Introduction
“ChatGPT said it. You trusted it. Who is responsible?”
ChatGPT and other AI tools can answer questions, write content, analyse information and even suggest solutions within seconds. Millions of people now use these tools for work, education, health information and everyday decisions.
But AI can also give wrong, incomplete or misleading answers. What happens when someone follows that answer and suffers real-world harm? Can the person blame the AI company? Can the developer face legal action? Or does responsibility remain with the person who acted on the answer?
The law does not provide one simple answer. The question may involve negligence, consumer protection, contractual terms, intermediary rules and emerging AI regulation. The answer also depends on what the AI system said, how the user relied on it and what harm followed.
Can an AI Company Be Legally Responsible?
AI does not have a legal personality that allows someone to sue the software itself. Legal responsibility usually falls on people or organisations connected with the system.
Negligence can become relevant when a person or company owes a legal duty, fails to meet the required standard of care, and that failure causes foreseeable harm. However, proving negligence in an AI-related case can be difficult.
A user cannot automatically claim negligence simply because ChatGPT gave an incorrect answer. AI systems generate responses based on patterns in data and system design. They can produce inaccurate information even when the user asks a reasonable question.
The legal issue becomes more complex when the provider knew about a serious and foreseeable risk and failed to take reasonable steps to reduce it. A court would need to examine the facts, the service provided, the warnings given, the user’s reliance and the connection between the alleged failure and the harm.
What If the User Relies on the Answer?
Consider a person who asks an AI chatbot about a legal deadline and receives an incorrect date. The person relies entirely on that answer and misses the actual deadline.
The wrong answer alone does not automatically establish legal liability. The person may also have had other sources available, such as a lawyer, court website or official government notification.
The situation can change when a service encourages users to rely on its output for a particular purpose. The nature of the service, its representations and its warnings may then become important.
This is why users should treat AI-generated answers as information rather than unquestionable authority. For legal, medical, financial or safety-related decisions, users should verify important information through reliable sources or qualified professionals.
Can Consumer Protection Law Apply?
The Consumer Protection Act, 2019 contains provisions on product liability and service-provider liability. Section 85 states that a product service provider may face liability where the service is faulty, deficient or inadequate, or where an act, omission or negligence causes harm. It also addresses inadequate instructions or warnings in certain circumstances.
This raises an important question for AI services. Could an AI product or service fall within consumer protection law when a consumer pays for it and suffers harm because of a defect or deficiency?
The answer would depend on the facts and the legal relationship between the user and provider. Courts would need to examine the nature of the service, the terms offered to the consumer, the alleged defect or deficiency and the harm suffered.
Therefore, “the AI made a mistake” would not by itself settle a product or service liability claim.
What About Intermediary Liability?
Intermediary law creates another layer of the discussion.
Section 79 of the Information Technology Act, 2000 provides certain protections to intermediaries for third-party information, subject to statutory conditions. The protection does not apply in every situation. For example, the Act sets out circumstances involving unlawful acts and failure to respond after the required notice or actual knowledge.
However, an AI provider is not automatically an “intermediary” for every activity simply because its service operates online. The legal classification depends on the role the company performs and the facts of the case.
This distinction matters because responsibility for generating an AI response may differ from responsibility for hosting or transmitting content created by another user.
India’s AI Rules Are Changing
India has started strengthening its legal framework for AI-generated content.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 came into force on 20 February 2026. The amended rules introduced the concept of “synthetically generated information” for certain realistic AI-generated or AI-altered audio-visual content. The government’s explanation includes realistic deepfakes, AI-generated images and videos, and voice cloning within the relevant framework.
The amended framework also places stronger duties on intermediaries concerning unlawful synthetic content. These duties include measures relating to labelling, traceability and preventing certain unlawful AI-generated material.
This does not mean that India now has one single law that makes an AI developer automatically responsible for every harmful AI answer. Instead, existing laws continue to play an important role while AI-specific governance develops.
India Is Also Building a Wider AI Governance Framework
India’s approach to AI regulation goes beyond the IT Rules.
MeitY released the India AI Governance Guidelines in 2025. The framework focuses on responsible AI development and includes accountability, safety, transparency and human-centred governance among its key principles.
In April 2026, the government also established the AI Governance and Economic Group to coordinate AI governance policy across government.
These developments show that AI accountability is becoming part of a broader regulatory discussion. However, governance guidelines and policy frameworks should not be confused with a general rule that automatically creates civil or criminal liability for every AI error.
So, Who Is Responsible When AI Causes Harm?
There may not be one responsible party in every case.
The answer can depend on the AI provider, the developer, the organisation deploying the system and the person who relied on the output. A business that uses AI to make decisions may also have different responsibilities from an individual who casually uses a chatbot.
The type of harm also matters. A wrong restaurant recommendation is very different from incorrect information that causes financial loss, medical harm, discrimination or reputational damage.
Courts may therefore need to examine the entire chain of events. They may ask who created the system, who controlled its use, what safeguards existed, what warnings the user received and how the harmful outcome occurred.
What Should You Do Before Relying on AI?
AI can be useful, but users should verify information before making decisions that could have serious consequences.
For legal questions, check the relevant legislation, government notification, court judgment or qualified legal professional. For medical concerns, consult an appropriate healthcare professional. For financial decisions, verify information through reliable financial or regulatory sources.
This does not mean AI has no value. It means that users should understand the limits of the technology. An AI response can assist your thinking, but it should not automatically replace professional judgment.
Conclusion
ChatGPT said it. You trusted it. But who is responsible?
The answer depends on the circumstances. An incorrect AI response does not automatically make the developer or provider legally liable. A successful claim may require proof of a legal duty, a failure to meet that duty, causation and actual harm, depending on the legal route involved.
Consumer protection, negligence principles, intermediary rules and emerging AI governance can all become relevant in different situations. India has also strengthened its rules for synthetic content and continues to develop a wider framework for responsible AI.
As AI becomes part of everyday decision-making, the bigger legal question is no longer only what AI can do. It is also who should answer when its use causes harm.


