The lack of a bespoke AI liability framework in England has led to a degree of uncertainty as to how questions of civil liability would be decided by an English court. The UK Jurisdiction Taskforce (UKJT)[1] sought to address this uncertainty in its Legal Statement on Liability for AI Harms under English Private Law (legal statement), which examines the circumstances in which and the legal bases on which English law is likely to impose liability for AI harms unintentionally caused. Its conclusion is, broadly, that English is well-equipped to answer these questions with sufficient certainty as it is. For now, at least.
The legal statement also looks specifically at liability for false statements made by AI chatbots, which we will consider in a following blog post.
The bases for imposing liability
The starting point is that AI cannot be held liable in its own right as it does not have a legal personality under English law. Where harm has been caused by AI, liability can only be attributed to a legal person (an individual or corporate entity) and will only be attributed in one of two scenarios: the person has voluntarily assumed responsibility, or the law imposes liability regardless of whether the person has voluntarily assumed liability.
Contract is, of course, the most common mechanism by which a person voluntarily takes on responsibility for a risk. Where a contract governs the situation in which harm arises from AI, liability will simply be a matter of determining the meaning of the relevant contractual provisions. The UKJT considers that in many – perhaps the majority – of cases, the chain of contracts between the various actors involved in the supply and use of AI will be the most important legal framework. However, as the normal, well-established rules of contractual interpretation can be applied in these cases with relative ease, the legal statement is more concerned with the other situation – namely, the imposition of liability where there is no contract (or there is a contract but it does not address liability for AI harm).
In noncontractual cases, liability will largely fall to be determined in accordance with the law of negligence. This, therefore, is what the legal statement primarily explores, considering each element of a negligence claim and applying it in AI contexts.
The law of negligence
In English law, a person is liable in negligence where that person owes a duty of care to another, fails to meet the required standard of care and thereby causes foreseeable harm to the other person. As the UKJT notes, the law of negligence has proved itself to be capable of rapid evolution and enormous flexibility, so there is no conceptual reason why its principles cannot be applied to harms caused by AI failures even though it does not appear to have been so applied to date.
The form of liability analysis is essentially the same whether the harm caused is physical or economic harm. However, in purely economic harm cases, English law requires that a special relationship has been voluntarily assumed by one person to another. In practice, therefore, liability for purely economic harm will for the most part be limited to professional negligence cases (which we consider below) and false statements made by AI (which we will consider in our following blog post).
Duty of care
Many of the circumstances in which one person will be deemed to owe a duty of care are already well established – manufacturers to consumers, doctors to patients, employers to employees, drivers to other road users, to name a few that would be relevant in the AI context. In novel situations, the court considers the closest analogies in the existing law and applies them by incremental extension.
In many cases, the addition of AI to the scenario will simply be considered a tool of those who exercise control over it; it would not change the underlying position as whether there is a duty of care in any given circumstance.
For noncommercial third parties (i.e., an individual not in the AI supply chain) harmed by AI, the most obvious target for a claim will often be the commercial AI user, as that is who they have had contact with. That does not mean that they actually are the appropriate defendant. How far up or down the AI supply chain the duty of care extends will primarily depend on whether the fault and the harm suffered were foreseeable.
By way of example, the UKJT suggests that while a foundation model developer would be unlikely to owe a duty to protect against harms that arise as a result of their model being used for unforeseeable purposes and not sufficiently tested by an industry participant further down the supply chain, that foundation model developer may be held to owe a duty where harm is foreseeably suffered as a result of foreseeable use.
Note should be taken here of the UKJT’s comment that a party in the AI supply chain that has taken active steps to push out updates to their software to address risks of harm may be more likely to be deemed to owe a duty of care.
Standard of care
Once a duty of care is established, the next issue is the standard of care that is owed. In nonprofessional negligence cases, the standard of care is to act as a reasonable person in their position would act in the circumstances.
This will be highly fact specific and will usually be the subject of expert evidence in any proceedings. However, at a minimum, anyone in the AI supply chain should be aware of and (where appropriate) be implementing industry guidance. The UKJT suggests that industry standards will present courts with a “useful yardstick” as to what represents reasonable practice, and it make specific reference to the AI Standards Hub in this context.
