Civil Law And Uae Fragmentation Of Liability Concepts In Networked Systems .

Civil Law and UAE: Fragmentation of Liability Concepts in Networked Systems

1. Meaning

Fragmentation of liability in networked systems refers to the difficulty of identifying, allocating, and proving civil responsibility when harm results from the combined activity of many interconnected actors rather than from one clearly identifiable wrongdoer.

A traditional civil-liability model is:

Actor → Wrongful Act → Causation → Damage → Liability → Compensation

A networked system may instead look like:

User → Platform → Developer → Cloud Provider → API → Data Provider → Payment Processor → Custodian → Automated System → Third Party

If something goes wrong, several participants may have contributed to the eventual loss.

Examples include:

cyberattacks;

fintech failures;

blockchain transactions;

AI systems;

cloud-service failures;

payment-platform disputes;

digital-asset custody;

online marketplaces;

smart contracts;

interconnected supply chains.

The fundamental UAE civil-law problem is therefore:

How should civil liability be allocated when multiple legally and technically distinct actors contribute to one harmful outcome?

2. Traditional Civil-Law Model

Traditional civil liability normally asks four basic questions:

Was there a legally relevant act or omission?

Was there a breach of a legal duty?

Did that conduct cause the damage?

What loss is legally compensable?

The model can be expressed as:

Duty → Breach → Causation → Damage → Remedy

This model works relatively easily where there is one claimant and one defendant.

For example:

A driver negligently damages B's vehicle.

The causal chain is comparatively short:

Driver's negligence → Collision → Vehicle damage

3. Networked Liability

In a networked environment, the chain can become:

Software developer

Platform operator

Cloud infrastructure

Data provider

Automated algorithm

Payment processor

Customer

Third-party intervention

Financial loss

There may be no single event that explains the entire damage.

Instead, responsibility may be distributed across several points in the network.

4. UAE Civil-Law Foundation

The current UAE civil-law framework is the Federal Decree-Law No. 25 of 2025, which entered into force on 1 June 2026 and repealed the 1985 Civil Transactions Law.

For harmful acts, the new Code adopts a compensation framework under which compensation is assessed by reference to the extent of the loss and lost profit where the loss of profit is a natural consequence of the harmful act.

This is particularly important for networked systems because the court must determine whether the eventual digital or economic harm is sufficiently connected to the defendant's conduct.

The modern question is therefore not merely:

“Who was involved?”

but:

“Which participant's legally relevant conduct caused which part of the loss?”

5. Liability Fragmentation

Liability can become fragmented in at least eight ways.

1. Actor fragmentation

Many people or companies participate.

2. Functional fragmentation

Different actors perform different technical functions.

3. Contractual fragmentation

Each participant may have a separate contract.

4. Geographic fragmentation

Participants may be located in different countries.

5. Causal fragmentation

Multiple events contribute to the damage.

6. Regulatory fragmentation

Different regulators may oversee different components.

7. Evidentiary fragmentation

Relevant evidence may exist across different databases and systems.

8. Enforcement fragmentation

Even after liability is established, responsible assets may be located elsewhere.

6. Legal Identity of Network Participants

One of the first problems is identifying the legally relevant actors.

A digital network might contain:

owner;

user;

developer;

operator;

administrator;

intermediary;

custodian;

payment provider;

cloud provider;

data controller;

data processor;

algorithm designer;

service provider;

beneficiary.

Technical participation does not automatically establish civil liability.

For example:

API provider ≠ platform operator

software developer ≠ user

wallet controller ≠ beneficial owner

cloud provider ≠ customer

algorithm ≠ legal person

The court must identify the relevant legal relationship before allocating liability.

7. Case Law 1 — Gate Mena v Tabarak Investment Capital

Gate Mena DMCC v Tabarak Investment Capital Ltd & Christian Thurner [2023] DIFC CA 002

This is an important authority concerning responsibility where one person is entrusted with control over another's property and affairs.

The DIFC Court of Appeal examined fiduciary obligations arising from the entrustment of authority and discretionary power.

The case illustrates that liability can arise from the functional role performed by an actor, rather than merely from formal ownership.

