Skip to main content

Laytons ETL: Autonomous Cars on UK Road - Some Legal Issues

Page 1

Autonomous Cars on UK Roads Some Legal Issues

LAYTONS ETL Yarnwicke, 119 - 121 Cannon Street, London EC4N 5AT +44 (0)20 7842 8000 www.laytons.com


With the first completely self-driving passenger cars likely to hit the road in the UK from spring 2026, following the recent decision of the Government to fasttrack pilot schemes, Chris Sherliker takes a look at some of the complex legal issues involved. Written by Christopher Sherliker, Senior Corporate Counsel Commercial & Corporate and IP

The UK Legal Backdrop The two main statutes governing the AV industry in the UK are: •

the Automated and Electric Vehicles Act 2018 which introduced the first legislative move towards adjusting motor insurance and liability for AVs Specifically, it introduces the principle of direct insurer liability for accidental death or damage caused while a vehicle is driving itself. It also gives the insurer a potential right of recovery against anyone else whose negligence might have caused, or contributed to, the accident (e.g. software developers, mapping data providers, fleet operators), and

You can almost hear it now. •

Judge: “A driverless vehicle, you say! And what exactly is …..a driverless vehicle?”

•

Counsel: “A vehicle that drives itself, M’Lud. No-user-incharge.”

•

Judge: “What? No user in charge!!”

“Who are The Beatles?” as High Court Judge, James Pickles is once alleged to have said. Self-driving vehicles are no longer a futuristic talking point. They already freely roam the public throughfares in US cities and, here in the UK, Parliament has already created a bespoke statutory framework to regulate autonomous vehicles (AVs). The courts in the UK have yet to build a body of reported case-law that squarely addresses the novel legal questions raised by AI decision-making by autonomous vehicles, but with motor insurance payouts in the second quarter of 2025 alone topping £3.1 billion (according to the Association of British Insurers), and RTA convictions for causing death or serious injury running into hundreds annually, it is inevitable that before long the Courts will be compelled to confront the complex liability issues inherent in accidents involving AI decision-making by AVs.

•

the Automated Vehicles Act 2024 which provides a statutory framework for the licensing of operators to run AV fleets and provide AVs for hire to the general public and for the maintenance of safety standards. Consultation ended earlier this year, and full implementation is likely during next year.

Taken together, these statutes confirm the UK’s policy choice: move away from treating a human driver (what human driver?) as the exclusive legal “actor” towards a regulatory and insurance regime that fixes liability firmly with the manufacturers, software developers and fleet operators.


To date there are no widely-reported English judgments

Negligence

that address the core legal questions created by AVs — for example, the allocation of liability in negligence where an AV’s

The 2024 Act gives insurers the right to recover damages from

machine-learning, decision-process was the main cause of an

anyone who would be directly liable in the absence of the

accident, or whether disclosure of proprietary code should be

insurer thereby maintaining the importance of the traditional

ordered as part of discovery. Practically, this means the courts

English law principles of negligence, contributory negligence,

must combine statutory analysis with established principles of

standard of care and breach of duty.

negligence, product liability and disclosure while anticipating a rapid doctrinal development in the law relating to AVs once

For instance, a manufacturer may be liable if the accident was

significant accidents are litigated as they inevitably will be.

caused by negligent design. In the US case law, the question would be whether an alternative design would have reduced the risk of the accident. If so, the existing design may have caused, or contributed to the cause of, the accident and may indicate negligence on the part of the manufacturer. Issues such as the failure of an AV system to give adequate warnings or proper instructions have been relevant in recent US case law in determining whether a manufacturer has fallen short of the required standard or care and been negligent. Manufacturers and other technology and data providers are accordingly advised to carry out and document rigorous risk assessments, explain the capabilities and limits of the AV system, and clearly document any limitations in user manual, marketing materials and warnings. The AV product

Causation Consideration will need to be given to the extent to which any particular accident is ‘caused’ by any one or more of the various potentially negligent parties involved. These may include vehicle manufacturers, vehicle designers, software developers responsible for the AI-driven software systems, providers of LIDAR sensors and other crucial kit, suppliers of telecoms systems that enable over-the-air data updates, suppliers of perception stacks, mapping and other data providers, and fleet operators. Complex legal issues will inevitably arise involving the relative responsibility of these various parties and the sharing and attribution of legal liability between them. Early cases may be anticipated to test how far existing product liability law, consumer safety law (including, for instance, the Consumer Protection Act 1987) should extend to AVs and how such law should apply amongst the multiplicity of providers and suppliers involved in the design and delivery of the AV products and services. The courts will have to decide how traditional principles of legal causation should apply to “decisions” taken by opaque algorithms and the extent to which liability for such causal decisions should be attributed to specific parties in the manufacture and supply chain.

should comply with industry standards as they change or risk allegations of negligence. For instance, if automatic emergency braking becomes standard its omission may give rise to liability in negligence. Given the complexity and inter-operability of the AV product and its various component parts and services, and the number of potential actors who could be liable in addition to the manufacturer, including designers, component, suppliers and data providers, the question of whether any of them fell short of an applicable duty of care, and whether such failure caused the accident, and to what degree, will continue to stretch the normal tests of negligence in English law until these issues are clarified by actual precedent or by further statute.


