
๐ง Listen to the full episode: Spotify | Apple Podcasts | YouTube
A note from Robert Kellar KC This piece is for general discussion and information purposes only. Nothing here should be treated as legal advice or relied on as such. These issues are highly fact-specific. Please take proper legal advice from a qualified lawyer before acting on anything discussed, and do not rely on AI as a substitute for that.
Direct answer: When an AI tool contributes to a clinical decision and a patient is harmed, English law cannot yet give a clean answer on who is liable. Robert Kellar KC, a barrister specialising in clinical negligence and regulation, sets out a liability chain that runs first to the practitioner, then to the deploying organisation, and only third to the software developer. He predicts AI will disrupt negligence law at three escalating levels, up to and including the reconceptualisation of the 70-year-old Bolam standard. For any regulated organisation, the strategic implication is that liability is decided long before a claim, in procurement contracts, governance structures, and the discipline of documented human judgement.
The Vacuum
Picture a clinician sitting with a patient. An AI tool flags a finding and recommends a treatment. The clinician acts on it. The recommendation was wrong, and the patient is harmed. The only question that matters next is who is liable, and right now English law cannot give a clear answer, not for the practitioner, not for the organisation that bought the software, and not for the company that built it.
That is the vacuum every organisation deploying AI is operating inside today, mostly without realising it. Robert Kellar KC is one of the few legal professionals in the country actively mapping it. He is a barrister at 1 Crown Office Row who qualified in 1999, and he has spent recent years litigating high-value clinical and dental negligence claims alongside regulatory work for doctors and dentists. He was asked to speak on AI and medical liability before ChatGPT existed, and has written and spoken on it with increasing frequency since.
The case study here is dentistry. The analysis applies to any profession where a regulated human is accountable for a decision an algorithm increasingly shapes.
The Liability Chain Runs to the Human First
The intuitive assumption is that when AI causes harm, the technology company is the natural defendant. The law, as Robert describes it, works in almost the reverse order. The first person it looks to is the practitioner, because both as good practice and as good governance, they are the one supervising the AI and making the clinical decision. Responsibility therefore remains with them.
The reality is that the first person that the law will look to, to compensate is the healthcare practitioner, the dentist. Ultimately it is they who will remain responsible. Robert Kellar KC
Second in line is the deployer, the practice or the group. Their exposure is twofold: vicarious liability for the negligence of the practitioner they employ, and their own systemic duties, of audit, of maintenance, of validation, which can give rise to direct liability. Only third is the product builder, potentially liable for a defective product. Those three, Robert says, are the defendants usually in the frame.
His prediction for how this plays out in practice is unsentimental. In the early innings of litigation, claimants will sue everybody and leave the defendants to work out between themselves who pays, which is how clinical negligence already works. It will simply take a new form.
Three Disruptions to the Law
Robert's central thesis is that as AI disrupts clinical practice, it will disrupt the law with it. He predicts three disruptions, at escalating levels of severity.
The first is higher standards of care. Errors once forgivable, an incidental or hard-to-interpret area of decay, become less forgivable once AI systems can reliably flag them. What was excusable becomes negligent, not because the clinician changed, but because the available standard did.
The second is a duty to use AI. Robert believes we are not quite at this tipping point, but as royal colleges and august bodies describe AI as standard practice in disciplines like radiology and pathology, the state of the art can become the expected practice, and failing to use it becomes the breach.
The third and most fundamental is a reconceptualisation of negligence itself. For nearly 70 years the Bolam standard has asked what a responsible body of practitioners would do. But that test strains when an advanced AI makes a recommendation at odds with what a responsible body would do.
Robert frames the dilemma precisely. Our instinct is to say clinical judgement trumps everything, that the clinician must press the mental override switch and do what they think is right. But the whole point of AI is to surface insights from data that humans cannot reach unaided, the concerning pattern in breast tissue no radiologist would see, the early decay no dentist would regard as significant. If we always require the human to override, we may deprive patients of exactly those insights.
Within the next decade or so, we're going to see cases which push at the limits of the traditional Bolam standard and perhaps dilute it or do away with it altogether. Robert Kellar KC
The Liability Sink: Two Traps Closing From Both Sides
Robert uses a term drawn from the wider literature, the liability sink, to describe how fault naturally flows to the human supervising the system. Because practitioners are in practice the people overseeing AI, they end up carrying the can when things go wrong. And the exposure comes from two opposite directions at once.
The first trap is automation bias: over time, uncritically following what the AI recommends without applying independent judgement, until an error produces a finding that a practitioner of ordinary skill should have known better. The second is the mirror image, the risk of liability for disagreeing with the AI when the AI was right and the human was wrong.
The practitioner is therefore squeezed. Defer too readily and you are negligent for not thinking. Override and you are negligent for being wrong. Robert's guidance for navigating the vice is concrete, and it rests on documentation.
