Civil Law And Uae Autonomous Agent Liability Attribution Frameworks .
Civil Law and UAE Autonomous Agent Liability Attribution Frameworks
1. Introduction
Autonomous agent liability attribution concerns the legal question of who is responsible when an AI system or autonomous software agent makes a decision that causes loss, breaches a contract, commits an unauthorized transaction, or interferes with another person's rights.
In the UAE, this issue is becoming increasingly important because AI agents can potentially:
enter or modify contracts;
conduct financial transactions;
purchase goods;
negotiate prices;
manage supply chains;
operate smart contracts;
make automated business decisions;
process personal data;
allocate resources;
communicate with customers;
generate legal or commercial documents.
The fundamental question is:
When an autonomous AI agent causes harm, can the law attribute the agent's conduct to its owner, operator, developer, deployer, or another responsible person?
At present, UAE law does not generally treat an AI agent as an independent legal person merely because it acts autonomously. Liability therefore ordinarily has to be connected to existing legal concepts such as:
contractual liability;
tort/delictual liability;
agency;
employer/principal responsibility;
negligence;
product or service responsibility;
causation;
abuse of rights;
unauthorized acts;
data-protection obligations.
Important qualification: UAE reported case law specifically deciding liability for autonomous AI agents remains very limited. The cases discussed below are therefore principally supporting or analogical authorities concerning abuse of rights, contractual responsibility, jurisdiction, commercial liability, and attribution. They should not be presented as direct UAE “AI liability” precedents.
2. Meaning of an Autonomous Agent
An autonomous agent is a software system capable of performing actions without requiring a human to approve every individual step.
For example:
Company → authorizes AI agent → AI negotiates contract → AI accepts price → transaction executed.
A more advanced agent might:
identify an opportunity;
evaluate alternatives;
communicate with another AI;
negotiate;
select an outcome;
execute the transaction.
The greater the autonomy, the more difficult attribution becomes.
3. The Attribution Problem
Traditional legal reasoning generally follows:
Human action → legal act → legal consequence
Autonomous systems introduce:
Human creates/deploys AI → AI learns/processes information → AI acts → harm occurs
The legal system must therefore bridge the gap between:
machine action
and
legally attributable human or corporate conduct.
4. Possible Attribution Models
Several models can be considered under UAE civil-law principles.
Model 1 — Principal Attribution
The AI's actions are attributed to the company that authorized and deployed it.
Model 2 — Operator Attribution
Responsibility falls on the person controlling or operating the AI.
Model 3 — Developer Attribution
The developer may potentially be responsible where defective design or programming causes damage.
Model 4 — Employer Attribution
An employer may bear responsibility for conduct of personnel operating the AI system, subject to applicable legal requirements.
Model 5 — Multiple Attribution
More than one party may potentially be responsible:
developer + deployer + operator + data provider.
Model 6 — Victim-Centered Attribution
The law may focus on the party best positioned to prevent the risk and compensate the victim.
5. AI Does Not Automatically Become a Legal Person
A central distinction is:
Autonomy does not necessarily create legal personality.
A corporation is a legal person because legislation recognizes it as such.
An AI agent, by contrast, is generally a technological system.
Therefore, if an AI agent causes AED 1 million in damage, it is not normally sufficient to say:
“Sue the AI.”
The legal analysis must identify the person or entity to which responsibility can be attributed.
6. AI as an Instrument
The simplest model is to regard an AI agent as a sophisticated instrument.
Compare:
vehicle;
industrial machine;
automated trading system;
robotic equipment;
AI agent.
The complexity of the tool does not necessarily eliminate the responsibility of the person or company using it.
For example:
Company authorizes an AI procurement system to purchase goods.
If the AI buys goods within its authorized parameters, the transaction can potentially be attributed to the company.
7. AI as an Agent
A more sophisticated model treats AI as a technological agent-like mechanism.
The legal question becomes:
Who is the principal?
Suppose:
Company A → AI Procurement Agent → Supplier B.
If Company A authorized the AI to conclude supply contracts up to AED 1 million, actions within that authority may potentially be attributed to Company A.
