Civil Law And Uae Fragmentation Of Liability Concepts In Networked Systems .
Civil Law and UAE: Fragmentation of Liability Concepts in Networked Systems
1. Meaning
Fragmentation of liability in networked systems refers to the difficulty of identifying, allocating, and proving civil responsibility when harm results from the combined activity of many interconnected actors rather than from one clearly identifiable wrongdoer.
A traditional civil-liability model is:
Actor → Wrongful Act → Causation → Damage → Liability → Compensation
A networked system may instead look like:
User → Platform → Developer → Cloud Provider → API → Data Provider → Payment Processor → Custodian → Automated System → Third Party
If something goes wrong, several participants may have contributed to the eventual loss.
Examples include:
cyberattacks;
fintech failures;
blockchain transactions;
AI systems;
cloud-service failures;
payment-platform disputes;
digital-asset custody;
online marketplaces;
smart contracts;
interconnected supply chains.
The fundamental UAE civil-law problem is therefore:
How should civil liability be allocated when multiple legally and technically distinct actors contribute to one harmful outcome?
2. Traditional Civil-Law Model
Traditional civil liability normally asks four basic questions:
Was there a legally relevant act or omission?
Was there a breach of a legal duty?
Did that conduct cause the damage?
What loss is legally compensable?
The model can be expressed as:
Duty → Breach → Causation → Damage → Remedy
This model works relatively easily where there is one claimant and one defendant.
For example:
A driver negligently damages B's vehicle.
The causal chain is comparatively short:
Driver's negligence → Collision → Vehicle damage
3. Networked Liability
In a networked environment, the chain can become:
Software developer
↓
Platform operator
↓
Cloud infrastructure
↓
Data provider
↓
Automated algorithm
↓
Payment processor
↓
Customer
↓
Third-party intervention
↓
Financial loss
There may be no single event that explains the entire damage.
Instead, responsibility may be distributed across several points in the network.
4. UAE Civil-Law Foundation
The current UAE civil-law framework is the Federal Decree-Law No. 25 of 2025, which entered into force on 1 June 2026 and repealed the 1985 Civil Transactions Law.
For harmful acts, the new Code adopts a compensation framework under which compensation is assessed by reference to the extent of the loss and lost profit where the loss of profit is a natural consequence of the harmful act.
This is particularly important for networked systems because the court must determine whether the eventual digital or economic harm is sufficiently connected to the defendant's conduct.
The modern question is therefore not merely:
“Who was involved?”
but:
“Which participant's legally relevant conduct caused which part of the loss?”
5. Liability Fragmentation
Liability can become fragmented in at least eight ways.
1. Actor fragmentation
Many people or companies participate.
2. Functional fragmentation
Different actors perform different technical functions.
3. Contractual fragmentation
Each participant may have a separate contract.
4. Geographic fragmentation
Participants may be located in different countries.
5. Causal fragmentation
Multiple events contribute to the damage.
6. Regulatory fragmentation
Different regulators may oversee different components.
7. Evidentiary fragmentation
Relevant evidence may exist across different databases and systems.
8. Enforcement fragmentation
Even after liability is established, responsible assets may be located elsewhere.
6. Legal Identity of Network Participants
One of the first problems is identifying the legally relevant actors.
A digital network might contain:
owner;
user;
developer;
operator;
administrator;
intermediary;
custodian;
payment provider;
cloud provider;
data controller;
data processor;
algorithm designer;
service provider;
beneficiary.
Technical participation does not automatically establish civil liability.
For example:
API provider ≠ platform operator
software developer ≠ user
wallet controller ≠ beneficial owner
cloud provider ≠ customer
algorithm ≠ legal person
The court must identify the relevant legal relationship before allocating liability.
7. Case Law 1 — Gate Mena v Tabarak Investment Capital
Gate Mena DMCC v Tabarak Investment Capital Ltd & Christian Thurner [2023] DIFC CA 002
This is an important authority concerning responsibility where one person is entrusted with control over another's property and affairs.
The DIFC Court of Appeal examined fiduciary obligations arising from the entrustment of authority and discretionary power.
The case illustrates that liability can arise from the functional role performed by an actor, rather than merely from formal ownership.
