// analysis
When AI asks you to pay: who decides the next step?

Who owns the debt, what the software decides, and how a debtor can challenge the result: a documentary investigation into AI debt collection in France.
When AI asks you to pay · Part 1
Read Part 2: examining the performance claims.
On page 7 of its French privacy notice, Intrum Corporate describes automated scoring that can inform whether a debt file should be referred for judicial recovery. Automation is therefore described as operating before a message reaches the debtor: it can help determine what happens to the case. [1]
That distinction matters. A conversation may sound entirely ordinary even though a system has already selected the case, chosen a contact channel or prepared an offer. Conversely, a language model may write the reply without having any authority over the amount demanded or the decision to pursue a claim.
Investigating AI debt collection means looking beyond the conversation. Who owns the claim? Which company is acting on that owner’s behalf? What information reaches the software, and where can a person challenge the result?
This documentary investigation concerns consumer debts in France. Material from other countries is identified separately. No reconstructed testimony or test of a live collection system is presented as evidence.
The sender may not own the debt
The creditor holds the right to demand payment. It may instruct a collection company to act on its behalf. Under the French rules governing third-party out-of-court collection, the written agreement must specify matters including the basis of the claim, the amounts to be collected and the collector’s remuneration. Outsourcing collection does not, by itself, transfer ownership of the claim. [2]
A sale is different. An assignment transfers the claim to a new owner, which may then appoint a collector of its own. Changing the creditor and changing the company that contacts the debtor are distinct events. [3]
Under the general French Civil Code rules, unless the debtor has already consented to the assignment, it must be notified to them or acknowledged by them before it can be asserted against them. Certain defences remain available against the buyer, including those inherent in the debt. Selling a claim does not, as a general principle, remove a dispute about whether it exists. Special rules may apply to particular financial transactions. [4]
The technology supplier has another role again. An investigation needs to establish separately who develops the software, who configures its rules and who owns the claim. One group may perform several functions, but that does not make the legal entities or their responsibilities interchangeable.
This map helps locate the relevant evidence. The underlying contract and account records establish the basis of a demand. The collection mandate describes the authority granted to the collector. Product documentation explains what a customer can automate. None is a substitute for the others.
A claim must be verifiable outside the interface
France’s consumer-protection authority, the DGCCRF, explains that a claim must be established, quantified or quantifiable, and due. These conditions concern the obligation to pay, not how convincingly a payment portal presents it. [5]
The burden of proof works in both directions. A party demanding performance must prove the obligation; a party claiming to have been released must show payment or another event that extinguished it. Investigators therefore need both the records supporting the original demand and the payments or corrections made afterwards. [6]
For collectors covered by Articles R124-1 to R124-7 of the French Code of Civil Enforcement Procedures, the collection letter must identify the collector and creditor, explain the basis of the demand and separate principal, interest and ancillary amounts. Subsequent collection steps must refer to that letter and its date. This does not mean that every text message must reproduce the full letter. The chapter concerns collection on behalf of others and provides for exceptions where a profession has its own rules. [7] [2]
Collection costs require a separate check. Without an enforceable title, they generally remain the creditor’s responsibility. The law provides exceptions, including certain legally required acts; a court can also charge a debtor acting in bad faith with specified necessary costs. Buying or operating an AI system does not automatically make its cost payable by the consumer. [8]
This groundwork is essential when attributing an error. A payment may already be missing from the data sent to the collector. If the model accurately repeats an incorrect balance, it has not necessarily invented the debt, but it has not corrected it either. The original information, the transfer and the resulting action need to be examined separately.
Before the system speaks, it makes choices
Public descriptions reveal several functions. They do not establish that every function is active on every case.
In a Belgian brochure about Ophelos, Intrum says message openings, clicks, logins and debt size help determine the timing, channel and content of communications. It describes reinforcement learning, in which the system adjusts its choices in response to the outcomes being sought. This is a supplier’s description published in Belgium, not an observation of French cases. [9]
PAIR Finance describes classifying incoming messages, including requests for more time, instalments and disputes, before routing their handling to a person or a generated response. Ophelos also advertises language models that identify circumstances requiring additional support. These are company descriptions of functionality, not independently validated performance findings. [10] [11]
A practical distinction helps keep the investigation precise. A fixed rule schedules a reminder. A score estimates a probability. An action-selection mechanism chooses the next step. A language model writes a response. Software with the necessary permissions can then implement a change. Combining those functions does not make them equivalent.
The system’s objective matters just as much as its architecture. Getting a response, collecting a first payment and completing an affordable repayment plan are different outcomes. Improvement in the first does not establish improvement in the others.
Nor does a click establish an ability to pay. Silence may have several explanations. The relevant question is how an operator handles that uncertainty, rather than treating a prediction as a verified fact about an individual.
