Civil Law And Aircraft Maintenance Ai Diagnostic Error Liability In Europe .

Civil Law and Aircraft Maintenance AI Diagnostic Error Liability in Europe

1. Introduction

Aircraft maintenance AI diagnostic error liability concerns situations where an AI-based system used in aircraft maintenance incorrectly identifies, fails to identify, or incorrectly classifies a technical defect, and that error contributes to:

unsafe maintenance;

incorrect release to service;

aircraft damage;

engine failure;

flight disruption;

passenger injury;

death;

economic loss.

A typical example is:

An airline uses an AI diagnostic system to analyse engine sensor data. The system incorrectly reports that an engine component is serviceable. The maintenance organisation relies on that diagnosis, does not replace the component, and the component subsequently fails.

The civil-law question becomes:

Who is legally responsible—the AI developer, maintenance organisation, airline/operator, certifying engineer, component manufacturer, or another party?

There is currently very little European reported case law specifically deciding liability for an AI diagnostic error in aircraft maintenance. Therefore, the existing European aviation cases concerning technical defects, maintenance, airworthiness inspections, certification and negligent maintenance documentation provide the principal legal analogies. It is important not to present those older cases as if they themselves involved AI.

2. Basic Liability Model

An AI maintenance error can be represented as:

AI diagnostic error
↓
Human/organisation relies on AI output
↓
Defect not repaired or incorrectly repaired
↓
Aircraft/component remains unsafe
↓
Incident or accident
↓
Damage

Civil liability can potentially arise at several points.

ActorPossible liability
AI developerDefective software, contract, negligence, product liability
AI supplierDefective system/service, contractual liability
Maintenance organisationNegligent maintenance or breach of regulatory duties
Certifying engineerWrong professional certification/release
Airline/operatorFailure to maintain continuing airworthiness
ManufacturerDefective component/design or inadequate technical information
CAMOFailure in continuing-airworthiness management
Certification authorityPossible public-law/State liability, subject to applicable law

3. European Aviation Law Background

Aircraft maintenance is heavily regulated.

The EU continuing-airworthiness framework covers:

aircraft;

engines;

components;

maintenance organisations;

continuing-airworthiness management;

inspections;

maintenance data;

certifying staff;

release to service.

The earlier Regulation 2042/2003 defined continuing airworthiness as the processes ensuring that, throughout the aircraft's operating life, it complies with applicable airworthiness requirements and remains in a condition for safe operation. It also defined maintenance to include overhaul, repair, inspection, replacement, modification and defect rectification. (EUR-Lex)

The current European system has evolved into the EASA regulatory framework, including the continuing-airworthiness requirements under Regulation (EU) No 1321/2014 and its subsequent amendments. Current Part-M provisions regulate maintenance organisations and certificates of release to service. (EUR-Lex)

4. The Most Important Principle: AI Does Not Replace Human Legal Responsibility

Suppose an AI system says:

"Engine vibration within acceptable parameters."

The maintenance engineer accepts the result.

Later the engine fails.

The maintenance organisation cannot automatically say:

"The AI made the mistake, therefore we have no liability."

The legal analysis normally asks:

Was the organisation required to perform a particular inspection?

Was AI use authorised for that task?

Was the AI system sufficiently validated?

Was human verification required?

Were applicable maintenance instructions followed?

Was the AI output obviously inconsistent with other evidence?

Did the certifying engineer have a duty to investigate?

Did the error cause the loss?

Thus:

AI assistance does not automatically transfer the legal duty from the regulated aviation organisation to the software.

5. Case Law 1 — Techniko Epimelitirio Elladas (TEE) and Others v Ipourgos, C-271/11

Court: CJEU
Date: 8 November 2012

This is one of the most important European cases for the legal standard applicable to aircraft airworthiness inspection.

The dispute concerned the qualifications of persons responsible for inspecting aircraft airworthiness under Regulation 2042/2003.

