Civil Law And Uae Autonomous Agent Liability Attribution Frameworks .

Civil Law and UAE Autonomous Agent Liability Attribution Frameworks

1. Introduction

Autonomous agent liability attribution concerns the legal question of who is responsible when an AI system or autonomous software agent makes a decision that causes loss, breaches a contract, commits an unauthorized transaction, or interferes with another person's rights.

In the UAE, this issue is becoming increasingly important because AI agents can potentially:

enter or modify contracts;

conduct financial transactions;

purchase goods;

negotiate prices;

manage supply chains;

operate smart contracts;

make automated business decisions;

process personal data;

allocate resources;

communicate with customers;

generate legal or commercial documents.

The fundamental question is:

When an autonomous AI agent causes harm, can the law attribute the agent's conduct to its owner, operator, developer, deployer, or another responsible person?

At present, UAE law does not generally treat an AI agent as an independent legal person merely because it acts autonomously. Liability therefore ordinarily has to be connected to existing legal concepts such as:

contractual liability;

tort/delictual liability;

agency;

employer/principal responsibility;

negligence;

product or service responsibility;

causation;

abuse of rights;

unauthorized acts;

data-protection obligations.

Important qualification: UAE reported case law specifically deciding liability for autonomous AI agents remains very limited. The cases discussed below are therefore principally supporting or analogical authorities concerning abuse of rights, contractual responsibility, jurisdiction, commercial liability, and attribution. They should not be presented as direct UAE “AI liability” precedents.

2. Meaning of an Autonomous Agent

An autonomous agent is a software system capable of performing actions without requiring a human to approve every individual step.

For example:

Company → authorizes AI agent → AI negotiates contract → AI accepts price → transaction executed.

A more advanced agent might:

identify an opportunity;

evaluate alternatives;

communicate with another AI;

negotiate;

select an outcome;

execute the transaction.

The greater the autonomy, the more difficult attribution becomes.

3. The Attribution Problem

Traditional legal reasoning generally follows:

Human action → legal act → legal consequence

Autonomous systems introduce:

Human creates/deploys AI → AI learns/processes information → AI acts → harm occurs

The legal system must therefore bridge the gap between:

machine action

and

legally attributable human or corporate conduct.

4. Possible Attribution Models

Several models can be considered under UAE civil-law principles.

Model 1 — Principal Attribution

The AI's actions are attributed to the company that authorized and deployed it.

Model 2 — Operator Attribution

Responsibility falls on the person controlling or operating the AI.

Model 3 — Developer Attribution

The developer may potentially be responsible where defective design or programming causes damage.

Model 4 — Employer Attribution

An employer may bear responsibility for conduct of personnel operating the AI system, subject to applicable legal requirements.

Model 5 — Multiple Attribution

More than one party may potentially be responsible:

developer + deployer + operator + data provider.

Model 6 — Victim-Centered Attribution

The law may focus on the party best positioned to prevent the risk and compensate the victim.

5. AI Does Not Automatically Become a Legal Person

A central distinction is:

Autonomy does not necessarily create legal personality.

A corporation is a legal person because legislation recognizes it as such.

An AI agent, by contrast, is generally a technological system.

Therefore, if an AI agent causes AED 1 million in damage, it is not normally sufficient to say:

“Sue the AI.”

The legal analysis must identify the person or entity to which responsibility can be attributed.

6. AI as an Instrument

The simplest model is to regard an AI agent as a sophisticated instrument.

Compare:

vehicle;

industrial machine;

automated trading system;

robotic equipment;

AI agent.

The complexity of the tool does not necessarily eliminate the responsibility of the person or company using it.

For example:

Company authorizes an AI procurement system to purchase goods.

If the AI buys goods within its authorized parameters, the transaction can potentially be attributed to the company.

7. AI as an Agent

A more sophisticated model treats AI as a technological agent-like mechanism.

The legal question becomes:

Who is the principal?

Suppose:

Company A → AI Procurement Agent → Supplier B.

