Civil Law And Ai-Powered Service Provider Liability In Europe .

Civil Law And AI-Powered Service Provider Liability In Europe

1. Introduction

AI-powered service provider liability concerns the civil responsibility of businesses that use, supply, operate, integrate, or maintain AI as part of a service where the AI causes or contributes to legally recognised harm.

Examples include:

AI medical-diagnostic services;

AI financial-advisory services;

automated insurance services;

AI recruitment platforms;

AI legal or professional services;

autonomous transport services;

AI customer-service systems;

AI cybersecurity services;

AI property-management systems;

AI-powered recommendation and decision services;

AI cloud/SaaS services.

The legal difficulty is that an AI service may involve software, data, human professionals, cloud infrastructure and a contractual service relationship simultaneously.

European law therefore does not create one universal tort called “AI service-provider liability.” Liability may instead arise from:

contract law;

national tort/delict law;

GDPR;

consumer law;

product liability;

AI Act compliance;

professional liability;

sector-specific legislation.

A major development is the new EU Product Liability Directive 2024/2853. It expressly treats software, including AI systems, as products, including software supplied through cloud technologies or SaaS. However, the Directive does not generally apply to services as such; it covers certain digital services that are integrated into or interconnected with a product and are within the manufacturer's control. (EUR-Lex)

2. Meaning of an AI-Powered Service Provider

An AI-powered service provider is an entity that uses or supplies AI in order to provide a service to another person or organisation.

Example

A financial company provides:

AI credit-assessment service → bank → consumer

The AI provider analyses:

income;

repayment history;

transactions;

employment information;

other personal data.

It generates a credit score.

The bank then refuses the customer's loan.

Possible legal questions include:

Was the AI assessment accurate?

Was personal data lawfully processed?

Was the automated decision legally permitted?

Was sufficient information provided?

Was there meaningful human review?

Did the service provider breach its contract?

Did the provider cause compensable damage?

3. Why AI Service Liability Is Different

Traditional services normally involve identifiable human decision-makers.

AI-powered services introduce:

A. Algorithmic autonomy

The system may make or recommend decisions without direct human intervention.

B. Black-box decision-making

The provider may not be able to give a simple explanation of every output.

C. Continuous modification

AI models can be updated or retrained after deployment.

D. Data dependency

The service may be defective because its training or input data are defective.

E. Multiple actors

The AI developer, cloud provider, service provider and customer may all participate.

F. Difficulty proving causation

It may be difficult to establish:

AI output → particular decision → specific damage.

4. European Legal Framework

A. Contractual Liability

Where a customer has contracted with an AI service provider, contractual liability is usually the first issue.

The contract may contain obligations concerning:

accuracy;

availability;

cybersecurity;

data protection;

service quality;

human supervision;

response times;

updates;

warranties;

professional standards.

For example:

AI accounting provider promises 99% accurate automated tax calculations.

If a defective AI output causes a customer's financial loss, the contractual terms and applicable national contract law may determine liability.

5. Tort/Delict Liability

National European civil-law systems generally maintain broader non-contractual liability.

The precise rules differ.

France

French civil liability may involve the general fault provisions of the Civil Code and, where relevant, special regimes such as defective-product liability.

Germany

German liability can arise particularly under § 823 BGB, subject to the requirements of the applicable cause of action.

Italy

Article 2043 of the Italian Civil Code provides the general framework for unlawful damage caused by another.

Spain

Spanish Civil Code provisions concerning extra-contractual liability may apply.

Therefore:

There is no single European AI tort law.

EU legislation increasingly harmonises particular areas, but national civil law remains important.

6. GDPR Liability

The GDPR becomes particularly important when an AI service provider processes personal data.

Relevant provisions include:

Article 5 — principles of processing;

Article 6 — lawful bases;

Articles 12–14 — transparency;

Article 15 — access;

Article 22 — automated individual decision-making;

Article 25 — data protection by design/default;

Article 32 — security;

Article 35 — impact assessment;

Article 82 — compensation.

