Civil Law And Uae Liability For Autonomous Infrastructure Failures .
Civil Law and UAE: Liability for Autonomous Infrastructure Failures
1. Introduction
Liability for autonomous infrastructure failures concerns the civil responsibility arising when infrastructure controlled, monitored, or operated partly by autonomous systems causes damage, interruption, loss, or physical harm.
Examples include:
- autonomous traffic-management systems;
- smart electricity grids;
- automated water-management systems;
- AI-controlled buildings;
- autonomous ports and logistics systems;
- smart elevators;
- automated warehouses;
- connected transport systems;
- autonomous vehicles and drones;
- AI-controlled industrial plants;
- cloud-controlled infrastructure;
- robotic construction equipment.
The difficult legal question is:
When an autonomous infrastructure system fails without a person directly causing the immediate failure, who bears the resulting civil liability?
The existing UAE civil-law framework can address many such disputes through established principles of harm, fault, causation, contractual liability, defective performance, professional responsibility, agency, product responsibility and compensation. However, autonomy creates difficult questions about identifying the legally relevant human or corporate actor.
A recent academic analysis specifically addressing autonomous AI systems under UAE law notes that traditional fault-and-causation principles face difficulties where autonomous systems produce harm without direct human intervention.
2. Meaning of Autonomous Infrastructure
An autonomous infrastructure system is infrastructure capable of making or implementing operational decisions with limited direct human intervention.
Traditional infrastructure
Human operator → Decision → Machine → Result
Autonomous infrastructure
Data → Algorithm/AI → Automated decision → Machine/system → Result
For example:
Sensors detect traffic congestion → AI analyses traffic → traffic lights automatically change → vehicles are redirected.
If the algorithm makes an incorrect decision and causes an accident, liability becomes more complicated.
3. The Fundamental UAE Liability Framework
For mainland UAE civil-law analysis, the starting point is the general civil-liability framework.
A commonly used formulation is:
Harm + legally relevant conduct/fault + causation = civil liability
Article 282 of the UAE Civil Transactions Law traditionally provides the foundational principle that harm caused to another gives rise to an obligation to make good the damage. Recent comparative discussion of autonomous systems under UAE law likewise identifies Article 282 as the foundational tort-liability provision.
The difficult part in autonomous systems is not simply proving:
“The machine caused the damage.”
The legal question is:
Which legally responsible person or entity is connected to the machine, and what legal duty was breached?
4. Autonomous Systems Do Not Automatically Become Legal Persons
A central principle is:
An autonomous machine or AI system should not automatically be treated as a legal person merely because it makes autonomous decisions.
The relevant legal actors may instead include:
- owner;
- operator;
- manufacturer;
- software developer;
- infrastructure manager;
- maintenance contractor;
- system integrator;
- data provider;
- cloud provider;
- cybersecurity provider;
- professional consultant;
- government or infrastructure authority.
Therefore:
Autonomy of operation does not necessarily mean autonomy of legal responsibility.
5. The Liability Chain
A useful analytical model is:
Infrastructure owner
↓
System designer
↓
Hardware manufacturer
↓
Software/AI developer
↓
System integrator
↓
Data provider
↓
Cloud/network provider
↓
Operator
↓
Autonomous system
↓
User/public
A failure may originate at any point.
6. Contractual Liability
The first question in a commercial autonomous-infrastructure dispute should often be:
What did the parties contractually promise?
Contracts may allocate responsibility for:
- system design;
- installation;
- testing;
- cybersecurity;
- maintenance;
- software updates;
- sensor calibration;
- uptime;
- safety;
- monitoring;
- emergency intervention;
- data accuracy.
For example, an infrastructure contract may provide that:
The technology supplier is responsible for software defects, while the operator is responsible for maintenance.
If a failure results from defective software, contractual allocation becomes highly relevant.
7. Tort Liability
Tort principles become particularly important where:
- there is no direct contract;
- a member of the public is injured;
- neighbouring property is damaged;
- infrastructure failure affects third parties;
- an autonomous vehicle injures a pedestrian.
