Civil Law And Uae Multi-Entity Liability In Autonomous Ai Networks .

Civil Law and UAE Multi-Entity Liability in Autonomous AI Networks

1. Introduction

Multi-entity liability in autonomous AI networks concerns situations where harm is produced by an AI system that is designed, supplied, trained, deployed, supervised, integrated, or operated by several different legal persons.

For example, an autonomous logistics network may involve:

an AI developer;

a cloud provider;

a data provider;

a hardware manufacturer;

an AI-system integrator;

a platform operator;

the business deploying the system;

a human supervisor; and

an insurer.

If the autonomous system causes damage, the difficult legal question is:

Which entity is legally responsible for the harm when no single entity directly performed the harmful act?

UAE civil law does not presently create a separate general doctrine of "autonomous AI network liability." The problem is instead analysed through existing principles of harmful acts, causation, multiple tortfeasors, agency, vicarious liability, product/service responsibility, contractual obligations, data protection, and evidence.

The current Federal Decree-Law No. 25 of 2025 promulgating the Civil Transactions Law, effective from 1 June 2026, is particularly important because Article 253 expressly addresses situations where multiple persons are responsible for the same harm. It allows liability to be allocated according to each person's share and permits the court, depending on the circumstances, to impose equal or joint-and-several liability. It also allows reduction of compensation where the injured party contributed to the harm. (UAE Legislation)

2. What Is an Autonomous AI Network?

An autonomous AI network is more complicated than a single AI application.

A simplified structure may be:

Developer

Foundation/AI model

Data provider

Cloud infrastructure

Integrator

Autonomous software/robot

Operating company

End user

The system may continuously:

collect information;

analyse data;

make predictions;

select an action;

execute the action;

learn from feedback;

interact with other software;

trigger physical consequences.

Therefore, a harmful outcome can emerge from the interaction of multiple systems rather than from one identifiable human decision.

3. Examples of Multi-Entity AI Harm

Example 1 — Autonomous vehicle

An autonomous vehicle causes an accident.

Potentially relevant entities:

AI developer;

vehicle manufacturer;

sensor manufacturer;

mapping-data provider;

software integrator;

fleet operator;

maintenance provider;

human safety supervisor.

Example 2 — AI financial system

An autonomous trading system makes erroneous transactions.

Potentially relevant entities:

algorithm developer;

financial institution;

data provider;

cloud provider;

system integrator;

trader/supervisor.

Example 3 — AI medical system

An AI diagnostic system produces an incorrect recommendation.

Potential actors may include:

AI developer;

hospital;

medical practitioner;

data supplier;

software integrator;

equipment manufacturer.

Example 4 — Autonomous industrial robot

A robot injures an employee.

Potentially relevant:

robot manufacturer;

AI developer;

industrial operator;

maintenance contractor;

software provider.

4. UAE Legal Framework

The relevant legal framework is not contained in one AI-liability statute.

Instead, several areas may interact.

Principal areas include:

Civil Transactions Law

Product and contractual liability

Medical Liability Law, where healthcare is involved

Consumer Protection Law

Personal Data Protection Law

Electronic Transactions and Trust Services Law

Commercial Companies Law

Insurance legislation

Cybercrime legislation

DIFC Digital Economy Court framework

applicable sector-specific regulations.

The UAE's new Civil Transactions Law describes itself as a comprehensive framework governing civil rights and obligations and modernises several areas of civil liability and contracts. (UAE Legislation)

5. Fundamental Principle — AI Has No Separate Civil Personality

An autonomous AI system is not, merely because it makes autonomous decisions, automatically treated as a separate legal person capable of bearing civil liability.

The relevant legal persons remain, depending on the circumstances:

developer;

manufacturer;

operator;

owner;

employer;

service provider;

data controller/processor;

contracting party;

insurer;

other responsible persons.

Therefore:

Autonomy of the machine does not automatically transfer liability from humans and legal entities to the machine.

The court must identify the legal relationship between the system and the persons/entities behind it.

