Civil Law And Uae Multi-Entity Liability In Autonomous Ai Networks .
Civil Law and UAE Multi-Entity Liability in Autonomous AI Networks
1. Introduction
Multi-entity liability in autonomous AI networks concerns situations where harm is produced by an AI system that is designed, supplied, trained, deployed, supervised, integrated, or operated by several different legal persons.
For example, an autonomous logistics network may involve:
an AI developer;
a cloud provider;
a data provider;
a hardware manufacturer;
an AI-system integrator;
a platform operator;
the business deploying the system;
a human supervisor; and
an insurer.
If the autonomous system causes damage, the difficult legal question is:
Which entity is legally responsible for the harm when no single entity directly performed the harmful act?
UAE civil law does not presently create a separate general doctrine of "autonomous AI network liability." The problem is instead analysed through existing principles of harmful acts, causation, multiple tortfeasors, agency, vicarious liability, product/service responsibility, contractual obligations, data protection, and evidence.
The current Federal Decree-Law No. 25 of 2025 promulgating the Civil Transactions Law, effective from 1 June 2026, is particularly important because Article 253 expressly addresses situations where multiple persons are responsible for the same harm. It allows liability to be allocated according to each person's share and permits the court, depending on the circumstances, to impose equal or joint-and-several liability. It also allows reduction of compensation where the injured party contributed to the harm. (UAE Legislation)
2. What Is an Autonomous AI Network?
An autonomous AI network is more complicated than a single AI application.
A simplified structure may be:
Developer
↓
Foundation/AI model
↓
Data provider
↓
Cloud infrastructure
↓
Integrator
↓
Autonomous software/robot
↓
Operating company
↓
End user
The system may continuously:
collect information;
analyse data;
make predictions;
select an action;
execute the action;
learn from feedback;
interact with other software;
trigger physical consequences.
Therefore, a harmful outcome can emerge from the interaction of multiple systems rather than from one identifiable human decision.
3. Examples of Multi-Entity AI Harm
Example 1 — Autonomous vehicle
An autonomous vehicle causes an accident.
Potentially relevant entities:
AI developer;
vehicle manufacturer;
sensor manufacturer;
mapping-data provider;
software integrator;
fleet operator;
maintenance provider;
human safety supervisor.
Example 2 — AI financial system
An autonomous trading system makes erroneous transactions.
Potentially relevant entities:
algorithm developer;
financial institution;
data provider;
cloud provider;
system integrator;
trader/supervisor.
Example 3 — AI medical system
An AI diagnostic system produces an incorrect recommendation.
Potential actors may include:
AI developer;
hospital;
medical practitioner;
data supplier;
software integrator;
equipment manufacturer.
Example 4 — Autonomous industrial robot
A robot injures an employee.
Potentially relevant:
robot manufacturer;
AI developer;
industrial operator;
maintenance contractor;
software provider.
4. UAE Legal Framework
The relevant legal framework is not contained in one AI-liability statute.
Instead, several areas may interact.
Principal areas include:
Civil Transactions Law
Product and contractual liability
Medical Liability Law, where healthcare is involved
Consumer Protection Law
Personal Data Protection Law
Electronic Transactions and Trust Services Law
Commercial Companies Law
Insurance legislation
Cybercrime legislation
DIFC Digital Economy Court framework
applicable sector-specific regulations.
The UAE's new Civil Transactions Law describes itself as a comprehensive framework governing civil rights and obligations and modernises several areas of civil liability and contracts. (UAE Legislation)
5. Fundamental Principle — AI Has No Separate Civil Personality
An autonomous AI system is not, merely because it makes autonomous decisions, automatically treated as a separate legal person capable of bearing civil liability.
The relevant legal persons remain, depending on the circumstances:
developer;
manufacturer;
operator;
owner;
employer;
service provider;
data controller/processor;
contracting party;
insurer;
other responsible persons.
Therefore:
Autonomy of the machine does not automatically transfer liability from humans and legal entities to the machine.
The court must identify the legal relationship between the system and the persons/entities behind it.