Principle

A person exercising control over another's property or affairs may owe duties involving:

loyalty;

avoiding conflicts;

avoiding secret profits;

proper use of information;

reasonable care and skill.

Networked-systems relevance

In digital networks, a person may not own the underlying asset but may exercise significant functional control over it.

Thus:

Control → Duty → Breach → Causation → Liability

can become more important than simple legal ownership.

8. Case Law 2 — Techteryx Ltd v Aria Commodities

Techteryx Ltd v Aria Commodities DMCC & Others [2025] DIFC DEC 001

This Digital Economy Court case involved a dispute concerning stablecoins and associated reserve assets.

The proceedings illustrate how traditional civil remedies such as:

proprietary claims;

tracing;

injunctions;

asset preservation;

can operate in a digital-asset environment.

Principle

The technological complexity of an asset does not eliminate traditional civil-law questions concerning:

ownership;

control;

possession;

tracing;

unjust enrichment;

fiduciary responsibility;

remedies.

Networked-liability significance

A digital asset transaction may involve several layers:

Token holder → platform → custodian → bank → reserve asset

Liability must therefore be allocated according to the legal role and conduct of each participant.

9. Case Law 3 — CoinMENA B.S.C. (C) v Foloosi Technologies Ltd

CoinMENA B.S.C. (C) v Foloosi Technologies Ltd [2025] DIFC CFI 067/2025

This fintech dispute demonstrates how civil claims involving digital-payment infrastructure can require the court to examine relationships between different technology and financial-service actors.

Principle

The fact that a transaction occurs through technological infrastructure does not eliminate ordinary contractual questions concerning:

obligations;

performance;

authority;

breach;

loss;

causation.

Networked significance

A payment failure can involve:

Customer → Fintech platform → Payment technology → Banking infrastructure

The court must identify which contractual relationship creates which obligation.

10. Case Law 4 — Graciela Ltd v Giacobbe

Graciela Limited v Giacobbe [2014] DIFC CFI 027

This case concerned sabotage of an IT system by a former employee.

The claimant incurred substantial expenses relating to:

restoration;

investigation;

network reconstruction;

emergency servers;

contractors;

employee time.

The Court awarded damages for losses connected with the IT-system damage.

Principle

Damage to a digital system can produce multiple consequential categories of recoverable economic loss.

Networked significance

The case illustrates the difference between:

technical event

and

legal consequences of that event.

An attack may technically affect one system but economically affect:

operations;

employees;

customers;

infrastructure;

business continuity.

Liability analysis therefore requires reconstruction of the causal chain.

11. Case Law 5 — IDBI Bank Ltd v Amira C Foods

IDBI Bank Ltd v Amira C Foods International DMCC [2019] DIFC CA 014

The DIFC Court of Appeal examined causation, damages and evidentiary questions surrounding alleged financial and reputational harm.

The Court's reasoning illustrates that a claimant must establish an appropriate connection between the alleged wrongful conduct and the claimed loss.

Principle

A claimant cannot simply identify a defendant's wrongful conduct and then attribute every subsequent economic consequence to that conduct.

There must be:

Wrong → Causal connection → Proven loss

Networked significance

This is crucial in interconnected systems because a single digital incident may be followed by numerous independent events.

12. Case Law 6 — Faizal Babu Moorkath v Expresso Telecom Group

Faizal Babu Moorkath v Expresso Telecom Group Ltd [2023] DIFC CFI 008

The Court emphasised that a civil claim requires legally recognised and sufficiently established loss.

The case is useful for distinguishing:

mere wrongdoing;

actionable loss;

legally recoverable damage.

Principle

Not every adverse consequence of conduct automatically becomes compensable damage.

Networked significance

In digital systems, claimants may identify:

lost opportunities;

reputational effects;

business disruption;

market effects;

consequential losses.

Each category still requires legal and evidentiary analysis.

13. Case Law 7 — Globemed Gulf Healthcare Solutions v Oman Insurance

Globemed Gulf Healthcare Solutions LLC v Oman Insurance Company PSC [2017] DIFC CFI 051

The Court distinguished actual or sufficiently certain future loss from merely speculative future harm.