6. Article 253 — Multiple Responsible Persons

Article 253 of the current Civil Transactions Law is particularly important.

It provides that:

where multiple persons are responsible for the same harm, each may be liable in proportion to their share.

The court may also determine that they are:

equally liable; or

jointly and severally liable,

depending on the circumstances.

The provision also allows compensation to be reduced or denied where the injured party contributed to causing or aggravating the damage. (UAE Legislation)

This provision provides a natural statutory foundation for multi-entity AI liability.

7. Why Article 253 Is Important for AI

Suppose an autonomous delivery robot injures a pedestrian.

The evidence establishes:

developer fault: 30%;

manufacturer fault: 20%;

integrator fault: 30%;

operator fault: 20%.

The court may consider allocating responsibility according to the respective contribution.

Alternatively, depending upon the legal relationship and circumstances, the court may impose joint and several liability, leaving the responsible entities to resolve contribution between themselves.

Thus, the law does not necessarily require the victim to identify a single "AI culprit."

8. Causation Is the Central Problem

The claimant must still establish a causal connection.

The chain may look like:

Defective training data

AI model produces erroneous output

Integrator fails to implement safety constraint

Operator deploys system

Autonomous system takes harmful action

Damage

The court must determine which links are legally significant.

This makes AI disputes different from conventional negligence claims.

9. Direct and Indirect Harm

UAE civil law historically distinguishes between direct action and indirect causation.

This distinction remains important when an AI system creates a chain of events.

A person who directly operates a dangerous machine may have a different liability position from:

a remote software developer;

a cloud provider;

a data supplier.

The legal question is not simply:

"Who created the AI?"

It is:

Whose legally relevant act or omission caused the damage?

The DIFC Courts, when discussing UAE Civil Code principles, have reproduced the former Articles 282–285 concerning harm, direct/indirect causation and deception. (DIFC Courts)

10. Developer Liability

An AI developer may potentially be responsible where the harm results from:

defective design;

inadequate safeguards;

foreseeable misuse;

failure to correct known defects;

inadequate testing;

unsafe model architecture;

failure to communicate known limitations.

But development alone does not automatically create liability.

The claimant must connect the developer's conduct to the damage.

11. Operator Liability

The operator may have the strongest factual connection with the harmful event.

For example, the operator may have:

ignored system warnings;

disabled safety mechanisms;

used the system outside its intended purpose;

failed to update software;

failed to maintain hardware;

failed to supervise an autonomous system.

Therefore, autonomous decision-making does not necessarily excuse the human or corporate operator.

12. Manufacturer Liability

Where AI operates through physical equipment, liability may involve the manufacturer.

Examples:

defective autonomous vehicle;

defective industrial robot;

defective drone;

defective medical device.

The manufacturer may potentially face liability for defects in:

hardware;

embedded software;

safety controls;

sensor systems.

However, software supplied by a separate entity may create a multi-party causation question.

13. AI Integrator Liability

The integrator occupies a particularly important position.

The integrator may combine:

AI model;

hardware;

data;

APIs;

cloud infrastructure;

sensors;

business processes.

The individual components may all be functioning properly, while the integration itself creates the defect.

For example:

AI model works correctly in isolation + sensor works correctly in isolation + software works correctly in isolation → integration causes unsafe autonomous action.

The integrator may therefore become an important defendant.

14. Data Provider Liability

AI systems depend heavily on data.

A data provider may potentially contribute to harm through:

inaccurate data;

corrupted data;

incomplete data;

outdated data;

unlawful data collection;

improperly labelled training data.

The Personal Data Protection Law is especially relevant where personal information is processed.

Federal Decree-Law No. 45 of 2021 requires appropriate technical and organisational measures to protect personal data and requires impact assessments for certain high-risk processing involving modern technologies. (UAE Legislation)

15. Cloud Provider Liability

A cloud provider may supply infrastructure rather than make the AI decision.

Therefore, liability cannot simply be imposed because:

"The AI was hosted on its servers."

