All NotesCivil LawLaw of Torts

Law of Torts

Artificial Intelligence, Autonomous Systems and Algorithmic Harm: Who Answers When the Decision Was Not Made by a Person

The law of torts attributes harm to a person: somebody was careless, somebody employed the person who was careless, or somebody carried on a hazardous activity. An autonomous system strains that structure, because the immediate cause of the harm is a decision that no human being made and which frequently nobody can fully explain. The question is not whether the existing torts can reach such harms, which they largely can, but through whom: the developer, the deployer, or the enterprise that chose to put the system into a setting where it could cause injury.

The routes available, the three structural problems, algorithmic harm and autonomous vehicles

1. Negligence of the Developer

  • The alleged breaches are in the design of the system, in the selection and curation of the training data, in testing and validation before release, and in the monitoring of the system after deployment.
  • The first difficulty is the standard. Negligence measures conduct against what a reasonably competent practitioner would have done, and for systems of this kind there is as yet no settled body of professional practice against which to measure a design decision. The Bolam approach examined in TORT 039 presupposes a responsible body of opinion, and where the field is new there may be several bodies of opinion and no consensus.
  • The second difficulty is causation. The claimant must show that a different design would have produced a different outcome, and the reasoning of the system cannot be reconstructed.
  • A failure to warn is the more promising ground, because it does not require the claimant to show what the system should have done, only that its known limitations were not disclosed.
  • And a continuing duty to monitor and to update follows from the post sale duty to warn examined in TORT 079: a developer who learns that his system fails in a particular class of case must warn those using it.

2. Negligence of the Deployer

  • The deployer is frequently the stronger defendant, because his own conduct is visible, documented and measurable in a way the system's is not.
  • The alleged breaches are selecting a system unsuited to the task; failing to supervise its output; failing to keep a human in the loop where the decision affects a person's rights or safety; failing to test the system against the population on which it will actually be used; and continuing to rely on it after its failures became apparent.
  • The duty arises most readily where the deployer has an existing relationship with the person affected: a hospital with a patient, a bank with a customer, an employer with an applicant.
  • A deployer cannot discharge his duty by pointing to the system. He chose to use it, and the decision to delegate a judgment to a machine is itself a decision for which he answers.

3. Product Liability

  • Section 84 of the Consumer Protection Act, 2019 attaches liability to a defect without proof of negligence, which answers the opacity problem directly: the claimant need not explain what went wrong inside the system, only that the product was defective and caused him harm.
  • The first open question is whether software is a product within the Act. The Act defines a product as any article or goods or substance or raw material or any extended cycle of such product which may be in gaseous, liquid or solid state, possessing intrinsic value which is capable of delivery either as wholly assembled or as a component part. Whether software supplied as a service falls within that is not settled.
  • The second is whether an output is a defect. A system that gives a wrong answer in one case out of a thousand may be performing exactly as designed, and a claimant must establish that the design itself was defective rather than that the output was wrong.
  • The failure to warn ground is again the most promising: section 84 makes a manufacturer liable where the product does not contain adequate instructions of correct usage to prevent harm, or a warning regarding improper or incorrect usage, and a system supplied without a clear statement of its known limitations falls squarely within it.

4. Vicarious and Strict Liability

Does it fit

Why

Vicarious liability

No

It requires a tort by a servant, which presupposes a person capable of committing one. A system is not a servant, and attributing a tort to it is a fiction that answers nothing

Non delegable duty

Partly

Where the deployer owed a duty to see that care was taken, as a hospital does, the use of a system does not discharge it. The duty is his own, performed through another

Rylands v. Fletcher

No

It requires the accumulation of a dangerous thing on land and its escape, neither of which describes a software system

Absolute liability: M.C. Mehta

Arguably

It attaches to a hazardous or inherently dangerous activity and not to fault, and an enterprise deploying an autonomous system in a safety critical setting is not far from that description. No Indian decision has yet so held

5. The Three Structural Problems

  • Opacity. The claimant cannot show why the system did what it did, so he cannot show what a reasonable designer would have done differently. This is a problem of proof, and the law has met it in other fields by res ipsa loquitur and by shifting the burden onto the party with the knowledge. The precautionary principle in environmental law, examined in TORT 081, does exactly that.
  • Diffusion. The harm is produced by a chain, the data, the model, the integration, the deployment and the use, and no single link is obviously the cause. This is a problem of causation, and the law has met it by material contribution and by joint and several liability.
  • Autonomy. The immediate decision was not made by any person at all. This is the genuinely novel problem, and the honest answer is that the law reaches it only by attributing the decision back to whoever chose to deploy a system that would make such decisions. That is not a fiction: the choice to delegate was made by a person, and it is that choice which the law examines.