6. Article 253 — Multiple Responsible Persons
Article 253 of the current Civil Transactions Law is particularly important.
It provides that:
where multiple persons are responsible for the same harm, each may be liable in proportion to their share.
The court may also determine that they are:
equally liable; or
jointly and severally liable,
depending on the circumstances.
The provision also allows compensation to be reduced or denied where the injured party contributed to causing or aggravating the damage. (UAE Legislation)
This provision provides a natural statutory foundation for multi-entity AI liability.
7. Why Article 253 Is Important for AI
Suppose an autonomous delivery robot injures a pedestrian.
The evidence establishes:
developer fault: 30%;
manufacturer fault: 20%;
integrator fault: 30%;
operator fault: 20%.
The court may consider allocating responsibility according to the respective contribution.
Alternatively, depending upon the legal relationship and circumstances, the court may impose joint and several liability, leaving the responsible entities to resolve contribution between themselves.
Thus, the law does not necessarily require the victim to identify a single "AI culprit."
8. Causation Is the Central Problem
The claimant must still establish a causal connection.
The chain may look like:
Defective training data
↓
AI model produces erroneous output
↓
Integrator fails to implement safety constraint
↓
Operator deploys system
↓
Autonomous system takes harmful action
↓
Damage
The court must determine which links are legally significant.
This makes AI disputes different from conventional negligence claims.
9. Direct and Indirect Harm
UAE civil law historically distinguishes between direct action and indirect causation.
This distinction remains important when an AI system creates a chain of events.
A person who directly operates a dangerous machine may have a different liability position from:
a remote software developer;
a cloud provider;
a data supplier.
The legal question is not simply:
"Who created the AI?"
It is:
Whose legally relevant act or omission caused the damage?
The DIFC Courts, when discussing UAE Civil Code principles, have reproduced the former Articles 282–285 concerning harm, direct/indirect causation and deception. (DIFC Courts)
10. Developer Liability
An AI developer may potentially be responsible where the harm results from:
defective design;
inadequate safeguards;
foreseeable misuse;
failure to correct known defects;
inadequate testing;
unsafe model architecture;
failure to communicate known limitations.
But development alone does not automatically create liability.
The claimant must connect the developer's conduct to the damage.
11. Operator Liability
The operator may have the strongest factual connection with the harmful event.
For example, the operator may have:
ignored system warnings;
disabled safety mechanisms;
used the system outside its intended purpose;
failed to update software;
failed to maintain hardware;
failed to supervise an autonomous system.
Therefore, autonomous decision-making does not necessarily excuse the human or corporate operator.
12. Manufacturer Liability
Where AI operates through physical equipment, liability may involve the manufacturer.
Examples:
defective autonomous vehicle;
defective industrial robot;
defective drone;
defective medical device.
The manufacturer may potentially face liability for defects in:
hardware;
embedded software;
safety controls;
sensor systems.
However, software supplied by a separate entity may create a multi-party causation question.
13. AI Integrator Liability
The integrator occupies a particularly important position.
The integrator may combine:
AI model;
hardware;
data;
APIs;
cloud infrastructure;
sensors;
business processes.
The individual components may all be functioning properly, while the integration itself creates the defect.
For example:
AI model works correctly in isolation + sensor works correctly in isolation + software works correctly in isolation → integration causes unsafe autonomous action.
The integrator may therefore become an important defendant.
14. Data Provider Liability
AI systems depend heavily on data.
A data provider may potentially contribute to harm through:
inaccurate data;
corrupted data;
incomplete data;
outdated data;
unlawful data collection;
improperly labelled training data.
The Personal Data Protection Law is especially relevant where personal information is processed.
Federal Decree-Law No. 45 of 2021 requires appropriate technical and organisational measures to protect personal data and requires impact assessments for certain high-risk processing involving modern technologies. (UAE Legislation)
15. Cloud Provider Liability
A cloud provider may supply infrastructure rather than make the AI decision.
Therefore, liability cannot simply be imposed because:
"The AI was hosted on its servers."
