Les limites de la
transparence algorithmique
Cet article en anglais est fondé sur une présentation donnée il y quelques mois lors de la Conférence internationale « Algorithmic transparency and the digital rule of law » organisée à l’école de droit de Sciences Po Paris. Merci à Lucas Anjos et Rebecca Mignot-Mahdavi pour l’invitation.
Abastract
In the face of concerns raised by AI systems in recent years, transparency has emerged as a central governance principle, enshrined in regulations from France’s Digital Republic Law to the EU AI Act. This talk examines the practical enforcement of algorithmic transparency provisions through action-research conducted by La Quadrature du Net, a French digital rights organization. Drawing on five years of Freedom of Information Act (FOIA) requests targeting surveillance algorithms deployed by French public authorities, we document systematic enforcement failures that render transparency requirements largely symbolic. Our findings suggest that transparency operates primarily as a legitimizing device for algorithmic governance rather than as an effective accountability mechanism.
Keywords: algorithmic transparency, FOIA, surveillance, action-research, France
Access the paper in PDF via HAL-SHS
1. Introduction
Transparency is widely promoted as a fundamental safeguard against algorithmic violence. From the EU’s General Data Protection Regulation (GDPR) to the recently adopted AI Act, transparency requirements have proliferated across regulatory frameworks governing automated decision-making systems. Yet transparency as a governance principle for computing technologies is hardly new. Similar proposals have been advanced as “remedies” to computerization controversies for more than half a century — though the term may have been different.
This talk examines the practical limits of algorithmic transparency through the lens of action-research conducted by La Quadrature du Net (LQDN), a French digital rights advocacy group. Between 2018 and 2024, LQDN filed dozens of FOIA requests targeting surveillance algorithms deployed by French public authorities as part of two campaigns: Technopolice (on tech policing) and France Contrôle (on automated welfare services). This sustained engagement with France’s transparency regime provides empirical grounding for assessing the gap between legal promises and enforcement realities.
It proceeds in three parts. It first traces the historical genealogy of computational transparency in France, showing how freedom of information and data protection emerged as twin responses to computerization controversies in the 1970s. Second, for background and as way to bring another disciplinary perspective to this legal conference, I review some Science and Technology Studies (STS) scholarship on transparency’s conceptual limitations as a governance mechanism. Third, echoing findings recently made by other French organizations like the Observatoire des algorithmes publics, I document systematic enforcement failures encountered in our FOIA work, revealing how legal exceptions, administrative resistance, and structural power asymmetries undermine transparency provisions in practice.
2. Historical Genealogy: Computerization and the Promise of Publicity
The contemporary discourse around algorithmic transparency obscures a longer history. Administrative transparency and data protection emerged in the 1970s as key political compromises addressing public concerns about computerization in Western polities. Understanding this genealogy reveals both the promise and limitations of transparency as a governance strategy.
The “Great Reversal” and Its Limits
In the late 18th century, Enlightenment thinkers articulated the promise of a “great reversal” compared to feudal times: privacy for the weak, transparency for the powerful, as Julian Assange would later sum it up. This principle positioned publicity — making state actions visible to citizens — as fundamental to democratic accountability. However, the administrative state that developed throughout the 19th and 20th centuries operated largely through secrecy, justified by appeals to efficiency, rationalization, and state security.
Computerization in the 1960s dramatically intensified these tensions. The prospect of centralized databases containing comprehensive information about citizens sparked unprecedented public controversy (Fuster, 2014). In the French context, revelation in 1974 of the SAFARI project — an ambitious plan to interconnect administrative databases using a single national identifier — provoked such fierce opposition that the government was forced to abandon it.
The 1978 Settlement: CADA and CNIL
The response of French 1970s reformers to these controversies took dual form. In 1978, parliament adopted both the “Commission d’Accès aux Documents Administratifs” (CADA) law establishing freedom of information rights (named after the ombusman body it created), and the data protection law creating the Commission Nationale de l’Informatique et des Libertés (CNIL). As the administrative judge (conseiller d’État) Guy Braibant observed in 1981, these reforms resulted from “the meeting of an idea (transparency) and a technique (computer science)” (Braibant 1981).