6. Algorithmic Harm

  • The typical case is an automated decision denying credit, insurance, employment, admission or a benefit, on grounds that are wrong, unexplained, or discriminatory in effect though not in intention.
  • The harm is usually pure economic loss or a loss of opportunity, which the law of negligence guards carefully for the reasons examined in TORT 075.
  • The stronger claims are against a public authority. Where the decision maker is the State, judicial review and the constitutional remedies are available, and a decision made without reasons, without a hearing, or on irrelevant considerations is assailable on ordinary administrative law grounds whether a human or a system made it.
  • A duty to give reasons is the practical lever. An authority that cannot explain a decision has not made a lawful one, and the opacity that defeats a negligence claim is itself the ground of review.
  • Discriminatory effect engages Articles 14 and 15 where the State is involved, and the absence of discriminatory intent is no answer where the effect is established.

7. Autonomous Vehicles

  • This is the clearest case, and the one the existing law handles best.
  • The owner remains liable under the Motor Vehicles Act, 1988, and the compulsory third party insurance answers the victim whatever the cause of the accident.
  • The manufacturer answers in product liability for a defect in the system.
  • The real contest is therefore between the insurer and the manufacturer, and the victim is kept out of it by the same logic that produces the pay and recover principle examined in TORT 086: the compulsory insurance provisions exist for the protection of a third party who had no part in any of the arrangements.
  • That structure is worth noticing as a model, because it solves for the victim without requiring anybody to decide the hard question of who was at fault, and leaves that question to be fought between two commercial parties who are equipped to fight it.

⚠ Why the answer is likely to be strict liability rather than a new tort

Proposals for reform in this field usually take one of two shapes: a new tort of algorithmic harm, or the conferment of legal personality on the system itself. The second answers nothing, since a system has no assets and personality without assets is an elaborate way of leaving the victim uncompensated. The first is unnecessary, because as this note shows the existing torts reach the conduct; what defeats a claimant is not the absence of a cause of action but the impossibility of proving fault in a process he cannot see. The law has met exactly that problem before, and it met it by dispensing with fault. That is what Rylands v. Fletcher did for the escape of dangerous things, what M.C. Mehta did for hazardous enterprises, what the Motor Vehicles Act did for road accidents, and what section 84 of the Consumer Protection Act did for defective products. In each case the legislature or the court concluded that where an enterprise creates a risk for its own purposes, and the victim cannot possibly prove what went wrong inside it, the enterprise should bear the loss as a cost of the activity. The argument for applying that reasoning to autonomous systems is not a novel one; it is the oldest argument in this part of the law.

8. The Position Stated Shortly

1. The law of torts attributes harm to a person, and an autonomous system strains that structure because the immediate decision was made by no one.

2. A claim against the developer lies in negligence in design, data curation, testing and monitoring, and its weaknesses are the absence of a settled standard and the opacity of causation.

3. A claim against the deployer is frequently stronger, because his own conduct in selecting, supervising and relying on the system is visible and measurable.

4. Section 84 of the Consumer Protection Act, 2019 attaches liability to a defect without proof of negligence, which answers the opacity problem.

5. Whether software is a product within the Act, and whether a wrong output is a defect, are both unsettled; failure to warn of known limitations is the most promising ground.

6. Vicarious liability does not fit, because it requires a tort by a servant and a system is not a servant.

7. Absolute liability under M.C. Mehta arguably does fit, since it attaches to a hazardous activity and not to fault, though no Indian decision has yet so held.

8. The three structural problems are opacity, which is a problem of proof; diffusion, which is a problem of causation; and autonomy, which is genuinely novel.

9. Algorithmic harm is usually pure economic loss, and the stronger claims are against a public authority where judicial review and a duty to give reasons are available.

10. Autonomous vehicles are handled well by the existing law: the owner and the insurer answer the victim, and the contest between insurer and manufacturer does not concern him.