A stronger case may arise if the provider:

breached a contractual security obligation;

failed to implement agreed safeguards;

materially interfered with the system;

negligently caused data corruption;

failed to follow a contractual service level.

The legal analysis therefore depends heavily upon contract + technical causation + actual fault.

16. Platform Liability

A platform may occupy a different position.

Consider an AI marketplace connecting:

autonomous agents;

consumers;

financial institutions;

service providers.

Potential claims may concern:

platform design;

negligent moderation;

misleading information;

security failures;

contractual obligations;

consumer protection.

Again, platform status alone should not automatically establish liability.

17. Employer/Vicarious Liability

Where an employee operates or supervises the autonomous system, employer liability may arise under ordinary principles of employer responsibility.

Example:

An employee negligently configures an autonomous warehouse robot.

The employer may face liability depending upon:

employment relationship;

scope of employment;

applicable statutory provisions;

causal connection.

Autonomy of the software does not eliminate traditional employer responsibility.

18. Agency and AI

Agency becomes particularly complicated when AI acts through an authorised human or corporate system.

The question becomes:

Was the AI merely a tool through which the principal acted, or did another entity independently cause the harmful conduct?

A recent DIFC Court of Appeal decision is useful here.

Khaled Salem Musabeh Humad Al Mheiri v John Cameron [2025] DIFC CA 008

The Court considered whether a contracting party could be responsible for deceitful representations made by another person, including an agent acting with authority, under the former UAE Civil Code provisions.

The Court noted that excluding liability for an agent's deceitful representations merely because the principal lacked actual knowledge could leave innocent parties vulnerable, although the precise construction of the relevant provisions was left for reconsideration. (DIFC Courts)

Relevance to autonomous AI

The case is not an AI case, but its reasoning provides an important analogy:

Principal → authorised intermediary → third-party harm

can resemble:

AI owner/operator → autonomous AI agent → third-party harm.

It demonstrates why the legal relationship between the principal and the intermediary must be carefully analysed.

19. Multi-Entity Liability and Corporate Groups

An AI network may be operated by a corporate group consisting of:

Parent company;

AI subsidiary;

cloud subsidiary;

data subsidiary;

operating company.

The existence of a corporate group does not automatically mean that all companies are liable.

Each company generally retains its separate legal personality.

The claimant must establish a proper legal basis for imposing liability on each entity.

20. Normand v Nathaniel [2024] DIFC SCT 125

This principle is illustrated by Normand v Nathaniel [2024] DIFC SCT 125.

The DIFC Court discussed the corporate-veil doctrine and explained that piercing the veil is an exceptional mechanism intended to prevent misuse or abuse of corporate form.

The Court rejected an attempt to use the doctrine merely to transfer a subsidiary's rights or liabilities to another corporate entity without a proper legal basis. (DIFC Courts)

Relevance

This is highly important for AI networks.

A claimant cannot simply argue:

"All companies belong to the same AI group, therefore all companies are liable."

Separate corporate personality remains relevant.

21. Multi-Entity Liability and Joinder

AI disputes may involve many potentially responsible parties.

A court therefore needs mechanisms for joining:

developer;

manufacturer;

operator;

data provider;

integrator;

service provider.

Mohamad Khalil Yakzan v Cyber Knight Technologies FZ-LLC [2024] DIFC CFI 077

The DIFC Court granted an application to add BlueCat Networks, Inc. and Knights for Telecom and Information Technology Company as additional defendants. (DIFC Courts)

The case was not an autonomous-AI liability case, but it illustrates an important procedural principle:

Technology disputes may require multiple entities to be brought before the court where their roles are potentially relevant to the dispute.

22. Evidence in Autonomous AI Litigation

Evidence is often the hardest part.

An autonomous AI system may generate:

logs;

model outputs;

decision trees;

sensor data;

API calls;

database records;

training data;

system prompts;

audit records;

software versions;

timestamps.

The claimant may not know which entity caused the error.