An AI service provider can potentially be:

controller;

joint controller;

processor;

depending on its actual role.

The contractual label alone does not necessarily determine the GDPR classification.

7. AI Act

The EU AI Act, Regulation (EU) 2024/1689, regulates providers and deployers of AI systems.

Its scope expressly includes:

providers placing AI systems on the EU market;

deployers established in the EU;

certain third-country providers where AI outputs are used in the EU;

importers;

distributors;

product manufacturers incorporating AI systems. (EUR-Lex)

The AI Act imposes different obligations depending upon the AI system's classification.

However:

AI Act compliance is not the same thing as civil-law immunity.

A provider can potentially comply with regulatory requirements and still face contractual, tortious, GDPR or product-liability claims if the relevant requirements of those regimes are satisfied.

8. Product Liability and AI Service Providers

This is one of the most important developments.

Directive 2024/2853 expressly states that software, including AI systems, is a product for the purposes of EU no-fault product liability, regardless of whether it is supplied through a device, communication network, cloud technology or SaaS model. It also states that AI-system providers can be treated as manufacturers. (EUR-Lex)

Thus:

AI software supplied as SaaS is no longer automatically outside the product-liability concept merely because it is delivered digitally.

However, an important distinction must be maintained:

AI software itself

Potentially a product under the new Directive.

A service as such

Not generally within the Directive's product-liability scope.

Related digital service integrated into/interconnected with a product

May be treated as a component where the statutory conditions are met.

The Directive specifically gives examples such as:

traffic-data services integrated into navigation systems;

health-monitoring services connected to physical products;

temperature-control services for smart appliances;

voice-assistant services controlling products. (EUR-Lex)

9. Effective Date of the New Product Liability Regime

The new Directive applies to products placed on the market or put into service after 9 December 2026 under the Directive's Article 2 framework. (EUR-Lex)

Therefore, in a current European litigation analysis, it is essential to distinguish:

old Product Liability Directive 85/374/EEC

from

new Product Liability Directive 2024/2853.

10. Case Law

Because AI-powered service-provider liability is still developing, there are relatively few reported judgments directly concerning an AI provider being sued for an AI-generated service failure.

The most useful authorities therefore combine:

direct AI/data-processing cases;

product-liability cases;

automated-decision cases;

digital-service cases.

Case 1 — SCHUFA Scoring

OQ v Land Hessen and SCHUFA Holding AG

Case C-634/21, CJEU, 7 December 2023, ECLI:EU:C:2023:957

Importance: Direct AI/automated-service analogy

SCHUFA is a private credit-information company providing creditworthiness information to customers such as banks.

It generated a probability score concerning an individual's ability to meet future payment obligations.

The bank used that score in making its credit decision.

The CJEU held that automated establishment of such a probability value can constitute an automated individual decision within Article 22 GDPR where the statutory conditions are satisfied and the score plays a determining role in the subsequent decision. (Infocuria)

Relevance to AI service providers

This is extremely important for:

AI service provider → automated assessment → customer decision → consumer harm

An AI provider cannot necessarily argue:

“We only generated the score; another company technically made the final decision.”

The actual role of the automated output matters.

Principle

An intermediate AI-generated score can have direct legal significance where another decision-maker relies upon it in a decisive way.

Case 2 — Dun & Bradstreet Austria

CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria

Case C-203/22, CJEU, 27 February 2025, ECLI:EU:C:2025:117

Importance: AI transparency and explanation

Dun & Bradstreet provided automated credit assessments.

The CJEU considered Article 15(1)(h) GDPR and the right to receive meaningful information about the logic involved in automated decision-making.

The Court held that the information supplied must enable the data subject to understand and challenge the automated decision. (curia)

Where trade secrets or third-party data are involved, the information cannot simply be withheld automatically; the competent supervisory authority or court may need to balance the competing interests. (Curia)

Relevance

Suppose an AI service provider says:

“Our model rejected your application.”

