“The AI made it up” is a technical explanation. It is not a legal defence and under the law of England and Wales it rarely comes close to one.
A hallucination is a confidently expressed falsehood produced by a generative AI system: a citation to a case that does not exist, a discount your business never offered, a specification that cannot be met. The term is now widely understood. What is less well understood is that it has no legal significance whatsoever. English law does not recognise a category of harm called a hallucination, and there is no statutory regime in this jurisdiction dedicated to allocating responsibility for one.
That absence is sometimes read as a gap. It is better understood as an answer. In July 2026 the UK Jurisdiction Taskforce published a legal statement on liability for AI harms under the private law of England and Wales, concluding that existing principles of contract, tort and statute are largely capable of resolving these disputes without AI-specific legislation. The statement is not binding, but it was produced by a senior group of practitioners and judges and reflects the direction of judicial thinking. The UK still has no AI Act, and the Government has shown no appetite for one.
For businesses deploying AI, that means the question is not “who is liable for the hallucination?” It is the far more familiar question: what did you promise, what care did you take, and who was harmed?
“The AI did it” is not a defence
The instinct to treat the AI system as the responsible actor fails at the first hurdle. An AI system has no legal personality. It cannot owe a duty, hold assets, or be sued. Vicarious liability – the doctrine that makes an employer answerable for its employee’s wrongdoing, has nothing to attach to. What survives is entirely conventional: your business is liable for what your employees do while using AI, and for what your systems say to your customers.
The courts have already shown limited patience. In Ayinde v London Borough of Haringey, heard together with Al-Haroun v Qatar National Bank, the Divisional Court dealt firmly with legal submissions containing fabricated case citations, reminding those before it that the obligation to check the source has not been suspended. The principle generalises well beyond litigation: where a person or organisation puts unverified AI output into the world as its own, the responsibility travels with it.
Where liability actually lands
Contract and consumer law. If you have promised a customer an outcome, an AI-generated error that defeats that promise is simply a breach. Under the Consumer Rights Act 2015, services supplied to consumers must be performed with reasonable care and skill, and digital content must be of satisfactory quality, fit for purpose and as described. None of those standards are softened because a model, rather than a person, produced the defective output.
Misleading statements to customers. A chatbot that invents a refund policy or misdescribes a product is making a statement on your behalf, and English law will treat it as yours. Depending on the facts, that can give rise to a misrepresentation claim and to regulatory exposure under the unfair commercial practices regime in the Digital Markets, Competition and Consumers Act 2024, which has applied since April 2025. The CMA can now enforce consumer protection law directly, with penalties reaching up to ten per cent of worldwide turnover. Automated misleading statements at scale are a materially different risk from a single misinformed employee.
Negligence. Where there is no contract, the ordinary duty to take reasonable care does the work. The UKJT statement identifies the recognisable failure modes: deploying AI for a task it is unsuited to, choosing an inappropriate model, conducting no meaningful due diligence, and failing to test or validate output. Notably, it also contemplates the mirror-image failure, that a competent professional may in time be negligent for not using AI where the standard of the field has moved. The reasonable-care standard is not static, and it is currently moving quickly.
Data protection and discrimination. If the AI output concerns an identifiable person, the UK GDPR is engaged, including the accuracy principle. The reforms in the Data (Use and Access) Act 2025 – all data protection provisions of which are now in force, widened the lawful bases available for significant automated decision-making while retaining a framework of safeguards, and tighter restrictions still apply to special category data. Separately, an AI screening or scoring tool that disadvantages a protected group can found a claim under the Equality Act 2010, where the opacity of the model is the employer’s problem to explain, not the claimant’s.
The one real gap: product liability
Strict liability under the Consumer Protection Act 1987 allows a claimant to recover for damage caused by a defective product without proving fault. Its application to AI is narrow: it bites where AI is embedded in a physical product, but standalone software and cloud-delivered systems sit largely outside it. A claimant harmed by a purely digital AI output must therefore fall back on contract or negligence, and prove considerably more.
This is understood to be an anomaly. The Law Commission is reviewing the product liability regime with digital products expressly in scope, with public consultation expected in the second half of 2026. Businesses supplying AI-enabled products should assume this position will tighten rather than relax.
What your supplier’s contract does and does not do
Most AI vendor terms disclaim the accuracy of output, place verification squarely on the customer, and cap liability at a fraction of fees paid. Read carefully, they are an allocation of risk to you.
It is worth being clear about what contractual protection achieves. Indemnities and caps agreed between you and your AI supplier govern recovery between the two of you. They do not stand between your business and a customer, employee or third party who has been harmed. That claimant sues you, on your contract or in tort, and your recourse against the vendor is a separate and often disappointing exercise. Contractual risk allocation is a recovery mechanism, not a shield.
What actually reduces exposure
The businesses handling this well are not the ones with the longest disclaimers. They are the ones who can evidence a process.
- Define what each AI tool is and is not approved to do, in writing, and keep that scope narrower than the technology permits.
- Make human review real rather than nominal – a reviewer with the time, competence and authority to reject the output.
- Keep records of model selection, testing and validation. When care is challenged, contemporaneous evidence is what answers it.
- Tell customers when they are dealing with an automated system, and do not let it make commitments the business would not honour.
- Check your insurance. Professional indemnity and cyber policies were not all written with generative AI in mind, and some now address it expressly.
The direction of travel
The reassuring conclusion, that established English law can absorb these disputes, is also the demanding one. It means there is no grace period, no transitional regime, and no novel defence to be constructed while the law catches up. Liability for a hallucination is decided by rules that have been in place for decades, applied to a technology adopted in months. The businesses that come out of this well will be those that documented their judgement at the time they exercised it.
This article is general information about the law of England and Wales as at August 2026. It is not legal advice and should not be relied upon as such. The UK Jurisdiction Taskforce legal statement referred to above is not binding, and the Law Commission’s product liability review is ongoing.