For example:
A smart traffic system malfunctions and causes a collision involving a person who has no contract with the technology supplier.
The injured person may need to rely on an applicable non-contractual civil-liability basis.
8. Causation Is the Central Difficulty
Autonomous infrastructure can produce a causal chain involving numerous events.
Example:
Faulty sensor
↓
Incorrect data
↓
AI prediction
↓
Automated decision
↓
Infrastructure response
↓
Physical damage
↓
Financial loss
The court must determine:
Which event constitutes the legally relevant cause?
This is more difficult than simply identifying the final mechanical event.
9. Human Fault May Exist Earlier in the Chain
Autonomy does not eliminate human involvement.
A failure may originate from:
- poor system design;
- inadequate training data;
- inadequate testing;
- negligent installation;
- failure to update software;
- defective maintenance;
- poor cybersecurity;
- inadequate monitoring;
- failure to establish emergency override procedures.
Thus:
The absence of immediate human intervention does not necessarily mean the absence of human or corporate fault.
10. Case Law 1 — Graciela Limited v Giacobbe
Graciela Limited v Giacobbe [2014] DIFC CFI 027
This is an important DIFC technology-liability authority.
The claimant's IT system was deliberately sabotaged. The court considered extensive technical and circumstantial evidence and found the defendant responsible for the interference. Compensation included system restoration, emergency servers, investigation expenses and employee time.
Relevance to autonomous infrastructure
Although the case concerned deliberate human interference rather than AI autonomy, it establishes an important principle:
Technical system failure can constitute legally compensable property interference when the responsible conduct and resulting loss are established.
It is useful by analogy for autonomous infrastructure because courts must still identify:
- the system affected;
- the harmful event;
- responsible conduct;
- causation;
- resulting loss.
11. Case Law 2 — Aegis Resources DMCC v Union Bank of India
Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004
This case involved cyber-fraud and security of an email/payment environment.
The judgment considered the security arrangements surrounding a managed email system and the respective responsibilities of the parties involved.
Relevance
The case demonstrates that in a technology ecosystem the court may need to ask:
- Who controlled the system?
- Who had security responsibilities?
- What security measures were expected?
- Who was responsible for implementation?
- Did the failure cause the loss?
Autonomous-infrastructure analogy
If an autonomous infrastructure system fails because of a cybersecurity vulnerability, responsibility may similarly depend upon the contractual and operational division of security responsibilities.
12. Case Law 3 — Shihab Khalil v Shuaa Capital PSC
Shihab Khalil v Shuaa Capital PSC [2009] DIFC CFI 017
The DIFC Court discussed the essentials of negligence and emphasised that a claimant must establish both lack of due care and that the lack of care caused the loss.
Principle
Negligence requires more than showing that something went wrong; the relevant lack of care and causal connection must be established.
Autonomous infrastructure
This principle is especially important where:
“The AI made a mistake”
is asserted as the explanation.
That statement alone does not necessarily establish legal liability.
The claimant may need to show that a responsible person or entity:
- failed to exercise required care;
- failed to test the system;
- failed to maintain it;
- failed to monitor it;
- or otherwise breached a relevant duty.
13. Case Law 4 — Aptiva Technologies FZE v Liberty Steel Group Holdings
Aptiva Technologies FZE v Liberty Steel Group Holdings (EMEA) Ltd [2024] DIFC CFI 076
This case concerned a multi-year software supply agreement and questions concerning contractual performance, termination and whether software was fit for purpose. The court noted that establishing unfitness would ordinarily require appropriate evidence, including expert evidence where technically necessary.
Relevance to autonomous infrastructure
Autonomous infrastructure is frequently based upon software.
Therefore, a failure may raise:
- fitness for purpose;
- software specifications;
- contractual warranties;
- maintenance obligations;
- expert evidence;
- causation.
Principle
A technical allegation must be supported by appropriate technical evidence where the issue requires specialised expertise.
