The ‘reasonable person’ is one of common law systems’ most durable standards. Common law systems, including Indian law, continue to assess conduct against such standard for the purpose of determining liability in diverse scenarios. Being objective by design, the framework supplies a workable benchmark across negligence, contract, criminal law, professional regulation and fiduciary duty without making liability dependent on a defendant’s unique characteristics and limitations.
However, artificial intelligence (“AI”) challenges this framework, since AI tends to alter the range of possibilities within which reasonableness operates. AI systems can process information at extraordinary speed and scale, act continuously and generate decisions without contemporaneous human direction. On the other hand, AI may lack context, common sense and social judgment. For companies deploying AI tools, the immediate question is how boards and business teams should evaluate capability, control, authorization and foreseeable risk when a system performs a function that was exclusively assigned to humans earlier.
This note addresses the implications for corporate governance, fiduciary duties, principal-agent relationships, contractual allocation of responsibility, disclosure risk and liability exposure. It also identifies practical steps which organizations can take while legal standards adjust to AI-enabled or AI-driven conduct.
The Traditional Standard and its Implicit Assumptions
Devised by courts, the legal fiction of a reasonable person contemplates an idealized median comprising ordinary sense, care and caution, including for the purpose of deciding whether a person’s action or choice was negligent (or lawful) based on a neutral assessment of fairness.
The standard traces to 19th century jurisprudence, which described negligence by reference to what a hypothetical person of ordinary prudence, guided by considerations that typically regulate human affairs, would have done in comparable circumstances. Instead of extreme wisdom or skill, a reasonable person is required to demonstrate only a threshold level of intelligence and judgment, commensurate with general community norms (instead of what the specific defendant actually thought or felt). Accordingly, acts and omissions are measured against what a typical member of the community would do in the same situation.
As a result, the standard carries certain implicit assumptions and limitations. The reasonable person is not supposed to be superhuman or perfect; instead, the law expects them to possess finite attention, memory and processing capacity. Foresight is similarly qualified, where a reasonable person must only anticipate reasonably foreseeable consequences. The legal inquiry depends on what the person concerned could know, perceive and control in the given circumstances, but nothing beyond that.
Following English common law principles, Indian law often measures conduct against the behavioral limits of a reasonable person. The statutory and judicial formulations of ‘good faith’ connect such inquiry to due care and attention, reinforcing the fact that such standard tracks the actor’s ability to manage a relevant risk. Such formulations give courts and legal persons a useful baseline, even as AI remains poised to fundamentally change the factual settings where considerations of reasonable behavior come into play.
How AI may Challenge the Standard
AI may challenge the traditional standard of reasonableness in certain material respects, including with respect to governance and liability, as follows:
Speed and scale
AI can process information at a speed and volume no human can match, operate without physical fatigue or cognitive decline, identify correlations across enormous datasets and compare large numbers of possible responses. While a human analyst may review hundreds of documents, an AI system may process millions in seconds. Such major differences in performance and ability may change the time, information and control assumptions of a conventional reasonable-person inquiry.
Opacity
AI decision-making is often probabilistic and difficult to understand or explain, including with respect to the developers themselves. The chain between input and output may be proprietary, technically complex or architecturally opaque. Such features create significant difficulties for doctrines that depend on identifiable decisions by identifiable actors, making documentation, testing and escalation important.
Autonomy
AI agents increasingly receive end objectives rather than detailed instructions, and may therefore determine intermediate steps by themselves, as well as select among alternatives, interact with other systems and adapt without human intervention. Accordingly, such agents can produce an action that nobody expressly asked or taught them to take. While this kind of autonomy is commercially useful because it creates value and increases efficiency, it also leads to attribution, authorization and control risks. For a discussion on opportunities, risks and evolving legal frameworks related to agentic AI, see here.
Simultaneous capability and limitation
AI can outperform humans in speed, memory, pattern recognition and continuous monitoring, even while lacking common sense, contextual judgment, social understanding and the type of intuitive appreciation of consequences that humans – as well as the law – take for granted. AI can succeed where no human could, but it may fail where a human might respond instinctively, pursuant to legal conditioning and awareness.
These characteristics require a capability-sensitive, context-specific inquiry. Increasingly, courts and regulators will need to first identify what the AI system could do, what it actually did, what information and instructions it received, what kind of human control was realistically possible and who benefited from its deployment, performance and/or scale of operations. Responsibility may then be allocated among the developer, manufacturer, deployer, employer, user, insurer and other actors according to capability, control, knowledge, benefit and available safeguards. Such sequencing may preserve familiar legal standards while making their application contextually appropriate.
