The UK Jurisdictional Taskforce Legal Statement and European developments
-
Insight Article 03 September 2026 03 September 2026
-
UK & Europe
-
Tech & AI evolution
AI is developing faster than the legal frameworks designed to govern technology risk.
By considering and comparing the UK Jurisdiction Taskforce's ("UKJT") Legal Statement on Liability for AI Harms (the “UKJT Legal Statement”), the EU AI Act and the revised EU Product Liability Directive, this article examines how different jurisdictions are approaching questions of AI liability, risk management and compensation, highlighting differing regulatory philosophies and the direction of future legal reform. As AI adoption accelerates and businesses operate across increasingly interconnected markets, understanding these emerging frameworks will be critical to assessing exposures, allocating risk and anticipating future liabilities and regulatory expectations.
Key Takeaways
-
The UKJT’s Legal Statement concludes that existing English law is generally capable of addressing AI-related harms without the need for a bespoke AI liability regime. Liability will ordinarily be allocated through established principles of contract, negligence and, in limited cases, product liability, with contractual risk allocation expected to remain the primary mechanism for resolving disputes across the AI value chain.
-
The EU has adopted a complementary but distinct approach to the UK. The EU AI Act focuses on preventing harm through risk-based regulation and governance obligations, while the revised EU Product Liability Directive focuses on ensuring compensation after harm occurs through a strict liability framework that now expressly extends to software and AI systems.
-
For insurers, AI presents significant liability and accumulation challenges. As AI supply chains become increasingly complex, disputes over responsibility, indemnity and recovery are likely to increase and the potential for a single AI defect to generate large-scale losses across multiple insureds heightens aggregation and exposure management concerns.
Background
Imagine a retailer uses an AI system to forecast customer demand ahead of the Christmas period. The system malfunctions and significantly underestimates demand for a best-selling product. The retailer loses millions in sales, shareholders allege that inaccurate disclosures were made to the market, and the company seeks to recover its losses. Who bears responsibility for that economic loss? The retailer that relied on the AI, the supplier of the AI application, or the developer of the underlying model? And does who each party contracted with, and the terms of the contracts ultimately determine where the liability sits?
These are precisely the types of questions the UKJT seeks to answer in its Legal Statement published in July 2026 after a public consultation. Established under the Ministry of Justice-backed LawtechUK initiative to provide authoritative guidance on legal issues arising from emerging technologies, the UKJT brings together senior judicial, legal and industry expertise. The UKJT Legal Statement considers whether existing English law is capable of identifying a legally responsible party when AI causes harm and, if so, how liability should be attributed across an increasingly complex AI value chain. The UKJT concludes English law already possesses the tools required to address AI-related harms through established principles of contract, negligence and product liability, without the need for a bespoke AI-specific liability regime.
The UK's approach sits alongside developments within the European Union, albeit with notable differences in approach. Taken together, these developments provide valuable insight into how courts, regulators, businesses and insurers may approach AI-related risk in the coming years.
The UKJT Legal Statement: contract as the primary mechanism
The scope of the UKJT Legal Statement is to focus “on the question of whether and in what circumstances those who have not set out deliberately to cause harm may be liable for harms resulting from the use of AI.” At the outset, the UKJT makes clear that AI itself cannot be liable. Unlike companies, AI systems do not possess legal personality and therefore cannot bear legal responsibility for their own actions. The legal exercise is instead one of identifying the natural person or legal entity within the AI value chain that should bear responsibility for the relevant harm.
The UKJT Legal Statement identifies contractual allocation of risk as the starting point for most AI-related disputes. Relationships within the AI value chain are typically governed by contracts containing performance standards, warranties, fitness for purpose, accuracy and reliability commitments, indemnities, exclusions and limitations of liability. As a result, responsibility for AI-related losses will generally depend upon the parties' express contractual arrangements. A foundation model developer, for example, may seek to exclude liability arising from a customer's particular deployment of an AI system, instead requiring the deployer to assume responsibility for testing, implementation and ongoing oversight.