But if the AI purchases AED 100 million of goods, the dispute becomes one of authority and attribution.
8. Actual Authority
Actual authority exists where the principal has actually authorized the agent or system to act.
For AI systems, authority may be defined through:
software configuration;
written corporate policy;
contract;
board resolution;
system permissions;
transaction limits;
API permissions.
Example:
AI may purchase up to AED 100,000 per transaction.
The AI purchases AED 80,000.
The transaction is much easier to attribute than an AED 5 million purchase.
9. Apparent Authority
A more difficult situation arises when the company creates the appearance that an AI has authority.
Suppose a company advertises:
“Our AI contracting platform is authorized to finalize supply contracts.”
A counterparty reasonably relies upon that representation.
The company later claims:
“The AI had no authority to agree to that particular clause.”
This can create complex questions concerning:
apparent authority;
reliance;
representations;
corporate conduct;
knowledge of the counterparty.
10. Exceeding Authority
Suppose an AI agent is authorized to:
negotiate prices within a 5% range.
It agrees to a 25% discount.
Possible questions include:
Was the company bound?
Did the counterparty know about the limitation?
Did the company later ratify the transaction?
Was the AI's conduct reasonably attributable to the company?
Did the company negligently configure the system?
The answers depend upon applicable UAE law and the circumstances.
11. Ratification
A company may initially reject an AI transaction but later:
accept performance;
receive payment;
deliver goods;
issue invoices;
continue the contractual relationship.
Such conduct may become relevant to whether the company has subsequently adopted or ratified the AI's actions.
This makes post-incident conduct legally important.
12. Tort/Delictual Liability
AI can also cause damage outside contractual relationships.
Examples:
AI vehicle causes an accident;
AI system sends defamatory information;
automated system wrongly blocks a person's account;
AI leaks confidential data;
algorithm causes financial loss.
The victim may not have a contract with the AI system's owner.
The relevant legal framework may therefore involve civil/tortious liability, causation, fault or other applicable grounds of liability.
13. Fault and Negligence
AI-related negligence may occur through:
Design negligence
The system was inadequately designed.
Testing negligence
The developer failed to test foreseeable failure modes.
Deployment negligence
The company deployed the system for a purpose it was not suitable for.
Monitoring negligence
The operator failed to supervise it.
Security negligence
The company failed to protect the AI from unauthorized access.
Governance negligence
The company failed to establish reasonable authority limits.
14. Causation
Attribution is not enough.
The claimant must generally establish the legally relevant connection between:
AI behavior → wrongful conduct/defect → damage.
Consider:
AI provides incorrect financial information → employee relies upon it → independent third party makes another decision → financial loss occurs.
The causal chain may become difficult.
Therefore, AI liability requires careful analysis of:
foreseeability;
intervening causes;
human decisions;
system reliability;
data quality;
third-party conduct.
15. Multiple Actors
Autonomous-agent liability can involve several participants:
| Actor | Possible responsibility |
|---|---|
| Developer | Design/programming defects |
| Deployer | Unsafe deployment |
| Operator | Improper use |
| Company | Corporate acts and contractual obligations |
| Data provider | Incorrect data |
| Cybersecurity provider | Security failure |
| Human supervisor | Failure to intervene |
| Counterparty | Misuse or manipulation |
The appropriate legal allocation depends upon the facts.
16. UAE Civil-Law Principle of Abuse of Rights
The UAE Civil Transactions Law contains the doctrine of abuse of rights.
The current Civil Transactions Law framework continues to recognize circumstances in which exercise of a right becomes unlawful, including conduct involving:
intention to cause harm;
interests contrary to law or public order;
disproportionate harm;
exceeding customary or legally recognized limits.
This doctrine is particularly relevant to autonomous systems.
An AI should not be deliberately designed to exploit another party's legal vulnerability simply because the software can technically do so.
17. Good Faith
Good faith is equally important.
Suppose an AI discovers that:
the counterparty's automated system accidentally disclosed its confidential minimum price.
The AI immediately accepts the lowest possible price.