Principle
A person exercising control over another's property or affairs may owe duties involving:
loyalty;
avoiding conflicts;
avoiding secret profits;
proper use of information;
reasonable care and skill.
Networked-systems relevance
In digital networks, a person may not own the underlying asset but may exercise significant functional control over it.
Thus:
Control → Duty → Breach → Causation → Liability
can become more important than simple legal ownership.
8. Case Law 2 — Techteryx Ltd v Aria Commodities
Techteryx Ltd v Aria Commodities DMCC & Others [2025] DIFC DEC 001
This Digital Economy Court case involved a dispute concerning stablecoins and associated reserve assets.
The proceedings illustrate how traditional civil remedies such as:
proprietary claims;
tracing;
injunctions;
asset preservation;
can operate in a digital-asset environment.
Principle
The technological complexity of an asset does not eliminate traditional civil-law questions concerning:
ownership;
control;
possession;
tracing;
unjust enrichment;
fiduciary responsibility;
remedies.
Networked-liability significance
A digital asset transaction may involve several layers:
Token holder → platform → custodian → bank → reserve asset
Liability must therefore be allocated according to the legal role and conduct of each participant.
9. Case Law 3 — CoinMENA B.S.C. (C) v Foloosi Technologies Ltd
CoinMENA B.S.C. (C) v Foloosi Technologies Ltd [2025] DIFC CFI 067/2025
This fintech dispute demonstrates how civil claims involving digital-payment infrastructure can require the court to examine relationships between different technology and financial-service actors.
Principle
The fact that a transaction occurs through technological infrastructure does not eliminate ordinary contractual questions concerning:
obligations;
performance;
authority;
breach;
loss;
causation.
Networked significance
A payment failure can involve:
Customer → Fintech platform → Payment technology → Banking infrastructure
The court must identify which contractual relationship creates which obligation.
10. Case Law 4 — Graciela Ltd v Giacobbe
Graciela Limited v Giacobbe [2014] DIFC CFI 027
This case concerned sabotage of an IT system by a former employee.
The claimant incurred substantial expenses relating to:
restoration;
investigation;
network reconstruction;
emergency servers;
contractors;
employee time.
The Court awarded damages for losses connected with the IT-system damage.
Principle
Damage to a digital system can produce multiple consequential categories of recoverable economic loss.
Networked significance
The case illustrates the difference between:
technical event
and
legal consequences of that event.
An attack may technically affect one system but economically affect:
operations;
employees;
customers;
infrastructure;
business continuity.
Liability analysis therefore requires reconstruction of the causal chain.
11. Case Law 5 — IDBI Bank Ltd v Amira C Foods
IDBI Bank Ltd v Amira C Foods International DMCC [2019] DIFC CA 014
The DIFC Court of Appeal examined causation, damages and evidentiary questions surrounding alleged financial and reputational harm.
The Court's reasoning illustrates that a claimant must establish an appropriate connection between the alleged wrongful conduct and the claimed loss.
Principle
A claimant cannot simply identify a defendant's wrongful conduct and then attribute every subsequent economic consequence to that conduct.
There must be:
Wrong → Causal connection → Proven loss
Networked significance
This is crucial in interconnected systems because a single digital incident may be followed by numerous independent events.
12. Case Law 6 — Faizal Babu Moorkath v Expresso Telecom Group
Faizal Babu Moorkath v Expresso Telecom Group Ltd [2023] DIFC CFI 008
The Court emphasised that a civil claim requires legally recognised and sufficiently established loss.
The case is useful for distinguishing:
mere wrongdoing;
actionable loss;
legally recoverable damage.
Principle
Not every adverse consequence of conduct automatically becomes compensable damage.
Networked significance
In digital systems, claimants may identify:
lost opportunities;
reputational effects;
business disruption;
market effects;
consequential losses.
Each category still requires legal and evidentiary analysis.
13. Case Law 7 — Globemed Gulf Healthcare Solutions v Oman Insurance
Globemed Gulf Healthcare Solutions LLC v Oman Insurance Company PSC [2017] DIFC CFI 051
The Court distinguished actual or sufficiently certain future loss from merely speculative future harm.
Principle
A future loss cannot become recoverable merely because it is theoretically possible.