14. Case Law 5 — Alucor Limited v Rohr Rein Chemie Middle East LLC
Alucor Limited v Rohr Rein Chemie Middle East LLC [2021] DIFC TCD 001
This dispute was transferred to the Technology and Construction Division because of its technically complex nature and involved contractual breaches and substantial damages claims.
The DIFC Courts expressly maintain a specialist Technology and Construction Division for technically complex claims, including engineering disputes and claims involving computers, software and network/IT systems.
Relevance
Autonomous infrastructure frequently combines:
- construction;
- engineering;
- software;
- sensors;
- telecommunications;
- automated control.
Therefore, a single failure may simultaneously constitute a construction, engineering and technology dispute.
15. Case Law 6 — Architeriors Interior Design LLC v Emirates National Investment Co LLC
Architeriors Interior Design LLC v Emirates National Investment Co LLC [2024] DIFC TCD 001
This case involved complex construction issues including:
- incomplete works;
- defective works;
- variations;
- delay;
- defects liability;
- waterproofing;
- contractual deductions.
Relevance to autonomous infrastructure
Smart infrastructure frequently combines traditional physical infrastructure with automated technology.
For example:
Smart building + automated HVAC + sensors + software + cloud monitoring.
If the building fails, responsibility may be divided between:
- construction contractor;
- electrical contractor;
- software supplier;
- sensor manufacturer;
- system integrator;
- maintenance provider.
Principle
Complex infrastructure liability must be analysed according to the individual contractual and technical responsibilities of the participating actors.
16. Case Law 7 — Five Real Estate Development LLC v Reem Emirates Aluminium LLC
Five Real Estate Development LLC v Reem Emirates Aluminium LLC [2020] DIFC TCD 009
The case concerned construction delay, contractual liquidated damages and alleged defects.
The court examined contractual allocation and concluded, among other things, that the relevant subcontractor was not responsible for the claimed delay on the evidence.
Relevance
This illustrates an important autonomous-infrastructure principle:
A party should not be held liable merely because its work formed part of a failed system.
There must be a legally established connection between:
Actor → Obligation → Breach → Causation → Loss.
17. Case Law 8 — BAM Higgs & Hill LLC v Affan Innovative Structures LLC
BAM Higgs & Hill LLC v Affan Innovative Structures LLC & Amer Affan [2021] DIFC CFI 106
The case concerned technically complex construction associated with the Museum of the Future and involved extensive engineering and expert evidence.
Relevance
The case demonstrates the importance of expert evidence where infrastructure disputes involve highly technical questions.
Autonomous infrastructure may require experts in:
- AI;
- software engineering;
- electrical engineering;
- cybersecurity;
- robotics;
- telecommunications;
- sensor systems.
18. Case-Law Summary
| Case | Main principle | Autonomous-infrastructure relevance |
|---|---|---|
| Graciela v Giacobbe | IT interference and technical evidence | System failure/damage |
| Aegis v Union Bank | Cybersecurity responsibilities and causation | Cyber-triggered autonomous failure |
| Shihab Khalil v Shuaa Capital | Duty of care + causation | Negligent system design/operation |
| Aptiva v Liberty Steel | Software contract and technical evidence | Software defects/fitness |
| Alucor v Rohr Rein Chemie | Technically complex construction dispute | Engineering + technology integration |
| Architeriors v ENI | Defects, delay and contractual allocation | Smart-building infrastructure |
| Five Real Estate v Reem | Contractual allocation and causation | Multiple infrastructure contractors |
| BAM v Affan | Complex engineering/expert evidence | Autonomous engineering systems |
Important: These cases do not establish a specific UAE doctrine of “autonomous infrastructure liability.” They are relevant authorities by analogy on technology, software, engineering, causation, contractual allocation and technical evidence. The UAE-specific autonomous-AI question remains an emerging area.
19. Manufacturer Liability
Suppose an autonomous machine malfunctions because of defective hardware.