Note should be taken here of the UKJT’s comment that in cases against users and those that deploy AI systems, the court will often need to examine not only the AI that was deployed but also whether reasonable steps were taken to select a model, and indeed to decide whether it was reasonable to use AI at all.
Professional negligence
In the vast majority of professional negligence cases, there will be a contract between a professional and their client that sets out the services to be performed and will be likely to contain an express or implied term that the professional must carry out the services with reasonable skill and care. In addition to the contractual obligations, the professional will also generally owe a concurrent duty of care at common law to exercise reasonable care and skill.
The standard of care in this context is to act in a way that a reasonable member of the profession with comparative rank and specialisation would have acted. That will involve the professional exercising reasonable care and skill in determining whether and, if so, how to use AI.
Again, this will likely be matter of expert evidence. The courts are likely to consider regulations or guidance produced by the relevant professional body. In this regard, the UKJT notes that while the guidance being produced by professional bodies currently tends to be fairly high level, more guidance and regulation is likely to emerge over time. The important message here is that this is not a static standard – given the rampant pace of development in AI systems, what is reasonable now may be negligent in the not-too-distant future.
Careful note should be taken here of the UKJT’s list of indicators of breach of duty, namely:
- Failure to conduct proper due diligence on an AI system (particularly new and/or innovative systems or systems from an untested provider)
- Not having sufficient understanding of the AI system being deployed
- Depending on the significance of the AI use, transparency may be important
- Damaging confidentiality of a client’s information is likely to be negligent
- Failure to ensure there has been sufficient testing to the check the AI system is suitable and appropriate for the task envisaged
- Failure to exercise oversight of the AI system’s output
The UKJT recognises that it may be difficult in practice for a professional to undertake due diligence and/or monitor outputs. In those circumstances, it suggests, the court may conclude either that there is a limit to what professionals can reasonably be expected to do, or that the professional should not have used the AI tool at all.
Although there will be circumstances in which a court finds that AI should not have been used, it is important for professionals to be aware that failure to use AI for a task when a professional exercising reasonable care and skill would have done so, can also lead to liability.
Causation
The final element in a claim for negligence is that the harm suffered must have been caused by the breach of duty. Causation is a two-stage enquiry: first the factual, then legal.
1. Factual causation
In the case of a breach of contract, the breach must be a ‘substantial cause of the loss’. In negligence, it has to be shown that the loss would not have been suffered ‘but for’ the breach.
This is likely to be one of the most contentious elements of many claims, and the UKJT highlights two potential sources of significant causal uncertainty: gaps in the evidence that arise because material has been destroyed, tampered with or simply not gathered, and the uncertainty that may arise owing to the opacity of AI itself.
The UKJT makes two interesting suggestions as to how absence of evidence of causation could be dealt with. The first is that where the absence of evidence is due to the defendant’s failure to record information that it reasonably should have, the court might take a ‘benevolent’ approach to the affected third party or make certain evidential presumptions (by adjusting its approach to evidence on particular factual issues). The second is that it may be possible to fill gaps in the factual evidence with expert evidence and, in particular, expert evidence obtained through experimentation (e.g., by running simulations). Even though the autonomous nature of AI and the number of potentially relevant inputs may preclude conclusions being reached with certainty, English civil law does not require certainty but operates on the balance of probabilities, which permits a degree of uncertainty and ‘is well suited for experimental proofs’.
With regard to the difficulties in establishing causation due to the opacity of the AI system’s function, the UKJT suggests that two principles developed in discrete areas of the law of negligence may be applied to bridge any gaps. The first is the principle that a claimant just needs to demonstrate that the defendant’s breach ‘materially increased the risk’ of the harm that was suffered. he second is the principle that where it is impossible to identify a single ‘but for’ cause of the harm owing to the presence of multiple contributing factors, the claimant just needs to demonstrate that the defendant’s breach ‘materially contributed’ to the damage even if that party cannot by itself be said to have been the ‘but for’ cause of the damage’. These are both quite niche principles that have only been applied in very specific categories of negligence claims to date. While the UKJT is of the view that there is no reason why these principles should not be applied beyond those categories of claims, it is by no means certain that courts would be willing to do so.