This dual framework reflected post-1968 political currents favoring liberalism and more flexible governance forms. Data protection and freedom of information appeared as concessions symbolizing a halt to the centralization of information and maintenance of secrecy that had characterized 1960s administrative modernization. Crucially, however, these reforms left fundamental power structures intact while providing procedural mechanisms for managing public concern – an illustration of wider trend of the time (Tréguer, 2014), of a form of “procedural fetichism” reducing the rule of law to its checks and balances rather than the substantive values it serves to protect.
The Digital Republic Law (2016)
France updated its transparency framework in 2016 through the Loi pour une République numérique (Digital Republic Law). This legislation added provisions specifically targeting algorithmic systems:
- Public bodies must provide general information about main algorithmic processes used in accomplishing their missions;
- Explicit notification should be issued when algorithms play a role in individual administrative decisions, with rights to additional information upon request;
- Thanks to constitutional case-law, source code is ostensibly covered by transparency requirements.
These provisions positioned France as a leader in algorithmic governance. Yet as the following sections demonstrate, legal frameworks and enforcement realities diverge dramatically.
3. Conceptual Limits: Insights from Science and Technology Studies
Before examining enforcement challenges empirically, it is worth considering transparency’s conceptual limitations. Science and Technology Studies (STS) scholars have developed sophisticated critiques of transparency as a governance mechanism that illuminate our empirical findings.
The Black Box Metaphor’s Insufficiency
Kate Crawford and Mike Ananny (2016) argue that demands to “open the black box” fundamentally misconceive contemporary algorithmic systems. “To ask to look inside the black box,” they write, “is perhaps too limited a demand and ultimately an ill-fitting metaphor for the complexities of contemporary algorithmic systems. It sidesteps the material and ideological complexities and effects of seeing and suggests a kind of easy certainty that knowing comes from looking.”
They emphasize that “holding an assemblage accountable requires not just seeing inside any one component of an assemblage but understanding how it works as a system” (Crawford and Ananny 2016, 8). Algorithmic systems comprise not just code but training data, organizational contexts, implementation decisions, feedback mechanisms, and downstream effects. Transparency that focuses narrowly on code disclosure fails to capture this systemic complexity.
Strategic Opacity and Legitimizing Functions
Nicolas Suzor and colleagues (2019) have warned that “the major threat is that transparency will be deployed in a way that obscures the responsibilities of platforms and helps resist demands for systemic change”. Their concept of “meaningful transparency” highlights how disclosure can actually impede accountability when deployed strategically.
Stohl, Stohl, and Leonardi (2016) develop this insight through their concept of “strategic opacity” — situations where organizations share huge amounts of unintelligible data that obfuscate rather than reveal valuable insights. Similarly, Kinchy and Schaffer (2018) document how “staged transparency” directs attention toward certain phenomena precisely to divert scrutiny from more sensitive issues.
These analyses suggest transparency can function as what Foucault might call a “power-knowledge” mechanism, producing particular forms of visibility that reinforce rather than challenge existing power relations. As I demonstrate below, French algorithmic transparency provisions exemplify precisely these dynamics.
4. Enforcement Realities: Systematic Failure in Practice
Between 2018 and 2024, La Quadrature du Net filed dozens of FOIA requests targeting surveillance algorithms deployed by French public authorities. This section documents the systematic enforcement failures we have encountered, revealing how legal promises of transparency are undermined through legal exceptions, administrative resistance, and structural asymmetries.
Successes and Strategic Value
Before detailing obstacles, it is important to acknowledge that FOIA requests have produced valuable results. We obtained documents on public tenders and partnerships between AI-powered video surveillance companies and local authorities, revealing the extent of private sector involvement in surveillance infrastructure. We accessed source code from welfare agencies including the Caisse d’Allocations Familiales (CAF) and France Travail (formerly Pôle Emploi), demonstrating that variable selection systematically targeted the most marginalized households for fraud investigation.
