AI and the Law in Hong Kong: Who Is Liable When an AI System Causes Harm?

AI and the Law in Hong Kong: Who Is Liable When an AI System Causes Harm?

AI and the Law in Hong Kong: Who Is Liable When an AI System Causes Harm?

Abstract — Hong Kong currently has no standalone AI statute, so AI liability Hong Kong-side is decided by existing law: negligence, contract, product and data-protection rules, and intellectual-property law. When an AI system causes harm, the question is usually who is responsible, the developer, the business that deployed it, or the user, and existing doctrines were not designed for autonomous, "black box" systems. Regulation so far is principles and guidance, not legislation. This guide explains the current framework, the liability gaps, the regulatory outlook, and what businesses should do now to manage the risk.

 

Introduction

Artificial intelligence is already making decisions that affect real people in Hong Kong, from credit scoring to medical triage to automated customer service, and when one of those decisions goes wrong, someone bears the loss. Yet artificial intelligence law HK 2026 is not found in a single dedicated statute. Instead, AI liability Hong Kong questions are answered by adapting long-standing legal principles to a very new technology. This guide explains how that works, where the law strains, and how the AI regulation Hong Kong picture is developing, so that businesses can understand their exposure before a problem arises rather than after.

 

Current Hong Kong legal framework

There is no AI-specific liability law in Hong Kong. When an AI system causes harm, claims are built from existing building blocks:

 

Negligence. If a developer, deployer or user owed a duty of care and failed to take reasonable care, and that caused foreseeable harm, ordinary negligence principles can apply.

Contract. Agreements between AI vendors, businesses and customers allocate risk, set warranties, and frequently try to limit or exclude liability (subject to the Control of Exemption Clauses Ordinance (Cap. 71)).

Product and consumer law. Where AI is embedded in a product or service, sale-of-goods and consumer-protection rules, including the Sale of Goods Ordinance (Cap. 26) and the Trade Descriptions Ordinance (Cap. 362), may be engaged.

Data protection. Using personal data to train or run AI must comply with the Personal Data (Privacy) Ordinance (Cap. 486).

Intellectual property and defamation. AI outputs can infringe copyright or trade marks, or publish defamatory content, with liability falling on those responsible for the output.

 

In short, the law already provides several routes; the difficulty is fitting them to how AI actually behaves.

 

Liability gaps

AI strains traditional liability in specific ways:

 

The "who" problem. A single harmful output may involve a model developer, a company that fine-tuned and deployed it, a data supplier, and an end user. Allocating responsibility among them is rarely straightforward.

Causation and the "black box". Where even the developer cannot fully explain why a model produced a given output, proving the chain of causation that negligence requires is harder.

Foreseeability. Autonomous systems can behave in ways their makers did not specifically anticipate, testing the boundaries of what harm was "reasonably foreseeable".

Standard of care. What counts as "reasonable care" in building, testing and monitoring an AI system is still being worked out.

 

These gaps do not mean no one is liable. They mean liability is contestable, which is precisely why clear contracts and good governance matter.

 

Regulatory outlook

Hong Kong's approach to AI governance Hong Kong-wide has so far been principles-based guidance rather than hard legislation. Regulators and public bodies have issued frameworks and expectations, for example guidance from the Privacy Commissioner for Personal Data on the ethical use of AI and on protecting personal data in AI systems, and sector guidance (such as for financial institutions) on adopting AI responsibly. The common themes are human oversight, risk assessment, transparency, fairness and accountability. Businesses should expect this guidance to harden over time, and should treat alignment with it as the practical standard of care today.

 

Sector-specific expectations

Even without a general AI law, some sectors already face concrete expectations. Financial regulators, for example, expect institutions adopting AI, including generative AI, to maintain proper governance, risk management and human accountability, and to treat customers fairly when AI informs decisions. Professionals such as doctors, lawyers and engineers remain bound by their existing duties of competence and care when they use AI tools, so "the model did it" is not a defence to a professional lapse. The practical takeaway is that your industry's existing rules already shape how you may use AI, and they should be the first place you look, alongside the cross-sector data-protection and consumer rules.

