Skip to main content

AI, the Rule of Law, and Algorithmic Rule by Law

By June 25, 2026Symposia

Nathalie A. Smuha, University of Toronto Faculty of Law

[Editor’s Note: ICONnect is pleased to feature a symposium by the five nominees for this year’s ICON-S Book Prize. This is the second entry in the symposium.]

Nathalie A. Smuha, Algorithmic Rule By Law: How Algorithmic Regulation in the Public Sector Erodes the Rule of Law. Cambridge: Cambridge University Press, 2024

Introduction

Governments are increasingly turning to algorithmic systems, including AI, to interpret, implement and enforce regulation. From allocating welfare benefits to assessing asylum applications, public decision-making is ever more assisted by, or even delegated to, such technologies. This turn to algorithmic regulation carries several potential benefits, not only for the internal efficiency of public administrations, but also for legal subjects. In fact, algorithmic systems are often introduced with the aim of serving people more proficiently, enhancing the enforcement and protection of their rights, and preventing arbitrary decisions. In other words, they are meant to advance the rule of law. However, in practice, instead of strengthening the rule of law, numerous examples demonstrate how public authorities’ reliance on algorithmic regulation can actually undermine the rule of law and even lead to rule by law.

My book, Algorithmic Rule by Law, seeks to navigate this tension. It discusses concrete instances of harmful algorithmic regulation and assesses whether the current legal framework – particularly in the European Union – is apt to deal with such problem. Spoiler: it is not, unfortunately so.

This lack of legal protection is only worsened by the fact that the rule of law is under pressure across the world, with authoritarian and illiberal tendencies rising, including in so-called Western liberal democracies. While I cannot possibly unpack these concerns comprehensively in a blogpost (and would hence gently recommend readers to pick up the book, which is available in open access), I will highlight some key elements in what follows.

The rule of law and rule by law

As is clear from the book’s title, my analysis draws on the contrast between the rule of law and rule by law, two concepts that have been defined in various ways.

My conception of the rule of law focuses on several of its protective normative goals, particularly in liberal democracies: it constrains political power and arbitrariness (we are ruled by laws, not by the arbitrary whims of human beings), it implies the law’s equal application (since all are subject to the law, those who rule and those who are being ruled alike), and it fosters legal certainty and predictability. Yet in order to play this protective role, law relies on textual openness and discretion, which enable the tailored and equitable application of general rules to particular situations (thus, ideally, leading to particularized justice). These features of the law also enable society to grapple with its inherent tensions, for instance, between generality and particularity, and between stability and flexibility. In other words, applying the law is not a mechanical exercise, but requires a thoughtful balancing of norms.

By contrast, with rule by law, I intend to denote a society in which law still has a role to play, yet without its protective goal in mind, leaving it vulnerable to become an instrument of oppression. This happens when law is carelessly applied in an overly rigid and legalistic manner, overlooking its underlying purpose and need for thoughtful balancing – a scenario often associated with ‘legalism’. But it can also occur when law is deliberately used in an attempt to undermine the checks that prevent excessive use of power by those who pursue autocratic or illiberal ends – a phenomenon associated with ‘autocratic legalism’. In each case, negligently or purposely, the law can be applied in a way that undercuts the very protection it is meant to afford.

Algorithmic regulation

This problematic application of law does not leave the algorithmic context unaffected. Algorithmic regulation can cause societal harm by undermining societal values such as the rule of law – especially when used in the public sector. When implemented irresponsibly, each of the rule of law’s underlying principles (as conceptualized, for instance, by the Venice Commission) can be hampered. And rather than doing so through individual decisions, the technology enables this to happen at scale, resulting in a potential systemic breach of the rule of law.

Consider, for instance, how reliance on a centralized biased system can not only undermine equality before the law (potentially even at the level of the entire population), but can also make it far more difficult to know that certain individuals or groups are treated unequally. And rather than enhancing legal certainty, the very opposite can occur through errors and bugs in the system, reliance on spurious correlations, or the system’s inability to apprehend things which for humans are ‘common sense’. In addition, the opacity that typically accompanies the systems’ use can make it more difficult for the legislative and judicial branches of power to ‘check and balance’ the executive’s actions, thereby exacerbating the already existing asymmetry of power between them.

This brings me to a crucial consideration. When laws and policies are transformed from text to code to make them machine-readable and executable, something can get ‘lost in translation’. This transformation is not a mere technical exercise – though it is often treated as such – but a deeply normative one. After all, legal concepts can be interpreted in different ways. Since the design and development choices of an algorithmic system can greatly influence its output, system developers (whom, for ease of reference, I refer to as ‘coders’) hence exercise significant power. This raises the question of who has (or should have) the authority to conduct such ‘translation’, and how we can ensure it corresponds to the legislator’s intention rather than the executive’s (or the private company that develops the system for the executive).

In sum, the very nature of the law and its implementation change when mediated by algorithmic systems. And as I demonstrate in the book, there is a real risk that – when undertaken irresponsibly – this mediation does not advance the rule of law, but actually undermines it and instead fosters rule by law. Under the guise of efficiency, and the veneer of legality, algorithmic regulation can undermine the protection that the law is supposed to afford in a liberal democracy – a threat that I conceptualize as ‘algorithmic rule by law’.