The CJEU held that persons responsible for inspecting aspects of aircraft airworthiness had to possess appropriate experience covering the relevant aspects of continuing airworthiness. It also stressed the need for appropriate education, training and assessment of competence. (EUR-Lex)

The Court emphasised that airworthiness inspection involves the ability to perform technical controls and assess whether their results justify certification that the aircraft is airworthy. (EUR-Lex)

Relevance to AI

Imagine:

An AI diagnostic tool performs the initial technical analysis.

The engineer remains responsible for deciding whether the aircraft is safe and whether certification/release can properly occur.

The case therefore supports an important principle:

Regulatory competence and responsibility cannot simply be replaced by reliance on an automated diagnostic output.

Practical implication

If an AI system produces an incorrect diagnosis, a court may examine whether the human certifying personnel:

had the necessary qualifications;

followed required procedures;

checked the AI output;

possessed sufficient technical information;

exercised appropriate professional judgment.

6. Case Law 2 — Wallentin-Hermann v Alitalia, C-549/07

Court: CJEU
Date: 22 December 2008

This landmark case concerned cancellation resulting from an aircraft technical problem.

The CJEU held that an ordinary technical problem is generally inherent in the normal exercise of an airline's activity and does not automatically constitute an extraordinary circumstance under Regulation 261/2004.

The Court also held that compliance with minimum maintenance rules does not, by itself, establish that the carrier took all reasonable measures. (EUR-Lex)

Relevance to AI maintenance

Although this was not an AI-liability case, its reasoning is important.

Suppose an airline says:

"Our AI system was approved and our technicians followed the normal procedure."

That fact alone would not necessarily eliminate liability under an applicable civil-law cause of action.

The broader principle is:

Regulatory or minimum maintenance compliance does not automatically answer every question concerning reasonable care, causation and responsibility.

7. Case Law 3 — van der Lans v KLM, C-257/14

Court: CJEU
Date: 17 September 2015

A KLM aircraft experienced engine-related problems involving a fuel pump and hydromechanical unit. (EUR-Lex)

The CJEU held that a technical problem occurring unexpectedly, which was not attributable to poor maintenance and was not discovered during routine maintenance, did not constitute an extraordinary circumstance under Article 5(3) of Regulation 261/2004.

The Court reasoned that unexpected technical problems and premature component failures are ordinarily connected with the complex operation of aircraft. (EUR-Lex)

Relevance to AI

This case helps distinguish:

AI failure to detect an ordinary maintenance problem

from

AI failure to detect a genuinely hidden manufacturing/design defect.

If an AI system misses an ordinary maintenance condition that the maintenance organisation should have detected, the organisation's duties remain important.

If the AI misses an entirely latent design defect that could not reasonably have been detected, causation and foreseeability become much more difficult.

8. Case Law 4 — A and Others v Finnair Oyj, C-832/18

Court: CJEU
Date: 12 March 2020

The dispute concerned an aircraft component that failed and the meaning of technical shortcomings inherent in aircraft maintenance.

The CJEU held that technical shortcomings inherent in aircraft maintenance generally do not constitute extraordinary circumstances. It specifically addressed the failure of an "on condition" component—one replaced when it becomes defective rather than at a predetermined interval. (EUR-Lex)

Relevance to AI

This is important for AI diagnostic systems.

Suppose an AI system is designed to predict component failure.

The system says:

"Component operating normally."

But the component fails prematurely.

A legal dispute could ask:

Was the component actually defective?

Was the defect detectable?

Was the AI intended to detect this failure?

Was the AI sufficiently accurate for the intended task?

Were alternative inspection procedures required?

Did the maintenance organisation have a duty to conduct physical inspection?

Key principle

An unexpected component failure does not itself establish that AI was defective or that the maintenance organisation was negligent.

The claimant must establish the relevant duty, breach, causation and damage.

9. Case Law 5 — Finnair Oyj v Fennia, C-832/18

The same judgment is particularly useful because it demonstrates how European courts approach technical aircraft-component failures.

The Court distinguished ordinary maintenance-related technical shortcomings from hidden manufacturing defects.

Technical failures associated with aircraft operation are normally treated differently from defects that are shown to arise from an underlying hidden manufacturing problem. (EUR-Lex)

AI relevance

Suppose:

AI says component healthy → component fails

There are at least two possibilities.