The customer asks:

“Why?”

The provider cannot necessarily satisfy the transparency requirement merely by saying:

“The neural network generated that result.”

Principle

AI complexity does not automatically eliminate the legal requirement for meaningful explanation.

Case 3 — Österreichische Post

UI v Österreichische Post AG

Case C-300/21, CJEU, 4 May 2023, ECLI:EU:C:2023:370

Importance: AI profiling and compensation

Österreichische Post processed information in order to predict individuals' political affinities.

The CJEU considered Article 82 GDPR and clarified that three elements are required for compensation:

GDPR-infringing processing;

damage;

causal link between the unlawful processing and damage.

The mere fact of a GDPR infringement does not automatically create a compensation claim, but EU law does not require non-material damage to exceed a particular seriousness threshold imposed by national law. (Infocuria)

AI-service relevance

Suppose an AI service provider:

collects personal data → creates an inferred profile → supplies the profile to a customer → consumer suffers damage.

The provider's AI-generated inference may therefore create GDPR liability if the applicable requirements are satisfied.

Principle

Unlawful AI data processing and compensable damage are related but distinct legal questions.

Case 4 — Boston Scientific

Boston Scientific Medizintechnik GmbH v AOK Sachsen-Anhalt and Betriebskrankenkasse RWE

Joined Cases C-503/13 and C-504/13, CJEU, 5 March 2015

Importance: Product defect and systemic risk

The cases concerned pacemakers and implantable cardioverter-defibrillators.

The CJEU held that products belonging to a group or production series presenting a significantly increased risk of failure could be regarded as defective without proving that every individual product had already manifested the defect.

AI service relevance

Consider an AI software service used by:

50,000 hospitals.

A particular model version is discovered to have a systematic diagnostic defect.

The problem may exist across a class of systems even where every individual customer has not yet suffered measurable harm.

This is important for:

recalls;

model replacement;

safety updates;

risk management.

Principle

A systemic defect affecting a product group can have legal significance even before every individual unit produces actual damage.

This principle becomes increasingly important under the new EU Product Liability Directive, which expressly includes software and AI systems within the product concept. (EUR-Lex)

Case 5 — Veedfald

Henning Veedfald v Århus Amtskommune

Case C-203/99, CJEU, 10 May 2001

Importance: Product liability and services

The case concerned a defective product used in connection with medical treatment.

The CJEU addressed the application of the EU defective-product regime where a product is supplied or used in the context of a broader service.

AI relevance

This is useful for distinguishing:

AI software/product

from

AI-enabled professional service.

For example:

AI diagnostic software → hospital → patient

The hospital may provide the medical service, while the AI developer provides software.

Different liability regimes can potentially apply to each participant.

Principle

A product can remain legally relevant even when it operates within a broader professional service.

Case 6 — Moteurs Leroy Somer

Moteurs Leroy Somer v Dalkia France

Case C-285/08, CJEU, 4 June 2009

Importance: Defective industrial product

The case involved a defective alternator that overheated and caused a fire in an industrial setting.

The CJEU considered the scope of the EU defective-product regime, particularly damage to property used for professional purposes.

AI-service relevance

Imagine:

AI industrial-management service → incorrect instruction → machine overheats → factory fire.

The case demonstrates why courts must distinguish between:

damage caused by the defective product;

damage to the defective product itself;

damage to other property;

economic losses.

Principle

Different categories of damage may fall under different legal regimes.

This is especially important for AI-powered industrial and professional services.

Case 7 — Sanofi Pasteur

W and Others v Sanofi Pasteur MSD

Case C-621/15, CJEU, 21 June 2017

Importance: Causation under technical uncertainty

The case concerned alleged harm from a vaccine and the evidentiary problem of establishing defect and causation where scientific knowledge was uncertain.

The CJEU recognised the importance of serious, specific and consistent evidence in circumstances where direct scientific proof may be difficult, subject to national evidentiary rules.

