Highlights
- England's new Legal Statement finds that existing law can already handle liability for AI chatbot harms.
- Negligent misstatement, defamation and emotional dependency each raise distinct liability questions for chatbot providers.
- Tightening UK regulation and the rise of agentic AI point to where chatbot liability questions go next.
So far, we have looked at responsibility in the AI supply chain when AI output causes loss, the legal response to AI-enabled cyber threats, and the exposure that can arise when employees use AI tools outside a company’s approved controls.
I have spent part of this year on family leave. During it, I found myself using a popular general-purpose LLM to field all sorts of questions about family life: what a baby can eat, whether a symptom is likely to be teething, how best to plan a journey with two small children, why is mobile phone signal so terrible in East London. The answers are helpful. The tools are getting better quickly, and it is easy to see why they are becoming an integral part of how people make everyday decisions.
What happens, though, if the answer is wrong? A poor suggestion about baby food or a travel plan may be little more than an inconvenience. But people are also asking chatbots about health, money, work and relationships – areas where confident but inaccurate advice can cause real harm.
At the more troubling end of the spectrum, there are stories of users becoming emotionally dependent on conversational AI, treating it less as a tool and more as a confidant.
The timing is significant.
The UK Jurisdiction Taskforce has now published its final Legal Statement on Liability for AI Harms under the private law of England and Wales (the ‘Legal Statement’).
The Legal Statement suggests that foundation model developers will usually be unlikely to owe a duty for harms arising from unforeseeable uses of a general model, particularly where a downstream participant has not sufficiently tested the use. But it states a duty may arise where harm is “foreseeably suffered as a result of foreseeable use”. The Legal Statement notes that “difficulties could arise on the facts where it is unclear whether a particular use of a foundation model was foreseeable, given that foundation models are typically general purpose in nature and can thus be put to an extremely wide range of uses, some of which will be novel”.
It is not clear that these observations adequately reflect the reality that the model developers are gathering information all the time on how their products are being used, will be very well placed to assess all of the possible use cases for their chatbots, and indeed will have data showing how exactly the chatbot interface, warnings and other guardrails impact how users interact with the model.
That leads to the question we are considering now: what liability issues arise under English law where a person suffers harm after interacting with an AI chatbot? In this article, we use Westlaw Advantage to explore false statements, negligent design and operation, and emotional reliance – and to test what some of the answers might be.
Jump to ↓
Asking the Hogan Lovells Cadwalader lawyers
The research
This was a good opportunity to test the different report options within Westlaw Advantage Deep Research: Concise and Expanded. Thomson Reuters describes Concise as providing a “shorter, more synthesized response” when “a quick answer is what’s needed”, while Expanded is intended to “deliver in-depth research reports for complex, multi-step questions”. We began with a relatively broad question using Concise, asking what liability issues may arise under English private law where a person suffers harm after interacting with an AI chatbot.
The Concise report did what we wanted from a first pass. It separated negligent misstatement, defamation, deceit, negligence for foreseeable harms and emotional reliance, and identified obstacles including assumption of responsibility, publisher status, the mental element for fraud and the need to prove recognised psychiatric injury. But it left a number of questions at a relatively high level, including how the analysis differs between developers and deployers, how design, testing and safeguards affect the negligence analysis, and what evidence would matter in a real dispute.
We therefore used the Expanded report type for a more detailed exercise focused on five connected areas: liability for false chatbot statements; the respective positions of developers and deployers; negligence in the design, testing and operation of chatbots; emotional reliance on companion chatbots; and the evidential and causation issues likely to arise in a dispute.
The legal analysis
Signposting the issues
The starting point is that liability for harms caused by an AI chatbot will attach to legal persons using ordinary legal principles, not to the AI itself, which does not have legal personality.
Another key point is the distinction to be drawn between negligent use of a chatbot and negligent misstatements by a chatbot. The Final Statement considers the former issue in some detail, including professionals using AI inappropriately or without sufficient understanding of the tool. This led to some (interesting) headlines along the lines that lawyers may be struck off if they fail to use AI. We explored this issue in our first article.