Situation A — maintenance problem

The component was deteriorating normally and should have been detected through the applicable maintenance regime.

Potential issues:

AI negligence;

human verification;

maintenance organisation liability.

Situation B — hidden manufacturing defect

The component contains a latent defect that could not reasonably have been detected.

Potential issues:

manufacturer;

product liability;

design defect;

continuing-airworthiness instructions.

Therefore, root-cause analysis is essential.

10. Case Law 6 — A v Finnair Oyj, C-385/23

Court: CJEU
Judgment: 13 June 2024

This case involved a technical failure caused by a hidden design defect affecting aircraft of the same type.

The CJEU confirmed that where a manufacturer or competent authority reveals that aircraft already in service are affected by a hidden manufacturing defect affecting flight safety, the resulting technical failure can be distinguished from ordinary operational maintenance problems. (EUR-Lex)

Relevance to AI

Imagine that an AI maintenance platform is trained using historical aircraft data.

It repeatedly identifies an unusual engine signal as:

"Normal variation."

Later, the manufacturer discovers that the signal was actually an early indicator of a hidden design defect.

The legal question would then involve:

whether the defect was technically discoverable;

whether the AI had access to relevant data;

whether the manufacturer knew about it;

whether the maintenance organisation received warnings;

whether the AI system was supposed to identify the defect;

whether human personnel should have recognised the anomaly.

Important distinction

This case does not create an AI liability rule.

It provides an aviation-law framework for distinguishing:

ordinary maintenance failure

from

latent design/manufacturing defect.

11. Case Law 7 — D. S.A. v P. S.A., C-411/23

Court: CJEU
Judgment: 13 June 2024

This case involved an aircraft-engine malfunction associated with a hidden design defect.

The aircraft operator had conducted an emergency inspection after the malfunction and the defect was identified following consultation with the engine manufacturer. The CJEU treated the hidden engine design defect as capable of constituting an extraordinary circumstance for the purposes of Regulation 261/2004. (tourismlaw.pt)

Relevance to AI

Consider:

AI system identifies no engine anomaly → emergency inspection later discovers design defect.

This case provides a useful analytical distinction:

AI diagnostic error

does not necessarily equal

maintenance negligence.

The court would first need to establish whether the underlying problem was:

a hidden design defect;

an ordinary maintenance issue;

a foreseeable component failure;

a software-detectable anomaly.

12. Case Law 8 — London Helicopters Ltd v Heliportugal LDA-INAC, [2006] EWHC 108 (QB)

Court: High Court of England and Wales

This case is especially important for AI-assisted maintenance because it concerns the legal significance of an aviation maintenance certificate.

A Portuguese company performed maintenance on a helicopter engine and issued a JAA Form One Authorised Release Certificate.

The claimant alleged that statements in the certificate were negligent and relied upon in subsequent transactions involving the engine. (vLex)

The court considered the jurisdictional consequences of the alleged negligent statements.

Relevance to AI

Imagine an AI system produces:

"Component serviceable — no defect detected."

A qualified engineer then signs a formal maintenance-release document based on that conclusion.

The existence of the AI system does not necessarily eliminate responsibility for the human certification statement.

The case is therefore particularly useful for:

AI-generated maintenance reports;

automated diagnostic certificates;

electronic maintenance records;

negligent misstatement;

reliance;

professional certification.

Principle

A technical certification or release statement can have independent legal significance when another person relies on it.

13. Case Law 9 — Sunrock Aircraft Corporation Ltd v Scandinavian Airlines System, [2007] EWCA Civ 882

Court: Court of Appeal of England and Wales

This case concerned aircraft maintenance obligations in the context of an aircraft lease.

The court examined detailed contractual obligations requiring the aircraft to be:

maintained;

serviced;

repaired;

overhauled;

in accordance with the manufacturer's approved maintenance programme. (BAILII)

The judgment illustrates the contractual importance of maintenance programmes and the technical condition of aircraft components.

Relevance to AI

Suppose an aircraft lease requires maintenance according to an approved programme.

The airline introduces an AI diagnostic system.

