RUSSIAN MARITIME LAW ASSOCIATION

PublicationsArticlesAutonomous ships and digitalisation

Article

Autonomous Shipping in Russia: Tortious Liability of Shipowners and Software Developers. Part 2

Ivan Kobchenko

National Research University “Higher School of Economics”, Moscow

In this article, the author continues the study of the allocation of tortious liability between the shipowner and software developer in the case of harm to third parties due to an error of the artificial intelligence of an autonomous vessel. Now the focus of attention shifts to the second of the two previously formulated model situations, namely the infliction of harm due to a ship collision (on the basis of Russian law). This analysis provides a new perspective on the standard of shipowner’s liability in a collision. Where harm is caused by a software error of an autonomous vessel, it is more equitable to impose the burden of strict liability on the shipowner for program errors. This approach should be pursued explicitly to avoid a mixture of de jure strict liability and de facto strict liability imputed under the guise of a fault-based breach of a duty to make a ship seaworthy. This does not exclude further recourse by the shipowner against the software developer. On the contrary, as regards the liability of the software developer towards third parties, the conclusions of the first part of the study remain valid: the software developer may bear the liability for fault-based violations committed while creating the IT product. At the same time, the question as to how far such a link between the software and its creator can be established remains open.

Autonomous Shipping in Russia: Tortious Liability of Shipowners and Software Developers. Part 2

1. Introduction This paper proposes to explore further the problems of tortious liability1 arising when an autonomous ship under the control of artificial intelligence causes non-contractual damage.

Key words: autonomous shipping, tortious liability, strict liability, liability of shipowner, ship collision, artificial intelligence, source of increased danger, actio in rem, seaworthiness of a ship.

The first part of the study focused on cases where an autonomous vessel causes damage to objects other than another maritime vessel.2 A different model situation – a collision between an autonomous vessel and another vessel – will be considered in this article. As it was before, the paper is divided into two parts – on the liability of shipowners and on the liability of software developers, respectively.

2. Tortious Liability in Case of a Ship Collision

2.1. Liability of the Shipowner

2.1.1. Current Liability Regime

A frequent cause of non-contractual damage at sea is a ship collision. As mentioned above, under the Merchant Shipping Code of the Russian Federation (MSC RF), a collision is not only a collision between two moving ships but also an allision between a moving ship and a ship anchored or otherwise secured. At the same time, the notion of collision is interpreted in maritime law broadly to include incidents between two vessels without direct physical contact. Foreign literature cites The Royal Eagle as a case where the vessel sailed at excessive speed and caused waves to sink the other vessel moored. The Admiralty Court held that this interaction is a collision of ships.3

In any discussion of collision liability, the starting point is Chapter XVII of the MSC RF, which is based on the 1910 Convention for the Unification of Certain Rules of Law with respect to Collisions between Vessels (hereinafter – the 1910 Convention).4

According to paragraph 1 of Art. 311 of this chapter, in case the collision is accidental (casus) or caused by force majeure, as well as if it is impossible to determine the cause of the collision, each person shall bear the losses he has suffered. Furthermore, in accordance with Art. 312 of the MSC RF, in case of a collision caused by the fault of one of the vessels, the losses shall be borne by the vessel liable for the collision. Finally, Art. 315 establishes the presumption of innocence of each vessel involved in the collision.

It can be seen that the special rules of the MSC RF generally correspond to the rule contained in paragraph 2 of section 3 of Art. 1079 of the Civil Code of the Russian Federation (CC RF), according to which the damage caused by the interaction of sources of increased danger (hereinafter also referred to as SID) is compensated on a common basis (as it would be in the case of interaction of several “non-sources” of increased danger).

Similarly to what is defined by the general tort law rules, the shipowner is released from liability if the damage was caused by accident, force majeure, or impossibility to show the cause of the damage. However, the presumption of innocence of a vessel in a collision remains an important feature of maritime law. In the vast majority of cases, a collision is caused either by negligent acts of the crew of one or both of the vessels or improper management of the shipowners (for example, lack of proper maintenance). It goes without saying that the shipowner is always responsible for the actions of the crew he has hired. Fault in a collision is usually established by checking the actions of the persons responsible for compliance with international regulations – the International Regulations for Preventing Collisions at Sea, 1972 (COLREGs),5 the International Convention for the Safety of Life at Sea, 1974 (SOLAS),6 the International Convention on Standards of Training, Certification and Watchkeeping for Seafarers, 1978 (STCW),7 and others.8

2.1.2. Statement of the Problem of Shipowner’s Liability for a Collision Caused by an Error in the Autonomous Vessel’s Software

When describing a shipowner’s liability for damage to an object other than a seagoing vessel, the notion of a source of increased danger is inevitably the subject of attention. The recognition of an autonomous vessel as a source of increased danger and the shipowner as the owner of such a source was sufficient to conclude that there should be strict liability imposed for a tort against a third party. The question of the shipowner’s fault in the software error or even the question of fault in the hacking of the autonomous vessel by cybercriminals was irrelevant.

