The lawyer spoke about the responsibility for the harm caused by AI
A special law on artificial intelligence has entered into force in Vietnam, which for the first time at the national level establishes the distribution of responsibility for harm caused by AI systems. We are talking about Law No. 134/2025/QH15, effective from March 2026. The document specifies who is responsible to the user and in what cases — the developer, the system operator, or third parties who have interfered with the algorithm. Ilya Vasilchuk, a judicial lawyer, an expert on the security of electronic transactions and real estate transactions, and a public figure, told Izvestia on June 26.
Earlier it was reported that during a vacation in Vietnam, a tourist uploaded a photo of blisters on her leg to the neural network, after which she received a version about a jellyfish bite. However, after consulting with the insurance company and contacting the clinic, the doctors diagnosed a burn from a poisonous tomcat beetle and prescribed treatment. Doctors warned that if the damage is not properly treated, there is a risk of blood poisoning.
As the expert explained, the law actually forms a multi-level responsibility model typical of a digital environment with a high level of automation. The developer is responsible for the model itself: architecture, code, and training data. If a technical defect is proven — for example, an error in the algorithm or an incorrect training sample that caused harm — it is he who can be held accountable.
An operator or deployment party (deployer) is singled out separately — a company or service that has implemented AI and provides users with access to it. He is given increased responsibility: even if the system worked correctly and without obvious violations, but damage was caused as a result of its use, the operator is obliged to compensate for it. At the same time, he retains the right of recourse against the developer or supplier of the technology, if this is stipulated in the contract.
"The third category is external intruders. If the damage is caused by outside interference, such as hacking and algorithm changes, the responsibility falls on the attacker. However, if the operator or supplier has not provided a sufficient level of protection, the responsibility can be distributed among all parties," the expert explained.
Vasilchuk noted that such a model reflects the general trend of AI regulation, in which responsibility is "split" between participants in the digital chain — from the creation of technology to its application.
In Russia, a separate law on artificial intelligence has not yet been adopted, but legal regulation is already being discussed. In the spring of 2026, the Ministry of Finance submitted a draft law, which later became known as "On supporting the development of artificial intelligence technologies in the Russian Federation." The document submitted to the State Duma under the number No. 1271570-8 assumes that developers, operators and owners of services will be responsible in proportion to the degree of guilt — if they knew or should have known about the possible negative consequences of the system.
The draft also establishes the grounds for exemption from liability: taking sufficient measures to prevent harm, force majeure, intent of the victim or interference of third parties.
At the same time, as the lawyer stated, the absence of a specialized law does not mean a legal vacuum. The current Russian law already applies general rules. In particular, Article 1064 of the Civil Code of the Russian Federation establishes the obligation to compensate for damage by the person who caused it, and Article 1095 of the Civil Code of the Russian Federation provides for the responsibility of the manufacturer or contractor for damage caused by defects in goods or services, regardless of the presence of guilt.
The lawyer stressed that the role of the human factor remains a key principle in such cases. The court will assess exactly how the user interacted with the AI: whether there were warnings about risks, whether the obvious limitations of the system were ignored, and whether the person could have prevented the consequences by their actions.
If the damage was caused solely by the user's fault, for example, by intentionally ignoring instructions or deliberately misusing the results of AI work, responsibility may be lifted from developers and operators.
According to the expert, the positioning of the service is of particular importance. If the system is claimed to be a tool for professional decisions — for example, in medicine or law — stricter requirements may apply to it. At the same time, AI is still considered as an auxiliary tool that does not replace a person's professional judgment and does not relieve him of ultimate responsibility for the decisions made.
The Reuters news agency reported on February 9 that medical equipment manufacturers are introducing artificial intelligence into their products, which harms patients during operations. At least 10 people were injured between the end of 2021 and November 2025. In most cases, the injuries were presumably caused by errors that caused the TruDi navigation system to give surgeons incorrect information about the location of instruments during operations on patients' heads.
Переведено сервисом «Яндекс Переводчик»