A stronger case may arise if the provider:
breached a contractual security obligation;
failed to implement agreed safeguards;
materially interfered with the system;
negligently caused data corruption;
failed to follow a contractual service level.
The legal analysis therefore depends heavily upon contract + technical causation + actual fault.
16. Platform Liability
A platform may occupy a different position.
Consider an AI marketplace connecting:
autonomous agents;
consumers;
financial institutions;
service providers.
Potential claims may concern:
platform design;
negligent moderation;
misleading information;
security failures;
contractual obligations;
consumer protection.
Again, platform status alone should not automatically establish liability.
17. Employer/Vicarious Liability
Where an employee operates or supervises the autonomous system, employer liability may arise under ordinary principles of employer responsibility.
Example:
An employee negligently configures an autonomous warehouse robot.
The employer may face liability depending upon:
employment relationship;
scope of employment;
applicable statutory provisions;
causal connection.
Autonomy of the software does not eliminate traditional employer responsibility.
18. Agency and AI
Agency becomes particularly complicated when AI acts through an authorised human or corporate system.
The question becomes:
Was the AI merely a tool through which the principal acted, or did another entity independently cause the harmful conduct?
A recent DIFC Court of Appeal decision is useful here.
Khaled Salem Musabeh Humad Al Mheiri v John Cameron [2025] DIFC CA 008
The Court considered whether a contracting party could be responsible for deceitful representations made by another person, including an agent acting with authority, under the former UAE Civil Code provisions.
The Court noted that excluding liability for an agent's deceitful representations merely because the principal lacked actual knowledge could leave innocent parties vulnerable, although the precise construction of the relevant provisions was left for reconsideration. (DIFC Courts)
Relevance to autonomous AI
The case is not an AI case, but its reasoning provides an important analogy:
Principal → authorised intermediary → third-party harm
can resemble:
AI owner/operator → autonomous AI agent → third-party harm.
It demonstrates why the legal relationship between the principal and the intermediary must be carefully analysed.
19. Multi-Entity Liability and Corporate Groups
An AI network may be operated by a corporate group consisting of:
Parent company;
AI subsidiary;
cloud subsidiary;
data subsidiary;
operating company.
The existence of a corporate group does not automatically mean that all companies are liable.
Each company generally retains its separate legal personality.
The claimant must establish a proper legal basis for imposing liability on each entity.
20. Normand v Nathaniel [2024] DIFC SCT 125
This principle is illustrated by Normand v Nathaniel [2024] DIFC SCT 125.
The DIFC Court discussed the corporate-veil doctrine and explained that piercing the veil is an exceptional mechanism intended to prevent misuse or abuse of corporate form.
The Court rejected an attempt to use the doctrine merely to transfer a subsidiary's rights or liabilities to another corporate entity without a proper legal basis. (DIFC Courts)
Relevance
This is highly important for AI networks.
A claimant cannot simply argue:
"All companies belong to the same AI group, therefore all companies are liable."
Separate corporate personality remains relevant.
21. Multi-Entity Liability and Joinder
AI disputes may involve many potentially responsible parties.
A court therefore needs mechanisms for joining:
developer;
manufacturer;
operator;
data provider;
integrator;
service provider.
Mohamad Khalil Yakzan v Cyber Knight Technologies FZ-LLC [2024] DIFC CFI 077
The DIFC Court granted an application to add BlueCat Networks, Inc. and Knights for Telecom and Information Technology Company as additional defendants. (DIFC Courts)
The case was not an autonomous-AI liability case, but it illustrates an important procedural principle:
Technology disputes may require multiple entities to be brought before the court where their roles are potentially relevant to the dispute.
22. Evidence in Autonomous AI Litigation
Evidence is often the hardest part.
An autonomous AI system may generate:
logs;
model outputs;
decision trees;
sensor data;
API calls;
database records;
training data;
system prompts;
audit records;
software versions;
timestamps.
The claimant may not know which entity caused the error.
