Article
Autonomous Shipping in Russia: Tortious Liability of Shipowners and Software Developers. Part 1
Higher School of Economics, Moscow
Autonomous Shipping in Russia: Tortious Liability of Shipowners and Software Developers. Part 1
1. Introduction O
ne of the latest trends in the maritime industry is the development of so-called autonomous
It is not difficult to imagine somewhere in the ocean a ship operated remotely, with no crew aboard at all… It is entirely possible that in the distant future the captain’s workplace will move to some centre ashore
Schönknecht R. et al. Ships and Shipping of the Future, 19731
(unmanned) shipping. The gist of this technology is the performance of standard operations by the vessel – mainly navigating from port A to port B – in the absence of any crew aboard.
At the same time, the category of autonomous vessels can be divided into two subspecies: a semi-autonomous vessel and a fully autonomous vessel. This classification is not exhaustive, but it has already been established in foreign literature and has proved its sufficiency when discussing the legal challenges of autonomous shipping.
A semi-autonomous vessel is a vessel that is controlled to some degree remotely by people who are not aboard such a vessel. Moreover, the vessel can also be controlled from another vessel (for example, as part of icebreaker or dredger convoys)2. Artificial intelligence can take part in the handling of a semi-autonomous vessel, but some human control – of a remote operator – remains here. On the contrary, a fully autonomous vessel means a vessel whose movement is not specifically monitored by anyone – this vessel is under the absolute command of artificial intelligence (AI).
The key topic of foreign researches on private law challenges of autonomous shipping is the liability for the tortious acts. Such liability may arise for two main reasons: 1) error of a remote operator in case of a semi-autonomous vessel; 2) malfunction of the software of a fully autonomous vessel or (less often) a semi-autonomous vessel.
However, it has been repeatedly pointed out in the literature that in case of an error of the operator of a semi-autonomous vessel, there should be no unique problems when compensating the respective losses. It is connected to the similarity of the legal status of remote operators and the status of the traditional crew of a vessel3. In addition, the very chance of human error, even in case of a semi-autonomous vessel, is to be reduced greatly due to the capabilities of computer systems.
In contrast, if an error of artificial intelligence and the resulting harm to a third party raises a number of questions in regard to the tortfeasors and the allocation of liability among them.
At first glance, it seems that the tortfeasor here is the one who controls the ship – that is, artificial intelligence (software). However, does not such a decision mean that the injured parties will be de facto deprived of compensation for the damage caused? It is so at least because AI today is fundamentally not subject to tortious liability (as well as to any liability at all).
Perhaps then the software developer should be held liable as the creator of the object (in the broad sense of the word) that has been a source of harm? However, how fair would that be from the point of the foreseeability and remoteness of harm? And what should be the answer if the error is not related to the faulty actions of the developer?
Finally, liability can be imposed on the shipowner as the main user of an autonomous vessel and the beneficiary of the activities that such a vessel carries out. However, the shipowner did not create and (most likely) did not even train the AI, he is not an expert in the relevant technologies at all. Moreover, perhaps it is why the shipowner has chosen a vessel with advanced software – to avoid or reduce his losses due to improper control of the vessel.
Therefore, tortious liability in case of a malfunction of the software of an autonomous vessel becomes a pressing issue for private maritime law. There are two most likely grounds on which such liability may arise:
1) infliction of loss to an object other than a vessel;
2) collision with another ship.
This article is devoted to the first case – that is, tortious liability for infliction of harm not to a ship but to any other object, under Russian law. Firstly, the liability of the owner of the autonomous vessel will be defined, and then the liability of the software developer.
2. Tortious Liability if There is No Ship Collision
2.1. Liability of the Shipowner
As it was pointed out in the literature, the most common example of a tort commited by a vessel without a collision with another vessel is damage to port facilities. As a rule, it is a case of a collision at low speed and with a modest loss of property (although sometimes it reaches millions of dollars). The legal relations arising from that are governed by the norms of national law (lex loci delicti commissi)4.
Consequently, in case of a malfunction in the software of an autonomous vessel and infliction of harm to facilities of a Russian port, the respective liability will be governed by the norms of the Civil Code of the Russian Federation (CC RF). Until now it has been generally recognised that in such cases Article 1079 of the CC RF on the infliction of harm by a source of increased danger (hereinafter also referred to as SID) is to be applied – the shipowner shall be freed from liability only if he proves that the harm arose as the result of force majeure or the intent of the victim5.
