Civil Law And Uae Artificial Intelligence Harm Liability .

 

Civil Law and UAE Artificial Intelligence Harm Liability

1. Introduction

Artificial Intelligence (AI) harm liability concerns the civil responsibility arising when an AI system causes injury, financial loss, property damage, privacy-related harm, reputational damage, contractual loss, or other legally recognised injury.

As of 2026, the UAE does not appear to have a comprehensive, AI-specific civil-liability statute assigning responsibility for every type of AI-generated harm. Instead, AI disputes are principally analysed through existing rules of civil liability, contract, evidence, consumer protection, data protection, product/service regulation, and sector-specific legislation. Recent UAE scholarship similarly identifies a legislative gap and proposes adapting traditional liability principles to autonomous AI systems.

The new Federal Decree-Law of 2025 promulgating the Civil Transactions Law, effective from 1 June 2026, is particularly important because it modernises the UAE's general civil-law framework and expressly reorganises the foundations of rights and obligations.

Accordingly, an AI-harm claim in the UAE will generally require analysis of:

AI system → human/legal-person actor → harmful conduct → damage → causation → applicable liability rule → compensation.

2. What Is AI Harm?

AI harm may take several forms.

A. Physical harm

Examples:

  • autonomous vehicle injures a pedestrian;
  • AI-controlled industrial machinery injures a worker;
  • medical AI contributes to an incorrect diagnosis;
  • autonomous robot damages property.

B. Economic harm

Examples:

  • algorithm incorrectly rejects a transaction;
  • AI trading system generates losses;
  • automated credit assessment causes wrongful financial exclusion;
  • AI pricing system produces substantial commercial losses.

C. Reputational harm

Examples:

  • generative AI falsely attributes criminal conduct to an individual;
  • AI produces defamatory information;
  • automated publication damages a person's reputation.

D. Privacy and data harm

Examples:

  • AI unlawfully processes personal information;
  • facial-recognition technology misidentifies an individual;
  • an AI model exposes confidential personal information.

E. Contractual harm

Examples:

  • AI-generated contract contains erroneous terms;
  • automated system incorrectly terminates a customer relationship;
  • AI-controlled procurement system makes an unauthorised commitment.

F. Digital and opportunity loss

An AI error may deprive someone of a commercial opportunity even without producing immediate physical damage.

The UAE Court of Cassation has recognised compensation for a missed opportunity where the loss is sufficiently established.

3. Fundamental UAE Civil-Liability Principle

The traditional UAE civil-law approach is based on the principle that a harmful act can generate an obligation to compensate.

Historically, Article 282 of the former Civil Transactions Law provided the broad principle that whoever causes harm to another is responsible for the resulting damage.

The UAE Court of Cassation explained that this principle is rooted in the Sharia maxims:

  • la darar wa la dirar — no harm and no reciprocal harm;
  • al-darar yuzal — harm must be removed.

In Civil Cassation No. 99 of Judicial Year 16 (1995), the Court explained the distinction between direct harm (mubasharah) and indirect causation (tasabbub).

For AI disputes, this creates an important question:

Who is legally responsible when the immediate harmful act is performed by an autonomous AI system rather than directly by a human being?

4. AI Does Not Automatically Become the Liable Person

A central legal problem is that an AI system is generally not treated as an independent natural or legal person merely because it can:

  • learn;
  • predict;
  • generate content;
  • make decisions;
  • operate autonomously.

Therefore, the claim ordinarily has to identify a legally responsible human or legal entity, such as:

  1. developer;
  2. manufacturer;
  3. software provider;
  4. system owner;
  5. operator;
  6. employer;
  7. deployer;
  8. service provider;
  9. data controller;
  10. professional user.

Recent UAE-focused scholarship specifically notes that autonomous AI does not fit neatly into the traditional categories of natural or legal personhood and that simply granting AI legal personality would not necessarily provide effective compensation to victims.