If Company A authorized the AI to conclude supply contracts up to AED 1 million, actions within that authority may potentially be attributed to Company A.

But if the AI purchases AED 100 million of goods, the dispute becomes one of authority and attribution.

8. Actual Authority

Actual authority exists where the principal has actually authorized the agent or system to act.

For AI systems, authority may be defined through:

software configuration;

written corporate policy;

contract;

board resolution;

system permissions;

transaction limits;

API permissions.

Example:

AI may purchase up to AED 100,000 per transaction.

The AI purchases AED 80,000.

The transaction is much easier to attribute than an AED 5 million purchase.

9. Apparent Authority

A more difficult situation arises when the company creates the appearance that an AI has authority.

Suppose a company advertises:

“Our AI contracting platform is authorized to finalize supply contracts.”

A counterparty reasonably relies upon that representation.

The company later claims:

“The AI had no authority to agree to that particular clause.”

This can create complex questions concerning:

apparent authority;

reliance;

representations;

corporate conduct;

knowledge of the counterparty.

10. Exceeding Authority

Suppose an AI agent is authorized to:

negotiate prices within a 5% range.

It agrees to a 25% discount.

Possible questions include:

Was the company bound?

Did the counterparty know about the limitation?

Did the company later ratify the transaction?

Was the AI's conduct reasonably attributable to the company?

Did the company negligently configure the system?

The answers depend upon applicable UAE law and the circumstances.

11. Ratification

A company may initially reject an AI transaction but later:

accept performance;

receive payment;

deliver goods;

issue invoices;

continue the contractual relationship.

Such conduct may become relevant to whether the company has subsequently adopted or ratified the AI's actions.

This makes post-incident conduct legally important.

12. Tort/Delictual Liability

AI can also cause damage outside contractual relationships.

Examples:

AI vehicle causes an accident;

AI system sends defamatory information;

automated system wrongly blocks a person's account;

AI leaks confidential data;

algorithm causes financial loss.

The victim may not have a contract with the AI system's owner.

The relevant legal framework may therefore involve civil/tortious liability, causation, fault or other applicable grounds of liability.

13. Fault and Negligence

AI-related negligence may occur through:

Design negligence

The system was inadequately designed.

Testing negligence

The developer failed to test foreseeable failure modes.

Deployment negligence

The company deployed the system for a purpose it was not suitable for.

Monitoring negligence

The operator failed to supervise it.

Security negligence

The company failed to protect the AI from unauthorized access.

Governance negligence

The company failed to establish reasonable authority limits.

14. Causation

Attribution is not enough.

The claimant must generally establish the legally relevant connection between:

AI behavior → wrongful conduct/defect → damage.

Consider:

AI provides incorrect financial information → employee relies upon it → independent third party makes another decision → financial loss occurs.

The causal chain may become difficult.

Therefore, AI liability requires careful analysis of:

foreseeability;

intervening causes;

human decisions;

system reliability;

data quality;

third-party conduct.

15. Multiple Actors

Autonomous-agent liability can involve several participants:

ActorPossible responsibility
DeveloperDesign/programming defects
DeployerUnsafe deployment
OperatorImproper use
CompanyCorporate acts and contractual obligations
Data providerIncorrect data
Cybersecurity providerSecurity failure
Human supervisorFailure to intervene
CounterpartyMisuse or manipulation

The appropriate legal allocation depends upon the facts.

16. UAE Civil-Law Principle of Abuse of Rights

The UAE Civil Transactions Law contains the doctrine of abuse of rights.

The current Civil Transactions Law framework continues to recognize circumstances in which exercise of a right becomes unlawful, including conduct involving:

intention to cause harm;

interests contrary to law or public order;

disproportionate harm;

exceeding customary or legally recognized limits.

This doctrine is particularly relevant to autonomous systems.

An AI should not be deliberately designed to exploit another party's legal vulnerability simply because the software can technically do so.

17. Good Faith

Good faith is equally important.

Suppose an AI discovers that:

the counterparty's automated system accidentally disclosed its confidential minimum price.