The AI says:

"No additional inspection necessary."

But the approved maintenance programme requires physical inspection.

The airline cannot necessarily substitute the AI output for the contractual maintenance obligation.

Principle

AI can assist maintenance; it does not automatically rewrite the maintenance obligations contained in an aircraft contract or approved maintenance programme.

14. Case Law 10 — Axis Specialty Europe SE v Honeywell International Inc. and Others, ECLI:NL:RBGEL:2026:5729

Court: District Court of Gelderland, Netherlands
Date: 15 July 2026

This is a particularly useful recent European civil case.

The dispute followed an aircraft emergency landing after engine failure.

The insurer alleged that the damage resulted from:

a construction/design defect in an engine component; and

incorrect maintenance instructions.

The defendants argued that the problem resulted from improperly performed aircraft maintenance.

The court rejected the claims against the engine manufacturer and other parties, finding insufficient proof of a defective product or attributable contractual breach. The case also involved a maintenance organisation, Aircraft Maintenance Netherlands. (lexboost.com)

Importance for AI maintenance

This is not an AI case, but it is highly relevant to an AI diagnostic-error dispute because it illustrates the central question:

What actually caused the aircraft failure?

If AI is involved, the claimant would similarly have to establish whether the loss resulted from:

AI diagnostic error;

human maintenance error;

manufacturer's defect;

defective maintenance instructions;

component failure;

improper installation;

another intervening cause.

Principle

Aviation liability depends on proving the actual causal chain rather than merely identifying a technical problem.

15. What Counts as an AI Diagnostic Error?

An AI maintenance system could fail in several ways.

15.1 False negative

The AI says:

"No defect."

But a defect exists.

This is probably the most important scenario.

15.2 False positive

The AI says:

"Critical defect."

But no defect exists.

This can cause:

unnecessary component replacement;

aircraft grounding;

financial loss;

flight cancellation.

15.3 Misclassification

The AI detects an abnormality but identifies the wrong component.

Example:

vibration originates in engine bearing A, but AI identifies bearing B.

15.4 Incorrect severity assessment

AI identifies a defect but classifies it as:

"low priority"

when it should be:

"immediate maintenance action."

15.5 Data error

AI receives incorrect:

sensor data;

maintenance history;

aircraft configuration;

component serial number.

The resulting diagnosis may therefore be wrong without the underlying algorithm being defective.

16. AI Hallucination in Aircraft Maintenance

AI systems based on generative models introduce an additional problem.

An AI may generate a technically plausible but incorrect statement, such as:

"The manufacturer's maintenance manual permits continued operation for 50 flight cycles."

If no such instruction exists, the consequence could be extremely serious.

Potential liability questions include:

Was the AI designed for safety-critical aviation use?

Was it approved for the task?

Did the system have access to authoritative maintenance data?

Did it cite its source?

Was hallucination risk tested?

Was human verification required?

Did the engineer rely upon the output?

17. AI Versus Traditional Diagnostic Software

The legal analysis may differ depending on the technology.

Traditional rule-based software

Example:

Sensor temperature > X → inspection required.

This is relatively predictable.

Machine-learning system

The system learns patterns from data.

Generative AI

The system may produce natural-language recommendations.

The more autonomous the system becomes, the more important questions of:

explainability;

validation;

traceability;

human oversight;

audit logs;

data quality

become.

18. Human-in-the-Loop Liability

European aircraft maintenance is fundamentally safety-oriented.

Therefore, a useful model is:

AI diagnosis

↓

qualified maintenance professional

↓

verification

↓

maintenance action

↓

certification/release

If the AI makes an error but the qualified engineer should reasonably have detected it, liability may remain with the human/organisation.

If the error was impossible to detect even through reasonable professional verification, liability analysis becomes more complicated.

19. Professional Standard of Care

A maintenance organisation may be expected to operate according to:

applicable EASA requirements;

approved maintenance procedures;

manufacturer's instructions;

approved maintenance data;

professional competence requirements;

organisational procedures.

The TEE judgment is especially relevant because it emphasises appropriate qualifications, experience, training and assessment of personnel performing airworthiness inspection functions. (EUR-Lex)

An AI system cannot simply be used to avoid those professional requirements.