The UKJT therefore considers that, in practice, contractual arrangements are likely to remain the most important legal framework governing liability arising from the use of AI.
Contractual allocation of risk remains central
The UKJT concludes that AI raises no fundamental difficulty for the law of contract. The fact that a contract relates to the development, supply or deployment of AI does not require new contractual principles. Instead, established rules governing interpretation, implied terms, breach, causation, remoteness and contractual limitations continue to apply in the ordinary way.
The practical challenge is therefore not a lack of legal doctrine but ensuring that contractual arrangements clearly allocate responsibility among the various participants within the AI supply chain. Unlike many conventional technology arrangements, AI ecosystems frequently involve multiple participants including data providers, foundation model developers, application developers, integrators and deployers. Determining which participant controlled or influenced the relevant output may therefore be significantly more challenging than in traditional software disputes.
Accordingly, contractual provisions addressing responsibility for training data, model outputs, human oversight, testing, cybersecurity, regulatory compliance, intellectual property infringement and third-party claims are likely to become increasingly important as AI adoption continues to accelerate.The UKJT also notes that organisations may be liable where AI-generated outputs are adopted, communicated or relied upon as statements made on behalf of the organisation itself. As AI-enabled customer-facing tools continue to expand, issues relating to negligent misstatement, misrepresentation and reliance are likely to become increasingly significant.
Negligence fills the gaps
The position becomes more complex where harm is suffered by individuals who are not part of the contractual chain or where the contract does not address the particular loss that has occurred; for example, a patient who suffers harm as a result of a doctor’s reliance on a diagnosis obtained from an AI system.
In such circumstances, the law of negligence continues to provide the principal route through which liability may be imposed. Courts will continue to apply familiar concepts of duty of care, breach, causation and foreseeability. While AI may complicate the underlying factual analysis, it does not fundamentally alter the legal framework.
In practical terms, this means that courts are likely to focus on questions such as whether adequate testing was undertaken, whether sufficient safeguards and guardrails were implemented, whether risks were properly monitored and whether the relevant harm was reasonably foreseeable.
The Legal Statement also notes that claimants may, in appropriate circumstances, pursue no-fault claims under existing product liability legislation. Nonetheless, as discussed further below, existing English product liability legislation may be too narrow to operate as a comprehensive solution to AI-related harms. The UKJT observes that contract will generally be the primary mechanism through which liability is allocated among participants within an AI supply chain, with negligence providing the principal fallback where contractual arrangements do not resolve the issue.
The EU AI Act: preventing harm before it occurs
Where the UKJT focuses on liability after harm has occurred, the EU AI Act is primarily concerned with preventing harm from occurring in the first place. Its purpose is not to determine who should compensate injured parties, but rather to establish a harmonised regulatory framework governing the development and deployment of AI systems across the European Union.
The legislation adopts a risk-based approach. AI systems are categorised according to the level of risk they present, with obligations increasing as risk increases.
On one end of the spectrum sits AI systems considered to pose an unacceptable risk, which are prohibited altogether. At the other end, are minimal-risk systems, which face few specific regulatory requirements. Between these categories sits the important class of high-risk AI systems, which are subject to extensive requirements.
The distinction between the results of the UKJT Legal Statement and the EU AI Act can therefore be viewed as a distinction between reactive and preventative approaches. The UKJT asks who should bear responsibility once harm occurs. The EU AI Act seeks to reduce the likelihood of harm occurring at all.
Recent EU developments
Recent developments have highlighted the practical challenges associated with implementing the EU AI Act. In 2026, the EU adopted the Digital Omnibus on AI, postponing the implementation of many obligations applicable to high-risk AI systems. Stand-alone high-risk systems will generally become subject to the regime from December 2027, while certain AI systems incorporated into regulated products have been deferred until August 2028.
The stated rationale was that the technical standards, conformity assessment procedures and regulatory infrastructure necessary to support implementation were not yet sufficiently developed.
For businesses, the delay provides additional time to prepare compliance programmes, governance frameworks and internal controls. It also reflects the broader regulatory challenge of balancing innovation with effective oversight in an area where technology continues to develop at unprecedented rates.
