Who Is Liable When AI Causes Harm? Rethinking Tort and Criminal Liability
Artificial Intelligence (AI) is rapidly becoming part of everyday life. From healthcare and banking to autonomous systems and generative AI, machines are fastly making or influencing decisions that affect people. But when an AI system causes harm, an important legal question arises: who should be held responsible? The developer, the company, the user, or the AI system itself?

Indian law currently does not acknowledge AI as a legal person capable of bearing independent liability. Therefore, responsibility must generally be traced to the human beings or legal entities involved in developing, deploying, controlling, or misusing the system. The challenge is that traditional principles of tort and criminal law were developed around human conduct, while AI systems can produce unpredictable outputs without direct human instructions.
In tort law, liability may arise where a person suffers injury because of negligence, defective products, or wrongful conduct. If an AI-powered medical system gives an incorrect recommendation, for example, determining liability could involve the hospital, doctor, software developer, or manufacturer. The key problem would be identifying who had control over the risk and whether reasonable precautions were taken.
The issue becomes more complicated with autonomous systems. AI models learn from enormous datasets and may create outputs that their developers could not specifically predict. India’s earlier policy discussions on AI liability have recognised this complexity and suggested reviewing existing laws, particularly in sectors such as healthcare, transportation and finance.
A possible future route is to distribute liability according to control, knowledge and participation. A developer who negligently designs an unsafe system should not run from responsibility merely because the final harmful decision was generated by an algorithm.
Criminal liability presents an even greater challenge because criminal offences generally need both a prohibited act and, where applicable, a guilty mental state. AI itself cannot presently possess legal mens rea. Consequently, criminal responsibility must ordinarily be attributed to a human actor whose conduct satisfies the requirements of the relevant offence.
For example, if an individual deliberately uses an AI system to create fraudulent documents, deepfakes or other unlawful content, the fact that AI generated the material should not automatically protect the user from prosecution.
Recent developments in India demonstrate this approach. The 2026 regulatory framework concerning synthetically generated information places specific due-diligence obligations on intermediaries and addresses unlawful AI-generated content. The Ministry of Electronics and Information Technology has also clarified that existing IT Act duties apply to AI-enabled systems rather than creating a separate legal category simply because content is AI-generated.
A practical legal framework should consider three factors: who created the risk, who controlled the system, and who could reasonably have prevented the harm. Developers may be liable for negligent design; companies may bear responsibility for inadequate safeguards; users may be liable for intentional misuse; and operators may be responsible where they ignore known risks.
Recent Indian litigation involving generative AI also demonstrates how difficult it is to fit modern AI systems into existing legal categories. In IndiaMART InterMESH Ltd. v. OpenAI Inc., the Delhi High Court noted the difficulty of applying the pre-AI IT Act structure to contemporary generative AI and discussed whether liability should be distributed between developers and users according to their control and participation.
AI should not become a legal “black box” where nobody is responsible because a machine produced harmful results. At the same time, imposing automatic liability on developers for every unpredictable AI output could discourage innovation.
The better idea is a risk-based model of liability, combining negligence, product liability, intermediary obligations and existing criminal law. As AI becomes more autonomous, India may eventually need dedicated legislation defining responsibilities across the AI lifecycle.
The central principle should remain simple: innovation may be automated, but accountability cannot be.
