Civil Law And Algorithmic Economic Crisis Liability In Europe .
Civil Law and Algorithmic Economic Crisis Liability in Europe
1. Introduction
Algorithmic economic crisis liability concerns situations where an AI system, algorithmic trading system, automated credit model, pricing engine, risk-management system, or other automated decision system contributes to large-scale economic harm, such as:
financial-market instability;
cascading bank losses;
mass credit restrictions;
algorithmic market manipulation;
automated liquidation of assets;
systemic trading losses;
supply-chain disruption;
widespread business failures;
large-scale consumer losses;
collapse of an algorithmically managed platform or financial service.
The difficult legal question is:
When an algorithm contributes to an economic crisis, who is civilly liable for the resulting losses?
European law does not presently contain one general rule saying that an AI developer automatically pays for an economic crisis caused by its algorithm. Liability normally has to be constructed through existing regimes—contract, tort/delict, GDPR, product liability, financial-services law, consumer law and, where applicable, the AI Act.
Importantly, the EU's proposed AI Liability Directive was withdrawn on 6 October 2025. Therefore, it should not be presented as current binding EU law. (EUR-Lex)
The current legal picture is better represented as:
AI ACT + PRODUCT LIABILITY + GDPR + FINANCIAL REGULATION + NATIONAL CIVIL LIABILITY
2. Meaning of Algorithmic Economic Crisis
An algorithmic economic crisis can be understood at three levels.
Level 1 — Individual economic damage
Example:
An automated credit algorithm incorrectly rejects a company's financing application, causing €2 million of losses.
This is comparatively easier to litigate.
Level 2 — Market-sector damage
Example:
An algorithm used by many banks incorrectly assesses risk, causing simultaneous withdrawal of credit from an entire sector.
Level 3 — Systemic economic damage
Example:
Several interconnected algorithms react to the same market signal, triggering automated selling, liquidity collapse and a financial-market crisis.
The third situation creates the greatest civil-law difficulties.
3. Basic Liability Chain
The fundamental structure is:
ALGORITHM → ERROR/DEFECT → UNLAWFUL OR NEGLIGENT CONDUCT → ECONOMIC DAMAGE → CAUSATION → LIABLE ACTOR → REMEDY
For systemic cases:
ALGORITHM → COMMON MODEL → CORRELATED DECISIONS → CASCADING EFFECT → MARKET DISRUPTION → MULTIPLE VICTIMS → CAUSATION PROBLEM → LIABILITY
4. Why Algorithmic Economic-Crisis Liability Is Difficult
Traditional civil liability generally assumes:
One defendant → one wrongful act → identifiable victim → identifiable damage.
Algorithmic crises can instead involve:
Many developers → many operators → many algorithms → interconnected decisions → millions of victims → market-wide losses.
Therefore, five major problems arise:
Causation
Identification of the responsible actor
Proof of fault
Pure economic loss
Quantification of widespread damage
5. Current EU Legal Framework
A. EU AI Act
The AI Act is primarily a preventive regulatory framework, not a general compensation statute.
It regulates matters such as:
risk management;
data governance;
technical documentation;
transparency;
human oversight;
accuracy;
robustness;
cybersecurity;
post-market monitoring.
Therefore:
AI Act violation ≠ automatic civil damages.
Instead, an AI Act breach may become important evidence when a claimant brings a civil-law claim under another applicable legal regime.
6. Product Liability Directive 2024/2853
The revised EU Product Liability Directive is extremely important for algorithmic liability.
The Directive expressly clarifies that software, including AI systems, can constitute a product for product-liability purposes. It covers software supplied through devices, networks, cloud technologies and software-as-a-service arrangements. (EUR-Lex)
This is a major change from the older product-liability framework.
Therefore:
DEFECTIVE AI SOFTWARE → PRODUCT LIABILITY
may become a viable route where the statutory conditions are satisfied.
The revised regime also recognises continuing liability issues involving software updates, upgrades and machine-learning algorithms under the producer's control. (EUR-Lex)
7. But Product Liability Does Not Solve Everything
An economic crisis may produce:
lost investments;
lost profits;
reduced share values;
business interruption;
loss of market opportunity;
contractual losses;
insolvency;
reputational damage.
Not every form of pure economic loss necessarily falls within the same product-liability route.
Therefore:
PRODUCT LIABILITY ≠ COMPLETE AI ECONOMIC-CRISIS LIABILITY SYSTEM
National tort/contract law may remain crucial.
8. GDPR
Where an algorithmic crisis involves personal data, GDPR can create an additional route.
Examples:
defective credit scoring;
mass profiling;
discriminatory risk assessment;
unlawful automated decision-making;
inaccurate financial profiles.
Article 82 GDPR can provide compensation where its requirements are satisfied.
But the CJEU has made clear that:
GDPR infringement + damage + causal connection
must be analysed.
9. Financial and Securities Law
Where algorithms operate in:
securities markets;
investment services;
banking;
payment systems;
insurance;
crypto-assets,
special financial regulation may apply.
