Published On: July 26, 2026
Authored By: Khwaish Verma
OP Jindal Global University
I. Introduction
I first came across the current issue while reading about Aadhaar exclusions in welfare delivery during my first week here, and kept thinking: where does Indian constitutional law actually stand on this? A senior colleague told me it was “a live problem” — which I took as encouragement to dig further.
The concrete image that stayed with me: you apply for a ration card. Your biometric authentication fails — not because you are ineligible, but because the Aadhaar-linked database has a data-entry error. An automated system denies your application. No official has looked at your file. No one has weighed your circumstances. What remedy do you have? Under Indian law today, the honest answer is: very few good ones.
This is not hypothetical. In Dushyant Kumar Jatav v Union of India, petitioners challenged exclusions generated by biometric authentication failures. The Allahabad High Court encountered a similar problem in Saurabh Kumar v State of Uttar Pradesh, involving algorithmic scoring that denied benefits without any intelligible reasoning being communicated to applicants.[1] Neither case produced a clear constitutional answer about what obligations govern automated state action.
The point is not that automation is bad. Sorting tax returns, scheduling hearings, cross-checking duplicate PAN cards — these are tasks where efficiency is the main concern and individual rights are not directly at stake. The constitutional anxiety begins when the algorithm makes substantive determinations about people: their welfare eligibility, their tax liability, their immigration status. That is what this article focuses on.
II. Algorithmic Governance in India: What Is Happening and Why It Matters
The term “algorithmic decision-making” covers a wide range. At one end are fully automated systems that generate final outcomes with no human involvement. At the other end are systems that assist officials by producing risk scores, where a human technically makes the final call but is heavily steered by the machine’s output. In between are systems that control what information reaches decision-makers, quietly shaping outcomes without anyone realising a choice was made.
What makes this especially difficult is what Frank Pasquale calls the “black box” problem.[2] Most algorithmic systems in Indian administration run on proprietary software. Even when government departments procure these systems, they often cannot fully explain how the model reaches its outputs. The opacity is not always deliberate, but the effect is the same: decisions affecting rights are made by processes that even the decision-maker cannot coherently explain.
This is a basic rule-of-law problem. One of the most fundamental things we learn in administrative law is that a government official exercising power must be able to account for it — to explain the reasons, identify the relevant facts, and be held responsible if the decision was wrong.[3] When a computer makes the decision, none of that is straightforwardly available.
III. The Constitutional Problems
A. Article 14: Arbitrary Action and the Duty to Give Reasons
Article 14 guarantees equality before the law and equal protection of the laws.[4] The Supreme Court has consistently read into it a general prohibition on arbitrary state action — every governmental decision must be based on some rational, articulable principle. As Bhagwati J. put it in S.P. Gupta v Union of India, “every action of the state must be informed with reason.”[5]
The problem with automated decisions is that this requirement of reason becomes very hard to satisfy. In Tata Cellular v Union of India, the Court confirmed that reasoned decision-making is not just good administrative practice — it is a constitutional requirement.[6] But what does a “reason” mean when the decision was made by a machine-learning model that no one can fully explain? If a welfare official says, “I denied your application because your risk score was 0.73,” that is not a reason. It is a label. The person receiving it has no way of knowing what fed into that score, whether the underlying data was wrong, or what they could do differently.
Some argue that the algorithm itself is the “policy” — that as long as the government has a consistent rule, individual outcomes are adequately reasoned. I find this unconvincing. A policy can be lawful in the abstract and still be applied to an individual in an arbitrary way. The constitutional requirement of reasons is about the specific decision affecting the specific person, not just the existence of a general rule behind it. Indian administrative law has always insisted on this distinction, and there is no good reason to abandon it because a computer is doing the applying.
B. Article 21: Fair Procedure and the Right to Be Heard
Article 21 protects life and personal liberty.[7] After Maneka Gandhi, we know that any procedure depriving a person of these must be fair, just, and reasonable.[8] This means the affected person should know the case against them, have some opportunity to respond, and receive a decision from someone capable of actually weighing what they say.
An algorithm cannot do any of these things. It cannot hear submissions or be persuaded by context. When an automated system produces an adverse decision about someone’s benefits, tax liability, or immigration status, and that person has no opportunity to challenge the algorithmic output before consequences fall on them, there is a real Article 21 problem.
The concern is compounded by what might be called error cascades. As the UK Court of Appeal observed in E v Secretary of State for the Home Department, automated systems can replicate and amplify errors across large populations when wrong assumptions or bad data are baked in from the start.[9] In India, where data quality in government databases is notoriously uneven, this is a particularly serious risk. A single incorrect entry in an Aadhaar database could generate systematically wrong automated outcomes for hundreds of people — and if there is no mandatory human review, those errors could persist for years.
C. The Puttaswamy Framework: Legality, Legitimate Aim, Proportionality
The nine-judge bench in Puttaswamy unanimously recognised privacy as a fundamental right under Article 21.[10] Chandrachud J. articulated a tripartite test for any state interference with privacy: there must be a law authorising it, a legitimate state aim, and the interference must be proportionate to that aim.[11] This applies directly to algorithmic systems, because they almost always involve the collection and processing of personal data.
