Insight
AI Liability and Governance: Who Is Responsible When the Algorithm Decides?
The accountability gap in artificial intelligence has moved from theoretical debate to live regulatory obligation. Senior counsel advising boards and in-house teams need a clear picture of where liability falls in 2026.
· 3 min read · By Jonathan Hirasawa Ashton – Managing Partner, UAE
The Accountability Problem in Context
On 18 May 2026, a California jury dismissed Elon Musk’s lawsuit against OpenAI and Sam Altman in under two hours, finding the claims time-barred under the applicable statute of limitations. The procedural outcome masked a far more significant governance question that remains unanswered: when an organisation constructs its entire commercial identity around a stated public mission and then quietly restructures to monetise that mission for private benefit, what legal obligations does it carry to those who relied on that representation?
The jury never reached the merits. OpenAI’s legal team established in closing arguments that the donations were unrestricted and that no binding promise had been made to maintain the nonprofit structure. Both propositions may be legally accurate. They do not resolve whether the governance failure was actionable under a different theory, in a different jurisdiction, or against a differently drafted founding document.
For in-house counsel and boards advising on AI governance, the lesson is not that mission statements are irrelevant. It is that mission statements which are never documented as enforceable commitments create exactly the kind of liability gap that produces expensive litigation, even where that litigation ultimately fails.
The UAE AI Act 2026: Operative Obligations
The UAE AI Act 2026, which entered into force in March 2026, is the primary domestic framework governing AI liability in the UAE. It establishes a four-tier risk classification for AI systems: minimal risk, limited risk, high risk, and unacceptable risk. The classification determines the compliance obligations that attach.
High-risk AI systems, defined to include applications in healthcare, financial services, employment and recruitment, educational assessment, critical infrastructure management, law enforcement, and border control, carry the most demanding obligations. These include mandatory conformity assessments, technical documentation, data governance requirements, human oversight mechanisms, accuracy and robustness standards, and post-market monitoring obligations. The self-assessment deadline for high-risk systems falls in September 2026.
Penalties for non-compliance reach AED 10 million per violation. Where non-compliance involves an AI system that causes material harm, the penalty framework operates alongside civil liability under the UAE Civil Transactions Law, which may permit affected parties to seek damages independently of regulatory action. Companies should not treat the AED 10 million figure as a ceiling on total exposure. It is a floor on regulatory liability only.
Extraterritorial Reach: The EU AI Act
The EU AI Act becomes fully applicable on 2 August 2026. Its extraterritorial scope is explicit: any provider whose AI system produces outputs used within the European Union is subject to the Act, regardless of where that provider is incorporated or established. For GCC companies with European commercial relationships, distribution agreements, or digital services accessed by European users, EU AI Act compliance is not optional.
The Act’s transparency obligations require that AI-generated content be labelled as such in certain use cases, and that users of high-risk AI systems be informed that they are interacting with an AI. These obligations apply to deployers as well as developers. A GCC business that licenses AI tools from a third-party provider and deploys them in customer-facing applications is a deployer within the meaning of the Act and carries corresponding obligations.
Governance Documentation: The Practical Obligation
The OpenAI litigation and the UAE and EU regulatory frameworks converge on a single practical point: governance documentation matters. The gap between what an AI system’s published principles say it will do and what it actually does is a compliance surface, not merely a reputational one. Boards should ensure that AI governance policies are reviewed by legal counsel for internal consistency, that the obligations they create are understood by technical and operational teams, and that post-deployment monitoring is sufficient to identify divergence early.
For businesses in the GCC that are early in their AI governance journey, the most practical starting point is a system inventory: identify every AI application in use, classify it against the UAE AI Act framework, and document the basis for that classification. That documentation is itself a compliance asset, and its absence is an early indicator of systemic governance risk.
This article is general information about the law at the date of publication. It is not legal advice and should not be relied on as such. For advice on your circumstances, talk to counsel.