20. AI Validation Duty

Before deployment, an organisation should potentially evaluate:

accuracy;

false-negative rate;

false-positive rate;

data quality;

aircraft-type specificity;

environmental conditions;

sensor reliability;

model drift;

software updates;

cybersecurity;

human factors.

Failure to validate a safety-critical AI system can become evidence relevant to negligence or breach of contract.

21. AI Model Drift

Aircraft systems change over time.

For example:

Aircraft A in 2024

may differ from:

Aircraft A after a 2026 software upgrade or component modification.

If an AI system was trained on the old configuration, its predictions may become unreliable.

Therefore:

AI maintenance systems require continuing validation, not simply one-time certification.

22. Data Quality and Causation

Suppose AI makes an incorrect diagnosis.

The airline must still prove:

bad data → wrong AI output → wrong maintenance decision → component failure → damage.

This is a chain of causation.

If the original sensor was already defective, the AI developer may argue:

"The AI received incorrect information."

If the engineer ignored contradictory physical evidence, the maintenance organisation may be implicated.

If the component itself contained a hidden manufacturing defect, the manufacturer may become relevant.

23. Multi-Party Liability

An aircraft accident can therefore produce a multi-party dispute.

Example

Manufacturer

→ defective component

Sensor manufacturer

→ inaccurate sensor

AI developer

→ incorrect diagnostic algorithm

Maintenance organisation

→ failed to verify AI output

Engineer

→ incorrectly certified aircraft

Airline

→ continued operation

The court must identify:

causation;

contractual relationships;

contribution;

indemnity;

applicable law.

24. Product Liability

An AI maintenance system may potentially raise product-liability questions depending on:

how the system is supplied;

whether it qualifies as a product under the applicable regime;

whether the alleged defect is in software;

whether the damage falls within the applicable liability rules.

The EU's new Product Liability Directive, Directive (EU) 2024/2853, significantly modernises the European regime and is particularly relevant to technologically sophisticated products.

Its application begins for products placed on the market or put into service after 8 December 2026. The Directive also preserves other contractual and non-contractual liability regimes. (EUR-Lex)

For AI maintenance systems, the precise classification will depend on the system and the transaction.

25. Contractual Liability

An airline may have a contract with:

AI provider;

MRO organisation;

aircraft manufacturer;

engine manufacturer;

software integrator.

The contract may specify:

accuracy standards;

service levels;

validation obligations;

warranties;

exclusions;

liability caps;

indemnities;

audit rights;

cybersecurity obligations.

Therefore, the same AI failure can generate both:

contractual liability

and

tort/delict liability.

26. Negligent Maintenance

The clearest traditional claim may be against the maintenance organisation.

Example:

The maintenance organisation's AI system identifies a hydraulic leak as insignificant. The engineer fails to conduct the required physical inspection. The aircraft is released and later suffers hydraulic failure.

Possible allegation:

The organisation failed to perform maintenance with the level of care required by the applicable aviation and professional standards.

The AI output becomes evidence, not necessarily the legal decision-maker.

27. Negligent Certification

Suppose an engineer signs:

"Aircraft approved for return to service."

The engineer knew that the AI system had low confidence but nevertheless signed without additional inspection.

Potential liability could arise from:

professional negligence;

breach of regulatory requirements;

negligent certification;

contractual breach.

London Helicopters illustrates why aviation certification documentation can become central to civil litigation. (vLex)

28. Manufacturer Liability

The manufacturer may be liable if:

the component was defective;

the maintenance manual was defective;

the diagnostic thresholds supplied by the manufacturer were incorrect;

known defects were not communicated;

safety information was inadequate.

The recent Dutch Axis v Honeywell litigation demonstrates how courts may have to distinguish between an alleged engine defect and incorrect maintenance as competing causal explanations. (lexboost.com)

29. AI Developer Liability

The AI developer may potentially face claims where:

the system was defective;

the system was marketed for a safety-critical purpose without adequate validation;

known limitations were concealed;

training data were inadequate;

updates introduced dangerous errors;

contractual performance standards were breached.