Deployment claims also need the right level of precision. In a statement published on 25 July 2025, Intrum listed France among the countries where Ophelos had gone live. The announcement did not identify the modules active in each portfolio. A national rollout is not evidence that generative AI is used throughout the business or that collection operates autonomously from end to end. [12]
What does referral for judicial recovery actually mean?
Intrum’s French notice states the company’s view that its automated decisions have no legal or similarly significant effect because contractual rights remain unchanged. It also says a person can request human reassessment and that human experts regularly supervise AI responses and decision logic. That stated supervision does not establish prior review of every case. These remain the company’s descriptions, without an established regulatory endorsement. [1]
Referring a case for judicial recovery does not mean an algorithm issues a judgment. It is not immediate authority to seize assets either. Compulsory enforcement requires, among other things, an enforceable title establishing a quantified and due claim. Selecting a file for further action and satisfying the conditions for enforcement are separate stages. [13]
The issue here concerns what happens to the person before any eventual judicial decision. Article 22 of the General Data Protection Regulation (GDPR) governs decisions based solely on automated processing that have legal or comparably significant effects. The French data-protection authority, the CNIL, explains that a decision can have a significant impact without formally changing a person’s rights. [23]
There are exceptions, including contractual necessity, specific legal authorisation with safeguards, and explicit consent. Their application depends on the circumstances and the relevant protections. A score is therefore neither automatically prohibited nor a general licence to automate decisions. [14]
A precedent helps frame the inquiry. On 7 December 2023, in the SCHUFA case, the Court of Justice of the European Union held that a score can constitute an automated decision where businesses give it a determining role in lending decisions. The case was not about Intrum or French debt collection. Its relevance here is that the practical influence of a result matters, even where another company acts on it afterwards. [15]
Assessing the collection process therefore requires operational evidence. Does the score recommend referral or trigger it? Does a person examine the supporting records beforehand? Can they reject the recommendation, and do they actually do so? What consequences follow for the person concerned?
The public documents reviewed do not answer that complete set of questions. They provide grounds to investigate the system’s authority, not grounds to declare an infringement.
Identifying an AI does not explain its decision
A more immediately observable question is whether an automated interlocutor identifies itself. The European Commission confirms that the transparency duties in AI Act Article 50 have applied since 2 August 2026. For covered systems that interact directly with people, providers must ensure people are informed of their artificial nature at the first interaction, subject notably to the exception where this is obvious. That particular duty does not cover a score operating solely in the background. [16]
Disclosure and explanation serve different purposes. Knowing that a machine is speaking does not explain the amount demanded, where its data came from or who authorised an offer.
The GDPR imposes separate information duties. Where data obtained elsewhere are used to contact a person, Article 14 generally requires information about the processing by the first communication, subject to its stated exceptions. The source of the data is among the information to be provided. [14] [24]
The absence of a new consent request does not itself establish unlawful processing. Consent is one of several legal bases under the GDPR. Another basis, such as legitimate interests, requires its conditions to be met, including balancing those interests against people’s rights. It does not remove the requirements concerning purpose, data minimisation and accuracy. [17]
A correction has to reach the system taking action
One scenario worth investigating is a correction made by the creditor that fails to reach a copy still being used for reminders. This is a possible failure mechanism, not an incident established in this investigation. It shows why acknowledging a mistake and correcting the process are different things.
The right to rectification covers inaccurate or incomplete personal data. The CNIL also explains that corrections must be communicated to recipients of the data, unless that proves impossible or involves disproportionate effort. A courteous acknowledgement cannot, on its own, establish that the correction has reached those recipients. [18]
Where data accuracy is disputed, restriction of processing can be requested while it is checked. This does not cancel a debt or universally halt proceedings. Some uses remain possible, notably for establishing, exercising or defending legal claims. [19]
An access request can help reconstruct a case by obtaining the data held and information about their origin, rather than another copy of general terms. The CNIL explains that a controller must also obtain assistance from processors holding relevant information. Access does not automatically extend to every internal document or to other people’s data. [22]
The 27 February 2025 Dun & Bradstreet Austria judgment, concerning automated credit assessment, further clarifies the explanation required in the situations it addresses: people must be able to understand which data were used and how. Trade secrets do not justify a blanket refusal; the relevant authority or court must be able to balance the interests involved. This is not an automatic right to receive source code. [20]
For the person being pursued, useful information may be much more concrete: which payment record was used, what result was produced and which action followed? That is where an error can be located and its correction checked.
Measuring whether the case was resolved
Automation can offer benefits. A system that quickly retrieves a payment record or makes it easier to correct an error could provide a genuine service. Lower processing costs are not inherently contrary to a debtor’s interests. The question is what the system resolves and what it leaves unresolved.
