Civil Law And Uae Smart City Infrastructure Liability .

 

Civil Law and UAE – Smart City Infrastructure Liability

1. Introduction

Smart city infrastructure liability concerns legal responsibility for harm caused by, or connected with, technologically advanced urban infrastructure.

A smart city may use:

  • intelligent traffic lights;
  • autonomous transport systems;
  • smart parking;
  • AI-based surveillance;
  • connected electricity grids;
  • smart water systems;
  • IoT sensors;
  • automated buildings;
  • digital identity systems;
  • public Wi-Fi and communication networks;
  • blockchain-based municipal services;
  • smart waste-management systems;
  • automated emergency systems;
  • AI-controlled infrastructure.

The legal question is simple:

If a smart infrastructure system causes harm, who is legally responsible?

Possible responsible parties can include:

  • the government authority;
  • infrastructure owner;
  • operator;
  • contractor;
  • technology supplier;
  • software developer;
  • maintenance company;
  • sensor manufacturer;
  • data provider;
  • system integrator;
  • cybersecurity provider; or
  • another person whose wrongful act caused the damage.

Under the current UAE Civil Transactions Law, Federal Decree by Law No. 25 of 2025, Article 271 provides a particularly relevant rule: a person controlling things requiring special care to prevent harm, or mechanical machinery, is liable for harm caused by those things or machinery, subject to the statutory exception for harm that could not be prevented and special legislation. Article 272 also allows preventive measures where danger is threatened.

2. Simple Meaning

Imagine a smart traffic intersection.

It contains:

Camera → AI software → traffic-control system → traffic lights

Suppose the system incorrectly keeps the traffic light green in two directions.

A collision occurs.

The legal investigation may ask:

  1. Was the infrastructure defective?
  2. Was the software defective?
  3. Was the sensor malfunctioning?
  4. Was the system incorrectly configured?
  5. Was maintenance neglected?
  6. Did the operator ignore warnings?
  7. Did a cyberattack cause the failure?
  8. Did a contractor install the system incorrectly?
  9. Did the government authority have a relevant legal duty?
  10. Who caused the actual damage?

This is the essence of smart-city infrastructure liability.

3. Basic Liability Formula

A useful examination formula is:

Duty/Responsibility + Wrongful Conduct + Damage + Causation = Possible Civil Liability

For infrastructure involving inherently dangerous or machinery-type systems, the special statutory rules may also become important.

4. Article 271 – Things Requiring Special Care and Machinery

Article 271 of the current Civil Transactions Law provides that whoever controls:

  • things requiring special care to prevent harm; or
  • mechanical machinery

is liable for harm caused by those things or machinery, subject to the statutory exception for harm that could not be prevented and special legal provisions.

This can be highly relevant to smart-city infrastructure.

Examples

Potentially relevant systems include:

  • automated gates;
  • elevators;
  • robotic systems;
  • autonomous transport;
  • mechanical traffic infrastructure;
  • industrial smart machinery;
  • automated construction equipment.

The key concept is control.

The person controlling the system may be more legally significant than simply the person who owns the physical equipment.

5. Preventive Liability – Article 272

Smart-city liability is not only about compensation after an accident.

Article 272 allows a person threatened with harm arising from:

  • a building;
  • an animal;
  • mechanical machinery; or
  • things requiring special care

to demand appropriate preventive measures.

If the responsible person does not act within an appropriate period, court intervention may be sought. In urgent circumstances, necessary protective measures may be taken at the responsible person's expense, subject to the statutory requirements.

Smart-city example

A smart electrical-control system repeatedly overheats.

Residents identify the danger before a fire occurs.

The legal issue may therefore become:

Can the responsible party be required to correct the dangerous condition before actual damage occurs?

This is particularly important for smart infrastructure because continuous monitoring can identify risks before traditional physical damage happens.

6. Direct and Indirect Damage

Traditional UAE civil-law principles distinguish between direct and consequential/indirect harm.

The former Article 283 of the Civil Transactions Law provided that harm may be direct or by causation. For direct harm, compensation was required without an additional fault requirement; for consequential harm, wrongdoing, deliberate conduct, or an act leading to the harm was relevant. The Federal Supreme Court has expressly explained this distinction.