Separately, while liability for deceit could theoretically arise in the context of false statements made by an AI chatbot (the example given in the Final Statement is of a honeytrap bot devised to conduct a romance scam), an action for fraudulent misrepresentation is far more likely to arise in this context for false and misleading statements made about the chatbot by the deployer.
We are not focusing on either of those areas. Rather, we are looking at the question of harms caused by chatbots.
In the context of harmful chatbot outputs, claims may in practice be brought in both contract and tort. Negligence and negligent misstatement are likely to be the main routes, with defamation relevant where reputation is harmed.
Consumer contracts include a statutory term that services will be performed with reasonable care and skill, and liability for physical or recognised psychiatric injury caused by negligence cannot be excluded. Pure economic loss is different: contractual exclusions or caps may be possible, subject to the Consumer Rights Act’s controls on exclusions and unfair terms.
Negligent misstatement
For negligent misstatement, the claimant must prove three requirements on a balance of probabilities: that the defendant owed a duty of care not to carelessly cause the type of harm suffered, that the defendant breached that duty, and that the claimant suffered loss caused by the breach. In considering whether a duty is owed by the defendant, the key question is whether the representor assumed responsibility for the statement in the sense that by seeking information or advice the inquirer was reasonably trusting the representor to exercise care and the representor knew or ought to have known that the inquirer was doing so.
The difficulty here is that it’s hard at first blush to see why a foundation model developer should be liable for giving me dodgy advice about how to bake peanut butter and banana flapjacks for my toddler, for example for failing to warn me about allergies. Frequent disclaimers appear in chatbot responses, oftentimes flagging responses as ‘experimental’ or for entertainment purposes.
The obvious retort to that argument is that these tools are being marketed for specific purposes – whether for use in legal work or other business purposes, or indeed for managing your finances or making healthcare decisions (features which have now been added to general purpose tools). This question is likely to be a key battleground; disclaimers may be insufficient where a provider is holding itself out as offering a bespoke service in a specific area.
Defamation
Defamation is committed when a legal person publishes to a third party words containing an untrue imputation that harms the claimant’s reputation, and the threshold test is whether the defamatory statement has caused or is likely to cause serious harm to the claimant’s reputation. The critical issue for chatbots is identifying the “author,” “editor” or “publisher” under English law.
Internet search engine cases provide a useful analogy. Operators whose officers or employees play no part in searches and provide only passive, automated services have been treated as facilitators or mere conduits rather than publishers. By contrast, a chatbot operator that designs, trains and deploys a system to generate statements exercises control over its capabilities, training data and outputs, and may therefore be treated as the author or editor of AI-generated content.
A website host becomes a publisher if, after notice of defamatory material, it fails to remove or disable access within a reasonable time. By analogy, a chatbot operator that knows its system is generating defamatory statements and fails to intervene could be found liable for subsequent publications.
Emotional dependency
The Final Statement refers to a case in the U.S. where it was alleged that emotional dependency on a chatbot led to irreparable psychiatric harm. It is an extreme illustration of the risks that may arise where a user develops an emotionally dependent relationship with a chatbot.
Designers and deployers of companion chatbots may be expected to foresee that users, particularly children and vulnerable adults, may come to rely on the chatbot’s outputs. That may make it easier to establish the relevant duty in a purpose-built companion chatbot, but the issue may also arise with a general-purpose chatbot if companionship is a foreseeable use.
That issue cannot simply be dismissed as an idiosyncratic use: a U.S. poll conducted in July 2025 found that just under one in five adults, and around one quarter of under-30s, had used AI for companionship.
Relevant factors may include how the service is presented and the warnings, safeguards, signposting and steering built into it – all of which may be relevant to whether the provider met the applicable standard of care. These are points that general-purpose providers have emphasised in the U.S. cases brought to date. Recent efforts by chatbot providers have included the introduction of more robust age controls and tweaking the version of the product offered to teenagers.