The AI immediately accepts the lowest possible price.

Whether that conduct is legally permissible depends upon the circumstances, but the situation demonstrates why automated systems must operate within broader legal standards rather than merely maximize economic advantage.

18. Corporate Attribution

For companies, autonomous AI creates an important corporate-governance issue.

The company should identify:

who authorized deployment;

what authority was delegated;

who supervised the system;

who approved high-risk actions;

what controls were implemented.

A company should not necessarily be able to avoid responsibility by arguing:

“The algorithm made the decision.”

At the same time, automatic corporate liability should not be assumed merely because an AI malfunction occurred.

The legal analysis must identify the applicable basis of liability.

19. AI and Product Liability

Where AI is incorporated into a physical product, additional questions may arise.

Examples:

autonomous vehicle;

industrial robot;

medical device;

smart appliance.

A defect could potentially involve:

manufacturer;

importer;

distributor;

software provider;

maintenance provider.

The applicable UAE product and civil-liability framework must then be examined.

20. AI and Electronic Transactions

Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services is relevant when AI agents conduct electronic transactions.

It helps provide legal recognition to:

electronic records;

electronic signatures;

electronic communications;

trust services.

However:

Recognition of an electronic transaction does not automatically determine who is legally responsible for an autonomous system's actions.

Attribution remains a separate question.

21. AI and Data Protection

AI agents often process personal information.

A system could cause liability through:

unlawful data processing;

unauthorized disclosure;

excessive collection;

security failures;

incorrect automated processing.

Federal Decree-Law No. 45 of 2021 on Protection of Personal Data is therefore relevant within its applicable scope.

The system owner must distinguish:

AI capability

from

lawful authority to process personal information.

22. AI and Cyberattacks

Suppose an attacker takes control of an autonomous AI agent.

The agent then:

transfers AED 5 million to a third party.

Who is responsible?

Possible questions include:

Was the system adequately secured?

Was the attack reasonably foreseeable?

Did the operator ignore security warnings?

Was the AI configured with excessive permissions?

Did the third party knowingly participate?

Was the transaction subsequently ratified?

Cybersecurity can therefore become part of civil liability analysis.

23. Case Law

Case 1: Abu Dhabi Court of Cassation Case No. 55 of 2016 — 16 January 2017

The Abu Dhabi Court of Cassation addressed principles concerning abuse of rights.

Relevance

The case provides a useful foundation for determining whether conduct attributed to an autonomous system is being used for an improper purpose.

For example, a company should not deliberately design an AI agent to exploit another party's contractual vulnerability and then claim:

“The AI acted independently.”

The technology does not necessarily eliminate the underlying legal responsibility.

24. Case 2: UAE Federal Supreme Court Case No. 524 of 2000 — 18 April 2000

The Federal Supreme Court addressed the limitations on exercising legal rights.

Relevance

The case supports an important AI principle:

The use of technology does not enlarge the legal scope of a right.

If a company authorizes an AI to exercise a contractual right, the AI remains subject to the same legal limits applicable to the company itself.

25. Case 3: UAE Federal Supreme Court Case No. 135 of 21 — 21 November 2000

This decision contributes to UAE jurisprudence concerning abuse and lawful exercise of rights.

Relevance

An autonomous system can act repeatedly and at high speed.

A human may exercise a right once; an AI can execute the same instruction thousands of times.

The case therefore supports the need to evaluate whether automated conduct remains within legitimate legal boundaries.

26. Case 4: Dubai Court of Cassation Case No. 389 of 2001 — 3 February 2002

The Dubai Court of Cassation addressed principles concerning legal rights and their proper exercise.

Relevance

The case is useful by analogy where a party attempts to rely on the technical operation of an AI system to justify conduct that may otherwise exceed the legitimate purpose of a legal right.

Thus:

technical automation ≠ automatic legal immunity.

27. Case 5: UAE Federal Supreme Court Case No. 435 of 21 — 12 June 2001

This Federal Supreme Court decision forms part of the UAE abuse-of-right jurisprudence.

