Scope of this briefing: This briefing is provided for general client information and does not constitute legal advice on any specific matter or set of facts. The positions taken in the UKJT's Legal Statement are persuasive, not binding, under English law, and no view is expressed here on how an Israeli court would treat the same questions -- neither source addresses Israeli law, and any Israeli-law read-across would require separate, specific analysis. Note: requires attorney verification before application to any specific client matter.
Two independent developments landed within days of each other and matter more together than either does alone. On 7 July 2026 the UK Jurisdiction Taskforce (UKJT) published its Legal Statement on Liability for AI Harms -- the most authoritative statement yet on how English private law treats AI-caused harm. Separately, Deloitte's 2026 legal-industry AI survey, published in June 2026 and drawing on 121 senior legal leaders, gives a dated, granular snapshot of how fast actual professional practice is changing. The link is not incidental: the UKJT's negligence standard for professionals is explicitly benchmarked against the conduct of competent practitioners at a given point in time -- so the Deloitte data isn't background colour, it's a live measurement of the very benchmark the legal test depends on.
Who is the UKJT
The UK Jurisdiction Taskforce is an industry-led initiative under LawtechUK, backed by the Ministry of Justice and chaired by Sir Geoffrey Vos, Master of the Rolls; its earlier Legal Statements on crypto and digital assets have been cited by English courts. This Statement was prepared by a team of senior KCs and barristers following a formal public consultation in January-February 2026.
Broad summary of the Legal Statement
The UKJT's central conclusion: English law needs no bespoke AI liability regime. Existing doctrines -- negligence, product liability, misrepresentation, defamation -- extend to AI-caused harm by ordinary common-law analogy to precedent. AI has no legal personality, so it cannot itself be sued or held vicariously liable; every liability question resolves to a human or corporate actor in the chain.
To analyse liability, the Statement maps the AI supply chain (adapting a framework from the Ada Lovelace Institute): Data/Compute Providers feed Foundation Model Developers, whose models reach Hosting Suppliers and, often via Brokers, Application Developers who build the tools Users interact with -- plus Affected Third Parties, Advisers, and Bad Actors outside the chain. Contract is the primary liability-allocation mechanism up and down the chain; where none applies, the question turns to negligence, and Foundation Model Developers specifically are unlikely to be liable for harm from unforeseeable uses of a general-purpose model -- unlike a narrowly-targeted Application Developer or careless User, who face materially higher risk.
On vicarious liability, the Statement is direct: AI has no legal personality, so no one can be vicariously liable for an AI system's own conduct. An employer remains fully liable for an employee's negligent AI use exactly as for any other employee error, and non-delegable duties (e.g. a hospital's duty to patients) apply identically whether or not AI sits behind the failure.
Product liability under the UK's Consumer Protection Act 1987 -- the one strict, no-fault basis -- has narrow reach: it applies only where AI is embedded in a physical product, and only to death, personal injury, or private-property damage; commercial-property damage, pure economic loss, and pure software (an AI model or chatbot not embedded in a physical good) all fall outside it. The Law Commission announced a review of the Act on 31 July 2025 expected to address pure software specifically -- an area to watch, not settled ground.
On causation, the Statement treats AI's black-box opacity as a difference of degree, not of kind, from evidential problems English courts already handle routinely (e.g. industrial disease claims) -- existing causation doctrine, including adverse-inference rules against a party whose own conduct created an evidential gap, can accommodate AI cases without new law.
Section C addresses false AI-generated statements, including chatbot “hallucinations.” AI cannot itself make a legal statement, so liability turns on whether a person or company made or adopted its output as their own -- at which point negligent misrepresentation, deceit, and defamation can all attach. Anyone who reviews AI output before publication is treated as an editor; a business publishing AI-generated statements is typically a commercial publisher. Clear AI-generated warnings can affect both a statement's meaning and defamation's “serious harm” threshold -- but disclosure alone doesn't answer whether reasonable care was exercised.
Deep dive: professional liability
For CIDAH's clients -- mostly professionals themselves, or engaging professionals, in regulated or client-facing work -- Section B.4 is the section that matters most directly, and its conclusion cuts both ways. A professional can be negligent for how they use AI: inadequate due diligence before adopting a new tool, using it without understanding what it does, failing to test or scrutinise outputs before relying on them, or handling privileged information through an inadequately secure system are all likely findings of breach. Equally, a professional can be negligent for failing to use AI where a reasonably competent peer, doing the same task, would have -- the Statement's example is an auditor skipping AI-assisted anomaly detection on a dataset too large for individual human review.
