TL;DR

The UK Jurisdiction Taskforce has published a legal statement on who bears responsibility when an AI system causes damage, and its answer is that England and Wales mostly has the tools already. Contract governs the supply chain, negligence covers the gaps, professional duties are unchanged, and no new legislation is needed before organisations can manage the risk.

Why a non-binding document matters

The taskforce writes statements, not law. Its influence is precedential in a looser sense: its earlier work on cryptoassets was picked up by the English courts, and the same route is plausible here. The scope is deliberately narrow — private-law harm that nobody intended, leaving out data protection, intellectual property and public-law challenges to state use of AI.

Between businesses in an AI supply chain, the statement is blunt that contract usually decides everything and is often the only mechanism available. What each party promised, who tested the system, who was supposed to check its output, and whether the failed use was even contemplated: these determine where loss lands. A warranty capped too low, or written by a supplier with no means to honour it, protects nobody.

Foundation model providers get no blanket immunity, though the analysis turns on foreseeability and on what they represented to whom. An application developer building for one defined purpose is markedly more exposed than a general-purpose model provider with no visibility of the deployment.

The two findings deployers should read twice

First, autonomy. Where a system does something harmful of its own accord, the taskforce expects courts to resist treating that as an event breaking the causal chain — particularly where the defendant was profiting from the activity. It expects the builder, or the business that put the system to work, to carry the loss in most such cases — the escape route being proof that behaviour of that kind was genuinely unforeseeable.

Second, evidence. Proving the claim stays the claimant’s job, but a defendant that ought to have kept records and failed to may find its own account read sceptically and its opponent’s read generously. That turns logging from good practice into a litigation asset.

Standalone software, meanwhile, almost certainly falls outside the Consumer Protection Act 1987, so strict product liability bites only when AI is embedded in something physical. The Law Commission is reviewing that boundary.

Looking forward

The practical instruction is unglamorous: define what the system is for, push responsibility through the contract chain, test against the actual use, supervise the output and write it all down. For the 83% of lawyers now worried about AI errors, the statement confirms the exposure sits with the professional, not the vendor.