AI-service relevance

AI systems present similar evidentiary problems.

For example:

AI diagnostic service → incorrect prediction → medical treatment → injury.

The claimant may not be able to inspect the complete model or reproduce its exact output.

The dispute may therefore concern:

system logs;

training data;

model validation;

known error rates;

alternative explanations;

expert evidence.

Principle

Technical complexity does not eliminate the need for proof of defect and causation, but European product-liability law recognises evidentiary difficulties in technically complex cases.

Case 8 — Google Spain

Google Spain SL and Google Inc. v AEPD and Mario Costeja González

Case C-131/12, CJEU, 13 May 2014

Importance: Responsibility for algorithmic processing

Google's search engine automatically processed information originating from third-party websites.

The CJEU recognised that the search-engine operator was itself processing personal data and could have obligations under EU data-protection law.

Relevance to AI services

This is useful for a general principle:

An AI service provider cannot necessarily escape responsibility merely because its system automatically processes information supplied by third parties.

The same problem can arise where an AI provider receives:

third-party databases;

public information;

customer-provided information;

external APIs.

Principle

Automated aggregation or processing of information can itself constitute legally relevant processing.

Case 9 — Amazon EU

Bundesverband der Verbraucherzentralen und Verbraucherverbände v Amazon EU Sàrl

Case C-649/17, CJEU, 10 July 2019

Importance: Digital service-provider obligations

The case concerned communication methods available to consumers dealing with an online trader.

The CJEU held that the trader did not necessarily have to provide a telephone number in every circumstance but had to provide an effective means of communication allowing consumers to contact it rapidly and efficiently.

AI-service relevance

An AI-powered service should not create a situation where:

AI makes decision → consumer disputes decision → no meaningful human/contact mechanism exists.

The digital nature of the service does not eliminate applicable consumer communication obligations.

Principle

Digital automation does not remove the provider's underlying consumer-law responsibilities.

9. Liability of Different AI Actors

A. AI Developer

Potential liability for:

defective software;

inadequate testing;

defective model;

unsafe architecture;

inadequate warnings;

defective updates.

Under the new Product Liability Directive, an AI-system developer/provider may fall within the manufacturer concept where the AI system is a product. (EUR-Lex)

B. AI Service Provider

The service provider may be responsible where it:

selects the model;

configures it;

controls inputs;

makes decisions through it;

provides the service to customers;

fails to monitor known risks.

C. Deployer

The deployer may be responsible where it:

uses the system improperly;

ignores instructions;

supplies defective data;

fails to supervise;

uses the system outside its intended purpose.

D. Integrator

An integrator combines:

AI + existing software + physical equipment + databases.

Incorrect integration may create a separate liability issue.

E. Cloud Provider

A cloud infrastructure provider will not automatically become liable merely because the AI system operates on its servers.

Liability depends on:

contractual role;

control;

defect;

causation;

applicable statutory regime.

10. AI Service Provider vs AI Product Manufacturer

This distinction is essential.

Situation 1

Company sells an AI-powered medical device.

Product liability is highly relevant.

Situation 2

Company supplies standalone AI software through SaaS.

The new Product Liability Directive expressly treats software, including AI systems supplied through SaaS, as a product. (EUR-Lex)

Situation 3

Company provides an ordinary professional service using AI internally.

Example:

Law firm uses AI to help prepare a legal document.

The client may primarily have a professional/contractual liability claim against the law firm, depending on national law and the engagement terms.

The AI developer is not automatically the client's contractual service provider.

Situation 4

AI service controls a physical product.

Example:

Autonomous vehicle navigation service.

A related digital service integrated into or interconnected with a product may fall within the new product-liability framework when the statutory conditions concerning the manufacturer's control are met. (EUR-Lex)

11. The Control Test

An important question is:

Who controlled the relevant AI component when the defect existed?

The new Product Liability Directive recognises continuing manufacturer control over software and related services in specified circumstances.