If you're disagreeing with it, you should document why. If you're agreeing with it, you should demonstrate you haven't simply delegated judgment to the system. Robert Kellar KC
On whether automation bias would be treated as mitigating or aggravating in a fitness to practise investigation, Robert's view is that the framework is capable of weighing it, at least in principle, as a mitigating factor. But everything is context specific. What steps did the practitioner take to educate themselves about the system's error rate? Did the system explain itself, and provide a confidence score, and was that score accurate? Was the output out of kilter with what a responsible body would do? And crucially, is there evidence the practitioner applied their own independent judgement at all?
The Contract Is Where Liability Is Quietly Decided
Operators buying AI think about accuracy and workflow. They rarely think about where the liability lands, and Robert's warning is that the contract is precisely where it gets decided, often against them. Suppliers can sign contracts that exclude their liability entirely or cap it, leaving the practice or group holding the baby.
He sets out two questions to ask before signing. The first is simply where liability sits contractually when the tool goes wrong. The second is explainability: if a patient later brings a complaint or a claim, can the supplier explain why the AI flagged, or failed to flag, a particular finding?
The more opaque a system is, the more difficult it is to exercise independent clinical judgment, and the more difficult it is to defend a claim if things go wrong. Robert Kellar KC
This links the technical property of the tool directly to legal exposure. Opacity is not just an ethical concern about black-box AI. It is a defensibility problem. A system whose reasoning cannot be reconstructed after the fact is a system that cannot be defended in front of a regulator or a court.
Regulation Is Not a Zero-Sum Game With Innovation
There is a familiar argument that regulatory ambiguity is a feature for early movers, letting innovation happen before the law catches up. I put it to Robert directly. His answer refuses the binary. The task is getting the balance right: over-regulate and you stifle innovation, under-regulate and you compromise patient safety, trust, and in the long run the uptake of the technology itself.
He notes the radically different global approaches, the EU's high-regulation model against the light-touch approach in the US, but his own conclusion is unambiguous.
Regulation is probably a good thing for innovators in the long run, because it provides certainty, it provides clarity about how to avoid risk and liability exposure. Robert Kellar KC
This reframes regulation from a cost imposed on innovators to an asset that serves them, because certainty is what lets an organisation deploy without unquantifiable tail risk. For anyone building or buying in this space, that is the more useful way to hold it.
The 1987 Problem, and Why the EU Framework Is the Answer
The vendor question exposes a genuine strangeness in English law. The Consumer Protection Act 1987 makes the producer of a defective product strictly liable, the claimant need not even prove negligence. But whether AI software counts as a product under a statute drafted in 1987, long before the internet as we know it, has never been settled by an English court. There is a line of authority holding that software is not a product because it is not a tangible good.
Robert's read is that where AI is integrated into a physical product bought by a practice, there is likely no difficulty. The harder case is AI uploaded from the cloud into a product the practice already owns. He suspects most High Court judges would strain to give the Act a purposive interpretation to move it with the times, but without certainty.
I suspect if push came to shove, most High Court judges would strain to give the act a purposive interpretation. Whether they would get there so as to say that AI was a product, I don't know. Robert Kellar KC
The EU, by contrast, has updated its Product Liability Directive to state abundantly and explicitly that software and AI are products. Robert expects the UK to follow eventually, but it may require intervention from Parliament to clear up the ambiguity. His practical recommendation bridges the gap in the meantime.
Use the EU compliance framework as a proxy for gold-standard safety and governance. Make procurement decisions by asking whether a product is EU AI Act compliant and whether it carries a conformity assessment to prove it. Do that, and you can say with high confidence that you have gold-standard governance now, and a product that will stand the test of time if UK law catches up. He notes too that the EU Liability Directive ties liability to regulatory standards, so the two speak to each other, and that it imposes onerous disclosure obligations on defendants, which makes the explainability point commercially load-bearing rather than merely good practice.
Where the Regulator Sits, and Why Waiting Is Not an Option
The professional accountability system rests on a simple premise: a registered professional made a decision and can be held accountable for it. AI pressures that premise. If a clinician follows an AI recommendation that proves wrong, were they exercising judgement or deferring to a machine? Robert's answer is that the registrant remains responsible in the regulator's eyes regardless of whether AI informed the decision. Rely on AI without exercising independent judgement, and you place yourself at regulatory risk.
But he is clear that the regulator owes the profession something in return: guidance. As far as he is aware, the GDC has no explicit AI-specific guidance, though it commissioned a rapid evidence assessment in 2024 to survey how AI is being used in areas like caries detection. The GMC, he notes, has some limited guidance. His view is that more is needed, and faster, covering the due diligence required before deployment, the degree of human oversight that is appropriate, and how consent obligations are engaged when AI is used in a patient-facing setting.
On the argument that the regulator should simply wait for litigation to reveal where the framework breaks, Robert is unusually firm.
