Civil Law And Uae Smart City Infrastructure Liability .
Civil Law and UAE – Smart City Infrastructure Liability
1. Introduction
Smart city infrastructure liability concerns legal responsibility for harm caused by, or connected with, technologically advanced urban infrastructure.
A smart city may use:
- intelligent traffic lights;
- autonomous transport systems;
- smart parking;
- AI-based surveillance;
- connected electricity grids;
- smart water systems;
- IoT sensors;
- automated buildings;
- digital identity systems;
- public Wi-Fi and communication networks;
- blockchain-based municipal services;
- smart waste-management systems;
- automated emergency systems;
- AI-controlled infrastructure.
The legal question is simple:
If a smart infrastructure system causes harm, who is legally responsible?
Possible responsible parties can include:
- the government authority;
- infrastructure owner;
- operator;
- contractor;
- technology supplier;
- software developer;
- maintenance company;
- sensor manufacturer;
- data provider;
- system integrator;
- cybersecurity provider; or
- another person whose wrongful act caused the damage.
Under the current UAE Civil Transactions Law, Federal Decree by Law No. 25 of 2025, Article 271 provides a particularly relevant rule: a person controlling things requiring special care to prevent harm, or mechanical machinery, is liable for harm caused by those things or machinery, subject to the statutory exception for harm that could not be prevented and special legislation. Article 272 also allows preventive measures where danger is threatened.
2. Simple Meaning
Imagine a smart traffic intersection.
It contains:
Camera → AI software → traffic-control system → traffic lights
Suppose the system incorrectly keeps the traffic light green in two directions.
A collision occurs.
The legal investigation may ask:
- Was the infrastructure defective?
- Was the software defective?
- Was the sensor malfunctioning?
- Was the system incorrectly configured?
- Was maintenance neglected?
- Did the operator ignore warnings?
- Did a cyberattack cause the failure?
- Did a contractor install the system incorrectly?
- Did the government authority have a relevant legal duty?
- Who caused the actual damage?
This is the essence of smart-city infrastructure liability.
3. Basic Liability Formula
A useful examination formula is:
Duty/Responsibility + Wrongful Conduct + Damage + Causation = Possible Civil Liability
For infrastructure involving inherently dangerous or machinery-type systems, the special statutory rules may also become important.
4. Article 271 – Things Requiring Special Care and Machinery
Article 271 of the current Civil Transactions Law provides that whoever controls:
- things requiring special care to prevent harm; or
- mechanical machinery
is liable for harm caused by those things or machinery, subject to the statutory exception for harm that could not be prevented and special legal provisions.
This can be highly relevant to smart-city infrastructure.
Examples
Potentially relevant systems include:
- automated gates;
- elevators;
- robotic systems;
- autonomous transport;
- mechanical traffic infrastructure;
- industrial smart machinery;
- automated construction equipment.
The key concept is control.
The person controlling the system may be more legally significant than simply the person who owns the physical equipment.
5. Preventive Liability – Article 272
Smart-city liability is not only about compensation after an accident.
Article 272 allows a person threatened with harm arising from:
- a building;
- an animal;
- mechanical machinery; or
- things requiring special care
to demand appropriate preventive measures.
If the responsible person does not act within an appropriate period, court intervention may be sought. In urgent circumstances, necessary protective measures may be taken at the responsible person's expense, subject to the statutory requirements.
Smart-city example
A smart electrical-control system repeatedly overheats.
Residents identify the danger before a fire occurs.
The legal issue may therefore become:
Can the responsible party be required to correct the dangerous condition before actual damage occurs?
This is particularly important for smart infrastructure because continuous monitoring can identify risks before traditional physical damage happens.
6. Direct and Indirect Damage
Traditional UAE civil-law principles distinguish between direct and consequential/indirect harm.
The former Article 283 of the Civil Transactions Law provided that harm may be direct or by causation. For direct harm, compensation was required without an additional fault requirement; for consequential harm, wrongdoing, deliberate conduct, or an act leading to the harm was relevant. The Federal Supreme Court has expressly explained this distinction.
Smart-city example – direct
An automated machine physically strikes a pedestrian.
The machine directly causes the injury.
