EN FR ES PT DE AR 中文

Who Is Liable When AI Causes Damage in the UK? Read the Contract, Not the Keynote

Standard AI vendor terms typically cap your recourse at about a year of fees, and UK law offers only a fact-specific route past the cap. The gap between real loss and realistic recovery belongs in your procurement maths, not your post-incident review.

Listen11 min

Ask who is liable when AI causes damage in the UK and the useful answer is not in any statute. It is in the limitation-of-liability clause you signed. As at the time of writing (August 2026), OpenAI's Business Terms provided that indirect and consequential losses were excluded and that total liability was capped at the fees paid for the relevant service in the previous 12 months. Anthropic's Commercial Terms of Service took the same overall shape: consequential loss excluded and aggregate liability capped by reference to fees paid, with the version we last reviewed measuring that cap over the preceding 12 months too. These documents are revised without ceremony, so check the version attached to your own order form rather than taking anyone's summary on trust, including this one. And to be explicit that the arithmetic here is an illustration, not a case study: if an agent running on a £60,000 subscription destroyed £2 million of production data, a fee-level cap of that kind would hold contractual recovery to £60,000, before any argument about whether the cap is enforceable. That is not an oversight. It is the deal.

None of this is an AI novelty. Enterprise software has been sold on exclusion clauses and fee-level caps for forty years. What changed is the blast radius: a chatbot that displays a wrong answer wastes minutes, while an agent holding production credentials acts on systems, money and people. The clause stayed the same size while the thing it excuses grew.

Who is liable when AI causes damage in the UK?

Not automatically you, which is the mistake the fatalistic version of this argument makes. English law implies real obligations into the deal. In a business-to-business contract, section 13 of the Supply of Goods and Services Act 1982 implies a term that the service will be carried out with reasonable care and skill; section 49 of the Consumer Rights Act 2015 does the same job for consumer contracts. A vendor whose system wrecks your data through carelessness is, on the face of it, in breach.

The cap is where the claim goes to die, and the cap is also where English law gets interesting. Under section 3 of the Unfair Contract Terms Act 1977, a party dealing on the other side's written standard terms can only exclude or restrict liability for its own breach so far as the term is reasonable. Most click-through enterprise AI agreements will look like standard terms, though even that is a question of fact: in African Export-Import Bank v Shebah Exploration [2017] EWCA Civ 845 the Court of Appeal required proof that the terms were habitually used and essentially unnegotiated before section 3 would bite. On the caps themselves, the courts have form both ways. In St Albans City and District Council v International Computers Ltd [1996] 4 All ER 481, a £100,000 cap for defective software was held unreasonable against a loss several times that size, the court noting the vendor's £50 million insurance cover and superior bargaining power. Five years later in Watford Electronics v Sanderson, a similar cap survived because two commercial parties had genuinely negotiated it. So a route past the cap exists, but it is fact-specific, expensive to run and far from guaranteed.

And there is a gate in front of it. English courts will generally hold commercial parties to their chosen governing law, and the standard terms of the large US vendors have historically chosen Californian law and Californian courts, though the contracting entity and the clause vary by region and product, so read yours. UCTA anticipates the tactic, but only partly: section 27(2) preserves the Act where a foreign-law clause appears imposed wholly or mainly to evade it, a deliberately narrow escape hatch, while section 26 removes many cross-border deals from the reasonableness test altogether, as the Court of Appeal confirmed in Trident Turboprop v First Flight Couriers, although that carve-out is built around supplies of goods and its reach into a pure services and API deal is arguable. None of that is solid enough to plan around. Pulling the contract under English law and jurisdiction is what puts the reasonableness test squarely on the table, which turns the driest clause in the document into the first thing worth negotiating.

Why hasn't product liability caught up with software?

Strict product liability, the regime that lets a claimant pursue a manufacturer without proving negligence, comes from the Consumer Protection Act 1987, drafted for tangible goods. Whether standalone software is a "product" within it has never been cleanly settled, and pure business losses were never its concern anyway. The EU has now answered the question for its own market: the revised Product Liability Directive explicitly brings software and AI systems into scope, with member states due to transpose it by 9 December 2026. Note its limits before you envy it: it protects people, covering death, injury, property and loss of personal data, not a company's wrecked production database. The other half of the Brussels plan went backwards: the proposed AI Liability Directive, which would have eased fault-based claims, was listed for withdrawal in the Commission's 2025 work programme (COM(2025) 45 final, 11 February 2025) on the stated ground that no agreement was foreseeable, and as at August 2026 no successor has been tabled. The AI Act, meanwhile, polices conduct and levies fines but creates no private right to damages. The UK has so far done none of this. For a British business there is no cavalry coming: the contract is the liability regime.