The Revised EU Product Liability Directive
The revised EU Product Liability Directive addresses the question of how individuals can obtain compensation when AI causes harm. In this respect, it sits closer to the UKJT Legal Statement, with both considering how responsibility is allocated once harm has occurred. Unlike negligence-based claims, the EU Directive operates on a strict liability basis, meaning claimants are not required to prove that a producer acted unreasonably. Instead, they must establish that the product was defective, that damage occurred and that the defect caused the relevant loss. In doing so, the EU Directive shifts much of the risk associated with defective products onto those placing them on the market, reflecting a policy choice that injured users should not bear the burden of proving fault.
A significant development is the EU Directive's express inclusion of software and AI systems within the definition of a "product". Historically, product liability frameworks were designed around physical goods and were often ill-suited to addressing purely digital technologies. The revised EU Directive seeks to address that gap.
Notably, this goes further than the position discussed by the UKJT, which observes that many standalone AI systems supplied as software or services may fall outside the scope of the Consumer Protection Act 1987. Although the Consumer Protection Act 1987 applies to products, including electricity, the UKJT notes that an AI system is not itself electricity merely because its outputs are conveyed through electrical processes, nor has English law generally regarded standalone software as a product unless incorporated into a tangible item. As a result, an AI-enabled smart fridge may fall within the regime, whereas a standalone AI system or software is unlikely to. The EU Directive therefore expands the circumstances in which users harmed by AI systems and software may seek compensation, reflecting a deliberate policy choice to adapt product liability law to modern software and AI-driven products.
Comparing the three approaches
Although all three frameworks engage with AI-related harms, they do so from different perspectives.
The UKJT Legal Statement focuses on attribution of responsibility through existing legal doctrines. The EU AI Act seeks to reduce risk through proactive regulation and governance requirements. The EU Product Liability Directive seeks to ensure effective compensation once damage has occurred.
Viewed together, they illustrate three distinct but complementary approaches:
- The UKJT asks who should be liable.
- The EU AI Act asks how harm can be prevented.
- The EU Product Liability Directive asks how victims can be compensated.
Implications for businesses and insurers
Several themes emerge consistently across the UKJT Legal Statement, the EU regulatory framework and recent AI litigation:
Increasing focus on governance and oversight
Across all approaches, increasing attention is being paid to the steps organisations may need to consider taking before harm occurs.
Whether framed as negligence under English law or regulatory compliance under the EU AI Act, courts and regulators are likely to scrutinise controls such as testing, validation, human oversight, risk assessments and governance arrangements.
For businesses, robust AI governance is not merely best practice but a risk management necessity. For insurers, governance maturity and evidence of controls may become an increasingly significant underwriting consideration. This reflects a broader trend towards accountability and risk management when deploying emerging technologies.
Greater uncertainty regarding liability allocation
AI supply chains often involve numerous participants, each performing different functions.
Developers, deployers, professional users, platform operators and manufacturers may all occupy positions within the relevant value chain. Where harm occurs, disputes are likely to arise regarding where liability ultimately attaches and whether responsibility can be transferred through contractual indemnities and exclusions.
For insurers, this may create reserving challenges and increase the complexity of contribution, indemnity and subrogated recovery actions.
Aggregation and accumulation of risk
AI possesses a unique ability to operate at scale. A defect within a widely deployed model may affect thousands of users simultaneously, potentially generating large volumes of claims arising from a common underlying cause. In some cases, the underlying defect may not become apparent until losses have materialised across numerous deployments, creating significant uncertainty as to the scope and timing of potential exposure.
Insurers may therefore face increasing challenges when assessing accumulation exposure, modelling potential losses and determining whether multiple claims arise from a single event or a series of separate occurrences.
As AI adoption continues to expand, these questions will become increasingly important to insurers across multiple lines of business, including general liability, professional indemnity, product liability, cyber and technology errors and omissions. As AI liability and associated risks continue to evolve, a combination of standalone AI insurance, or AI-specific endorsements can help organisations manage the risk exposure. We will explore this further in the next article in our series.
End