Smart-city example – direct

An automated machine physically strikes a pedestrian.

The machine directly causes the injury.

Smart-city example – consequential

A defective sensor provides incorrect data.

That data causes an automated traffic system to change signal timings.

The signal change causes an accident.

The court must examine the chain:

sensor → data → software → traffic signal → accident → injury

7. Causation in Smart Infrastructure

Causation can become particularly complicated because smart-city systems contain many interconnected components.

Consider:

Sensor

Network

Cloud platform

AI algorithm

Control centre

Physical infrastructure

Person suffers harm

If the system fails, several parties may argue:

“The problem was not caused by us.”

The court therefore needs to determine the legally relevant causal connection.

8. Human Error and Automated Systems

Automation does not eliminate human responsibility.

For example:

An AI traffic-management system warns an operator:

“Sensor malfunction detected.”

The operator ignores the warning.

An accident occurs.

The dispute may involve:

  • software responsibility;
  • operator negligence;
  • maintenance responsibility;
  • system-design responsibility;
  • causation.

Therefore:

Automation can change the form of the decision-making process without necessarily eliminating human responsibility.

9. Software Defects

A smart-city system can fail because of software.

Examples:

  • incorrect algorithm;
  • coding error;
  • faulty update;
  • incompatible software;
  • incorrect configuration;
  • failure to patch;
  • defective AI model;
  • incorrect sensor interpretation.

The legal claim may potentially be based on:

  • contract;
  • tort/civil wrongdoing;
  • product liability;
  • professional negligence;
  • statutory responsibility.

The correct legal classification depends on the relationship between the parties and applicable legislation.

10. Hardware and Sensor Failure

Smart infrastructure depends heavily on sensors.

Examples:

  • temperature sensors;
  • traffic cameras;
  • pressure sensors;
  • pollution sensors;
  • water-level sensors;
  • electricity meters;
  • biometric devices.

If a sensor produces incorrect information, the consequences may be physical.

Example

A flood sensor incorrectly reports:

“Water level normal.”

The automated drainage system therefore does not activate.

Flooding damages nearby property.

Possible defendants may include:

  • sensor manufacturer;
  • maintenance contractor;
  • system operator;
  • infrastructure owner.

But liability must be established against the particular party under the applicable legal rules.

11. Cyberattack and Smart Infrastructure

Cybersecurity creates a difficult liability problem.

Suppose hackers enter a smart-city traffic system and cause signals to malfunction.

Potential questions include:

  1. Was there a cyberattack?
  2. Could it reasonably have been prevented?
  3. Was cybersecurity adequate?
  4. Did the operator ignore known vulnerabilities?
  5. Was software properly updated?
  6. Did a third-party supplier create the vulnerability?
  7. Was the attack an external cause?
  8. Did the system operator have a contractual or statutory duty to maintain security?

The UAE's general civil-liability principles may therefore interact with:

  • cybersecurity legislation;
  • data-protection legislation;
  • electronic-transactions rules;
  • sector-specific regulation;
  • contractual obligations.

12. Public Authority Liability

A smart city frequently involves government or municipal authorities.

This creates an important distinction between:

Public-law responsibility

The authority's statutory/regulatory duties.

Civil liability

Compensation for legally recognised private harm.

The existence of public authority involvement does not automatically answer the civil-liability question.

A court may need to determine:

  • what legal duty existed;
  • whether the authority breached it;
  • whether immunity or special statutory provisions apply;
  • whether the claimant suffered compensable damage;
  • whether the authority's conduct caused the damage.

13. Contractor Liability

Smart-city projects are often delivered through multiple contractors.

For example:

Government authority

Main contractor

Technology integrator

Software developer

Sensor supplier

Maintenance provider

A failure may involve several participants.

The contractual allocation of responsibilities therefore becomes extremely important.

14. Contractual vs Tortious Liability

A UAE Supreme Court judgment, Commercial Cassation No. 941 of 2019, explained that where the injured party and alleged wrongdoer are connected by a contractual relationship, the court should not simply apply tort liability to a contractual compensation dispute unless circumstances such as a crime, fraud or sufficiently serious wrongdoing satisfy the requirements of tort liability. The judgment also reiterated the importance of fault, damage and causation.