The exposure nobody capped

Your vendor capped your recourse; nobody capped your exposure. If an agent you deployed damages a third party's systems or data, the claim will usually come to you first: yours is the contract, the system and the name in view, and your onward claim against the vendor runs straight into the clause above. A claimant might in principle sue the vendor directly in negligence, but English tort law is stingy with pure economic loss, so do not count on being second in line. The asymmetry sharpens when the agent is judging people rather than deleting files. If an automated sift skews against staff who took parental leave, the claim ordinarily lands on the employer: under section 109 of the Equality Act 2010 an organisation answers for what its employees and agents do in its name, and "the software did it" is less a defence than a confession that nobody was watching. The supplier of the scoring tool is unlikely to be the respondent at the tribunal, though not untouchably so: section 112 can reach those who knowingly help a contravention. Keeping a human on consequential calls is basic liability engineering.

Most of what gets filed under AI incidents is skipped engineering hygiene. NIST's Secure Software Development Framework prescribes the unglamorous controls: separated environments, least privilege, audited access. An agent that can reach production data it never needed is weak evidence of emergent machine will and strong evidence that somebody skipped the basics. That cuts both ways. The exposure is controllable, which is good news. But a court or an insurer is likely to read missing standard controls as fault on your side, which weakens your defence against third parties and your own reasonableness arguments against the vendor at the same time. The organisations that thinned their engineering teams on the promise that AI made the discipline redundant are precisely the ones no longer building the separation and change gates that kept deployment safe, which is why securing agentic systems is an organisational problem before it is a model problem.

The keynote and the contract

The chief executives of OpenAI and Anthropic both signed the 2023 statement on AI risk declaring that mitigating the risk of extinction from AI should be a global priority alongside pandemics and nuclear war. The same companies sell the technology on terms that cap their downside at around a year of fees. When the keynote and the contract disagree about how dangerous a product is, believe the contract: it is the only place the vendor's real probability estimates are written down. And liability allocation is negotiable when the market demands it. Microsoft's Customer Copyright Commitment and Google Cloud's generative AI indemnity both promise to defend customers against copyright claims over model output, because IP anxiety was blocking enterprise deals. Agent-damage indemnities will arrive the same way, when buyers make them a condition of purchase. Until then, ask anyway: the strength of the refusal tells you how the vendor prices its own product's risk. These are allocation questions that belong in technical strategy work long before an agent gets production credentials.

So the defensible verdict is not that the buyer bears everything, always. It is that on standard terms the gap between your realistic loss and your realistic recovery is wide enough to be a board matter, and English law narrows it only occasionally, expensively and after the fact. None of this is legal advice, and the cases above turned on their facts: a live dispute needs a solicitor qualified in England and Wales reading your actual documents. Price the gap in procurement instead: English governing law and jurisdiction, a cap that tracks your actual exposure, an indemnity for autonomous actions, and the engineering discipline that keeps you out of the fact pattern altogether. The cheapest time to fix the allocation is before deployment, which is exactly when almost nobody looks.

Questions people ask

Can I sue my AI vendor if its agent deletes my data?

In principle yes: business contracts carry an implied term of reasonable care and skill under section 13 of the Supply of Goods and Services Act 1982, and an unreasonable liability cap in standard terms can be challenged under the Unfair Contract Terms Act 1977, as in St Albans v ICL. In practice the challenge is fact-specific, costly, and may be blocked where the contract sits under foreign law or falls within UCTA's international supply carve-out, so your realistic recourse is often whatever cap you signed.

Does the Consumer Rights Act 2015 apply to business AI contracts?

No. Section 49 of the Consumer Rights Act, which requires services to be performed with reasonable care and skill, protects consumers dealing with traders. A business buying AI services relies instead on the equivalent implied term in the Supply of Goods and Services Act 1982 and on UCTA 1977's reasonableness test to attack unfair exclusions, which is why the governing-law clause matters so much.

What liability clauses should an AI procurement contract include?

Start with English governing law and jurisdiction, since that is what makes UCTA's reasonableness test reachable at all. Then seek a liability cap proportionate to your actual exposure rather than the licence fee, an indemnity covering damage caused by autonomous agent actions, incident notification duties, and audit rights. Expect resistance; its strength tells you how the vendor rates its own product.

Related

Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.