It's not fair, in my view, as a matter of policy, simply to discipline dentists first and provide the guidance later. Robert Kellar KC
The practical case reinforces the principle. Most dental regulatory cases do not reach the High Court, so waiting for the higher courts to generate guidance could mean waiting an awfully long time for anything meaningful. The burden, he argues, is on the regulator to provide early guidance rather than watch and wait.
The Governance Stack to Build Before Deployment
Asked what professional governance a multi-site group needs before a single clinician touches an AI tool in front of a patient, Robert offers what he calls some starters for ten, scaled to the size of the organisation and the nature of the tools.
A designated AI clinical and governance lead who genuinely understands the regulatory terrain. A pre-deployment due diligence framework confirming that any medical devices are properly registered with the MHRA, clinically validated, and have had their contractual provisions and insurance cover reviewed. A written policy on clinician responsibility, emphasising that dentists must always exercise their own judgement and remain responsible for decisions. And an incident monitoring and audit system that captures when AI produces unexpected or incorrect output, reviewed at group level rather than site level, so that patterns can be identified, addressed, and fed back to the supplier.
Asked for the single governance action to take in the next 90 days, his answer is unambiguous: appoint a dedicated AI clinical lead who knows something about governance, and if they do not, have them learn quickly. Failing that, retain a good lawyer who does, and let them audit and make recommendations.
The Prediction
I closed by asking Robert who will be standing in the dock when the first high-profile AI clinical negligence case in dentistry reaches the courts. His answer is the sharpest summary of the entire argument, and it should concentrate the mind of every individual practitioner working under an AI system they did not choose and cannot fully interrogate.
It's going to be the good old-fashioned dental practitioner who will bear the brunt of the claimant's ire. They're going to be the easiest person to sue. I think it will be the poor old dental practitioner who is the common carrier. Robert Kellar KC
The charge, he predicts, will be one of two things: that you applied automation bias, or that you disagreed with an AI savant when you should not have. The same vice, closing from both sides. Which is precisely why the documentation of independent judgement is not administrative hygiene. It is the practitioner's primary defence.
What This Means For Practitioners, Operators and Investors
For practitioners, the message is to protect yourself through documented judgement. Whether you agree or disagree with the AI, the record of why you decided as you did is your evidence that you exercised judgement rather than delegated it. That record is the difference between a defensible position and a liability sink.
For operators and groups, liability is decided before a claim ever arises, in the contract and the governance structure. Read where your supplier has placed the risk, insist on explainability, use EU AI Act compliance as your procurement standard, and put an accountable, informed AI clinical lead in the seat before you scale, not after the first incident.
For founders and investors, the commercial reality is that explainability and clear liability terms are becoming product requirements, not features. An opaque system is harder to defend, and under a European-style disclosure regime that difficulty becomes a direct commercial exposure. Building for transparency and conformity now is a durable advantage as the law moves toward the EU model.
The organisations that navigate this well will not be the ones that waited for the law to settle. They will be the ones that built defensible governance while the vacuum still existed.
Key Takeaways
The liability chain runs to the human first. The practitioner is the first defendant, then the deploying organisation, and only third the developer.
AI will disrupt negligence law at three escalating levels: higher standards of care, a possible duty to use AI, and the reconceptualisation of the 70-year-old Bolam standard.
The practitioner is caught in a vice. Automation bias creates liability for deferring, and the risk of disagreeing creates liability for overriding. Documented independent judgement is the defence.
Liability is decided in the contract. Suppliers can exclude or cap their liability, so ask where liability sits and whether the system can explain its decisions before you sign.
Regulation is not zero-sum with innovation. Certainty serves innovators, and the absence of UK-specific rules is not a free pass.
Use the EU framework as your gold standard. Whether AI is a product under the 1987 Act is unsettled in the UK, so use EU AI Act compliance and conformity assessments as your procurement proxy.
Build the governance stack before deployment. A designated AI clinical lead, a due diligence framework, a written responsibility policy, and group-level incident audit, ideally within 90 days.
This article draws on the TechDental conversation with Robert Kellar KC. It is for general information only and is not legal advice. Full episode on Apple Podcasts, Spotify, and YouTube.
About the Guest
Robert Kellar KC is a barrister at 1 Crown Office Row specialising in clinical negligence, professional discipline and regulation, public law and personal injury. He qualified in 1999 and has spent recent years litigating high-value clinical and dental negligence claims alongside regulatory work for doctors and dentists. He is a board advisor and a writer, speaker and thinker on medicine, AI and web3.
Connect with Robert: linkedin.com/in/robertkellarbarrister1crownofficerow | 1cor.com/london
About TechDental
TechDental is a strategic intelligence platform for founders, executives, operators and investors shaping the future of dentistry. Through high-level analysis and systems-focused conversations, we explore how AI, governance frameworks and regulation influence performance, safety and enterprise value in dental organisations.
www.techdental.com | info@techdental.com
