If "some buggy ML classifier" is allowed to make decisions that trigger broad enforcement, that classifier is, for all intents and purposes, a policy maker. The claim made by the article is somewhat broad relative to the evidence presented, but whether policy decisions are automated or not doesn't really matter.
In the past I would have agreed with this statement, but nowadays I would assume an organization's actions are their policy until they state and act otherwise.