However, the mere existence of an incorrect AI prediction does not automatically establish developer liability.

The claimant still needs the applicable legal basis and proof.

30. The Importance of Audit Logs

For AI aviation disputes, auditability may be decisive.

The system should ideally preserve:

input data;

model version;

output;

confidence level;

time of analysis;

user identity;

system configuration;

data source;

software version;

subsequent corrections.

Without such information, it may become difficult to determine:

Why did the AI reach its conclusion?

and

Who relied on that conclusion?

31. Burden of Proof

A claimant generally needs to establish the elements of the particular legal claim.

For example:

Negligence

Duty → breach → causation → damage

Contract

Contract → obligation → breach → loss

Product liability

Product → defect → damage → causal relationship

Certification challenge

Legal power/duty → unlawful decision or omission → legally available remedy

AI makes the factual proof more complicated but does not eliminate these basic legal structures.

32. Evidence Required

Important evidence could include:

Technical evidence

aircraft sensor data;

flight-data recorder information;

maintenance records;

engine logs;

component history;

AI diagnostic output.

AI evidence

model version;

training data;

validation records;

accuracy statistics;

confidence score;

model update history;

system logs;

error reports.

Human evidence

engineer's notes;

maintenance instructions;

communications;

inspection records;

reasons for accepting/rejecting AI output.

33. Causation Example

Suppose:

AI incorrectly says "no defect."

But investigation shows:

sensor was malfunctioning;

engineer did not perform required manual inspection;

maintenance manual required physical inspection;

component also had a hidden manufacturing defect.

There may be several causes.

A court might need to determine:

Did the AI error cause the failure?

Did the sensor error cause the AI error?

Would proper human inspection have detected the defect?

Was the defect detectable at all?

Did the manufacturer's defect independently cause the accident?

This is why AI aviation cases are likely to be multi-party technical causation cases.

34. Liability Matrix

ErrorPotential responsible party
Incorrect AI algorithmAI developer/provider
Bad training dataAI developer/data supplier
Bad sensor dataSensor manufacturer/maintenance organisation
Failure to validate AIMaintenance organisation/operator
Ignoring AI warningMaintenance organisation
Blindly trusting AICertifying professional/organisation
Incorrect maintenance manualManufacturer
Hidden component defectComponent manufacturer
Failure to issue safety informationManufacturer/possibly relevant authority
Incorrect certificate of releaseCertifying organisation/person

Actual liability depends on the governing national and EU rules and the evidence.

35. AI Diagnostic Error and Passenger Claims

If the maintenance error causes a flight accident, passengers may have claims under the Montreal Convention and applicable passenger-liability rules.

The existence of AI does not automatically change the Convention's liability framework.

The passenger may primarily claim against the air carrier, while the carrier may subsequently seek:

contribution;

indemnity;

contractual recovery;

product-liability damages

from the maintenance organisation, manufacturer or technology provider.

Thus:

Passenger claim

and

airline's recovery claim against maintenance/AI actors

can be legally separate.

36. AI Error and Economic Loss

Not every AI error will cause physical damage.

Example:

AI falsely identifies a dangerous engine defect and the airline grounds 20 aircraft.

Possible loss:

cancelled flights;

passenger rebooking;

aircraft downtime;

crew costs;

lost revenue;

unnecessary component replacement.

Recovery of purely economic loss depends heavily on:

contract;

applicable national tort law;

contractual exclusions;

remoteness;

foreseeability;

statutory liability regime.

37. False Positive Versus False Negative

This distinction is particularly important.

False negative

AI misses a real defect.

Potential result:

safety risk + physical damage.

False positive

AI incorrectly detects a defect.

Potential result:

economic loss + unnecessary maintenance.

The legal analysis may be different because physical injury and property damage are usually treated differently from pure economic loss.

38. AI and Continuing Airworthiness

The European framework makes continuing airworthiness a continuing obligation.

The earlier EU framework placed responsibilities on owners/operators and continuing-airworthiness organisations and required reporting of conditions that could endanger flight safety. (EUR-Lex)

This is significant for AI because a diagnostic system may operate continuously.