Many algorithmic systems in Indian administration are authorised only by executive orders or departmental circulars — there is no specific parliamentary statute saying “the government may use algorithmic profiling to determine welfare eligibility using the following data for the following purposes.” That level of legal precision is what Puttaswamy seems to require. The proportionality requirement creates further difficulties: using bulk algorithmic profiling of entire welfare populations to detect fraud may be disproportionate when targeted, evidence-based investigation would achieve the same goal with far less privacy intrusion. I am not aware of any such justification being offered for most of these systems.
D. A Note on Algorithmic Discrimination
This is the part I found most troubling in my research. Machine-learning systems are trained on historical data — and historical data in India reflects decades of structural inequality based on caste, religion, gender, and economic status.[12] When an algorithm trained on such data is used to make governmental decisions, it can reproduce those inequalities under a veneer of mathematical objectivity. A welfare-eligibility model might not use caste as a direct variable, but if it uses proxies like address, surname, or transaction patterns, the discriminatory effect can be very similar.
Articles 15 and 16 prohibit discrimination on specified grounds.[13] There is a credible argument that indirect algorithmic discrimination — where a facially neutral system produces systematically worse outcomes for protected groups — should be treated as a constitutional violation. Indian courts have not yet squarely addressed this, but comparative jurisprudence supports the idea that formal neutrality is not enough when structural discriminatory effects are demonstrable.
IV. Why Existing Legal Remedies Are Not Enough
The RTI Act 2005 is probably the first thing that comes to mind here, and I initially thought it might be more useful than it turns out to be.[14] In theory, citizens could ask for an algorithmic system’s source code or training data. In practice this almost never works. Public authorities routinely invoke exemptions for third-party commercial information — because the software was procured from a private vendor — or for national security. Even when information is disclosed, understanding a machine-learning model requires technical expertise that most affected individuals simply do not have.
Constitutional litigation under Articles 32 and 226 faces enormous practical obstacles.[15] Courts lack the technical capacity to audit algorithmic systems. Proving that a specific output resulted from a constitutional violation requires expert evidence that is expensive and hard to produce. The Supreme Court’s reluctance to second-guess technocratic administrative decisions, articulated in cases like Ram Jethmalani v Union of India,[16] can make judges hesitant to intervene even when something has clearly gone wrong. These difficulties fall hardest on the people who most need relief — low-income individuals denied welfare, migrants flagged by immigration systems — who are also least likely to have access to expensive technical litigation.
The DPDPA 2023 was a significant step forward on data protection: it establishes rights of access, correction, and erasure.[17] But reading through it carefully, I think it leaves out most of what matters for algorithmic accountability. There is no right to an explanation of an automated decision. Human review is not required. The exemptions for government bodies in national security and public order[18] are so broad they risk swallowing most of the contexts in which algorithmic state power is most dangerous.
V. What Other Countries Have Done
The EU’s approach is the most developed. Article 22 of the GDPR gives individuals a right not to be subject to fully automated decisions that significantly affect them, unless specifically authorised by law with appropriate safeguards. The EU AI Act 2024 goes further: it classifies AI systems used in welfare administration, law enforcement, and immigration as “high-risk,” and imposes mandatory transparency, human oversight, and conformity-assessment requirements before deployment.[19] What I find compelling about this model is the risk-based structure — not all AI is treated the same, and the framework scales scrutiny to consequences.
In the US, the Administrative Procedure Act’s prohibition on “arbitrary or capricious” agency action has been applied to algorithmic decisions.[20] The White House AI Bill of Rights articulated clear principles, including a right to explanation and a right to human review. I should note that the executive framework has since shifted considerably, which makes the US a less reliable model than it was a year ago — but the principles themselves remain worth noting.
The UK has introduced an Algorithmic Transparency Recording Standard requiring government departments to publish records of the algorithmic tools they use. It is a relatively simple administrative transparency measure, but it does something important: it makes these systems publicly known and creates a baseline that civil society and journalists can use. I found this interesting partly because it does not try to do everything at once — it starts with just making things visible, which seems like a realistic first step for any government.
VI. What India Should Do: Some Proposals
I want to be upfront that these proposals are probably more aspirational than technically worked out — I have not had the chance to consult practitioners who actually litigate these issues, and that shows. With that caveat:
A. A Doctrine of Algorithmic Due Process
Before getting to legislation, I want to suggest that Indian courts could, even without new statutes, develop a doctrine of algorithmic due process from existing constitutional principles. The core of this doctrine would be four requirements for any automated system that makes, or substantially determines, a governmental decision affecting individual rights.
First, transparency: the existence of the algorithmic system and a plain-language description of how it works must be publicly available.
Second, explainability: an individual receiving an adverse automated decision must get an explanation specific enough to allow a real challenge — not just a score, but the primary factors and how they were weighted.