Worth flagging because it's easy to get backwards: transparency about AI use is sometimes necessary (the Statement treats a law firm's failure to disclose AI use in assessing a claim as itself a possible breach), but never sufficient. Telling a client AI was used doesn't cure a failure to exercise reasonable care in deciding whether to use it, which tool, or how carefully to check its output -- disclosure and competence are separate obligations.
The standard throughout is the ordinary professional-negligence yardstick -- what a reasonably competent peer of comparable seniority and specialism would have done -- and it moves as practice moves: conduct reasonable last year can become negligent as tools and peer practice mature. That's exactly where the Deloitte data becomes directly relevant.
What the Deloitte data shows about where the profession actually stands
Deloitte's 2026 survey -- 121 senior legal leaders, surveyed April-May 2026 across nine industry sectors and four regions -- gives a dated, granular picture of exactly the competent-professional-practice benchmark the UKJT standard measures against.
Adoption has moved fast: Deloitte's 2024 survey found 76% of legal departments with no AI adoption; by 2026 that's fallen to 2%, with 61% in active deployment and 10% describing AI as fully embedded.
Adoption is sharply uneven by task, which matters given the UKJT standard is task-specific, not a single line to cross. Document review, summarisation, and comparison lead (roughly half at scaling or fully embedded); data extraction, legal research, drafting, and knowledge search follow at 35-40%. Predictive analytics in litigation and client-facing AI-generated advice each show ~64-65% no-adoption -- itself relevant evidence of what's currently reasonable for those specific tasks.
Governance hasn't kept pace: AI governance frameworks exist at 68% of organisations (82% of the most mature), but defined QA frameworks -- the mechanism most relevant to the negligence test's “did you scrutinise the output” limb -- exist at only 24% overall (33% among the most mature), the survey's single lowest-scoring component.
There's also a live client-communication gap: 58% of General Counsels say external providers rarely or never proactively discuss AI use with them, and only 4% report a direct benefit from a provider's AI use. Against the UKJT's conclusion that meaningful AI use can itself require disclosure, this is a gap worth closing proactively, not waiting to be asked about.
Why they're connected
The two documents aren't simply two AI-news items that happened to land in the same month. The UKJT's negligence test is explicitly measured against competent professionals' actions at the relevant time -- and Deloitte's survey is a dated, sector-wide snapshot of exactly that standard, still moving fast: document-heavy tasks near 50% mainstream adoption, QA frameworks at just 24%, client-facing AI advice barely adopted. Conduct that looks reasonable against today's data may not look reasonable against tomorrow's -- and because negligence is assessed at the time of the alleged breach, not in hindsight, that trajectory matters as much as the current snapshot.
Practical takeaways
- Document the rationale for using -- or not using -- AI on each matter type, including what testing or verification was carried out; this is the record a court would look for under the Statement's B.4 analysis.
- Formalize a quality-assurance checkpoint for AI-assisted output before it reaches a client or a court, rather than ad hoc review -- Deloitte's data suggests this is where most organisations, including highly AI-mature ones, are furthest behind.
- Be proactive and specific with clients about where and how AI is used on their matters; the Statement treats significant, undisclosed AI use as potentially itself a breach of duty.
- Track AI-adoption norms by task, not as a single yes/no threshold -- the reasonable-practice bar for document review already differs materially from the bar for AI-generated advice delivered directly to a client.
CIDAH IN PRACTICE
We already apply the same discipline the Statement describes: every AI-assisted client draft carries a mandatory disclosure statement, and a supervising attorney reviews and signs off on it before it reaches you -- the quality-assurance checkpoint the Deloitte data shows most legal organizations, even the most AI-mature ones, still lack.
This document combines the firm's advanced AI system with experienced legal expertise, under the close supervision and approval of senior attorney.
Related
- Healthcare AI Implementation: The Sheba-OpenAI Partnership
- Abu Dhabi Launches World's First AI-Powered Judicial Platform
- US FTC Proposes Policy on AI "Accuracy Suppression" -- Public Comment Period Closes Soon