News & Insight

AI July 10, 2026
Who pays when AI gets it wrong?  UKJT publishes Statement on liability for AI harms under English private law

Who pays when AI gets it wrong? UKJT publishes Statement on liability for AI harms under English private law

AI does not have legal personality under English law.

So, when an AI system causes harm – a chatbot invents a refund policy, a model mis-prices a trade, an automated tool gives a customer the wrong information – the liability cannot rest with the machine.  It has to land on a legal person.  The question is which one.

That question now has an answer of sorts.  On 7 July 2026, the UK Jurisdiction Taskforce (the “UKJT”) published its Legal Statement on Liability for AI Harms under the private law of England and Wales (the “Statement”), following a public consultation which closed on 13 February 2026.

What is the UKJT, and does the Statement bind anyone?

The UKJT is an industry-led initiative under LawtechUK, supported by the Ministry of Justice and chaired by Sir Geoffrey Vos, the Master of the Rolls.  Its job is to explain, quickly and authoritatively, how English law applies to new technology.  The Statement was prepared by a drafting team of barristers led by Matthew Lavy KC, in consultation with a wider expert group.  It states the law as it is: the drafting team deliberately avoided expressing a view on what the law should be.

Two things to be clear about upfront.  First, the Statement is not legislation and it binds no court: there is nothing here that anyone must comply with by this afternoon.  Second, it would be a mistake to dismiss it on that basis.  The UKJT’s earlier legal statements – on cryptoassets and smart contracts (2019) and on digital securities (2023) – have been cited with approval by the English courts and relied upon by parties choosing English law for technology transactions.  Until the cases start coming through, the Statement is the best available map of where liability for AI harms is likely to fall.

No new law needed

The Statement concludes that English law’s existing doctrines – contract, negligence, product liability and the law governing false statements (negligent misstatement, defamation and deceit) – already provide a coherent framework for deciding who is responsible when AI causes harm.  Negligence in particular, the Statement says, has a track record of flexibility and incremental adaptation: there is “no conceptual reason” why it cannot be applied to harms caused by AI failures.  In launch remarks, Matthew Lavy KC put it more directly still: providing remedies for AI harms “does not require a new liability regime”.

The Statement is deliberately technology-agnostic.  It defines AI simply as technology that is autonomous – meaning an unpredictable relationship between input and output, opacity in the reasoning that connects the two, and a limited ability on the part of the user to control what comes out.  Autonomy is the point: it is a capability that English private law has previously only had to deal with in humans.  The Statement maps the AI supply chain using the Ada Lovelace Institute’s actor framework, with additions of its own – data providers, compute providers, foundation model developers, hosting suppliers, brokers, application developers and users – and asks where responsibility sits at each link.

The focus is on non-deliberate harm.  Where somebody uses AI as a tool to inflict harm deliberately, existing law already deals with them, AI or no AI.