Third, human review: no significant adverse decision should be final without an opportunity to request review by a human official.
Fourth, non-discrimination: algorithmic systems must be audited for discriminatory impact, and where disparate impact on a constitutionally protected group is shown, the burden shifts to the state to justify it.
None of these requirements is alien to Indian law. All can be derived from principles already articulated in Maneka Gandhi, Puttaswamy, Tata Cellular, and S.P. Gupta. The basic structure doctrine[21] — which protects core constitutional values from erosion even through seemingly legitimate reforms — would seem to support the view that wholesale delegation of sovereign administrative power to opaque automated systems is constitutionally impermissible.
B. Legislative Recommendations
Constitutional doctrine can only go so far, and courts move slowly. For systematic accountability, Parliament needs to act. Drawing on the Srikrishna Committee’s data protection recommendations,[22] I would suggest the following.
An Algorithmic Accountability Act should be enacted, requiring a public register of all algorithmic systems used in governmental decision-making. Before any such system is deployed in a high-stakes context, a mandatory algorithmic impact assessment covering accuracy, error rates, and potential discriminatory effects should be completed and published. Individuals should have a statutory right to explanation and a statutory right to human review. Civil liability should attach for harms caused by negligent algorithmic design or deployment.
The DPDPA 2023 should be amended to remove or narrow the broad governmental exemptions that currently undercut its protections. The RTI Act should be explicitly extended to require disclosure of algorithmic systems in plain language, along with independently audited accuracy statistics.
Finally, the Law Commission has previously recommended specialised tribunals for emerging governance challenges.[23] An Algorithmic Review Tribunal — with technical expertise on its panel and expedited procedures — would address the capacity gap in courts that makes algorithmic accountability litigation so difficult. I realise this raises obvious questions about staffing, funding, and independence that I cannot fully answer here. But the basic idea seems right, and similar bodies exist elsewhere.
VII. Conclusion
I started with a simple image: a person denied welfare benefits by a computer, with no explanation, no human who considered their circumstances, and no obvious way to challenge what happened. I think that image captures something real and urgent about the direction Indian administration is moving in.
The constitutional framework — Articles 14 and 21, and the Puttaswamy privacy doctrine — already contains the principles needed to govern algorithmic state power: reasons, fair procedure, proportionality, non-discrimination. An automated decision-making system that provides none of these should be constitutionally suspect, regardless of how efficient it is.
What is missing is explicit doctrinal recognition of these requirements in the algorithmic context, and a legislative framework to enforce them systematically. Other countries have begun building that framework. India, which has one of the world’s most ambitious digital governance programmes and one of its most sophisticated constitutional courts, is well placed to do the same.
The rule of law is not just about what the state can do. It is also about how the state does it — through whom, with what accountability, and subject to what challenge. When the state lets an algorithm decide — without transparency, without oversight, without any real avenue for challenge — that is not just an administrative inconvenience. It is a constitutional problem. And it deserves to be treated as one.
Footnotes
[1] Saurabh Kumar v State of Uttar Pradesh (Allahabad HC, 2018) (unreported); Dushyant Kumar Jatav v Union of India WP (C) No 6490/2018 (Supreme Court of India).
[2] Frank Pasquale, The Black Box Society: The Secret Algorithms That Control Money and Information (Harvard University Press 2015) 3.
[3] State of Orissa v Dr (Miss) Binapani Dei AIR 1967 SC 1269.
[4] Constitution of India 1950, art 14.
[5] S.P. Gupta v Union of India AIR 1982 SC 149, 197.
[6] Tata Cellular v Union of India (1994) 6 SCC 651.
[7] Constitution of India 1950, art 21.
[8] Maneka Gandhi v Union of India AIR 1978 SC 597.
[9] E v Secretary of State for the Home Department [2004] QB 1044 (CA), para 66.
[10] Justice K.S. Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
[11] ibid [180] (D.Y. Chandrachud J).
[12] Cathy O’Neil, Weapons of Math Destruction: How Big Data Increases Inequality and Threatens Democracy (Crown 2016) 8.
[13] Constitution of India 1950, arts 15, 16.
[14] Right to Information Act 2005, s 4(1)(b).
[15] Constitution of India 1950, arts 32, 226.
[16] Ram Jethmalani v Union of India (2011) 8 SCC 1.
[17] Digital Personal Data Protection Act 2023, ss 6, 12–13.
[18] ibid, ss 17–18.
[19] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data [2016] OJ L119/1 (GDPR), art 22; Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence [2024] OJ L1689/1 (EU AI Act), arts 13–14.
[20] Administrative Procedure Act 1946 (US), s 706(2)(A).
[21] Kesavananda Bharati v State of Kerala AIR 1973 SC 1461.
[22] Personal Data Protection Committee, “A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians” (Report of the Committee of Experts under the Chairmanship of Justice B.N. Srikrishna, MeitY 2018) 18–22.
[23] Law Commission of India, ‘Assessment of Statutory Frameworks of Tribunals in India’ (Report No 272, 2017) para 4.1.