Smart-city example

A municipality hires Company A to maintain smart traffic lights.

The system fails.

The municipality sues Company A.

The court must first examine:

What did the maintenance contract require?

This may be principally a contractual dispute rather than simply a tort claim.

15. Case Law 1 – Federal Supreme Court, Civil Judgment No. 99/1995

This UAE Federal Supreme Court decision is important for the distinction between direct harm and harm by causation.

The Court explained that direct harmful conduct can create liability without requiring proof of additional intent or negligence, while consequential harm requires the additional conditions identified by the Civil Transactions Law. It also discussed external causes such as force majeure, unexpected events, third-party conduct and conduct of the injured person.

Smart-city application

If an automated machine directly damages property, the direct-harm principle may become relevant.

If a defective component indirectly causes a later accident, the court may undertake a more detailed causation analysis.

Principle

The structure of liability depends partly on how the infrastructure caused the damage.

16. Case Law 2 – UAE Federal Supreme Court, Commercial Cassation No. 941/2019

This decision is especially useful for distinguishing contractual and tortious responsibility.

The Court stated that where a contractual relationship exists, tort principles should not simply replace contractual rules unless the circumstances satisfy the applicable basis for tort liability, such as crime, fraud or serious wrongdoing. It also stated that fault, damage and causation are fundamental elements of liability.

Smart-city application

If a smart-city operator breaches a maintenance contract, the claimant should first identify the contractual obligation.

Principle

The legal source of the duty matters.

17. Case Law 3 – Graciela Ltd v Giacobbe [2014] DIFC CFI 027

This is particularly relevant to technology infrastructure.

The defendant was alleged to have sabotaged the claimant's IT system.

The DIFC Court found that deliberate interference with the IT system constituted wrongful interference with property under the DIFC Law of Obligations and awarded damages for resulting losses.

The judgment expressly considered costs relating to:

  • restoration of the IT system;
  • network rebuilding;
  • contractors; and
  • other losses.

Smart-city application

A smart city depends on interconnected IT systems.

If someone intentionally interferes with a municipal digital infrastructure system, the infrastructure itself can be the subject of legally protected interests.

Principle

Digital infrastructure can constitute legally protected property or interests, and unlawful interference can generate damages.

18. Case Law 4 – Aegis Resources DMCC v Union Bank of India [2020] DIFC CFI 004

This case concerned negligence and contributory negligence.

The DIFC Court considered whether the claimant's own negligent conduct contributed to its losses and discussed the reduction of liability according to the claimant's contribution under the DIFC Law of Obligations.

Smart-city application

Suppose:

  • a smart-city operator fails to maintain cybersecurity; but
  • a user knowingly ignores repeated security warnings.

The court may have to examine whether the claimant's own conduct contributed to the damage, depending on the applicable legal regime.

Principle

The conduct of the injured party can be relevant to the amount of recoverable loss.

19. Case Law 5 – BAM Higgs & Hill LLC v Affan Innovative Structures LLC [2021] DIFC CFI 106

The DIFC Court considered the relationship between:

  • duty;
  • breach;
  • damage; and
  • causation.

The judgment emphasised that actionable loss is necessary before a negligence claim can succeed. The case has also generated subsequent procedural decisions in 2026, including an order refusing permission to appeal.

Smart-city application

A claimant cannot simply say:

“The smart system was defective.”

The claimant must establish legally actionable damage and the connection between the defect and that damage.

Principle

Technical failure does not automatically equal compensable legal damage.

20. Case Law 6 – Nael v Niamh Bank [2024] DIFC CA 015

This case concerned guarantees connected with a large public infrastructure project.

The underlying construction contract involved infrastructure works for a large public project, and the employer terminated the contractor and made demands under guarantees following the contractor's insolvency.

Although this is not a smart-city tort case, it is useful for understanding the contractual architecture of large infrastructure projects.

Smart-city application

Large smart-city projects similarly involve:

  • contractors;
  • employers;
  • guarantees;
  • performance obligations;
  • termination;
  • insolvency risk.

Principle

Infrastructure liability can involve multiple interconnected contractual relationships, not merely a simple owner-versus-injured-person claim.

