17.08.2026

Who Is Liable When AI Gets It Wrong: Broken Production, Infringed Rights

Liability for a model's mistake sits with whoever took its output into their work. How to allocate that risk by contract between client, studio and vendor.

Who Is Liable When AI Gets It Wrong: Broken Production, Infringed RightsWho Is Liable When AI Gets It Wrong: Broken Production, Infringed Rights

Liability for a model's mistake sits with whoever took its output into their work. The system itself is not a legal subject: it holds no assets, carries no obligations and cannot answer in court. So the question of how to push a production outage onto a neural network has no answer, and the useful conversation starts somewhere else — how to spread the risk across the people and companies that are actually in the chain.

We work through the rules of three jurisdictions and what each one means for your contracts.

United States: the person who filed it answers for it

The instructive case came out of the Southern District of New York. In Mata v. Avianca, lawyers filed an opposition brief citing six court decisions that do not exist; ChatGPT had invented them. Asked directly whether the cases were genuine, the model confirmed they were, and one of the lawyers filed an affidavit attesting to their authenticity.

The court imposed sanctions under Rule 11 or, in the alternative, the court's inherent authority — 5,000 dollars, jointly and severally — on both lawyers and their firm, and ordered them to write to the plaintiff and to each judge to whom a fabricated decision had been attributed. The part of the reasoning that travels across professions: the duty of reasonable inquiry rests with whoever signs the filing, and it cannot be handed to a tool.

The same logic runs through software work. Not knowing that a generated fragment contained someone else's protected code removes nothing: good faith can affect the size of an award, and it does not remove liability itself.

Where the line with the model provider runs

The provider answers for its own product: for a model that by design produces prohibited output, and for failing the promises in its own contract. Claims about training data land on the provider only so far as its contract and the courts put them there; the practice has not settled. The moment the output is pulled into your work — into a commit, a build, a document for a client — responsibility for it moves to you. That handover is the dividing line, and a contract can shift it only in money terms: a provider can reimburse your losses, and it cannot answer to your client in your place. Separately from that, the new European directive lets an injured party sue a software manufacturer directly, alongside you — within the damage the directive covers: life and health, damage to personal property, destruction of data.

EU: from December 2026, software counts as a product

Directive (EU) 2024/2853 rewrites the regime for defective products and brings software and AI systems expressly within the definition of a product. Liability is strict: the injured party proves the defect, the damage and the link between them, without having to prove fault.

Table: who answers for an AI error in the US, the EU and the UAE

The dividing line is 9 December 2026: products placed on the market or put into service after that day fall under the new rules, while earlier ones stay under Directive 85/374/EEC. Member states have to transpose the directive by the same date.

UAE: a new civil code

The entire base has just changed here. Federal Decree-Law No. 25 of 2025 replaced the 1985 civil law in full and has applied since 1 June 2026. What matters for this topic is that, on the reading of the law firms tracking it, the reform sharpened the rules on causation, contributory fault and joint liability.

The practical conclusion is short: arrangements drafted under the old code need reworking, and carrying them into new contracts unchanged does not hold. Contracts concluded before 1 June 2026 generally remain under the previous code, which makes references to articles of the 1985 law the first thing worth checking.

When production breaks or a claim lands, a dispute between the parties to a contract does not turn on which tool was used. The court looks at what the contract says: who was responsible for checking the output, by what means the check was run, and what the parties agreed to do if it failed. With those three points missing from the text, liability falls back on the general rules, and they almost always point at whoever delivered the work to the client.
The gap we see most often works like this: the contract sets out in detail WHAT the contractor delivers and says nothing about WHAT IT WAS MADE WITH. Until AI use is named in the text outright, as far as the contract goes it is not there — and its consequences land on the client anyway.
— Futura Digital's assessment

Allocating the risk by contract

Three relationships below, and what each one needs in writing.

Client and contractor studio

  • Disclosure of AI use broken down by category of work; a general line about "modern tooling" closes nothing here.
  • A warranty of clean title in the delivered material.
  • An obligation to hand over provenance evidence along with the files.
  • Indemnity for third-party claims, capped against the value of the work.

Company and employee

  • A list of tasks where models are permitted, and a list of data that never goes into them.
  • A requirement to check output before use and to record that the check happened.
  • Recovery from an employee runs into what that employee can actually pay, so the weight falls on procedure: it protects the company long before any recovery does.

Company and AI vendor

  • Commitments on training with your data.
  • Indemnity for intellectual property claims against the output.
  • Retention and deletion terms.
  • Service availability, if your production depends on it.
  • The tier determines how much protection you get, and the gap between a consumer and an enterprise plan is measured in exactly these clauses.

The liability ladder inside a company

So far this has been about the company answering. The second question follows immediately: the company has paid, and now it looks inside for who carries the cost. The answer shapes what goes into the employment contract and into the contractor agreement, so it belongs here. Under UAE law it works like this:

  • Employee. Labour law does not cap liability itself: the employer recovers the full loss through a separate claim.
  • Contractor or sole establishment. Answers under the contract and with their own assets.
  • Director. Under the companies law, answers to the company, to its shareholders and to third parties for fraud, abuse of powers, breach of the law or the constitution, and gross error.
  • Insolvency. Under the bankruptcy law, the court may order directors and de facto managers to cover company debts personally where assets cover less than a fifth of the debts and the court finds mismanagement or the acts the statute lists: undue risk-taking, disposals at an undervalue, preference transactions in the two years before insolvency.

The ladder leads somewhere counterintuitive: pushing risk downward onto the people doing the work makes little economic sense. Recovery from an employee runs into what that employee can pay, so the measures that actually work sit upstream — checking the output, and allocating risk by contract to parties that carry insurance and capital. The same applies to product launch support in external markets, where platform requirements join your chain.

The short version

The model answers for nothing, so liability is distributed entirely among people and companies. In the US it lands on whoever signed off the output; in the EU, from December 2026, defective software falls under strict liability; in the UAE the whole civil code has changed. The working answer to all three is the same: name AI use in your contracts and set out who checks the output. That is also where an AI usage assessment starts, along with the wider conversation about publishing and gamedev support.

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.