights are recognized and respected without distinction of any kind. If a government uses an automated risk assessment tool that systematically biases outcomes against a protected group — and lacks the institutional capacity to analyse or mitigate that bias — it becomes difficult to argue that the state has taken reasonable measures to prevent discriminatory outcomes. The foreseeability of such harm is increasingly documented in academic literature and technical studies, yet states lacking technical oversight networks remain ill-equipped to meet their due diligence obligations.

Similarly, the right to effective remedy — a central component of international human rights law — imposes procedural obligations. Article 2(3) of the ICCPR requires states to ensure that anyone whose rights are violated has access to an effective remedy through competent judicial, administrative or legislative mechanisms. When an AI system produces an adverse decision, due diligence requires that there be mechanisms to challenge that decision and correct errors. Without institutional capacity to audit, review and correct algorithmic outputs, effective remedies remain theoretical.

Crucially, the standard of due diligence is measured by reasonableness, not convenience. States are judged against the backdrop of what is feasible to prevent foreseeable human rights harms. Where a technology is integral to public administration and its risks to human rights are documented, failing to establish oversight mechanisms, transparency requirements or accessible grievance processes raises serious questions under the state’s existing obligations. The fact that AI systems are complex does not diminish the obligation — if anything, it heightens the expectation that states will invest in capacity to govern their use responsibly.

From an independent legal analysis perspective, due diligence provides a familiar legal lens through which to assess the human rights implications of government-deployed AI systems. While soft law instruments do not themselves create new rights, they interpret existing obligations in contemporary settings and are relevant to assessing due diligence. States that deploy AI without such frameworks to monitor and mitigate rights impacts risk falling short of their binding international duties.

 

Share this:

Related Content

0 Comments

Submit a Comment