21. Case Law 7 – Maalik Investments Ltd v Mabili Interior Decoration Design LLC [2022] DIFC SCT 117

This dispute involved fit-out works and alleged negligence causing damage to a third-party office.

The court considered allegations concerning:

  • delay;
  • approvals;
  • performance of works; and
  • damage caused to another office through alleged negligence. 

Smart-city application

Smart-city projects also involve complex construction and installation phases.

A defect can originate during:

design → installation → testing → commissioning → operation

Principle

Infrastructure liability can arise from defective implementation before the smart system even becomes operational.

22. Case Law 8 – Latha v Lavni [2022] DIFC SCT 022

This case concerned a software programme that allegedly failed to perform its required purpose.

The claimant argued that the software developer failed to develop and implement the software according to the agreement and timeline and that repeated notifications of deficiencies were not adequately addressed.

Smart-city application

This is highly relevant to smart infrastructure because smart-city projects frequently depend upon software development contracts.

Principle

A software failure can create contractual liability where the supplier does not deliver the agreed functionality.

23. Case-Law Table

CaseIssueSmart-city lesson
Federal Supreme Court, Civil Judgment No. 99/1995Direct/consequential harmIdentify how infrastructure caused damage
Federal Supreme Court, Commercial Cassation No. 941/2019Contract vs tortIdentify the legal source of the duty
Graciela v Giacobbe [2014]IT-system sabotageDigital infrastructure can be legally protected
Aegis Resources v Union Bank [2020]Negligence/contributory negligenceClaimant's own conduct can matter
BAM Higgs & Hill v Affan [2021]Duty, damage and causationTechnical failure requires actionable loss
Nael v Niamh Bank [2024]Public infrastructure contractsLarge infrastructure involves layered contracts
Maalik Investments v Mabili [2022]Construction/installation damageLiability can arise during implementation
Latha v Lavni [2022]Software failureSoftware obligations can generate contractual liability

Important: The DIFC cases are DIFC authorities and should not be treated as binding precedents of the ordinary mainland UAE courts.

24. Who Can Be Liable?

A. Infrastructure owner

The owner may have responsibilities concerning:

  • safety;
  • maintenance;
  • operation;
  • monitoring.

Article 271's control-based approach is important where the infrastructure falls within its scope.

B. Operator

The operator may be responsible for:

  • incorrect operation;
  • failure to respond to alerts;
  • failure to shut down dangerous systems;
  • inadequate supervision.

C. Contractor

A contractor may be liable for:

  • defective installation;
  • poor construction;
  • failure to follow specifications;
  • negligent implementation.

D. Software developer

Potential responsibility may arise from:

  • defective software;
  • failure to meet specifications;
  • negligent coding;
  • failure to correct known defects.

E. Manufacturer

A manufacturer may face liability under applicable product-liability rules where a defective product causes damage.

F. Maintenance company

Failure to:

  • inspect;
  • repair;
  • patch;
  • calibrate;
  • replace defective components

can become relevant.

25. Smart-City Infrastructure and Product Liability

Suppose a smart traffic sensor is manufactured with a defect.

The sensor sends incorrect information.

The traffic-control system responds incorrectly.

An accident occurs.

The legal chain may be:

Defective sensor

Incorrect data

Incorrect automated decision

Accident

Damage

The claimant may potentially have claims against different participants, but each claim requires its own legal basis.

26. Smart Buildings

Smart buildings may contain:

  • automated elevators;
  • biometric entry;
  • HVAC automation;
  • fire detection;
  • automated doors;
  • energy-management systems;
  • security cameras;
  • access-control software.

Example

An automated door incorrectly locks an emergency exit.

A fire occurs.

The legal analysis could involve:

  • building owner;
  • facility manager;
  • software provider;
  • maintenance contractor;
  • equipment manufacturer.

The court would need evidence establishing:

what failed + who controlled it + whether there was a duty + whether the failure caused the injury.

27. Autonomous Transport

Autonomous vehicles create particularly complex liability questions.

Suppose:

AI driving system → detects pedestrian incorrectly → vehicle fails to brake → injury.

Possible questions:

  • Was the AI system defective?
  • Was the sensor defective?
  • Was the vehicle maintained?
  • Was the software properly updated?
  • Was the driver expected to supervise?
  • Was the road infrastructure defective?
  • Did another vehicle create the emergency?
  • Was there a cyberattack?