5. Main Theories of AI Liability

5.1 Fault-based liability

The claimant may argue that the responsible person:

  • failed to test the AI;
  • used defective training data;
  • failed to supervise the system;
  • ignored warnings;
  • failed to update software;
  • deployed an unsuitable model;
  • failed to provide adequate human oversight.

The basic structure is:

Wrongful conduct + damage + causal connection = liability.

6. Direct AI Harm and Indirect AI Harm

This distinction is particularly important under UAE civil-law reasoning.

Direct harm

Suppose an autonomous robot physically strikes a person because its operator activates it improperly.

The operator's conduct may constitute a direct causal connection.

Indirect harm

Suppose:

Developer → defective algorithm → AI decision → human action → damage.

The developer may be several causal steps away from the ultimate injury.

The tribunal or court must determine whether the chain is legally sufficient.

The UAE Court of Cassation's distinction between direct harm and causative/indirect harm in Cassation No. 99/1995 is therefore highly relevant by analogy.

7. Product and Equipment Liability

An AI system can also raise questions analogous to defective-product or dangerous-equipment liability.

For example:

An autonomous industrial robot contains a software defect that causes it to move unexpectedly and injure a worker.

Potential defendants could include:

  • manufacturer;
  • software developer;
  • system integrator;
  • owner;
  • operator.

The important question becomes:

Which actor had control over the risk that materialised?

Recent UAE academic analysis has considered whether existing rules governing things and mechanical equipment can be adapted to AI-enabled machines.

8. Negligent AI Deployment

One of the strongest potential liability theories will often be negligent deployment rather than “AI liability” as a separate legal category.

For example, a company deploys an AI recruitment system without testing it for obvious discriminatory errors.

If a person suffers legally recognised damage, the court could examine:

  • whether reasonable testing was performed;
  • whether warnings existed;
  • whether the company monitored performance;
  • whether human review was available;
  • whether the company knew about systematic errors.

The AI's autonomy would not necessarily eliminate the deployer's responsibility.

9. Human Oversight

Human supervision is likely to become an important factor.

Consider:

AI recommendation → human decision-maker → harmful decision.

The human decision-maker cannot necessarily avoid liability by saying:

“The computer told me to do it.”

The relevant inquiry would include:

  • Was human review required?
  • Was the AI output obviously unreliable?
  • Did the user blindly accept it?
  • Were warning signals ignored?
  • Was the system appropriate for the task?

10. AI Hallucinations

Generative AI can produce false information, commonly called hallucinations.

Suppose an AI legal system falsely generates:

“Person X committed fraud.”

The statement is published to thousands of people.

Potential harm could include:

  • reputation;
  • employment;
  • business opportunities;
  • financial loss.

The victim would need to establish the applicable legal basis, the responsible actor, causation and compensable damage.

A 2026 UAE-focused study specifically identifies AI hallucinations as a growing civil-liability problem and highlights difficulties concerning fault, causation and identifying the responsible party.

11. Causation: The Biggest AI Liability Problem

AI cases may involve extremely complicated causal chains.

For example:

Developer → training data → algorithm → deployment → AI output → human reliance → financial loss.

The claimant must establish that the legally relevant conduct caused the injury.

Possible intervening causes include:

  • user misconduct;
  • third-party hacking;
  • incorrect data;
  • unforeseeable use;
  • system modification;
  • force majeure;
  • victim's own conduct.

The traditional UAE distinction between direct and indirect harm therefore becomes particularly significant.

12. Contributory Conduct

The injured person may also contribute to the harm.

For example:

A company is warned:

“Do not rely on this AI system without human verification.”

It nevertheless uses the output without checking it and suffers loss.

The court may have to consider whether the claimant's conduct contributed to the damage.

The new Civil Transactions Law expressly provides for reduction or denial of compensation where the injured person's conduct contributed to causing or aggravating the harm.

13. Multiple Responsible Parties

AI systems often involve an entire technological ecosystem:

Developer + cloud provider + data provider + system integrator + owner + operator + user.

The new Civil Transactions Law addresses situations involving multiple persons responsible for harm and permits allocation according to their respective shares, while also allowing joint or several liability where appropriate.