Response speed is therefore an incomplete measure. Was a dispute actually recorded? Did an offer take verified information into account? Can an authorised person take over the case? The same questions apply when the first contact is with a human agent.
There is also a basic security step: verify the company through a known channel, independently of any link in the message. France’s Cybermalveillance.gouv.fr recommends such checks for suspicious communications. Preserve the original message and do not give sensitive information to an unauthenticated recipient. An unfamiliar name does not prove fraud, but convincing language does not prove authenticity either. [21]
The documents reviewed shift attention towards decisions made before the conversation begins. Establishing their effects will require configurations and execution records linking an input to a decision and a subsequent action in a real case. A tool can make collection easier to administer. Assessing its value also requires knowing whether the person asked to pay can get the underlying claim checked.
For further context, our investigation into how personal traces become saleable profiles follows the move from observation to inference. Our article on personal data after a contract ends examines copies and recipients. The profiling glossary entry distinguishes evaluating a person from making a fully automated decision.
Method and limitations
Public documents reviewed on 24 September 2026 include French legislation, CNIL and European Commission publications, CJEU press-office releases and operator documentation. The Court’s press releases summarise judgments; they do not replace the full judgments and are not binding on the Court.
No interviews seeking responses from the companies, individual case investigation or platform tests were conducted for this version. Company documentation establishes what operators say, not the actual performance of each module. The publication date of Intrum’s notice cannot be established from its filename alone. The findings do not measure an error rate or establish an infringement by a named operator.
The diagrams explain principles, rather than reproduce a verified company architecture. Rules specific to public debts, business-to-business claims and special procedures are not extrapolated to the cases discussed here.
Sources and documents
All references were consulted on 24 September 2026. Dates below identify publication, a displayed update or the effective date of a statutory provision, as indicated. French-law references remain French sources; this English edition does not substitute another jurisdiction’s rules.
- Intrum Corporate. French debtor privacy notice, p. 7. Publication date not established; version viewed on 24 September 2026.
- Légifrance. Code of Civil Enforcement Procedures, R124-1 and R124-3. Applicable versions checked on 24 September 2026.
- Légifrance. Civil Code, Article 1321. Version effective from 1 October 2016.
- Légifrance. Civil Code, Article 1324. Version effective from 1 October 2016.
- DGCCRF. Out-of-court debt collection: the applicable rules. Displayed publication date: 24 October 2025.
- Légifrance. Civil Code, Article 1353. Version effective from 1 October 2016.
- Légifrance. Code of Civil Enforcement Procedures, R124-4. Version effective from 2 February 2013.
- Légifrance. Code of Civil Enforcement Procedures, L111-8. Version effective from 19 March 2014.
- Intrum Belgique. Ophelos personalisation brochure, p. 1. Undated document published in Belgium.
- PAIR Finance. French-language description of AI functions. Undated page; version viewed on 24 September 2026.
- Ophelos. French-language AI product description. Undated page; version viewed on 24 September 2026.
- Intrum. Ophelos expansion to Portugal and Italy. Published 25 July 2025; France is listed among earlier deployments.
- Légifrance. Code of Civil Enforcement Procedures, L111-2. Version effective from 1 June 2012.
- CNIL. GDPR, Chapter III, particularly Articles 14 and 22. Regulation dated 27 April 2016; text checked on 24 September 2026.
- CJUE, service de presse. Case C-634/21, SCHUFA: press release 186/23, p. 1. Judgment and press release: 7 December 2023.
- Commission européenne. FAQ on AI Act Article 50 transparency obligations. Displayed update: 24 July 2026; applicable from 2 August 2026.
- CNIL. GDPR, Chapter II, Articles 5 and 6. Regulation dated 27 April 2016; text checked on 24 September 2026.
- CNIL. The right to rectification: correcting your information. Page viewed on 24 September 2026.
- CNIL. The right to restriction of processing. Page viewed on 24 September 2026; read with GDPR Article 18.
- CJUE, service de presse. Case C-203/22, Dun & Bradstreet Austria: press release 22/25. Judgment and press release: 27 February 2025.
- Cybermalveillance.gouv.fr. Phishing: protective steps. Published 10 January 2020; displayed update 7 May 2026.
- CNIL. Responding to a data-access request. Displayed publication: 13 June 2017; version viewed on 24 September 2026.
- CNIL. Profiling and fully automated decisions. Displayed publication: 29 May 2018.
- CNIL. Informing people and ensuring transparency. Displayed publication: 29 July 2019; body identifies an update on 26 July 2019.
This analysis is not investment advice.
// cite this analysis
l0g, “When AI asks you to pay: who decides the next step?”, l0g.fr, published September 24, 2026, updated September 24, 2026, https://l0g.fr/en/analysis/ai-debt-collection-1-who-decides-reminder/
$ cd ../analysis