Therefore, courts may need to consider:

Technical evidence

source code;

model architecture;

system logs;

version histories.

Documentary evidence

contracts;

specifications;

risk assessments;

testing reports.

Expert evidence

AI engineering;

cybersecurity;

software architecture;

causation.

23. Black-Box AI and Burden of Proof

A major challenge is the black-box problem.

Suppose:

Input A → AI → harmful decision.

But nobody can easily explain why the AI produced that result.

The claimant may know:

the input;

the output;

the damage.

But may not know:

model parameters;

training process;

internal decision pathway.

This can make conventional negligence litigation difficult.

A court may therefore need expert evidence and careful consideration of which entity possessed the relevant technical information.

24. Data Protection and AI Liability

Federal Decree-Law No. 45 of 2021 is important where autonomous AI processes personal data.

The law requires security measures proportionate to processing risks and provides for impact assessment in certain high-risk processing operations involving modern technologies. (UAE Legislation)

This creates a potential liability chain:

Data controller

AI processor

Cloud provider

AI model

Automated decision

Data subject harm

The parties' respective contractual and statutory responsibilities must be distinguished.

25. Autonomous AI and Moral Damage

AI harm may include:

Material damage

financial loss;

property damage;

lost profits;

medical expenses.

Moral damage

reputational harm;

dignity injury;

privacy harm;

psychological suffering.

Article 254 of the new Civil Transactions Law expressly recognises moral harm, including infringement of freedom, honour, reputation, social standing and financial status. (UAE Legislation)

Therefore, an autonomous AI system causing reputational injury could potentially generate both:

material compensation + moral compensation.

26. Case Law 1 — Al Mheiri v Cameron [2025] DIFC CA 008

Issue

Liability for representations made through an agent.

Principle

The Court considered whether a contracting party may be liable for deceitful representations made by an authorised agent under UAE law.

Relevance to autonomous AI

An autonomous AI system can be viewed, depending on its legal structure, as an instrument through which an entity performs contractual or operational functions.

The case therefore provides an analogy for:

principal → agent → representation → third-party harm. (DIFC Courts)

Qualification: This is a DIFC case and concerned human agency/deceit, not autonomous AI.

27. Case Law 2 — Muzoon Holding LLC v Arif Naqvi [2022] DIFC CFI 080

The case concerned allegations of deceit and inducing breach of a legal right under the DIFC Law of Obligations.

The Court considered whether the defendant could be held personally responsible for conduct associated with an investment structure involving other entities. (DIFC Courts)

Relevance

The case demonstrates the importance of distinguishing:

the entity that actually received the benefit;

the person/entity that committed the relevant conduct;

the person alleged to have induced the conduct.

This is directly relevant when an AI network contains several independent entities.

28. Case Law 3 — Yakzan v Cyber Knight Technologies [2024] DIFC CFI 077

The Court permitted additional technology companies to be added as defendants.

Principle

Where multiple entities may be connected to the technological conduct underlying a claim, procedural rules can allow those entities to be brought into the same proceedings. (DIFC Courts)

AI relevance

In an autonomous AI claim, the parties may include:

software company;

network company;

AI provider;

system integrator.

Joinder can allow the court to examine the complete causal chain.

29. Case Law 4 — Normand v Nathaniel [2024] DIFC SCT 125

Principle

Corporate personality remains important.

The Court explained that piercing the corporate veil is a limited doctrine aimed at preventing misuse or abuse of the corporate form. (DIFC Courts)

AI relevance

A claimant cannot simply impose liability on every company in an AI corporate group.

There must be a proper legal basis, such as:

direct harmful conduct;

contractual obligation;

agency;

vicarious liability;

statutory responsibility;

proven abuse of corporate personality.

30. Case Law 5 — Lals Holdings Ltd v Emirates Insurance Co [2024] DIFC CA 002

The case involved multiple corporate claimants, an insurer and an insurance broker.

