The Compromis for the 2027 Philip C. Jessup International Law Moot Court Competition identifies, among its principal issues, what the International Law Students Association describes as “sanction designations generated by artificial intelligence”. The agreed facts are that Rendor’s Bureau of Financial Security uses an artificial intelligence system to generate a preliminary list of persons and companies potentially satisfying the criteria for targeted sanctions. Officials then “independently reviewed and verified” the factual basis of each proposed designation before making recommendations to the Prime Minister. The sanctions are subject to annual review, and designated persons and companies may seek judicial relief.
This hypothetical is rather carefully constructed, as it usually is Jessup problems. The AI system does not formally impose a sanction, and it is not like a human official simply presses a button accepting an algorithmic recommendation: there is an intervening process of factual verification, followed by a political decision and, at least in the case described in the Compromis, access to domestic courts. The facts therefore place students in a much more plausible and difficult setting than the familiar image of an autonomous machine taking a decision on behalf of the state.
I would like to use that setting to ask a narrow question: what does due process require when AI helps a state identify the individuals or companies against whom coercive economic measures will be taken? I argue that the presence of a human decision-maker cannot by itself resolve the procedural problem: where an AI system materially shapes who becomes the object of state scrutiny, due process may require sufficient information about that role to allow the affected person to contest the path that led to designation. The central idea is contestability: human involvement remains important, although its significance under the law depends upon what the human actually reviews and upon what the person affected can subsequently challenge.
Targeted sanctions and the older problem of procedural fairness
Targeted sanctions have long posed a procedural difficulty for international law. They are attractive partly because of their apparent precision: instead of measures directed against an economy as a whole, asset freezes, travel restrictions and related measures can be directed against named individuals and entities. Precision, however, intensifies the consequences of identification. Once coercion is organised through lists, the process by which a person enters the list acquires immediate significance. In Kadi, the Court of Justice of the EU insisted upon effective judicial protection in relation to restrictive measures implementing United Nations sanctions. In Kadi II, the Court required the competent EU authority, when a listing was challenged, to establish that the reasons relied upon were well founded. The persons concerned had to be placed in a position to make their views known effectively, while the courts had to be capable of examining the information or evidence supporting the listing. A related concern appears in the ECtHR case law. In Al-Dulimi and Montana Management Inc v Switzerland, the Court addressed measures implementing a United Nations sanctions regime and stressed the need for appropriate judicial scrutiny of listing measures carrying extremely serious consequences. The case confirms that access to a court has little value if the court cannot engage meaningfully with the basis upon which coercive measures were imposed.
This case-law developed in a world in which the difficult questions concerned secret intelligence, inaccessible evidence, reasons for listing and the relationship between international sanctions regimes and domestic or regional guarantees. AI adds another layer, as it may influence the process at a stage before the reasons eventually presented to the target have even crystallised. International law therefore has to consider the process of selection as well as the evidence supporting the final decision.
The first stage: identification
The most interesting feature of the Jessup hypothetical is the sequence in paragraph 35. The Bureau of Financial Security begins with an AI-generated preliminary list, and officials subsequently verify the factual basis of each proposed designation. An AI system can process corporate records, financial transactions, public statements, contractual relationships and other information, and identify multiple entities as possible candidates for sanctions. Human officials must then investigate those one hundred entities and independently confirm that twenty satisfy the criteria in the law. The ultimate decision may rest upon reliable evidence. The designations may all be substantively justified, but even so, the AI system has exercised considerable influence over the state’s use of investigative attention as it determined, or at least strongly influenced, which entities entered the field of official scrutiny. AI, in other words, effectively sets the agenda. Administrative resources are finite and officials rarely investigate every person or company that could conceivably satisfy a sanctions criterion. A system that generates the pool of candidates therefore participates in the allocation of state attention. Its influence may survive a subsequent human assessment, because the human assessor begins from a population already selected by the machine. Accuracy alone, therefore, cannot exhaust the due-process inquiry. A human official may verify every allegation made by a system that systematically over-selects companies from a particular country, sector or corporate structure because of the data upon which it was trained or the proxies through which risk is inferred. Each individual designation could be supported by evidence: the verification exercise would still tell us very little about those similarly situated companies that never entered the list, or about the variables that caused one company to receive investigative attention while another did not.
The international law of sanctions is comfortable asking whether there is evidence supporting the designation of X. AI may require an additional inquiry into how X became a candidate for designation. I do not suggest that every use of software in an investigation creates a new procedural right: a database search, a spreadsheet or a conventional risk model can also structure attention. It is the degree of algorithmic influence that is crucial. An AI tool that merely organises material already selected by officials presents a different problem from a system whose output defines the population that officials will investigate.
The second stage: human verification
The Compromis anticipates the obvious response: Rendor’s officials independently review and verify the factual basis of each proposed designation. This is a strong safeguard as it reduces the risk that an erroneous machine output will travel directly into a coercive legal measure, and preserves an identifiable human decision-maker who can be held institutionally responsible. The increasingly common phrase “human in the loop”, however, can conceal more than it reveals. There are several forms of human involvement, and their significance depends upon the task assigned to the reviewer: a person may check that the evidence associated with a recommended target is accurate; another person may reconsider the inference drawn from that evidence; a third person may also interrogate the operation of the system itself: why the target was selected, which variables were decisive, whether relevant data were missing, whether proxies generated systematic skew, and whether comparable cases were treated consistently. These are different exercises. The Jessup facts specify factual verification, though they do not say whether officials examine the process that produced the preliminary list. That silence produces the central puzzle in the problem. Verification can establish that Castell Group did what the government says it did, but it does not necessarily establish why Castell Group entered the investigative pool, whether the AI system treated comparable companies similarly, or whether the system relied upon an inappropriate proxy in selecting it for scrutiny.
