Last updated on August 9th, 2026 at 07:14 am
TL;DR: A business uses an AI tool to draft a document, answer a customer query, or generate content, and the output turns out to be wrong, defamatory, or infringing, and now someone has suffered a loss. The instinctive assumption is that the AI company is responsible, since it built the tool. In practice, the business that deployed the AI is usually the one exposed, because the AI vendor’s own terms of service are written specifically to shield the vendor: disclaimers that the output may be inaccurate, no warranty of fitness for any particular purpose, and a requirement that the user independently verify anything before relying on it. This guide explains why that allocation happens, the legal theories courts and regulators actually use to assign fault, how the position looks in the US, UK, and EU, and a dedicated section on India. It closes with what happens specifically when the AI in question drafted or reviewed a contract.
Quick overview: “Who’s liable when AI gets it wrong” sounds like a novel question, but the legal tools used to answer it are mostly old ones: negligence, vicarious liability, product liability, and contract law, applied to a new kind of tool. This guide walks through a realistic scenario, explains why the deploying business usually carries the exposure rather than the AI vendor, covers the legal theories in play globally, and closes with a dedicated section on India and a specific look at AI-assisted contract drafting.
The scenario: when AI output causes real trouble
Picture a business that uses a general-purpose AI tool to draft a client-facing document, answer a legal or compliance question, or generate marketing content, without a human independently checking the output before it goes out. The AI gets something wrong: bad advice that a customer relies on and loses money over, a generated passage that turns out to closely mirror someone else’s copyrighted work, or a factual claim that is confidently stated and completely false. The business only discovers the problem after the damage is done, a complaint, a legal notice, or a customer walking away from a bad outcome they were told to trust.
This is not a hypothetical edge case. It is the ordinary way AI-related liability actually surfaces in business: not through some dramatic algorithmic failure, but through an unreviewed output that someone acted on.
Why the business using the AI is usually the one exposed
Here is the thesis worth understanding before anything else in this guide: when something goes wrong, the business that deployed the AI tool is generally more exposed than the company that built it, and this is by design, not accident.
AI vendors write their terms of service specifically to limit their own liability. Standard clauses disclaim any warranty that outputs are accurate, state that the tool is provided “as is,” and place the responsibility for verifying and using the output appropriately squarely on the customer. This is standard, enforceable contract drafting, and it means that when a business relies on AI output without independent verification and something goes wrong, the vendor’s terms usually leave little room to shift the loss back to them. The business that used the tool, and acted on its output, or let a customer act on it, is left holding the exposure.
This is not a loophole; it reflects how liability doctrines actually work. The party that made the decision to deploy the tool, and to rely on its output without adequate safeguards, is generally the party a court or regulator looks to first.
The legal theories actually used to assign fault
Across most jurisdictions, four established legal theories, not any AI-specific law, do the actual work of assigning liability.
Negligence. The party deploying an AI system generally owes a duty of care in how it uses that system: adequate testing, reasonable oversight, and appropriate validation of outputs before acting on them. Deploying a tool without adequate verification, and relying on its output regardless, can itself be treated as a breach of that duty. Failing to check an AI-generated factual claim or citation before relying on it is increasingly treated as exactly this kind of carelessness, not a neutral technology failure.
Vicarious liability. A business is generally liable for the actions of its employees and agents within the scope of their work, and courts have extended this logic to an employee’s use of an AI tool in the course of their job. If an employee uses an AI tool and its output causes harm, the employer is typically the one answering for it, in the same way an employer answers for an employee’s other work-related conduct.
Product or service liability. Where an AI tool is itself defective, flawed in design, trained on inadequate or biased data, or missing basic safeguards, liability can attach to the developer under product or service liability principles. This route is real but narrower than the other three, because most general-purpose AI tools are supplied under contract terms that exclude the kind of warranty product liability claims typically rest on.
Contract-based allocation. Where a business uses an AI vendor’s tool under a commercial agreement, the contract itself usually decides who bears the loss, and this is where the vendor’s advantage is built in from the start. Warranty disclaimers, liability caps, and indemnity carve-outs in a vendor’s standard terms are drafted to protect the vendor, and a business that signs them without negotiation has effectively pre-agreed to carry more of the risk. Our guide on AI vendor contracts and the clauses every business must check covers exactly what to look for before signing, and our broader guide on why not having a limitation of liability clause can kill your startup explains why these caps matter so much once something does go wrong.