The claim included allegations that the broker had failed to arrange appropriate insurance and had breached contractual and tortious duties. The DIFC Court of Appeal dismissed the appeal. (DIFC Courts)

AI relevance

It illustrates a multi-entity responsibility structure:

customer → broker → insurer

rather than a single bilateral relationship.

The analogy is useful for autonomous AI:

customer → integrator → AI provider → insurer

where different entities may have different contractual and tortious obligations.

31. Case Law 6 — Stelian Gheorghe v BSA Ahmad Bin Hezeem & Associates [2025] DIFC CFI 045

This case directly involved AI-generated legal material.

The defendants contended that some evidence and the claim form may have been generated partly using AI. The Court observed that errors in legal material were problematic and ultimately stayed the proceedings in favour of arbitration. (DIFC Courts)

Importance for AI liability

The case demonstrates that:

AI-generated material does not automatically become reliable merely because it is technologically generated;

human legal professionals remain responsible for material placed before the court;

AI involvement does not itself transfer legal responsibility to the software.

This is an important principle for autonomous AI networks:

Use of an autonomous or generative system does not automatically eliminate the legal responsibility of the human or entity deploying it.

32. Case Law 7 — Krystal Financial Consultants LLC v Nextgen Robopark Investment LLC [2025] DIFC CA 007

This case involved a dispute between entities connected with an investment/technology venture.

The DIFC Court of Appeal judgment of 16 June 2026 addressed the appeal from the first-instance proceedings. (DIFC Courts)

Relevance

Although not a decided autonomous-AI tort case, it illustrates why the legal identity and contractual relationship of the entities involved in technology-related ventures must be separately analysed.

33. Case Law 8 — Emirates NBD Bank v Almakhawi [2026] DIFC CFI 039

The DIFC Court considered claims involving multiple defendants and UAE civil-law principles concerning harmful acts, deception and responsibility.

The judgment reproduced former Civil Code Articles 282–285, including:

liability for harm;

direct and consequential harm;

direct versus indirect actors;

liability for deception. (DIFC Courts)

AI relevance

These principles provide a conceptual framework for analysing:

AI developer → integrator → operator → autonomous action → harm.

The critical issue remains causation and each entity's legally relevant contribution.

34. Direct AI Authority — DIFC Digital Economy Court

The UAE's most important institutional development is the DIFC Digital Economy Court (DEC).

Part 58 of the DIFC Courts Rules expressly provides that the DEC can hear claims involving:

artificial intelligence;

devices dependent on or controlled by AI;

complex databases;

digital assets;

blockchain;

automatic dispute resolution;

DAOs;

DeFi;

DApps;

digital signatures;

robotics;

cyber-physical systems;

unmanned aerial vehicles;

3D printing;

AI-related insurance claims. (DIFC Courts)

This is highly relevant to autonomous AI networks because Part 58 expressly covers both AI and physical cyber-physical systems.

35. AI Does Not Become a Defendant Merely Because It Is Autonomous

The DEC framework is important precisely because it treats AI as the subject matter of disputes, not necessarily as an independent legal person.

Part 58 allows claims concerning AI-controlled devices and systems, but it does not establish a general rule that AI itself possesses separate legal personality.

Therefore:

Technological autonomy ≠ legal personality.

The legal analysis remains focused on the humans and entities responsible under applicable law.

36. Multi-Entity AI Liability Model

A useful model is:

Level 1 — Developer

Question:

Did defective design or coding cause the harm?

Level 2 — Data provider

Question:

Did defective or unlawfully supplied data materially cause the harm?

Level 3 — Integrator

Question:

Did the integration create the risk?

Level 4 — Infrastructure provider

Question:

Did cloud/network failure cause the damage?

Level 5 — Operator

Question:

Was deployment negligent?

Level 6 — Supervisor

Question:

Was human oversight inadequate?

Level 7 — Owner

Question:

Did ownership or control trigger a statutory liability?

Level 8 — Insurer

Question:

Is there contractual insurance coverage?

