Share this post

AI and Robotic Surgery: Innovation, Risk and Legalities

With robotic surgery growing at a remarkable pace, we look at who is liable if it all goes wrong.

The operating theatre is changing. What was once the sole domain of a surgeon’s steady hands is now increasingly assisted – and in some cases directed – by robotic systems and artificial intelligence (AI). For patients, it is expected to offer greater precision, smaller incisions and faster recoveries. But as this technology reshapes modern medicine, it raises a critical question when something goes wrong: who is responsible?

Robot-assisted surgery in the UK has grown at a remarkable pace. According to the Private Healthcare Information Network (PHIN), there was a 626% increase in robot-assisted procedures across the NHS and private sector between 2017 and 2022, with more than 100,000 procedures conducted in 2024 alone – a stark contrast to 11,000 in 2016. NHS England now projects that robotic assistance will support half a million operations per year by 2035, with nine in 10 keyhole surgeries expected to involve keyhole surgeries expected to involve robotic technology within a decade.

Guy’s and St Thomas’ NHS Foundation Trust, which installed its first da Vinci surgical system in 2004, became the first UK trust to complete 10,000 robotic cases in 2023 – a landmark that illustrates how embedded this technology has become in mainstream care. Today, robotic procedures span urology, gynaecology, thoracic and general surgery, with 67% of NHS trusts operating at least one robotic system as of 2024, compared to just 20% a decade ago.

The benefits are well-documented: enhanced precision, reduced blood loss, shorter hospital stays and faster patient recovery. Robotic systems such as the da Vinci eliminate natural hand tremors and allow surgeons to operate through incisions no wider than a few millimetres. Yet the integration of these systems into medicine does not eliminate risk – it transforms it.

Complications from robotic surgery can arise from system malfunctions, software errors, inadequate surgeon training, or the simple absence of tactile feedback that experienced surgeons rely on. A particularly sobering case unfolded at the Freeman Hospital in Newcastle in November 2015. A patient, Stephen Pettitt, died from complications following a robotic heart surgery. The inquest revealed that the operating surgeon admitted he “could have done with more dry-run training” on the robot because he’d had no one-on-one training on the device. Crucially, the manufacturer’s technical experts – known as ‘proctors’ – who were supposed to be present throughout the operation, left halfway through the procedure. The coroner concluded that Mr Pettitt’s death was a “direct consequence of the operation and its complications,” and that the cause of his death was in part because “the operation was undertaken with robotic assistance.” The coroner also acknowledged an “absence of any benchmark” for training on modern technologies in healthcare technologies. The Trust’s medical director issued an apology, acknowledging a failure to ensure the standard of care reasonably expected.

This case is not an isolated one, and other complications have been reported by hospitals across the globe. But who is responsible when the tech goes wrong?

The Complex Case of Liability

Medical negligence law in the UK is well-established in principle; a claimant must demonstrate that a duty of care existed, that this duty was breached and that the breach caused harm, whether that is injury, complications to an existing injury or the death of a patient. In conventional surgery, identifying the responsible party is relatively straightforward. In robotic and AI-assisted surgery, it is anything but.

When robotic surgery goes wrong in the UK, responsibility depends on the reason why the surgery failed. If a surgeon used the robotic system negligently, made poor clinical decisions during the procedure, failed to inform the patient of the risks or didn’t perform proper pre-operative checks, they could be liable. However, the question of whether a medical negligence claim is brought against a surgeon or the employer always depends on the indemnity arrangements in place. NHS surgeons are always indemnified by the Trusts they work for – private-sector surgeons usually have their own insurance arrangements in place.

If the injury was caused by a machine or software defect, the manufacturer of the device may also face liability under product liability laws such as the Consumer Protection Act 1987. Were the claim to be brought as product liability, then it would be subject to the relevant rules and limitation periods associated with such claims. However, the claimant should take action as soon as possible after an injury, and certainly within three years of the injury occurring.

This complexity is not merely theoretical. The iRobotSurgeon Survey, a peer-reviewed international study, gathered responses from 2,191 participants across 78 countries and found that as robots took on more decision-making, people were less likely to blame the surgeon if something went wrong. However, even in situations where a fully autonomous robotic system makes decisions without human input, many respondents still believed the surgeon should share responsibility. The findings show there is still no clear consensus on who should be held accountable when harm is caused by a fully autonomous technology. Researchers noted concern that human operators risk becoming what they called a “moral crumple zone,” absorbing disproportionate responsibility when accidents occur, even where the technology itself was at fault.

Technology in Healthcare and Data Protection

Beyond the operating theatre, AI’s role in healthcare introduces a separate but equally serious risk: the security of personal data.

AI systems in healthcare typically require access to vast datasets of patient information for training and real-time analysis. This data is transmitted to centralised cloud servers, and it is important to note that, once the health data leaves the healthcare provider’s own systems, control can be substantially diminished. Common areas of risk include bias from training data, a lack of transparency, and privacy vulnerabilities arising from the extensive data requirements of AI systems.

In June 2024, Synnovis, a supplier of pathology services to the NHS, was struck by a ransomware attack. The attack resulted in the theft and publication of nearly 400GB of patient data, disruption to blood transfusion services, and postponements to operations and appointments. Tragically, the attack has also been linked to at least one patient death.

In a separate incident, NHS IT provider, Advanced Computer Software Group Ltd (Advanced), was fined £3 million by the Information Commissioner’s Office (ICO) after a 2022 ransomware attack compromised the data of nearly 80,000 people and temporarily shut down the NHS 111 service. The ICO described Advanced’s security measures as falling “seriously short” of what is expected from an organisation processing such a volume of sensitive information.

Under the UK GDPR and the Data Protection Act 2018, health data is classified as a special category of personal data, attracting heightened legal protection. The ICO has published dedicated guidance on AI and data protection, requiring organisations deploying AI systems to embed data protection principles from the outset – a concept known as data protection by design. Failure to meet these obligations can result in fines of up to £17.5 million or 4% of global annual turnover, as well as compensation claims for distress and loss by affected individuals.

The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, has further strengthened the framework by establishing mandatory information standards for health and social care IT systems and broadening the rules around automated decision-making – both of relevance as AI becomes more deeply embedded in clinical care.

What Patients Should Know

If you or a loved one has suffered an injury following robotic or AI-assisted medical treatment, the legal avenues available to you are the same as in any medical negligence case, but the investigation required is considerably more intricate. Robotic surgical systems maintain detailed metadata logs of every procedure, recording in real time the movements made and the programming used. Unlike surgery performed by hand, where the surgeon’s own post-operative notes form the primary record, these logs provide an objective account of what took place. They can be invaluable evidence in establishing what went wrong and why.

The pace of adopting technology in healthcare shows no signs of slowing down. NHS England’s ambition to make robotic assistance the default for keyhole surgery within a decade represents a profound transformation of surgical care. As AI moves from assisting surgeons to augmenting clinical decision-making more broadly, the legal frameworks that govern accountability, consent and data protection will need to evolve with it.

For now, the law treats robotic systems as tools and their operators as accountable professionals. But as machines grow more autonomous and algorithms more influential, the question of who – or what – bears responsibility for a patient’s outcome will become one of the defining legal challenges of modern medicine.

If you believe you are a victim of medical negligence, whether it is at the hands of a human being or following robotic or AI-assisted medical treatment, our team can help you bring a claim to ensure you receive the justice and compensation you deserve.

Contact us today by clicking the button to get started.

Share this post

Other Blog Posts

Start Your Medical Negligence Claim

If you have suffered as a result of medical negligence, our team can help you claim compensation.