Civil Law And Ai-Based Occupational Health Risk Prediction Liability In Europe .

Civil Law And AI-Based Occupational Health Risk Prediction Liability In Europe

1. Introduction

AI-based occupational health risk prediction refers to the use of artificial intelligence, machine learning, predictive analytics, wearable-device data, workplace sensors, medical information, productivity data or environmental information to predict whether a worker may face a health or safety risk.

Examples include AI systems predicting:

occupational stress or burnout;

heat stress;

respiratory disease;

musculoskeletal injury;

fatigue;

workplace accidents;

chemical exposure;

hearing damage;

cardiovascular risk;

ergonomic injury;

dangerous working patterns;

exposure to toxic substances;

future sickness absence.

The legal problem arises when an AI system incorrectly predicts, fails to predict, or improperly acts upon an occupational health risk.

For example:

An AI system predicts that a worker has a low risk of heat injury. The employer therefore does not provide additional protective measures. The worker subsequently suffers serious heat-related illness.

Or:

An AI system predicts that a worker is at high risk of stress-related illness. The employer uses that prediction to reduce the worker's responsibilities or terminate employment.

These two situations involve very different legal questions. The first concerns failure to protect health, while the second may involve privacy, discrimination, employment rights and unlawful processing of health data.

There is currently no major European judgment specifically deciding civil liability for an AI occupational-health prediction system. Therefore, the strongest analysis combines the EU AI Act, occupational-safety law, GDPR and established CJEU/ECtHR jurisprudence on workplace health risks, automated profiling and access to information.

2. Core Legal Framework

The principal legal regimes are:

EU AI Act

GDPR

EU Framework Directive 89/391/EEC on occupational safety and health

EU Working Time Directive 2003/88/EC

EU equality and employment law

EU Charter of Fundamental Rights

European Convention on Human Rights

National civil/tort/delict and employment law

Product liability law where the AI is itself a defective product

Contractual liability between employer and AI provider

The basic liability structure is:

AI prediction error + employer/managerial reliance + failure of reasonable protection + causation + injury = potential liability.

3. EU AI Act and Occupational Health

The AI Act is particularly relevant because it recognises that AI used in employment and worker management can significantly affect workers' rights.

AI systems used in employment and worker management for matters such as allocating tasks, monitoring or evaluating workers can fall within the high-risk AI framework, subject to the detailed classification rules and exceptions in Article 6 and Annex III. The AI Act specifically identifies risks to workers' rights and the possibility of discriminatory outcomes. (EUR-Lex)

This is highly relevant to occupational-health prediction because a system may simultaneously:

process health-related information;

profile workers;

make predictions about individual workers;

influence employment decisions;

influence workplace safety measures.

The AI Act requires appropriate risk management for high-risk systems. Article 9 establishes a continuous and iterative risk-management process covering reasonably foreseeable risks to health, safety and fundamental rights throughout the AI system's lifecycle. (EUR-Lex)

Therefore, an employer cannot necessarily argue:

“The AI worked correctly when we purchased it.”

The relevant question can be whether the system remained adequately monitored, validated and controlled during its actual deployment.

4. Employer's Existing Occupational-Safety Duty

AI does not replace traditional occupational-safety obligations.

The foundational EU instrument is Directive 89/391/EEC.

Its basic philosophy is that employers have duties concerning the safety and health of workers in every aspect related to work.

This is particularly important for AI prediction because the employer remains responsible for the workplace even when technological tools are used to assess risks.

5. Case 1 — Commission v United Kingdom, C-127/05

Court: CJEU
Date: 14 June 2007

This case concerned Article 5 of Directive 89/391/EEC and the employer's duty concerning worker safety and health.

The case is important because it addresses the scope of the employer's occupational-health responsibilities and the relationship between employer liability and the EU framework on workplace safety. (Infocuria)

Application to AI

Suppose an employer uses an AI occupational-health prediction platform.

The employer cannot simply say:

“The algorithm was responsible.”

The employer still has to consider whether its overall health-and-safety system was adequate.

For example:

Was the AI properly validated?

Were known limitations understood?