Smart-city example – consequential
A defective sensor provides incorrect data.
That data causes an automated traffic system to change signal timings.
The signal change causes an accident.
The court must examine the chain:
sensor → data → software → traffic signal → accident → injury
7. Causation in Smart Infrastructure
Causation can become particularly complicated because smart-city systems contain many interconnected components.
Consider:
Sensor
↓
Network
↓
Cloud platform
↓
AI algorithm
↓
Control centre
↓
Physical infrastructure
↓
Person suffers harm
If the system fails, several parties may argue:
“The problem was not caused by us.”
The court therefore needs to determine the legally relevant causal connection.
8. Human Error and Automated Systems
Automation does not eliminate human responsibility.
For example:
An AI traffic-management system warns an operator:
“Sensor malfunction detected.”
The operator ignores the warning.
An accident occurs.
The dispute may involve:
- software responsibility;
- operator negligence;
- maintenance responsibility;
- system-design responsibility;
- causation.
Therefore:
Automation can change the form of the decision-making process without necessarily eliminating human responsibility.
9. Software Defects
A smart-city system can fail because of software.
Examples:
- incorrect algorithm;
- coding error;
- faulty update;
- incompatible software;
- incorrect configuration;
- failure to patch;
- defective AI model;
- incorrect sensor interpretation.
The legal claim may potentially be based on:
- contract;
- tort/civil wrongdoing;
- product liability;
- professional negligence;
- statutory responsibility.
The correct legal classification depends on the relationship between the parties and applicable legislation.
10. Hardware and Sensor Failure
Smart infrastructure depends heavily on sensors.
Examples:
- temperature sensors;
- traffic cameras;
- pressure sensors;
- pollution sensors;
- water-level sensors;
- electricity meters;
- biometric devices.
If a sensor produces incorrect information, the consequences may be physical.
Example
A flood sensor incorrectly reports:
“Water level normal.”
The automated drainage system therefore does not activate.
Flooding damages nearby property.
Possible defendants may include:
- sensor manufacturer;
- maintenance contractor;
- system operator;
- infrastructure owner.
But liability must be established against the particular party under the applicable legal rules.
11. Cyberattack and Smart Infrastructure
Cybersecurity creates a difficult liability problem.
Suppose hackers enter a smart-city traffic system and cause signals to malfunction.
Potential questions include:
- Was there a cyberattack?
- Could it reasonably have been prevented?
- Was cybersecurity adequate?
- Did the operator ignore known vulnerabilities?
- Was software properly updated?
- Did a third-party supplier create the vulnerability?
- Was the attack an external cause?
- Did the system operator have a contractual or statutory duty to maintain security?
The UAE's general civil-liability principles may therefore interact with:
- cybersecurity legislation;
- data-protection legislation;
- electronic-transactions rules;
- sector-specific regulation;
- contractual obligations.
12. Public Authority Liability
A smart city frequently involves government or municipal authorities.
This creates an important distinction between:
Public-law responsibility
The authority's statutory/regulatory duties.
Civil liability
Compensation for legally recognised private harm.
The existence of public authority involvement does not automatically answer the civil-liability question.
A court may need to determine:
- what legal duty existed;
- whether the authority breached it;
- whether immunity or special statutory provisions apply;
- whether the claimant suffered compensable damage;
- whether the authority's conduct caused the damage.
13. Contractor Liability
Smart-city projects are often delivered through multiple contractors.
For example:
Government authority
↓
Main contractor
↓
Technology integrator
↓
Software developer
↓
Sensor supplier
↓
Maintenance provider
A failure may involve several participants.
The contractual allocation of responsibilities therefore becomes extremely important.
14. Contractual vs Tortious Liability
A UAE Supreme Court judgment, Commercial Cassation No. 941 of 2019, explained that where the injured party and alleged wrongdoer are connected by a contractual relationship, the court should not simply apply tort liability to a contractual compensation dispute unless circumstances such as a crime, fraud or sufficiently serious wrongdoing satisfy the requirements of tort liability. The judgment also reiterated the importance of fault, damage and causation.
Smart-city example
A municipality hires Company A to maintain smart traffic lights.
The system fails.
The municipality sues Company A.
The court must first examine:
What did the maintenance contract require?