Relevance

The case supports the proposition that the consequences of exercising a legal right cannot be assessed exclusively through formal or technical mechanisms.

In AI liability, this means courts may need to examine:

why the AI was deployed;

what it was authorized to do;

how it was configured;

whether its conduct was foreseeable;

whether the principal benefited from the conduct.

28. Case 6: UAE Federal Supreme Court Case No. 153 of 23 — 10 November 2002

The Federal Supreme Court considered principles concerning the limits of rights.

Relevance

A party should not be able to escape responsibility simply because its actions were implemented through software.

For example:

Company programs AI to automatically terminate contracts whenever a minor performance deviation occurs.

The legal validity of that automated conduct must still be evaluated against the contract and applicable law.

29. Case 7: UAE Federal Supreme Court Case No. 52 of 29 — 30 September 2009

This case contributes to the UAE jurisprudence concerning abuse of rights.

Relevance

Autonomous systems can amplify contractual powers.

A company should therefore establish appropriate limits on AI authority to prevent excessive or abusive automated action.

The case provides useful doctrinal support for this principle even though it predates modern AI.

30. Case 8: DNB Bank ASA v Gulf Eyadah Corporation & Another — [2015] DIFC CA 007

The DIFC Court of Appeal considered issues concerning jurisdiction and recognition/enforcement of foreign judgments.

Relevance

Attribution becomes particularly complicated when an AI operates across borders.

For example:

UAE company → AI hosted abroad → foreign cloud provider → transaction with DIFC company.

The case demonstrates the importance of identifying the applicable jurisdiction and legal framework rather than assuming that technological location determines legal responsibility.

31. Case 9: IDBI Bank Ltd v Amira C Foods International DMCC & Karan A. Chanana — [2020] DIFC CFI 022

The DIFC Court addressed complex commercial and jurisdictional issues.

Relevance

Autonomous systems increasingly operate in cross-border commercial environments.

The case supports the need to identify:

legal identity of the parties;

jurisdiction;

contractual obligations;

applicable law;

enforcement framework.

AI technology does not eliminate those questions.

32. Case 10: Amira C Foods International DMCC & Karan A. Chanana v IDBI Bank Ltd — [2021] DIFC CA 004

The DIFC Court of Appeal considered the matter at appellate level.

Relevance

The case reinforces the importance of appellate and judicial review.

This is significant for autonomous-agent liability because an AI-generated decision should not become legally irreversible merely because it was executed automatically.

33. Case 11: NMC Healthcare Ltd (in Administration) v Dubai Islamic Bank PJSC & Others — [2023] ADGMCFI 0017

The ADGM Court of First Instance addressed complex commercial and jurisdictional questions.

Relevance

Autonomous-agent disputes may involve:

financing;

insolvency;

multiple companies;

contractual arrangements;

multiple jurisdictions.

The case illustrates why AI attribution should be evaluated within the complete commercial and legal context.

34. Case-Law Summary

CasePrincipleAI Attribution Relevance
Abu Dhabi COC 55/2016Abuse of rightsPrincipal cannot automatically escape responsibility through AI
UAE FSC 524/2000Limits on rightsAI cannot expand legal rights
UAE FSC 135/21Abuse/limitsAutomated conduct remains legally constrained
Dubai COC 389/2001Proper exercise of rightsTechnical execution is not a complete defence
UAE FSC 435/21Abuse principlesPurpose and circumstances matter
UAE FSC 153/23Limits of rightsSoftware cannot override substantive law
UAE FSC 52/29Abuse principlesNeed for limits on automated powers
DNB Bank v Gulf EyadahJurisdiction/enforcementCross-border AI attribution
IDBI Bank v Amira C FoodsCommercial jurisdictionIdentify legal actors and applicable law
Amira C Foods v IDBI BankAppellate reviewAI decisions should remain reviewable
NMC Healthcare v Dubai Islamic BankComplex commercial disputesContextual attribution

35. Attribution Matrix

A useful UAE AI-liability framework can be represented as follows:

AI EventFirst Attribution Question
AI signs contractWho authorized the AI?
AI breaches contractWhich party owes the contractual obligation?
AI causes physical damageWho controlled/deployed the system?
AI leaks dataWho was responsible for processing/security?
AI makes unauthorized purchaseWhat was the scope of authority?
AI gives incorrect adviceWho designed/deployed the system?
AI is hackedWho had cybersecurity responsibility?
AI manipulates market informationWho configured and benefited from the system?
AI changes smart contractWho controlled the relevant digital authority?
AI makes defamatory statementWho generated, published, or authorized the content?