The Principal-Agent Framework and AI Agents
Traditional agency law starts with an identifiable principal and agent, instructions and authority and an intelligible relationship between the agent’s conduct and the principal’s intent. AI agents complicate each of these assumptions. After receiving a broad goal, an AI system may pursue unintended strategies to achieve such goal, as well as negotiate terms which the principal never contemplated, or interact with another AI system in a chain of machine-mediated decisions. A recent incident in Australia, along with major cybersecurity breaches involving leading AI companies, illustrates this point.
Given rapid recent advances in AI technology, corporate principals may face such issues immediately. Companies deploying autonomous procurement agents, AI-driven trading systems or automated customer-service chatbots may authorize a business objective, while the system can independently select the means to secure such objective in the most efficient manner possible – i.e., according to the system’s own understanding, which may be contrary to human morality or normative constraints. The critical question is whether responsibility should follow the ordinary consequences of agency in situations where the principal did not specifically authorize or reasonably anticipate the agentic actions involved. The answer, in turn, may be subject to diligence, system capabilities, access controls and adequate monitoring, along with the principal’s ability to intervene.
Companies should understand their AI systems’ powers along with their intended functions. Procurement, deployment and third-party contracts should allocate risks arising from autonomy, data access, external-system interaction, monitoring, indemnification and change management. Existing rules and principles, which were designed for human agents, may not always be appropriate to address such emergent issues.
Corporate Governance and Board-Level Implications
Boards and senior management may need to confront questions such as: what does reasonable oversight mean when a company delegates significant functions to systems operating at a scale and speed beyond ordinary managerial supervision? The duty of care, including as understood in global regulatory regimes, requires informed decision-making and reasonable monitoring systems. AI makes the design of such systems a critical governance issue.
A company using AI to execute thousands of transactions, interact with customers, make credit decisions or manage supply chains, should understand how the system behaves at the margins. Average accuracy may not answer questions about outliers (i.e., data points that deviate significantly from the norm, potentially indicating errors or anomalies), drift (i.e., the degradation of machine learning (“ML”) model performance due to changes in data or in the relationships between input and output variables, potentially producing faulty decisions and incorrect predictions), escalation failures, unauthorized access or concentration of risk. Information and reporting systems must be designed for outputs generated at machine speed.
Capability-sensitive oversight may involve proportionate governance and evolving best practices, such as when deployers of highly autonomous AI systems take necessary steps to understand failure modes, unexplored capabilities and supervisory constraints. While the legal standard of reasonableness may prove resilient, its substance and scope could expand with changes in the underlying technology being overseen.
Boards should ask whether their oversight structure reflects the actual capabilities and risks of the AI systems which the company deploys. AI governance should appear in board materials, risk reporting, escalation protocols and internal audit work. Treating AI as merely a compliance checkbox may leave the company exposed when a system’s capabilities exceed the limited governance mechanisms designed for conventional software.
Emerging Litigation and Regulatory Developments
Recent developments across advanced jurisdictions reveal key patterns of how existing doctrines may be applied to AI-enabled conduct even while their underlying assumptions are re-assessed.
European Union
The EU’s AI Act uses a risk-based classification system with obligations scaling from minimal to prohibited. It requires conformity assessments for high-risk AI systems and seeks to regulate AI by capability and risk category. The EU’s Product Liability Directive treats software, including AI systems, as a product for purposes of no-fault liability, and recognizes continuing manufacturer control over updates and ML algorithms. The continuing debate in Europe over a separate AI-liability directive reflects regional concerns about how evidence and causation should account for systems whose operation is difficult for claimants to observe.
United Kingdom
The UK’s Automated Vehicles Act 2024 assigns responsibility for automated driving to an authorized self-driving entity, protects users from criminal driving offences when the automated feature is engaged and connects civil liability to the existing insurance architecture. Responsibility rests with the regulated entity that controls the relevant capability, while users receive protection for conduct which the system performs.
United States
In the US, copyright disputes are testing whether doctrines developed around human-scale research can accommodate computational extraction and model training at industrial scale. Key cases have involved claims concerning the use of copyrighted works or images to train generative systems. Such proceedings raise questions about training, ingestion, storage, outputs, market substitution and fair use.
India
The Digital Personal Data Protection Act, 2023 and its rules may intersect with AI deployment, particularly where systems process personal data or support automated decision-making. While Indian courts have applied the principles of absolute liability (no-fault liability without exceptions when harm occurs) to environmental cases, hazardous and inherently dangerous industrial activity, motor vehicle accidents, nuclear damage, public liability insurance and custodial wrongs, AI raises different questions – including on software capability, data use and the element of control. The statutory fair-dealing protection for private/ personal use and ‘research’ under the Copyright Act, 1957 may continue to be invoked for the purpose of addressing judicial challenges to AI training practices, including in light of desired policy goals related to technological innovation, sovereign large language model (LLM) development, public benefit and national interest. Nonetheless, the ability to document, verify and substantiate facts about system architecture, training cut-offs, retrieval mechanics, output comparison and the availability of opt-out and crawler controls, may need to form part of a new governance playbook for the near future.