The traditional civil-law concepts of harm, fault/control, causation and external causes remain relevant, although special legislation may govern the particular technology.

28. Smart Traffic Infrastructure

Smart traffic systems may use:

  • cameras;
  • radar;
  • GPS;
  • AI;
  • vehicle-to-infrastructure communication;
  • automatic signalling.

A malfunction can create:

  • personal injury;
  • vehicle damage;
  • traffic disruption;
  • economic losses.

The most important evidence may include:

  • system logs;
  • sensor records;
  • maintenance records;
  • software versions;
  • alerts;
  • timestamps;
  • operator intervention records.

29. Smart Electricity and Water Systems

Smart utilities can automatically control:

  • electricity distribution;
  • water pressure;
  • consumption;
  • emergency shut-off;
  • leakage detection.

A software or sensor failure could produce:

  • fire;
  • flooding;
  • property damage;
  • service interruption;
  • business losses.

The liability analysis must distinguish between:

physical infrastructure failure

and

digital-control failure.

30. Cybersecurity Liability

Smart infrastructure creates a major cybersecurity question:

Who bears responsibility when a cyberattack causes physical damage?

Suppose hackers manipulate a smart water-control system and cause flooding.

The responsible infrastructure operator may argue:

“The damage was caused by hackers.”

The claimant may respond:

“The operator failed to implement reasonable security measures.”

The court would need to examine:

  • foreseeability;
  • security obligations;
  • applicable statutory requirements;
  • contractual duties;
  • system vulnerabilities;
  • external causation;
  • evidence.

31. Data Failure and Physical Damage

One of the most important new issues is that digital errors can produce physical harm.

For example:

Wrong digital data → wrong automated instruction → physical event → injury

This means civil liability can no longer be analysed solely through traditional physical infrastructure.

The digital layer and physical layer must be analysed together.

32. Government Smart-City Systems

A government-operated system may provide:

  • public transport;
  • traffic control;
  • emergency response;
  • public safety;
  • utilities;
  • municipal services.

A claimant should identify the exact legal relationship.

For example:

Private contractor

Contractual/tort liability may be relevant.

Government authority

Public-law and applicable governmental-liability rules may also need to be considered.

Mixed public-private project

Both contractual allocation and statutory responsibilities may matter.

33. Preventive Liability Is Especially Important

Traditional litigation often begins:

“The damage has already happened.”

Smart-city systems permit another approach:

“The system is creating a foreseeable danger; prevent the damage now.”

Article 272 of the current Civil Transactions Law is therefore conceptually important because it permits measures to avert certain threatened harm involving buildings, machinery and things requiring special care.

34. Expert Evidence

Smart-city cases are likely to require technical experts.

Experts may examine:

  • source code;
  • system architecture;
  • sensor accuracy;
  • cybersecurity;
  • maintenance records;
  • AI models;
  • network logs;
  • system design;
  • physical infrastructure;
  • causation.

The court, however, remains responsible for the ultimate legal determination.

Important distinction

Expert: explains technical facts.

Court: decides legal responsibility.

35. Contract Drafting for Smart-City Projects

Smart infrastructure contracts should clearly address:

1. System performance

What exactly must the system do?

2. Maintenance

Who maintains it?

3. Cybersecurity

Who protects it?

4. Updates

Who installs software patches?

5. Data

Who owns and controls the data?

6. AI decisions

Who is responsible for automated decisions?

7. Downtime

What happens if the system fails?

8. Liability

Who bears which risks?

9. Insurance

What risks must be insured?

10. Evidence

What logs must be retained?

11. Audit

Who can inspect the system?

12. Termination

What happens if the system repeatedly fails?

36. Causation Diagram

A useful way to analyse a smart-city accident is:

Design

Manufacture

Installation

Software

Sensor

Network

AI/Algorithm

Automated Decision

Physical Infrastructure

Harm

Economic/Physical Loss

At each stage ask:

Who controlled this stage?

and:

What evidence proves the failure?

37. Defences

A defendant may argue:

1. No defect

The system operated according to specification.

2. No negligence

Reasonable precautions were taken.

3. No causation

Another factor caused the damage.

4. External cause

The incident resulted from an event outside the defendant's responsibility.