Therefore, courts may need to consider:
Technical evidence
source code;
model architecture;
system logs;
version histories.
Documentary evidence
contracts;
specifications;
risk assessments;
testing reports.
Expert evidence
AI engineering;
cybersecurity;
software architecture;
causation.
23. Black-Box AI and Burden of Proof
A major challenge is the black-box problem.
Suppose:
Input A → AI → harmful decision.
But nobody can easily explain why the AI produced that result.
The claimant may know:
the input;
the output;
the damage.
But may not know:
model parameters;
training process;
internal decision pathway.
This can make conventional negligence litigation difficult.
A court may therefore need expert evidence and careful consideration of which entity possessed the relevant technical information.
24. Data Protection and AI Liability
Federal Decree-Law No. 45 of 2021 is important where autonomous AI processes personal data.
The law requires security measures proportionate to processing risks and provides for impact assessment in certain high-risk processing operations involving modern technologies. (UAE Legislation)
This creates a potential liability chain:
Data controller
↓
AI processor
↓
Cloud provider
↓
AI model
↓
Automated decision
↓
Data subject harm
The parties' respective contractual and statutory responsibilities must be distinguished.
25. Autonomous AI and Moral Damage
AI harm may include:
Material damage
financial loss;
property damage;
lost profits;
medical expenses.
Moral damage
reputational harm;
dignity injury;
privacy harm;
psychological suffering.
Article 254 of the new Civil Transactions Law expressly recognises moral harm, including infringement of freedom, honour, reputation, social standing and financial status. (UAE Legislation)
Therefore, an autonomous AI system causing reputational injury could potentially generate both:
material compensation + moral compensation.
26. Case Law 1 — Al Mheiri v Cameron [2025] DIFC CA 008
Issue
Liability for representations made through an agent.
Principle
The Court considered whether a contracting party may be liable for deceitful representations made by an authorised agent under UAE law.
Relevance to autonomous AI
An autonomous AI system can be viewed, depending on its legal structure, as an instrument through which an entity performs contractual or operational functions.
The case therefore provides an analogy for:
principal → agent → representation → third-party harm. (DIFC Courts)
Qualification: This is a DIFC case and concerned human agency/deceit, not autonomous AI.
27. Case Law 2 — Muzoon Holding LLC v Arif Naqvi [2022] DIFC CFI 080
The case concerned allegations of deceit and inducing breach of a legal right under the DIFC Law of Obligations.
The Court considered whether the defendant could be held personally responsible for conduct associated with an investment structure involving other entities. (DIFC Courts)
Relevance
The case demonstrates the importance of distinguishing:
the entity that actually received the benefit;
the person/entity that committed the relevant conduct;
the person alleged to have induced the conduct.
This is directly relevant when an AI network contains several independent entities.
28. Case Law 3 — Yakzan v Cyber Knight Technologies [2024] DIFC CFI 077
The Court permitted additional technology companies to be added as defendants.
Principle
Where multiple entities may be connected to the technological conduct underlying a claim, procedural rules can allow those entities to be brought into the same proceedings. (DIFC Courts)
AI relevance
In an autonomous AI claim, the parties may include:
software company;
network company;
AI provider;
system integrator.
Joinder can allow the court to examine the complete causal chain.
29. Case Law 4 — Normand v Nathaniel [2024] DIFC SCT 125
Principle
Corporate personality remains important.
The Court explained that piercing the corporate veil is a limited doctrine aimed at preventing misuse or abuse of the corporate form. (DIFC Courts)
AI relevance
A claimant cannot simply impose liability on every company in an AI corporate group.
There must be a proper legal basis, such as:
direct harmful conduct;
contractual obligation;
agency;
vicarious liability;
statutory responsibility;
proven abuse of corporate personality.
30. Case Law 5 — Lals Holdings Ltd v Emirates Insurance Co [2024] DIFC CA 002
The case involved multiple corporate claimants, an insurer and an insurance broker.
