Articles
When AI goes rogue… is the UK ready?
Category
Commercial Insight
Date
Following OpenAI’s revelation that some of its most advanced models went rogue and hacked a start-up, Lewis McKeown in our Commercial team explains how UK law may struggle to keep up with such advancements…
Recent reports of AI systems creating fake online profiles, misleading people and acting outside controlled testing environments raise an important question: what happens when an AI system causes harm?
The technology is developing quickly, but UK law is struggling to keep up.
If an AI system accesses a company’s network, damages its software or disrupts its operations, there may be difficulty finding a clear route for the affected business to recover its losses from the creator or owner of the system.
Existing computer misuse laws were largely written with human hackers in mind. They rely on ideas such as intention and knowledge, which are harder to apply when an AI system has acted with a degree of independence or “gone rogue”.
Other areas of law may only provide part of the answer. A negligence claim might be possible, but it could be difficult to prove whether or not the organisation responsible for the AI has taken reasonable precautions to prevent the type of harm which occurs. Data protection law could apply where personal information has been misused, but it may not cover the full cost of repairing systems, rebuilding software or dealing with business disruption.
Without a modern legal framework designed specifically to deal with AI created harms, those affected by them may have to rely on common law principles developed long before computers even existed.
For example, the law has traditionally allowed claims where someone’s activities cause serious and unreasonable interference with another person’s property. Other principles may apply where physical equipment has been altered or damaged, even if the immediate cause was digital.
There is also long-established caselaw that can make a person responsible when something under their control escapes and harms someone else as a “nuisance” claim, including strict liability nuisance claims where the “thing” is likely to cause mischief on escape.
Applying these principles to AI would be far from straightforward. Courts would need to decide whether interference with servers, software and digital networks can be treated in the same way as more traditional forms of property damage.
They would also need to decide who should be responsible when the immediate action was taken by an AI system that has no legal identity of its own. However, it does seem reasonably likely that these forms of common law claim would be the way forward for making claims against AI companies where the AI has “escaped” its confines and caused harm.
Developers and businesses are unlikely to be able to avoid responsibility simply by saying “the AI did it”. However, the lack of clear legislation dealing with these issues specifically and expressly in relation to AI creates uncertainty for everyone involved, including those developing AI, those using it and those harmed by it.
The real issue is not whether old legal principles and case law can provide a workable answer and basis for legal claims and compensation to be awarded by the courts. The problem is that they may currently be the only answer available.
Until clearer legislation on responsibility for autonomous AI is developed in the UK, the UK may have to govern some of the world’s newest technology using legal principles developed centuries ago.