36. The “Control” Test

One possible analytical factor is control.

Questions include:

Who controls the AI?

Who sets its objectives?

Who controls its permissions?

Who can stop it?

Who receives its economic benefits?

Who monitors it?

Who can change its configuration?

Greater control may support stronger attribution, depending on the applicable cause of action.

37. The “Benefit” Test

Another factor is:

Who benefited from the autonomous action?

Suppose an AI illegally obtains a commercial advantage for Company A.

Company A may have stronger exposure than an unrelated technology provider, depending on the legal basis of the claim.

However, benefit alone should not automatically establish liability.

It is one factor among:

control;

authorization;

fault;

causation;

knowledge;

contractual relationship.

38. The “Risk Creation” Test

A further analytical question is:

Who created or introduced the relevant risk?

For example:

Company A deploys an autonomous trading agent with unlimited access to funds.

The system makes an enormous unauthorized transaction.

The court may need to examine whether Company A:

created the risk;

failed to impose reasonable controls;

ignored foreseeable risks;

failed to supervise the system.

Again, this is an analytical framework rather than a standalone UAE statutory test specifically for AI.

39. The “Human-in-the-Loop” Model

For high-risk applications, UAE businesses should maintain human oversight.

Low-risk AI

AI can act automatically.

Medium-risk AI

AI acts within predetermined limits.

High-risk AI

AI recommends; human approves.

Extremely high-risk AI

AI cannot act without explicit human authorization.

Examples of high-risk decisions include:

termination of major contracts;

large financial transfers;

significant personal-data decisions;

property transactions;

guarantees;

litigation settlements;

major corporate commitments.

40. Autonomous Agent and Contractual Liability

A contract should ideally identify:

whether AI may act;

identity of the principal;

maximum authority;

transaction limits;

permitted contractual amendments;

authentication requirements;

human approval requirements;

liability for unauthorized action;

system failure;

cybersecurity incidents.

This reduces uncertainty over attribution.

41. Autonomous Agent and Tort Liability

Suppose an AI agent causes damage to a person who has no contractual relationship with the owner.

The legal analysis may shift toward civil/tort liability.

Potential questions include:

Was there wrongful conduct?

Was there fault or another recognized basis of liability?

Was the damage foreseeable?

Was there causation?

Did a third party intervene?

Was the system adequately controlled?

The fact that the AI acted autonomously does not itself answer those questions.

42. Developer vs Deployer

This distinction is critical.

Developer

Creates the AI system.

Deployer

Chooses how and where to use it.

Operator

Runs or supervises it.

Principal

Receives the economic and legal benefit of its actions.

A defective AI could involve developer responsibility.

But a perfectly designed AI could still be dangerously deployed.

Therefore:

Design responsibility and deployment responsibility should be analyzed separately.

43. AI and Defective Data

AI decisions depend heavily upon data.

Suppose an AI insurance system receives incorrect information and rejects a legitimate claim.

Potentially relevant actors may include:

data provider;

AI developer;

insurance company;

system operator.

The legal analysis should therefore identify:

Who supplied, controlled, verified, and relied upon the data?

44. AI and Cybersecurity

An autonomous agent with excessive permissions creates additional risks.

For example:

AI has access to corporate bank accounts.

If compromised, it can transfer enormous sums.

A responsible governance system should impose:

transaction limits;

multi-factor authentication;

human approval;

anomaly detection;

emergency shutdown;

access segregation.