Potential claimant:
Infrastructure owner
Potential defendant:
Manufacturer
Potential legal issues:
- product defect;
- contractual warranty;
- negligence;
- statutory obligations;
- causation;
- damage.
The manufacturer's liability will depend on the applicable legal regime and contractual structure.
20. Software Developer Liability
Suppose the hardware works correctly but the AI software incorrectly interprets sensor information.
Potential issues include:
- defective software;
- failure to meet specifications;
- inadequate testing;
- failure to warn;
- cybersecurity vulnerability;
- negligent programming.
However, the developer is not automatically liable merely because the software produced an undesirable result.
The court must establish the applicable legal duty and causal connection.
21. System Integrator Liability
The system integrator may be particularly important.
The integrator connects:
- sensors;
- software;
- hardware;
- databases;
- networks;
- control systems.
Suppose every component works independently but fails when integrated.
The relevant question becomes:
Was the integration itself defective?
This can create a distinct contractual or tortious liability issue.
22. Maintenance Provider Liability
Autonomous systems require:
- software updates;
- sensor calibration;
- hardware maintenance;
- cybersecurity patches;
- system monitoring.
A failure may occur because maintenance was not properly performed.
Example:
A traffic-control AI is functioning correctly, but its sensors become inaccurate because scheduled calibration was not performed.
Potential liability may therefore arise from maintenance failure rather than AI failure.
23. Data Provider Liability
Autonomous systems depend upon data.
Examples:
- weather data;
- traffic data;
- mapping information;
- sensor feeds;
- financial information;
- geographic information.
If defective data causes an autonomous decision, the data provider may become relevant to the liability analysis.
The legal question is:
Did the data provider owe a duty concerning accuracy, reliability or suitability for the intended use?
24. Cloud-Service Provider Liability
Many autonomous systems operate through cloud infrastructure.
A failure may involve:
AI → Cloud → Network → Infrastructure
Potential causes include:
- outage;
- latency;
- data corruption;
- cyberattack;
- configuration error.
The applicable cloud agreement may allocate responsibility for:
- uptime;
- backup;
- security;
- disaster recovery;
- data integrity.
25. Infrastructure Operator Liability
The operator may have obligations concerning:
- monitoring;
- emergency intervention;
- maintenance;
- human override;
- system configuration.
Autonomy does not necessarily eliminate operator responsibility.
For example:
An operator ignores repeated warnings that an autonomous system is malfunctioning.
The resulting damage may raise questions concerning operator conduct.
26. Owner Liability
Ownership can be legally relevant where the applicable law imposes duties connected with:
- control;
- maintenance;
- operation;
- dangerous activities;
- property.
But ownership alone should not automatically be treated as proof of every possible form of liability.
The exact legal basis must be established.
27. Public Infrastructure
Autonomous infrastructure can also be operated by public authorities.
Examples:
- smart traffic systems;
- automated public transport;
- water networks;
- electricity infrastructure.
A failure may raise separate questions concerning:
- public authority powers;
- statutory duties;
- civil liability;
- governmental responsibility;
- contractual outsourcing;
- immunity or special procedural rules where applicable.
The legal analysis therefore differs from an ordinary private commercial system.
28. Autonomous Vehicle Infrastructure
Consider an autonomous road network.
Sensors → AI traffic control → traffic lights → connected vehicles
A malfunction causes an accident.
Potential actors:
- road authority;
- infrastructure operator;
- sensor manufacturer;
- AI developer;
- vehicle manufacturer;
- connectivity provider;
- vehicle owner/operator;
- maintenance provider.
The court must identify the causal chain rather than automatically imposing liability on the entity operating the road.
29. Smart Grid Failure
Consider an autonomous electricity grid.
An AI system predicts demand incorrectly.
The system:
increases power distribution → overload occurs → equipment fails → businesses lose production.
Potential losses include:
- physical damage;
- business interruption;
- lost profits;
- equipment replacement;
- consequential losses.