37. Allocation of Liability

The court can conceptually construct:

Damage

Causal contribution of Entity A

Causal contribution of Entity B

Causal contribution of Entity C

Causal contribution of Entity D

Article 253 allocation

The exact outcome depends on:

applicable law;

contractual arrangements;

evidence;

causation;

degree of fault;

statutory liability;

contribution by the injured person.

38. Joint and Several Liability

This is especially important.

Suppose:

developer = 25%;

integrator = 25%;

operator = 50%.

Article 253 allows the court, depending on the circumstances, to impose proportional responsibility or determine equal/joint-and-several liability. (UAE Legislation)

Joint-and-several liability can be particularly important to victims because otherwise the victim may be forced to identify precisely which entity caused which portion of the AI failure.

39. Contribution Between Defendants

Where one defendant pays more than its ultimate share, questions of contribution may arise between the responsible parties.

For example:

Bank pays the injured party → Bank establishes that software provider was also responsible → Bank seeks contribution from software provider.

This prevents the victim from having to resolve all internal allocation disputes before obtaining compensation.

40. Contractual Allocation of AI Risk

AI contracts increasingly contain:

indemnities;

limitation clauses;

warranties;

service-level agreements;

audit rights;

cybersecurity obligations;

data warranties;

model-performance obligations.

These provisions can determine which entity ultimately bears the economic burden.

However, contractual allocation does not necessarily eliminate statutory liability toward third parties.

Example

Developer and operator agree:

"Operator assumes all AI-related risk."

If the AI injures a third party, the agreement may affect recourse between developer and operator, but it does not automatically determine the third party's statutory claim.

41. Insurance

Autonomous AI networks may require:

professional indemnity insurance;

cyber insurance;

product liability insurance;

technology errors-and-omissions insurance;

autonomous-vehicle insurance;

directors' and officers' insurance.

The insurer may itself become involved in litigation concerning:

coverage;

exclusions;

causation;

misrepresentation;

contribution between insurers.

The DIFC Digital Economy Court expressly includes insurance claims connected with AI and other digital-economy technologies within its jurisdictional framework. (DIFC Courts)

42. AI Liability and Consumer Protection

Where an autonomous AI service is supplied to consumers, additional issues may arise:

defective service;

misleading representations;

unfair terms;

inadequate warnings;

unsafe products;

privacy violations.

The consumer may have a claim against the entity that supplied the service even if the underlying AI model was developed by another company.

The supplier may then seek contractual contribution from the developer.

43. AI Liability and Privacy

Autonomous AI networks can continuously process personal information.

Potential harms include:

unauthorised disclosure;

profiling;

incorrect automated decisions;

data loss;

identity misuse;

unlawful processing.

The UAE Personal Data Protection Law requires appropriate security measures and, in specified high-risk circumstances, a data-protection impact assessment before processing using modern technologies. (UAE Legislation)

Thus:

AI liability + data protection liability

may arise from the same event.

44. AI Liability and Cybersecurity

Suppose an attacker manipulates an autonomous AI system.

Potential defendants might include:

software provider;

cybersecurity contractor;

cloud provider;

operator.

The court must distinguish:

external cyberattack

from

failure to implement reasonable security safeguards.

An external hacker does not automatically eliminate the liability of an entity that negligently created or maintained a foreseeable vulnerability.

45. The "Human-in-the-Loop" Problem

Many autonomous systems claim to retain human oversight.

But the court may ask:

Was the human actually capable of intervening?

Did the human receive the warning?

Was sufficient time available?

Did the system obscure the warning?

Was the human trained?

Did the employer provide adequate procedures?

Therefore, merely stating:

"A human was technically responsible"

may not resolve liability.

The factual effectiveness of human supervision matters.

46. The "Human-on-the-Loop" Problem

Some systems operate autonomously while humans monitor them.

If the system acts rapidly, human intervention may be practically impossible.

This raises a fundamental question:

Can an entity rely on nominal human supervision when the system is designed to operate faster than a human can intervene?

