Four important recent publications have highlighted the legal and governance framework within which AI in healthcare should operate when considering the issue of civil liability. The conclusion these publications come to is that the existing legal framework in the UK is sufficient for patient redress by way of a negligence claim against the healthcare provider. Where a patient is successful, it will then be for that health provider to seek an appropriate indemnity or contribution from the AI supplier based in contract.

In theory, this seems straightforward, but it again highlights the need for any health provider to be able to evidence the necessary good governance when developing, procuring or rolling out AI – whether that is to successfully defend a claim or seek an appropriate indemnity from a third party.

This insight considers these four publications and gives an overview of the current position of the AI liability gap.

Legal issues and proposals

CERSI AI: AI and Professional Liability in Health and Care — Opportunities for Action

As we discussed previously in this article, while using AI in healthcare has many benefits, it also presents a significant challenge with a “liability gap”. AI is not a legal entity and concerns around any duty of care owed by an AI developer to a patient, as well as how the black box thinking of AI can be deciphered, means it is difficult to prove negligence in the traditional way if the AI goes wrong. Furthermore, as highlighted by the CERSI AI consultation, patients and professionals alike worry that it is the clinicians using AI who become “liability sinks” by “facing the risk of absorbing consequences they had little meaningful power to prevent”.

UK Jurisdiction Taskforce: Liability for AI Harms under the private law of England and Wales

This summer, the UK Jurisdiction Taskforce (UKJT) report on Liability for AI harms highlighted that where a non-delegable duty of care is owed, such as by an NHS Trust to its patients, then a hospital could be vicariously liable for a clinician using AI. Using a “reasonable skill and care standard a professional may be found negligent for using AI inappropriately, for using an unsuitable model, for failing to conduct proper due diligence, or for failing to test AI or validate its outputs effectively. Equally a professional could be liable for failing to use AI in circumstances where a competent member of their profession would have done so.”

The report recognised that in the absence of a relevant contract the question of whether a party is liable for loss caused non-deliberately by using AI will fall to be determined by the law of negligence. In essence, the UKJT ‘s conclusion was that existing principles of contract and negligence can address AI liability harms without the need for more bespoke AI liability legislation.

National Commission into the Regulation of AI in Healthcare: Recommendations for a future regulatory framework

The central conclusion of the National Commission into the Regulation of AI in Healthcare is that “the regulation and assurance of AI in healthcare must become more proportionate, lifecycle-based and system-wide”. A cross-government response will follow separately, setting out how government and system partners will consider and take forward the 44 recommendations. It also concluded that clinical negligence law remains suitable for claims involving AI in healthcare while recognising concerns around allocation of responsibility between manufacturers, health providers, clinicians and regulators.

NHS Resolution guidance on scheme coverage and liability issues concerning the use of Artificial Intelligence (AI)

Finally, NHS Resolution recently published their guidance on scheme coverage. This guidance specifically confirms that medical care which involves the use of AI is covered by NHS Resolution’s existing indemnity schemes but also points out that “failure to have appropriate contracts in place may result in the organisation being responsible for additional liabilities”. Organisations should maintain governance frameworks and staff training on purpose, use and limitations of AI. Patient communication around use of AI should also be offered, and monitoring and oversight of AI tools should be put in place.

All of this arises in a context in which the public is increasingly aware of the potential risks AI poses, as well as the benefits.

Practical considerations

In the context of legal liability for AI, the above documents look to bridge the liability gap. Sufficient evidence to show all reasonable precautions were taken to assess and manage foreseeable risks in adopting AI should help in a successful defence to a negligence claim.

However, if a health provider is found liable, then to seek a route of recovery via a contractual indemnity from a third-party AI supplier or developer, it is imperative that the health provider can supply:

  • Contracts with third parties with clear reference to appropriate liability levels, standards and warranties
  • Information from suppliers and developers as to the capability of AI software and bias testing
  • Evidence of testing, monitoring and updating of different versions
  • Documentation around guidance, training and regulatory approval
  • In NHS commissioned or provided services, giving effect to Information Standards DCB0160 and DCB0129 developed by NHS England. These help to ensure that digital technology is properly assessed for clinical risks before use in patient care. DCB0129 sets out requirements for technology manufacturers, and DCB0160 covers how health and social care organisations deploy and use these systems safely. These Standards are currently under review by NHS England, and the revised versions will need to be considered once published.
Conclusion

Disclosure around AI implementation will be a key part of future litigation, but being able to evidence that disclosure will both protect organisations and provide a potential route for recovery from a third party. In the same way as preparing for a data breach crisis, healthcare organisations using AI should prepare for potential litigation by considering what documentation is available to show good governance.

To hear more about the use of AI in healthcare, register for our upcoming webinars in Capsticks’ ‘Digital transformation in healthcare’ series.

A session on Thursday 12 November 2026 will provide an information law update and explore how to manage the influx of SARs and FOI requests made via AI.

A session on Tuesday 8 December 2026 will look specifically at this issue of bridging the liability gaps and minimising risk.

How Capsticks can help

Capsticks’ digital healthcare team can advise on all aspects of purchasing and integrating AI into your organisation or developing your own AI, including consideration of issues ranging from data management and sharing information to procurement, employment issues and litigation risk management. For further information, please contact Partner Majid Hassan or Partner Andrew Latham.