The short answer
In almost every case, your business is. UK law does not treat “the AI did it” as a defence. If an employee acts on a wrong AI output and a customer is harmed, liability sits with the organisation, the same as any other mistake by a member of staff or a tool it chose to use. That is exactly why a human check and a clear policy matter.
This is the question that keeps sensible business owners up at night, and rightly so. The short answer is not comforting, but it is clear. When AI produces something wrong and your business acts on it, the buck stops with your business.
None of this is a reason to avoid AI. It is a reason to use it with a hand on the wheel. Please note this article is general information, not legal advice. For anything specific, talk to a solicitor.
So who is actually responsible?
Your business. If a member of staff uses an AI tool as part of their job and gets it wrong, the law generally treats that the way it treats any other workplace mistake. The employer carries the responsibility to the customer or third party. You cannot outsource accountability to a piece of software any more than you could blame a faulty calculator.
Suing the AI vendor is rarely a realistic route either. Their terms almost always place responsibility for how you use the output squarely on you.
How does this go wrong in real life?
Two well-known cases make it concrete. Air Canada was ordered by a Canadian tribunal in 2024 to honour a refund policy its own website chatbot had invented, after it argued unsuccessfully that the chatbot was responsible for its own words. And in the United States, lawyers in the Mata v Avianca case were sanctioned in 2023 after they filed a brief citing court cases that ChatGPT had entirely made up.
The pattern is the same every time. A person trusted an AI output without checking it, acted on it, and the organisation wore the consequences.
What does UK law say right now?
There is no single UK statute that creates special AI liability. Instead, the existing law applies. Negligence, breach of contract, consumer protection, and UK GDPR for anything involving personal data. The UK has chosen a pro-innovation approach rather than one big AI law, which puts the onus on businesses to use these tools responsibly under the rules that already exist.
How do you protect your business?
Five safeguards that carry most of the weight
- A human check on anything that matters. A named person signs off AI-assisted work before it reaches a client or the public.
- A written AI policy. It shows you took reasonable steps, which matters if anything is ever challenged.
- Approved, paid tools for client work. Business plans with proper data terms, not free personal accounts.
- Records. Keep a light trail of where AI was used on important work, so you can reconstruct what happened.
- Training. People who understand how AI gets things wrong are far less likely to be caught out by it.
Who's Liable When AI Gets It Wrong? – frequently asked questions
If AI gives bad advice and someone acts on it, who is liable?
Normally the business, not the tool. UK law treats it much like any other mistake by staff or equipment the business chose to rely on. That is why a human check on important work is essential.
Can we blame the AI vendor if the output is wrong?
Rarely. Most AI tools' terms place responsibility for how you use the output on you, the user. Suing the vendor is not a realistic route for the vast majority of businesses.
Does UK GDPR apply to how we use AI?
Yes, wherever personal data is involved. Putting customer or employee personal data into an AI tool is processing that data, so your usual data protection obligations still apply. Use tools with proper business data terms.
Can an employee be disciplined for misusing AI?
They can, if there is a clear policy they have breached. This is one more reason to have a written AI policy: it sets the standard everyone is held to and makes fair action possible.
How do we reduce legal risk from AI at work?
A human check on anything that matters, a written policy, approved paid tools for client work, light record-keeping, and training. Together these show you took reasonable care.
Which Oxford AI School training fits this need?
Put the safeguards in place before you need them. Policy and practical training, in person across the UK or live online.
Reduce your AI risk without killing the upside
Our AI Policy Workshop helps your team agree the safeguards above and build the habit of checking, so you get the productivity and skip the headlines.
Book the AI Policy Workshop Keep your data safe