It specifically addresses defects arising after placing on the market through:

software updates;

upgrades;

machine-learning algorithms.

It also addresses cybersecurity vulnerabilities and inadequate security updates in certain circumstances. (EUR-Lex)

This represents an important departure from a purely traditional physical-product model.

12. AI Updates and Continuous Liability

Traditional products generally leave the manufacturer's control after sale.

AI products can behave differently.

Example:

January: AI service is safe.

March: Provider deploys model update.

April: Updated model generates dangerous output.

May: Customer suffers damage.

The legal question becomes:

Is the provider responsible for the post-deployment change?

The new Product Liability Directive expressly contemplates defects arising after placing the product on the market where software, related services or machine-learning algorithms remain within the manufacturer's control. (EUR-Lex)

13. Cybersecurity Liability

AI services can fail because of cyberattacks.

Example:

Hacker manipulates AI model → AI gives incorrect command → customer suffers loss.

Possible issues include:

inadequate security;

failure to patch;

foreseeable cyber risks;

third-party intervention;

causation;

contractual cybersecurity obligations.

The new Product Liability Directive specifically recognises that cybersecurity vulnerabilities and failure to provide necessary security updates can affect product safety and liability. (EUR-Lex)

14. AI Hallucination and Service Liability

Generative AI creates another problem.

Example:

AI legal service generates a fictitious legal authority.

The customer relies on it and loses a legal claim.

Potential defendants could include:

AI developer;

AI service provider;

professional firm deploying the AI;

human professional who failed to verify the output.

But liability is not automatic.

The claimant would need to establish the relevant legal elements, which may include:

duty/contractual obligation;

breach or defect;

causation;

legally recognised damage.

15. AI Medical-Service Liability

Consider:

AI diagnostic service says “no cancer” → doctor relies on output → delayed treatment → injury.

Potential liability may involve:

AI provider

Defective model or inadequate warnings.

Hospital

Failure of clinical supervision.

Doctor

Professional negligence under applicable national law.

Software manufacturer

Product liability where applicable.

Data provider

Potentially defective clinical data.

Thus:

AI does not replace the ordinary professional-liability framework.

It adds another technological layer to it.

16. AI Financial-Service Liability

Example:

AI investment service recommends a high-risk investment.

Customer loses €100,000.

Questions include:

Was the service contractually obligated to provide suitable advice?

Was the AI properly trained?

Were warnings given?

Was the consumer properly informed?

Was the provider subject to financial-sector regulation?

Was the AI output automatically generated?

Did the customer receive human review?

GDPR may also apply if personal profiling was involved.

17. AI Employment-Service Liability

Example:

AI recruitment service incorrectly classifies an applicant as unsuitable.

Potential legal issues:

GDPR;

anti-discrimination law;

AI Act;

employment law;

contract;

tort/delict.

SCHUFA is particularly useful by analogy because the CJEU recognised that an automated score can have legal significance where it plays a determining role in a subsequent decision. (Infocuria)

18. Transparency as a Liability Issue

AI service providers should be able to address:

what the system does;

what data it uses;

relevant limitations;

degree of automation;

human oversight;

significant risks;

circumstances in which the system should not be relied upon.

The Dun & Bradstreet judgment is especially significant because meaningful information about automated logic must be sufficient to enable understanding and challenge of the decision in the circumstances covered by the GDPR. (curia)

19. Human Oversight

One of the most important principles is:

Human involvement does not automatically eliminate AI-service-provider liability.

There is a difference between:

Genuine human review

A qualified human examines the AI output and independently decides.

and

Rubber-stamp review

A human merely clicks:

“Approve AI recommendation.”

The second situation can raise much stronger questions about whether the human intervention was genuinely meaningful.

The SCHUFA decision demonstrates why courts may examine the actual influence of automated output rather than merely the formal existence of another decision-maker. (curia)

20. Causation

Causation is likely to be one of the most difficult aspects of AI-service litigation.