The liability analysis must consider:
- contractual obligations;
- system specifications;
- prediction accuracy;
- maintenance;
- causation;
- foreseeability;
- limitation clauses;
- claimant mitigation.
30. Autonomous Water Infrastructure
Suppose an AI-controlled water system incorrectly opens a valve.
The result is:
flooding → property damage → business interruption.
Potential defendants could include:
- infrastructure owner;
- system integrator;
- software provider;
- sensor manufacturer;
- maintenance contractor.
Expert evidence may be necessary to establish why the valve opened and whether the relevant actor breached its obligation.
31. Smart Building Failure
A smart building may use AI to control:
- temperature;
- elevators;
- fire systems;
- lighting;
- access control;
- energy consumption.
Suppose an autonomous fire-management system incorrectly classifies an event and delays an emergency response.
Potential liability questions include:
- Was the system designed correctly?
- Was it certified?
- Was it properly installed?
- Were sensors maintained?
- Was the software updated?
- Was human override available?
- Was the operator properly trained?
32. Autonomous Infrastructure and Product Liability
A defective physical component may cause the failure.
Examples:
- faulty sensor;
- defective circuit;
- defective controller;
- defective robotic component.
The legal analysis may involve:
Product defect + damage + causation + applicable statutory/contractual rules.
33. Autonomous Infrastructure and Professional Negligence
Professionals may design or certify autonomous infrastructure.
Examples:
- engineers;
- architects;
- cybersecurity specialists;
- software consultants.
If a professional negligently designs a system, liability may potentially arise from professional obligations.
The Technology and Construction Division specifically handles technically complex disputes involving engineers, architects, specialised advisers, computers, software and IT systems.
34. Failure to Update the System
Autonomous infrastructure changes over time.
A system that was safe when deployed may become vulnerable because:
- software becomes outdated;
- security vulnerabilities emerge;
- environmental conditions change;
- datasets become obsolete;
- regulatory standards change.
Therefore, liability may arise from:
failure to maintain operational safety over the system's lifecycle.
35. Cybersecurity Failure
Autonomous infrastructure is vulnerable to cyberattacks.
Imagine:
Hacker → compromised sensor → false data → AI decision → infrastructure failure.
The attacker may be the immediate cause.
But other questions remain:
- Was the system reasonably secured?
- Was a known vulnerability left unpatched?
- Was cybersecurity contractually allocated?
- Did the operator ignore warnings?
Thus:
Third-party hacking does not automatically resolve every question of civil responsibility.
36. Force Majeure
An autonomous system may fail because of:
- extreme weather;
- natural disaster;
- major telecommunications outage;
- extraordinary cyberattack;
- war-related disruption.
Whether this excuses contractual liability depends upon the applicable contract and governing law.
The parties should distinguish:
external event
from
failure to design reasonable resilience against foreseeable events.
37. Foreseeability
Foreseeability can become important when assessing the extent of recoverable damage.
Example:
A software provider causes a short system interruption.
The customer claims:
AED 100 million in indirect global losses.
The court may need to determine:
- whether such loss was legally attributable;
- whether it was foreseeable;
- whether contractual limitations apply;
- whether mitigation was possible.
38. Economic Loss
Autonomous infrastructure failures can cause enormous pure economic loss.
Examples:
- trading-system outage;
- airport automation failure;
- logistics interruption;
- electricity outage;
- cloud failure.
The claimant may seek:
- repair costs;
- replacement costs;
- lost revenue;
- business interruption;
- other consequential losses.
The availability and extent of recovery depend on the applicable legal rules and contractual arrangements.
39. Multiple Defendants
Autonomous infrastructure cases may involve several defendants.
A court could potentially need to analyse:
Manufacturer + Software Developer + Operator + Maintainer + Integrator
The claimant must establish the relevant legal basis against each defendant rather than simply treating the entire ecosystem as one entity.
40. Contribution and Indemnity
Suppose the infrastructure owner pays compensation to an injured party.
The owner may then have contractual or other legal rights against:
- software provider;
- maintenance company;
- contractor;
- manufacturer.