How the US, UK, and EU approach AI liability
United States. There is no single federal AI liability statute; liability is assembled from existing negligence, product liability, and contract law, applied state by state, with sector regulators (financial, healthcare, consumer protection) adding specific obligations on top. The result is a patchwork where the same AI failure can be assessed differently depending on the state and sector involved.
United Kingdom. The UK has similarly avoided a standalone AI liability statute, relying on existing tort and contract principles, with sector regulators issuing AI-specific guidance rather than binding new liability rules. The emphasis, similar to the negligence-based approach elsewhere, is on whether the deploying business exercised reasonable care and oversight.
European Union. The EU has gone furthest with the EU AI Act, a risk-based framework being phased in through 2025 and 2026, which imposes specific transparency, risk-management, and human-oversight obligations on providers and deployers of “high-risk” AI systems, obligations that exist independently of, and in addition to, ordinary negligence and product liability principles. This makes the EU the jurisdiction where a business’s AI governance practices are most directly regulated, not just indirectly relevant to a liability claim after the fact. Our contract lawyers in the EU advise on AI Act compliance alongside contractual risk allocation, and our contract lawyers in the USA and contract lawyers in London advise on the equivalent US and UK positions.
India: liability without a dedicated AI statute
India has no standalone AI liability law, and this is unlikely to change imminently. Instead, AI-related harm is addressed through the same general legal tools courts apply everywhere else: the law of torts (negligence, vicarious liability, and in limited circumstances strict liability), the Consumer Protection Act, 2019 (which can extend to defective AI-enabled products and services), the Information Technology Act, 2000 (covering AI-generated content, intermediary liability, and related cyber issues), the Copyright Act, 1957 (which protects computer-generated works but does not grant authorship to an AI system itself, relevant where AI output infringes someone else’s copyright, a topic our guide on AI training and copyright in India covers in depth), and the Bharatiya Nyaya Sanhita, 2023 for conduct that rises to criminal liability.
Indian courts and regulators are already applying the negligence-based logic described above in practice. The Supreme Court’s own draft Regulations for the Use of Artificial Intelligence in Courts, 2026 treat AI as an assistive tool only, with human oversight and accountability retained throughout, and legal commentary has been explicit that failing to verify an AI-generated output before relying on it can itself be treated as evidence of negligence. For a business, the practical read is the same as globally: deploying AI without adequate validation or oversight is where liability exposure concentrates, and the absence of a dedicated statute does not mean the absence of consequences. Our technology lawyers advise on structuring AI use and vendor contracts to manage this exposure under Indian law specifically.
What happens if you use AI to draft or review a contract, and it goes wrong
This deserves its own section, because it is one of the fastest-growing sources of exactly the exposure described above, and it is entirely avoidable.
When a business uses an AI tool to draft or review a contract, the tool can miss a clause that should have been there, get a governing-law or jurisdiction reference wrong, produce a clause that looks standard but does not actually protect the business signing it, or simply reproduce a clause style that reads correctly but has no real legal grounding in the jurisdiction the contract needs to work in. The document looks complete and professional. The gap is invisible until the contract is tested, in a dispute, at renewal, or when a counterparty’s lawyer reads it closely, and by then the business has already signed something it cannot rely on. Our guide on why AI-generated contract templates can be dangerous for your business covers this specific failure pattern in more depth, and our what should be included in every business contract guide sets out the baseline any AI-assisted draft needs to be checked against.
Because the AI vendor’s terms almost certainly disclaim responsibility for the accuracy of anything it generates, including a contract, the business that signed the AI-drafted agreement carries the consequences of any gap in it, not the AI provider. An AI tool can be a genuinely useful starting point for a first draft, but treating its output as a finished, reliable legal document without qualified review is precisely the “no human verification” failure pattern that runs through this entire guide.
If you have used AI to draft or review a contract and want to know whether it actually protects you, that is exactly what a proper legal review is for. Our contract drafting and contract review and revision services can check an AI-generated draft before you sign it, and you can speak to our contract lawyers in India or the jurisdiction that governs your agreement.
The two mistakes that create most of this exposure
Almost all of the liability described in this guide traces back to two avoidable gaps.
No human review step before anything AI-generated is acted on or sent out. Whether it is advice given to a customer, content published under the business’s name, or a contract that gets signed, the single most effective safeguard is a qualified person checking the output before it has consequences. Treating AI output as provisional, not final, closes most of the exposure this guide describes.
Liability with the AI vendor is never addressed until something has already gone wrong. Most businesses sign an AI vendor’s standard terms without reading the liability and indemnity sections, and only discover what those terms actually say once a dispute is already underway. Reviewing, and where possible negotiating, those terms before signing, particularly the liability cap and any indemnity for third-party claims arising from the AI’s output, is far cheaper than discovering the gap during a dispute. Our guide on the essential contracts every AI startup must have and the indemnity clause explained cover exactly this ground.
Frequently asked questions
Who is liable when an AI tool makes a mistake?
In most cases, the business that deployed the AI tool and acted on, or allowed a customer to rely on, its output, rather than the company that built the AI. This is largely because AI vendors’ terms of service disclaim warranties on output accuracy and place the responsibility for verification on the user. Liability is generally assessed through existing legal theories, negligence, vicarious liability, product liability, and the terms of the contract with the AI vendor, rather than through any AI-specific liability statute.
Can a business avoid liability by using a well-known or reputable AI tool?
Not automatically. The reputation or scale of the AI vendor does not remove the deploying business’s own duty to verify outputs before relying on them or letting others rely on them. Liability generally attaches to the party that decided to deploy the tool and to act on its output without adequate oversight, regardless of how established the underlying AI provider is.
Does the AI vendor’s terms of service protect a business that uses their tool?
The vendor’s terms protect the vendor, not the business using the tool. Standard AI vendor terms disclaim warranties on accuracy, exclude liability for output-related harm, and require the user to independently verify anything before relying on it. This means the business using the AI tool typically cannot rely on the vendor’s terms to shift liability back to the vendor when something goes wrong.
Is there a dedicated AI liability law in India?
No. India does not have a standalone statute governing AI liability. Liability is instead addressed through existing legal frameworks: tort principles (negligence, vicarious liability), the Consumer Protection Act, 2019, the Information Technology Act, 2000, the Copyright Act, 1957, and the Bharatiya Nyaya Sanhita, 2023 for criminal conduct. Indian courts and regulators are increasingly treating a failure to verify AI-generated output before relying on it as evidence of negligence.
What happens if an AI-drafted contract has a mistake in it?
The business that signed the AI-drafted contract bears the consequences of any gap or error in it, not the AI tool’s provider, since the vendor’s terms almost certainly disclaim responsibility for the accuracy of generated content, including legal documents. An AI tool can be a useful starting point for a draft, but the resulting document should be reviewed by a qualified lawyer before signing, since gaps are often invisible until the contract is tested in a dispute.
What is the single most effective way to reduce AI liability exposure?
Requiring a qualified human review of any AI-generated output before it is acted on, published, or relied on by a customer, combined with reviewing and, where possible, negotiating the liability and indemnity terms in any AI vendor contract before signing rather than after a dispute arises. Together, these two steps close most of the exposure that businesses currently face from AI use.
Authored and reviewed by Prakhar Rai, Advocate, founder of My Legal Pal. Prakhar is enrolled with the Bar Council of India and has over ten years of experience advising technology businesses on AI liability, vendor contracts, and regulatory risk across India and cross-border. He is an alumnus of the National Law School of India University, Bangalore, where he completed his Master of Business Laws, and of La Martiniere. Connect on LinkedIn.
This article is general information, not legal advice. AI liability law is genuinely unsettled and continues to develop through regulation and judicial interpretation. For advice on your own AI use or vendor contracts, speak to a qualified lawyer.
If your business uses AI and you want to understand or reduce your liability exposure, our team can help, including reviewing an AI-drafted contract before you sign it. We handle contract drafting and contract review and revision, and you can speak to our contract lawyers in India or our technology lawyers.