 

Recent developments

AI legal liability has moved rapidly up the agenda in Hong Kong's legal and business community in 2026, featuring prominently in professional and industry discussions. The direction of travel is clear: more guidance, more regulatory attention to how personal data feeds AI, and growing pressure on businesses to document how their AI systems are governed. What has not changed is the underlying point that, until any dedicated statute arrives, AI harm is judged through existing negligence, contract, data-protection and IP law. Organisations that build strong governance now will be better placed whether or not specific AI legislation follows.

 

A worked example

Imagine a Hong Kong clinic that uses an AI tool to triage patients, and the tool wrongly downgrades an urgent case, causing harm. Who is exposed? The clinic that deployed the tool may face a negligence claim if it failed to supervise the system or ignored its limits. The developer may face contractual claims from the clinic, and potentially a negligence claim, depending on how the tool was built and what it promised. The contract between them will be scrutinised for warranties and liability caps. If the tool was trained on patient data without proper consent, the Personal Data (Privacy) Ordinance (Cap. 486) is engaged as well. One incident, several overlapping claims, and no single "AI statute" to resolve them: that is the reality of AI liability in Hong Kong today.

 

A practical governance checklist

Until dedicated legislation arrives, good governance is both risk management and evidence of reasonable care:

 

Keep a human in the loop for consequential decisions, with the ability to review and override.

Assess risk before deployment, and document the assessment.

Vet and contract with vendors carefully, addressing data, security, liability and audit rights.

Be transparent with affected people about when and how AI is used.

Monitor and log the system's performance, and act on errors.

Align with regulatory guidance, including the Privacy Commissioner's expectations on AI and personal data.

 

A business that can show this kind of governance is far better placed if something goes wrong, whatever shape future regulation takes.

 

FAQ

1. Is there an AI law in Hong Kong?
Not a standalone one. AI-related harm is currently addressed through existing negligence, contract, consumer, data-protection and intellectual-property law.

 

2. Who is liable if an AI system causes harm?
It depends on the facts. Responsibility may fall on the developer, the business that deployed the system, or the user, and often a combination, depending on duties of care and the contracts in place.

 

3. Can a business contract out of AI liability?
Contracts can allocate and limit risk, but exclusion clauses are subject to legal controls such as the Control of Exemption Clauses Ordinance (Cap. 71), and cannot always exclude everything.

 

4. Does data-protection law apply to AI?
Yes. Using personal data to train or operate AI must comply with the Personal Data (Privacy) Ordinance (Cap. 486).

 

5. What should my business do now?
Adopt an AI governance framework with human oversight, risk assessments, clear vendor contracts and records, aligned to current regulatory guidance.

 

6. Could the user of an AI tool be liable, not just the developer?
Yes. A business that deploys or relies on an AI system can be liable for how it uses it, alongside or instead of the developer.

 

7. Does Hong Kong follow the EU AI Act?
No. Hong Kong has its own approach and currently relies on existing law plus regulatory guidance rather than a single AI statute.

 

8. Will Hong Kong pass a dedicated AI law?
Possibly in time. The current direction is principles-based guidance, with the prospect of regulation under discussion.

 

When to contact a solicitor

Get advice before deploying an AI system that makes consequential decisions, when negotiating AI vendor contracts, after any incident where an AI output caused loss, or if a regulator raises questions. A technology law solicitor HK-side can help you allocate risk and build a defensible governance record.

 

Talk to ask.legal Hong Kong

Deploying AI and unsure where liability sits? Contact ask.legal Hong Kong to be matched with a Hong Kong technology law solicitor who can review your contracts, governance and risk.

 

Sources and further reading

Personal Data (Privacy) Ordinance (Cap. 486); Control of Exemption Clauses Ordinance (Cap. 71); Sale of Goods Ordinance (Cap. 26); Trade Descriptions Ordinance (Cap. 362).

Office of the Privacy Commissioner for Personal Data (PCPD), guidance on AI and data protection: https://www.pcpd.org.hk

 

About the author: prepared by the ask.legal Hong Kong editorial team.

Last updated: June 2026.

This article is general information about the law of Hong Kong as at 2026, not legal advice. For advice on your circumstances, consult a qualified Hong Kong legal practitioner.

 

Back to the blog