Principle

A future loss cannot become recoverable merely because it is theoretically possible.

There must be sufficient certainty concerning the relevant damage.

Networked significance

Networked systems often produce long-tail consequences.

For example:

Cyberattack → customer loss → reputational decline → future revenue reduction

The claimant must establish whether the later losses are sufficiently certain and legally connected to the original event.

14. Case Law 8 — Linux v Lizeth

Linux v Lizeth [2022] DIFC SCT 237

The dispute involved allegations concerning a copied digital platform and associated business, data and security-related losses.

The case demonstrates that digital claims remain subject to ordinary requirements concerning:

contractual obligations;

proof;

causation;

loss.

Principle

The digital character of a dispute does not eliminate the requirement to establish the legal basis of liability.

Networked significance

Digital networks can create many technical explanations for a loss, but civil liability still requires a legally supported causal theory.

15. Multiple Causes

One of the biggest problems in networked systems is concurrent causation.

Suppose:

Platform A has a security weakness;

Provider B fails to update software;

User C ignores a security warning;

Attacker D exploits the vulnerability.

The final loss may result from all four factors.

The legal question becomes:

Should one actor bear all of the loss, or should responsibility be divided?

The answer depends on the applicable rules concerning:

causation;

contribution;

fault;

contractual allocation;

contributory conduct;

intervening events;

statutory responsibility.

16. Chain of Causation

A useful analytical model is:

Initial Conduct

Technical Event

Intermediate Event

Third-Party Conduct

Economic Consequence

Claimed Loss

The court should examine every important link.

For example:

Negligent cybersecurity

Unauthorised access

Data alteration

Payment fraud

Bank rejection

Customer losses

The defendant may be responsible for some consequences but not necessarily every consequence.

17. Intervening Acts

A third party may intervene between the defendant's conduct and the eventual harm.

Examples include:

hackers;

employees;

customers;

independent contractors;

banks;

software providers.

But third-party intervention does not automatically eliminate the original actor's liability.

The important questions are:

Was the intervention foreseeable?

Was it independent?

Was it extraordinary?

Did it constitute a new dominant cause?

Was the original defendant already under a duty to protect against that type of risk?

18. Contractual Fragmentation

Networked systems frequently operate through a chain of separate contracts.

For example:

Customer ↔ Platform

Platform ↔ Cloud Provider

Platform ↔ Payment Processor

Payment Processor ↔ Bank

Developer ↔ Platform

A customer may therefore discover that the actor technically responsible for the failure is not the party with whom the customer contracted.

This creates questions concerning:

privity;

third-party rights;

agency;

negligence/civil liability;

implied duties;

warranties;

limitation clauses;

indemnities.

19. Liability Allocation Through Contracts

Parties can often allocate risk through:

indemnities;

warranties;

insurance;

limitation clauses;

exclusion clauses;

service-level agreements;

cybersecurity obligations;

audit rights;

compliance obligations.

Thus contractual fragmentation can become a mechanism for private allocation of network risk.

However, contractual allocation cannot necessarily eliminate mandatory statutory liability or obligations imposed by public law.

20. Distributed Liability

A network may contain several categories of responsibility.

Primary liability

The actor whose conduct directly caused the loss.

Secondary liability

A person responsible because of a legally recognised relationship with another actor.

Contractual liability

Responsibility arising from failure to perform an agreement.

Civil/tort liability

Responsibility arising from harmful conduct independently of contract.

Fiduciary liability

Responsibility arising from entrusted authority or property.

Regulatory liability

Consequences of violating regulatory obligations.

These categories should not automatically be merged.

21. Regulatory Breach Does Not Automatically Equal Civil Damages

A particularly important distinction is:

Regulatory violation ≠ automatic private-law damages

A regulatory breach may be evidence relevant to a civil claim, but the claimant may still need to establish:

legally protected interest;

breach;

causation;

actual loss;

recoverability.

This is particularly important in fintech and AI disputes.

22. AI Network Liability

AI creates an especially fragmented responsibility structure.

Consider:

Developer

Model provider

Data provider

Cloud provider

Integrator

Business deploying AI

Human decision-maker

Affected person

If an AI system produces harmful output, possible questions include:

Who designed the system?