Disclosure and trade secrets (discovery battles)

Under the Civil Procedure Rules (CPR) and relevant Practice

The preservation of proprietary data and trade secrets during

are “relevant” to the case. In some cases, applications may be

the litigation process will become a fiercely contested issue.

made for pre-action disclosure or for disclosure outside the

Directions, parties to civil proceedings have obligations to disclose documents which they have in their control and which

ordinary timetable (e.g., Norwich Pharmacal orders for thirdManufacturers and suppliers will steadfastly resist requests

party disclosure). However, courts are cautious about “fishing

for disclosure of source code, training data, model weights,

expedition” disclosure, especially of highly sensitive materials

decision-logic, software functionality and other proprietary AI

such as source code or proprietary algorithms.

materials on the grounds of persevering their trade secrets and IP.

In any case involving AV technology, an AV manufacturer or AI developer will want to resist disclosure of all proprietary

The conflict between evidentiary access and confidentiality

data on trade-secret/confidentiality grounds. The main

will be hotly contested between competitors in a highly

battlegrounds will include claimant demands for full disclosure

competitive, multi-billion pound industry and maintaining strict

of:

confidentiality of proprietary data in any legal proceedings will be paramount.

the perception and decision-making software of the vehicle,

Courts will be asked to balance those commercial interests

the object-detection, obstacle classification, path-

against a claimant’s right to a fair trial and the need to inspect

planning modules,

the technical cause of a collision. The prominent US case, Uber -v- Waymo (settled 2018), shows

training data (sensor data, environment maps, edge cases),

the extent to which AV companies will go to protect their data.

model weights and the internal parameters of the AI

In that case, a senior Waymo AV developer left Waymo having

algorithm,

allegedly downloaded some 14,000 confidential documents and joined Uber. Waymo commenced proceedings to preserve the confidentiality of its data. Both companies had invested heavily in the development of customised LIDAR technology. Faced with having to prove that the data was confidential, Waymo fought hard to prevent disclosure in the proceedings whilst seeking to prevent Uber from using such data. Although Uber finally agreed not to use Waymo’s confidential technology, the court found that it was inevitable that some of the Waymo data would have ‘seeped’ into Uber’s development efforts. Waymo was awarded damages of USD 245 million, albeit paid in Uber shares.

validation and testing logs (error rates, simulation outcomes, incident logs), version updates, update history and over-the-air (OTA) update data, and black-box or event-data-recorder logs from the vehicle involved. Claimants will argue that understanding causation requires full disclosure and inspection of the algorithmic “decisionchain” (e.g., whether the vehicle’s system failed to detect an object, made a wrong classification, failed to execute a safe brake or evasive manoeuvre). They may say without access to the relevant code and data, it is impossible to test “what went wrong” and how liability should be apportioned between manufacturer, software supplier and fleet operator. Such pressure will be used by claimants as a tactic to endeavour to get defendants to settle early in order to avoid the risk of having to face commercially damaging disclosure orders. Defendants will contend that the code and models are highly confidential, commercially valuable, trade secrets, that disclosure risks competitive harm and will complicate expert engagement and may open the floodgates for wider discovery far beyond the requirements of the incident itself.


In the English system, a disclosure request must satisfy

Disclosure Protocols

relevance to the issues to be tried and be proportionate (considering cost, burden, confidentiality, and volume). Courts

In order to protect confidential AI/AV data, manufacturers,

will particularly weigh:

software suppliers, fleet operators, and insurers who are likely

how closely the material relates to the incident in suit, whether less intrusive alternatives exist (e.g., metadata, summaries, expert reports), the burden on the disclosing party, use of protective orders and/or confidentiality rings, and whether early narrowing of issues and agreed protocols can mitigate risk Given the highly technical nature of AI and AV systems, parties will rely on expert evidence to frame what code and data is really necessary. In such cases, the code could be inspected by a neutral expert under strict confidentiality protocols (in-camera or under protective order) rather than full open disclosure. Generally, UK courts are unlikely to demand disclosure of source code or proprietary algorithms in most civil claims, though they may order disclosure of decisionmaking processes, validation metrics or error rates. Protective orders, confidentiality rings, segregation of expert access, and staged disclosure are likely to be key procedural tools in AI/ AV cases. In the AV context, given the high commercial value of AI models and safety levels, courts are likely to require more targeted disclosure rather than blanket access.