This may be principally a contractual dispute rather than simply a tort claim.
15. Case Law 1 – Federal Supreme Court, Civil Judgment No. 99/1995
This UAE Federal Supreme Court decision is important for the distinction between direct harm and harm by causation.
The Court explained that direct harmful conduct can create liability without requiring proof of additional intent or negligence, while consequential harm requires the additional conditions identified by the Civil Transactions Law. It also discussed external causes such as force majeure, unexpected events, third-party conduct and conduct of the injured person.
Smart-city application
If an automated machine directly damages property, the direct-harm principle may become relevant.
If a defective component indirectly causes a later accident, the court may undertake a more detailed causation analysis.
Principle
The structure of liability depends partly on how the infrastructure caused the damage.
16. Case Law 2 – UAE Federal Supreme Court, Commercial Cassation No. 941/2019
This decision is especially useful for distinguishing contractual and tortious responsibility.
The Court stated that where a contractual relationship exists, tort principles should not simply replace contractual rules unless the circumstances satisfy the applicable basis for tort liability, such as crime, fraud or serious wrongdoing. It also stated that fault, damage and causation are fundamental elements of liability.
Smart-city application
If a smart-city operator breaches a maintenance contract, the claimant should first identify the contractual obligation.
Principle
The legal source of the duty matters.
17. Case Law 3 – Graciela Ltd v Giacobbe [2014] DIFC CFI 027
This is particularly relevant to technology infrastructure.
The defendant was alleged to have sabotaged the claimant's IT system.
The DIFC Court found that deliberate interference with the IT system constituted wrongful interference with property under the DIFC Law of Obligations and awarded damages for resulting losses.
The judgment expressly considered costs relating to:
- restoration of the IT system;
- network rebuilding;
- contractors; and
- other losses.
Smart-city application
A smart city depends on interconnected IT systems.
If someone intentionally interferes with a municipal digital infrastructure system, the infrastructure itself can be the subject of legally protected interests.
Principle
Digital infrastructure can constitute legally protected property or interests, and unlawful interference can generate damages.
18. Case Law 4 – Aegis Resources DMCC v Union Bank of India [2020] DIFC CFI 004
This case concerned negligence and contributory negligence.
The DIFC Court considered whether the claimant's own negligent conduct contributed to its losses and discussed the reduction of liability according to the claimant's contribution under the DIFC Law of Obligations.
Smart-city application
Suppose:
- a smart-city operator fails to maintain cybersecurity; but
- a user knowingly ignores repeated security warnings.
The court may have to examine whether the claimant's own conduct contributed to the damage, depending on the applicable legal regime.
Principle
The conduct of the injured party can be relevant to the amount of recoverable loss.
19. Case Law 5 – BAM Higgs & Hill LLC v Affan Innovative Structures LLC [2021] DIFC CFI 106
The DIFC Court considered the relationship between:
- duty;
- breach;
- damage; and
- causation.
The judgment emphasised that actionable loss is necessary before a negligence claim can succeed. The case has also generated subsequent procedural decisions in 2026, including an order refusing permission to appeal.
Smart-city application
A claimant cannot simply say:
“The smart system was defective.”
The claimant must establish legally actionable damage and the connection between the defect and that damage.
Principle
Technical failure does not automatically equal compensable legal damage.
20. Case Law 6 – Nael v Niamh Bank [2024] DIFC CA 015
This case concerned guarantees connected with a large public infrastructure project.
The underlying construction contract involved infrastructure works for a large public project, and the employer terminated the contractor and made demands under guarantees following the contractor's insolvency.
Although this is not a smart-city tort case, it is useful for understanding the contractual architecture of large infrastructure projects.
Smart-city application
Large smart-city projects similarly involve:
- contractors;
- employers;
- guarantees;
- performance obligations;
- termination;
- insolvency risk.
Principle
Infrastructure liability can involve multiple interconnected contractual relationships, not merely a simple owner-versus-injured-person claim.
21. Case Law 7 – Maalik Investments Ltd v Mabili Interior Decoration Design LLC [2022] DIFC SCT 117
This dispute involved fit-out works and alleged negligence causing damage to a third-party office.
