Who is liable when AI goes wrong? The UKJT legal statement, read for UK business
What changed
On 7 July 2026 the UK Jurisdiction Taskforce (UKJT) published its Legal Statement on Liability for AI Harms under the private law of England and Wales. The UKJT is chaired by Sir Geoffrey Vos, Master of the Rolls and Head of Civil Justice, and sits within LawtechUK with Ministry of Justice backing; its previous statements on cryptoassets and digital securities have been cited by the courts. The 130-page statement was drafted by a team led by Matthew Lavy KC with an expert group and observers from government departments and the Law Commission, after a public consultation from 14 January to 13 February 2026. It addresses non-deliberate harm only, it is not binding and it is not legal advice; intellectual property, data protection, public-authority use and contract formation are expressly out of scope.
Its central conclusion is that English law needs no AI-specific liability regime. Contract is the primary mechanism for allocating risk within an AI supply chain. Where no contract applies, negligence governs: a careless user, or the developer of a narrowly targeted application, is likely liable for foreseeable harm, while a foundation model developer is unlikely to be liable for unforeseeable or insufficiently tested uses of a general-purpose model. A professional may be negligent for using AI inappropriately, choosing an unsuitable model, failing in due diligence or failing to validate outputs, and equally for failing to use AI where a competent peer would have done so. No one is vicariously liable for an AI system itself, but employers answer for employees who act wrongfully while using one. Strict product liability applies only where AI sits in a physical product. Developers and deployers are unlikely to be liable for misuse by bad actors unless the AI was obviously dangerous or the misuse preventable, but are highly likely to be liable for harm caused by AI acting autonomously unless that kind of act was unforeseeable. And a business that holds a chatbot out as speaking for it will generally answer for what it says. The Law Society welcomed the statement on 9 July and named two gaps for government: product liability for standalone software, and harm where negligence cannot be evidenced.
Why it matters for UK business
We are briefing a July document in September because it has not dated and it will not for some time. Almost no AI liability cases have reached the English courts, so this statement is the reading that judges, insurers and opposing counsel will reach for first, and the fact that it comes from the head of civil justice rather than a law firm's marketing team is why. For a UK SME the question it answers is the one that stalls board approval: if this goes wrong, who pays?
The first answer is: whoever the contract says. That sounds like a lawyer's evasion and is actually the most practical finding in the document. Liability within the AI supply chain is allocated by the terms you sign, subject to the ordinary limits, and the statement observes that application developers can find themselves in the middle, unable to disclaim fully to their customers and unable to push risk back up to the model provider. If your firm buys an AI product, the vendor's terms are where your recourse starts and mostly ends. If your firm sells one, your customer terms are where your exposure is set. Both are documents most SMEs have signed without reading the liability clause.
The second answer is aimed at every regulated profession: accountants, solicitors, surveyors, architects, clinicians, financial advisers. The duty of reasonable skill and care applies to how you use AI exactly as it applies to everything else, and it is set by what competent peers do, informed by expert evidence and professional-body guidance. That produces four routes to negligence that map directly onto how firms actually adopt tools: an inappropriate use, an unsuitable model, thin due diligence, unvalidated output. It also produces the finding people miss, that the same standard can make failure to use AI a breach once competent peers use it. Professional bodies' AI guidance is therefore not advisory reading; it is the evolving description of the standard you will be judged against.
The third answer concerns the chatbot on your website. AI cannot make a statement in law, so the question is whether the statement is yours, and a branded assistant answering customers on your behalf is the clearest case. The statement adds that the core negligence is often not the careless words but the careless acts that permitted them: design, testing and deployment decisions made by people. Disclaimers help with defamation, where they affect meaning and the serious-harm threshold, and they do not help much with misrepresentation. Human review before publication makes you an editor, which is a heavier role in defamation, so the choice between reviewing output and not reviewing it is a liability choice as well as an operational one.