Algorithmic rule by law

To better understand this threat, I identified five pathologies that underpin it. The first is the primacy of techno-rationality: reliance on algorithmic regulation often tends to prioritize algorithm-induced efficiency and procedural rationality over normative values like human rights and administrative justice.

Secondly, administrative actions are no longer determined by trained civil servants, who are bound by deontological rules to serve the public interest. Instead, they are influenced by the handful of people who design and develop algorithmic systems, and thereby gain significant influence over public decision-making. Instead of rule of law, we may end up not with ‘rule of code’, but with ‘rule of coders’, as they are the ones who shape the system’s (and hence, indirectly, the law’s) affordances. Moreover, these coders necessarily use their discretion ex ante in a centralized manner, rather than ex post when applying general rules to particular situations to thoughtfully balance out the law’s tensions.

The third pathology concerns the automation of legalism. Reliance on algorithmic regulation can reduce the law’s inherent openness and ambiguity to an overly formalized and narrow shape, leading to a legalistic approach instead. The fact that discretion at the street-level is reduced also weakens the possibility to correct the law’s hard edges where needed.

This is, fourthly, coupled with a deficit of accountability.Theopacity that typically accompanies the design and implementation processes of algorithmic regulation tends to diminish the possibility to exert oversight over the executive’s operations, and to ensure that constitutional checks and balances are maintained.

Finally, reliance on algorithmic regulation also introduces a systemic vulnerability into the legal system as a whole. After all, the functioning of algorithmic systems rests on the establishment of an underlying technical infrastructure. The systems and infrastructure are not only inherently malleable (with a few clicks of a mouse, their parameters and affordances can be changed almost instantly, without anyone noticing it), but they can also be deployed in a way that undermines the law’s protection in a systemic way.

Let me stress that not all instances of algorithmic regulation necessarily lead to algorithmic rule by law. I am depicting a worst-case scenario, but one that has, sadly, proven to be non-hypothetical. Moreover, it is important to keep in mind that the manifestation of algorithmic rule by law can occur both negligently and deliberately. Once again, two scenarios are possible.

Under a first scenario, a government may introduce algorithmic regulation with good intentions, yet without considering the risks I described. An example is the Dutch Childcare Benefits Scandal, where the negligent use of algorithmic regulation scaled an already highly problematic legalistic policy, thus compounding the injustice that occurred. Such a scenario not only adversely affects the rule of law, but also puts in place a scaled algorithmic infrastructure that a future, less well-intentioned government, could use for less benign purposes.

Under a second scenario, a more autocratic-minded government can purposely introduce algorithmic regulation under the pretense of merely optimizing the executive’s efficiency, while in fact pushing through illiberal policies and benefitting from algorithmic opacity. As I mentioned elsewhere, one can think here of the US Department of Government Efficiency’s reliance on algorithmic systems to terminate research grants related to equity and diversity, or Hungary’s intended use of facial recognition systems to monitor and counter pride gatherings. Evidently, neither of these scenarios is desirable.

Going forward

Yet the situation is not without remedy. First of all, it makes sense to explore which legal mechanisms already exist to help face this threat, and to make strategic use of them where possible. While most jurisdictions have at least some rules in place that can (partially) curb the excesses of algorithmic rule by law, virtually all have significant gaps in protection. My book’s analysis focuses on the EU legal order in particular and examines legal safeguards in both primary law (such as Treaty provisions dealing with the rule of law and with infringement procedures) and secondary law (such as the Conditionality Regulation, the General Data Protection Regulation, and the brand-new Artificial Intelligence Act). However, as already alluded to in the introduction, even the EU’s extensive regulatory framework is deficient in countering the mentioned risks.

Several legal, organizational and technical measures can be adopted to offer better protection. These range from enabling public participation in decisions about ‘algorithmization’; and ensuring oversight and accountability not only of the systems’ output, but also of the choices made ‘upstream’ in the development process; to strengthening constitutional checks and balances more generally. Yet implementing such measures will not be easy, particularly given the geopolitical pressures behind the ‘race to AI’.

Across the globe, there is a strong impetus to adopt algorithmic systems in the public sector – a goal embedded in practically all national AI strategies – all the while underestimating how such adoption can fragilize the rule of law both in the short and in the longer term. Despite many concrete examples of harm, the threat of algorithmic rule by law is simply not (yet) on lawmakers’ agendas. I sincerely hope my book can help change this, and that it can inspire further research as well as regulatory action in this area. Yet most of all, I hope it can act as an acute reminder of why the rule of law matters, and why – in this digital age – upholding its protective functions is more important than ever.

Suggested ctiation: Nathalie A. Smuha, AI, the Rule of Law, and Algorithmic Rule by Law, Int’l J. Const. L. Blog, Jun. 25, 2026, at: http://www.iconnectblog.com/ai-the-rule-of-law-and-algorithmic-rule-by-law/

Leave a Reply