loading...
Published on August 5, 2026
Liability in the Age of AI: The UKJT confirms existing law can meet new challenges

In July 2026, the UK Jurisdiction Taskforce (“UKJT”) published its ‘Legal statement on liability for AI harms under the private law of England and Wales.’ The legal statement considers a fundamental question: whether and in what circumstances those who have not set out to deliberately cause harm may be liable for harm resulting from the use of AI.

The UKJT’s central conclusion is clear: notwithstanding the novel issues which may arise from the use of AI, English law is a “well-developed flexible common law system”. It “has frequently accommodated novel and disruptive technical developments and demonstrated the ability to provide certainty and predictability in the context of technological innovation” and is able to respond to such issues through the application of existing legal principles albeit this will always be dependent on the facts of each case. In other words, it is business as usual.

Definition of AI

The legal statement adopts a simple definition of AI: “a technology that is autonomous”, emphasising that the key characteristic is autonomy, used to capture: (a) an unpredictable relationship between input and output (the so called “black box problem”); (b) the opacity of reasoning; and (c) the limited ability on the part of a user to control output.  

Liability for loss caused by the use of AI

Typically, an AI supply chain is connected by: (a) data providers, (b) foundation model developers, (c) application developers and (d) users. Crucially, no one actor in the chain has complete visibility of the entire chain. For instance, the AI provider may have limited visibility of how a system will be deployed, just as the deployer may have limited insight into how end users will engage with it. Since harm can arise at any point, identifying where liability should lie is difficult.

The legal statement considers two sources of liability for loss caused non-deliberately by the use of AI: (a) responsibilities voluntarily assumed by parties for a risk – most commonly by contract; and (b) through liabilities imposed by law, such as the law of negligence.

Contractual liability

In practice, contracts are likely to remain the “primary basis on which liability for harm is allocated amongst parties within an AI supply chain.” The question of whether a person is liable for the harm and to what extent will ultimately depend on the terms agreed, including warranties, indemnities, limitations and exclusions clauses, and will continue to be subject to the normal rules limiting freedom of contract.

Non-contractual liability

  • Negligence. In the absence of a contract, liability will depend on established principles of negligence: a person is liable where a duty of care is owed, where that person fails to meet the required standard of care, and where this failure caused foreseeable harm. For instance, a careless user of AI, or the developer of a narrowly targeted application, is likely in many circumstances to be held liable for foreseeable harm, whereas a foundation model developer is less likely to be liable for harm arising from the unforeseeable use of its general-purpose model further down the supply chain. Ultimately, each case will be fact dependant and the court is likely to look to analogous case law for guidance.  
     
  • Vicarious liability. Under English law, AI has no legal personality. Therefore, no one can be vicariously liable for the actions or failures of an AI system itself, and liability must be attributed to a legal person. For instance, an employer may be held vicariously liable for AI-related harm if that harm arises because a human employee acts wrongfully while using AI.

Professional liability.

The legal statement is also a reminder that regulated professionals are subject to an obligation to exercise reasonable skill and care in carrying out their duties which extends to their use of AI. Judged against that standard, a professional may be found negligent for: (a) using AI inappropriately; (b) using an unsuitable model; (c) failing to conduct proper due diligence; or (d) failing to test AI or validate outputs effectively. Conversely, a professional may also be liable for failing to use AI. This will be judged according to whether a reasonable professional of a comparable rank / specialism should have used AI in the context of a specific case which, will turn upon professional bodies’ regulations and/or guidance (if any) and on the expert evidence as to the actions of competent professionals in the field. An example referred to in the legal statement is an auditor’s failure to use an AI system to help detect anomalies and fraud in a business that involved a very large number of similar individual transactions, where individual human review would be impossible in practical terms.

Liability in the absence of fault.

In the absence of contractual warranties, generally the risk of harm lies where it falls in the absence of fault. One exception to this is the statutory imposition of ‘strict’ liability for death, personal injury, or damage to private property caused by a defective product, irrespective of whether the manufacturer was at fault. As it stands, under English law, this strict liability would arise only where AI is integrated into physical products such as an automated industrial machine or a robot.

Factual and legal causation

The legal statement confirms that the general rule that a person will not be liable for loss unless the loss would have been avoided ‘but for’ that person’s acts or omissions is flexible enough to apply in the context to AI. However, evidential difficulties may not allow determination of what would have happened in the counterfactual or where it is conceptually impossible to do so, because the reasoning process between the input and output is often opaque and may not be recoverable after the fact, albeit the legal statement acknowledges that these are not challenges which are unique to AI.

