921 11 23 17/18 | 921 11 21 07 | fcsjc@uva.es | Plaza de la Universidad, 1, 40005, Segovia

State Obligations in the Digital Age

Por Juan García Salamanca

Report A/HRC/62/33, submitted by the United Nations High Commissioner for Human Rights pursuant to Human Rights Council resolution 59/11, examines how the «due diligence» standard — a figure already well established in general international law — applies to artificial intelligence in relation to States’ obligations to respect, protect and fulfil human rights.

Unlike most Council reports on digital technologies, this one treats human rights due diligence not merely as a tool for corporate compliance, but as a State obligation with deep roots in general international law, and to do so it adopts a more narrowly focused and legally technical approach while asking what that State obligation actually requires in practice once artificial intelligence enters the picture.

The central thesis is that due diligence applied to AI is not a new legal category specific to this technology, but a concrete expression of a standard predating AI by decades, developed most systematically in environmental law and, more recently, cyberspace. What is genuinely new is the practical difficulty of applying it to systems that are opaque, data-intensive, deployed at scale, assembled through fragmented cross-border supply chains, and increasingly autonomous through «agentic AI,» involving multiple interacting agents. The High Commissioner argues these characteristics raise, rather than lower, the threshold of State responsibility: already documented risks — algorithmic bias, discriminatory outcomes, automation-driven errors — prevent States from credibly claiming ignorance as justification for inaction.

The report grounds its argument in due diligence’s normative foundations, tracing the doctrine from classic sources — the Trail Smelter arbitration and the Corfu Channel case — to more recent jurisprudence, particularly the Inter-American Court’s May 2025 Advisory Opinion on Climate Emergency and Human Rights, which the report treats as the most advanced judicial articulation of due diligence as a binding, systemic, rights-centred framework for State authority. The «enhanced due diligence» standard from that Opinion — comprehensive, forward-looking risk assessment grounded in the best available science, with independent monitoring, transparency and access to remedy — is transposed directly into the AI context.

On this basis, the report identifies four distinctive AI features challenging due diligence: opacity and limited explainability, compounded by agentic AI’s autonomous multi-agent interactions; scalability, allowing automated decisions to affect entire populations rapidly, with small error rates spreading quickly; AI’s data-intensive nature, relying on privacy-invasive collection and sometimes non-causal correlations; and complex, fragmented value chains spanning hardware manufacturers, cloud providers, data brokers, labelling contractors, and public/private deployers across multiple jurisdictions. This last feature generates «jurisdictional gaps,» where no single State exercises comprehensive oversight over systems whose data is collected, processed and deployed across different countries, letting foreseeable risks — such as exploitative labour in data labelling — escape effective regulation.

The report structures its operational guidance around four due diligence functions. The first is prevention through risk identification, requiring human rights impact assessments across the AI lifecycle, with sector-specific safeguards in sensitive areas like welfare administration, law enforcement, migration and military applications. Decisively, the report invokes the precautionary principle: where risks in these high-impact areas cannot be adequately assessed or mitigated, due diligence may require States to refrain from deployment altogether — treating prohibition, not just regulation, as the only compliant outcome in certain cases. Public procurement is flagged as a significant, often overlooked preventive gap, since many jurisdictions require impact assessments from public authorities in general terms but lack binding standards specifically governing procurement of privately developed AI systems running public services.

The second function is regulating businesses through a «smart mix» of voluntary and binding measures, citing as emerging — though heterogeneous — models the EU’s Corporate Sustainability Due Diligence Directive, the EU AI Act, and South Korea’s AI Basic Act. The third is accountability and access to effective remedies, where the report identifies a structural weakness: existing AI grievance mechanisms often rely on non-binding processes, limited transparency, and trade-secret protections impeding access to justice, compounded by jurisdictional fragmentation in transnational systems. The fourth is participation and international cooperation, framed not as good practice but as a State obligation under Article 25 of the ICCPR, drawing an explicit analogy with environmental governance’s emphasis on joint standard-setting and coordinated oversight to prevent regulatory havens.

Throughout, the report emphasises that due diligence is triggered by foreseeability of harm, not actual prior knowledge — States «know or ought to know» of risks already documented in scientific literature, closing off credible claims of surprise as a defence against inaction. This standard, combined with the precautionary principle’s reduced evidentiary threshold, effectively shifts the burden of proof onto States to demonstrate deployment safety, rather than requiring affected individuals to prove harm has occurred.

Ultimately, the report insists new AI risks must be addressed through due diligence’s specific legal architecture rather than voluntary ethical principles alone, anchoring recommendations in binding doctrine to close the gap between State due diligence for AI and the corporate obligations already codified in the UN Guiding Principles on Business and Human Rights.

The recommendations are correspondingly ambitious — from continuous impact assessments across the AI lifecycle to outright prohibition of high-risk uses, to closing procurement gaps and strengthening international cooperation. What remains comparatively unexplored, consistent with the report’s analytical mandate, is how these obligations would be enforced against States lacking the political will or technical capacity for the required risk assessments — a gap implicitly acknowledged by closing with a recommendation to simply engage OHCHR’s advisory services, without proposing any binding compliance mechanism.

Enlace al informe completo: Aquí

Juan García Salamanca

 

Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *