Old Law, New Tech: How English Law Can Tackle AI-Related Harms
The rapid adoption of AI has led to a familiar question: does English law need a new liability regime to deal with harms caused by AI? According to the UK Jurisdiction Taskforce’s recent Legal Statement on Liability for AI harms, the answer, at least for now, is no. AI undoubtedly creates new practical and technical challenges. However, those challenges do not necessarily require entirely new legal rules. Existing principles of contract and negligence, supported where appropriate by doctrines such as vicarious liability and strict product liability, remain capable of addressing AI-related claims.
Responsibility will depend on control, not simply involvement
AI systems are rarely created, supplied and used by a single organisation. A typical AI supply chain may involve foundation model developers, application providers, hosting companies, businesses integrating AI into their services and end users. Liability is therefore unlikely to turn simply on who built or supplied the system. Instead, the key question will be who controlled the relevant risk and who was responsible for the act or omission that caused the harm.
Contractual arrangements will often be central to allocating responsibility between the parties involved and the primary starting point for redress. However, businesses developing or deploying AI are of course likely to use warranties, indemnities, service obligations and limitations of liability to manage risk.
Where contractual arrangements do not provide the answer, negligence is likely to remain the main route for assessing liability for AI-related harm. The legal questions remain familiar: was there a duty of care, what standard of care applied, was that standard breached, and did the breach cause the loss? AI may make those questions more complex in practice, but it does not change the underlying legal analysis.
AI does not replace human responsibility
AI systems do not have legal personality. They cannot owe duties of care or be held liable in their own right. Even where an AI system operates with significant autonomy, relevant responsibilities remain with the individuals and organisations that design, deploy and oversee it.
This limits the role of vicarious liability. A person or organisation will not become liable simply because an AI system produces an unexpected or harmful result. Liability will depend on the conduct of those responsible for the system; including decisions about how it was developed, implemented, supervised and used. That said, employers may still be vicariously responsible where employees cause harm through the improper use of AI in the course of their work.
More broadly, the adoption of AI does not transfer responsibility to a technology provider. Organisations remain accountable for choosing appropriate tech tools, putting suitable safeguards in place and monitoring their use.
Professional standards will evolve with AI adoption
AI also raises important questions about professional liability. The duty to exercise reasonable care and skill increasingly includes how technology is selected and used in delivering professional services. A professional may therefore face liability where they rely on AI without proper oversight, choose an unsuitable system, fail to conduct appropriate due diligence, or accept AI-generated outputs without adequate review.
As AI becomes more embedded within professional practice, there may be situations where failing to consider or use appropriate AI tools becomes relevant to whether professional work has reached the standard of care required. The extent to which legal practitioners and other professionals will be determined to have fallen short in future if they do not leverage AI remains to be seen. However, it is clear that as AI use becomes standard and delivers time and cost savings, consideration of whether AI could or should have been used will increasingly be considered in deciding whether work has been performed adequately.
The limits of strict liability
The position is different where defective AI-enabled products cause physical harm. The Consumer Protection Act 1987 provides a route to strict liability where a defective product causes death, personal injury or damage to private property, without the need to prove negligence. However, while the current framework could align with the situation where AI is incorporated into physical products, harms caused by other AI products are more challenging. Software-only AI services, cloud-based systems and foundation models are unlikely, under the current interpretation of the legislation, to fall within this regime. For many AI-related harms, negligence will therefore remain the main route to recovery.
Where disputes are likely to arise
Questions of causation are unlikely to require entirely new legal approaches. The traditional “but for” test will remain the starting point, with courts applying existing principles where AI creates additional evidential or technical difficulties. Similarly, developers and deployers will not automatically be liable where a third party misuses an AI system. Liability will depend on the circumstances, including whether the misuse was foreseeable, whether appropriate safeguards existed and whether reasonable steps could have been taken to reduce the risk.
AI-generated statements are likely to create another area of potential exposure. Recent European case law provides an indication of how courts may approach issues of attribution and responsibility. In Germany, the Oberlandesgericht Hamm held that a company could be responsible for inaccurate statements generated by a chatbot deployed on its website. The Court treated the chatbot’s responses as attributable to the company, rather than as statements made by an independent third party.
The position under English law will depend on established principles of attribution, publication and control. Organisations may face liability where AI-generated outputs are presented as communications on their behalf or where users are encouraged to rely on those outputs. Defamation risks will similarly depend on questions of publication; responsibility and the degree of control exercised over the AI system.
Comment
The UKJT Legal Statement demonstrates the flexibility of English private law and its ability to address liability in the context of new technologies. AI does not remove the need to ask familiar questions about duty, control, foreseeability and reasonable conduct. Litigation around AI-related harms is likely to continue to increase and a key priority for businesses using AI systems will need to be ensuring that appropriate governance, oversight and risk management processes are in place.
As AI becomes increasingly autonomous and embedded into products and services, the key question is unlikely to be whether English law can respond to AI-related harms, which will undoubtedly feature in more cases coming before the courts. The more important question will be whether organisations designing and using those systems have adequately complied with their legal obligations including those under contractual arrangements as well as in relation to the law of negligence, and any applicable regulatory regimes, such as any guidance or Codes of Practice issued by Ofcom.