Introduction
Artificial intelligence (AI) systems—from autonomous vehicles and industrial robots to generative large-language models—are transforming how decisions are made and actions are executed across society. Yet these same qualities of autonomy, opacity, and unpredictability challenge the foundational principles of criminal law, which historically require a voluntary act (actus reus) and culpable mind (mens rea). Jurisdictions worldwide are crafting new liability regimes to ensure accountability for AI-caused harms. India, too, faces this imperative, relying initially on existing criminal statutes while policymakers and scholars propose bespoke reforms. This explainer surveys global liability models and examines India’s current stance and emerging proposals, concluding with recommendations for a coherent, future-ready framework.
I. The Global Liability Landscape
A. European Union: AI Act and Liability Directive
The EU’s Artificial Intelligence Act (AI Act) classifies AI applications by risk and imposes compliance duties on providers and deployers—especially for “high-risk” systems. The now-withdrawn AI Liability Directive (AILD) proposed a rebuttable presumption of causation when a claimant shows that a defendant breached an AI Act duty (e.g., inadequate human oversight) and that breach “reasonably likely” influenced the harm. It also envisaged enhanced access to technical logs and design documents to support evidence gathering. Although the AILD was shelved in February 2025 for lack of consensus, EU member states must still interpret national tort rules in light of AI Act standards, ensuring that fault-based claims can proceed where AI compliance duties are violated.
B. United States: Sectoral Enforcement and DOJ Guidance
Absent a comprehensive federal AI statute, the U.S. relies on sectoral laws and existing criminal statutes. In August 2024, the Department of Justice recommended a sentencing enhancement for offenses where AI “significantly contributed” to planning, execution, or concealment, signaling that AI misuse can aggravate criminal punishment. High-profile prosecutions include wire-fraud charges against a startup founder accused of “AI washing”—misrepresenting labor-intensive or rudimentary automation as cutting-edge AI to defraud investors. Federal agencies like the FTC and SEC similarly deploy consumer-protection and securities laws to address deceptive AI claims.
C. United Kingdom: Common Law Adaptation
The UK’s National AI Strategy and draft Data Protection and Digital Information Bill envisage statutory guidance on AI safety and fairness, borrowing risk-based concepts from the EU. Courts are already applying negligence and breach of statutory duty doctrines to algorithmic decision-making, assessing whether deployers met a reasonable duty of care when designing or operating AI.
D. Singapore: Model Governance Frameworks
Singapore forges a multi-agency, principles-based approach. Its Model AI Governance Framework (A*STAR 2020) and sectoral codes mandate human oversight for high-risk AI, robust transparency measures, and collaboration on cross-border evidence sharing for AI-facilitated online crimes under the Online Criminal Harms Act. While it lacks a standalone AI liability law, its best practices shape a pragmatic, risk-calibrated model.
E. Comparative Liability Models
Scholars outline four paradigms for AI criminal liability:
- Instrumentality Model: AI as a tool; humans (operators, programmers) bear full liability.
- Foreseeability/Negligence Model: Liability for actors who fail to foresee and mitigate AI-caused harms.
- Direct AI Personhood Model: Granting limited legal personality to AI (sui generis entities) capable of mens rea/actus reus analogues.
- Strict Liability for High-Risk AI: No-fault liability for developers or deployers of enumerated high-risk systems, coupled with mandatory insurance.
II. India’s Current Legal Framework
A. Reliance on Existing Statutes
India has not yet enacted dedicated AI liability legislation. In the interim, AI-related harms fall under established criminal laws:
- Indian Penal Code, 1860 (IPC): Traditional offenses—such as causing death by negligence, assault, or destruction of property—apply when AI systems cause harm, attributing liability to individuals whose actions or omissions led to the harm.
- Information Technology Act, 2000 (IT Act): Sections 43 and 66 cover unauthorized access, data breaches, and cyber-enabled offenses, including those committed via AI-powered tools.
- Bharatiya Nyaya Sanhita, 2023 (BNS): India’s new criminal code, set to replace the IPC, retains core mens rea and actus reus principles but does not yet expressly address AI autonomy.