Whether someone who develops AI can be liable for misuse of that AI by a bad actor or for autonomous acts of the AI will be “highly fact-specific”. However, generally, a developer or deployer of AI is unlikely to be held liable for the misuse of AI by a bad actor unless the AI in question was obviously dangerous, or the person had the power to prevent the misuse but failed to do so when it should have done. In contrast, a developer or deployer of an AI system would be liable for harms caused by the AI acting autonomously, unless acts of the kind in question were unforeseeable. This will depend on: (a) the capabilities and limitations of the AI in question; (b) the level of autonomy; and (c) the degree of supervision that is exercised or should have been exercised over it.

In principle, the partial defence of contributory negligence is available. Again, depending on the factual context, a non-commercial user of AI is less likely to be found to be contributory negligent than a commercial user.

False statements made by an AI chatbot

The legal statement explains that liability for negligent or fraudulent misstatement, defamation or deceit may arise where AI-generated output is attributable to a legal person. AI is not a legal person and there is no English authority on the question of whether an AI can make a statement “on behalf” of a legal person. Liability may arise where a legal person holds out an AI chatbot as communicating on its behalf, or if there is an express or implied representation that the chatbot’s statements are correct. Factual analysis is also required to demonstrate whether a person “adopted” a statement generated by AI.

Whilst deceit is harder to establish, it “could arise in the context of false statements made by an AI chatbot, but only if the AI developer or user intended that the AI should produce the false output (or was reckless about whether it was true or false) and intended that someone would believe it to be true”, but the key question would be whether the developer or user had sufficient intent.

Liability may arise for defamatory statements made by AI, but only for a person deemed in law to be a publisher of the AI’s output. Whether a person within the supply chain will be considered a publisher will be fact-specific, but a person who exercises any manual review over the output before it is published will be liable as an editor. The extent to which statements are defamatory, both as to their meaning and to whether the threshold requirement of ‘serious harm’ to reputation is met, will depend on the context of the statement, for instance, are there clear warnings in place that the words are AI generated and may contain hallucinations.

In practical terms, the legal statement appears to suggest that businesses should not assume that the use of AI creates a legal “grey area” in which existing legal principles do not apply. Existing duties relating to contractual risk allocation, reasonable care, product safety, professional standards and reputational harm will continue to apply even where AI plays a role in the decision-making process.

Looking ahead

The legal statement is notable not for creating new rules, but for confirming that existing rules are capable of governing AI-related harms without the need for a wholesale reform. It is also likely to be influential in shaping the development of English law as more AI-related disputes reach the courts.

For practitioners, early consideration should be given to the evidence needed to establish liability, whether that evidence exists, and whether and how it can be preserved. Relevant material may include: AI audits logs, metadata repositories, models cards, documentation about testing. Given the technical complexity of AI disputes, expert evidence is also likely to play a central role in assessing the applicable standard of care, establishing causation and evaluating alleged product defects.

The message for businesses is clear: the courts are likely to focus less on whether AI was involved and more likely to scrutinise, on a case-by-case basis, whether businesses developing, deploying and supervising AI systems have acted reasonably in the circumstances of a case. Questions as to whether adequate controls, the implementation of appropriate testing and monitoring mechanisms, mitigation and identification of foreseeable risks are likely to rise.

Therefore, businesses adopting AI should continue to focus on: (a) ensuring contractual protections are in place across supply chains and existing and new contractual provisions are clearly drafted; (b) implementing robust governance policies and staff training on the proper use of AI; and (c) ensuring that there is sufficient human oversight of the testing and verification of AI systems and their outputs. As AI systems become increasingly sophisticated, and adoption accelerates, disputes are likely to turn on familiar questions of responsibility, foreseeability and reasonable conduct rather than the novelty of the technology itself.

For more information about the content of this article, please contact Matthew Marshall and Krupa Vekaria.

News
Aug 17, 2026
Cometsambre SA v Lloyd’s Insurance Company SA HIG 5321: The English High Court provides important guidance on the duty of fair presentation under the Insurance Act
Introduction and summary In a recent decision, Cometsambre SA v Lloyd’s Insurance Company SA, the English High Court provided important...
Aug 11, 2026
Estate of Euan McIntyre Lindsay & Anor v Outlook Finance Ltd & Anor [2026] EWCA Civ 1005
Can a judgment procured by fraud be set aside against a non-fraudulent party, in circumstances where an innocent party adopted...
Aug 5, 2026
Liability in the Age of AI: The UKJT confirms existing law can meet new challenges
In July 2026, the UK Jurisdiction Taskforce (“UKJT”) published its ‘Legal statement on liability for AI harms under the private...
Jul 28, 2026
Supreme Court Confirms the Narrow Scope of Issue Estoppel
The Supreme Court has delivered an important judgment on the limits of issue estoppel in Skatteforvaltningen (the Danish Customs and...