This is particularly suitable for AI disputes because responsibility may be distributed across multiple actors.

14. Compensation for AI Harm

The new UAE Civil Transactions Law provides a modern compensation framework.

Compensation may address:

  • actual financial loss;
  • loss of profit where legally recoverable;
  • moral harm;
  • future damage where legally established;
  • loss of opportunity where applicable.

Article 255 provides that compensation is assessed according to the loss suffered and lost profit where it constitutes a natural consequence of the harmful act.

15. Moral Harm

AI can cause significant non-economic harm.

Examples:

  • defamatory AI output;
  • reputational damage;
  • unlawful exposure of sensitive information;
  • infringement of dignity;
  • wrongful publication.

The new Civil Transactions Law expressly recognises moral harm, including infringement of freedom, honour, reputation, social standing or financial status.

Therefore, an AI injury does not necessarily have to be purely financial.

16. AI and Professional Liability

AI used by professionals creates a special problem.

Examples:

  • lawyer using AI to prepare legal advice;
  • doctor using diagnostic AI;
  • engineer using AI for structural calculations;
  • accountant using AI-generated financial analysis.

The professional may remain responsible for the professional service even where AI was used as an assistance tool.

The central question becomes:

Did the professional exercise the level of care reasonably expected from a competent professional?

This is particularly important because recent UAE academic research has separately examined civil liability arising from AI use in the legal profession.

17. AI and Medical Liability

Consider:

An AI diagnostic system identifies a tumour as benign.

The physician relies entirely upon the system.

The patient suffers serious harm.

Potential defendants could include:

  • hospital;
  • physician;
  • AI provider;
  • software developer;
  • medical-device manufacturer.

The tribunal would need expert evidence to determine:

  1. whether the AI was defective;
  2. whether the doctor should have detected the error;
  3. whether the AI was properly certified/validated;
  4. whether the error caused the injury;
  5. whether earlier intervention would have changed the outcome.

18. AI and Autonomous Vehicles

Suppose an autonomous vehicle hits a pedestrian.

Potential causes:

  • defective sensor;
  • faulty software;
  • poor training data;
  • improper maintenance;
  • negligent owner;
  • negligent manufacturer;
  • external interference.

The legal analysis must separate:

design defect → manufacturing/software defect → maintenance failure → operator negligence → external cause.

This is an ideal UAE civil-liability simulation because several liability theories may overlap.

19. AI and Financial Algorithms

Suppose an AI trading system causes AED 10 million in losses.

Questions include:

  • Was the system authorised?
  • Was it within contractual limits?
  • Was the algorithm properly tested?
  • Was the loss foreseeable?
  • Did the user monitor the system?
  • Did market volatility constitute an intervening cause?
  • Was the loss caused by defective programming?

The answer will depend heavily on contractual allocation of risk and expert evidence.

20. AI and Contractual Liability

AI can generate liability without any traditional tort claim.

For example:

A software company promises that its AI platform will achieve a specific level of accuracy.

The system repeatedly fails.

The customer suffers commercial losses.

The dispute may be primarily contractual.

The court or tribunal would examine:

  • contractual promises;
  • warranties;
  • limitations of liability;
  • exclusion clauses;
  • service-level agreements;
  • representations;
  • causation;
  • damages.

21. Six+ Important UAE Case Laws

Important qualification: There is presently no well-established body of reported UAE Court of Cassation decisions specifically deciding liability for harm caused by modern generative or autonomous AI systems. Therefore, the cases below are general UAE civil-liability and evidentiary precedents applied by analogy to AI-harm disputes, not cases that themselves involved ChatGPT, generative AI or autonomous AI.

That distinction is important for academically accurate legal writing.

Case 1 — UAE Court of Cassation, Civil Cassation No. 99 of Judicial Year 16, 17 December 1995

Principle

The Court explained the fundamental distinction between:

  • direct harm; and
  • indirect causation.

Direct harm generally creates liability without requiring additional proof of intent or negligence, whereas indirect causation requires the legally relevant form of wrongdoing or causal connection.