From Anthropomorphism to Functional Analysis
An anthropomorphic approach to AI runs the risk of assigning human judgment, intent or foresight to systems, especially when AI outputs only appear to be generated by humans. On the other hand, a technologically reductionist approach may treat an AI-enabled/ -driven action as if a conventional tool produced it, thereby assuming that the most proximate human actor should bear the entire risk. Both such heuristic shortcuts can obscure capability, control and effective liability allocation.
The better approach may involve a functional analysis which remains sensitive to actual capabilities. Here, the relevant legal inquiry may include key questions such as: (i) What was the system capable of doing? (ii) What did it lack? (iii) How autonomous was it? (iv) What scale and speed did it introduce? (v) Who designed and/or controlled the relevant capability? (vi) Who benefited from it? (vii) What safeguards were reasonably available? And so on. Such sequential examination and evaluative logic may give courts and corporate decision-makers a factual foundation for allocating responsibility.
Since AI can arguably reduce error, improve safety, expand access to expertise, detect fraud, accelerate scientific discovery and make previously uneconomic services viable, future legal standards may – and should –preserve such benefits through a pro-innovation approach. At the same time, emerging regulations may require safeguards that are proportionate to capability, control and consequence. In different circumstances, the appropriate expectation may be higher or lower than the equivalent mean, while in some cases, the legal question may change altogether.
A functional approach to dealing with AI could potentially preserve incentives related to innovation while ensuring that legal expectations correspond to actual capabilities and limitations.
Indicative Practical Guidance
Based on the current trends, key governance measures which may become increasingly relevant in future disputes include the following:
Conduct capability mapping
Understand what each AI system can actually do, including external-system access, autonomous strategy generation, data access, escalation behavior and failure modes. The relevant legal inquiry may compare the capabilities which the company deployed with the functions intended. A narrow model operating within defined parameters carries different implications from an agent that can act across consequential systems.
Implement proportionate governance frameworks
Boards should ensure that oversight reflects the scale, speed, autonomy and consequence of deployed systems. Governance should include defined ownership, escalation pathways, testing, monitoring, incident response and board-level AI literacy. Board materials and public statements should match validated capabilities. Exaggerated claims may create disclosure and consumer-protection exposure.
Document decision-making rationale
Maintain a contemporaneous record of why the company selected a system, what constraints it imposed, what testing it performed, what risks it considered and who approved residual risk. This documented record may become material in potential litigation involving foreseeability, fiduciary duty, vendor reliance and disclosure.
Allocate responsibility contractually
AI procurement agreements, deployment contracts and service-level agreements should address autonomous conduct, training data, scraping, outputs, indemnification, audit rights, incident response and responsibility for ongoing monitoring. Parties should define who bears the risk of unauthorized activity, third-party claims, model changes and failures in vendor controls.
Monitor global litigation trends and regulatory developments
Other than developments under Indian law, companies operating globally should track judicial and interpretive trends stemming from legislation in other jurisdictions (e.g., under the EU’s AI Act), along with emerging practices in sector-specific AI frameworks and regulatory enforcement priorities.
Analyze limitations on foreseeability
It may be increasingly important to distinguish (i) consequences that may be unforeseeable despite reasonable diligence from (ii) those that may be unforeseeable because the company failed to understand a known capability of its own system, especially from the perspective of potential liability and remedial action.
Engage constructively with standard-setting
Companies that participate in industry bodies, regulatory consultations and standard-setting organizations can help shape workable expectations for AI-enabled conduct. Early policy engagement may also provide a clearer view of emerging controls and evidentiary expectations.
Conclusion
Common law’s reasonable person standard is likely to remain indispensable, although its content and boundaries may evolve, especially with widespread technology-led disruption. As AI performs, replaces and augments functions historically undertaken by humans alone, future legal analysis may account for a system’s actual capabilities, limitations, autonomy and control environment. Such evolving and uncertain environment may soon lead to new rules of liability allocation among actors who designed, deployed, benefited from and/or could have constrained the relevant conduct.
In order to navigate this transition, companies may need to understand their AI systems’ actual capabilities, govern them proportionately, document their decisions, assign responsibility contractually and communicate to regulators and stakeholders with precision.
This insight has been authored by Rajat Sethi and Dr. Deborshi Barat from S&R Associates. They can be reached at [email protected] and [email protected], respectively, for any questions. This insight is intended only as a general discussion of issues and is not intended for any solicitation of work. It should not be regarded as legal advice and no legal or business decision should be based on its content.