If the system detects a repeated anomaly, the organisation may have to determine whether the condition should be:

investigated;

reported;

repaired;

monitored;

communicated to the authority or design organisation.

AI therefore becomes part of a broader continuing-airworthiness governance system.

39. AI and Mandatory Reporting

European aviation law contains mechanisms for reporting safety-related conditions.

The regulatory material identifies maintenance-related events such as:

incorrect assembly;

structural damage;

defects in life-controlled parts;

failures discovered through mandatory inspections. (EUR-Lex)

If an AI system repeatedly detects an anomaly but the organisation fails to investigate or report it when required, that omission could become important evidence in subsequent liability proceedings.

40. Is AI Certification Enough?

No.

An organisation might say:

"The AI software was certified."

That does not necessarily answer:

whether it was used for the correct purpose;

whether it was properly configured;

whether the relevant aircraft type was within its validated scope;

whether its output was correctly interpreted;

whether human verification was required;

whether it had been updated;

whether its training data remained representative.

Therefore:

Software approval is not necessarily equivalent to proof that every individual AI diagnosis was correct.

41. Human Oversight

A robust legal and safety model would involve:

Level 1 — AI

Detects anomaly.

Level 2 — Engineer

Reviews output.

Level 3 — Technical procedure

Determines required inspection.

Level 4 — Certifying person

Makes the legally relevant maintenance decision.

Level 5 — Documentation

Records the decision and basis.

This structure makes it easier to determine responsibility after an incident.

42. Defences

Potential defendants may argue:

1. No defect

The AI system operated according to specification.

2. No breach

All required procedures were followed.

3. Intervening cause

The accident resulted from another defect.

4. Human misuse

The operator used the AI outside its intended purpose.

5. Incorrect input data

The AI received inaccurate sensor or maintenance information.

6. Hidden manufacturing defect

The underlying aircraft/component defect was not reasonably detectable.

7. Contributory negligence

The claimant or operator failed to comply with maintenance requirements.

8. Contractual limitation

The contract may contain agreed limitations, subject to applicable law.

43. Why TEE Is Particularly Important

For an AI maintenance case, TEE provides perhaps the clearest regulatory analogy.

The CJEU required persons responsible for aircraft airworthiness inspection to have appropriate experience, training and competence. (EUR-Lex)

This supports the proposition that:

A regulated maintenance decision remains a professional responsibility even where technological tools assist the decision-maker.

An AI system can therefore be viewed as a tool within the maintenance process, unless applicable law expressly gives it a different regulatory status.

44. Why London Helicopters Is Important

London Helicopters shows how an aviation maintenance certificate can create legal consequences when third parties rely upon it.

The case involved a JAA Form One certificate issued after engine maintenance and allegations that statements in that certificate were negligent. (vLex)

For AI:

AI diagnosis → engineer's certification → reliance → damage

could create a chain of legal responsibility.

45. Why van der Lans Is Important

van der Lans shows that unexpected component failure does not automatically establish an extraordinary external event.

The CJEU treated ordinary technical problems as connected with the operation and maintenance of aircraft. (EUR-Lex)

For AI liability:

The fact that the AI "unexpectedly" made a wrong prediction does not itself establish that the error was legally unavoidable.

The court must investigate why the error occurred and whether the organisation should reasonably have prevented or detected it.

46. Why the 2024 Finnair and LOT Cases Matter

The 2024 hidden-design-defect cases provide an important boundary.

Where a manufacturer discovers that an aircraft type has a hidden safety-related design/manufacturing defect, European law recognises that this is fundamentally different from ordinary maintenance problems. (EUR-Lex)

Thus, in an AI case:

AI failure to detect a genuinely hidden design defect should not automatically be characterised as negligent AI maintenance.

The underlying defect may instead point toward manufacturer/product-liability issues.