Was human supervision provided?

Were workers informed?

Were obvious warning signs ignored?

Was the AI treated as the only risk-assessment mechanism?

Principle

Delegating risk prediction to technology does not automatically eliminate the employer's occupational-safety responsibility.

6. Case 2 — M v European Medicines Agency, F-6/11

Court: EU Civil Service Tribunal
Date: 28 September 2011

The case involved a damages claim concerning a workplace accident and alleged breaches of obligations concerning the health and safety of workers. The action was ultimately dismissed as manifestly inadmissible, so it is not an authority establishing liability on the merits. (Infocuria)

Why it remains useful

The case demonstrates that workplace injury claims within the EU institutional context can involve questions concerning:

workplace safety;

employer/institutional duties;

causation;

damages;

procedural admissibility.

AI application

If an AI system allegedly failed to identify an occupational hazard, a claimant would still need to establish the applicable legal duty, breach, causation and recoverable damage.

Therefore:

An AI prediction error alone is not automatically equivalent to legally compensable injury.

This case should be cited as contextual/analogical authority, not as a case that decided AI liability.

7. Case 3 — Vilnes and Others v Norway

Court: ECtHR
Date: 5 December 2013/24 March 2014

This is one of the most important European occupational-health cases for an AI prediction problem.

The applicants were professional divers who suffered health problems connected with diving operations.

The ECtHR found a violation of Article 8 ECHR because the authorities failed to ensure that the applicants received essential information concerning risks associated with decompression tables, enabling them to assess the dangers to their health and safety. The Court emphasised the importance of information even where there was scientific uncertainty about the precise long-term risks. (Regjeringen.no)

AI application

Imagine an AI system predicts:

“Low probability of occupational neurological injury.”

But the employer knows that:

the prediction model is uncertain;

the training data are incomplete;

the scientific evidence is developing;

there are known limitations in the model.

If the employer does not disclose meaningful information about the limitations of the prediction system, Vilnes becomes highly relevant by analogy.

Principle

Workers' ability to understand health risks cannot simply be replaced by an opaque technological prediction.

This is especially important where AI produces probabilistic rather than certain conclusions.

8. Case 4 — Brincat and Others v Malta

Court: ECtHR
Date: 24 July 2014

The case concerned shipyard workers exposed to asbestos over many years.

The ECtHR found violations of Articles 2 and 8 ECHR, holding that the State had failed to take adequate measures to protect workers and inform them about serious health risks associated with asbestos exposure. (HUDOC)

Importance for predictive AI

The case demonstrates that occupational-health protection involves more than responding to an injury after it occurs.

There is a preventive dimension.

Therefore, if an employer possesses an AI system capable of detecting a serious occupational risk, questions may arise about:

whether the employer should act on the warning;

whether failure to investigate an alert is negligent;

whether workers should be informed;

whether protective measures should be introduced.

Example

AI predicts:

“High probability of harmful chemical exposure.”

Employer ignores the warning because:

“The system sometimes makes mistakes.”

If the employer had other evidence confirming the risk, ignoring the AI warning could potentially become relevant evidence in a negligence or occupational-safety claim.

Principle

Occupational health law is fundamentally preventive, not merely compensatory.

9. Case 5 — Howald Moor and Others v Switzerland

Court: ECtHR
Date: 11 March 2014

This case concerned asbestos exposure and the difficulty of bringing a civil claim because the disease manifested itself decades after occupational exposure.

The ECtHR found that the limitation rules restricted access to court excessively because the disease could not reasonably have been known within the ordinary limitation period. (FulLegal)

AI relevance

AI occupational-health prediction creates a similar temporal problem.

Suppose:

2026: AI predicts “low risk.”

2035: worker develops occupational disease.

2038: independent scientific evidence establishes that the AI model systematically underestimated the risk.

The claimant may have difficulty proving:

when the defect existed;

when the employer knew;

when the disease became discoverable;

whether the AI caused or merely failed to detect the condition.

Howald Moor demonstrates why limitation rules can become particularly problematic for latent occupational diseases. (Council of Europe)

Principle

Long-latency occupational diseases require careful treatment of limitation and discoverability.