5. Third-party interference

A hacker or another person caused the event.

6. Claimant's own conduct

The claimant contributed to the damage.

7. Contractual limitation

A valid limitation clause may affect contractual liability, subject to mandatory law.

38. Simple Practical Example

Situation

Dubai introduces an AI-based traffic-management system.

A contractor installs cameras.

A software company supplies the AI.

A maintenance company maintains the system.

A government authority operates it.

One camera begins producing incorrect data.

The AI misinterprets the traffic.

The signal changes incorrectly.

Two vehicles collide.

Legal analysis

Step 1: Identify the malfunction.

Camera or AI?

Step 2: Identify control.

Who controlled the defective component?

Step 3: Identify duty.

What did the contract/statute require?

Step 4: Identify fault.

Was there negligence or another legally relevant basis?

Step 5: Establish causation.

Did the defect actually cause the accident?

Step 6: Determine damage.

Injury? Vehicle damage? Other proven loss?

Step 7: Identify responsible parties.

Owner? Operator? Contractor? Software supplier? Manufacturer?

Step 8: Consider external causes.

Was there a cyberattack or another intervening event?

Step 9: Determine remedy.

Compensation, repair, replacement, or another remedy?

39. Simple Legal Framework

Smart City Liability

1. Identify infrastructure

2. Identify controller/operator

3. Identify legal duty

4. Identify malfunction/wrongdoing

5. Establish damage

6. Establish causation

7. Examine external causes

8. Allocate responsibility

9. Calculate compensation

40. Mainland UAE vs DIFC

IssueMainland UAEDIFC
General civil liabilityUAE Civil Transactions LawDIFC laws
Machinery/thing liabilityCurrent Civil Transactions Law Article 271DIFC obligations framework
Electronic systemsUAE electronic-transactions frameworkDIFC digital-economy framework
Technology disputesOrdinary competent courts/specialised forums as applicableDigital Economy Court
IT-system casesUAE law may apply depending on jurisdictionDIFC has direct technology jurisprudence
Case precedentsFederal/local UAE courtsDIFC Courts

The distinction is critical.

A case such as Graciela v Giacobbe is valuable for understanding technology-related liability, but it is a DIFC authority, not a binding mainland UAE precedent.

41. Key Legal Principles

Remember these 12 points:

  1. Smart infrastructure can create civil liability.
  2. Control of dangerous machinery can be legally important.
  3. Article 271 is particularly relevant to machinery and things requiring special care.
  4. Preventive relief may be available where dangerous conditions threaten harm.
  5. Damage must be legally recognised and proved.
  6. Causation is essential.
  7. Digital failure can cause physical damage.
  8. Software can be part of the liability chain.
  9. Cyberattacks require analysis of external causation and security duties.
  10. Contractual and tortious liability must be distinguished.
  11. Technical experts may be essential, but courts decide legal liability.
  12. DIFC technology cases should not automatically be treated as mainland UAE precedent.

42. Exam-Ready Conclusion

Smart city infrastructure liability in UAE civil law concerns responsibility for harm arising from interconnected physical and digital urban systems. The current Civil Transactions Law is particularly relevant because Article 271 imposes liability on the person controlling things requiring special care or mechanical machinery for harm caused by them, subject to the statutory exceptions. Article 272 also provides a preventive mechanism for threatened harm.

The traditional UAE liability framework further requires careful examination of wrongdoing/fault, damage and causation, with a distinction between direct and consequential harm. UAE Supreme Court jurisprudence confirms that these elements must be properly established.

In a smart-city dispute, therefore, the central question is not simply “Who owns the technology?” It is:

Who had the relevant legal duty or control, what failed, did that failure constitute legally actionable wrongdoing or breach, did it cause the damage, and what remedy follows?

Quick Revision Formula

Smart Infrastructure → Control/Duty → System Failure → Wrongdoing/Breach → Damage → Causation → Responsible Party → Compensation/Preventive Remedy

The major development is that digital and physical infrastructure are becoming legally interconnected: a defective sensor, algorithm, software system or cyber-control mechanism can ultimately produce ordinary physical harm, requiring traditional civil-law principles to be applied to technologically complex factual situations.

LEAVE A COMMENT