47. Ten-Case Summary

CaseMain legal relevance to AI maintenance
TEE and Others, C-271/11Qualifications, competence and airworthiness inspection
Wallentin-Hermann, C-549/07Technical defects and maintenance responsibility
van der Lans, C-257/14Unexpected component failure and maintenance
A and Others v Finnair, C-832/18Aircraft-component failure and maintenance
Finnair, C-385/23Hidden aircraft design defect
D. S.A. v P. S.A., C-411/23Hidden engine design defect
London Helicopters v HeliportugalMaintenance certificate and negligent misstatement
Sunrock v SASContractual aircraft maintenance obligations
Axis v Honeywell, ECLI:NL:RBGEL:2026:5729Recent European civil dispute over maintenance versus engine defect
Current EU continuing-airworthiness jurisprudence/regulationMaintenance organisations, inspection and release responsibilities

The first seven are particularly useful for building the doctrinal framework; the 2026 Dutch case is especially useful as a recent civil-liability example concerning competing maintenance and product-defect explanations. (lexboost.com)

48. Practical Hypothetical

Facts

An airline uses an AI engine-diagnostic system.

The AI analyses vibration data and reports:

"No immediate maintenance action required."

The engineer accepts the result.

Three days later, an engine component fails.

Investigation reveals:

the component had a developing defect;

the AI had received correct sensor data;

the AI model had been trained on a different engine configuration;

the maintenance organisation had not updated the model;

the manufacturer's manual required an additional inspection;

the engineer did not perform that inspection.

Possible claims

Against AI provider:
Failure of the software to perform according to contractual/specification requirements.

Against maintenance organisation:
Failure to properly validate or supervise the AI and failure to comply with maintenance procedures.

Against engineer:
Possible professional negligence, depending on the applicable law.

Against manufacturer:
Only if evidence establishes a manufacturing/design defect or another actionable failure.

Against airline:
Possible responsibility for continuing-airworthiness management, depending on the applicable allocation of duties.

49. Core Legal Test

For an aircraft maintenance AI diagnostic claim, the court can conceptually ask:

Step 1 — Duty

Who had the legal duty to diagnose or maintain the aircraft?

Step 2 — Standard

What standard applied?

EASA requirements;

approved maintenance programme;

manufacturer's instructions;

contract;

professional standard.

Step 3 — AI performance

What exactly did the AI system do?

Step 4 — Human reliance

Who relied on its output?

Step 5 — Verification

Was human verification required or reasonably expected?

Step 6 — Causation

Would proper diagnosis have prevented the damage?

Step 7 — Damage

What legally recoverable loss occurred?

Step 8 — Allocation

Should responsibility be divided between:

AI provider;

MRO;

engineer;

manufacturer;

operator?

50. Conclusion

Aircraft maintenance AI diagnostic error liability in Europe is an emerging civil-liability field rather than an area with a mature body of AI-specific aviation judgments. The existing European case law provides the legal building blocks.

TEE establishes the importance of competent, appropriately trained airworthiness personnel. (EUR-Lex) Wallentin-Hermann, van der Lans and Finnair distinguish ordinary technical/maintenance problems from exceptional hidden defects. (EUR-Lex) The 2024 Finnair and LOT cases further clarify the significance of hidden design defects affecting aircraft safety. (EUR-Lex) London Helicopters demonstrates that maintenance certification documents can themselves generate civil disputes where others rely on their contents. (vLex) The recent Dutch Axis v Honeywell judgment illustrates the importance of proving the actual causal source of an aircraft failure where maintenance error and alleged product defect compete as explanations. (lexboost.com)

The central principle is:

AI may assist aircraft maintenance, but the legal responsibility for ensuring continuing airworthiness does not automatically disappear merely because a diagnostic decision was made or assisted by an algorithm.

Ultra-short revision

AI maintenance liability = AI error + maintenance duty + human oversight + regulatory compliance + causation + damage.

Key cases:

TEE → competent airworthiness inspectors

Wallentin-Hermann → technical defects

van der Lans → unexpected component failure

Finnair C-832/18 → maintenance/component failure

Finnair C-385/23 → hidden design defect

LOT C-411/23 → hidden engine defect

London Helicopters → maintenance certificate/reliance

Sunrock → contractual maintenance obligations

Axis v Honeywell → maintenance error versus product defect.

LEAVE A COMMENT