Where the liability lands

  • You cannot sue the bot.  AI has no legal personality, so liability attaches to legal persons – developers, deployers, users, employers – through ordinary legal principles.
  • Contract does the heavy lifting.  Within an AI supply chain, contract is the primary – often the only – mechanism for allocating liability.  Warranties, indemnities, caps and exclusions do the work, and the Statement sees no special difficulty in applying ordinary contract law to AI.  One limit worth remembering: no party can exclude or limit liability for death or personal injury caused by its own negligence.
  • Negligence fills the gaps.  Where there is no contract, the main route to liability is negligence: duty of care, breach, causation and remoteness in the usual way.  A careless user of AI is likely to be liable for foreseeable harm, and the developer of a narrowly targeted application is likely to owe duties to those foreseeably affected by it.
  • Foundation model developers are largely insulated.  The developers of general-purpose models (so-called foundation models, such as the large language models sitting underneath most chatbots) are, in most circumstances, unlikely to be liable for unforeseeable or insufficiently tested downstream uses of those models.  Misuse of AI by an independent bad actor will generally break the chain of causation – unless the AI was obviously dangerous, or the developer had the power to prevent the misuse and failed to do so when it should have done.  Where the harm comes instead from the AI acting autonomously, the position reverses: a developer or deployer is highly likely to be liable unless acts of that kind were unforeseeable.
  • Causation will bend, not break.  The ‘but for’ test applies as usual, and where the evidence is hard the courts have tools.  The published Statement – adding to the consultation draft – points to ‘material contribution’: where multiple wrongdoers have collectively caused the damage, a defendant whose negligence materially contributed to it can be liable even though its own conduct cannot, by itself, be shown to be the ‘but for’ cause – an approach the Supreme Court recently appears to have endorsed as a general principle.
  • Professionals: the duty cuts both ways.  A professional may be negligent for using AI carelessly – selecting an unsuitable tool, skipping due diligence on it, or failing to validate its output and check for hallucinations (confident but false output).  But the Statement also contemplates liability for failing to use AI where a competent member of the profession would have done so – its own examples include a radiologist who fails to use an AI system that is extremely effective at spotting tumours and could have been procured at reasonable cost, an auditor who fails to deploy AI on transaction volumes no human team could review, and a solicitor in the Business and Property Courts who fails to advise the client to consider AI-assisted document review.  That second limb should make every adviser sit up.
  • You cannot hide behind the chatbot.  Where a business presents a chatbot as speaking on its behalf, adopts its statements as its own, or negligently designs or deploys the system, liability for false statements can remain with the business.  Whoever manually reviews output before publication will be liable as an editor, and a business deploying AI to publish in the course of business will most likely count as a commercial publisher (although possibly not until it has notice of the statement complained of).  A claimant must still show serious harm to reputation, and context counts: clear warnings that words are AI-generated and may contain hallucinations will influence both defamatory meaning and whether that threshold is met.  Some defamation defences, though, fall away where there has been no human review.
  • Product liability is narrower than you might think.  The Consumer Protection Act 1987 imposes strict liability (that is, liability without fault) where AI is embedded in a defective tangible product – an automated industrial machine, say, or a robot.  The Statement’s own line-drawing: a fridge with integrated computer vision is covered; an LLM-based chatbot is not.  Even where the Act applies, it covers only death, personal injury and damage to private property – in practice, property damage claims can only be brought by consumers, which takes most commercial deployments of embedded AI outside the Act altogether. Standalone software falls outside the current Act, and the Law Commission announced on 31 July 2025 that it intends to review the CPA 1987, including the status of ‘pure software’.
  • Employers answer for employees, not for AI.  Vicarious liability – the liability of one person for the wrongs of another, classically an employer for an employee – does not apply to the acts of an AI system itself, because the system is not a legal person.  But an employer will answer in the usual way for an employee who negligently uses AI in the course of their employment, and a person who owes a non-delegable duty to protect another – an NHS Trust’s duty to its patients, say – answers for AI-related harm in the ordinary way too.

What the Statement leaves out

The Statement stays out of intellectual property, data protection, economic torts, competition law, the use of AI by public authorities and questions of AI contract formation.  For the data protection side of AI – including the Data (Use and Access) Act 2025 – see our recent piece HERE.

What should tech businesses do now?

Nothing in the Statement is mandatory.  But because it sketches how the courts are likely to allocate AI liability, it is the yardstick against which contracts and governance should now be checked.  At least five practical points arise:

  • Contracts first: review customer terms, SaaS agreements and supply-chain contracts to check that AI risk is allocated deliberately – and that warranties, indemnities, caps and exclusions line up with one another through the chain rather than contradicting each other.
  • Paper the governance: adopt recognised standards, test and monitor systems, document whether and how AI is used, and keep a human in the loop validating output.  If a claim comes, this is the evidence that reasonable care was taken.
  • Watch what the bot says: how a chatbot is presented, what disclosures sit around it, and what your marketing claims say about your AI systems will all bear on whether its statements are attributed to the business.
  • Professionals, calibrate: the standard of care now looks both ways – at careless use of AI and, increasingly, at unjustified refusal to use it.
  • Check the insurance: consider whether existing policies respond to AI-related claims and how any exclusions bite.

A pitch for English law

There is a jurisdictional prize here.  The EU AI Act regulates the design and deployment of AI but does not address private law liability, and most jurisdictions are still debating the question.  By concluding that English law already provides the answers, the Statement makes a quiet pitch for English governing law in AI contracts and disputes.

It also, for now, answers a question we left open in Nothing new under the sun, where we drew the parallel between today’s increasingly autonomous bots and the 16th-century invention of the company, and asked whether AI might one day be deserving of a legal personality of its own.  The Statement takes the orthodox line: AI is not a legal person, and responsibility for what it does is to be allocated among the humans and companies around it.  Whether that holds once bots are building bots and operating beyond the control of their creators is a question for another day – and, as we observed then, whichever jurisdiction first legislates for AI personhood will enjoy considerable first-mover advantage.  English law has form for creative jurisprudence.

Humphreys Law advises founders, investors and technology companies on AI development, deployment and contracting.  If you would like your customer terms, supply contracts or AI governance reviewed against the Statement, contact a member of the HLaw team.

All the thoughts and commentary that HLaw publishes on this website, including those set out above, are subject to the terms and conditions of use of this website.  None of the above constitutes legal advice and is not to be relied upon.  Much of the above will no doubt fall out of date and conflict with future law and practice one day.  None of the above should be relied upon.  Always seek your own independent professional advice.

Humphreys Law

If you would like to contact a member of our team, please get in touch by filling in the form below.

"*" indicates required fields

Humphreys Law