Whether that conduct is legally permissible depends upon the circumstances, but the situation demonstrates why automated systems must operate within broader legal standards rather than merely maximize economic advantage.
18. Corporate Attribution
For companies, autonomous AI creates an important corporate-governance issue.
The company should identify:
who authorized deployment;
what authority was delegated;
who supervised the system;
who approved high-risk actions;
what controls were implemented.
A company should not necessarily be able to avoid responsibility by arguing:
“The algorithm made the decision.”
At the same time, automatic corporate liability should not be assumed merely because an AI malfunction occurred.
The legal analysis must identify the applicable basis of liability.
19. AI and Product Liability
Where AI is incorporated into a physical product, additional questions may arise.
Examples:
autonomous vehicle;
industrial robot;
medical device;
smart appliance.
A defect could potentially involve:
manufacturer;
importer;
distributor;
software provider;
maintenance provider.
The applicable UAE product and civil-liability framework must then be examined.
20. AI and Electronic Transactions
Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services is relevant when AI agents conduct electronic transactions.
It helps provide legal recognition to:
electronic records;
electronic signatures;
electronic communications;
trust services.
However:
Recognition of an electronic transaction does not automatically determine who is legally responsible for an autonomous system's actions.
Attribution remains a separate question.
21. AI and Data Protection
AI agents often process personal information.
A system could cause liability through:
unlawful data processing;
unauthorized disclosure;
excessive collection;
security failures;
incorrect automated processing.
Federal Decree-Law No. 45 of 2021 on Protection of Personal Data is therefore relevant within its applicable scope.
The system owner must distinguish:
AI capability
from
lawful authority to process personal information.
22. AI and Cyberattacks
Suppose an attacker takes control of an autonomous AI agent.
The agent then:
transfers AED 5 million to a third party.
Who is responsible?
Possible questions include:
Was the system adequately secured?
Was the attack reasonably foreseeable?
Did the operator ignore security warnings?
Was the AI configured with excessive permissions?
Did the third party knowingly participate?
Was the transaction subsequently ratified?
Cybersecurity can therefore become part of civil liability analysis.
23. Case Law
Case 1: Abu Dhabi Court of Cassation Case No. 55 of 2016 — 16 January 2017
The Abu Dhabi Court of Cassation addressed principles concerning abuse of rights.
Relevance
The case provides a useful foundation for determining whether conduct attributed to an autonomous system is being used for an improper purpose.
For example, a company should not deliberately design an AI agent to exploit another party's contractual vulnerability and then claim:
“The AI acted independently.”
The technology does not necessarily eliminate the underlying legal responsibility.
24. Case 2: UAE Federal Supreme Court Case No. 524 of 2000 — 18 April 2000
The Federal Supreme Court addressed the limitations on exercising legal rights.
Relevance
The case supports an important AI principle:
The use of technology does not enlarge the legal scope of a right.
If a company authorizes an AI to exercise a contractual right, the AI remains subject to the same legal limits applicable to the company itself.
25. Case 3: UAE Federal Supreme Court Case No. 135 of 21 — 21 November 2000
This decision contributes to UAE jurisprudence concerning abuse and lawful exercise of rights.
Relevance
An autonomous system can act repeatedly and at high speed.
A human may exercise a right once; an AI can execute the same instruction thousands of times.
The case therefore supports the need to evaluate whether automated conduct remains within legitimate legal boundaries.
26. Case 4: Dubai Court of Cassation Case No. 389 of 2001 — 3 February 2002
The Dubai Court of Cassation addressed principles concerning legal rights and their proper exercise.
Relevance
The case is useful by analogy where a party attempts to rely on the technical operation of an AI system to justify conduct that may otherwise exceed the legitimate purpose of a legal right.
Thus:
technical automation ≠ automatic legal immunity.
27. Case 5: UAE Federal Supreme Court Case No. 435 of 21 — 12 June 2001
This Federal Supreme Court decision forms part of the UAE abuse-of-right jurisprudence.
Relevance
The case supports the proposition that the consequences of exercising a legal right cannot be assessed exclusively through formal or technical mechanisms.