Therefore:
The ultimate economic burden may differ from the party initially sued.
41. Contractual Risk Allocation
Sophisticated autonomous-infrastructure contracts should specify:
Design responsibility
Who designs the system?
Validation
Who tests it?
Data
Who supplies and validates data?
Cybersecurity
Who secures the infrastructure?
Updates
Who patches software?
Monitoring
Who monitors performance?
Human override
Who must intervene?
Insurance
Who carries insurance?
Indemnification
Who reimburses third-party claims?
42. Human-in-the-Loop
A strong risk-control model is:
Autonomous operation + human oversight + emergency override + audit logs
This can help establish:
- who was responsible for monitoring;
- whether warnings were received;
- whether intervention was possible;
- whether intervention was required.
It also improves evidentiary analysis after an accident.
43. Audit Logs
Autonomous systems should ideally preserve:
- sensor data;
- algorithmic decisions;
- system warnings;
- human interventions;
- software versions;
- maintenance records;
- cybersecurity events.
These records can help answer:
Why did the system act as it did?
Without reliable records, establishing causation can become extremely difficult.
44. Explainability
If an AI system makes a critical infrastructure decision, affected parties may need to understand:
- what information was considered;
- what decision was made;
- when it was made;
- which system component made it;
- whether a human could override it.
Explainability is therefore not merely an AI-ethics issue.
It can become an evidentiary and liability issue.
45. Autonomous Infrastructure and Evidence
A claimant may need to establish:
System state → Decision → Action → Damage
For example:
Sensor recorded 90 km/h → AI classified traffic as low risk → signal changed → collision occurred.
Each stage must be technically verified.
The Graciela and Aegis cases illustrate why technical and electronic evidence can become central in determining responsibility for technology-related loss.
46. No Automatic “AI Liability”
An important legal principle is:
AI autonomy should not automatically create strict liability for every actor connected to the system.
Otherwise:
- developers could be liable for every downstream use;
- cloud providers could be liable for every application;
- infrastructure operators could be liable for every algorithmic error.
The better legal analysis is to identify the specific duty and causal connection.
47. Should AI Have Legal Personality?
The proposition that AI should itself become a legal person has been discussed academically.
Under the traditional UAE civil-law framework, however, the more practical approach is generally to identify responsible human or corporate actors rather than simply transferring liability to an autonomous system.
A recent academic study on UAE autonomous-AI liability similarly argues that giving AI legal personality would not by itself solve compensation and accountability problems because an AI system does not necessarily possess independent assets or ordinary legal capacity.
48. Autonomous Infrastructure as a Chain of Responsibility
A useful model is:
Stage 1 — Design
Who designed it?
Stage 2 — Development
Who programmed it?
Stage 3 — Integration
Who connected the components?
Stage 4 — Deployment
Who put it into operation?
Stage 5 — Monitoring
Who supervised it?
Stage 6 — Maintenance
Who maintained it?
Stage 7 — Incident
What actually failed?
Stage 8 — Damage
What loss resulted?
Stage 9 — Legal allocation
Which actor bears responsibility?
49. Practical Liability Matrix
| Actor | Possible responsibility |
|---|---|
| Owner | Operation/control obligations |
| Operator | Monitoring and intervention |
| Manufacturer | Hardware defect |
| Software developer | Software/design defect |
| System integrator | Integration failure |
| Data provider | Defective data where legally responsible |
| Cloud provider | Contractual infrastructure failure |
| Maintenance provider | Failure to maintain/update |
| Cybersecurity provider | Security-service obligations |
| Engineer | Professional negligence |
| Contractor | Construction/installation defects |
| Insurer | Contractual coverage |
| User | Misuse or contributory conduct |
These are potential categories, not automatic findings of liability.
50. Autonomous Infrastructure and the Burden of Proof
A claimant may face substantial difficulties because the defendant controls:
- source code;
- system logs;
- sensor data;
- maintenance records;
- AI models;
- cybersecurity records.
This can make evidence access particularly important.