10. Case 6 — SCHUFA Holding, C-634/21

Court: CJEU
Date: 7 December 2023

This is not an occupational-health case, but it is highly relevant to AI-based worker profiling.

The CJEU examined automated scoring under Article 22 GDPR.

The Court recognised that an automatically generated probability value can constitute automated decision-making where it plays a determining role in a subsequent decision producing significant effects. (curia)

Occupational-health example

An employer's AI system generates:

“Worker has an 82% probability of developing stress-related illness.”

The employer then automatically:

transfers the employee;

denies promotion;

changes working hours;

reduces responsibilities;

terminates employment.

The legal question is not merely whether the prediction was medically accurate.

It is also:

What legal effect did the automated profile have on the worker?

Principle

An algorithmic prediction can become legally significant when it determines or materially influences consequential decisions about an individual.

11. Case 7 — Dun & Bradstreet Austria, C-203/22

Court: CJEU
Date: 27 February 2025

The CJEU considered the GDPR right to receive meaningful information about the logic involved in automated decision-making and profiling.

The judgment concerned automated credit scoring rather than occupational health, so its application here is analogical.

The Court's reasoning is highly relevant where an AI system produces a consequential worker-risk profile. (Curia)

Occupational-health example

An employee asks:

“Why did your AI classify me as high risk?”

A legally meaningful answer may require more than:

“The model calculated your risk at 91%.”

The worker may need sufficiently meaningful information to understand:

what relevant information was used;

how the information influenced the outcome;

what factors contributed to the classification;

whether inaccurate information was used;

whether the system relied on profiling.

Principle

An unexplained occupational-health score may create serious transparency and contestability problems where it affects the worker's legal or employment position.

12. Case 8 — Meta Platforms, C-252/21

Court: CJEU
Date: 4 July 2023

The case concerned processing of personal data, including special-category data, and the interaction between data protection and other legal regimes.

It is relevant by analogy because occupational-health AI will frequently process extremely sensitive information.

Health data problem

Occupational-health prediction may use:

medical history;

disability-related information;

biometric information;

sleep information;

stress indicators;

heart-rate information;

genetic information;

mental-health indicators.

Many such categories can fall within the GDPR's special-category personal-data framework.

Therefore, the employer must not assume that:

“We collected the information for workplace safety, therefore we can use it for every employment purpose.”

Purpose limitation and data minimisation remain important.

13. Special Problem: Health Data

AI occupational-health systems can be particularly intrusive because they may combine:

Medical data + biometric data + workplace behaviour + productivity + location + environmental data.

This creates a significant GDPR issue.

Example

An employer installs wearable devices that measure:

heart rate;

sleep;

movement;

fatigue;

body temperature.

The AI predicts:

“Employee X has a high probability of burnout.”

The employer then uses this information to determine promotion eligibility.

This can transform a health-and-safety tool into an employment profiling system.

That change in purpose can be legally significant.

14. AI Occupational Health Risk Prediction: Five Different Legal Situations

Situation 1 — False negative

AI says:

“Low risk.”

Actual result:

Worker suffers occupational injury.

This is primarily a safety and negligence/causation problem.

Situation 2 — False positive

AI says:

“High risk.”

Worker is actually healthy.

Employer then imposes restrictions.

This can become an employment, privacy, discrimination and automated-decision problem.

Situation 3 — Correct prediction but employer ignores it

AI correctly identifies:

“High probability of dangerous chemical exposure.”

Employer does nothing.

Worker is injured.

The AI itself may not be defective. The issue may instead be:

failure to act on a known warning.

Situation 4 — Correct AI but bad underlying data

AI correctly processes:

“The worker's medical data indicates high risk.”

But the medical data belong to another employee.

This is a data accuracy and data-protection problem.

Situation 5 — Correct AI but unlawful use

The AI accurately predicts a health condition, but the employer uses it to discriminate against the employee.

Here the problem is not prediction accuracy.

It is:

unlawful use of personal/health information.