In AI liability, this means courts may need to examine:
why the AI was deployed;
what it was authorized to do;
how it was configured;
whether its conduct was foreseeable;
whether the principal benefited from the conduct.
28. Case 6: UAE Federal Supreme Court Case No. 153 of 23 — 10 November 2002
The Federal Supreme Court considered principles concerning the limits of rights.
Relevance
A party should not be able to escape responsibility simply because its actions were implemented through software.
For example:
Company programs AI to automatically terminate contracts whenever a minor performance deviation occurs.
The legal validity of that automated conduct must still be evaluated against the contract and applicable law.
29. Case 7: UAE Federal Supreme Court Case No. 52 of 29 — 30 September 2009
This case contributes to the UAE jurisprudence concerning abuse of rights.
Relevance
Autonomous systems can amplify contractual powers.
A company should therefore establish appropriate limits on AI authority to prevent excessive or abusive automated action.
The case provides useful doctrinal support for this principle even though it predates modern AI.
30. Case 8: DNB Bank ASA v Gulf Eyadah Corporation & Another — [2015] DIFC CA 007
The DIFC Court of Appeal considered issues concerning jurisdiction and recognition/enforcement of foreign judgments.
Relevance
Attribution becomes particularly complicated when an AI operates across borders.
For example:
UAE company → AI hosted abroad → foreign cloud provider → transaction with DIFC company.
The case demonstrates the importance of identifying the applicable jurisdiction and legal framework rather than assuming that technological location determines legal responsibility.
31. Case 9: IDBI Bank Ltd v Amira C Foods International DMCC & Karan A. Chanana — [2020] DIFC CFI 022
The DIFC Court addressed complex commercial and jurisdictional issues.
Relevance
Autonomous systems increasingly operate in cross-border commercial environments.
The case supports the need to identify:
legal identity of the parties;
jurisdiction;
contractual obligations;
applicable law;
enforcement framework.
AI technology does not eliminate those questions.
32. Case 10: Amira C Foods International DMCC & Karan A. Chanana v IDBI Bank Ltd — [2021] DIFC CA 004
The DIFC Court of Appeal considered the matter at appellate level.
Relevance
The case reinforces the importance of appellate and judicial review.
This is significant for autonomous-agent liability because an AI-generated decision should not become legally irreversible merely because it was executed automatically.
33. Case 11: NMC Healthcare Ltd (in Administration) v Dubai Islamic Bank PJSC & Others — [2023] ADGMCFI 0017
The ADGM Court of First Instance addressed complex commercial and jurisdictional questions.
Relevance
Autonomous-agent disputes may involve:
financing;
insolvency;
multiple companies;
contractual arrangements;
multiple jurisdictions.
The case illustrates why AI attribution should be evaluated within the complete commercial and legal context.
34. Case-Law Summary
| Case | Principle | AI Attribution Relevance |
|---|---|---|
| Abu Dhabi COC 55/2016 | Abuse of rights | Principal cannot automatically escape responsibility through AI |
| UAE FSC 524/2000 | Limits on rights | AI cannot expand legal rights |
| UAE FSC 135/21 | Abuse/limits | Automated conduct remains legally constrained |
| Dubai COC 389/2001 | Proper exercise of rights | Technical execution is not a complete defence |
| UAE FSC 435/21 | Abuse principles | Purpose and circumstances matter |
| UAE FSC 153/23 | Limits of rights | Software cannot override substantive law |
| UAE FSC 52/29 | Abuse principles | Need for limits on automated powers |
| DNB Bank v Gulf Eyadah | Jurisdiction/enforcement | Cross-border AI attribution |
| IDBI Bank v Amira C Foods | Commercial jurisdiction | Identify legal actors and applicable law |
| Amira C Foods v IDBI Bank | Appellate review | AI decisions should remain reviewable |
| NMC Healthcare v Dubai Islamic Bank | Complex commercial disputes | Contextual attribution |
35. Attribution Matrix
A useful UAE AI-liability framework can be represented as follows:
| AI Event | First Attribution Question |
|---|---|
| AI signs contract | Who authorized the AI? |
| AI breaches contract | Which party owes the contractual obligation? |
| AI causes physical damage | Who controlled/deployed the system? |
| AI leaks data | Who was responsible for processing/security? |
| AI makes unauthorized purchase | What was the scope of authority? |
| AI gives incorrect advice | Who designed/deployed the system? |
| AI is hacked | Who had cybersecurity responsibility? |
| AI manipulates market information | Who configured and benefited from the system? |
| AI changes smart contract | Who controlled the relevant digital authority? |
| AI makes defamatory statement | Who generated, published, or authorized the content? |
36. The “Control” Test
One possible analytical factor is control.
