Liability for AI harms

time 5 min 2 sec
Written by

Who is liable when AI systems make mistakes? I have been discussing this publicly and privately for some time now, and while there are a range of views in the legal community it has been my opinion that the existing legal principles of liability are adequate for the task. Yes, there could be difficult questions of fact when complex models and decision-making processes are involved, but over time we have seen how litigants, judges and arbitrators eventually work out how to wrestle with disputes involving new technologies.

Thus, it was with considerable interest that I read the UK Jurisdiction Taskforce (“UJKT”) “Legal Statement on Liability for AI Harms” published last month. At 130 pages it is quite a read (although the end notes start at page 90) so here is my take on the key points made. You can find a copy here: https://lawtechuk.io/ukjt/public-consultation-liability-for-ai-harms-under-the-private-law-of-england-and-wales/

The Legal Statement addresses liability under the private law of England and Wales for harms caused by AI systems. It was prepared in response to growing concern, since the rise of generative AI from 2022, about whether and when AI developers and others in the AI supply chain might be liable for harm.

Although AI has expanded rapidly and various regulatory initiatives (such as the EU’s AI Act) have emerged, these largely do not address civil liability for AI harms, and England and Wales have no AI-specific liability regime. The Statement’s premise is that English common law, being flexible, has historically adapted well to new technologies and can already answer liability questions without bespoke AI legislation. The Statement focuses on non-deliberate harm, on the basis that industry participants generally do not intend to cause harm and that deliberate wrongdoing via AI is not expected to raise materially different legal issues. It excludes intellectual property, data protection, AI use by public authorities, and contract formation issues.

The Statement adopts a technology-neutral definition of AI focused on “autonomy”, meaning an unpredictable relationship between input and output, opacity of reasoning, and limited user control over output, as the feature that drives legal uncertainty.

Liability for AI-caused harm arises either from responsibilities a party has voluntarily assumed (principally through contract) or from liability imposed by law regardless of agreement. Contract is expected to be the primary mechanism allocating liability within an AI supply chain and between AI users and those harmed, subject to ordinary contract law limits such as the rule against excluding liability for personal injury caused by negligence. Where no contract applies, liability will usually turn on the established law of negligence: whether a duty of care is owed, whether the required standard of care was met, and whether a failure to do so caused foreseeable harm. The Statement finds no conceptual barrier to applying ordinary negligence principles to AI failures. As a general pattern, careless AI users and developers of narrow, targeted applications are more likely to face liability, whereas developers of general-purpose “foundation models” are less likely to be liable for harm from unforeseeable or untested uses of their models.

Because AI is not a legal person, no one can be vicariously liable for an AI system’s own actions — but an employer can still be vicariously liable where a human employee acts wrongfully while using AI, applying ordinary principles.

Professionals such as lawyers, architects and doctors must exercise reasonable skill and care in their use of AI just as in any other aspect of their work, judged against the standards of competent members of that profession. A professional may be negligent for using AI inappropriately, choosing an unsuitable model, failing to conduct due diligence, or failing to validate AI outputs, and could equally be liable for failing to use AI where a competent peer would have done so.

Absent a contractual warranty, English law generally leaves the risk of harm where it falls in the absence of fault, though statutory strict liability for death, personal injury or property damage caused by a defective product can apply (currently only where AI is embedded in a physical product such as a robot or automated machine) turning on whether the product’s safety fell below what people are generally entitled to expect.

Ordinary “but for” causation generally applies without special difficulty in AI cases, though evidential challenges can arise; and a developer or deployer is generally unlikely to be liable for a bad actor’s misuse of AI unless the AI was obviously dangerous or misuse could have been prevented but was not, with more extreme circumstances required for more general-purpose AI. By contrast, developers or deployers are highly likely to be liable for harm caused by an AI system acting autonomously, unless that conduct was unforeseeable, with the outcome depending on the AI’s capabilities, its level of autonomy, and the supervision exercised over it. Contributory negligence remains available as a partial defense, with commercial users more likely than non-commercial users to be found contributorily negligent, depending on the facts.

Liability for a chatbot’s statement generally requires that a legal person made or “adopted” the statement, since AI itself is not a legal person; liability can arise where a business holds the chatbot out as speaking on its behalf or represents its outputs as accurate. Defamation liability can attach to those in the supply chain deemed “publishers” of AI output, including those who review content before publication (treated as editors) and commercial deployers who publish AI outputs in business. Statutory protections limit exposure for non-authors, non-editors and non-commercial publishers, and clear AI-generated-content warnings potentially affect both meaning and the “serious harm” threshold. Liability for deceit requires that the AI developer or user intended (or was reckless as to whether) the AI would produce a false statement intended to be believed, turning centrally on the developer’s intentionality.

The Statement concludes that existing English private law — principally contract, negligence, vicarious liability, product liability, causation principles, and the law on misstatements and defamation — is generally capable of addressing AI-caused harm without a bespoke AI liability regime, though outcomes remain highly fact-dependent. Well, that’s what I have been saying …

Written by