15. Causation in AI Occupational-Health Litigation

Causation will probably be one of the most difficult issues.

The claimant may need to establish:

Step 1 — AI error

The model incorrectly predicted the risk.

Step 2 — Employer reliance

The employer relied upon that prediction.

Step 3 — Failure of protection

Because of the prediction, reasonable protective measures were not adopted.

Step 4 — Injury

The worker suffered physical or psychological harm.

Step 5 — Causal connection

The failure materially contributed to the injury.

Thus:

AI error → reliance → inadequate protection → exposure → injury

is much stronger than simply:

AI error → injury

16. Scientific Uncertainty

Occupational disease often develops slowly.

AI models also operate probabilistically.

Therefore, litigation may involve statements such as:

“The model only predicted a 30% probability.”

That does not automatically answer the legal question.

The court may have to examine:

model accuracy;

confidence intervals;

false-negative rate;

training data;

validation studies;

known limitations;

scientific literature;

alternative causes;

employer's knowledge;

precautionary duties.

Vilnes is particularly useful because the ECtHR recognised that occupational-health protection can require precautions even where scientific knowledge is incomplete. (Regjeringen.no)

17. AI Risk Prediction and the Precautionary Principle

A dangerous misconception would be:

“If AI is not 100% certain, the employer does not need to act.”

Occupational-health law generally works differently.

If there is credible evidence of a serious workplace risk, the employer may need to investigate and mitigate it even when scientific certainty is incomplete.

This is consistent with the preventive logic visible in Vilnes and Brincat.

18. Employer Liability

An employer deploying occupational-health AI may face several possible allegations.

Negligent deployment

The employer selected an unsuitable system.

Negligent validation

The employer failed to test the model against its actual workforce.

Negligent monitoring

The employer ignored model drift.

Negligent reliance

The employer treated predictions as medical certainty.

Failure to warn

Workers were not told about relevant risks or limitations.

Data-protection breach

Health information was unlawfully processed.

Discrimination

AI predictions were used to disadvantage protected groups.

Failure to accommodate

AI incorrectly predicted disability or health limitations and the employer failed to consider reasonable accommodation obligations.

19. AI Provider Liability

The AI developer/provider may potentially face separate liability.

Relevant failures may include:

defective algorithm design;

inadequate training data;

inadequate testing;

unreasonable false-negative rates;

misleading accuracy claims;

failure to identify foreseeable misuse;

inadequate documentation;

defective updates;

cybersecurity failures.

The AI Act's lifecycle risk-management model is important here because high-risk AI systems require continuing identification and mitigation of foreseeable risks to health, safety and fundamental rights. (EUR-Lex)

20. Product Liability Dimension

A separate question arises where the AI occupational-health system qualifies as a product under applicable EU product-liability legislation.

For example:

AI-controlled industrial safety equipment predicts that a worker is safe near a machine and disables a protective intervention.

If the software or AI component is defective and causes physical injury, product-liability principles may become relevant.

However, one must distinguish:

defective AI product;

negligent employer deployment;

incorrect use;

defective workplace equipment;

inaccurate medical data;

independent human negligence.

They may produce different liability outcomes.

21. Worker Privacy

AI occupational-health prediction can create a major privacy problem.

Consider:

A wearable device records sleep quality every night.

The employer's AI then predicts:

“Worker is suffering from chronic fatigue.”

The worker may reasonably ask:

Why was this data collected?

Was collection necessary?

Who has access?

How long is it retained?

Is it used for health and safety only?

Is it used for performance management?

Is the worker automatically profiled?

Can the worker challenge the result?

The GDPR therefore becomes an important part of the civil-liability analysis.

22. Worker Discrimination

Suppose AI predicts that:

older workers have greater probability of musculoskeletal injury.

The employer subsequently reduces the workload or promotion opportunities of older employees.

Even if the statistical correlation is genuine, the employer cannot automatically assume that an individual worker should be disadvantaged solely because of a statistical prediction.

The legal analysis must distinguish:

risk prevention from employment discrimination.

