No human required: Austria’s plan for AI-only government decisions

A sweeping change to Austria's administrative law would let authorities issue binding decisions using AI systems with no human ever reviewing the outcome. EDRi member epicenter.works has sent an open letter to parliament, and is looking for input from readers elsewhere in Europe about how other countries are handling, or planning to handle, the same issue.

By epicenter.works (guest author) · October 8, 2026

Austria to allow LLMs to make government decisions with no human oversight

Austria is about to find out what happens when a member state lets large language models write legally binding government decisions, with no human required to review them.

This autumn, the Constitutional Affairs Committee of Austria’s parliament will debate a sweeping change to the country’s General Administrative Procedure Act (AVG). The AVG is the default procedural code for essentially all administrative proceedings in Austria, covering everything from social assistance and building permits to business licensing and public subsidies. A single change to the general code can therefore affect how decisions get made across almost the entire administration, not just in one sector. According to the draft law, authorities would for the first time be allowed to issue fully automated administrative decisions: legally binding rulings with direct effect on a person’s rights, comparable to what other jurisdictions might call an administrative act or order, without a human ever reviewing the specific outcome before it goes out.

Ahead of this autumn’s debate, epicenter.works has written to the Constitutional Affairs Committee, sending an open letter laying out exactly why fully automated decisions with no human review are incompatible with fundamental rights.

Different technology, same law

Let’s be precise about what’s actually being automated, because the draft treats generative AI the same way previous automation laws treated simple rule-based software.

Classic automated administrative systems are deterministic: same input, same output, traceable logic. A system built on a large language model works fundamentally differently in three ways that each map directly onto a legal guarantee:

  • Hallucination. LLMs generate outputs that sound plausible but can be flatly wrong or entirely invented. Even specialised legal AI systems show hallucination rates of roughly 17 to 33%, and errors are often impossible for the affected person to spot. Hallucinated facts underpinning a binding decision affect the right to a fair trial under Article 6 of the European Convention on Human Rights: a person can’t meaningfully exercise that right when the decision against them is built on evidence that doesn’t exist.
  • Black box. How the system arrived at a given output is structurally not fully explainable. This is not simply “not yet documented” but not explainable even in principle with current models. That sits uneasily with a basic rule-of-law demand: that the exercise of state power be transparent and reviewable, not just efficient.
  • Bias. Systematic distortions like race, income level, migration status etc. are baked into how these models are trained and can’t be engineered away by picking a “better” vendor. Left unchecked, this risks group-based unequal treatment that no one notices, because the system doesn’t expose it, touching the principle of non-discrimination, which both EU law and the Austrian constitution guarantee explicitly.

These aren’t implementation flaws. They’re inherent to how current LLMs work, and every legal objection below follows directly from this technical reality.

Not hypothetical: two examples, months apart

Weeks before this autumn’s parliamentary debate, Austria’s own state-run AI assistant “ida” supplied a preview of the problem: it falsely described a sitting vice-chancellor as a former government member and invented a government minister who doesn’t exist.

A more serious example came out of the UK in July 2026. An Upper Tribunal judge found that the Home Office had refused an asylum claim, from a woman who had fled forced child marriage and severe violence, by citing a policy document that, on inspection, appears never to have existed. The judge noted the refusal letter bore the hallmarks of AI-generated content, and suggested the reference was likely an AI hallucination, warning that this would represent an extremely serious failing on the department’s part if confirmed.

Read together, these two cases show an escalation from a chatbot inventing a minister’s name in Austria to a fabricated document underpinning an actual refusal of protection in the UK, in exactly the kind of fundamental-rights-sensitive, factually complex proceeding that should never be handed to a system with no reliable way of checking its own claims.

Two new powers, one big problem

The draft bill (89/ME) gives authorities two new powers that are each individually contentious:

  • Chatbots (§§ 13, 13a AVG) that don’t just inform citizens but can treat what someone tells the system as a formal submission in a proceeding.
  • Fully automated decisions (§ 18a AVG) with real legal effect, and no human involved in the individual case. Which types of proceedings actually qualify for this is largely left to secondary legislation, a regulation, rather than being written into the law itself.

The second point runs into a structural problem that goes beyond AI risk management: under Austrian constitutional law, decisions this consequential are supposed to be made by parliament, through a law, not delegated to the administration to decide for itself. The draft hands that call to whichever “top authority” is materially responsible for the matter at hand, and that’s a far more scattered group than it sounds. Depending on the subject, it could be a federal minister, a state government, or, since Austria’s roughly 2,092 municipalities each administer their own local affairs, a municipal council. There is no single or small set of bodies deciding this: the power to define the scope of automation is spread across potentially thousands of separate decision-makers, each authorising the use of a technology whose risks they may have little capacity to assess, and each one also responsible for making sure their own system meets the AI Act’s sector-specific requirements. Relying on thousands of potential decision-makers to each verify their own compliance is an inadequate safeguard. There’s no exclusion in the law itself for sensitive areas like asylum or social welfare, either. That’s left entirely to secondary legislation, case by case.

Austrian courts have long required that a human official retain what’s known as “decisive influence” over an automated decision for it to count as a genuine act of the state at all, a standard built for simple, rule-based systems decades ago. Nobody has a workable answer for what that standard even means applied to a model that cannot fully explain its own output. The draft’s four safeguards, traceability, a testing phase, the ability to intervene, and ongoing checks, are standard IT governance measures for any public-sector deployment. They don’t actually test whether “decisive influence” exists; they sidestep the question.

The draft also shifts risk onto the people affected by it. Citizens get two weeks to challenge an automated decision, a tight window when errors from an LLM are often invisible without close scrutiny, while the authority itself can revoke the same decision on its own initiative for up to two months, in some cases even without pointing to a specific error, simply citing a “systemic” one. The government keeps the option to fix its own mistakes later; the person on the receiving end carries the uncertainty in the meantime. Moreover, Austria still has no independent AI oversight body, despite the EU AI Act calling for exactly that.

What epicenter.works demands

The organisation’s position is straightforward:

  • A human must make the final call in administrative decisions as the rule, not the exception.
  • No blank check for complex or sensitive cases. The draft must contain a statutory exclusion for proceedings involving particularly complex facts or that are especially sensitive from a fundamental-rights perspective, such as asylum or social assistance.
  • Parliament, not future regulation, must decide. Whether these areas ever get automated should be settled in the law itself from the outset, not left to a regulation decided later by the same authority that would benefit from automating them.

Turning an insider debate into a national story

In March 2026, the ministry sent the draft bill out for consultation. For months, the debate stayed confined to the 35 submissions filed during that process, a technical, insider affair. The draft has since been tabled in parliament as a government bill, and parliamentary debate is scheduled for this autumn and winter.

epicenter.works still hopes the process produces changes before it’s finalised, which is part of why it published its open letter to the Constitutional Affairs Committee at the start of September 2026. Within days, Austria’s national broadcaster ORF covered the bill on television and online, and public radio interviewed the president of Austria’s judges’ association. This is no longer a niche debate confined to legal-tech circles.

An outlier, or the first of many?

As far as epicenter.works is aware, Austria is currently an absolute outlier in planning to allow fully automated decisions across such a broad range of administrative matters, with the scope largely left open to future regulation. But the organisation holds that claim loosely: there is no coherent, up-to-date evidence base on where other European countries stand, and gaps in its own knowledge are likely.

Has a comparable law been discussed, proposed, or is it even considered feasible in your country? If you know of anything, or can confirm that nothing like it exists, epicenter.works would genuinely like to hear from you.

Contribution by: EDRi member, epicenter.works