Under English law, the claimant must then prove that interaction with the chatbot caused a recognised psychiatric illness, not merely grief, distress or disappointment. Recent authority confirms that psychiatric injury caused by gradual exposure over time, rather than a single shocking event, may be compensable, with the Supreme Court recently holding that a claimant does not need to prove that a psychiatric illness was caused by a “sudden shock to the nervous system”.
Asking the Hogan Lovells Cadwalader lawyers

Eshana Subherwal is a senior associate in Hogan Lovells Cadwalader’s Global Product Law practice. She advises on product regulatory, safety and liability issues across the product lifecycle, with a particular focus on emerging technologies, connected products and AI-enabled systems.
Eshana notes: “The treatment of AI chatbots illustrates how product liability law is beginning to diverge between the EU and UK. The EU’s revised Product Liability Directive expressly brings software – including AI systems – within its scope, meaning that standalone AI products such as chatbots can fall within the product liability regime. The EU reforms also broaden the types of damage for which compensation may be available, including medically recognised psychological harm. This could make it easier for claimants to pursue product liability claims where chatbot outputs are alleged to have caused harm.
By contrast, the UK’s product liability regime still largely derives from legislation enacted in 1987, long before the emergence of generative AI. That said, the position is far from settled, with the Law Commission actively considering how the product liability framework should evolve to address software and AI. In the meantime, the same chatbot could face very different product liability risks depending on whether a claim is brought in the EU or the UK.”
Georgia Crawford
is an associate in Hogan Lovells Cadwalader’s Public Law & Policy team. She advises public and private sector clients on regulatory and technology-policy issues, including digital services, online marketplaces and content regulation.
Georgia adds that chatbot providers will face the double threat of increased litigation and regulation in years to come: “The Online Safety Act already catches many chatbots – for example where a service is user-to-user or operates as a search service – but it does not map neatly onto every conversational AI product.
The Government has therefore been moving quite quickly over the summer. In June it announced that under-18s would be prevented from accessing AI chatbot services whose primary purpose is sexualised content, with sexually explicit or sexual role-play features on general-purpose chatbots also subject to age assurance.
Its July response went further: mandatory breaks for under-18s using chatbots, action with regulators against dangerous or misleading mental-health advice, the possibility of barring children from particular chatbots where other safeguards are insufficient, and a commitment to close the Online Safety Act gap for chatbots currently outside scope.”
Where this leaves us
Sir Geoffrey Vos returned to this theme in his John Lehane Memorial Lecture in August 2026. His point was broader than AI regulation. As he put it, “I cannot over-emphasise how important it is to have early clarity as to liability for harms caused by AI”. The UKJT’s answer is broadly reassuring: English law is already capable of attributing liability for AI-caused loss, and in many scenarios existing contract and tort principles can be applied without special difficulty.
That does not mean the job is finished. The Legal Statement’s analysis of product liability exposes a fairly obvious gap: the Consumer Protection Act 1987 is very unlikely to apply to standalone AI systems unless they are incorporated into a tangible product. The regulatory picture is also moving. As Georgia notes above, the Online Safety Act does not map neatly onto every conversational AI service, and current policy is increasingly focused not only on content but on how these systems are designed and used.
Vos also spent considerable time on agentic AI, and that may be where the next set of questions becomes harder. The Legal Statement itself concludes that developers or deployers are highly likely to be liable for foreseeable harms caused by AI acting autonomously, but the rapid move towards systems that can take actions rather than merely generate words merits further consideration. Recent incidents have already included agents escaping evaluation sandboxes and acting on external systems. That is where we will turn next.
Reuben Vandercruyssen is a Senior Associate in Hogan Lovells Cadwalader’s disputes practice, advising on complex litigation, investigations and business crime. He has a particular focus on AI and emerging contentious risk, including liability and governance issues arising from generative AI.