23. AI Bias

Bias can enter through:

historical workplace injury data;

underrepresentation of women;

underrepresentation of disabled workers;

age differences;

different occupational exposures;

different medical baselines;

poor-quality wearable data.

For example, a fatigue model trained mainly on young male workers may perform poorly for older workers or women.

The AI Act's risk-management framework expressly requires attention to risks to health, safety and fundamental rights. (EUR-Lex)

24. Human Oversight

A safe system should operate approximately as:

AI prediction → occupational-health professional → employer safety assessment → worker consultation → protective action

rather than:

AI prediction → automatic employment decision

Human oversight is particularly important because an AI prediction is generally a probability, not a medical diagnosis.

25. Right to Challenge the Prediction

A worker should potentially be able to challenge:

incorrect input data;

incorrect medical information;

erroneous model output;

inappropriate profiling;

discriminatory assumptions;

use of irrelevant information.

The reasoning in Dun & Bradstreet concerning meaningful information about automated profiling is particularly useful here. (Curia)

26. Occupational Health AI and Access to Information

Vilnes is especially significant.

The ECtHR recognised that individuals exposed to occupational risks may need information sufficient to understand those risks. (Regjeringen.no)

Applied to AI:

A worker should not necessarily be told the entire source code, but the legal system may require meaningful information concerning:

what the system predicts;

relevant limitations;

significant risk factors;

reliability;

known uncertainty;

consequences of the prediction.

This is different from demanding disclosure of every technical detail.

27. Long-Term Occupational Diseases

AI may be used to predict diseases with long latency:

cancer;

asbestos-related disease;

occupational respiratory disease;

neurological disease;

hearing loss.

Howald Moor demonstrates the difficulty that arises when an occupational disease becomes apparent many years after exposure. (FulLegal)

For AI systems, litigation may therefore require preservation of:

model versions;

training datasets;

prediction logs;

risk scores;

system updates;

employer decisions;

worker exposure records.

Otherwise, years later it may become impossible to determine which model produced which prediction.

28. AI Model Drift

A particularly important futuristic issue is model drift.

Suppose:

2026: Model accuracy = 95%.

2029: Workplace conditions change.

2030: New chemicals are introduced.

2031: Model accuracy falls substantially.

If the employer continues using the original model without reassessment, liability may arise from failure to monitor, even if the original AI was technically sound.

This fits the AI Act's requirement for continuing lifecycle risk management and updating of risk controls. (EUR-Lex)

29. AI Prediction vs Medical Diagnosis

A court should distinguish:

AI risk prediction

“You have a 70% risk of developing occupational asthma.”

from:

Medical diagnosis

“You have occupational asthma.”

An employer should not necessarily treat the first as equivalent to the second.

This distinction becomes crucial when employment consequences follow.

30. Important Case-Law Synthesis

CaseMain principleRelevance to AI occupational-health prediction
Commission v United Kingdom, C-127/05Employer/workplace safety obligations under Directive 89/391Employer cannot outsource safety responsibility to AI
M v EMA, F-6/11Workplace accident/damages contextWorkplace injury and institutional safety duties
Vilnes v NorwayWorkers must receive essential information about occupational health risksAI risk transparency
Brincat v MaltaState must protect and inform workers about serious occupational risksPreventive AI risk management
Howald Moor v SwitzerlandLatent occupational disease and access to courtLong-term AI prediction/disease claims
SCHUFA, C-634/21Automated scoring can constitute significant automated decision-makingWorker profiling
Dun & Bradstreet, C-203/22Meaningful information about automated profilingExplainability and challenge
Meta Platforms, C-252/21Protection of personal data and special-category informationHealth-data processing

The occupational-health cases should be understood as direct authorities on workplace health risks, while the AI/GDPR cases are analogical authorities on automated profiling and transparency. There is not yet a settled CJEU/ECtHR doctrine specifically assigning civil damages for an AI occupational-health prediction error.