The court considered allegations concerning:
- delay;
- approvals;
- performance of works; and
- damage caused to another office through alleged negligence.
Smart-city application
Smart-city projects also involve complex construction and installation phases.
A defect can originate during:
design → installation → testing → commissioning → operation
Principle
Infrastructure liability can arise from defective implementation before the smart system even becomes operational.
22. Case Law 8 – Latha v Lavni [2022] DIFC SCT 022
This case concerned a software programme that allegedly failed to perform its required purpose.
The claimant argued that the software developer failed to develop and implement the software according to the agreement and timeline and that repeated notifications of deficiencies were not adequately addressed.
Smart-city application
This is highly relevant to smart infrastructure because smart-city projects frequently depend upon software development contracts.
Principle
A software failure can create contractual liability where the supplier does not deliver the agreed functionality.
23. Case-Law Table
| Case | Issue | Smart-city lesson |
|---|---|---|
| Federal Supreme Court, Civil Judgment No. 99/1995 | Direct/consequential harm | Identify how infrastructure caused damage |
| Federal Supreme Court, Commercial Cassation No. 941/2019 | Contract vs tort | Identify the legal source of the duty |
| Graciela v Giacobbe [2014] | IT-system sabotage | Digital infrastructure can be legally protected |
| Aegis Resources v Union Bank [2020] | Negligence/contributory negligence | Claimant's own conduct can matter |
| BAM Higgs & Hill v Affan [2021] | Duty, damage and causation | Technical failure requires actionable loss |
| Nael v Niamh Bank [2024] | Public infrastructure contracts | Large infrastructure involves layered contracts |
| Maalik Investments v Mabili [2022] | Construction/installation damage | Liability can arise during implementation |
| Latha v Lavni [2022] | Software failure | Software obligations can generate contractual liability |
Important: The DIFC cases are DIFC authorities and should not be treated as binding precedents of the ordinary mainland UAE courts.
24. Who Can Be Liable?
A. Infrastructure owner
The owner may have responsibilities concerning:
- safety;
- maintenance;
- operation;
- monitoring.
Article 271's control-based approach is important where the infrastructure falls within its scope.
B. Operator
The operator may be responsible for:
- incorrect operation;
- failure to respond to alerts;
- failure to shut down dangerous systems;
- inadequate supervision.
C. Contractor
A contractor may be liable for:
- defective installation;
- poor construction;
- failure to follow specifications;
- negligent implementation.
D. Software developer
Potential responsibility may arise from:
- defective software;
- failure to meet specifications;
- negligent coding;
- failure to correct known defects.
E. Manufacturer
A manufacturer may face liability under applicable product-liability rules where a defective product causes damage.
F. Maintenance company
Failure to:
- inspect;
- repair;
- patch;
- calibrate;
- replace defective components
can become relevant.
25. Smart-City Infrastructure and Product Liability
Suppose a smart traffic sensor is manufactured with a defect.
The sensor sends incorrect information.
The traffic-control system responds incorrectly.
An accident occurs.
The legal chain may be:
Defective sensor
↓
Incorrect data
↓
Incorrect automated decision
↓
Accident
↓
Damage
The claimant may potentially have claims against different participants, but each claim requires its own legal basis.
26. Smart Buildings
Smart buildings may contain:
- automated elevators;
- biometric entry;
- HVAC automation;
- fire detection;
- automated doors;
- energy-management systems;
- security cameras;
- access-control software.
Example
An automated door incorrectly locks an emergency exit.
A fire occurs.
The legal analysis could involve:
- building owner;
- facility manager;
- software provider;
- maintenance contractor;
- equipment manufacturer.
The court would need evidence establishing:
what failed + who controlled it + whether there was a duty + whether the failure caused the injury.
27. Autonomous Transport
Autonomous vehicles create particularly complex liability questions.
Suppose:
AI driving system → detects pedestrian incorrectly → vehicle fails to brake → injury.
Possible questions:
- Was the AI system defective?
- Was the sensor defective?
- Was the vehicle maintained?
- Was the software properly updated?
- Was the driver expected to supervise?
- Was the road infrastructure defective?
- Did another vehicle create the emergency?
- Was there a cyberattack?
