Artificial Intelligence and Legal Liability in Kuwait: The Current Framework and Its Challenges
05 September 2026

A legal analysis of artificial intelligence in Kuwait: the absence of dedicated legislation and how existing rules apply, civil liability for harm caused by automated systems, personal data protection, ownership of outputs and copyright, use in regulated sectors, and AI evidence before the courts.

Artificial intelligence systems have entered fields until recently reserved to humans: assessing finance applications, screening CVs, diagnosing medical conditions, generating text and images, and driving vehicles. As this use expands, a central question emerges. Who bears responsibility when the system gets it wrong? Kuwait, like most States, does not yet have comprehensive dedicated legislation governing artificial intelligence, so the matter is addressed by applying existing general rules in the civil code and in data protection, intellectual property, and cybercrime legislation. This article examines that framework and its limits.

The Current Legislative Position

A distinction must be drawn between the absence of dedicated legislation and a legal vacuum. The latter does not exist:

  • No legal vacuum: AI activities are subject to the general rules of liability, contract, data protection, and intellectual property. The system is a tool used by a person, natural or legal, who answers for its use.
  • Relevant legislation: the subject intersects with Civil Code No. 67 of 1980, Cybercrime Law No. 63 of 2015, Electronic Transactions Law No. 20 of 2014, and data protection and intellectual property legislation.
  • Sector regulation: regulators in sensitive sectors issue instructions governing the use of automated models, particularly in banking, finance, and healthcare.
  • International direction: comparative legislation is moving towards a risk-classification approach imposing heightened obligations on high-risk applications, a trend expected to influence regional regulation.

Civil Liability for Harm Caused by Automated Systems

These systems raise a genuine difficulty because their behaviour may not be fully predictable even to their developer. Liability rules nonetheless remain applicable:

  • Contractual liability: where harm arises from breach of a contractual obligation, such as supplying a system that fails to meet agreed specifications, the supplier is liable under the contract terms.
  • Tortious liability: founded on fault, damage, and causation. The fault typically consists in neglecting testing, validation, or disclosure of the system's limitations.
  • Liability for things: the rules on the custodian of a thing requiring special care may be invoked, treating the operator as the party with effective control over the system.
  • Product liability: the developer may answer for a defect in design or training data, or for inadequate warning against unsuitable uses.
  • Multiple parties: liability is frequently distributed among developer, operator, and user, and apportioning it requires precise technical expertise.

The greatest challenge remains proving causation within systems whose decisions are difficult to explain. Practice is therefore moving towards requiring operators to maintain operational logs enabling decisions to be traced and explained.

Personal Data Protection

These systems are built on data, and this is where the most common legal risks arise:

  • Lawfulness of processing: collection and processing must rest on a lawful basis. Mere availability of data does not justify its use.
  • Purpose limitation: using data collected for one purpose to train a model for another may constitute a breach.
  • Sensitive data: health, financial, and biometric data require heightened protection, and risks increase where they are used in automated classification systems.
  • Automated decisions: taking a decision materially affecting a person's position in complete reliance on an automated system without human review raises serious concerns, and a right of objection and review should be available.
  • Cross-border transfers: storing data on external servers requires examination of transfer and retention obligations.

Ownership of Outputs and Copyright

Automatically generated content raises questions not yet settled internationally. The practical framework may be summarised as follows:

  • Originality and human contribution: copyright protection traditionally rests on human creativity, raising the question whether outputs generated without sufficient human creative input attract protection.
  • Mixed contribution: where the system served only as a tool assisting a human author in execution, the work is protected for that author.
  • Training data: using protected works to train models without licence raises potential liability towards rightsholders.
  • Contractual regulation: absent legislative resolution, terms of use and agreements between the parties become the practical reference for who owns outputs and the limits of their use.
  • Disclosure: disclosing the use of AI in producing content directed at the public is advisable to avoid characterisation as misleading.

Use in Regulated Sectors

Requirements intensify as the impact of the decision on individuals increases:

  • Banking and finance: using models for creditworthiness assessment or suspicious transaction monitoring requires model governance, explainability, and periodic review.
  • Healthcare: diagnostic support systems do not relieve the physician of responsibility. The clinical decision remains attributable to them, and blind reliance on the system may itself constitute fault.
  • Recruitment: automated screening tools may reproduce biases present in training data, requiring periodic testing of their impact.
  • Legal practice: these tools may assist in research and drafting, but responsibility for verifying accuracy and citations rests with the lawyer alone.

Artificial Intelligence in Judicial Proof

This development affects the courtroom from two opposing directions:

  • Machine-generated evidence: such as pattern analysis or facial recognition, subject to the court's assessment and to technical challenge, and not admissible as conclusive proof in itself.
  • Fabricated evidence: deepfake audio and video present a serious challenge requiring specialist technical examination to verify authenticity before any reliance is placed on a recording.
  • Chain of custody: the rules on the integrity of digital evidence and documentation of its source remain decisive to its weight.
  • Rights of the defence: the defence should be enabled to examine how the system operates and the sources of its data. Evidence that cannot be examined carries reduced weight.

Recommendations for Businesses

  • Adopt a written internal policy defining permitted and prohibited uses of AI tools and prohibiting entry of confidential data into them.
  • Review supply agreements with system providers to include performance warranties, liability caps, and indemnities.
  • Maintain operational logs enabling material decisions to be traced and explained if challenged.
  • Retain genuine human review of every decision affecting individual rights, not merely formal sign-off.
  • Test systems periodically for bias and systematic error, and document the results.
  • Train staff on the limits of these tools. Excessive trust in their outputs is the most common error.

Adopting artificial intelligence is a sound commercial decision, but it requires a parallel legal structure defining responsibilities and protecting the business and its clients. Yamnak Law Firm advises on drafting use policies, reviewing agreements for automated systems, and assessing legal risk, and represents clients in disputes arising from harm caused by automated systems.

Need Legal Advice?

The Yumnaak Law Firm team is ready to help with trusted expertise.

Book Appointment Contact Us
Supporting Services
التوثيق
Tawtheeq & POA
poa.moj.gov.kw
وزارة العدل
MOJ eServices
eservices.moj.gov.kw
SYSLAWS
Made in Kuwait
SYSLAWS.COM

All rights reserved to Yumnaak Law Firm 2026 YUMNAAK LAW FIRM