In contrast, a different standard of liability has traditionally been applied in ship collisions. Unless the injured party provides sufficient evidence of the fault of the crew or management of the other vessel, the recovery of the losses suffered will be dismissed. As a consequence, all of the foreign authors rightly point out that as the autonomy of seagoing vessels increases, significant problems will arise in establishing liability of shipowners for ship collisions.

As mentioned earlier, fully autonomous vessels sail exclusively on the basis of commands from artificial intelligence or other software, and human control is eliminated here. Semi-autonomous vessels, on the other hand, either navigate in “autopilot” mode but with the help of AI (which makes them quite similar to fully autonomous vessels), or they are controlled by a remote operator who uses the AI as only an assistant in avoiding steering errors. Consequently, a collision between an autonomous vessel and another vessel is very likely to occur solely due to an error in the vessel’s software, in which case the fault of the shipowner just cannot be established.9

Such a result is primarily connected to the aforementioned features of artificial intelligence: in addition to installing software and performing other auxiliary actions, the shipowner is not able to identify and repair in advance defects in the AI algorithms. In the field of autonomous shipping, the problem of the shipowner’s unconditional innocence in a collision involving his vessel seems to be one of the most difficult to solve as for today. Some possible ways of resolving this problem will be explored below.

2.1.3. Options for Dealing with the Fault (Innocence) of the Shipowner

I. Extremely high standard of conduct, or de facto strict liability of the shipowner

It is traditional for maritime law to govern in detail the responsibilities of the shipowner to maintain the vessel in a proper condition. Of course, in the case of autonomous vessels, these duties will remain in full force and will be supplemented by requirements to install software updates, comply with the instructions issued by the software developer (the so-called “manuals”), and so on.10 However, it may be very difficult to determine what is the proper level of a shipowner’s reasonable and bona fide conduct. Therefore, it is possible that one solution to the identified problem would be to distort the assessment of the shipowner’s fault and impose very stringent duties of prior inspection of the autonomous vessel, which would turn de jure fault-based liability for failures in the ship’s machinery into de facto strict liability.11

Such a solution would not be revolutionary, since, with the technical development of ship mechanisms, courts of some jurisdictions have already begun to apply de facto strict liability to shipowners for any breakdowns in the ships.12 Given the well-known trend in Russian jurisprudence to replace the fault-based liability with strict liability independent of the conduct of the tortfeasor, it can be assumed that the Russian legal system will also serve as an example of establishing de facto strict liability.

As pointed out by Norwegian researchers, examples of the application of an extremely high standard of conduct, which equals to de facto strict liability, can be found in Scandinavian case law. For example, in the Bravur case, the ship’s steering gear failed while mooring. It was found that the breakdown could have been solely the fault of the vessel’s manufacturer, but both first and appeal instances held the shipowner liable for tort.13

What arguments do or can the courts use to impose liability on the shipowner in such situations? The key argument here is a fault-based failure to ensure the seaworthiness of the vessel (see the Bravur case). For example, paragraph 1 of Art. 124 of the MSC RF stipulates the carrier’s obligation to make the vessel seaworthy in advance, including ensuring that it is technically seaworthy, sufficiently equipped, and manned.

In is also noted in the foreign literature that failure to secure the seaworthiness of a vessel may be derived from “unseaworthiness or breakdown of machinery”.14 However, the problem is that the assurance of seaworthiness is not an absolute guarantee but rather a due diligence obligation.15 In other words, the shipowner is only liable for the unseaworthiness of the vessel if his fault is found.16 Moreover, under paragraph 2 of Art. 124 of the MSC RF, the carrier is not liable for unseaworthiness caused by hidden defects of the ship.

