AI Liability in the Middle East: Who Pays When the Algorithm Gets It Wrong?

  • Insight Article 2026年9月15日 2026年9月15日
  • 中东

  • Tech & AI evolution

  • 技术、外包与数据

The Middle East is rapidly positioning itself as a global leader in artificial intelligence. Governments across the region, particularly in the UAE and Saudi Arabia, are investing heavily in AI infrastructure, digital transformation, smart cities, autonomous systems and data-driven public services. As AI becomes increasingly embedded in commercial and governmental decision-making, however, a difficult legal question is beginning to emerge: who is liable when AI causes harm?

While AI promises significant economic and societal benefits, it also introduces novel risks. Algorithms can make inaccurate decisions, autonomous systems can malfunction, generative AI tools can produce misleading content, and AI-driven processes can result in unlawful discrimination, privacy breaches or financial loss. In many cases, determining responsibility is far from straightforward. Unlike traditional technologies, AI systems often operate with varying degrees of autonomy, may evolve over time through machine learning, and frequently involve multiple stakeholders, including developers, deployers, data providers, platform operators and end users.

For courts, regulators and businesses across the Middle East, these developments raise challenging questions regarding liability, accountability and risk allocation.

The Growing Litigation Risk

Although the Middle East has not yet experienced the volume of AI-related litigation seen in jurisdictions such as the United States and Europe, the risk profile is changing rapidly. As AI adoption increases, disputes are likely to arise in a variety of contexts.

Consider a financial institution relying on an AI model to assess creditworthiness. If the model incorrectly rejects qualified applicants or produces discriminatory outcomes, affected individuals may seek redress. Similarly, an AI-powered medical diagnostic tool that generates inaccurate recommendations could expose healthcare providers and technology vendors to claims arising from patient harm.

In the employment sphere, AI recruitment tools may be challenged for biased hiring decisions. In the construction, transportation and logistics sectors, autonomous systems could cause physical damage or injury. 

Generative AI creates its own set of risks, including misinformation, intellectual property infringement, reputational harm and the creation of inaccurate business-critical content.

The central issue in each case is likely to be the same: determining who bears responsibility when the technology contributes to a harmful outcome.

Applying Existing Legal Principles to New Technology

Despite suggestions that AI requires an entirely new liability regime, many AI-related disputes in the civil onshore courts across the Middle East are likely to be addressed (at least in the short term) through existing civil liability principles rather than specialist AI legislation.

Liability for Harmful Acts and Civil Liability

While courts in jurisdictions such as the UK and US may often analyse such claims through principles of ‘negligence’ and ‘duty of care’, civil courts across the Middle East are more likely to apply established principles governing liability for ‘acts causing harm’, as well as contractual breaches and regulatory non-compliance.

The Middle East may also see a different litigation landscape emerge from that of the UK and US. Collective litigation mechanisms remain relatively limited across much of the region, reducing the likelihood of large-scale class actions based on AI-related failures. However, organisations may still face substantial exposure through individual claims, regulatory investigations, administrative penalties and reputational damage. In that respect, the financial and operational consequences of a significant AI failure could be just as serious, even if they arise through different legal avenues.

Ultimately, courts in the region are unlikely to treat AI as a legal actor capable of assuming responsibility in its own right. Consistent with broader legal principles applied internationally, liability is likely to continue to rest with the individuals and organisations that design, deploy, supervise and rely upon AI systems. The challenge will be determining where responsibility should sit when increasingly autonomous technologies contribute to harmful outcomes.

Product Liability

Product liability concepts may become increasingly relevant where AI systems are embedded within software products, consumer devices, vehicles, healthcare solutions or industrial technologies.

Traditionally, product liability frameworks focus on defective products that cause damage. AI raises more complex issues because harm may arise not from a manufacturing defect but from data quality issues, algorithmic design choices, changes in system performance over time, or unforeseen system behaviour.

Future disputes in the region may test whether an AI system can be considered defective when it performs exactly as designed but nevertheless generates harmful or inaccurate outcomes. Courts may also have to consider whether responsibility rests with the software developer, the hardware manufacturer, the data provider or another participant in the AI supply chain.

Contractual Liability

Commercial contracts are likely to become a critical tool for managing AI-related risk.

Businesses increasingly procure AI capabilities through licensing agreements, cloud platforms and software-as-a-service arrangements. Contractual provisions governing liability, warranties, indemnities, audit rights and limitations of use may therefore become the first line of defence when disputes arise.

In practice, much of the litigation risk associated with enterprise AI adoption may be allocated contractually before any dispute reaches the court. Organisations that fail to negotiate appropriate contractual protections could find themselves assuming risks that would otherwise be transferable.

Employee Conduct and Organisational Responsibility

AI risks do not arise solely from the technology itself. In many cases, liability may stem from how employees use, supervise or rely upon AI systems in their day-to-day roles.

