ABSTRACT
“Increasingly, artificial intelligence (AI) operates through geographically fragmented systems, in which development, training, processing, deployment and potential harm can take place across various jurisdictions. This fragmentation reveals a fundamental structural deficiency of private international law as it still relies on connecting factors that are linked to geographical elements such as domicile, conduct, injury, and place of performance. Although some legal instruments address specific aspects of digital activities, including the Brussels I Recast Regulation, Rome I Regulation, Rome II Regulation, GDPR, EU AI Act, and UNCITRAL instruments, no methodological framework exists for determining jurisdiction and applicable law in disputes involving AI. The main thesis of the paper is that territoriality should neither be abandoned nor should it be a decisive factor. Instead, courts should use an AI Connection Test, analyzing the connections relating to defendant, deployment, harm, market, data, operation, and regulation, alongside foreseeability and fairness, in order to establish jurisdiction. With respect to choice of law, there should be a corresponding “closest and most significant AI connection” test, distinguishing between contractual, consumer, data protection, tortious, product liability, and regulatory disputes. The idea is to balance justice access, regulatory sovereignty, predictability and protecting people who are affected.”
KEYWORDS Artificial Intelligence; Cross-Border Disputes; Private International Law; Jurisdiction; Choice of Law; Extraterritoriality; Algorithmic Liability; Digital Governance.
INTRODUCTION
Consider a diagnostic AI system created by a US-incorporated company, trained based on data collected in India, with the computational resources of which spread through various nations, deployed by a hospital in Germany, and that causes damage to a French patient. The ensuing legal action would raise issues related to contract law, product liability, data protection, consumer protection and tort law all at the same time. As a consequence, it is far from clear where the conduct took place for legal purposes.
The territorial assumption becomes complicated in the case of AI precisely because of the geographical dispersion of the entire life cycle of the technology. Different stages such as development, training, deployment, data processing and effects may occur in different States. At the same time, AI can function non-stop and without any human involvement, while data can be transmitted over national boundaries instantly.
Private international law in its traditional form is still used to arrange jurisdiction on the basis of notions such as the defendant’s domicile, territorial act, locus in quo, and performance of contract. In the United States, there must be an adequate connection between the defendant, forum and the claim, whereas the system used in Europe provides for domicile-based jurisdiction together with special provisions for contracts and torts.The Indian system, in turn, bases jurisdiction on defendant’s residence, business, and locus in quo of the cause of action
It is submitted in the present article that these notions retain their value but are inadequate connecting factors for AI systems.
EXISTING LEGAL FRAMEWORK: WHERE TERRITORIALITY CURRENTLY STANDS
- TRADITIONAL JURISDICTIONAL PRINCIPLES
Traditionally, private international law has relied on domicile or residence of the defendant, occurrence of the detrimental event, the location of contractual performance, or other connection between the case and the forum in determining jurisdiction. Forum selection clauses may also take into account party autonomy but subject to legal restrictions.
In US law, the creation of connections by the defendant with the forum is particularly relevant. In Walden v. Fiore, for example, the Supreme Court held that personal jurisdiction should be created by contacts established by the defendant with the forum. But in Ford Motor Co. v. Montana Eighth Judicial District Court, the Court acknowledged that commercial activities in the forum by the defendant can create the necessary relationship, even though the particular product that caused the damage was never sold there.
The Indian legal system allows jurisdiction in cases where the defendant resides, does business, or works for his personal profit and where the cause of action either wholly or partially arises, according to Section 20 of the Code of Civil Procedure, 1908. With regards to the online world, Banyan Tree Holding (P) Ltd. v. A. Murali Krishna Reddy stated that mere availability of the site would not suffice.
- CHOICE OF LAW
Choice-of-law rules similarly rely upon connecting factors. Rome I prioritises party autonomy for contractual obligations, while Rome II generally directs non-contractual obligations toward the law of the country where damage occurs.These rules promote predictability but become difficult where AI-generated harm has multiple geographical manifestations.
- DIGITAL AND AI FRAMEWORKS
The EU has also gone beyond territoriality through means such as the GDPR and EU AI Act. Article 3 of the GDPR may apply to the processing activities of parties located outside the Union in situations where there are certain links with people or activities within the Union.Article 2 of the AI Act applies to some third country suppliers and users, as well as where the output from AI systems located outside the EU is being used within the EU.
In terms of EU law, Brussels I Recast contains the rules regarding jurisdiction and recognition of civil and commercial judgments, whereas Rome I and Rome II deal with contractual and non-contractual obligations.UNCITRAL has adopted a technology neutral approach to this issue via its Model Law on Electronic Commerce and its recent Model Law on Automated Contracting (2024). The former provides for the legal recognition of automation and AI in contract-making and performance, including attribution of outputs of automated systems. Notably, UNCITRAL makes it clear that the Model Law does not constitute a full set of rules for AI or any issues outside the contractual context.
In consequence, the law has been able to adapt to the process of digitalization but is sectoral in nature. It is able to acknowledge automation and regulate foreign entities that use AI, depending on the case at hand.
WHY THE EXISTING FRAMEWORK IS INSUFFICIENT
The key issue is jurisdictional fragmentation, because an AI system can be covered by multiple jurisdictions depending on its use and deployment: the domicile of the defendant, the residence of the plaintiff, the place of deployment, the place of data processing, the targeted market and the place where the injury occurs.
The “place of injury” criterion has been especially difficult to apply to AI decisions, because an AI decision might be made using infrastructure in one country and data from another country, deployed in a third country and having consequences in yet a fourth. Choosing one location over all the others for legal purposes could amount to disregarding the technological and commercial context that led to the injury.