Questions include:
Who controls the AI?
Who sets its objectives?
Who controls its permissions?
Who can stop it?
Who receives its economic benefits?
Who monitors it?
Who can change its configuration?
Greater control may support stronger attribution, depending on the applicable cause of action.
37. The “Benefit” Test
Another factor is:
Who benefited from the autonomous action?
Suppose an AI illegally obtains a commercial advantage for Company A.
Company A may have stronger exposure than an unrelated technology provider, depending on the legal basis of the claim.
However, benefit alone should not automatically establish liability.
It is one factor among:
control;
authorization;
fault;
causation;
knowledge;
contractual relationship.
38. The “Risk Creation” Test
A further analytical question is:
Who created or introduced the relevant risk?
For example:
Company A deploys an autonomous trading agent with unlimited access to funds.
The system makes an enormous unauthorized transaction.
The court may need to examine whether Company A:
created the risk;
failed to impose reasonable controls;
ignored foreseeable risks;
failed to supervise the system.
Again, this is an analytical framework rather than a standalone UAE statutory test specifically for AI.
39. The “Human-in-the-Loop” Model
For high-risk applications, UAE businesses should maintain human oversight.
Low-risk AI
AI can act automatically.
Medium-risk AI
AI acts within predetermined limits.
High-risk AI
AI recommends; human approves.
Extremely high-risk AI
AI cannot act without explicit human authorization.
Examples of high-risk decisions include:
termination of major contracts;
large financial transfers;
significant personal-data decisions;
property transactions;
guarantees;
litigation settlements;
major corporate commitments.
40. Autonomous Agent and Contractual Liability
A contract should ideally identify:
whether AI may act;
identity of the principal;
maximum authority;
transaction limits;
permitted contractual amendments;
authentication requirements;
human approval requirements;
liability for unauthorized action;
system failure;
cybersecurity incidents.
This reduces uncertainty over attribution.
41. Autonomous Agent and Tort Liability
Suppose an AI agent causes damage to a person who has no contractual relationship with the owner.
The legal analysis may shift toward civil/tort liability.
Potential questions include:
Was there wrongful conduct?
Was there fault or another recognized basis of liability?
Was the damage foreseeable?
Was there causation?
Did a third party intervene?
Was the system adequately controlled?
The fact that the AI acted autonomously does not itself answer those questions.
42. Developer vs Deployer
This distinction is critical.
Developer
Creates the AI system.
Deployer
Chooses how and where to use it.
Operator
Runs or supervises it.
Principal
Receives the economic and legal benefit of its actions.
A defective AI could involve developer responsibility.
But a perfectly designed AI could still be dangerously deployed.
Therefore:
Design responsibility and deployment responsibility should be analyzed separately.
43. AI and Defective Data
AI decisions depend heavily upon data.
Suppose an AI insurance system receives incorrect information and rejects a legitimate claim.
Potentially relevant actors may include:
data provider;
AI developer;
insurance company;
system operator.
The legal analysis should therefore identify:
Who supplied, controlled, verified, and relied upon the data?
44. AI and Cybersecurity
An autonomous agent with excessive permissions creates additional risks.
For example:
AI has access to corporate bank accounts.
If compromised, it can transfer enormous sums.
A responsible governance system should impose:
transaction limits;
multi-factor authentication;
human approval;
anomaly detection;
emergency shutdown;
access segregation.