Who supplied the data?

Who deployed it?

Who controlled its operation?

Who failed to supervise it?

Was there a warning?

Was human review required?

Was the harm foreseeable?

Which actor had the ability to prevent it?

The central civil-law issue is therefore attribution.

23. Blockchain and DAO Liability

Blockchain systems create another problem because control may be distributed.

A DAO could involve:

developers;

token holders;

governance participants;

multisignature controllers;

treasury managers;

infrastructure providers;

smart-contract developers.

A technically decentralised network does not automatically become a legally personless environment.

The court must identify:

Technical Role → Legal Role → Duty → Conduct → Causation → Liability

24. Smart Contracts

A smart contract can automatically execute code.

But:

Automatic execution ≠ automatic legal validity

A smart contract may still raise questions about:

contractual intention;

authority;

mistake;

fraud;

programming error;

breach;

restitution;

unjust enrichment;

ownership;

remedies.

The software executes automatically, but civil law must determine who is legally responsible for the relevant transaction or defect.

25. Cybersecurity Liability

Cyber incidents are a classic example of fragmented liability.

Suppose a platform suffers a data breach.

Potential actors include:

software developer;

platform operator;

cloud provider;

security contractor;

employee;

attacker;

data processor.

The legal inquiry should identify:

Duty

Who owed the relevant security obligation?

Breach

Who failed to meet it?

Causation

Did that failure materially contribute to the breach?

Loss

What damage resulted?

Allocation

Should responsibility be divided?

26. Evidentiary Fragmentation

Networked systems create large quantities of evidence:

server logs;

blockchain records;

emails;

access records;

API logs;

transaction histories;

metadata;

security reports;

expert analyses.

Evidence may be controlled by several independent entities.

Consequently, proving liability can itself become a network problem.

A claimant may need:

Digital Evidence → Technical Expert → Causal Reconstruction → Legal Attribution

27. Expert Evidence

Technical complexity often requires expert evidence.

However, an expert should generally explain:

how the system worked;

what happened technically;

what caused the failure;

what financial consequences followed.

The court, rather than the expert, decides the ultimate legal question of liability.

This distinction is particularly important in AI, cybersecurity and blockchain disputes.

28. The "Many Actors, One Harm" Problem

The central conceptual difficulty can be represented as:

             Developer                 │ Cloud Provider ──┼── Platform                 │          Payment Provider                 │               User                 │          Third-Party Event                 │               LOSS

The loss may be singular.

The causes may be plural.

Therefore:

One Harm ≠ One Defendant

29. Fragmentation and Proportionate Responsibility

Where several parties contributed to the loss, the legal system may need to determine:

whether each actor is independently liable;

whether liability is joint;

whether liability is several;

whether contribution is available;

whether the claimant's own conduct contributed;

whether contractual indemnification reallocates the economic burden.

The answer depends upon the applicable UAE federal, Emirate-level, DIFC, ADGM or foreign rules governing the particular dispute.

30. Digital Causation Model

For examination and legal analysis, use this model:

Digital Conduct

Identifiable Legal Duty

Breach

Technical Causal Event

Intermediate Events

Foreseeable/Natural Consequence

Proven Damage

Recoverable Loss

Allocation of Liability

This prevents the analysis from jumping directly from:

"The defendant was connected to the system"

to:

"The defendant is responsible for everything that happened."

31. Key Principles From the Cases

CaseImportant principle
Gate Mena v Tabarak [2023] DIFC CA 002Functional control can generate fiduciary responsibilities
Techteryx v Aria Commodities [2025] DIFC DEC 001Traditional civil remedies can operate in digital-asset networks
CoinMENA v Foloosi [2025] DIFC CFI 067/2025Fintech disputes remain subject to ordinary contractual analysis
Graciela v Giacobbe [2014] DIFC CFI 027Digital-system damage can generate consequential economic loss
IDBI Bank v Amira C Foods [2019] DIFC CA 014Loss requires appropriate causal and evidentiary connection
Faizal Babu Moorkath v Expresso Telecom [2023] DIFC CFI 008Actionable loss must be legally recognised and established
Globemed v Oman Insurance [2017] DIFC CFI 051Future loss must satisfy sufficient certainty
Linux v Lizeth [2022] DIFC SCT 237Digital claims still require proof of contractual/legal causation and loss

32. UAE-Specific Legal Challenges

A. Multiple court systems

UAE onshore courts, DIFC Courts and ADGM Courts operate within distinct legal frameworks.