These victories required sustained effort and provided crucial empirical grounding for advocacy campaigns as well as litigation strategies. However, they represent exceptions proving a rule of systematic obstruction.
Legal Exceptions and Expanding Interpretations
First, it is worth stressing that the original 1978 CADA law contains extensive exceptions allowing administrations to refuse disclosure to protect: “deliberations of the Government,” “national defense and foreign policy secrets,” “state security and public safety,” and “in general, secrets protected by law.” These vague formulations provide enormous discretion.
Law enforcement and intelligence agencies enjoy particularly broad exemptions. Article 20 of France’s data protection law authorizes “non-public executive orders” for surveillance systems related to “national security and public security,” effectively exempting such systems from transparency requirements – a possibility that the Government has used extensively despite dubious constitutional grounding.
Crucially, through case-law, interpretations have expanded over time. In 2020, CADA refused disclosure of source code for the AliceM facial recognition authentication system on grounds of information system security. In its 2021 activity report, CADA suggested “this position is likely to apply to any source code” — effectively nullifying algorithmic transparency provisions for the systems raising greatest concern (CADA 2021).
The EU AI Act continues this pattern through blanket law enforcement exemptions, demonstrating how exceptions intended as narrow carve-outs become general rules when security is invoked.
Temporal Strategies: Delay as Denial
Even when requests ultimately succeed, temporal dynamics often neutralize their value. Obtaining documents typically requires lengthy battles with CADA’s ombudsman process, and the public authorities targettted. By the time disclosure occurs — if it occurs — strategic value for human rights defenders has often dissipated. Meanwhile, disclosed algorithm versions are frequently obsolete, superseded by undisclosed updates.
This temporal dimension reveals how procedural rights can be honored in form while defeated in substance. For activists and journalists operating on tight timelines, delayed disclosure functions as effective denial.
Non-Compliance Without Consequences
Perhaps most striking is administrative non-compliance even with positive CADA opinions. Many public bodies simply stop responding once CADA orders disclosure. The Interior Ministry, for example, has refused to provide bilateral policing treaties and internal regulations we know exist. Public authorities like the city of Marseille have refused to disclose a video-surveillance audit that was later disclosed to other requesters.
This head-in-the-sand strategy faces no meaningful sanctions. We are currently preparing legal challenges, but litigation is costly, time-consuming, and uncertain, especially for civil society organizations with limited resources.
Good Faith Presumptions and Invisible Documents
Even when we possess strong evidence that documents exist, administrations can simply claim otherwise — and CADA typically accepts these claims at face value (the Ministry of the Interior has often resorted to that tactic). Meeting minutes and correspondence are almost never disclosed despite being clearly covered by law. Even more shocking is the fact that privacy impact assessments, legally required for “innovative” algorithmic systems affecting fundamental rights, have never been provided in but one occasion (the city of Marseille regarding its AI video-surveillance experiment). In that one case, the CNIL eventually ruled that the methodology was so weak that the whole thing had to be redone from scratch.
This pattern suggests systematic concealment rather than isolated failures. Yet France’s transparency regime places the burden of proof on requesters while presuming administrative good faith — an asymmetry that systematically favors secrecy.
Redaction as Obstruction
When forced to disclose (e.g. with an opinion of the CADA to that effect), administrations often provide documents so redacted to the point of being useless. For instance, CAF claimed that the names of variable names in source code must be hidden to prevent welfare recipients from learning to evade fraud detection — a bogus justification it used to conceal the institution’s hard-coded discriminatory practices.
BPIfrance, which funds many surveillance technology projects through public investment, invoked commercial confidentiality and redacted pretty much the entire documents that they finally agreed to disclose after a positive opinion from CADA.
Trade Secrets Trump Public Interest
When algorithms are developed in partnership with private companies, trade secrets routinely defeat transparency provisions. INRIA, France’s national computer science research institute, refused to disclose research reports produced in partnership with defense contractor Thales, citing intellectual property rights.