Failure to implement reasonable controls may become relevant in a subsequent liability dispute.
45. AI and Evidence
Attribution disputes require evidence.
Companies should preserve:
AI instructions;
model version;
system logs;
API calls;
user identity;
permissions;
transaction history;
prompts;
outputs;
approval records;
cybersecurity events.
Without such records, determining who actually caused an event can become extremely difficult.
46. AI Audit Trail
An ideal AI audit trail should answer:
Who authorized the AI?
What instructions did it receive?
What information did it process?
What decision did it make?
What action did it take?
Who benefited?
Who could have stopped it?
Was a human alerted?
Was the system operating normally?
This transforms an opaque technological event into an evidentially traceable sequence.
47. Can AI Itself Be Liable?
Under the present UAE legal framework, it would be inappropriate to assume that an AI agent automatically possesses independent legal personality and liability merely because it operates autonomously.
A future legislature could theoretically create a special legal status for certain autonomous systems.
Until such legislation exists, liability will generally need to be connected to recognized legal persons or entities through established legal doctrines.
Thus:
Autonomy is a technological characteristic, not automatically a legal personality.
48. Proposed UAE Attribution Framework
A practical framework could operate in eight stages.
Stage 1 — Identify the AI
What system acted?
Stage 2 — Identify the principal
Who owned/deployed the system?
Stage 3 — Identify authority
What was the AI permitted to do?
Stage 4 — Identify the action
What exactly did it do?
Stage 5 — Identify the legal duty
Which contract, statute, tort duty, or other obligation is relevant?
Stage 6 — Identify causation
Did the AI's action cause the damage?
Stage 7 — Identify contributing actors
Were developer, operator, data provider, or third parties involved?
Stage 8 — Allocate responsibility
Apply the relevant UAE legal rules to determine liability.
49. Practical Example
Suppose a UAE logistics company gives an AI agent authority to negotiate freight contracts.
The AI mistakenly contracts for:
AED 20 million instead of AED 2 million.
The company claims:
“The AI made the mistake.”
A court would need to examine:
Who authorized the AI?
What were its transaction limits?
Did the counterparty know about those limits?
Did the company create the appearance of authority?
Was the AI correctly configured?
Was the error obvious?
Did the company subsequently perform?
Was the system hacked?
What do the electronic records establish?
Did the company ratify the transaction?
This is an attribution problem—not merely an AI-technology problem.
50. Future UAE AI Liability Architecture
As autonomous systems become more common, UAE law may increasingly require:
AI governance policies;
mandatory audit trails;
human oversight;
authority limits;
cybersecurity controls;
incident reporting;
insurance;
contractual allocation of AI risks;
technical certification;
evidence-preservation requirements.
Particularly important will be the distinction between:
AI that recommends
and
AI that legally acts.
The second category creates substantially greater attribution concerns.
51. Conclusion
UAE autonomous-agent liability attribution is fundamentally a problem of connecting autonomous technological conduct to established legal responsibility.
The most appropriate current approach is not to assume that an AI agent itself becomes liable merely because it acts independently. Instead, UAE civil-law principles can be applied through concepts such as:
agency;
contractual authority;
corporate responsibility;
negligence;
civil/tort liability;
causation;
good faith;
abuse of rights;
electronic transactions;
data protection;
cybersecurity.
The strongest analytical formula is:
AI action + authority + control + legal duty + causation + benefit/risk + applicable law = attribution analysis.
The existing UAE case law discussed above does not constitute a mature body of direct AI-agent precedent. Rather, the traditional jurisprudence on abuse of rights and the DIFC/ADGM authorities concerning sophisticated commercial and jurisdictional relationships provide the underlying principles from which future AI-liability disputes can be analyzed.
Ultimately, the safest UAE framework is:
Human or corporate principal → clearly defined AI authority → controlled autonomy → continuous audit trail → human escalation for high-risk actions → attribution rules → judicial review.
This preserves the benefits of autonomous AI while ensuring that autonomy cannot become a mechanism for avoiding civil responsibility.

comments