English Law Already Decides Who Pays When AI Goes Wrong

AI liability under English law illustrated through an AI supply chain, legal contract and risk-monitoring system.

Quick answer: The UK Jurisdiction Taskforce has published the first comprehensive analysis of how English private law handles AI harms. Its conclusions are more useful and in places more uncomfortable than the absence of an AI Act might lead you to expect.

A great deal of commentary treats the lack of a UK AI Act as a legal vacuum: nobody knows who is responsible, so nothing can be decided until Parliament acts. The UK Jurisdiction Taskforce has now produced the most authoritative answer available, and its central finding is that the vacuum does not exist.

The Legal Statement on Liability for AI Harms was published on 7 July following a consultation opened in January, and has been working its way through legal commentary since. It is the first comprehensive analysis of how the private law of England and Wales applies to non-deliberate AI harms — cases where nobody set out to cause damage but damage occurred anyway. It covers negligence, vicarious liability, professional liability, product liability and the law of false statements, including negligent misrepresentation, defamation and deceit.

The conclusion is that English law is flexible, has absorbed disruptive technologies before, and is generally well equipped for the questions AI raises — with the caveat, repeated throughout, that application will always be highly fact-dependent.

Is contract where your risk actually sits?

The UKJT expects contract to be the primary basis on which liability is allocated between participants in an AI supply chain. Not statute, not tort — the agreements the parties signed.

That is a plain statement with immediate consequences, because a large proportion of AI supply agreements currently in force were not drafted with this allocation in mind. Model provider terms, integrator contracts, reseller arrangements and client MSAs were frequently written before anyone had thought carefully about what happens when a system produces a confidently wrong output that someone relies on. If contract is the primary allocator, then the position you negotiated — including the position you accepted by not negotiating — is your risk position.

Does professional liability run in both directions?

The most counter-intuitive finding, and the one most likely to surprise a board, is that professionals can be liable in negligence both for over-reliance on AI and for failure to use it.

The logic is unremarkable once stated. Negligence measures conduct against the standard of a reasonable practitioner, and that standard moves as practice moves. A professional who accepts an AI output uncritically may fall below it. So, in time, may a professional who declines to use a tool that competent practitioners in the field now use as a matter of course.

The defensive instinct — avoid AI and avoid the liability — does not hold up. The standard of care is set by what reasonable practitioners do, and that is a moving target in both directions.

What’s the finding to act on this quarter?

The most operationally significant part of the Statement concerns causation, and it deserves close attention from anyone building or deploying these systems.

The ordinary “but for” test will often remain workable. But the UKJT acknowledges real difficulty where the nature of an AI system makes a counterfactual hard or impossible to establish — where evidence was never gathered, was not retained, or cannot be reconstructed because the system behaved autonomously.

English law, the Statement says, is capable of responding to such evidential gaps. It may do so by drawing inferences, or by treating a claimant’s evidence more benevolently where the defendant’s own failure to record or retain relevant information contributed to the uncertainty.

Read that again in commercial terms. If your system does not log what it did and why, and a dispute arises about what it did and why, the court may resolve the resulting uncertainty against you. Observability stops being an engineering virtue and becomes a legal position. Decision logs, input and output retention, model and prompt versioning, and evaluation records are, on this reading, part of your defence — and their absence is part of the claimant’s case.

Where does the risk land in the supply chain?

The Statement also concludes that foundation model developers are unlikely to bear liability for unforeseeable downstream harms.

It is worth being direct about what that means. The party most likely to answer for a harmful outcome is not the organisation that trained the model. It is the organisation that selected it, integrated it, configured it and put it in front of users — which, in most commercial arrangements, means the integrator and the deploying client rather than the lab.

Anyone building AI systems for clients should be reading that as a description of their own position.

What gaps could the UKJT not close?

The Statement is candid about its limits, and the Law Society has highlighted the same points. Product liability remains limited to tangible goods, which leaves a gap where software causes harm without being embodied in a physical product; that question now sits with the Law Commission and may require legislation. Highly autonomous systems, and causation where decision-making is genuinely opaque, remain the hardest unresolved problems.

So this is not a complete answer. It is a considerably better map than existed a year ago, with the remaining blank areas honestly marked.

What’s the honest summary?

“No AI Act” has never meant “no law”. It means the law arrives through contract, negligence and professional standards rather than through a single statute, and that it will be applied to specific facts by courts rather than announced in advance by regulators.

For organisations deploying AI, three practical conclusions follow. Review the contracts, because that is where liability is being allocated whether or not anyone negotiated it deliberately. Keep records, because their absence may be held against you. And stop treating non-adoption as the safe option, because the standard of care does not stand still.

Key takeaways

  • The UKJT’s Legal Statement, published 7 July after a January consultation, concludes English private law already has the tools to handle AI harms, covering negligence, vicarious liability, professional liability, product liability and false statements.
  • Contract, not statute or tort, is the primary way the UKJT expects liability to be allocated in an AI supply chain, which makes existing model provider terms, integrator contracts and client MSAs a live risk if they weren’t drafted with this in mind.
  • Professionals can be found negligent both for over-relying on AI and for failing to use it, since the standard of a “reasonable practitioner” moves in both directions as adoption becomes normal.
  • Where causation is hard to establish because a system behaved autonomously and evidence wasn’t retained, English law may resolve that uncertainty against whoever failed to keep the records, making logging and observability a legal position, not just an engineering one.
  • Foundation model developers are unlikely to bear liability for unforeseeable downstream harms. Risk lands instead on whoever selected, integrated, configured and deployed the system, usually the integrator and the client, not the lab.
  • The UKJT is candid about what it couldn’t resolve: product liability’s limits with non-physical software harms, and causation for highly autonomous or genuinely opaque decision-making, both of which may require legislation.

FAQs

Does the UK have an AI Act like the EU?
No, and the UKJT’s central finding is that this doesn’t leave a legal vacuum. English private law, through negligence, contract, professional liability and product liability, already applies to AI harms; it just arrives through existing legal principles rather than a single dedicated statute.

Who is liable when an AI system causes harm under English law?
It depends heavily on the facts, but the UKJT’s Statement points toward contract as the primary allocator of liability between supply chain participants, and toward the organisation that selected, integrated and deployed a system, rather than the model developer, as the party most likely to answer for downstream harm.

Can a professional be negligent for using AI, or for not using it?
Both, according to the UKJT. Over-reliance on an AI output without proper scrutiny can fall below the standard of a reasonable practitioner, but so can refusing to use a tool that competent practitioners in the field now use as standard practice.

Why does record-keeping matter for AI liability?
Because where causation is hard to establish due to an AI system’s autonomous behaviour, English law may resolve the resulting evidential uncertainty against whoever failed to log or retain relevant information. Decision logs, input/output retention, and model versioning function as part of a legal defence, not just good engineering practice.

Are foundation model developers liable for how their models are used?
The UKJT concludes they’re unlikely to bear liability for unforeseeable downstream harms. That risk tends to sit with the organisation further down the supply chain that selected, configured and deployed the model in front of users.

What has the UKJT Legal Statement not resolved?
Product liability remains limited to tangible goods, leaving a gap for harm caused by software that isn’t embodied in a physical product, a question the Law Commission may need to legislate on. Causation involving highly autonomous or genuinely opaque decision-making systems also remains unresolved.

Have a project in mind? Let’s get to work.

Let’s chat about how we can help you. Fill in the details and we’ll get back to you as soon we can.