The claim included allegations that the broker had failed to arrange appropriate insurance and had breached contractual and tortious duties. The DIFC Court of Appeal dismissed the appeal. (DIFC Courts)
AI relevance
It illustrates a multi-entity responsibility structure:
customer → broker → insurer
rather than a single bilateral relationship.
The analogy is useful for autonomous AI:
customer → integrator → AI provider → insurer
where different entities may have different contractual and tortious obligations.
31. Case Law 6 — Stelian Gheorghe v BSA Ahmad Bin Hezeem & Associates [2025] DIFC CFI 045
This case directly involved AI-generated legal material.
The defendants contended that some evidence and the claim form may have been generated partly using AI. The Court observed that errors in legal material were problematic and ultimately stayed the proceedings in favour of arbitration. (DIFC Courts)
Importance for AI liability
The case demonstrates that:
AI-generated material does not automatically become reliable merely because it is technologically generated;
human legal professionals remain responsible for material placed before the court;
AI involvement does not itself transfer legal responsibility to the software.
This is an important principle for autonomous AI networks:
Use of an autonomous or generative system does not automatically eliminate the legal responsibility of the human or entity deploying it.
32. Case Law 7 — Krystal Financial Consultants LLC v Nextgen Robopark Investment LLC [2025] DIFC CA 007
This case involved a dispute between entities connected with an investment/technology venture.
The DIFC Court of Appeal judgment of 16 June 2026 addressed the appeal from the first-instance proceedings. (DIFC Courts)
Relevance
Although not a decided autonomous-AI tort case, it illustrates why the legal identity and contractual relationship of the entities involved in technology-related ventures must be separately analysed.
33. Case Law 8 — Emirates NBD Bank v Almakhawi [2026] DIFC CFI 039
The DIFC Court considered claims involving multiple defendants and UAE civil-law principles concerning harmful acts, deception and responsibility.
The judgment reproduced former Civil Code Articles 282–285, including:
liability for harm;
direct and consequential harm;
direct versus indirect actors;
liability for deception. (DIFC Courts)
AI relevance
These principles provide a conceptual framework for analysing:
AI developer → integrator → operator → autonomous action → harm.
The critical issue remains causation and each entity's legally relevant contribution.
34. Direct AI Authority — DIFC Digital Economy Court
The UAE's most important institutional development is the DIFC Digital Economy Court (DEC).
Part 58 of the DIFC Courts Rules expressly provides that the DEC can hear claims involving:
artificial intelligence;
devices dependent on or controlled by AI;
complex databases;
digital assets;
blockchain;
automatic dispute resolution;
DAOs;
DeFi;
DApps;
digital signatures;
robotics;
cyber-physical systems;
unmanned aerial vehicles;
3D printing;
AI-related insurance claims. (DIFC Courts)
This is highly relevant to autonomous AI networks because Part 58 expressly covers both AI and physical cyber-physical systems.
35. AI Does Not Become a Defendant Merely Because It Is Autonomous
The DEC framework is important precisely because it treats AI as the subject matter of disputes, not necessarily as an independent legal person.
Part 58 allows claims concerning AI-controlled devices and systems, but it does not establish a general rule that AI itself possesses separate legal personality.
Therefore:
Technological autonomy ≠ legal personality.
The legal analysis remains focused on the humans and entities responsible under applicable law.
36. Multi-Entity AI Liability Model
A useful model is:
Level 1 — Developer
Question:
Did defective design or coding cause the harm?
Level 2 — Data provider
Question:
Did defective or unlawfully supplied data materially cause the harm?
Level 3 — Integrator
Question:
Did the integration create the risk?
Level 4 — Infrastructure provider
Question:
Did cloud/network failure cause the damage?
Level 5 — Operator
Question:
Was deployment negligent?
Level 6 — Supervisor
Question:
Was human oversight inadequate?
Level 7 — Owner
Question:
Did ownership or control trigger a statutory liability?
Level 8 — Insurer
Question:
Is there contractual insurance coverage?