B. Multiple governing laws

A contract may select foreign law.

C. Cross-border defendants

The relevant actor may be outside the UAE.

D. Digital assets

Assets may exist through globally distributed technological infrastructure.

E. AI

Responsibility may be divided between developers, providers and users.

F. Cybersecurity

Evidence and technical infrastructure may cross borders.

G. Enforcement

The responsible party's assets may be in another jurisdiction.

33. Fragmentation Does Not Mean No Liability

A common mistake is to assume:

"Because many actors contributed, nobody can be held responsible."

That is incorrect.

Fragmentation changes the method of attribution.

The court can ask:

Who owed the duty?

Who controlled the relevant risk?

Who breached the duty?

Which conduct caused which loss?

Was the loss a natural or legally attributable consequence?

Did another event intervene?

What remedy is legally available?

34. A Unified UAE Analytical Framework

For a networked civil-liability dispute, the following framework is useful:

Step 1 — Map the network

Identify every relevant actor.

Step 2 — Identify legal relationships

Determine which parties are connected contractually, fiduciary-wise or through other legal relationships.

Step 3 — Identify duties

Determine the legal duty applicable to each participant.

Step 4 — Identify breach

Determine precisely what each actor allegedly did or failed to do.

Step 5 — Reconstruct causation

Trace the technical and factual chain.

Step 6 — Separate losses

Identify:

direct loss;

consequential loss;

lost profits;

future loss;

moral harm where relevant.

Step 7 — Consider intervening causes

Analyse third-party conduct and independent events.

Step 8 — Allocate liability

Determine the legal responsibility of each participant.

Step 9 — Apply contractual risk allocation

Consider:

indemnities;

warranties;

insurance;

limitation clauses.

Step 10 — Determine remedy

Consider compensation, restitution, injunctions, specific performance or other applicable remedies.

35. Examination Answer Structure

A strong answer can be condensed into:

Fragmentation of liability in networked systems occurs when multiple interconnected technical and legal actors contribute to a single harmful outcome. UAE civil law addresses this problem through the identification of legally relevant actors, duties, breach, causation, recoverable loss and remedies. Digital complexity does not itself create liability, nor does the presence of multiple actors eliminate it. Cases such as Gate Mena v Tabarak, Techteryx v Aria Commodities, CoinMENA v Foloosi, Graciela v Giacobbe, IDBI Bank v Amira C Foods, Faizal Babu Moorkath v Expresso Telecom, Globemed v Oman Insurance and Linux v Lizeth illustrate how traditional civil-law concepts can be applied to increasingly interconnected digital and commercial environments.

36. Conclusion

Fragmentation of liability concepts in networked systems represents a major challenge for contemporary UAE civil law.

Traditional civil liability assumes a relatively identifiable relationship:

Wrongdoer → Wrong → Damage → Compensation

Networked systems replace that simple structure with:

Multiple Actors → Multiple Duties → Multiple Interventions → Multiple Causal Links → Multiple Losses

The UAE legal response is therefore likely to depend increasingly on functional attribution rather than purely technological attribution. The fact that an actor operates a platform, writes code, provides infrastructure, controls a wallet or processes data does not by itself establish liability. The decisive analysis remains the identification of the legal role, applicable duty, breach, causal connection and legally recoverable damage.

The most useful formula is:

Network Participant → Legal Role → Duty → Breach → Causation → Natural/Legally Attributable Consequence → Proven Loss → Liability → Remedy

That framework allows classical UAE civil-law principles to be applied to modern fintech, AI, cybersecurity, blockchain, cloud computing, digital platforms and other networked systems without assuming that technological complexity automatically produces either unlimited or unassignable liability.

LEAVE A COMMENT