Automating the state with untested technology
This coming autumn and winter, Austria's Constitutional Affairs Committee will consider a major overhaul of the country's General Administrative Procedure Act (AVG). The proposed changes would permit government agencies to issue legally binding decisions generated entirely by artificial intelligence, with no human intervention required to review the outcome before it takes effect. The AVG serves as the foundational procedural framework for virtually all administrative action across Austria—from welfare payments and construction permits to business registration and grant distribution. A modification to this single statute therefore ripples across the entire public administration rather than affecting just one domain.
The Vienna-based civil rights group epicenter.works, which is affiliated with the European Digital Rights network, has submitted an open letter to the Constitutional Affairs Committee ahead of the debate, arguing that fully automated decisions without human oversight violate core rights protections. The organisation is also reaching out to digital rights advocates and policymakers across Europe to understand whether other nations are contemplating comparable measures.
Why language models are not simple automation
The draft legislation treats generative AI systems identically to conventional rule-based automation, but the technical differences are substantial and carry direct legal implications.
Traditional automated systems operate deterministically: identical inputs produce identical outputs through traceable logic paths. Large language models function on fundamentally different principles, each raising distinct legal concerns:
- Hallucination. LLMs produce text that appears credible but may be factually incorrect or entirely fabricated. Even specialised legal AI systems exhibit hallucination rates between roughly 17 and 33 percent, and the affected person often cannot detect these errors. When false information underpins a binding administrative decision, it undermines the right to a fair trial guaranteed by Article 6 of the European Convention on Human Rights, since the person cannot meaningfully defend themselves against evidence that does not exist.
- Black box. The mechanism by which the system reaches a particular conclusion cannot be fully explained. This is not a documentation gap but a structural limitation inherent to current models. This conflicts with a fundamental principle of the rule of law: that state power be exercised transparently and subject to review, not merely efficiently.
- Bias. Systematic distortions related to race, income, migration status and other characteristics are embedded in how these models are trained and cannot be eliminated through vendor selection. Without intervention, this creates the risk of systematic unequal treatment along group lines that remains invisible because the system does not expose it, violating the non-discrimination principle enshrined in both EU law and the Austrian constitution.
These are not implementation problems that better engineering can solve. They are intrinsic to how current LLMs operate, and each legal objection flows directly from this technical reality.
Real-world warnings from Austria and the UK
Just weeks before the autumn parliamentary debate, Austria's government-operated AI assistant "ida" provided a cautionary example: it falsely identified a sitting vice-chancellor as a former government official and invented a government minister who does not exist.
A more consequential case emerged from the United Kingdom in July 2026. An Upper Tribunal judge determined that the Home Office had denied an asylum application from a woman fleeing forced child marriage and severe violence by citing a policy document that appears never to have existed. The judge noted that the refusal letter showed signs of AI-generated text and suggested the reference was likely an AI hallucination, cautioning that this would constitute an extremely serious breach if confirmed.
Taken together, these incidents trace a troubling progression: from an Austrian chatbot inventing a minister's name to a fabricated document supporting an actual asylum denial in the UK, precisely the kind of fundamental-rights-sensitive, factually intricate decision that should never be entrusted to a system lacking reliable self-verification.
Two powers, one structural flaw
The draft bill (89/ME) introduces two distinct authorities that each raise concerns:
- Chatbots (§§ 13, 13a AVG) capable of not only providing information but also accepting what a citizen tells the system as a formal submission in a proceeding.
- Fully automated decisions (§ 18a AVG) with genuine legal force and no human participation in the individual case. The law leaves it largely to secondary regulation to determine which proceedings qualify, rather than specifying this in the statute itself.
The second provision encounters a constitutional difficulty that transcends AI governance: under Austrian constitutional doctrine, decisions of this magnitude should be made by parliament through legislation, not delegated to the administration to determine unilaterally. Instead, the draft grants this authority to whichever "top authority" oversees the relevant subject matter—a far more dispersed group than the language suggests. Depending on the issue, this could mean a federal minister, a state government, or one of Austria's approximately 2,092 municipalities, each managing its own local administration. Rather than a single body or small group making this choice, the power to define automation's scope is distributed across potentially thousands of separate decision-makers, each authorising a technology whose risks they may lack the capacity to evaluate, and each also responsible for ensuring their system complies with the EU AI Act's sector-specific obligations. Relying on thousands of independent authorities to verify their own compliance provides inadequate protection. The law contains no built-in exclusion for sensitive domains such as asylum or social welfare; that determination is left entirely to future regulation, decided case by case.
Austrian courts have long held that a human official must retain what is termed "decisive influence" over an automated decision for it to constitute a genuine state action—a standard developed for simple, rule-based systems from decades past. No one has articulated a workable interpretation of that standard when applied to a model incapable of fully explaining its own reasoning. The draft's four safeguards—traceability, testing, intervention capacity, and ongoing monitoring—represent standard information-technology governance practices for any public-sector system. They do not actually establish whether "decisive influence" exists; they circumvent the question.
The draft also places the burden of error on the public. Citizens have two weeks to contest an automated decision, a narrow timeframe when LLM errors are frequently undetectable without careful analysis, whereas the authority can revoke the same decision on its own motion for up to two months, sometimes without identifying a specific error and simply citing a "systemic" one. The government retains the ability to correct its own mistakes later; the individual bears the uncertainty in the interim. Additionally, Austria currently lacks an independent AI oversight body, despite the EU AI Act's requirement for one.
What epicenter.works is demanding
The organisation's demands are clear:
- A human must make the final determination in administrative decisions as the standard practice, not the exception.
- No open-ended delegation for complex or sensitive matters. The law must include an explicit statutory prohibition on automation for proceedings involving particularly complex factual questions or that raise significant fundamental-rights concerns, including asylum and social assistance.
- Parliament must decide, not future regulation. Whether these categories should ever be automated must be settled in the statute itself from the beginning, not delegated to a regulation adopted later by the same authority that would benefit from automating them.
From technical consultation to public debate
In March 2026, the ministry circulated the draft bill for public comment. For months, discussion remained confined to 35 submissions received during the consultation period, a specialised conversation among experts. The draft subsequently entered parliament as a government bill, with debate scheduled for autumn and winter.
epicenter.works published its open letter to the Constitutional Affairs Committee in early September 2026, hoping to influence the process before finalisation. Within days, Austria's national public broadcaster ORF covered the bill on television and online, and public radio featured an interview with the president of Austria's judges' association. The issue has moved beyond a narrow technical discussion among legal-technology specialists.
Is Austria alone?
To epicenter.works' knowledge, Austria stands alone in planning to permit fully automated decisions across such a wide spectrum of administrative functions, with the scope substantially left to future regulation. The organisation acknowledges this claim with caution: no comprehensive, current inventory exists documenting where other European nations stand on this question, and gaps in its own awareness are probable.
Has your country discussed, proposed, or considered a comparable law? If you are aware of anything—or can confirm that nothing of this kind exists—epicenter.works would welcome hearing from you.