37. Allocation of Liability
The court can conceptually construct:
Damage
↓
Causal contribution of Entity A
↓
Causal contribution of Entity B
↓
Causal contribution of Entity C
↓
Causal contribution of Entity D
↓
Article 253 allocation
The exact outcome depends on:
applicable law;
contractual arrangements;
evidence;
causation;
degree of fault;
statutory liability;
contribution by the injured person.
38. Joint and Several Liability
This is especially important.
Suppose:
developer = 25%;
integrator = 25%;
operator = 50%.
Article 253 allows the court, depending on the circumstances, to impose proportional responsibility or determine equal/joint-and-several liability. (UAE Legislation)
Joint-and-several liability can be particularly important to victims because otherwise the victim may be forced to identify precisely which entity caused which portion of the AI failure.
39. Contribution Between Defendants
Where one defendant pays more than its ultimate share, questions of contribution may arise between the responsible parties.
For example:
Bank pays the injured party → Bank establishes that software provider was also responsible → Bank seeks contribution from software provider.
This prevents the victim from having to resolve all internal allocation disputes before obtaining compensation.
40. Contractual Allocation of AI Risk
AI contracts increasingly contain:
indemnities;
limitation clauses;
warranties;
service-level agreements;
audit rights;
cybersecurity obligations;
data warranties;
model-performance obligations.
These provisions can determine which entity ultimately bears the economic burden.
However, contractual allocation does not necessarily eliminate statutory liability toward third parties.
Example
Developer and operator agree:
"Operator assumes all AI-related risk."
If the AI injures a third party, the agreement may affect recourse between developer and operator, but it does not automatically determine the third party's statutory claim.
41. Insurance
Autonomous AI networks may require:
professional indemnity insurance;
cyber insurance;
product liability insurance;
technology errors-and-omissions insurance;
autonomous-vehicle insurance;
directors' and officers' insurance.
The insurer may itself become involved in litigation concerning:
coverage;
exclusions;
causation;
misrepresentation;
contribution between insurers.
The DIFC Digital Economy Court expressly includes insurance claims connected with AI and other digital-economy technologies within its jurisdictional framework. (DIFC Courts)
42. AI Liability and Consumer Protection
Where an autonomous AI service is supplied to consumers, additional issues may arise:
defective service;
misleading representations;
unfair terms;
inadequate warnings;
unsafe products;
privacy violations.
The consumer may have a claim against the entity that supplied the service even if the underlying AI model was developed by another company.
The supplier may then seek contractual contribution from the developer.
43. AI Liability and Privacy
Autonomous AI networks can continuously process personal information.
Potential harms include:
unauthorised disclosure;
profiling;
incorrect automated decisions;
data loss;
identity misuse;
unlawful processing.
The UAE Personal Data Protection Law requires appropriate security measures and, in specified high-risk circumstances, a data-protection impact assessment before processing using modern technologies. (UAE Legislation)
Thus:
AI liability + data protection liability
may arise from the same event.
44. AI Liability and Cybersecurity
Suppose an attacker manipulates an autonomous AI system.
Potential defendants might include:
software provider;
cybersecurity contractor;
cloud provider;
operator.
The court must distinguish:
external cyberattack
from
failure to implement reasonable security safeguards.
An external hacker does not automatically eliminate the liability of an entity that negligently created or maintained a foreseeable vulnerability.
45. The "Human-in-the-Loop" Problem
Many autonomous systems claim to retain human oversight.
But the court may ask:
Was the human actually capable of intervening?
Did the human receive the warning?
Was sufficient time available?
Did the system obscure the warning?
Was the human trained?
Did the employer provide adequate procedures?
Therefore, merely stating:
"A human was technically responsible"
may not resolve liability.
The factual effectiveness of human supervision matters.
46. The "Human-on-the-Loop" Problem
Some systems operate autonomously while humans monitor them.
If the system acts rapidly, human intervention may be practically impossible.
This raises a fundamental question:
Can an entity rely on nominal human supervision when the system is designed to operate faster than a human can intervene?
This will likely become increasingly important in future UAE litigation involving autonomous vehicles, robotics and financial systems.
