Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. Risk and Compliance
  4. UKJT legal statement on liability for AI harms: Applying existing principles to increasingly autonomous systems
5MIN

UKJT legal statement on liability for AI harms: Applying existing principles to increasingly autonomous systems

Jul 29 2026

Accountability is a recurring theme across the UK’s recent AI policy agenda. As we discussed in our recent blogs on the FCA’s Mills Review and HM Treasury’s Financial Services AI Adoption Plan, policymakers are increasingly focused on how existing regulatory frameworks will operate as firms move further along the AI autonomy spectrum, from AI-assisted decision-making towards systems that make decisions and take actions under human oversight.

The debate is not confined to regulation. On 7 July 2026, the UK Jurisdiction Taskforce (UKJT) published its final legal statement on liability for AI harms (for a discussion of the draft, see here), examining whether existing principles of English private law are capable of allocating responsibility when the use of AI causes harm. 

The UKJT’s central conclusion is that English law is generally capable of addressing harms caused by the use of AI, without a need for a wholly new, AI-specific liability regime. The reasoning starts from a simple premise: AI systems have no legal personality and cannot themselves be liable, so responsibility must be allocated among the natural and legal persons involved in their development, deployment and use. As a “well-developed flexible common law system”, English law “has frequently accommodated novel and disruptive technical developments and demonstrated the ability to provide certainty and predictability in the context of technological innovation”.

The UKJT therefore concludes that questions of liability can generally be resolved through established legal principles, including:

  • Contract: Contract “will generally be the primary basis on which liability for harm is allocated amongst parties within an AI supply chain”, with “the fact that the subject matter of a contract may be AI pos[ing] no special difficulty”.
  • Negligence: In the absence of a relevant contract, liability for non-deliberate AI-related harms will often be determined under the law of negligence. Liability will depend on familiar questions of duty, breach, causation and foreseeability, with outcomes likely to be highly fact-sensitive. This is not undermined by the fact that the harm has been caused by AI failures, with the UKJT noting that in many cases there is no “practical difficulty in applying the normal principles in an AI context”. In general terms, liability for foreseeable harm is more likely to attach to careless users or developers of narrowly targeted applications, while foundation model developers are, in most circumstances, less likely to be liable for harms arising from unforeseeable or insufficiently tested uses of their general-purpose models.
  • Factual and legal causation: The ‘but for’ test (that is, the general rule that a person will not be liable for loss unless the loss would have been avoided ‘but for’ that person’s acts or omissions) is generally flexible enough to apply, although AI systems may give rise to evidential difficulties where their operation is too opaque to establish what would have happened in the counterfactual scenario, which is not necessarily a challenge that is unique to AI. Fact-specific questions may arise as to intervening cause, where harm results from third-party misuse or from autonomous acts of the AI.
    • On misuse, the statement draws an analogy with a somewhat extreme example of a knife manufacturer – although the knife manufacturer is presumably aware that its products could be misused, the manufacturer will not generally be liable for injury caused by a criminal’s misuse of a knife as the independent decision of the criminal involved is likely to be sufficient to break the chain of causation. An AI developer or deployer may similarly be unlikely to be held liable for the misuse of the AI by a bad actor, unless the AI in question was obviously dangerous (and did not include suitable safeguards or controls), or they could have prevented the misuse and failed to do so when they should have. The more general purpose the AI in question, the more extreme the circumstances would have to be before liability would arise.
    • Autonomous acts point the other way, as they are closer in substance to human decisions, although from a policy perspective, it is not always clear there would be someone who could be held legally responsible. The UKJT concludes that it is “highly likely that a developer and/or deployer of an AI system would be liable for harms caused by the AI acting autonomously, unless acts of the kind in question were unforeseeable”. Much will turn on the system’s capabilities and limitations, its level of autonomy, and the degree of supervision that was or should have been exercised. Any considerations of liability in an autonomous AI context will therefore be fact-specific and unlikely to yield a straightforward answer.
  • Contributory negligence: Damages may be reduced where claimants have contributed to the loss, particularly in a commercial context.
  • AI-generated statements: Liability for negligent or fraudulent misstatement, defamation or deceit may arise where AI-generated output is attributable to a legal person. Liability is more likely where a legal person presents an AI chatbot as communicating on its behalf, adopts its output, or publishes it without adequate oversight. In many cases, the relevant negligence may lie less in the output itself than in the human decisions surrounding the AI system’s design, testing and deployment. Deceit is harder to establish. It “could arise in the context of false statements made by an AI chatbot, but only if the AI developer or user intended that the AI should produce the false output (or was reckless about whether it was true or false) and intended that someone would believe it to be true”. The pivotal question, in other words, is whether the developer or user had sufficient intent.
  • Vicarious liability, non-delegable and professional duties: AI’s lack of legal personality does not displace doctrines such as vicarious liability for employees’ use of AI, non-delegable duties, or professional duties of care. For professionals, duties of reasonable skill and care extend to the use of AI and, in some circumstances, may even extend to a failure to use AI, where a competent peer would have done so.
  • Statutory product liability: Strict liability for product defects under the Consumer Protection Act 1987 is likely to apply only in relatively narrow circumstances, principally where AI is integrated into physical products. Otherwise, in the absence of fault, "the risk of harm lies where it falls”. (The law in this area is, however, likely to develop, with the Law Commission currently reviewing the scope of the product liability regime, including how it applies to AI and other software: see further here.)

The statement therefore adopts a pragmatic position: the challenge is not the absence of law, but the application of established legal principles to novel facts. The UKJT’s central point is that, while the fact patterns may be increasingly novel, the legal toolkit for addressing them already exists within a legal system that has long adapted to accommodate technological change. 

Tags

aiproduct liabilityfinancial servicesfinancial servicesunited kingdom

Authors

London

Lucy Clark

Senior Associate
London

Andrew Austin

Partner, Head of London Dispute Resolution
London

Claire Harrop

Partner - Financial Services Regulatory & UK Head of Fintech
London

Cyrus Pocha

Partner - Financial Services Regulatory & Co-head Global Fintech Group, London
London

Lauren Moorin

Counsel
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome