Not the AI. Under the private law of England and Wales an AI system has no legal personality, so it cannot be liable and cannot act as anyone's agent; responsibility runs to people and organisations. In practice that means the organisation that chose to deploy it, the professional who relied on its output, and the employer of the person who used it. The courts have already applied the principle to lawyers who filed AI-invented cases: the duty to check sat with the lawyer and could not be passed to a client or a tool. The harder problem is inside organisations, where a decision a machine shaped often has no named human owner until something goes wrong.
The answer, in one line
People and organisations, never the AI. Under the private law of England and Wales an AI system has no legal personality and cannot be liable, so responsibility runs to the organisation that deployed it, the professional who relied on it, and the employer of the person who used it.
What the law says in England and Wales#
The clearest statement is the UK Jurisdiction Taskforce's 2026 legal statement on liability for AI harms, drafted by a team led by Matthew Lavy KC. Its view is that the common law can handle AI harm without new legislation. An AI system has no legal personality and cannot be liable or act as an agent in law. Contract allocates risk first, and negligence applies where no contract does. Organisations that deploy a system, and developers who build applications on a model, carry more negligence exposure for unforeseeable uses of a general-purpose model than the company that built the model. Professionals can be negligent for careless use of AI, and also for failing to use it where a competent practitioner would. An employer is vicariously liable only through a human employee's wrongdoing.
A legal statement is not a judgment, and at the time of review no English court had ruled on harm caused by an autonomous agent. But the direction is consistent: there is always a person or an organisation to answer, usually the one that chose to use the tool. Whether a company can disown what its own chatbot or agent did is covered at can a company blame its AI agent, and the other side of the duty at could a professional be negligent for not using AI.
What the courts have already done#
The most developed record is in law, because fabricated citations are easy to detect. Damien Charlotin's database held 2,022 court decisions involving AI-fabricated or misrepresented material as at 6 September 2026: 1,163 involving litigants representing themselves, 805 involving lawyers, and 31 involving judges. It counts only cases where a court ruled, so the true number is higher.
In England, the Divisional Court's judgment in Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank in 2025 set the rule out in terms. Freely available generative tools are not capable of reliable legal research. Anyone using them has a professional duty to check the output against authoritative sources. The duty extends to a lawyer relying on someone else's AI-assisted work, and a lawyer cannot rely on a lay client for the accuracy of citations. The court listed powers running from public admonition and wasted costs to contempt proceedings and referral to the police. The case is about lawyers. The principle, that using the tool does not move the duty, is the one most professions will meet.
What regulators require#
Where regulation exists, it assigns responsibility to named people. The EU AI Act's Article 26 requires deployers of high-risk systems to assign human oversight to people with the necessary competence, training and authority, to suspend use where a system presents a risk, and to keep the automatically generated logs for at least six months. Most uses at work will fall outside the high-risk categories, and the duties create obligations rather than evidence that anyone meets them. In UK financial services, the Senior Managers and Certification Regime asks the same question in its own terms; see SM&CR and AI.
Where responsibility goes missing#
The legal answer is clear. The organisational answer often is not. A draft is produced by the tool, approved by someone who assumed it had been checked, and acted on by someone who assumed it had been approved. Each person can say, truthfully, that the decision was not theirs. A human in the loop who follows the machine is not oversight: Skitka, Mosier and Burdick showed in 1999 that people working with automated aids both miss what the system fails to flag and follow advice that is wrong.
Accountability on paper can also mean nothing in practice. Wright and colleagues studied New York City's law requiring audits of automated hiring tools and found only 18 employers had posted an audit report, roughly 5 per cent of those examined, under a law designed so that non-compliance could not be established. They called the result null compliance. Singh, Cobbe and Norval argue that accountability needs decision provenance: a record of the inputs to a decision, the decision itself, and what followed. Without a record, nobody can show who decided anything. The question of who checks is taken further at who owns verification when AI does the work.
Making it answerable before it goes wrong#
Four decisions, made in advance and written down. Which decisions a machine may make, and which it may only inform. Who is the named owner of each class of decision, with the authority to stop it. What people must remain able to do without the tool, so the owner can still check. And how anyone would know if it went wrong: the log, the sample, the person who looks. The UK National Cyber Security Centre's advice on agents adds a fifth for anything autonomous: you should always be able to pull the plug. These are the core of Rules Before Tools, and how to allocate them is set out at how AI decision rights should be allocated.
The test is simple. Pick a decision your organisation made this month with AI involved, and ask who would answer for it in front of a client, a regulator or a court. If the true answer is a committee, a vendor or the tool, the organisation has a gap the law will not fill on its behalf.
What this does not show#
This is not legal advice, and it describes England and Wales; other jurisdictions differ, and the European rules cited apply only to high-risk systems. The UK Jurisdiction Taskforce statement covers private law, not criminal liability or regulatory duties, and no English judgment on harm by an autonomous agent had been reported at the time of review. The court record is concentrated in law because fake citations are easy to spot; it does not show that other professions err less. And none of it shows how often organisations actually name owners for AI-shaped decisions. That has not been measured.
Essay · SS-2026-416 · 2 peer-reviewed studies, 2 compiled reviews, 2 argued perspectives and 2 of other kinds
Hirji, R. (2026). Who is responsible when AI gets it wrong?. The SuperSkills evidence base, SS-2026-416. https://thesuperskills.com/research/who-is-responsible-when-ai-gets-it-wrong. Last reviewed 5 October 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work