47. Standard of Care for AI Developers
In the absence of a dedicated AI civil-liability statute, courts may examine:
industry standards;
contractual standards;
regulatory requirements;
foreseeable risks;
testing practices;
security standards;
warnings;
system documentation;
known defects.
The relevant question is not simply:
"Did the AI make a mistake?"
Instead:
Was the conduct of the legally responsible entity unreasonable or otherwise legally actionable in light of the circumstances?
48. Foreseeability
Foreseeability becomes particularly important.
If an AI developer knew that:
the system could hallucinate;
the model could misclassify objects;
a safety constraint could fail;
the system was vulnerable to adversarial input;
and nevertheless deployed the system without adequate safeguards, the foreseeability analysis may become important.
Conversely, genuinely unforeseeable behaviour may complicate causation and fault.
49. Autonomous AI and Product Liability
When AI is embedded in a physical product, several liability regimes can overlap.
For example:
Autonomous car
→ vehicle defect
→ software defect
→ sensor defect
→ data defect
→ integration defect
→ operator negligence.
This creates a classic multi-entity liability problem.
The claimant may need to establish whether the defect originated in:
hardware;
software;
data;
integration;
maintenance;
deployment.
50. Autonomous AI and Professional Liability
Professionals using AI cannot necessarily transfer responsibility to the AI supplier.
For example:
A doctor uses an AI diagnostic system.
The AI recommends treatment X.
The doctor follows it.
The patient suffers harm.
Potential questions include:
Was the doctor required to independently verify the recommendation?
Did the hospital approve the system?
Was the AI properly validated?
Was the software supplied with adequate warnings?
Was the doctor's reliance reasonable?
Did the AI provider make misleading claims?
The final allocation may involve several entities.
51. AI and Evidence Preservation
AI cases require preservation of:
model version;
training data;
system logs;
prompts;
outputs;
API calls;
configuration settings;
software updates;
human intervention records.
Without these records, establishing causation becomes extremely difficult.
Therefore, auditability is not merely a technical feature; it can become legally significant evidence.
52. Practical Hypothetical
Facts
A UAE logistics company deploys an autonomous warehouse robot.
The robot:
receives navigation software from Company A;
uses sensors manufactured by Company B;
uses an AI model from Company C;
operates on cloud infrastructure from Company D;
is integrated by Company E;
is operated by Company F.
The robot injures an employee.
Possible analysis
Company A: software defect?
Company B: defective sensor?
Company C: defective AI model?
Company D: cloud failure?
Company E: integration error?
Company F: negligent deployment or supervision?
The court would then analyse:
duty;
breach/fault;
causation;
damage;
statutory responsibility;
contractual allocation;
Article 253 multi-person liability.
53. Possible Remedies
Depending upon the claim, remedies may include:
Compensation
For:
property damage;
bodily injury;
financial loss;
lost profits;
moral damage.
Injunctions
To prevent continuing harmful AI activity.
Specific corrective measures
For example:
disabling defective functionality;
correcting data;
restoring access.
Contractual remedies
termination;
damages;
indemnification.
Data remedies
deletion;
correction;
restriction of processing where legally available.
54. Important Distinction — AI Error vs Legal Fault
This is a crucial examination point.
An AI error does not automatically equal civil liability.
There must be a legally recognised basis for liability.
Similarly:
Human involvement does not automatically eliminate AI-related liability.
The court must determine:
Who owed the duty?
What duty was breached?
What caused the damage?
What evidence proves causation?
How should responsibility be allocated?