31. Potential Liability Matrix

ConductPossible legal issue
AI misses serious workplace riskOccupational negligence / safety breach
Employer ignores AI warningFailure to protect workers
AI falsely predicts illnessPrivacy/employment consequences
Health data collected unlawfullyGDPR
AI discriminates by age/sex/disabilityEquality law
AI gives unexplained health scoreTransparency/automated decision-making
AI model becomes inaccurate over timeMonitoring/risk-management failure
Provider exaggerates accuracyContract/tort/product liability
AI data are incorrectGDPR accuracy + negligence
AI causes delayed recognition of diseaseCausation/limitation
AI recommendation automatically determines employment actionArticle 22 GDPR / employment law
Worker is never informed about serious AI-predicted riskOccupational-health/fundamental-rights concern

32. Defences and Counterarguments

Employers and AI providers may argue:

1. AI was only advisory

The employer did not treat the prediction as determinative.

2. Human professional independently assessed the risk

This may weaken an argument based on automated decision-making.

3. The injury had another cause

This creates a causation issue.

4. The prediction was scientifically reasonable

A model can be imperfect without necessarily being legally defective.

5. The risk was unforeseeable

This may affect negligence analysis.

6. The employer acted immediately after receiving the warning

This may reduce liability for failure to protect.

7. The worker's health information was processed under a valid legal basis

This may address part of the GDPR analysis but does not automatically resolve other employment-law questions.

33. Most Important Legal Distinction

The following four situations should never be automatically merged:

A. Bad AI

The model itself is defective.

B. Good AI, bad data

The algorithm operates correctly but receives incorrect information.

C. Good AI, bad employer

The system correctly predicts the risk but the employer ignores it.

D. Good AI, unlawful use

The prediction is accurate but is used for discriminatory or otherwise unlawful employment purposes.

This distinction is central to determining the correct defendant and cause of action.

34. Future Litigation Questions

European courts are likely to face questions such as:

Who owns the AI occupational-risk prediction records?

Must the employer disclose the model's accuracy rate?

Must the worker receive the risk score?

Can an employer rely on an AI system instead of an occupational-health professional?

Who proves that an AI prediction was defective?

How should courts treat probabilistic evidence?

What happens when scientific evidence is uncertain?

Who is liable when a third-party AI provider supplied the model?

How should AI model drift affect liability?

Can health-risk profiling be used in promotion decisions?

Can a worker challenge an AI health classification?

How should limitation periods operate for diseases discovered decades later?

Can trade-secret protection restrict disclosure of the model?

What happens when AI uses health data for a purpose different from workplace safety?

Can an employer be liable for ignoring a low-confidence but serious AI warning?

35. Exam-Oriented Conclusion

AI-based occupational-health risk prediction liability in Europe is an emerging area where traditional occupational-safety law meets AI regulation, data protection and fundamental rights.

The most important point is that AI does not transfer the employer's occupational-health responsibility to the algorithm. European occupational-safety law continues to place substantial responsibility on employers to protect workers. The CJEU's workplace-safety jurisprudence, including Commission v United Kingdom, supports this framework. (Infocuria)

The ECtHR's decisions in Vilnes and Brincat emphasise the preventive importance of protecting workers and providing meaningful information concerning occupational health risks. (Regjeringen.no)

Howald Moor demonstrates the special difficulties created by latent occupational diseases and limitation periods. (FulLegal)

Meanwhile, SCHUFA and Dun & Bradstreet provide important principles for analysing AI profiling, automated decision-making and meaningful explanations. (curia)

The AI Act adds a modern regulatory layer requiring appropriate risk management for relevant high-risk AI systems and continuous attention to risks affecting health, safety and fundamental rights. (EUR-Lex)

Thus, liability should be analysed through:

AI DESIGN + DATA QUALITY + VALIDATION + HUMAN OVERSIGHT + WORKER INFORMATION + HEALTH-DATA LAW + EMPLOYER DUTY + CAUSATION + DAMAGE + REMEDY

Ultra-basic revision formula

PREDICT → PROTECT → INFORM → SUPERVISE → VERIFY → CAUSATION → LIABILITY → COMPENSATION

One-line exam answer

“In Europe, an AI occupational-health prediction is a risk-management tool, not a substitute for the employer's duty to protect workers or for legally required human and medical judgment.”

LEAVE A COMMENT