Civil liability may therefore exist alongside:
supervisory enforcement;
market-abuse rules;
prudential requirements;
investment-service duties;
contractual obligations.
This is especially important where the algorithm is used for automated trading or financial-risk management.
10. Case Law
There is an important qualification:
There is currently no large body of European case law directly deciding that an autonomous AI algorithm caused a continent-wide economic crisis and determining civil damages for all resulting losses.
Accordingly, the following authorities should be divided into:
A. Direct algorithmic/data cases
and
B. Analogical civil/product-liability cases.
That distinction is legally important.
11. Case 1 — SCHUFA Holding (Scoring), C-634/21
Court: CJEU
Date: 7 December 2023
This is one of the strongest direct algorithmic authorities.
Facts
SCHUFA generated credit scores representing the probability that an individual would meet future payment obligations.
Those scores were used by third parties in making decisions concerning individuals.
Principle
The CJEU held that automated scoring can fall within Article 22 GDPR where it effectively plays a decisive role in an automated decision having significant effects.
The case demonstrates that an apparently intermediate algorithmic output—such as a score—can itself have legally significant consequences. (Infocuria)
Relevance to economic crisis
Suppose a financial institution uses an automated risk model and thousands of institutions use similar models.
A common error could cause:
SIMILAR RISK MODEL → SIMILAR DECISIONS → SIMULTANEOUS CREDIT CONTRACTION
SCHUFA therefore helps establish the legal significance of algorithmic outputs even where another entity technically makes the final decision.
Classification
Direct algorithmic authority; individual rather than systemic economic harm.
12. Case 2 — Dun & Bradstreet Austria, C-203/22
Court: CJEU
Date: 27 February 2025
This is another particularly important algorithmic authority.
Facts
An individual's creditworthiness was assessed automatically.
The automated assessment contributed to refusal of a mobile-phone contract.
Principle
The CJEU held that the person concerned must receive meaningful information concerning the logic involved in the automated decision-making, sufficient to understand and challenge the decision. (curia)
Relevance
In a systemic algorithmic crisis, transparency becomes crucial.
A court may need to investigate:
what model was used;
what variables were used;
what threshold was applied;
what risk assumptions existed;
whether the model was validated;
whether known errors existed.
Dun & Bradstreet demonstrates that the black-box character of an algorithm cannot simply end the legal inquiry.
Classification
Direct algorithmic authority; strong evidentiary relevance.
13. Case 3 — Österreichische Post, C-300/21
Court: CJEU
Date: 4 May 2023
Facts
Österreichische Post used an algorithm to classify individuals according to socio-demographic characteristics and infer political affinities.
Principle
The CJEU held that a mere GDPR infringement does not automatically create a right to compensation.
There must be:
unlawful processing;
damage;
causal connection between the infringement and the damage.
At the same time, non-material damage does not need to satisfy a special minimum seriousness threshold imposed by national law. (Infocuria)
Relevance
This is crucial to algorithmic economic-crisis claims.
A claimant cannot simply argue:
“The algorithm violated the law, therefore I receive all my economic losses.”
The claimant must establish the legally relevant damage and causal relationship.
Classification
Direct algorithmic/data authority; important compensation principle.
14. Case 4 — Google Spain, C-131/12
Court: CJEU Grand Chamber
Date: 13 May 2014
Principle
The CJEU recognised significant responsibilities for operators involved in personal-data processing.
The judgment concerned search-engine processing and the rights of data subjects. (Infocuria)
Relevance to AI economic crises
Algorithmic economic systems often contain several actors:
DATA PROVIDER → MODEL DEVELOPER → PLATFORM → OPERATOR → CUSTOMER
Google Spain demonstrates why identifying the legally responsible data-processing actor matters.
The same conceptual issue arises with AI:
Who actually controlled the harmful processing?
Classification
Analogical authority concerning allocation of responsibility.
15. Case 5 — Boston Scientific Medizintechnik, Joined C-503/13 and C-504/13
Court: CJEU
Date: 5 March 2015
This is an important product-liability analogy.
Facts
Pacemakers and implantable cardioverter-defibrillators were found to have a potential defect.
Principle
The CJEU held that where products belonging to the same group or production series have a potential defect creating an abnormal risk, products of that group can be treated as defective under the Product Liability Directive.
The Court also recognised liability consequences associated with replacement of the defective products. (Infocuria)
Application to AI
Imagine a widely deployed AI system containing a common defect.
Instead of:
one defective device,
there could be:
one defective algorithm deployed to 100,000 systems.
Boston Scientific provides an analogy for thinking about systemic or class-wide defect risk.
Important limitation
Boston Scientific concerned physical medical devices, not AI.
Therefore it is:
Analogical, not direct AI authority.
16. Case 6 — W and Others, C-621/15
Court: CJEU
Date: 21 June 2017
Facts
The case concerned alleged vaccine defects and causation.
Principle
The CJEU considered whether national evidentiary rules could permit courts to rely on a body of serious, specific and consistent evidence concerning defect and causation despite the absence of scientific consensus.