This pattern reflects a broader trend toward public-private partnerships in surveillance infrastructure development. When private actors are involved, intellectual property regimes designed to protect commercial interests systematically override transparency requirements meant to protect public rights.
Individual Harm Requirements As Hurdles
French law provides enhanced transparency rights to individuals subject to algorithmic decisions. However, proving individual harm often creates impossible hurdles. When facial recognition is used in criminal investigations, for example, its use rarely appears transparently in case files — making it impossible to prove one was subjected to it, thus precluding requests for information about how it was used.
5. Conclusion: Beyond Transparency
Our empirical findings confirm the critique of STS scholars: transparency operates primarily as a legitimizing device that manages surveillance controversies without meaningfully constraining algorithmic governance. Legal provisions create an appearance of accountability while systematic enforcement failures ensure opacity in practice.
This dynamic is not accidental but structural. Transparency regimes emerge from political compromises that leave fundamental power asymmetries intact. They provide procedural mechanisms for managing public concern while enabling continued expansion of surveillance infrastructure. As Suzor et al. (2019) warn, transparency can “help resist demands for systemic change” by channeling critique into administrative procedures that powerful actors can systematically evade.
What alternatives exist? First, we must recognize that meaningful accountability requires addressing power asymmetries, not just information asymmetries. This means moving beyond disclosure toward substantive constraints on what algorithmic systems can do, not just requirements to explain what they do.
Second, we need enforcement mechanisms with teeth. Transparency requirements without meaningful sanctions for non-compliance are mere exhortation. Independent oversight bodies need investigative powers, more resources, and actual authority to compel compliance — not just advisory roles than can easily be ignored.
Third, we should consider whether a much wider net of digital surveillance applications should be prohibited outright rather than subjected to transparency requirements. Some technologies are fundamentally incompatible with democratic values regardless of how transparent their operation. The question is not how to make facial recognition surveillance accountable but whether such surveillance should exist at all in a democracy.
Finally, researchers and activists must remain vigilant about transparency’s limitations while using available tools strategically. FOIA requests can produce valuable results despite systematic obstruction. But we cannot mistake these tactical victories for strategic solutions. Real accountability requires political struggle and a new-found power balance, not just administrative procedures.
References
Braibant, Guy. 1981. “Droit d’accès et droit à l’information.” In Service public et libertés. Mélanges offerts au professeur Robert-Edouard Charlier Paris. Éditions de l’Université et de l’enseignement moderne.
Commission d’Accès aux Documents Administratifs (CADA). 2021. Rapport d’activité 2020. Available at: https://www.cada.fr/sites/default/files/rapport_2020.pdf
Crawford, Kate, and Mike Ananny. 2016. “Seeing Without Knowing: Limitations of the Transparency Ideal and Its Application to Algorithmic Accountability.” New Media & Society 20(3): 973-89.
Fuster Gloria González, 2014, The Emergence of Personal Data Protection as a Fundamental Right of the EU, Springer Science & Business.
Kinchy, Abby, and Guy Schaffer. 2018. “Disclosure Conflicts: Crude Oil Trains, Fracking Chemicals, and the Politics of Transparency.” Science Technology and Human Values 43(6): 1011–38.
Stohl, Cynthia, Michael Stohl, and Paul M. Leonardi. 2016. “Managing Opacity: Information Visibility and the Paradox of Transparency in the Digital Age.” International Journal of Communication 10: 123–37.
Suzor, Nicolas P., Sarah Myers West, Andrew Quodling, and Jillian York. 2019. “What Do We Mean When We Talk about Transparency? Toward Meaningful Transparency in Commercial Content Moderation.” International Journal of Communication 13: 1526–43.
Tréguer, Félix. 2024. “From Radical Contention to Deference: A Sociogenesis of Intelligence Oversight in the United States (1967-1981).” In Intelligence Oversight in Times of Transnational Impunity: Who Will Watch the Watchers?, edited by Didier Bigo, Emma McCluskey, and Félix Tréguer. New Intelligence Studies. Routledge. https://sciencespo.hal.science/hal-03952830.