B. Judicial Oversight and High Courts
High Courts and the Supreme Court have acknowledged AI’s expanding role in case management, forensic analysis, and predictive policing, emphasizing that any AI deployment must respect constitutional rights to fair trial, equality, and privacy. Courts have used existing statutes to regulate AI in policing—mandating transparency in algorithmic risk assessments—and excised invasive surveillance lacking legal safeguards.
C. Academic and Policy Analyses
Legal scholars identify foundational challenges: AI systems lack human-like intentionality, creating conceptual strains when applying actus reus and mens rea; autonomous “black-box” algorithms resist straightforward causal attribution; and no entity currently holds exclusive responsibility for AI’s emergent actions. Researchers propose preliminary solutions:
- Treat AI as an “innocent agent,” attributing liability to programmers when instructions foreseeably cause harm or to users when misuse of AI leads to offenses.
- Impose negligence liability on developers for faulty AI designs and on deployers for foreseeable harms, drawing on comparative models of gross-negligence in medical jurisprudence.
- Explore sui generis electronic personhood for highly autonomous AI, paralleling EU discussions of “electronic persons” under civil law.
III. Emerging Indian Proposals for AI Liability
A. Draft “Crafting a Liability Regime for AI Systems in India”
An expert report advocates a risk-based liability regime aligned with international best practices. Key recommendations include:
- Tiered liability: Strict liability for high-risk AI (autonomous vehicles, medical devices); negligence-based liability for lower-risk applications.
- Rebuttable presumption of causation: Borrowing from the EU’s AILD, easing evidence burdens by presuming that failures in human oversight or system robustness contributed to harm.
- Mandatory insurance: Requiring operators to secure financial coverage for AI-caused damages, ensuring prompt victim compensation.
- Transparency obligations: Compulsory logging of AI decisions and maintainable audit trails to facilitate investigations and prosecutions.
B. Regulatory Sandboxes and Standards
Policymakers contemplate regulatory sandboxes—time-limited, supervised environments where novel AI applications can be tested under prescribed safeguards, mirroring the UK’s and EU’s sandbox proposals. Concurrently, India’s Bureau of Indian Standards and MeitY are developing AI quality and safety standards to codify technical requirements for robust AI systems.
C. Human Oversight and Ethical Governance
Building on Singapore’s and EU’s frameworks, proposals urge embedding “meaningful human control” in high-risk AI deployments, mandating:
- Human-in-the-loop review for critical decisions (e.g., law enforcement profiling, bail recommendations).
- Ethical AI boards within organizations to oversee design, deployment, and incident investigation.
- Periodic impact assessments (akin to EU’s DPIAs) to identify and mitigate privacy, fairness, and safety risks.
IV. Policy Implications and Practitioner Guidance
A. Harmonize Domestic and International Standards
India should align its forthcoming AI liability rules with global risk-based regimes—particularly the EU AI Act’s classifications—while adapting negligence and strict-liability doctrines to local contexts.
B. Enact Foundational AI Legislation
Parliament must draft an AI Accountability Act incorporating:
- Clear definitions of AI autonomy levels and corresponding liability tiers.
- Rebuttable causation presumptions and evidence-disclosure protocols.
- Mandatory AI incident reporting and public registries of high-risk deployments.
C. Strengthen Judicial Capacity
Courts require technical expertise—through judicial training and expert panels—to interpret AI logs, assess compliance with technical standards, and adjudicate liability fairly.
D. Foster Multi-Stakeholder Collaboration
Effective regimes demand tripartite dialogue among government agencies, academia, industry, and civil society to iterate standards, update statutes, and ensure adaptive governance.
Conclusion
AI’s disruptive potential necessitates that criminal law transcend its anthropocentric roots, blending established fault-based models, risk-based regulatory duties, and strict-liability mechanisms to ensure accountability for AI-caused harms. India’s reliance on legacy statutes is a stopgap; its next frontier lies in bespoke AI liability legislation, harmonized with international best practices and underpinned by robust human-oversight mandates. Only through such evolution can India safeguard public safety, uphold justice, and foster responsible AI innovation.
