Monday, 10 August 2026

If the computer is not accountable, who is?

“A computer can never be held accountable
Therefore a computer must never make a management decision”

So went a famous internal IBM training manual in 1979.

As a piece of management advice, it is impeccable. It would be foolish indeed to entrust a highly consequential decision entirely to a computer. And yes, in management terms a computer cannot be held accountable. It can’t be hauled up before a disciplinary committee. You can’t put the computer on a warning. You can’t cut its bonus. You can’t send it on a training course (at least then, you couldn’t). You can sack it: pull out the plug and hope that it hasn’t figured out a way of surviving without power; but woe betide whoever does that without first checking with the business.

However, the adage is normally taken to be about the law: accountability meaning legal liability. This IBM blogpost in 2025 understood it that way.

If the manual was indeed talking about legal liability, the first line may have been making the point that a computer does not have a separate legal personality and so cannot itself be sued for a mistake. That is true. But does it necessarily follow that a computer must never make a management decision? Perversely, some might welcome the opportunity to have decisions made that can’t be dragged through the courts.

In fact there is a good legal reason for being cautious about allowing a computer to make a decision; but the reason is not that the computer cannot be made legally liable, but that some human being or corporation behind it can be. The computer’s decision can readily be attributed legally to some individual or corporate person.

This has all become topical again with the rise of AI – indeed AI was the subject of that 2025 IBM blog. The UK Jurisdiction Task Force has recently published a Legal Statement on Liability for AI Harms. Its 130 pages discuss exhaustively how civil liability can arise for harm resulting from use of AI, and who can be liable for what. The message is that, despite the output of AI systems being indeterminate, AI harm fits well into the existing common law framework which can readily adapt to cope with such uncertainties as may exist.

There is one topic that the Task Force Statement only touches on: how legal liability is attributed to a corporate body (as opposed to an individual). The Statement explains how an employer (which may include a corporation) can be vicariously liable for the acts of its employees, but does not discuss (beyond a brief reference in a footnote) the mechanism, set out by Lord Hoffmann in the Meridian Privy Council decision, by which a corporation can become directly liable for activities carried out on its behalf. The Meridian framework (which emphasises a flexible, purpose-oriented approach) applies to both statutory and common law torts.

If liability is direct rather than vicarious, then the corporation would be regarded as itself making a misstatement. For negligent misstatement purposes (for instance) the question would then be whether it owes a duty of care (which would be fact-dependent) and if so whether it breached the relevant standard of care in making the misstatement.

Discussion of a corporation’s liability for the misdeeds of its computer systems would not be complete without mention of the Court of Appeal decision in Ferguson v British Gas. The background was that British Gas’s computerised debt collection system had, over a period of five months, sent out erroneous bills and letters to their former customer, Ms Ferguson (including threats to cut off her gas supply, to start legal proceedings and to report her to credit rating agencies). Her numerous complaints were in vain. Finally she sued British Gas for harassment.

British Gas sought to strike out the harassment claim on the basis that neither the acts of its automated billing system, nor the required knowledge for harassment, could be attributed to the corporation.

The Court of Appeal was having none of it. Without deciding the attribution point, (which was incompletely argued before it, albeit the court referred to Meridian), the court dismissed the strike-out application on the basis that it was arguable that, as a matter of either direct or vicarious liability, the conduct and relevant knowledge could be attributed to British Gas; or at least that there was insufficient evidence before the court to enable it to decide the issue.

Jacob L.J. (with whom Sedley L.J. agreed) appears to have assumed that the conduct of the billing system was attributable to British Gas, then went to consider the more difficult question of knowledge. Lloyd L.J. identified (but did not decide) a broader issue which included the question of whether it was necessary (as a matter of construction of the legislation in question) to identify any individual who engaged in the relevant conduct: 

“the policy issue, as a matter of the true interpretation of the Act, whether conduct carried out in the course of the business of a particular body is to be attributed, for the purposes of this Act, to that body as a whole regardless of whether any one individual within the organisation was doing it all, or knew of it all being done, and if so at what level in the organisation that person was operating.”

The flexible ‘attribution rule’ approach of Meridian, with its shift away from anthropomorphic approaches to corporate liability, could mean that identifying such a human being is no longer necessary. Even if that is taking Meridian too far, the task would be approached with due regard to context and purpose of the liability under consideration. 

The observations of Sedley L.J. in Ferguson were particularly trenchant:

“One excuse which has formed part of British Gas's legal argument for striking out the claim, and which has been advanced as incontestable and decisive, is that a large corporation such as British Gas cannot be legally responsible for mistakes made either by its computerised debt recovery system or by the personnel responsible for programming and operating it. The short answer is that it can be, for reasons explained by Lord Justice Jacob. It would be remarkable if it could not: it would mean that the privilege of incorporation not only shielded its shareholders and directors from personal liability for its debts but protected the company itself from legal liabilities which a natural person cannot evade. That is not what legal personality means.”

If the computerised bill system had been AI-driven, one wonders how impressed the Ferguson court would have been with distinctions between determinate and indeterminate computer outputs. That speculation aside, when considering corporate tortious liability for AI errors it seems likely that at some point the Meridian framework will come into play.


No comments:

Post a Comment

Note: only a member of this blog may post a comment.