Kiran Chita, a solicitor at Reading-based law firm, Field Seymour Parkes, looks at some of the liability issues associated with the use of generative AI.
Artificial intelligence (AI) is no longer a futuristic concept. It is embedded in our daily lives, from chatbots and algorithmic personalised recommendations to autonomous vehicles and fraud detection. As AI systems become more autonomous and capable of making decisions without direct human input, the legal frameworks that govern responsibility and liability are struggling to keep pace. Here we take a look at the evolving landscape of AI liability, the challenges it presents and practical steps that businesses can take to mitigate risk at this stage.
What has changed?
Whilst AI is not a particularly new concept, recent advancements have seen a marked shift from deterministic to adaptive AI. Previously, traditional systems would operate on deterministic principles, i.e. a rule-based system where a certain input would produce a predictable output. Recently, we have witnessed a significant transition to an adaptive AI where an input does not guarantee a specific output – instead the AI is capable of adapting or ‘learning’ over time and can produce outputs that even their developers are unable to anticipate.
This is particularly evident with large language models (LLMs), such as ChatGPT, that are now widely used. These models operate based on machine learning and are trained on vast volumes of natural language text, the sheer volume of data they process allows these systems to improve their outputs over time. This shift introduces a fundamental legal challenge: how do we assign liability for decisions made by systems that are not fully understood, even by their developers?
Existing legal frameworks
Typical fault-based approached to liability may struggle to apply effectively where damage is caused by AI-enabled products and services. The existing rules often require victims to demonstrate a wrongful act or omission by the individual responsible for the damage, AI presents numerous challenges in this respect.
Negligence
Negligence requires the claimant to prove that the defendant owed a duty of care to the that the defendant breached the duty and this caused harm, and that the harm was reasonably foreseeable. The nature of AI introduces challenges in proving each of these steps. It may be difficult to establish a duty of care if the relationship is not proximate and if multiple parties (developers, deployers, users, etc) are involved. There are also challenges with establishing causation and foreseeability due to the ‘black box’ nature of AI, i.e. if developers cannot predict outcomes or understand why an AI took a particular approach, it is difficult to prove whether those actions or that approach caused the harm and that the harm was reasonably foreseeable. In the landmark decision of Moffatt v Air Canada 2024 BCCRT 149, Air Canada was held liable for negligent misrepresentation for inaccurate statements made by its website chatbot. The tribunal found that consumers should not be expected to know which sections of Air Canada’s website are accurate and which are not. Instead, it should be obvious to Air Canada that it is responsible for all the information on its website regardless of whether that information comes from a static page or a chatbot.
Although decided in Canada, the case has attracted international attention (including in the UK) for its early indication on how courts may allocate liability in the context of AI-generated advice in commercial contexts. Due to the specific facts of the case, issues of proximity were not in contention – the position may be different where the AI is operating more independently and not necessarily through one website or one organisation so that its actions cannot be clearly attributed to the responsibility of a specific party.
Contract law
In B2C2 v Quoine Pte [2020] the Singapore Court of Appeal considered the common law doctrine of mistake in a contract formed by algorithmic agents. The doctrine of mistake provides that if Party A knows that the Party B is mistaken about a fundamental term of the contract, Party A cannot rely on that contract being property entered into. The doctrine exists to stop parties from taking advantage of parties’ mistakes.
This case concerned a contract for cryptocurrency trades automatically entered into by the parties’ algorithmic trading bots. Quoine’s bot made a mistake due to a defect in Quoine’s software and the trades were executed at a rate 250 times the exchange rate (meaning that B2C2 did 250 times better than it thought it was going to do). Quoine cancelled the trades and B2C2 sued Quoine for breach of contract. Quoine argued that the trades had been entered into due to the bot’s mistake and were therefore voidable. The court found that because the bot operated in a deterministic fashion (i.e. followed rules) and did not use ‘true’ AI, the programmer’s intent could be imputed to the system.
This reasoning may not hold in future cases involving agentic or adaptive AI where the AI system makes decisions that cannot be traced to a specific programmer or set of rules. How can courts attribute intent if an AI has acted in a way that was not foreseen or intended by its human operator? This may be particularly so when even the programmers and developers cannot explain why an AI system behaves in a certain way or opts for certain actions as opposed to others. The difficulty in understanding why an AI system does what it does means that it is also difficult to determine which party’s actions have led to the AI taking a particular action. Adaptive AI systems are constantly learning and developing, an output will be the result of inputs from various parties and determining which specific inputs resulted in an particular output is challenging and potentially fundamentally at odds with the nature of AI systems.