2. Legal causation
Legal causation is a question of whether, even though a person’s conduct was a ‘but for’ cause of loss, someone or something has intervened to break the chain of causation. The UKJT consider two scenarios in this regard: deliberate misuse of an AI system by a third party and harm caused by an AI system operating autonomously.
Regarding deliberate misuse, the general position under negligence law is that a person is not liable for the consequence of the actions of a third party, unless that person has created the source of the danger or otherwise assumed a responsibility for it. The UKJT are of the view that while it is not impossible that a party in the AI supply chain might be held responsible for creating a source of danger by bringing into existence without suitable safeguards or otherwise failing to control (when it has special powers to do so) an AI model or system which it knows to be capable of certain types of harm if misused, such cases are likely to be rare. The more general purpose the AI system in question, the more extreme the circumstances would have to be before a liability risk would realistically arise.
Note should be taken of the UKJT’s suggestion regarding an ability to supervise use where an AI developer has a degree of supervision of its AI model/app (e.g., it reviews prompts), it may have some active awareness of attempts to utilise the AI to cause harm. If, in such circumstances that developer chooses not to impose guardrails to prevent such misuse, that decision may be a relevant factor in determining legal causation.
Regarding the autonomy of the AI system, the UKJT states that it would expect the court to be ‘very slow’ to reach the conclusion that an AI system ‘learning’ new principles of action or behaviours could be deemed to constitute a novel intervening act which breaks the chain of causation between any programming, data selection and other decisions and the eventual output of the system. This is not least due to the policy considerations that tend to favour finding a legal person liable where harm has been caused – especially if the person in question could benefit from the activity which gave rise to the harm.
This is, however, the situation as it stands now. The UKJT specifically acknowledges that the more capable and autonomous AI becomes and less foreseeable all possible harms therefore become, the position may well change. While the courts may be willing to expand the ambit of a duty of care progressively to cover all such harms, this would ‘undoubtedly require innovation and, at a minimum, gives rise to uncertainty’.
Contributory negligence
The principle of contributory negligence would apply to AI harm cases in just the same way as to any other negligence case. Where someone who suffers an AI harm has themselves been at fault, and where there is a causal link between that fault and the harm they have suffered, a court may reduce the damages that the person would otherwise have been awarded to such an extent as the court thinks just and equitable having regard to the claimant’s share in the responsibility for the damage.
Accordingly, if a user relies on an AI output without performing any sort of verification in circumstances where it is obvious that the consequences of AI error will be serious, contributory negligence is a possibility. The courts will likely treat noncommercial users slightly more benevolently than commercial users in this regard, but a noncommercial user who ignores very clear warnings or obviously risky AI output should expect to have their damages reduced.
Strict (no-fault) liability and the Consumer Protection Act 1987
The general position in English law is that absent negligence, the risk of loss for nondeliberate harm lies where it falls. Accordingly, those involved in an AI supply chain will not be liable for harms caused by the AI where there is no negligence on their part. The major exception to this is where the AI system is incorporated into a tangible product,[2] in which case the Consumer Protection Act 1987 (CPR 1987) applies and imposes strict (i.e., no-fault) liability for harms where a product is shown to be defective (i.e., unsafe).
Vicarious liability
In addition to direct liability, the principle of vicarious liability allows a person to be held liable for wrongs committed by another person. This usually arises in cases where employers are held liable for the harm caused by their employees. As AI is not a person, no one can be held liable for its actions or failures. However, the principle still applies in cases of employees’ wrongful use of AI, for which employers can still be held liable in the normal way.
Key takeaways
The following are the most pressing points to be addressed without delay.
- Control exposure to risk as far as possible through contracts.
- Map the potential scope of your duty of care.
- Have a robust system to ensure awareness and proper implementation of any relevant industry regulations and guidance.
- Keep all the above up to date – this is a rapidly evolving area (both in terms of the technology and its regulation), and anyone involved must respond accordingly.
[1] The UKJT was established to clarify key questions regarding the legal status of, and basic legal principles applicable to, developing technologies under English law. It is chaired by Sir Geoffrey Vos, Master of the Rolls (the second most senior judge in England and Wales). Accordingly, while its legal statements are not legally binding, they are highly authoritative.
[2] The Law Commission has announced an intention to review the status of ‘pure software’ in the context of the CPA1987, so it could be that AI systems may fall within its ambit in the future.
Contributors