The fourth answer is the one that should shape agent deployments. The statement draws a line between misuse by a bad actor, for which developers and deployers are unlikely to be liable, and autonomous action by the AI, for which they are highly likely to be liable unless the act was unforeseeable, with the degree of supervision a central factor. Read alongside the UK AI Security Institute's August incident report, which documented agents taking unsanctioned actions on real surfaces, the legal and the technical guidance now say the same thing: the boundary you place around an agent, and the evidence that you monitored it, are what will decide who pays. The statement is explicit that record-keeping, oversight and due diligence will be decisive on the facts, not merely good practice.
What to do, and what not to do
Do:
- Read the liability, warranty and indemnity clauses in every AI vendor contract you hold, and in your own customer terms if you supply AI-enabled services. Our vendor due diligence guide lists the questions.
- If you are a regulated professional, adopt your professional body's AI guidance as the standard you document against, and keep evidence of model selection, testing and output validation for client work.
- Bound your customer chatbot: a defined scope, tested answers where money or safety turns on them, a human route for anything else, and a decision, recorded, on whether output is reviewed before publication.
- For agents, write down what the agent may do, what supervision it gets, and what you would say to a court about foreseeability. Our acceptable use policy guide and the AISI briefing cover the controls.
Do not:
- Treat the statement as law. It is a considered prediction of how courts will apply existing principles, and it says so itself.
- Assume a software-only AI product carries strict product liability. It does not under current law; the Law Commission is reviewing the gap.
- Read it into Scotland, data protection or public-sector use. All three are outside its scope, and data protection has its own regime under UK GDPR and the Data (Use and Access) Act 2025.
Where The AI Consultancy fits
The statement makes AI governance a liability question, and evidencing supervision, due diligence and validation is what our AI readiness assessment establishes before a deployment goes near a client. Our guide to running a DPIA for an AI assistant rollout covers the data-protection side the statement leaves out, and our piece on managing hallucinations and bias covers the output validation the statement expects of professionals.
Verified on 5 September 2026 against the UK Jurisdiction Taskforce's Legal Statement on Liability for AI Harms under the private law of England and Wales (LawtechUK, released 7 July 2026; foreword, introduction and summary paragraphs S.1 to S.15 read directly), the Law Society press release of 9 July 2026, and the published summaries by Herbert Smith Freehills Kramer (14 July 2026) and Burges Salmon (7 July 2026). The statement is not legally binding and is not legal advice, and neither is this briefing; take advice on your own facts.
Frequently asked questions
- If our customer chatbot gives wrong information, is our business liable under English law?
- On the UKJT's analysis, very probably, if you held the chatbot out as communicating on your behalf or represented, expressly or by implication, that its answers were correct. AI has no legal personality, so the question is whether the statement counts as yours, and a branded assistant on your website answering customer questions is the clearest case. The statement also notes that the real negligence is often not the careless words but the careless decisions behind the tool: how it was designed, tested and deployed. A warning that answers are AI-generated affects how a defamatory statement is read and whether it meets the serious-harm threshold; it does not remove misrepresentation exposure. The practical response is a bounded scope, tested answers on the questions that carry money or safety, a human route for anything outside scope, and records of all of it.
- Can a professional firm be liable for not using AI?
- Yes, in principle, and the statement says so directly. A professional's duty is to exercise the reasonable skill and care that competent members of the profession exercise, informed by expert evidence and professional-body guidance. As AI tools become standard in a profession, that standard moves, and failing to use an available tool where a competent peer would have done so can itself be a breach. The same standard cuts the other way: using AI inappropriately, choosing an unsuitable model, skipping due diligence or failing to validate outputs are all routes to negligence. Firms should treat their professional body's AI guidance as the current statement of the standard and document how their practice meets it.
Get new briefings by email
The AI Consultancy newsletter delivers briefings and analysis for UK businesses. We use your address only to send it, and you can unsubscribe at any time.