The Court also linked the general civil-liability principles to the Sharia maxims “no harm and no reciprocal harm” and “harm must be removed.”

AI significance

This is arguably the most important traditional UAE case for AI liability.

An AI system can create a complex causal chain, and the court will need to determine whether the defendant:

  • directly caused the harm;
  • indirectly caused it;
  • controlled the relevant risk;
  • or was separated from the injury by an intervening cause.

22. Case 2 — UAE Court of Cassation, Civil Cassation No. 880 of 2021

Principle

The Court recognised that compensation may include:

  • material damage outside other statutory compensation;
  • present damage;
  • future damage;
  • loss of opportunity.

It emphasised that the relevant elements of damage must be established.

AI significance

This is highly relevant where AI causes:

  • future economic loss;
  • lost business opportunities;
  • loss of earning capacity;
  • long-term consequences.

For example, wrongful AI-based rejection of a business opportunity could potentially generate a claim if the lost opportunity is sufficiently established.

23. Case 3 — UAE Court of Cassation, Civil Cassation Nos. 434 and 448 of 2007

Principle

The Court recognised the trial court's authority to evaluate evidence, including medical and expert reports, and to assess appropriate compensation where no fixed statutory or contractual standard controls, provided the reasoning is legally and factually sufficient.

AI significance

AI-harm litigation will frequently require:

  • software experts;
  • cybersecurity experts;
  • medical experts;
  • data scientists;
  • forensic experts.

This case supports the importance of properly evaluating technical evidence rather than treating an expert's conclusion as automatically decisive.

24. Case 4 — UAE Court of Cassation, Commercial Cassation No. 215 of 2020

Principle

The Court held that a judgment cannot simply rely on an expert report without adequately explaining the reasoning supporting the expert's conclusions or dealing with a material defence.

 

AI significance

This is extremely important for AI.

Suppose an AI developer submits a technical report stating:

“The algorithm was functioning correctly.”

The court cannot necessarily treat that conclusion as conclusive.

The court must be able to understand:

  • methodology;
  • data;
  • assumptions;
  • testing;
  • limitations;
  • causal analysis.

25. Case 5 — UAE Court of Cassation, Commercial Cassation No. 767 of 2021

Principle

The Court stated that an expert's function concerns factual and technical matters; legal questions remain for the court.

The court can evaluate expert work, but its assessment must address the substance of the dispute and be supported by cogent reasoning.

AI significance

This is directly applicable to algorithmic disputes.

A data scientist may explain:

  • how the model operates;
  • whether bias exists;
  • whether the code malfunctioned;
  • whether data was corrupted.

But the expert should not decide:

“Therefore the defendant is legally liable.”

That legal conclusion belongs to the court.

26. Case 6 — UAE Court of Cassation, Civil Cassation No. 647 of 2021

Principle

The Court required judgments to demonstrate a genuine understanding of the facts and evidence.

It also stressed that a material defence supported by documents and capable of changing the result must be properly examined.

AI significance

AI disputes can contain thousands of technical documents.

A court cannot simply accept a defendant's statement:

“The AI system was technically compliant.”

It must examine material evidence such as:

  • audit logs;
  • training records;
  • testing reports;
  • system alerts;
  • incident records;
  • model documentation.

27. Case 7 — UAE Court of Cassation, Civil Cassation No. 79 of 2020

Principle

The Court held that a material defence capable of changing the outcome must be considered.

It also addressed the binding character of qualifying admissions and the requirement to assess an admission as a whole.

AI significance

Imagine a developer admits:

“We knew the model had a 15% error rate.”

But then argues:

“The claimant ignored the system's warnings.”

The court should consider the entire evidentiary context rather than selectively accepting one statement.

28. Case 8 — UAE Court of Cassation, Commercial Cassation Nos. 1012 and 1023 of 2022

Principle

The Court emphasised the distinction between technical expert analysis and legal responsibility.

An expert cannot effectively determine legal liability merely by allocating responsibility; the court must examine the contractual and legal foundation independently.