Suppose:

AI gives wrong advice

↓

human professional receives advice

↓

professional makes decision

↓

customer suffers loss

Who caused the damage?

Possible answers may depend upon:

whether the AI output was defective;

whether the human should have detected the error;

whether the service provider gave adequate warnings;

whether the customer's conduct contributed;

whether another independent event caused the loss.

The Sanofi Pasteur line of reasoning is relevant because complex technical causation cannot simply be assumed from temporal sequence.

21. Evidence

AI litigation requires specialised evidence.

Important material can include:

Model information

model version;

architecture;

training methodology;

validation;

testing.

Input data

customer data;

third-party data;

sensor data;

external databases.

Output

exact AI response;

probability score;

recommendation;

classification.

Operational evidence

logs;

timestamps;

human interventions;

model updates.

Contractual evidence

terms of service;

warranties;

disclaimers;

service-level agreements.

22. Black-Box Evidence

The provider may argue:

“We cannot explain the precise output because the model is complex.”

That argument does not necessarily end the inquiry.

The CJEU's Dun & Bradstreet decision demonstrates that, where GDPR automated-decision rights apply, the individual can be entitled to meaningful information about the logic involved. (curia)

Courts may also need to balance:

transparency;

privacy;

third-party data;

trade secrets;

intellectual property.

23. Contractual Disclaimers

AI providers may attempt to include terms such as:

“AI output is provided for informational purposes only.”

Such clauses can be relevant but do not necessarily eliminate all liability.

Their effectiveness depends upon:

applicable national contract law;

consumer status;

mandatory statutory rights;

unfair-terms rules;

the precise wording;

the provider's actual conduct.

A provider cannot necessarily contract out of mandatory statutory liability simply by calling its AI output “informational.”

24. Professional Services

The distinction is especially important when AI is used by professionals.

Lawyer uses AI

The client generally has a professional relationship with the lawyer, not necessarily with the AI developer.

Doctor uses AI

The patient normally has a medical relationship with the doctor/hospital.

Accountant uses AI

The client normally contracts with the accounting firm.

Therefore:

AI deployment does not automatically transfer professional responsibility from the professional to the AI developer.

The professional may still have a duty to verify AI-generated work.

25. Consumer AI Services

Consumer-facing AI services raise additional issues.

Examples:

AI travel-planning service;

AI financial service;

AI shopping assistant;

AI health application;

AI educational service.

Consumer law can address:

unfair contract terms;

misleading statements;

transparency;

pricing;

withdrawal rights where applicable;

digital-content/service obligations;

compensation.

26. Joint Liability

A single accident may involve:

AI developer + service provider + deployer + professional + hardware manufacturer.

The new Product Liability Directive expressly contemplates situations where more than one party is liable for the same damage and provides for joint and several liability in specified defective-component situations. (EUR-Lex)

National tort and contract law may also provide mechanisms for contribution or allocation between responsible parties.

27. Defences

Potential defences include:

1. No defect

The AI system was not defective.

2. No breach

The service provider complied with its contractual and legal obligations.

3. No causation

The AI output did not cause the damage.

4. Human intervention

An independent human decision caused the loss.

5. Unforeseeable misuse

The system was used outside reasonably foreseeable conditions.

6. Third-party interference

A third party manipulated the system.

7. State of scientific and technical knowledge

The applicable product-liability regime may permit this defence under specified conditions.

8. Customer's own conduct

The customer's conduct contributed to the damage.

28. Damages

Depending upon the applicable legal regime, compensation may concern:

Personal injury

medical expenses;

rehabilitation;

loss of earnings;

disability;

pain and suffering where recognised.

Property damage

physical property;

equipment;

data-related consequences where legally compensable.

Economic loss

lost profits;

business interruption;

additional costs.