In addition, a source of increased danger is usually understood in literature and in case law to mean activity with increased danger or with the usage of a particularly dangerous object (or as this object itself), which is associated with the impossibility of full or permanent human control over such activity (such an object)6.
However, in the course of the development of autonomous shipping, several important issues may arise in regard to the application of provisions on sources of increased danger to autonomous vessels. Each of them should be considered separately.
I. Is an autonomous vessel a source of increased danger?
It should be noted that one of the main advantages of autonomous vessels is a reduction in the number of accidents and incidents at sea. It is related to the fact that statistically approximately 80% of incidents are associated with intentional or (more often) negligent actions of people7. In other words, an increase in the safety of activities is reached because of a decrease in human control over it. A contradiction stands out here: from the point of classical tort law, an autonomous vessel is a source of even greater danger compared to an ordinary vessel; on the contrary, the real chance of an accident due to a computer error is tens and hundreds of times less than due to human negligence.
It seems that the key to the problem resides in the answer to the question of how soon after the alleged spread of artificial intelligence it will be possible to confirm a really drastic change in the difference between the security level of human activity and the security level of AI activity. As has been repeatedly pointed out in the literature, software algorithms “are notable for a high degree of complexity which makes them an obscure system (a “black box” in the technical literature) even for the developer”8. One can check the meaning and accuracy of AI calculations only by complex technical methods9. This leads to a high degree of unpredictability of AI decisions and an increase of the risk of errors at the first stages of its application (the training period). No less important implication is the lack of real opportunities for the captain, crew and shipowner to identify and prevent defective AI calculations in advance10.
Therefore, at the first stages of the autonomous vessels use, a dramatic increase in the safety of navigation may be slightly late. Then the modern interpretation of a seagoing vessel as a SID will correspond enough to the danger to those around that stems from an autonomous vessel.
II. Is the owner of an autonomous vessel the owner within the meaning of Article 1079 of the CC RF?
A curious opinion was recently expressed in the literature that the harm caused by autonomous vehicles (cars were meant) “may differ fundamentally from the harm caused by usual vehicles”11. According to the authors, if it comes to a high degree of autonomy of the vehicle, then it is not possible to insist on the infliction of harm by the owner of the SID. It is associated with the fact that the owner of the autonomous vehicle is always only the passenger therein (like a customer in a taxi), he does not actually control the movement of the mechanisms of the car. Meanwhile, in order to hold a person liable as a SID owner, it is necessary that the loss is inflicted when this owner carries out activities that create increased danger. Consequently, Article 1079 of the Civil Code shall not be applicable to torts committed while the operation of autonomous vehicles. Nevertheless, the authors leave the problem of retaining the burden of strict liability on the owners of autonomous vehicles at the discretion of the legislator (legal policy)12.
These arguments are not free from shortcomings. Firstly, as the authors themselves correctly note, the Supreme Court of the Russian Federation interprets the SID owner as any legal entity or individual who lawfully exploits a SID13. Moreover, the authors admit that an unmanned vehicle is a source of increased danger. However, it is obvious then that the very use of an autonomous vehicle on any legal ground already makes a person the SID owner. Generally speaking, civil law barely has cognisance of the simultaneous existence of a SID and at the same time absence of the owner of this SID. Is not the meaning of the institution of SID as the basis for imposing strict liability lost in such a paradox?
Secondly, it seems an unnecessary sophistication to simultaneously refuse to apply Article 1079 of the Civil Code to autonomous transport torts and at the same time introduce strict liability for their owners based on other grounds. The fact is that the institution of SID is used more flexibly in Russia than the mentioned authors suggest. For example, it is a known position of the Supreme Court of the Russian Federation that a person who manages a SID only for the performance of labour or other similar duties under an employment or civil law contract, concluded with the real SID owner, is not deemed as the SID owner14.
It can be readily seen that it is difficult to affirm in this case any direct control of the SID owner over the operation of this SID. Nevertheless, the SID owner retains both his status and the burden of strict liability. It is also possible to develop the argument of the Supreme Court and suppose that in the case of autonomous vessels, shipowners shall be liable for the miscalculations of artificial intelligence in the same way as the employer is vicariously liable for the employee he hired15.
