The UK Jurisdictional Taskforce has recently published its statement on liability for AI harms (the Statement), which the Law Society has welcomed as providing "much needed clarity".
The Statement does not include recommendations as to what the law should be and in fact concludes that reform is not necessary. While it acknowledges there is a lack of precedent for liability in relation to AI, the Statement differentiates between perceived and actual uncertainty. It states that existing principles of tort and contract law are well established and sufficiently flexible to address novel situations, including the use of AI. A separate or specific framework is not required.
The Statement highlights that AI is a tool. The question of whether and how it should be used is no different from the use of any other resource. AI has no legal personality, and cannot be liable in its own right. Liability remains with the user.
Another takeaway from the Statement is that liability for harm may arise where a professional fails to use AI when other members of the profession would have done so. This is not the first time the possibility of negligence arising from a failure to use AI has been raised. It remains to be seen how a standard of care that incorporates AI use develops, particularly given the differences in adoption, resources, and support across the profession.
How does liability arise?
Predictably, the Statement identifies two principal bases of liability:
- Contractual responsibilities voluntarily assumed by parties
- Duties imposed by law, for example as a result of negligence
Where the relationship is governed by contract, liability will depend upon the terms of the agreement between the parties in the usual way. The contract may specify what AI system should be used, or that a particular result (for example an accuracy threshold) should be met.
Alternatively, liability can arise from negligence where, in the absence of contractual arrangements, a party nevertheless owes a duty of care and fails to meet the required standard, leading to foreseeable harm.
Professional negligence and AI
If a professional fails to perform the obligations owed to their client with reasonable skill and care, the relevant benchmark for establishing negligence remains what would be expected of a competent member of the relevant profession, with professional guidance and regulatory standards playing an important role in establishing the position. If a professional acts negligently and that negligence causes loss, they should expect to be held liable. These principles apply equally to the use of AI. But what are the allegations that might be made against a professional?
Examples include:
- Using AI inappropriately
- Using an unsuitable model
- Failing to conduct proper due diligence
- Failing to test AI
- Failing to validate output
- Failing to use AI in circumstances where a competent member of the profession would have done so
The Statement also considers whether liability can attach to false statements made by AI. By way of illustration, the Statement refers to a scenario where a barrister uses AI to prepare submissions and the system "hallucinates" authorities which the barrister does not remove before submitting the document. This has been the cause of a number of problems and not surprisingly we are told that in such a case, the barrister will have breached their duty of care and may be in contempt of court. The result as we know from the reported cases is that the lawyers may be referred to their regulator and face cost sanctions. The Statement therefore emphasises that the responsibility remains firmly on the professional rather than the AI system itself in terms of output.
Insurers of professional services firms will want to know how their clients are using AI and what checks and balances are in place to avoid exposures. The governance and auditing of AI will no doubt be high on underwriters' agenda.
Our analysis
While both recently reported cases and various regulatory bodies (including the Royal Institution of Chartered Surveyors, the Financial Conduct Authority, the Bar Standards Board and the Solicitors Regulation Authority) have provided guidance addressing professionals' duties in respect of AI, the principles of negligence and causation examined in the Statement are familiar to all professionals and their insurers. This is a new category of risk but otherwise it is business as usual in terms of duties to clients and the court.
The proposition that professionals may be negligent for failing to use AI is not also not new. Sir Geoffrey Vos indicated in a speech in March 2024 that he anticipated legal activity in the future would include claims brought in respect of negligent or inappropriate use of AI and the negligent failure to use AI at all.
Refusing to engage with AI is not an option and law firms must adapt, keep pace as best they can, and to ensure that their employees have the necessary training, supervision, and policies and procedures.
Sir Geoffrey Vos has repeatedly advocated three "core rules" for lawyers and judges using AI, namely:
1. To understand what AI is doing before using it
2. Not to put private data into a public system and risk the loss of privilege in that data
3. To check the output and ensure that you can demonstrate by a clear audit trail that you have done so
There is no doubt that the liability and regulatory landscape in this area will continue to evolve and lawyers must pay close attention to regulatory guidance, judicial decisions, and commentary and ensure that their colleagues do likewise.