It can be assumed that defects in the artificial intelligence of an autonomous vessel, which the shipowner cannot identify and correct in advance, are such hidden defects. Consequently, even in terms of the seaworthiness of the vessel, the conduct of a normal owner of an autonomous vessel would be faultless. It should be said that the courts in such a case do or will do the same to shipowners as they often do to owners of so-called controlled things. Such things are not sources of increased danger but have such strict requirements for their maintenance that these requirements deprive the owner of any possibility of proving his innocence.17 The most famous example here is the flooding of downstairs neighbours due to a burst water pipe in the flat above.

Finally, it is needed to explore the suitability of the above approach from a legal policy perspective. It appears that any inconsistency between de jure and de facto regulation is not practical for the law system. Consequently, both the widespread tendency in Russian jurisprudence described above and the retention of a purely formal criterion of fault to hide the actual strict liability of shipowners are not satisfactory. As the Finnish authors point out, “Interpreting the statute to provide for de facto strictly liability could ameliorate the problem, yet be intellectually dishonest”.18

II. De jure and de facto strict liability of the shipowner

The proposal to raise explicitly the standard of liability of the owner of an autonomous vessel for a collision is dominant in the researches on the topic. Moreover, it can be said that for collisions caused by an error in an autonomous vessel’s software, all authors now either predict or argue for the imposition of strict liability on the shipowner. In addition, the Russian drafters of the relevant regulatory changes also say that the shipowner should continue to bear all losses arising from maritime accidents.19 Of course, he is also entitled to make a separate claim against the software developer, which is highly likely to be governed in advance in their license or other agreement. In this context, it is impossible not to agree with the foreign colleagues. Such a rigid approach to collision liability for the owner of an autonomous vessel can be justified by the following arguments.

First and foremost, application of strict liability in the sphere of such disruptive, complex, and ambiguous in terms of safety technologies will be in line with general trends in maritime law. These trends are the tightening of the grounds of tortious and contractual liability in the field of new forms of energy in transport.20

It is connected to the following two points.

1. Firstly, it is the owner of the autonomous vessel who alone gains benefit from the use of the newest but possibly dangerous equipment / machinery. Thus, imposing strict liability on him

11 would be a kind of “compensation” to society for the increased risk of harm.21 Moreover, imposing strict liability will encourage the shipowner to continually improve the technical equipment of the autonomous vessel, as has been the case in the past with trains and cars.22 It can be seen that these and similar arguments are also used to justify strict liability of the owner of a SID.

Given that under Russian law there is no obstacle to recognising the software as a separate SID within another SID (autonomous vessel),23 then a kind of “double” liability of the SID owner can be developed. Firstly, the shipowner is liable for the vessel that is usually a dangerous machine. However, in the case of a collision, this does not matter as there is a similar SID (vessel) on the opposite side. Therefore, a kind of “second tier” of liability is then used, and the shipowner is held liable for the autonomous vessel’s software, which serves as a second, additional source of danger. In other words, putting a dangerous seagoing vessel at the disposal of a “dangerous” artificial intelligence multiplies the shipowner’s liability.

Finally, it is important to keep in mind the specifics of operating an autonomous vessel whose crew is not onboard and does not risk being left on the high seas and – which is often the case – being killed in a collision or being prosecuted in a foreign jurisdiction, and therefore this crew is less motivated to prevent collisions.24

However, all these arguments do not answer the question of what to do when two autonomous ships collide. It seems that the only solution here is to “infiltrate” the “brains” of each of the collided vessels and compare whose software acted (more) “in fault”, that is made the wrong calculations. This “fault” can then be imputed to the shipowner.25

11

Another option, which has long been suggested in the foreign literature for car accidents, is to allocate liability on the basis of the initial degree of danger or likelihood of harm as regards each vehicle without examining other aspects of the tort committed.26 However, it is not clear whether and how it is possible to calculate in advance which software is undoubtedly more dangerous.

2. Secondly, the well-known problems of “catching” the vessel in fault and her owner (who is often an offshore company) are extremely important. In addition, the vessel herself may not be a valuable asset after a collision – for example, the cost of lifting the vessel from the seabed may far exceed her value.