Generally speaking, it is difficult to find another person, apart from the shipowner, who could be deemed as the SID owner. However, it is always necessary to take into account a separate problem which is not specifically deliberated on in this work – it is the distinction between the liability of the shipowner and the registered owner of the vessel for the damage caused by the vessel. It is known that under Russian law any person who operates a ship on his own behalf is understood to mean a shipowner (Article 8 of the Merchant Shipping Code of the Russian Federation (MSC RF)). That person can be either a ship manager, or a ship operator, or a bareboat charterer, or any formally or substantially other participants of merchant shipping industry. However, such an owner often does not have any property that could be used to satisfy the claims of the injured persons based on Article 1079 of the CC RF. Therefore, claimants usually engage the registered owner of the vessel in the dispute as well because the seagoing vessel can be sold profitably at auction in the future. In judicial practice, the liability is imposed on the registered owners from time to time, even if they had absolutely nothing to do with the tort committed. As a rule, either the institution of a maritime lien on a ship is applied for this purpose (Articles 367–373 of the MSC RF), or the registered owner of the vessel is held to be the SID owner within the meaning of Article 1079 of the Civil Code16.
2.2. Liability of the Software Developer
The second subject that may be liable for infliction of harm due to the failure of the AI of an autonomous vessel is the developer of such an AI. Literally all foreign researches that deal with liability for the acts of autonomous vessels also discuss the liability of developers of software for such vessels. Indeed, since in the future the maritime industry will rely more on computer systems, part of the turnover will be taken over by IT companies professionally engaged in software development. However, the corresponding risks associated with the malfunction of the product they produce should also pass to them along with the profits.
As regards the relationship between ship owners and software developers, these risks can and most likely will be distributed under the contract. It is unlikely that there will be many peculiarities here associated exactly with autonomous vessels. It seems correct that, as the foreign authors state, in most cases events will develop precisely according to the scenario “compensation for damage by the shipowner / his insurer => recourse / subrogation claim under the contract with the software developer”17.
On the contrary, there is no such certainty in regard to tort liability. As noted in the literature, it is still unclear what are the conditions for software developers’ liability for harm caused to third parties. Moreover, it is unclear whether this liability shall be fault-based or strict18.
It seems that in general there are no obstacles to imposing tortious liability on software develo pers – the only question is how strict it shall be. In this regard, it is necessary to keep in mind some circumstances that go beyond the legal dogmatics.
The first thing to consider is what the possible economic response of those entities that will bear new risks might be. As rightly pointed out by experts, it is undesirable to transfer all the risks of losses from the use of new technologies to their deve lopers at once, because in this case they will lose any interest in continuing their activities19. Moreover, the transfer of risks to IT companies will also create difficulties in assessing the scope of such losses. And this in turn may lead either to the impossibility of insurance coverage of such risks or to extremely high insurance premiums which will be unaffordable for software developers20.
Consequently, it is necessary to find a balance between the full irresponsibility of the software developer and his absolute liability for any defects, some kind of diversification of liability among market participants is needed21. Therefore, it seems reasonable to use the standard of fault-based liability of IT companies towards third parties – just as it is proposed to do in general with all developers of artificial intelligence systems22.
It appears that for Russian law such a solution would not only be balanced but also relatively simple to implement within the framework of the current regulation. Obviously, Article 1095 of the CC RF is not applicable in the situation described at least because artificial intelligence is bought by the shipowner for commercial purposes. Therefore, it is necessary to use the general tort law provisions (Art. 1064 of the CC RF). It seems reasonable that the fault of the software developer is presumed given that it should be easier for him as a professional to demonstrate the exercise of due care and prudence in creating a digital product.
Perhaps the well-known objectification of fault in Russian judicial practice in the field of torts will serve here as an additional balancer. It is almost always a case that to impose liability on an entrepreneur it is actually enough to establish illegality (wrongfulness), harm and the connection between them23. However, even such a proposal may be subject to criticism since the formally fault-based liability of software developers will serve as the shelter for actually strict and excessive liability. Unfortunately, the problem here is that it is difficult to propose an easier standard of conduct for software developers. In this case, it is possible only to hope that Russian courts will soften their approaches to the criterion of fault and that this criterion will be taken into account when resolving specific disputes.
The ambiguity of the issue is evidenced by the relevant European researches. From the very beginning, their authors build on a slightly different regulatory framework, which includes national legislation on defects of goods (works, services) and Directive 85/374/EEC of July 25, 1985, on the approximation of the laws, regulations and administrative provisions of the Member States concerning liability for defective products. This Directive is in force for all EU countries and countries of the European Economic Area24. Under this Directive manufacturers are strictly liable for the quality of their products (strict product liability). At the same time, it is concluded in most researches that the application of such a liability standard in the sphere of software development for autonomous ships would be an adequate solution to the contradictions already described above25. Some authors even call for exemption of the shipowner from liability always in case of damage caused purely due to the software designer’s mistake26.