This will likely become increasingly important in future UAE litigation involving autonomous vehicles, robotics and financial systems.

47. Standard of Care for AI Developers

In the absence of a dedicated AI civil-liability statute, courts may examine:

industry standards;

contractual standards;

regulatory requirements;

foreseeable risks;

testing practices;

security standards;

warnings;

system documentation;

known defects.

The relevant question is not simply:

"Did the AI make a mistake?"

Instead:

Was the conduct of the legally responsible entity unreasonable or otherwise legally actionable in light of the circumstances?

48. Foreseeability

Foreseeability becomes particularly important.

If an AI developer knew that:

the system could hallucinate;

the model could misclassify objects;

a safety constraint could fail;

the system was vulnerable to adversarial input;

and nevertheless deployed the system without adequate safeguards, the foreseeability analysis may become important.

Conversely, genuinely unforeseeable behaviour may complicate causation and fault.

49. Autonomous AI and Product Liability

When AI is embedded in a physical product, several liability regimes can overlap.

For example:

Autonomous car

→ vehicle defect
→ software defect
→ sensor defect
→ data defect
→ integration defect
→ operator negligence.

This creates a classic multi-entity liability problem.

The claimant may need to establish whether the defect originated in:

hardware;

software;

data;

integration;

maintenance;

deployment.

50. Autonomous AI and Professional Liability

Professionals using AI cannot necessarily transfer responsibility to the AI supplier.

For example:

A doctor uses an AI diagnostic system.

The AI recommends treatment X.

The doctor follows it.

The patient suffers harm.

Potential questions include:

Was the doctor required to independently verify the recommendation?

Did the hospital approve the system?

Was the AI properly validated?

Was the software supplied with adequate warnings?

Was the doctor's reliance reasonable?

Did the AI provider make misleading claims?

The final allocation may involve several entities.

51. AI and Evidence Preservation

AI cases require preservation of:

model version;

training data;

system logs;

prompts;

outputs;

API calls;

configuration settings;

software updates;

human intervention records.

Without these records, establishing causation becomes extremely difficult.

Therefore, auditability is not merely a technical feature; it can become legally significant evidence.

52. Practical Hypothetical

Facts

A UAE logistics company deploys an autonomous warehouse robot.

The robot:

receives navigation software from Company A;

uses sensors manufactured by Company B;

uses an AI model from Company C;

operates on cloud infrastructure from Company D;

is integrated by Company E;

is operated by Company F.

The robot injures an employee.

Possible analysis

Company A: software defect?

Company B: defective sensor?

Company C: defective AI model?

Company D: cloud failure?

Company E: integration error?

Company F: negligent deployment or supervision?

The court would then analyse:

duty;

breach/fault;

causation;

damage;

statutory responsibility;

contractual allocation;

Article 253 multi-person liability.

53. Possible Remedies

Depending upon the claim, remedies may include:

Compensation

For:

property damage;

bodily injury;

financial loss;

lost profits;

moral damage.

Injunctions

To prevent continuing harmful AI activity.

Specific corrective measures

For example:

disabling defective functionality;

correcting data;

restoring access.

Contractual remedies

termination;

damages;

indemnification.

Data remedies

deletion;

correction;

restriction of processing where legally available.

54. Important Distinction — AI Error vs Legal Fault

This is a crucial examination point.

An AI error does not automatically equal civil liability.

There must be a legally recognised basis for liability.

Similarly:

Human involvement does not automatically eliminate AI-related liability.

The court must determine:

Who owed the duty?
What duty was breached?
What caused the damage?
What evidence proves causation?
How should responsibility be allocated?