This point is particularly important in the Middle East, where courts and regulators have traditionally focused on the conduct of individuals and organisations responsible for deploying and overseeing a technology, rather than the technology itself. As a result, businesses may face exposure where employees use AI tools improperly, rely on AI-generated outputs without appropriate verification, disclose confidential information to AI platforms, or make decisions based on inaccurate AI recommendations. The use of AI is unlikely to ever remove the obligation to exercise professional judgement or appropriate supervision. 

The practical focus should therefore be on governance. Businesses should implement clear AI policies, define permitted and prohibited uses of AI systems, establish approval and escalation procedures, and provide regular staff training. Consideration should also be given to allocating responsibility for AI oversight within the organisation, including through management structures, compliance functions and, where appropriate, employment contracts and job descriptions. 

As AI adoption accelerates across the UAE and the wider region, effective governance and human oversight may become one of the most important factors in reducing legal risk. In many cases, the key question for courts and regulators may not be whether the AI system failed, but whether the organisation using it exercised appropriate control over its employees and the technology they deployed. 

Data Protection and Regulatory Exposure

The development and deployment of AI systems often depends upon access to large volumes of data. Consequently, AI-related disputes are likely to intersect with privacy and data protection obligations.

Across the Middle East, regulators have increasingly focused on data governance and cybersecurity. In the UAE, federal data protection legislation, as well as sector-specific requirements and free zone frameworks such as those operating in the DIFC and ADGM, impose obligations regarding the collection, processing and protection of personal data.

AI systems trained on improperly obtained datasets or deployed in ways that exceed authorised purposes may expose organisations to regulatory investigations, administrative penalties and private claims. The regulatory risk becomes even greater where AI systems process sensitive personal information or make decisions that significantly affect individuals.

AI-related disputes may also engage broader legal risks beyond data protection. In the UAE, for example, individuals and organisations deploying AI systems may face exposure under the UAE’s cybercrime law where AI-generated content results in unlawful access to information, misuse of personal data, defamatory statements or offensive content. These risks are particularly relevant in the context of generative AI tools, where inaccurate or harmful outputs can be produced at scale. Businesses should therefore assess AI compliance through a wider legal lens rather than treating it solely as a data protection issue. 

Who Will Ultimately Be Responsible?

Will liability rest with the developer of an AI system, the organisation deploying it, or the end user?

The answer is unlikely to be uniform.

A software developer may be exposed where harm results from flawed design, inadequate testing or misleading representations about the system's capabilities. A deploying organisation may face liability if it implements AI irresponsibly, ignores known risks or relies on outputs without appropriate oversight. End users may also bear responsibility where they misuse systems contrary to instructions or established safeguards.

In many cases, liability may be shared among multiple participants. Courts will likely focus on the degree of control exercised by each party, the foreseeability of the harm and the steps taken to prevent it. The more critical the decision being made by AI, the greater the expectation that meaningful human oversight will remain in place.

The Middle East's Emerging Regulatory Approach

One of the most significant challenges is that AI regulation in the Middle East remains at an evolutionary stage.

Unlike the European Union, which has adopted the AI Act and established a comprehensive risk-based regulatory framework, most Middle Eastern jurisdictions have thus far focused on developing AI strategies, governance principles and sector-specific guidance rather than introducing extensive standalone AI legislation.

The UAE has emerged as a regional leader in AI governance, building upon its national AI strategy and wider digital economy initiatives. The Kingdom of Saudi Arabia has similarly prioritised AI as part of Vision 2030 and its broader technological transformation agenda. Both jurisdictions are seeking to encourage innovation while maintaining appropriate safeguards.

As a result, courts in the region will likely continue relying heavily on existing legal frameworks, including contract law, tort principles, product liability concepts, consumer protection rules, data protection obligations and sector-specific regulations, when addressing AI-related disputes.

This approach contrasts with jurisdictions that are introducing dedicated AI legislation and may produce a more incremental evolution of liability principles.

Looking Ahead

The Middle East's AI ambitions show no signs of slowing. As AI systems become more sophisticated and increasingly integrated into economic and public life, disputes arising from their use are inevitable.

For businesses operating in the region, the question is no longer whether AI creates legal risk, but how that risk should be managed. Organisations should be creating or reviewing their AI governance frameworks, policies, staff training, contractual protections, testing procedures, compliance obligations and accountability mechanisms now, rather than waiting for the first significant claim to arise.

The legal framework governing AI liability in the Middle East is still developing. Yet one principle is already becoming clear: while algorithms may generate outputs or influence decisions, legal responsibility will almost certainly continue to rest with human actors and the organisations that deploy them. Courts in the UAE have historically focused on the conduct of the individuals and entities exercising control over a technology rather than the technology itself. AI is unlikely to change that fundamental principle, even if it makes the allocation of responsibility more complex. 

您也许对此感兴趣

结束

掌握其礼的最新消息

注册您的邮箱,获取其礼最新消息!