The traditional civil-law concepts of harm, fault/control, causation and external causes remain relevant, although special legislation may govern the particular technology.
28. Smart Traffic Infrastructure
Smart traffic systems may use:
- cameras;
- radar;
- GPS;
- AI;
- vehicle-to-infrastructure communication;
- automatic signalling.
A malfunction can create:
- personal injury;
- vehicle damage;
- traffic disruption;
- economic losses.
The most important evidence may include:
- system logs;
- sensor records;
- maintenance records;
- software versions;
- alerts;
- timestamps;
- operator intervention records.
29. Smart Electricity and Water Systems
Smart utilities can automatically control:
- electricity distribution;
- water pressure;
- consumption;
- emergency shut-off;
- leakage detection.
A software or sensor failure could produce:
- fire;
- flooding;
- property damage;
- service interruption;
- business losses.
The liability analysis must distinguish between:
physical infrastructure failure
and
digital-control failure.
30. Cybersecurity Liability
Smart infrastructure creates a major cybersecurity question:
Who bears responsibility when a cyberattack causes physical damage?
Suppose hackers manipulate a smart water-control system and cause flooding.
The responsible infrastructure operator may argue:
“The damage was caused by hackers.”
The claimant may respond:
“The operator failed to implement reasonable security measures.”
The court would need to examine:
- foreseeability;
- security obligations;
- applicable statutory requirements;
- contractual duties;
- system vulnerabilities;
- external causation;
- evidence.
31. Data Failure and Physical Damage
One of the most important new issues is that digital errors can produce physical harm.
For example:
Wrong digital data → wrong automated instruction → physical event → injury
This means civil liability can no longer be analysed solely through traditional physical infrastructure.
The digital layer and physical layer must be analysed together.
32. Government Smart-City Systems
A government-operated system may provide:
- public transport;
- traffic control;
- emergency response;
- public safety;
- utilities;
- municipal services.
A claimant should identify the exact legal relationship.
For example:
Private contractor
Contractual/tort liability may be relevant.
Government authority
Public-law and applicable governmental-liability rules may also need to be considered.
Mixed public-private project
Both contractual allocation and statutory responsibilities may matter.
33. Preventive Liability Is Especially Important
Traditional litigation often begins:
“The damage has already happened.”
Smart-city systems permit another approach:
“The system is creating a foreseeable danger; prevent the damage now.”
Article 272 of the current Civil Transactions Law is therefore conceptually important because it permits measures to avert certain threatened harm involving buildings, machinery and things requiring special care.
34. Expert Evidence
Smart-city cases are likely to require technical experts.
Experts may examine:
- source code;
- system architecture;
- sensor accuracy;
- cybersecurity;
- maintenance records;
- AI models;
- network logs;
- system design;
- physical infrastructure;
- causation.
The court, however, remains responsible for the ultimate legal determination.
Important distinction
Expert: explains technical facts.
Court: decides legal responsibility.
35. Contract Drafting for Smart-City Projects
Smart infrastructure contracts should clearly address:
1. System performance
What exactly must the system do?
2. Maintenance
Who maintains it?
3. Cybersecurity
Who protects it?
4. Updates
Who installs software patches?
5. Data
Who owns and controls the data?
6. AI decisions
Who is responsible for automated decisions?
7. Downtime
What happens if the system fails?
8. Liability
Who bears which risks?
9. Insurance
What risks must be insured?
10. Evidence
What logs must be retained?
11. Audit
Who can inspect the system?
12. Termination
What happens if the system repeatedly fails?
36. Causation Diagram
A useful way to analyse a smart-city accident is:
Design
↓
Manufacture
↓
Installation
↓
Software
↓
Sensor
↓
Network
↓
AI/Algorithm
↓
Automated Decision
↓
Physical Infrastructure
↓
Harm
↓
Economic/Physical Loss
At each stage ask:
Who controlled this stage?
and:
What evidence proves the failure?
37. Defences
A defendant may argue:
1. No defect
The system operated according to specification.
2. No negligence
Reasonable precautions were taken.
3. No causation
Another factor caused the damage.
4. External cause
The incident resulted from an event outside the defendant's responsibility.
5. Third-party interference
A hacker or another person caused the event.