These arguments also relate to the reluctance to shift the problems of finding the liable party, pursuing direct claim against the software developer, and taking other actions to the aggrieved party. As shown in the literature, strict liability of the shipowner is necessary to better the lot of the aggrieved party. At the same time, it is true that the recovery of compensation from the software developer is a concern for the shipowner if the cause of the collision is a technical failure of his ship.27 Finally, shipowners are generally the biggest actors in the industry who can take the risk of liability into account when building their business and obtain appropriate insurance coverage.28

In this context, it should be mentioned that a well-known solution to the problem of increasing risks in an industry is the introduction of increased financial security – compulsory insurance. The recent regulation of civilian drones in the European Union and Germany in particular may serve as an example. The cautious attitude of German law towards drones is represented in two measures taken. Firstly, drones are generally recognised as sources of increased danger.29 Secondly, a multitude of public law duties are imposed in connection with drones’ operation, including compulsory liability insurance.30

Last but not least, the argument in favour of strict liability of the owner of an autonomous vessel is a well-known personification of ships in maritime law. Even on the basis of the previously mentioned Articles 312 and 315 of the MSC RF, it can be noticed that the Code seems to give a juridical personality to a seagoing vessel. As a matter of fact, these articles are named “The Fault of a Ship in Collision” and “Presumption of Innocence of Ships” accordingly. The same applies to Art. 313 (“The Fault of Two and More Ships in Collision”).

This unusual (for lawyers of the civil law system) approach to the juridical personality of the seagoing vessel is directly related to the text of the original source of the according chapter of the MSC RF – it is the 1910 Convention. For example, the wording of Art. 3 of the Convention (“If the collision is caused by the fault of one of the vessels”) has been adapted in Art. 312 of the MSC RF as the condition “В случае, если столкновение судов произошло по вине одного из судов” (basically, it is a literal translation from English into Russian). Furthermore, the content of the Convention was predetermined by English law.

Just as an aside, it is interesting to notice the selection made when the rules of the 1910 Convention have been incorporated into the MSC RF. For example, Art. 3 of the Convention (see above) reads as “If the collision is caused by the fault of one of the vessels, liability to make good the damages attaches to the one which has committed the fault”. At the same time, Art. 312 of the MSC RF uses the wording “the one [shipowner] who is liable for the collision shall bear the losses”. Similarly, the wording of paragraph 3 of Art. 4 of the Convention “the vessels in fault are jointly as well as severally liable” and “she [the vessel] ought ultimately to bear” reads in the Russian adaptation (paragraph 2 of Art. 313 of the MSC RF) as “the shipowners… are jointly and severally liable” and “the shipowner who paid the greater sum”. Obviously, the wording of the MSC RF was influenced by the absence in the civil law system as well as in domestic jurisprudence of relevant legal constructions and understanding of a ship as a “defendant” in a tort action.

In contrast, the language of the 1910 Convention relates to the classic English law doctrine of a claim against the vessel (action in rem).

As pointed out, one of the main problems in merchant shipping is “catching” the vessel that caused the damage before she leaves a port or immediately after she calls at the port. In most cases, the shipowner just do not have other property in this jurisdiction. If the injured party fails to arrest the liable vessel, this party will either have to resort to court proceedings in another jurisdiction or try to enforce a judgment in another jurisdiction, which can be very expensive and inconvenient.

However, even to arrest a ship, the court have to establish jurisdiction over the defendant, notify the defendant of the proceedings, and comply with other requirements (fair hearing). Consequently, English maritime law came up historically with a special legal doctrine – the claim was not brought against the shipowner (in personam), but against the ship herself (in rem).31 This allows to arrest the ship in port until she is sold under the court order. This personification of the vessel (without the necessity to follow all the procedural rules) provides effective instrument for persons injured by the vessel (shipowner, crew). The shipowner might not appear in court at all if he does not consider it necessary.32

It can be said that strict liability in a ship collision caused by an error in the software of an autonomous vessel fits well with the trend of such “emancipation” of the vessel existing in maritime law.

Up to now the rules of the 1910 Convention and the same rules of the MSC RF should not have been interpreted literally, as it is obvious that the real cause of the collision is either the management or the crew of the ship.33 In other words, the anthropomorphic wording of the law34 seemed to be no more than a figurative expression.35 On the contrary, such rules now can be seen in a new perspective – the researchers discuss the juridical personality of artificial intelligence, computer systems make complex decisions on their own, and there may be no person at all liable for the collision but the AI. Therefore, it is natural that foreign authors point to a literal reading of the 1910 Convention, where the question of compensation is resolved not by determining the fault of the seafarers, shipowner, registered owner, or other juridical person, but only by establishing the vessel in fault.36 Consequently, the shipowner should be liable for a collision caused by a software error of an autonomous ship under the strict liability model, as if the ship with the “software in fault” was held a juridical person that is personally liable for the tort.