55. Six+ Important Cases — Revision Table

CaseMain doctrineAI-network relevance
Al Mheiri v Cameron [2025] DIFC CA 008Agency/deceitPrincipal and intermediary responsibility
Muzoon Holding v Naqvi [2022] DIFC CFI 080Deceit/inducing breachSeparating entity and individual responsibility
Yakzan v Cyber Knight [2024] DIFC CFI 077Joinder of technology entitiesMultiple defendants in technology disputes
Normand v Nathaniel [2024] DIFC SCT 125Corporate veilSeparate liability of AI group companies
Lals Holdings v Emirates Insurance [2024] DIFC CA 002Multi-party contractual/tortious dutiesBroker–insurer–customer allocation
Stelian Gheorghe v BSA [2025] DIFC CFI 045AI-generated legal materialHuman responsibility despite AI use
Emirates NBD v Almakhawi [2026] DIFC CFI 039Harm, causation, deceptionMultiple responsible actors
Krystal Financial Consultants v Nextgen Robopark [2025] DIFC CA 007Technology-related corporate disputeMulti-entity technology structure

These are analogical and foundational authorities, not a collection of decided UAE cases specifically imposing tort liability on autonomous AI networks. As of September 2026, the UAE's reported jurisprudence has not yet produced a mature body of appellate decisions squarely deciding a catastrophic autonomous-AI multi-entity liability case. The DIFC's Part 58 framework is consequently particularly significant for future disputes. (DIFC Courts)

56. Role of the DIFC Digital Economy Court

The DIFC has expressly anticipated this class of dispute.

Part 58 identifies claims involving:

AI;

AI-controlled devices;

robotics;

autonomous systems;

complex databases;

cyber-physical systems;

UAVs;

automatic dispute resolution;

AI-related insurance.

It also permits the Digital Economy Court to use sophisticated digital procedures and AI-driven smart forms. (DIFC Courts)

This is significant because autonomous AI disputes may require courts to understand not only traditional contracts and torts but also:

algorithms;

data architecture;

machine-learning systems;

cloud infrastructure;

digital evidence;

robotics.

57. Future Direction of UAE AI Liability

The likely development of UAE private law will revolve around several questions:

1. Explainability

Who must explain why the autonomous system acted as it did?

2. Auditability

Who must preserve technical records?

3. Allocation

How should liability be divided between developer, integrator and operator?

4. Insurance

Who must insure autonomous-system risks?

5. Contract

How far can sophisticated parties allocate AI risk contractually?

6. Consumer protection

Can suppliers contract out of responsibility toward consumers?

7. Product liability

Should defective AI software be treated like a defective product?

8. Corporate groups

When, if ever, should related AI companies share responsibility?

58. Exam-Oriented Legal Formula

Multi-Entity Autonomous AI Liability

AI System

Multiple Legal Entities

Duty / Contract / Statutory Obligation

Fault or Legally Relevant Conduct

Causation

Damage

Article 253 Multi-Person Liability

Proportional or Joint-and-Several Liability

Contribution Between Responsible Entities

59. Conclusion

UAE civil law presently approaches multi-entity liability in autonomous AI networks through existing principles rather than by treating AI as an independent legal person.

The most important current provision is Article 253 of the 2025 Civil Transactions Law, which expressly addresses situations where multiple persons are responsible for the same harm and permits proportional, equal or joint-and-several liability depending on the circumstances. (UAE Legislation)

The central legal challenge is therefore causal attribution:

Developer → data provider → cloud provider → integrator → operator → autonomous AI → harm

The court must identify which links in this chain constitute legally relevant conduct and how responsibility should be allocated.

The existing cases involving agency, corporate personality, technology companies, AI-generated legal material, deception, insurance and multi-party harm provide useful building blocks. Particularly important are Al Mheiri v Cameron, Yakzan v Cyber Knight, Normand v Nathaniel, Lals Holdings v Emirates Insurance, and Stelian Gheorghe v BSA. The DIFC Digital Economy Court's Part 58 is especially significant because it expressly covers AI, AI-controlled devices, robotics and cyber-physical systems. (DIFC Courts)

Core principle for examination:

Autonomous AI may perform the immediate operation, but UAE civil liability continues to be attributed to the legally responsible human or corporate actors through established rules of duty, causation, agency, harmful acts, contractual responsibility and multi-person liability.

LEAVE A COMMENT