What's new in the UKJT's final legal statement on civil liability for AI harm, and what does this mean for businesses in the supply chain and/or as end users?
Published: 11 August 2026
Authors: Alex Bishop & Peter Richards-Gaskin
The UK Jurisdiction Taskforce (UKJT) has published its final legal statement on liability for AI harm, following consultation on its draft legal statement published earlier this year. While the UKJT’s core conclusions (as discussed in our previous article) remain largely unchanged, the final statement incorporates some further analysis in certain areas. This article focusses on those developments and the key takeaways for businesses, both in the AI supply chain and as end users.
Summary of key updates
Vicarious liability and non-delegable duties
- the final statement discusses a further important aspect of potential liability for harm caused by another, namely where there is a non-delegable duty to protect against that harm1. Giving the example of an NHS Trust procuring an AI diagnostic tool from a third-party developer, the statement notes the Trust would not be able to avoid liability for any harm caused to a patient as a result of a defect in the tool by arguing the defect was the developer’s fault. The Trust would, however, likely consider seeking a contribution from the developer under the Civil Liability (Contribution) Act 1978 – subject to the usual analysis on causation, contributory negligence and so on.
Factual causation and material contribution to damage
- the final statement also includes a new discussion around the principle of ‘material contribution to damage’ – to date predominantly applied in cases involving industrial disease and clinical negligence, but arguably of general application. The principle essentially fills a gap left where, through multiple wrongdoers, harm was caused, but on a strict ‘but for’ analysis no single wrongdoer’s act or omission caused the harm. An example is given of two waste plants, one using human employees only and the other an AI system, negligently discharging equal amounts of waste into a river which together take the pollution level above a particular threshold.
Contributory negligence
- the potential impact of contributory negligence was not addressed in the draft statement – the final statement now considers how such arguments may play part of the assessment of liability for harm caused by AI. The statement does not suggest that any particular new principles or analysis need apply, but emphasises that the question will always be highly fact specific, and the nature of the user (commercial or non-commercial) and the level of verification of the AI output will be key themes.
Defamation
- the expanded discussion in the final statement emphasises that the extent to which anyone in the AI supply chain may be considered a publisher is highly fact specific. This may be most straightforward to establish in the case of commercial publishers using AI tools to generate content for their website. At the other end of the scale, the UKJT suggests that a Foundation Model Developer, with no involvement in publication of a statement beyond having licensed the use of their model, may potentially be deemed a publisher of a defamatory statement generated by it - if they have sufficient practical ability to prevent further publication.
- the final statement also acknowledges that how the defences available under s.1 of the Defamation Act 1996 and s.5 of the Defamation Act 2013 may apply in relation to AI-generated content is unclear. In relation to s.5 of the 2013 Act for example (Operators of websites), the potential defence is predicated on the basis of there being a ‘poster’ of a statement with whom the website operator must seek to correspond, but query whether/who a court would consider to be a ‘poster’ of an AI-generated statement.
What does this mean for businesses?
As noted in our previous article, in most commercial contexts the contractual arrangements between the parties in an AI supply chain will be the most important legal framework governing liability for any harm arising. For businesses operating in this space and their advisers negotiating commercial contracts, meticulous attention to detail must go hand in hand with a thorough understanding of the technology (both as it stands and how it may evolve) as well as its intended/likely deployment downstream.
For businesses as end users of AI tools the key points to note include:
- generally speaking, an organisation could not be held vicariously liable for harm caused by an AI tool it is using since the tool itself, in the absence of its own legal personality, could not be held primarily liable. An organisation could however be held vicariously liable for wrongdoing, such as negligence, by an employee in connection with their use of an AI tool. Moreover, an organisation using an AI tool in the performance of a non-delegable duty could not avoid primary liability to anyone harmed as a result of a defect in the AI tool, but could seek to recoup (at least partially) any such liability incurred by way of a contribution claim against the tool developer (subject of course to the usual analysis and any contractual arrangements preventing or limiting their ability to do so).
- more particularly, organisations using chatbots may potentially be liable for false statements made by it if the chatbot is held out as communicating on the organisation’s behalf, if there is an express or implied representation that the chatbot’s output is accurate, and/or if the chatbot makes a defamatory statement. Such organisations should make clear to users that the chatbot is AI-powered, that its output may be inaccurate/contain hallucinations, and that any views expressed do not represent those of the organisation. Those organisations in scope of the EU AI Act are likely to be familiar with these types of requirements, given their alignment with the Act’s transparency obligations.
- for professional services firms, consideration of whether, when and how to deploy AI tools must form part of their ongoing assessment, exercising reasonable care and skill, of how to carry out their client’s instructions. While any guidance from relevant regulators and professional bodies will be instructive in this respect, given the implications for their own liability, amongst other good reasons, professionals must exercise their own judgment in the context of the particular matter and their client’s objectives. In some scenarios, a client may prefer to forego a potential benefit of using AI in order to avoid a potential risk. The critical foundational step is to identify and explain competently the potential options and the risks and benefits of each.
1 Such duties are rare and their defining features were articulated by the Supreme Court in Woodland v Essex County Council [2013] UKSC 66 (23 October 2013) at paragraph [23]. In short where it is established that Party A owes a non-delegable duty of care to Party B and outsources an integral part of its functions to Party C, if Party B suffers harm as a result of Party C’s negligence in the performance of that particular function, Party A will still be liable to Party B. Non-delegable duties may arise for example in the context of prisons, care homes and schools.