AI Liability in English Law: What the UKJT Legal Statement Changes

AI liability in English law now has an authoritative reference point. The UK Jurisdiction Taskforce’s Legal Statement on Liability for AI Harms, published in July 2026 following a public consultation, concludes that English private law — contract, negligence, professional liability and the law of false statements — is already capable of resolving most AI liability disputes without AI-specific legislation. Three of its conclusions matter immediately for any organisation using AI: professionals can be negligent both for using AI badly and for failing to use it where a competent peer would have; an organisation cannot escape responsibility for a chatbot it presents as speaking on its behalf; and foundation model developers will not usually be liable for unforeseeable downstream uses of their general-purpose models — which pushes responsibility towards the businesses that deploy them.

The Statement is not legislation and it does not bind a court. But the UKJT — chaired by Sir Geoffrey Vos, the Master of the Rolls — has form: its earlier legal statements on cryptoassets and smart contracts have been picked up by English judges and relied on commercially. Treating this one as optional reading would be a mistake.

The starting point: AI cannot be liable, so someone else is

The Statement’s foundation is simple. AI has no legal personality under English law, so it cannot itself be responsible for harm. Liability for loss caused by AI must therefore be attributed to legal persons — developers, deployers, professionals, businesses — using ordinary legal principles. Where contracts exist between the parties, those contracts will usually do most of the work of allocating risk, including through warranties about accuracy or performance. Where there is no contract, the primary route is negligence.

The consequence is that the interesting question is rarely “is anyone liable?” It is “which link in the AI supply chain carries the risk?” — and the Statement’s answers to that question generally move risk away from the model layer and towards the point of deployment.

The professional negligence squeeze

For professional services firms, the Statement describes a squeeze from both directions. A professional may be negligent for using AI inappropriately: selecting an unsuitable model, failing to carry out due diligence on the tool, or failing to validate AI-generated output — including checking for hallucinated content. That much is intuitive.

Less intuitive, and more commercially significant, is the other side: a professional may also be negligent for failing to use AI in circumstances where a competent member of the profession would have done so. As AI tools become standard in a field — document review, imaging analysis, anomaly detection — the standard of care moves with the profession. The safe harbour is not “we don’t use AI”; it is a documented, reasoned position on which tools are used, for what, with what checks.

Both limbs of the squeeze are evidence questions. When the allegation is negligent use, the defence is records of model selection, due diligence, validation and human review. When the allegation is negligent non-use, the defence is a record of the assessment that led to the decision. Either way, the firm that governs its AI estate in writing is in a categorically better litigation position than the firm that decided informally.

Chatbots: your words, even when a machine wrote them

The Statement addresses the scenario every customer-facing business worries about: false statements generated by an AI chatbot. Its analysis is that organisations cannot automatically avoid responsibility for AI-generated information. Liability is likely to attach where an organisation presents a chatbot as communicating on its behalf, adopts AI-generated statements as its own, or negligently designs or deploys the system.

The defamation analysis is sharper still: businesses deploying AI to publish content are likely to be treated as commercial publishers, and several familiar defences — honest opinion, public interest — are unlikely to be available for wholly AI-generated statements that no human reviewed. Removing human review from a content pipeline does not just create quality risk; it strips out legal defences.

The practical control set follows directly: clear framing of what the chatbot is and is not authorised to say, guardrails on scope, human review for consequential outputs, and records showing all of it operates in practice.

Where the gaps remain

The Statement is candid about uncertainty. The Consumer Protection Act 1987 imposes strict liability for defective products, but its scope is tangible goods; the UKJT’s view is that it is unlikely to apply in its current form to standalone AI software. The Law Commission is reviewing product liability law — including the status of pure software — with a public consultation planned for the second half of 2026, so this gap is on the legislative radar rather than permanent.

Causation is the other frontier. Opaque, autonomous systems make it harder to explain why a particular output occurred, though the Statement takes the view that English law’s ordinary causation rules can accommodate the evidential difficulty. For defendants, that is another argument for logging and traceability: the party that can reconstruct what its system did is better placed on causation than the party that cannot.

What this means for AI governance

Read together with the UK’s regulator-led approach and the EU AI Act’s extraterritorial reach, the Statement completes a picture in which UK organisations face AI accountability from three directions: regulators applying existing law, EU obligations arriving through customer relationships, and now a clarified private-law liability landscape in which negligence claims will turn on the quality of an organisation’s AI decision-making records.

Every liability conclusion in the Statement resolves, in practice, to the same operational question: can you show your working? Which tools you selected and why, what due diligence you performed, what validation and human review operates, what the system is authorised to do, and how you responded when something changed. That is precisely the record an AI governance audit trail exists to produce — and after July 2026, it is not just a compliance artefact. It is the raw material of a negligence defence.

English law did not need a new statute to make AI users accountable. It needed a clear statement that the old rules apply — and now it has one.