There must be sufficient certainty concerning the relevant damage.
Networked significance
Networked systems often produce long-tail consequences.
For example:
Cyberattack → customer loss → reputational decline → future revenue reduction
The claimant must establish whether the later losses are sufficiently certain and legally connected to the original event.
14. Case Law 8 — Linux v Lizeth
Linux v Lizeth [2022] DIFC SCT 237
The dispute involved allegations concerning a copied digital platform and associated business, data and security-related losses.
The case demonstrates that digital claims remain subject to ordinary requirements concerning:
contractual obligations;
proof;
causation;
loss.
Principle
The digital character of a dispute does not eliminate the requirement to establish the legal basis of liability.
Networked significance
Digital networks can create many technical explanations for a loss, but civil liability still requires a legally supported causal theory.
15. Multiple Causes
One of the biggest problems in networked systems is concurrent causation.
Suppose:
Platform A has a security weakness;
Provider B fails to update software;
User C ignores a security warning;
Attacker D exploits the vulnerability.
The final loss may result from all four factors.
The legal question becomes:
Should one actor bear all of the loss, or should responsibility be divided?
The answer depends on the applicable rules concerning:
causation;
contribution;
fault;
contractual allocation;
contributory conduct;
intervening events;
statutory responsibility.
16. Chain of Causation
A useful analytical model is:
Initial Conduct
↓
Technical Event
↓
Intermediate Event
↓
Third-Party Conduct
↓
Economic Consequence
↓
Claimed Loss
The court should examine every important link.
For example:
Negligent cybersecurity
↓
Unauthorised access
↓
Data alteration
↓
Payment fraud
↓
Bank rejection
↓
Customer losses
The defendant may be responsible for some consequences but not necessarily every consequence.
17. Intervening Acts
A third party may intervene between the defendant's conduct and the eventual harm.
Examples include:
hackers;
employees;
customers;
independent contractors;
banks;
software providers.
But third-party intervention does not automatically eliminate the original actor's liability.
The important questions are:
Was the intervention foreseeable?
Was it independent?
Was it extraordinary?
Did it constitute a new dominant cause?
Was the original defendant already under a duty to protect against that type of risk?
18. Contractual Fragmentation
Networked systems frequently operate through a chain of separate contracts.
For example:
Customer ↔ Platform
Platform ↔ Cloud Provider
Platform ↔ Payment Processor
Payment Processor ↔ Bank
Developer ↔ Platform
A customer may therefore discover that the actor technically responsible for the failure is not the party with whom the customer contracted.
This creates questions concerning:
privity;
third-party rights;
agency;
negligence/civil liability;
implied duties;
warranties;
limitation clauses;
indemnities.
19. Liability Allocation Through Contracts
Parties can often allocate risk through:
indemnities;
warranties;
insurance;
limitation clauses;
exclusion clauses;
service-level agreements;
cybersecurity obligations;
audit rights;
compliance obligations.
Thus contractual fragmentation can become a mechanism for private allocation of network risk.
However, contractual allocation cannot necessarily eliminate mandatory statutory liability or obligations imposed by public law.
20. Distributed Liability
A network may contain several categories of responsibility.
Primary liability
The actor whose conduct directly caused the loss.
Secondary liability
A person responsible because of a legally recognised relationship with another actor.
Contractual liability
Responsibility arising from failure to perform an agreement.
Civil/tort liability
Responsibility arising from harmful conduct independently of contract.
Fiduciary liability
Responsibility arising from entrusted authority or property.
Regulatory liability
Consequences of violating regulatory obligations.
These categories should not automatically be merged.
21. Regulatory Breach Does Not Automatically Equal Civil Damages
A particularly important distinction is:
Regulatory violation ≠ automatic private-law damages
A regulatory breach may be evidence relevant to a civil claim, but the claimant may still need to establish:
legally protected interest;
breach;
causation;
actual loss;
recoverability.
This is particularly important in fintech and AI disputes.
22. AI Network Liability
AI creates an especially fragmented responsibility structure.
Consider:
Developer
↓
Model provider
↓
Data provider
↓
Cloud provider
↓
Integrator
↓
Business deploying AI
↓
Human decision-maker
↓
Affected person
If an AI system produces harmful output, possible questions include:
Who designed the system?