AI significance

This principle is particularly valuable where parties submit competing AI-risk assessments.

For example:

Expert: “The software provider is 70% responsible.”

The tribunal cannot simply adopt that conclusion.

It must determine:

  • what contractual obligation existed;
  • what legal duty existed;
  • whether it was breached;
  • whether the breach caused damage;
  • how liability should legally be allocated.

29. AI Liability Matrix

AI HarmPotential responsible partyMain legal issue
Autonomous vehicle injuryManufacturer/operator/developerCausation and defect
Medical AI errorDoctor/hospital/providerProfessional negligence
AI hallucinationProvider/user/publisherAccuracy and publication
Algorithmic financial lossDeveloper/user/institutionContract, negligence, causation
AI discriminationEmployer/providerWrongful decision and damage
Data leakageController/processor/providerData/privacy obligations
Defective robotManufacturer/operatorEquipment/product liability
AI-generated contract errorUser/providerContractual responsibility
Cyber-AI failureProvider/operatorSecurity and causation
AI trading errorUser/developer/platformContract and economic loss

30. Burden of Proof

A claimant will generally need to establish the relevant elements of the claim.

In AI disputes, evidence may include:

  • source code;
  • logs;
  • model documentation;
  • training data;
  • audit trails;
  • testing results;
  • contracts;
  • expert reports;
  • system warnings;
  • human intervention records.

The major practical problem is information asymmetry.

The AI provider may possess virtually all evidence necessary to understand why the system produced the harmful result.

This makes disclosure and expert examination especially important.

31. Black-Box AI and Proof Problems

A claimant may say:

“The AI caused my loss.”

But that alone is insufficient.

The claimant may not know:

  • what data trained the model;
  • what variables influenced the output;
  • what version was deployed;
  • whether the model changed;
  • whether the output was predictable;
  • whether a human altered the result.

Therefore, AI litigation may require a sophisticated evidentiary approach.

The UAE jurisprudence requiring courts to carefully assess expert evidence and material defences is particularly important here.

32. AI Provider vs AI User

A useful distinction is:

Provider

Creates or supplies the system.

Potential liability:

  • defective design;
  • inadequate warnings;
  • software defect;
  • insufficient testing;
  • cybersecurity weaknesses.

User/deployer

Uses the system in a particular environment.

Potential liability:

  • improper configuration;
  • excessive reliance;
  • failure to supervise;
  • use outside intended purpose;
  • failure to update;
  • ignoring warnings.

Human decision-maker

Uses the AI recommendation to make the final decision.

Potential liability:

  • failure to exercise professional judgment;
  • unreasonable reliance;
  • failure to verify.

33. Can AI Itself Be Sued?

Under the current UAE civil-liability framework, treating AI as an independent legal person is highly problematic.

A legal claim ordinarily requires an identifiable legally responsible person or entity capable of bearing rights and obligations.

Current UAE scholarship therefore generally views human or corporate responsibility as more practical than granting autonomous AI independent legal personality.

This produces the following model:

AI = instrument/system

rather than:

AI = independent legal defendant.

34. Strict Liability Possibility

A major future legal question is whether certain high-risk AI systems should be governed by strict or objective liability.

Examples:

  • autonomous vehicles;
  • medical AI;
  • industrial robots;
  • dangerous autonomous machinery.

Under strict liability, the injured person would not necessarily need to prove traditional negligence.

Instead, the focus could be:

harm + risk-generating activity + legally responsible controller = compensation.

Recent UAE academic research expressly considers strict/objective liability as a possible future mechanism for AI-generated digital harm.

However, this should currently be described as a legal-development proposal, not as a universally established UAE rule for AI.

35. Force Majeure and Third-Party Acts

An AI defendant may argue that the harm resulted from:

  • cyberattack;
  • malicious third party;
  • unforeseeable infrastructure failure;
  • force majeure;
  • victim's own conduct.