6. Claimant's own conduct
The claimant contributed to the damage.
7. Contractual limitation
A valid limitation clause may affect contractual liability, subject to mandatory law.
38. Simple Practical Example
Situation
Dubai introduces an AI-based traffic-management system.
A contractor installs cameras.
A software company supplies the AI.
A maintenance company maintains the system.
A government authority operates it.
One camera begins producing incorrect data.
The AI misinterprets the traffic.
The signal changes incorrectly.
Two vehicles collide.
Legal analysis
Step 1: Identify the malfunction.
Camera or AI?
Step 2: Identify control.
Who controlled the defective component?
Step 3: Identify duty.
What did the contract/statute require?
Step 4: Identify fault.
Was there negligence or another legally relevant basis?
Step 5: Establish causation.
Did the defect actually cause the accident?
Step 6: Determine damage.
Injury? Vehicle damage? Other proven loss?
Step 7: Identify responsible parties.
Owner? Operator? Contractor? Software supplier? Manufacturer?
Step 8: Consider external causes.
Was there a cyberattack or another intervening event?
Step 9: Determine remedy.
Compensation, repair, replacement, or another remedy?
39. Simple Legal Framework
Smart City Liability
1. Identify infrastructure
↓
2. Identify controller/operator
↓
3. Identify legal duty
↓
4. Identify malfunction/wrongdoing
↓
5. Establish damage
↓
6. Establish causation
↓
7. Examine external causes
↓
8. Allocate responsibility
↓
9. Calculate compensation
40. Mainland UAE vs DIFC
| Issue | Mainland UAE | DIFC |
|---|---|---|
| General civil liability | UAE Civil Transactions Law | DIFC laws |
| Machinery/thing liability | Current Civil Transactions Law Article 271 | DIFC obligations framework |
| Electronic systems | UAE electronic-transactions framework | DIFC digital-economy framework |
| Technology disputes | Ordinary competent courts/specialised forums as applicable | Digital Economy Court |
| IT-system cases | UAE law may apply depending on jurisdiction | DIFC has direct technology jurisprudence |
| Case precedents | Federal/local UAE courts | DIFC Courts |
The distinction is critical.
A case such as Graciela v Giacobbe is valuable for understanding technology-related liability, but it is a DIFC authority, not a binding mainland UAE precedent.
41. Key Legal Principles
Remember these 12 points:
- Smart infrastructure can create civil liability.
- Control of dangerous machinery can be legally important.
- Article 271 is particularly relevant to machinery and things requiring special care.
- Preventive relief may be available where dangerous conditions threaten harm.
- Damage must be legally recognised and proved.
- Causation is essential.
- Digital failure can cause physical damage.
- Software can be part of the liability chain.
- Cyberattacks require analysis of external causation and security duties.
- Contractual and tortious liability must be distinguished.
- Technical experts may be essential, but courts decide legal liability.
- DIFC technology cases should not automatically be treated as mainland UAE precedent.
42. Exam-Ready Conclusion
Smart city infrastructure liability in UAE civil law concerns responsibility for harm arising from interconnected physical and digital urban systems. The current Civil Transactions Law is particularly relevant because Article 271 imposes liability on the person controlling things requiring special care or mechanical machinery for harm caused by them, subject to the statutory exceptions. Article 272 also provides a preventive mechanism for threatened harm.
The traditional UAE liability framework further requires careful examination of wrongdoing/fault, damage and causation, with a distinction between direct and consequential harm. UAE Supreme Court jurisprudence confirms that these elements must be properly established.
In a smart-city dispute, therefore, the central question is not simply “Who owns the technology?” It is:
Who had the relevant legal duty or control, what failed, did that failure constitute legally actionable wrongdoing or breach, did it cause the damage, and what remedy follows?
Quick Revision Formula
Smart Infrastructure → Control/Duty → System Failure → Wrongdoing/Breach → Damage → Causation → Responsible Party → Compensation/Preventive Remedy
The major development is that digital and physical infrastructure are becoming legally interconnected: a defective sensor, algorithm, software system or cyber-control mechanism can ultimately produce ordinary physical harm, requiring traditional civil-law principles to be applied to technologically complex factual situations.

comments