A separate question is how this new standard of liability for shipowners will be stipulated. For example, there are already proposals in the literature for the adoption of a relevant international convention.37 It is even more difficult to say how such innovations will be accepted in the shipowners’ community. History is full of cases of international conventions being paralysed as a result of their rejection by the community.38

Thus, it can be concluded that strict liability should be imposed in the future on shipowners for ship collisions caused by an error in their ship’s software. This standard of liability should be established explicitly, rather than implemented under the guise of an unachievable standard of proper conduct. When third parties are compensated, the shipowner is entitled to recourse against the software developer, which will be governed by an agreement between them.

2.2. Liability of the Software Developer

Does anything change in the liability of the software developer if, for example, his mistake made the vessel collide with another vessel? Probably not. As it was before, the IT company is directly liable to third parties for fault-based errors committed while developing the software (artificial intelligence, computer system). Moreover, the developer will be liable to the shipowner for losses caused,

11 but this aspect is barely specific for the autonomous shipping.

The only issue that may be discussed in more detail here is the possibility of a third party claim directly against the software developer in case the software error has not only resulted in a tort, but also caused a breach of contract between the shipowner and the third party.

One might think that the rules of Art. 1095 and generally paragraph 3 of Chapter 59 of the CC RF are supposed to establish an exhaustive list of cases when a third party may bring a direct tort action against the manufacturer of the goods even when he is entitled to obtain compensation from his debtor under the contract.

However, it can also be assumed that the meaning of Art. 1095 of the CC RF applies only to the manufacturer’s strict liability towards the end consumer. If the developer made a mistake by his own fault while creating the software, then he should always be ready for a direct tort claim against him on the basis of Art. 1064 of the CC RF (General Bases of Liability for the Causing of Harm).

The latter solution is more likely to ensure enough the interests of the injured party, especially in cases where such party failed to arrest the autonomous vessel or where the value of the vessel does not cover the damage caused. It seems strange that the developer’s liability would depend on the actions of the shipowner and the third party – if they did not make a contract, the developer would be liable under a direct claim by the third party, and if they did, then the developer would be liable only under the shipowner’s contractual claim.

Thus, IT companies should be ready for possible claims against them, not only for torts of an autonomous vessel but also for contractual losses of a third party if the vessel’s artificial intelligence was responsible for making incorrect navigational and other decisions. As in the abovementioned situations, the problem of liability insurance for such companies is quite acute and is subject to a separate study. Finally, the question remains as to how far such a link between the developer and his product can extend, especially as regards purely commercial transactions.

Main Conclusions

Consequently, a different view should be taken of the liability of the shipowner (but not the liability of the software developer) in the situation of collision caused by an error in the software of an autonomous vessel.

In this situation, it is more appropriate for the shipowner to compensate even the losses caused without his fault or fault of the crew. It is preferable to establish such a high standard of liability directly, which will prevent the courts from applying it implicitly under the guise of the shipowner’s fault-based failure to ensure the seaworthiness of the ship. The shipowner retains the right of recourse against the IT company and the court will have to examine not only the fault of the company but also the contents of the contract between the company and the shipowner.

There is essentially no change in the liability of the software developers to third parties. Moreover, it is theoretically possible to sue them not only for the tort of autonomous vessel but also for contractual losses of a third party in case it is proven that the software developer is in fault for the software error. Similar to the whole sphere of autonomous shipping, developers’ liability insurance needs to be researched separately given the possible imposition of liability on them. Finally, it is difficult to say how far such a link between the developer and his product should extend – this issue deserves a separate discussion.

11

Illustration from the Maritime Law journal 1/2022, p. 110

Notes

#autonomousshipping#tortliability#software#rumla#maritimelaw#internationallaw#strictliability#shipownerliability#shipcollision#artificialintelligence#sourceofincreaseddanger#actioinrem#seaworthinessofship

More on «Autonomous ships and digitalisation»
Cyber Risks: The Limits of Liability in Modern Marine InsuranceArticle · 2/2026 · Pakharenko O.CMI Conference in MontrealJournal news · 2023Database of Judicial Decisions on International ConventionsArticle · 4/2022 · Overview prepared by Konstantin KrasnokutskiyThe Bill on Autonomous Shipping: Some Concerns and SuggestionsArticle · 1/2022 · Anna Arkhipova

← The Bill on Autonomous Shipping: Some Concerns and…The Upcoming CMI Assembly in Antwerp →