Who supplied the data?
Who deployed it?
Who controlled its operation?
Who failed to supervise it?
Was there a warning?
Was human review required?
Was the harm foreseeable?
Which actor had the ability to prevent it?
The central civil-law issue is therefore attribution.
23. Blockchain and DAO Liability
Blockchain systems create another problem because control may be distributed.
A DAO could involve:
developers;
token holders;
governance participants;
multisignature controllers;
treasury managers;
infrastructure providers;
smart-contract developers.
A technically decentralised network does not automatically become a legally personless environment.
The court must identify:
Technical Role → Legal Role → Duty → Conduct → Causation → Liability
24. Smart Contracts
A smart contract can automatically execute code.
But:
Automatic execution ≠ automatic legal validity
A smart contract may still raise questions about:
contractual intention;
authority;
mistake;
fraud;
programming error;
breach;
restitution;
unjust enrichment;
ownership;
remedies.
The software executes automatically, but civil law must determine who is legally responsible for the relevant transaction or defect.
25. Cybersecurity Liability
Cyber incidents are a classic example of fragmented liability.
Suppose a platform suffers a data breach.
Potential actors include:
software developer;
platform operator;
cloud provider;
security contractor;
employee;
attacker;
data processor.
The legal inquiry should identify:
Duty
Who owed the relevant security obligation?
Breach
Who failed to meet it?
Causation
Did that failure materially contribute to the breach?
Loss
What damage resulted?
Allocation
Should responsibility be divided?
26. Evidentiary Fragmentation
Networked systems create large quantities of evidence:
server logs;
blockchain records;
emails;
access records;
API logs;
transaction histories;
metadata;
security reports;
expert analyses.
Evidence may be controlled by several independent entities.
Consequently, proving liability can itself become a network problem.
A claimant may need:
Digital Evidence → Technical Expert → Causal Reconstruction → Legal Attribution
27. Expert Evidence
Technical complexity often requires expert evidence.
However, an expert should generally explain:
how the system worked;
what happened technically;
what caused the failure;
what financial consequences followed.
The court, rather than the expert, decides the ultimate legal question of liability.
This distinction is particularly important in AI, cybersecurity and blockchain disputes.
28. The "Many Actors, One Harm" Problem
The central conceptual difficulty can be represented as:
Developer │ Cloud Provider ──┼── Platform │ Payment Provider │ User │ Third-Party Event │ LOSS
The loss may be singular.
The causes may be plural.
Therefore:
One Harm ≠ One Defendant
29. Fragmentation and Proportionate Responsibility
Where several parties contributed to the loss, the legal system may need to determine:
whether each actor is independently liable;
whether liability is joint;
whether liability is several;
whether contribution is available;
whether the claimant's own conduct contributed;
whether contractual indemnification reallocates the economic burden.
The answer depends upon the applicable UAE federal, Emirate-level, DIFC, ADGM or foreign rules governing the particular dispute.
30. Digital Causation Model
For examination and legal analysis, use this model:
Digital Conduct
↓
Identifiable Legal Duty
↓
Breach
↓
Technical Causal Event
↓
Intermediate Events
↓
Foreseeable/Natural Consequence
↓
Proven Damage
↓
Recoverable Loss
↓
Allocation of Liability
This prevents the analysis from jumping directly from:
"The defendant was connected to the system"
to:
"The defendant is responsible for everything that happened."
31. Key Principles From the Cases
| Case | Important principle |
|---|---|
| Gate Mena v Tabarak [2023] DIFC CA 002 | Functional control can generate fiduciary responsibilities |
| Techteryx v Aria Commodities [2025] DIFC DEC 001 | Traditional civil remedies can operate in digital-asset networks |
| CoinMENA v Foloosi [2025] DIFC CFI 067/2025 | Fintech disputes remain subject to ordinary contractual analysis |
| Graciela v Giacobbe [2014] DIFC CFI 027 | Digital-system damage can generate consequential economic loss |
| IDBI Bank v Amira C Foods [2019] DIFC CA 014 | Loss requires appropriate causal and evidentiary connection |
| Faizal Babu Moorkath v Expresso Telecom [2023] DIFC CFI 008 | Actionable loss must be legally recognised and established |
| Globemed v Oman Insurance [2017] DIFC CFI 051 | Future loss must satisfy sufficient certainty |
| Linux v Lizeth [2022] DIFC SCT 237 | Digital claims still require proof of contractual/legal causation and loss |
32. UAE-Specific Legal Challenges
A. Multiple court systems
UAE onshore courts, DIFC Courts and ADGM Courts operate within distinct legal frameworks.