GDPR-related damage

Where Article 82 applies, compensation requires infringement, damage and causal connection. Österreichische Post is the central authority. (Infocuria)

29. Important Distinction: Product Liability vs Service Liability

SituationMain legal issue
Defective AI softwareProduct liability
AI software supplied through SaaSNew PLD may apply
AI service integrated with a physical productRelated-service/component rules
Professional uses AIProfessional/contractual liability
AI processes personal dataGDPR
Automated significant decisionGDPR Article 22
Consumer-facing AIConsumer law
AI causes physical injuryTort/product liability
AI causes financial lossContract/tort/sectoral rules
AI provider breaches regulatory dutiesAI Act/sectoral regulation

30. Eight Important Cases — Quick Revision

CaseMain principleAI-service relevance
SCHUFA, C-634/21 (2023)Automated scoring can constitute automated decision-makingVery high
Dun & Bradstreet, C-203/22 (2025)Meaningful explanation of automated logicVery high
Österreichische Post, C-300/21 (2023)GDPR damage and causationVery high
Google Spain, C-131/12 (2014)Algorithmic processing creates legal responsibilityHigh
Boston Scientific, C-503/13 & C-504/13 (2015)Systemic product defectHigh
Veedfald, C-203/99 (2001)Product liability in service contextHigh
Moteurs Leroy Somer, C-285/08 (2009)Industrial product damageHigh
Sanofi Pasteur, C-621/15 (2017)Technical causation/evidenceHigh
Amazon EU, C-649/17 (2019)Digital consumer-service obligationsMedium–high

31. Key Legal Principles

Principle 1

AI service providers are not automatically liable for every incorrect AI output.

Principle 2

Liability normally requires an applicable legal basis and the relevant elements such as breach/defect, causation and damage.

Principle 3

The new Product Liability Directive expressly treats AI systems and software as products.

Principle 4

The new Directive nevertheless distinguishes products from services as such. Related digital services integrated into/interconnected with products can receive special treatment. (EUR-Lex)

Principle 5

SaaS delivery does not by itself prevent software from being treated as a product under the new regime. (EUR-Lex)

Principle 6

AI providers processing personal data can face GDPR obligations independently of product liability.

Principle 7

Automated scoring can have legal significance even if another organisation formally makes the final decision — SCHUFA. (curia)

Principle 8

Meaningful explanation can be required for automated decisions covered by the GDPR — Dun & Bradstreet. (curia)

Principle 9

A GDPR infringement alone does not automatically establish compensable damage — Österreichische Post. (Infocuria)

Principle 10

AI does not eliminate professional responsibility where a human professional deploys the technology.

32. Simple Liability Formula

For examination purposes:

AI-powered service + applicable legal duty/product defect + breach/defect + causation + legally recognised damage = potential liability.

For GDPR:

Unlawful AI data processing + damage + causal link = potential Article 82 compensation claim. (Curia)

For automated decision-making:

Personal data + automated decision/profiling + legally significant effect + Article 22 conditions = potential GDPR challenge.

For product liability:

Defective AI/software product + damage + causal connection = potential no-fault product liability, subject to the applicable temporal and statutory conditions.

33. Conclusion

AI-powered service provider liability in Europe is a multi-layered civil-law problem rather than a single AI-liability doctrine.

The most significant recent development is the EU Product Liability Directive 2024/2853, which modernises product liability for the digital economy and expressly treats software and AI systems as products, including software delivered through cloud and SaaS models. At the same time, services as such remain outside the Directive except for specified integrated or interconnected digital services. (EUR-Lex)

The GDPR provides a separate and extremely important liability framework. SCHUFA establishes the importance of automated scoring; Dun & Bradstreet strengthens the right to meaningful information about automated logic; and Österreichische Post establishes the need for infringement, damage and causation for Article 82 compensation. (Infocuria)

The central legal question in future litigation will often be:

Was the harm caused by the AI itself, by the way the service provider deployed it, by defective data, by human reliance, by a physical product, or by a combination of these factors?

Accordingly, the strongest European liability analysis is usually:

AI system → service relationship → applicable legal regime → provider's role/control → defect or breach → causation → damage → allocation of liability.

LEAVE A COMMENT