The traditional UAE civil-law approach recognises the significance of an external cause in determining whether responsibility is broken or reduced. This reasoning appears clearly in the UAE Court of Cassation's analysis of direct/indirect harm and external causes in Cassation No. 99/1995.

36. AI Liability and Public Policy

AI systems operating in sensitive areas can raise broader public-policy concerns.

Examples include:

  • automated governmental decisions;
  • autonomous weapons;
  • healthcare;
  • financial services;
  • biometric identification;
  • employment screening.

In these fields, civil liability may interact with:

  • administrative law;
  • constitutional principles;
  • privacy law;
  • consumer protection;
  • criminal law;
  • sector-specific regulation.

Therefore, a purely contractual approach may sometimes be inadequate.

37. Future UAE AI Liability Model

A possible future UAE framework could adopt a layered system:

Level 1 — Ordinary negligence

For ordinary AI applications.

Level 2 — Professional liability

For medical, legal, engineering and financial AI.

Level 3 — Product liability

For defective AI-enabled products.

Level 4 — Strict liability

For designated high-risk autonomous systems.

Level 5 — Mandatory insurance

For particularly dangerous AI applications.

Level 6 — Mandatory logging and auditability

To make causation and responsibility provable.

These ideas are consistent with recent UAE-focused scholarship advocating stronger transparency, strict liability and insurance mechanisms for AI harm.

38. Practical Hypothetical

Facts

A UAE hospital uses an AI diagnostic system.

The system classifies a malignant tumour as benign.

The physician accepts the result without independent verification.

The patient's condition worsens.

Potential defendants

  1. AI developer;
  2. hospital;
  3. physician;
  4. system integrator.

Issues

Issue 1: Was the AI defective?

Issue 2: Was the physician negligent?

Issue 3: Did the hospital improperly deploy the system?

Issue 4: Was adequate testing performed?

Issue 5: Did the AI error cause the injury?

Issue 6: Was earlier treatment reasonably likely to have changed the outcome?

Issue 7: What damages are recoverable?

The court would likely need extensive expert evidence.

39. Important Legal Principle

The most defensible current UAE approach is:

AI autonomy does not automatically eliminate human or corporate civil responsibility.

Instead, the court should identify the person or entity that:

  • created the risk;
  • controlled the system;
  • deployed the system;
  • failed to supervise it;
  • breached a contractual or legal obligation;
  • or otherwise legally caused the harm.

This approach is consistent with the UAE's traditional causation framework and the developing scholarly analysis of autonomous AI.

40. Conclusion

UAE Artificial Intelligence Harm Liability is an emerging area rather than a fully codified independent field of UAE civil law.

The present legal framework can nevertheless address many AI injuries through established principles concerning:

  • harmful acts;
  • fault;
  • causation;
  • direct and indirect damage;
  • contractual liability;
  • professional responsibility;
  • equipment/product risks;
  • multiple responsible parties;
  • contributory conduct;
  • expert evidence;
  • compensation;
  • moral harm;
  • loss of opportunity.

The most useful UAE authorities for analysing AI harm are Civil Cassation No. 99/1995, Civil Cassation Nos. 434–448/2007, Civil Cassation No. 79/2020, Civil Cassation No. 647/2021, Civil Cassation No. 880/2021, Commercial Cassation No. 215/2020, Commercial Cassation No. 767/2021, and Commercial Cassation Nos. 1012/1023/2022. These are not AI-specific precedents; they provide the general civil-liability, causation, compensation and expert-evidence principles that would likely form the foundation for future UAE AI-liability litigation.

Final legal proposition

The central problem in UAE AI liability is not whether AI can “make a mistake”; it is identifying the legally responsible human or corporate actor, proving causation in a technically complex environment, and providing adequate compensation for the resulting harm.

The direction of current UAE legal scholarship is toward stronger human accountability, transparency, auditability, risk-based responsibility, possible strict liability for high-risk systems, and insurance mechanisms, while the existing civil-law framework continues to provide the immediate foundation for claims.

 

 

 

 

 

 

 

 

 

 

 

 

LEAVE A COMMENT