55. Six+ Important Cases — Revision Table
| Case | Main doctrine | AI-network relevance |
|---|---|---|
| Al Mheiri v Cameron [2025] DIFC CA 008 | Agency/deceit | Principal and intermediary responsibility |
| Muzoon Holding v Naqvi [2022] DIFC CFI 080 | Deceit/inducing breach | Separating entity and individual responsibility |
| Yakzan v Cyber Knight [2024] DIFC CFI 077 | Joinder of technology entities | Multiple defendants in technology disputes |
| Normand v Nathaniel [2024] DIFC SCT 125 | Corporate veil | Separate liability of AI group companies |
| Lals Holdings v Emirates Insurance [2024] DIFC CA 002 | Multi-party contractual/tortious duties | Broker–insurer–customer allocation |
| Stelian Gheorghe v BSA [2025] DIFC CFI 045 | AI-generated legal material | Human responsibility despite AI use |
| Emirates NBD v Almakhawi [2026] DIFC CFI 039 | Harm, causation, deception | Multiple responsible actors |
| Krystal Financial Consultants v Nextgen Robopark [2025] DIFC CA 007 | Technology-related corporate dispute | Multi-entity technology structure |
These are analogical and foundational authorities, not a collection of decided UAE cases specifically imposing tort liability on autonomous AI networks. As of September 2026, the UAE's reported jurisprudence has not yet produced a mature body of appellate decisions squarely deciding a catastrophic autonomous-AI multi-entity liability case. The DIFC's Part 58 framework is consequently particularly significant for future disputes. (DIFC Courts)
56. Role of the DIFC Digital Economy Court
The DIFC has expressly anticipated this class of dispute.
Part 58 identifies claims involving:
AI;
AI-controlled devices;
robotics;
autonomous systems;
complex databases;
cyber-physical systems;
UAVs;
automatic dispute resolution;
AI-related insurance.
It also permits the Digital Economy Court to use sophisticated digital procedures and AI-driven smart forms. (DIFC Courts)
This is significant because autonomous AI disputes may require courts to understand not only traditional contracts and torts but also:
algorithms;
data architecture;
machine-learning systems;
cloud infrastructure;
digital evidence;
robotics.
57. Future Direction of UAE AI Liability
The likely development of UAE private law will revolve around several questions:
1. Explainability
Who must explain why the autonomous system acted as it did?
2. Auditability
Who must preserve technical records?
3. Allocation
How should liability be divided between developer, integrator and operator?
4. Insurance
Who must insure autonomous-system risks?
5. Contract
How far can sophisticated parties allocate AI risk contractually?
6. Consumer protection
Can suppliers contract out of responsibility toward consumers?
7. Product liability
Should defective AI software be treated like a defective product?
8. Corporate groups
When, if ever, should related AI companies share responsibility?
58. Exam-Oriented Legal Formula
Multi-Entity Autonomous AI Liability
AI System
↓
Multiple Legal Entities
↓
Duty / Contract / Statutory Obligation
↓
Fault or Legally Relevant Conduct
↓
Causation
↓
Damage
↓
Article 253 Multi-Person Liability
↓
Proportional or Joint-and-Several Liability
↓
Contribution Between Responsible Entities
59. Conclusion
UAE civil law presently approaches multi-entity liability in autonomous AI networks through existing principles rather than by treating AI as an independent legal person.
The most important current provision is Article 253 of the 2025 Civil Transactions Law, which expressly addresses situations where multiple persons are responsible for the same harm and permits proportional, equal or joint-and-several liability depending on the circumstances. (UAE Legislation)
The central legal challenge is therefore causal attribution:
Developer → data provider → cloud provider → integrator → operator → autonomous AI → harm
The court must identify which links in this chain constitute legally relevant conduct and how responsibility should be allocated.
The existing cases involving agency, corporate personality, technology companies, AI-generated legal material, deception, insurance and multi-party harm provide useful building blocks. Particularly important are Al Mheiri v Cameron, Yakzan v Cyber Knight, Normand v Nathaniel, Lals Holdings v Emirates Insurance, and Stelian Gheorghe v BSA. The DIFC Digital Economy Court's Part 58 is especially significant because it expressly covers AI, AI-controlled devices, robotics and cyber-physical systems. (DIFC Courts)
Core principle for examination:
Autonomous AI may perform the immediate operation, but UAE civil liability continues to be attributed to the legally responsible human or corporate actors through established rules of duty, causation, agency, harmful acts, contractual responsibility and multi-person liability.

comments