B. Multiple governing laws
A contract may select foreign law.
C. Cross-border defendants
The relevant actor may be outside the UAE.
D. Digital assets
Assets may exist through globally distributed technological infrastructure.
E. AI
Responsibility may be divided between developers, providers and users.
F. Cybersecurity
Evidence and technical infrastructure may cross borders.
G. Enforcement
The responsible party's assets may be in another jurisdiction.
33. Fragmentation Does Not Mean No Liability
A common mistake is to assume:
"Because many actors contributed, nobody can be held responsible."
That is incorrect.
Fragmentation changes the method of attribution.
The court can ask:
Who owed the duty?
Who controlled the relevant risk?
Who breached the duty?
Which conduct caused which loss?
Was the loss a natural or legally attributable consequence?
Did another event intervene?
What remedy is legally available?
34. A Unified UAE Analytical Framework
For a networked civil-liability dispute, the following framework is useful:
Step 1 — Map the network
Identify every relevant actor.
Step 2 — Identify legal relationships
Determine which parties are connected contractually, fiduciary-wise or through other legal relationships.
Step 3 — Identify duties
Determine the legal duty applicable to each participant.
Step 4 — Identify breach
Determine precisely what each actor allegedly did or failed to do.
Step 5 — Reconstruct causation
Trace the technical and factual chain.
Step 6 — Separate losses
Identify:
direct loss;
consequential loss;
lost profits;
future loss;
moral harm where relevant.
Step 7 — Consider intervening causes
Analyse third-party conduct and independent events.
Step 8 — Allocate liability
Determine the legal responsibility of each participant.
Step 9 — Apply contractual risk allocation
Consider:
indemnities;
warranties;
insurance;
limitation clauses.
Step 10 — Determine remedy
Consider compensation, restitution, injunctions, specific performance or other applicable remedies.
35. Examination Answer Structure
A strong answer can be condensed into:
Fragmentation of liability in networked systems occurs when multiple interconnected technical and legal actors contribute to a single harmful outcome. UAE civil law addresses this problem through the identification of legally relevant actors, duties, breach, causation, recoverable loss and remedies. Digital complexity does not itself create liability, nor does the presence of multiple actors eliminate it. Cases such as Gate Mena v Tabarak, Techteryx v Aria Commodities, CoinMENA v Foloosi, Graciela v Giacobbe, IDBI Bank v Amira C Foods, Faizal Babu Moorkath v Expresso Telecom, Globemed v Oman Insurance and Linux v Lizeth illustrate how traditional civil-law concepts can be applied to increasingly interconnected digital and commercial environments.
36. Conclusion
Fragmentation of liability concepts in networked systems represents a major challenge for contemporary UAE civil law.
Traditional civil liability assumes a relatively identifiable relationship:
Wrongdoer → Wrong → Damage → Compensation
Networked systems replace that simple structure with:
Multiple Actors → Multiple Duties → Multiple Interventions → Multiple Causal Links → Multiple Losses
The UAE legal response is therefore likely to depend increasingly on functional attribution rather than purely technological attribution. The fact that an actor operates a platform, writes code, provides infrastructure, controls a wallet or processes data does not by itself establish liability. The decisive analysis remains the identification of the legal role, applicable duty, breach, causal connection and legally recoverable damage.
The most useful formula is:
Network Participant → Legal Role → Duty → Breach → Causation → Natural/Legally Attributable Consequence → Proven Loss → Liability → Remedy
That framework allows classical UAE civil-law principles to be applied to modern fintech, AI, cybersecurity, blockchain, cloud computing, digital platforms and other networked systems without assuming that technological complexity automatically produces either unlimited or unassignable liability.

comments