However, other papers have expressed doubts concerning the application of strict product liabi lity to IT companies in the autonomous shipping sphere. This is largely due to the protracted debate as to whether the EEC Directive applies to new products such as artificial intelligence systems27. Even among works on autonomous shipping, there are both those where it is acknowledged that the Directive covers the software28 and those where it is said that such extensive application is not possible29.
In any case, it is clear that if a survey of the ship after it has been damaged reveals that the software malfunction could have been avoided through repair or maintenance (e.g. by installing appropriate upgrades)30, the liability should fall solely on the shipowner. It is the owner who bears liability for maintenance of the ship and its machinery in a condition that meets all standards. The same conclusion is valid if the shipowner exploited his vessel against the law31.
Finally, the following important question arises in connection with what has been said. Is the software developer entitled to the same limitations of liability that shipowners actively benefit from in modern maritime law? As noted in the literature, there is some contradiction here because the general rules on full recovery of losses have to be applied in an industry with a long tradition of limitation of liability32.
The starting point for answering the question can be the provisions of Chapter XXI of the MSC RF. These provisions are based on the rules of the Convention on Limitation of Liability for Maritime Claims, 1976 (hereinafter – the 1976 Limitation Convention).
On the one hand, according to subparagraph 1 of § 1 of Article 355 of the MSC RF, the limitation of liability covers, in particular, any claims arising from damage to port facilities inflicted in direct connection with the operation of a ship. However, the commentaries rightly draw attention to the words “in direct connection with the operation of a ship”. It is pointed out that they have “extended to a certain degree the scope of this subparagraph to include claims related to acts outside a vessel and not arising out of the operation of a vessel”33. As it can be seen in foreign sources, it may seem due to the aforementioned expansive interpretation that the 1976 Limitation Convention should also be applied to tortious liability for defects in the software of an autonomous ship34.
However, under paragraphs 1 and 2 of Article 354 of the MSC RF, marine claims can be limited if they are brought against a shipowner, an insurer, a salvor and persons for acts or omissions of whom the shipowner or the insurer are liable. Neither the MSC RF nor the 1976 Limitation Convention provide for the list of persons for whom the shipowner is liable, which is why this wording is understood differently in different jurisdictions. Under Russian law, it is interpreted restrictively and is regarded as referring only to the protection of shipowner’s employees and agents35. Similarly, in Finland and Norway, the shipowner is liable for third parties only if the work they perform falls within “typical shipowner’s activity”36. The creation of a complex IT product – artificial intelligence – barely falls into this “activity”. This activity would rather include the actions of, for example, a programmer who is hired by the owner of an autonomous ship to install computer system updates or the actions of a remote operator of a semi-autonomous ship37.
Consequently, at least de lege lata third party claims against software developers are not subject to the limitations of liability under maritime law. One way or another, a similar conclusion is reached by the majority of foreign authors38.
Main Conclusions
We can draw the following conclusions in regard to the liability of the shipowner and the software developer for damage caused by an autonomous vessel to an object other than another seagoing vessel.
The first and main person on whom liability should be imposed in such a situation is the shipowner as the owner of a source of increased danger39. Moreover, both the traditional approaches to the definition of the SID and its owner remain valid, as well as the main arguments in favour of imposing on such an owner the burden of strict liability.
In turn, the software developer may be held liable for errors of the autonomous vessel along with the shipowner. This would be a natural reflection of the principle of simultaneous transfer to economic entities not only the profits from their activities but also the inherent risks of such activities. At the same time, it is likely that in most cases there will only be a recourse claim by the shipowner against the software developer based on the contract between them. However, a direct claim of third parties based on Article 1064 of the CC RF may also be brought against the IT company. The principle of guilt and the presumption of fault of the tortfeasor will be applicable here.
In this regard, Russian courts need to take a more balanced approach to fault as a criterion of software developers’ liability. It is important to take in each case into account both particular and general consequences for the industry of imposing liability on a person. Software developers should take into account that in case they are held liable they will not be entitled to the same limitations of liability that are currently stipulated in favour of the shipowners.

Notes