Product liability
Product liability law is designed to protect consumers from defective products that cause harm, and means that producers are strictly liable for damage caused by defective products, regardless of fault. The new EU Product Liability Directive (2024/2853) (Directive) revises the existing regime to explicitly include software (both embedded and standalone) and AI integrated products within its scope, marking a step towards addressing AI-related risks. The Directive also expands the concept of a ‘defect’ to include any issues that arise from software updates or cybersecurity vulnerabilities, as well as products with the ability to develop unexpected behaviour (meaning manufacturers will be liable for any damage caused by that behaviour). The Directive also expands the definition of ‘producer’ to include not only the original manufacturer but also suppliers, integrators and those who substantially modify or retrain AI systems. Whilst this acknowledges the reality that multiple parties will be involved in an AI system, determining responsibility in complex AI supply chains will remain a challenge due to the very nature of AI. The changes introduced show that product liability law is adapting to AI, but we expect further regulation will be required in the future to ensure effective consumer protection and allocation of risk. The revised Directive came into force on 9 December 2024 and EU member states must implement the changes required into their national laws by December 2026. Of course, post-Brexit, the Directive is not directly applicable in the UK, but it will have relevance for those that export relevant products to the EU. It also provides a helpful benchmark given that the UK is unlikely to deviate significantly from the EU approach.
A final option
One radical proposal is to grant AI systems legal personality. Whilst the UK Commission’s paper on Artificial Intelligence and the Law acknowledges this as a theoretical possibility, it does not dismiss the idea entirely, the paper itself does not propose reforms and is intended instead to raise awareness and discussion of the legal issues raised by AI. On the other hand, the European Parliament has firmly rejected the idea, stating that any legal changes should “start with the clarification that AI systems have neither legal personality nor human conscience” (see the European Parliament’s resolutions on the ethical and legal aspects of AI).
How to prepare?
As seen in the above, it is not yet clear how the varied and novel issues that AI poses will be handled under existing legal frameworks. Although various jurisdictions are in the process of adopting or have adopted some form of AI regulation, we are still far from a comprehensive picture of what the legal framework around AI will look like. So, what can businesses do now to protect themselves against the risk of liability and economic risk of AI going wrong? While regulation is evolving, the following measures can help mitigate risk:
- Conduct an AI audit: Map out where and how AI systems are used across the business and categorise the potential internal and external risks such as data bias, decision-making opacity and third-party dependencies.
- Embed AI governance into internal structures: In the same way that data protection ‘by design’ is now a familiar concept to businesses, AI responsibility ‘by design’ should also be adopted. This could involve ensuring responsibility is allocated for AI oversight at every stage of AI use in the business, creating an AI ethics committee, facilitating collaboration between legal, compliance and technical teams and obtaining external advice on best practice.
- Factor AI risk into due diligence: Raise AI specific queries and account for AI risks in M&A transactions, both at the due diligence stage and then perhaps allocating responsibility for AI risks in deal documentation (warranties and indemnities, etc).
- Implement AI ethics training and policies: Implement clear policies on AI use, including acceptable use, transparency and accountability. Staff should be aware of these polices and trained on AI risks, ethical considerations and escalation procedures.
- Monitor regulatory developments: Stay abreast of emerging AI regulations and guidance, both at the governmental and industry level. Engage with external advisors to facilitate compliance and anticipate future requirements.
- Proactively engage with suppliers: Understand suppliers’ use of AI before engaging them and ensure that contracts with suppliers include appropriate warranties, indemnities and audit rights. For AI-specific suppliers, businesses should ensure they understand how those AI systems are developed, tested and maintained and that they meet the appropriate legal and ethical standards.
Conclusions
AI presents transformative opportunities but also novel legal and ethical challenges. As the law struggles to maintain pace with technological advancements, businesses cannot afford to wait for regulatory clarity before taking action. By adopting robust governance, risk management and ethical frameworks, business can proactively manage risk whilst also positioning themselves to take advantage of the many benefits of AI.
If you have any questions about artificial intelligence or would like any assistance, please contact FSP’s commercial & technology team at commercialtechnologygroup@fsp-law.com.
About the author
Kiran Chita – Solicitor at Field Seymour Parkes
Kiran qualified as a solicitor in 2023 and joined FSP’s Commercial, IP and Technology team in July 2025.
She advises clients across a broad range of sectors including technology, medical equipment, retail and manufacturing. She supports clients with a commercial matters including drafting, advising on and negotiating key business contracts as well as advising on data protection and intellectual property matters.