Courts may therefore need to manage:
- disclosure;
- expert evidence;
- forensic examination;
- electronic records;
- confidentiality;
- trade secrets.
51. Specialist Judicial Infrastructure
The DIFC Courts' Technology and Construction Division is particularly relevant to this subject because its jurisdiction encompasses technically complex disputes, including engineering, construction, software, computers, networks, IT systems, cybercrime and emerging technologies such as AI and connected cars.
This institutional development demonstrates that autonomous infrastructure disputes may require judges to deal with both traditional civil-law principles and highly technical evidence.
52. Key Challenges in UAE Autonomous-Infrastructure Liability
1. Causation uncertainty
Multiple automated decisions may occur before damage.
2. Distributed responsibility
Many companies may participate in one system.
3. Black-box algorithms
The system's reasoning may be difficult to reconstruct.
4. Cyberattacks
Third-party attacks may interrupt autonomous operations.
5. Software updates
Responsibility can shift throughout the system's lifecycle.
6. Data dependency
Incorrect data may generate correct algorithmic processing but an incorrect result.
7. Contract fragmentation
Different participants may have different contracts.
8. Cross-border technology
The developer, cloud provider and operator may be in different jurisdictions.
53. Recommended Legal Risk Framework
For UAE businesses deploying autonomous infrastructure:
Before deployment
- identify every participant;
- allocate responsibility;
- conduct testing;
- document specifications;
- obtain appropriate insurance.
During operation
- maintain audit logs;
- monitor performance;
- patch vulnerabilities;
- calibrate sensors;
- maintain human override.
After failure
- preserve evidence;
- isolate affected systems;
- conduct forensic investigation;
- identify the causal chain;
- notify relevant parties;
- assess contractual indemnities and insurance.
54. Exam-Oriented Framework
For a problem question, use:
F — Failure
What exactly failed?
A — Actor
Which human/entity controlled or supplied the relevant component?
D — Duty
What contractual, statutory or tortious duty existed?
B — Breach
Was that duty breached?
C — Causation
Did the breach cause the damage?
D — Damage
What legally recoverable loss occurred?
R — Risk allocation
Did the contract allocate the risk?
M — Remedy
What compensation or other remedy is available?
55. Important Distinction
Autonomous failure
The system makes an unexpected decision.
Legal fault
A legally responsible actor failed to satisfy a relevant duty.
These are not automatically the same thing.
Therefore:
Autonomous action is a factual event; legal liability is a normative legal conclusion.
56. Final Conclusion
UAE civil law can address many autonomous-infrastructure failures using established principles of:
- civil liability;
- contractual responsibility;
- fault;
- causation;
- damage;
- product responsibility;
- professional negligence;
- corporate responsibility;
- indemnity;
- insurance;
- evidence.
The major difficulty is attribution.
A failure may result from a combination of:
hardware + software + data + cybersecurity + human supervision + maintenance + environmental conditions.
Consequently, the appropriate approach is not to ask simply:
“Did the AI cause the accident?”
Instead, the legally meaningful questions are:
Who designed the system? Who controlled it? Who owed the relevant duty? Who failed to perform that duty? Did that failure cause the damage? And how did the parties allocate the resulting risk?
The existing UAE and DIFC authorities on technology, engineering, cybersecurity and software disputes provide useful foundations for answering these questions, even though specific case law directly deciding liability for a fully autonomous infrastructure failure remains limited and developing.
One-line exam definition
Liability for autonomous infrastructure failures under UAE civil-law principles concerns the allocation of responsibility for damage caused by autonomous or AI-controlled infrastructure by identifying the applicable duty, responsible actor, breach, causal connection, damage, contractual risk allocation and appropriate remedy.
Jurisdictional note: The cases discussed above are principally DIFC authorities, not binding Federal UAE precedents. They are particularly useful because the DIFC Courts have a specialist Technology and Construction Division expressly dealing with technically complex engineering, software, cybersecurity and emerging-technology disputes.

comments