Identification of the responsible party also becomes difficult because an AI system can include developers, foundation model providers, deployers, data providers, distributors and end-users. It may not always be possible to identify whose conduct was relevant under the rules of international private law.
Moreover, jurisdictional fragmentation poses risks of law overlap, regulatory conflict, forum shopping and challenges in recognition and enforcement. Party autonomy can give certainty to commercial relations, but cannot replace mandatory rules.
Thus, territoriality is not outdated; territoriality alone is not sufficient. The question should be how jurisdiction has the most legitimate and strong relationship to the dispute of the AI.
THE PROPOSED “AI-CONNECTION TEST”
The proposed approach for assessing jurisdiction is called the AI-Connection Test. Instead of privileging one location by default, the court should consider eight connections.
First, Defendant Connection: where is the developer or responsible company established or operates primarily from?
Second, Deployment Connection: where was the AI deployed or used?
Third, Harm Connection: where is the claimant located and where the harm occurred?
Fourth, Market Connection: was the system designed specifically for users in the forum?
Fifth, Data Connection: where was data collected, processed and used?
Sixth, Operational Connection: where were the actual computing and/or decision making activities done?
Seventh, Regulatory Connection: which jurisdiction has the greatest legitimate regulatory interest in this case?
Eighth, Predictability/Fairness: can the defendant reasonably anticipate jurisdiction of this forum and its laws?
Such considerations should not be accorded equal weight. Rather, their relative importance should depend upon the nature of the dispute. Where there is discrimination by the AI system against a local person, the factors of harm, operation and regulation may play a larger role. Where there is an automated business transaction, the factors of defendant, contract and market may take on more importance.
The analysis thus does not render territoriality irrelevant, but rather transforms it from an inflexible requirement into one factor among others in determining substantial AI connection.
PROPOSED CHOICE-OF-LAW RULE
There is no reason why the questions of jurisdiction and choice of law should merge. As far as contractual AI disputes are concerned, party autonomy should be the principle, while the mandatory rules on consumers, data protection, and safety standards should take precedence. If the dispute concerns consumers, more weight should be given to the habitual residence of the consumer and the market targeted by the AI system. If the dispute pertains to data protection, then the law that governs the particular data protection regime should apply if its territorial requirements are met.
For the tortious harm caused by AI and product liability, this article suggests adopting a closest and most significant AI connection test. Determining the applicable law would depend on the place of harm, connection of the claimant, defendant’s connection, deployment of AI, market targeting, and regulatory interests. Disputes concerning intellectual property may still need to meet stronger territorial connections as the IP rights are territorially based.
PRACTICAL APPLICATION AND INTERNATIONAL COOPERATION
The suggested scheme can be used in relation to the case of a US-originated AI system developed based on the Indian database that is applied in Germany and causes damage to a patient from France. In this case, the court will determine the type of claim and assess the relations with the particular AI system. If the claim is about negligent deployment, the emphasis will be placed on Germany and France, but if it relates to the data protection, the focus will be made on the connections concerning data and the claimant.
International cooperation is still needed to facilitate recognition and enforcement of judgments. The neutral attitude of UNCITRAL to technologies is helpful in this situation as a basis for establishing harmonized principles, and arbitration can be an alternative for certain commercial AI claims.
CONCLUSION
AI has not eliminated territoriality; it has made territoriality alone inadequate. The distributed nature of AI requires private international law to move beyond reliance on a single geographical connecting factor. The proposed AI-Connection Test combines defendant, deployment, harm, market, data, operational and regulatory connections with foreseeability and fairness. Its corresponding closest and most significant AI connection approach provides a flexible basis for determining applicable law while preserving party autonomy and mandatory protective rules.
This framework seeks to balance access to justice, regulatory sovereignty, predictability for AI developers and businesses, protection of affected individuals and prevention of forum shopping. The future of cross-border AI disputes should therefore move from asking “where did the conduct occur?” toward asking “which jurisdiction has the most legitimate and substantial connection to the AI dispute?”
REFERENCES
- Cases
- Walden v. Fiore, 571 U.S. 277, 283–85 (2014).
- Ford Motor Co. v. Montana Eighth Judicial District Court, 592 U.S. 351, 359–65 (2021).
- Banyan Tree Holding (P) Ltd. v. A. Murali Krishna Reddy, 2009 SCC OnLine Del 3780 (Delhi High Court, 2009).
- Indian Legislation
- The Code of Civil Procedure, 1908, § 20 (India).
- European Union Regulations
- Regulation (EU) No. 1215/2012 of the European Parliament and of the Council of 12 December 2012 on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters (Brussels I Recast), arts. 4, 7, 25, 2012 O.J. (L 351) 1.
- Regulation (EC) No. 593/2008 of the European Parliament and of the Council of 17 June 2008 on the law applicable to contractual obligations (Rome I), arts. 3–4, 2008 O.J. (L 177) 6.
- Regulation (EC) No. 864/2007 of the European Parliament and of the Council of 11 July 2007 on the law applicable to non-contractual obligations (Rome II), arts. 4–5, 2007 O.J. (L 199) 40.
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation), art. 3, 2016 O.J. (L 119) 1.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), art. 2, 2024 O.J. (L 168) 1.
- International Instruments
- UNCITRAL Model Law on Electronic Commerce (1996). United Nations Commission on International Trade Law.
- UNCITRAL Model Law on Automated Contracting (2024). United Nations Commission on International Trade Law.
“PRIME LEGAL is a National Award-winning law firm with over two decades of experience
across diverse legal sectors. We are dedicated to setting the standard for legal excellence in
civil, criminal, and family law.”
WRITTEN BY: KHWAISH SACHDEVA