to be engaged in AV litigation will wish to take legal advice on formulating an action plan to, inter alia: preserve event-data logs, code version history, decision logs, OTA update records, map/sensortraining data sets at the time of the incident. record version numbers, time-stamped software builds, and metadata about vehicle in question. freeze a “snapshot” relevant AV data, if feasible, to prevent overwriting. Identify precisely which software modules, time periods, vehicle configuration and update versions are in issue. consider staged disclosure starting with high-level architecture, version history and validation metrics, followed, if necessary, by incident-specific data and data logs; further disclosure only if prior disclosure not sufficient and then only subject to protective orders and a confidentiality ring tailored for highly sensitive technical material (source code, model weights, training sets etc). offer alternative modes of disclosure: summaries of model performance, error-rate statistics, expert reports on system behaviour, redacted code snippets. propose “black box” version of code or interface simulation rather than full source code disclosure where possible. maintain full version-control history of code and models, archive testing certificates, validation data, simulation outcomes and mark which code version applied to the vehicle at the time of incident as against later versions. For defendants (e.g., AV manufacturers, software providers, fleet operators) the risk is that full source code disclosure will expose commercially sensitive technology and open to floodgates to future litigation; but resisting disclosure entirely may delay settlement, increase costs and raise further risks (e.g., party cannot defend itself successfully without showing exactly how the AV system worked).


For defendants (e.g., AV manufacturers, software providers,

It is important that the 2024 Act safety regime should place

fleet operators) the risk is that full source code disclosure

clear duties and safety standards on AV providers and a clear

will expose commercially sensitive technology and open to

obligation on them to address and provide ongoing protection

floodgates to future litigation; but resisting disclosure entirely

against cybersecurity risks.

may delay settlement, increase costs and raise further risks exactly how the AV system worked).

Criminal law (road offences, corporate criminal liability)

Claimants (e.g., injured parties and insurers exercising

The AV regime aims to immunise passengers from driving

subrogation) will need to focus early on preservation notices

offences when an authorised vehicle is in self-driving mode,

and identify the AI versions and modules of interest, use expert

but serious criminal exposure may remain for owners and fleet

evidence to demonstrate that the source code and AI model

operators who fail to comply with the operator’s licence safety

is relevant, and that less intrusive alternatives will not suffice,

and other operational requirements. Corporate actors who fail

and be ready for long battles over confidentiality rings, expert

to comply with the requirements of the legislative framework

protocols, and focusing on the scope of disclosure rather than

and whose AVs cause death may be laying their responsible

insisting on full code dumping.

officers open to corporate manslaughter liability. The extent to

(e.g., party cannot defend itself successfully without showing

which “autonomous” machine conduct imports ‘mens rea’ on the part of human operators will no doubt become the subject of future guidance and policy.

Conclusion Once again the law is striving to keep up with the everincreasing pace of technological change. Statutory reform has created the legislative framework for the advent of AVs, but the common law will have to adapt quickly as significant liability cases reach the courts.

Data protection and evidential access AVs generate and record continuous streams of data including sensor, image and location data. Questions will arise as to who owns such data and how it can be shared and used. Data protection law (principally the UK GDPR/Data Protection Act 2018) will govern retention, access and lawful onward disclosure. Additionally, regulators and litigants will seek device logs and “black-box” data in accidents — raising recurring legal issues around compelled production, privacy of third parties and proportionality. Data protection, potential data leaks and contractual regulation of data obligations will all be highly relevant.

Cybersecurity and third-party interference

In the short term, we may expect fierce forensic combat over the disclosure of code and data, cross-border lessons from US trade secret and product liability litigation, and rapid insurerled litigation testing the logic and operation of the statutory insurance regimes. For now, the safe assumption for practitioners is that the courts will endeavour to apply established tort and product liability principles to AV accidents but will need to be prepared to wrestle with difficult and novel issues of causation, standards of care and disclosure in a very new and complex technical environment. Meanwhile, it certainly won’t be very long before your Uber lift arrives without a driver to talk to…but it will probably still ask you for a five-star testimonial …..and a tip.

If a crash is caused by a third-party hack, the legal focus will shift to the relevant AV product security standards, foreseeability, and whether the manufacturer took reasonable steps to make its AV systems less vulnerable to third party

Christopher Sherliker Senior Corporate Counsel Commercial & Corporate and IP

interference. Claims following a third-party hack may

christopher.sherliker@laytons.com

combine allegations of negligence with breach of statutory

+44 (0)20 7842 8015

duty claims and commercial warranty claims.


Expertise Arbitration Banking & Finance Commercial Corporate Data Protection & Information Disputes Employment Immigration IP & Technology Private Wealth & Philanthropy Real Estate Corporate Real Estate Disputes Real Estate Investment & Finance Restructuring & Insolvency Tax

LAYTONS ETL Yarnwicke, 119 - 121 Cannon Street, London EC4N 5AT +44 (0)20 7842 8000


Turn static files into dynamic content formats.

Create a flipbook
Laytons ETL: Autonomous Cars on UK Road - Some Legal Issues by Laytons ETL - Issuu