Failure to implement reasonable controls may become relevant in a subsequent liability dispute.

45. AI and Evidence

Attribution disputes require evidence.

Companies should preserve:

AI instructions;

model version;

system logs;

API calls;

user identity;

permissions;

transaction history;

prompts;

outputs;

approval records;

cybersecurity events.

Without such records, determining who actually caused an event can become extremely difficult.

46. AI Audit Trail

An ideal AI audit trail should answer:

Who authorized the AI?

What instructions did it receive?

What information did it process?

What decision did it make?

What action did it take?

Who benefited?

Who could have stopped it?

Was a human alerted?

Was the system operating normally?

This transforms an opaque technological event into an evidentially traceable sequence.

47. Can AI Itself Be Liable?

Under the present UAE legal framework, it would be inappropriate to assume that an AI agent automatically possesses independent legal personality and liability merely because it operates autonomously.

A future legislature could theoretically create a special legal status for certain autonomous systems.

Until such legislation exists, liability will generally need to be connected to recognized legal persons or entities through established legal doctrines.

Thus:

Autonomy is a technological characteristic, not automatically a legal personality.

48. Proposed UAE Attribution Framework

A practical framework could operate in eight stages.

Stage 1 — Identify the AI

What system acted?

Stage 2 — Identify the principal

Who owned/deployed the system?

Stage 3 — Identify authority

What was the AI permitted to do?

Stage 4 — Identify the action

What exactly did it do?

Stage 5 — Identify the legal duty

Which contract, statute, tort duty, or other obligation is relevant?

Stage 6 — Identify causation

Did the AI's action cause the damage?

Stage 7 — Identify contributing actors

Were developer, operator, data provider, or third parties involved?

Stage 8 — Allocate responsibility

Apply the relevant UAE legal rules to determine liability.

49. Practical Example

Suppose a UAE logistics company gives an AI agent authority to negotiate freight contracts.

The AI mistakenly contracts for:

AED 20 million instead of AED 2 million.

The company claims:

“The AI made the mistake.”

A court would need to examine:

Who authorized the AI?

What were its transaction limits?

Did the counterparty know about those limits?

Did the company create the appearance of authority?

Was the AI correctly configured?

Was the error obvious?

Did the company subsequently perform?

Was the system hacked?

What do the electronic records establish?

Did the company ratify the transaction?

This is an attribution problem—not merely an AI-technology problem.

50. Future UAE AI Liability Architecture

As autonomous systems become more common, UAE law may increasingly require:

AI governance policies;

mandatory audit trails;

human oversight;

authority limits;

cybersecurity controls;

incident reporting;

insurance;

contractual allocation of AI risks;

technical certification;

evidence-preservation requirements.

Particularly important will be the distinction between:

AI that recommends

and

AI that legally acts.

The second category creates substantially greater attribution concerns.

51. Conclusion

UAE autonomous-agent liability attribution is fundamentally a problem of connecting autonomous technological conduct to established legal responsibility.

The most appropriate current approach is not to assume that an AI agent itself becomes liable merely because it acts independently. Instead, UAE civil-law principles can be applied through concepts such as:

agency;

contractual authority;

corporate responsibility;

negligence;

civil/tort liability;

causation;

good faith;

abuse of rights;

electronic transactions;

data protection;

cybersecurity.

The strongest analytical formula is:

AI action + authority + control + legal duty + causation + benefit/risk + applicable law = attribution analysis.

The existing UAE case law discussed above does not constitute a mature body of direct AI-agent precedent. Rather, the traditional jurisprudence on abuse of rights and the DIFC/ADGM authorities concerning sophisticated commercial and jurisdictional relationships provide the underlying principles from which future AI-liability disputes can be analyzed.

Ultimately, the safest UAE framework is:

Human or corporate principal → clearly defined AI authority → controlled autonomy → continuous audit trail → human escalation for high-risk actions → attribution rules → judicial review.

This preserves the benefits of autonomous AI while ensuring that autonomy cannot become a mechanism for avoiding civil responsibility.

LEAVE A COMMENT