Human review should therefore be assessed functionally: did the reviewer have access to information about how the system produced its recommendation? Could the reviewer depart from the recommendation in practice? Was the reviewer trained to identify limitations in the system? Did the review extend to the basis for selection, or only to the factual allegations assembled after selection? Was there any procedure for detecting systematic patterns across recommendations? A human signature at the end of the process says very little without answers to questions of this kind. This approach also avoids an unhelpful debate about whether AI “makes” the decision. Public administration has always involved distributed decision-making: investigators, databases, analysts, officials and ministers may each contribute to a final measure. AI can be analysed in the same institutional terms. The relevant issue is the degree and character of its contribution to the exercise of public power.
The third stage: contestation
The strongest consequence, in my view, concerns the position of the target. Due process is relational: it is concerned with the ability of a person affected by public power to understand, answer and challenge the case that justifies its exercise. If AI has materially contributed to the route leading to designation, meaningful challenge may require some access to information about that contribution. This does not entail disclosure of source code in every sanction case: source code may reveal very little to the person affected and may be protected by legitimate interests relating to security, confidentiality or intellectual property. A demand for complete technical transparency could also be disproportionate. A more useful question is what information is necessary to make the challenge effective.
Depending upon the system, that information might include the fact that AI was used; the purpose for which it was used; the categories of data considered; the principal factors relevant to selection; known limitations; the level of human involvement; and sufficient information to identify significant errors or inappropriate proxies. In some cases, disclosure to an independent court or specialised reviewing body may provide protection where disclosure directly to the target would compromise legitimate public interests. The point is that the reviewing process must be capable of engaging with the AI contribution when that contribution is sufficiently important to the adverse measure.
Article 14 of the 2024 Framework Convention on Artificial Intelligence supports this approach, as it requires parties, within its terms, to ensure that relevant information about AI systems with the potential significantly to affect human rights is documented and, where appropriate, made available to affected persons. The information must be sufficient to enable them to contest decisions made or substantially informed by the use of the system and, where relevant and appropriate, the use of the system itself. Article 15 adds a requirement for effective procedural safeguards where an AI system significantly affects the enjoyment of human rights. The accompanying Explanatory Report identifies technical complexity, data-driven operation, opacity and information asymmetry as features that can impair a person’s ability to exercise rights or use procedural safeguards, and also explains that information should be sufficiently clear and meaningful to allow the person concerned to use it effectively in proceedings. Crucially for the Jessup scenario, the Report treats “substantially informed” as a threshold: every use of AI in decision-making does not activate the same procedural demands. Human oversight is identified as one possible safeguard where AI substantially informs decisions affecting human rights.
I would resist reading these provisions as establishing a general international right to an explanation of every algorithmic operation. The concept of contestability connects the amount and type of information required to the practical possibility of challenging an exercise of public power, but also fits comfortably with the existing trajectory of sanctions jurisprudence. Kadi questions whether a listed person can know and answer the case against them and whether a court can test its evidential basis. AI extends that logic upstream: where algorithmic selection has substantially shaped the case that comes to exist, the reviewing body may also need to examine that contribution.
A correct decision can still raise procedural problems
There is a final point which I think deserves emphasis. Discussion of AI and legal decision-making may begin with error: hallucinated information, biased data, false positives or unreliable predictions. These are serious concerns, though they can obscure a more interesting legal possibility: an AI-assisted decision may be substantively correct and still generate a procedural problem. If one assumes, in the Jessup problem, that every factual proposition used to justify the sanctions is true, and also that the human officials conduct a conscientious investigation and correctly conclude that Castell satisfies the applicable criteria, nothing in that scenario eliminates the possibility that the AI system played a decisive role in selecting Castell from a larger population of potential targets through criteria that the company cannot identify or challenge.
This point is especially important in sanctions regimes because selection is central to their operation. A targeted measure is, by definition, selective. Legal scrutiny naturally concentrates upon whether the selected person falls within the relevant criterion. AI requires one to look one stage earlier and question how the state constructed the class of persons to whom it chose to apply that scrutiny.
The answer cannot be that every target has a right to reconstruct every internal investigative choice made by government: states retain legitimate interests in confidentiality, effective enforcement and the protection of intelligence sources. Procedural rights are routinely balanced against such interests. My claim is more modest: once algorithmic selection substantially shapes the exercise of coercive public power, its role becomes part of the procedural environment in which effective review must operate. A legal system cannot assume that independent verification of the final evidence automatically answers questions created at the selection stage.
From the Jessup problem to international law
The Jessup Compromis does not clarify, for obvious reasons, whether Rendor’s use of AI violates international law. Rendor can point to independent factual verification, a final human decision, notification, judicial challenge and annual review; Astoria can ask whether those safeguards permit any scrutiny of the process through which Castell was identified as a target in the first place. The fictional dispute is valuable because it isolates a problem that real legal systems will increasingly encounter.
I would formulate the emerging principle in terms of contestability. The greater the contribution of AI to an adverse exercise of state power, the stronger the case for procedures enabling the affected person, and any reviewing court, to understand and challenge that contribution to the degree necessary for effective review. Such procedures need not require complete technical disclosure, and they do require more than the ritual assurance that a human official remained somewhere in the process.
For international law, this approach has the additional advantage that it does not require the invention of an entirely new catalogue of “AI rights”. Existing concepts such as reasons, evidence, access to review, equality, proportionality and procedural fairness already provide much of the necessary vocabulary. The actual challenge is to apply them to a decision-making process in which public power may be shaped before the formally responsible human actor begins to act. When an algorithm builds the list and a human decides whom to sanction, the relevant inquiry is not exhausted by asking whether a human remained in the loop. International law must also question whether the person placed in that loop can meaningfully contest how the algorithm put them there.