Last month, the UK Jurisdiction Taskforce (UKJT) published its much anticipated Legal Statement on Liability for AI Harms under English law (the Statement).

Whilst the Statement is not legally binding, its authors are a panel of eminent legal professionals and scholars. As such, the Statement carries a high-level of credibility and we would expect to see it cited in due course as the volume of AI cases coming before the courts increases. The Statement therefore provides valuable guidance on how the courts are likely to apply existing common law principles to a variety of AI scenarios.

The authors’ overall conclusion will reassure many organisations. English law is not starting from scratch on AI liability. Existing principles of contract, negligence, professional liability and misrepresentation are generally capable of dealing with AI-related disputes.

We consider below some of the key findings from the Statement.    

English and Welsh common law can deal with AI issues

As the Statement notes, English law is:

… a well-developed flexible common law system [that] has frequently accommodated novel and disruptive technical developments and demonstrated the ability to provide certainty and predictability in the context of technical innovation”. 

In other words, the lack of AI-specific case law or legislation does not mean that AI issues are unregulated by common law. Rather, until specific legislation is introduced and/or cases set a precedent, lawyers should apply existing common law principles to AI issues, just as has been done previously for then new technologies such as the fax, the internet or smartphones, which are now commonplace (or obsolete) but were once considered new, cutting edge and mistakenly “unregulated”.

Contract is king

The Statement focuses on the likely position under English common law, as opposed to under statute or contract.

However, as the authors emphasise, a contract (rather than common law) will very frequently be the primary mechanism by which parties involved in the AI supply chain will allocate responsibility for risk, and liability for loss, with common law only stepping in where a contract fails to address a particular issue or poor drafting requires gaps to be plugged or disputes over interpretation to be resolved.

As such, the message is clear: the best way to allocate responsibility, mitigate risk and manage liability between parties in connection with the acquisition or use of AI systems (as well as avoiding the time and expense of becoming involved in a precedent setting case) remains a comprehensive and well-drafted contract.

Cannot sue AI – it has no legal personality

English law attributes liability for loss and damage either to individuals or to legal entities which the law deems to have a separate legal personality (for example, limited companies).

As the Statement notes, despite the novel and often anthropomorphic qualities of AI, AI does not have a separate legal personality under English law and as such cannot be held liable for loss and damage in its own right.

Whilst that lack of a separate legal personality can present challenges when seeking to apply legal principles based on the question of what a person has (or has not) done or whether one person can be held liable for acts or omissions of another person, in the case of AI those challenges are often more technical/theoretical in nature and it is usually possible to attribute liability based on the use by a person of AI or even potentially in some cases, the failure to use AI.

For businesses, the message is clear: outsourcing decision-making to AI does not outsource legal responsibility.

Vicarious liability

The Statement gives as an example of a person being liable for the acts or omission of another the well-established principle of vicarious liability: employers are typically held vicariously liable for the acts or omissions of their employees.

The fact that Al does not have a separate legal personality does not prevent a person being held directly/vicariously liable for the actions or omissions of an AI system. For example, if an employee makes wrongful use of AI that results in loss or damage to their employer’s clients, the employer will in most cases by vicariously liable.     

The Statement also notes that this would be the case where a non-delegable duty of care exists, such as the duty owed by an NHS Trust to protect its patients from harm. 

Liability for chatbot statements

The issue of liability for false statements made by AI chatbots is fascinating.

Although there is currently limited English case law on the issue, the UKJT suggests English courts are likely to treat businesses as responsible for chatbot statements made through AI systems presented as communicating on their behalf.

That aligns with the approach already being taken by regulators (including the Competition and Markets Authority and Advertising Standards Agency) and with a Canadian case that held an airline responsible for the accuracy of statements made by an AI chatbot.

For organisations deploying customer-facing AI, chatbot outputs should therefore be treated with the same care as any other published communication.

Loss and damage which may be caused by AI

The authors acknowledge that AI has the potential to cause both: (i) financial loss (for example, AI incorrectly predicting loss-making trades; and/or (ii) physical harm (e.g.  property damage or personal injury where AI has direct control over equipment, such as such as autonomous vehicles, or making an incorrect medical diagnosis).

Who can be held liable for AI harms?

Applying existing common law principles to harm caused by AI, a claimant would need to establish:

  • a duty of care is owed; 
  • the relevant standard of care had not been met; 
  • that failure caused the loss or damage alleged to have been suffered; and
  • that loss or damage was sufficiently foreseeable to permit recovery (i.e. the Hadley v Baxendale test).

Evidential challenges for AI claims

The Statement acknowledges that many future disputes will turn not on legal principles but on evidence.

In particular, due to the opaque nature of AI (why did it do what it did? Did it hallucinate?), questions around audit trails, human oversight, record keeping, testing and explainability may become critical. Businesses that can demonstrate how an AI system was selected, trained, tested, monitored and supervised are likely to be in a stronger position than those that cannot.

In short: good AI governance may therefore become as important as the underlying technology itself.

Liability for not using AI?

Some comments made in the Statement have already attracted media reports that professionals are at risk of being struck off for not using AI.

The UKJT highlights the risk that professionals may be liable if they fail to use AI with “reasonable skill and care”, the nature of which in any particular profession or field is not fixed and will change over time, often to reflect advances in science and technology. Scientific or other advances might mean that certain acts or omissions previously adopted by most members of a profession are now considered negligent. The key question is always what, at the relevant point in time, is the standard of care ordinarily exercised by reasonably competent members of the relevant profession with a comparable rank and specialisation?

Conversely, increasingly the point approaches where failing to use AI (e.g. to analyse data or undertake research) will itself be considered negligent.

The result is a potential squeeze from both directions: professionals may need to justify both their use of AI and their decision not to use it.

Not every issue has been solved

While the Statement is broadly optimistic about the ability of English and Welsh common law to respond to legal challenges and uncertainties on the use of AI, it also identifies areas of continuing uncertainty. For example, there are possible gaps in product liability law, particularly in relation to standalone AI software, and situations where harm clearly occurs but traditional negligence principles may struggle to identify fault. The Law Society has already suggested that some of these issues may ultimately require legislative intervention.

Watch this space.