The victim nevertheless retained the burden of proving the relevant elements. (curia)
Importance for algorithmic crises
Algorithmic causation can be scientifically difficult.
Suppose:
algorithmic error → market reaction → liquidity shortage → business collapse.
The claimant may not possess direct evidence of every step.
Courts may therefore have to evaluate:
statistical evidence;
technical evidence;
expert reports;
model documentation;
system logs;
counterfactual analysis.
Classification
Analogical but highly relevant causation authority.
17. Case 7 — O'Byrne v Sanofi Pasteur, C-127/04
Court: CJEU
Date: 9 February 2006
The case concerned the concept of when a product was put into circulation for product-liability purposes and the relationship between a producer and its subsidiary. (Infocuria)
Relevance to AI
AI supply chains are often complicated:
Developer → cloud provider → integrator → distributor → bank → end-user.
The O'Byrne principles are relevant by analogy to determining:
who placed the relevant product into circulation;
which entity is the producer;
when responsibility attaches.
Classification
Analogical product-liability authority.
18. Case 8 — Boston Scientific + O'Byrne Together
These cases become particularly useful when combined.
The question becomes:
Who introduced the defective AI system into the economic environment, and when did the defect become legally relevant?
For example:
AI Developer
↓
Cloud Deployment
↓
Financial Institution
↓
Automated Risk Decisions
↓
Market Impact
The revised Product Liability Directive now expressly treats software and AI systems as products for no-fault liability purposes, making these older cases particularly useful background principles. (EUR-Lex)
19. The Causation Problem
Causation is probably the biggest obstacle in systemic algorithmic-crisis litigation.
Consider:
AI model error
↓
Bank changes lending
↓
Credit becomes scarce
↓
Companies reduce investment
↓
Employment falls
↓
Asset prices fall
↓
Further defaults
↓
Economic crisis
Who caused the final loss?
Potential causes may include:
algorithm;
programmer;
bank;
traders;
regulators;
market conditions;
other algorithms;
geopolitical events;
consumer behaviour.
Civil courts generally cannot simply assume:
Algorithm present = algorithm legally caused the crisis.
20. Concurrent Causation
Several algorithms may operate simultaneously.
For example:
Algorithm A: detects increasing risk.
Algorithm B: automatically sells assets.
Algorithm C: changes lending conditions.
Algorithm D: increases collateral requirements.
Each reaction may amplify the others.
This creates:
ALGORITHMIC FEEDBACK LOOP
A court would have to determine whether a defendant's conduct was:
a factual cause;
a legally relevant cause;
a substantial/contributing cause under the applicable national law;
too remote to generate liability.
The precise test remains dependent on the applicable national civil law.
21. Pure Economic Loss
This is another major difficulty.
Suppose an algorithm causes a stock market crash.
Investors claim:
“My shares lost €500,000.”
That is economic loss.
But European national civil-law systems differ regarding:
pure economic loss;
remoteness;
protective norms;
market losses;
consequential losses;
speculative losses.
Therefore:
EU AI regulation does not create one uniform European rule for every form of pure economic loss.
National private law remains extremely important.
22. Individual Loss vs Systemic Loss
| Individual claim | Systemic claim |
|---|---|
| One victim | Thousands/millions |
| One decision | Interconnected decisions |
| Easier causation | Difficult causation |
| Identifiable damage | Aggregate market damage |
| One defendant possible | Multiple actors |
| Personal data may be central | Market structure may be central |
| Traditional civil action | Collective/class/representative mechanisms may become important |
This distinction should always be made in an examination answer.
23. Algorithmic Market Manipulation
A separate category arises where an algorithm is intentionally or negligently designed to manipulate markets.
Examples include:
coordinated automated orders;
artificial price signals;
spoofing-type strategies;
manipulative order patterns;
automated dissemination of misleading market information.
Here the analysis may involve:
MARKET-ABUSE LAW + FINANCIAL REGULATION + CIVIL LIABILITY
The civil claimant may still need to prove:
wrongful conduct → loss → causation → recoverable damage.
24. Algorithmic Trading and Flash-Crash Scenario
Consider:
AI trading system receives a false signal.
It begins selling.
Other algorithms detect the selling and also sell.
The market price collapses.
Then:
automated stop-loss mechanisms activate.
This creates:
SELL → DETECT → SELL → DETECT → SELL
The resulting economic loss could be enormous.
The civil-law questions become:
Was the algorithm defective?
Was it negligently designed?
Was it inadequately tested?
Was monitoring inadequate?
Was human supervision required?
Was the operator warned?
Was there a duty to stop the system?
Was the market collapse foreseeable?
Which losses are legally recoverable?
25. AI Act as Evidence of Breach
The AI Act is primarily preventive.
But in a civil claim, regulatory requirements may become important evidence concerning the expected standard of care.
For example:
Failure to undertake appropriate risk management
could potentially support an argument that the operator failed to take reasonable precautions.
However:
AI Act breach does not automatically equal civil liability.
The claimant must still establish the applicable private-law elements.
26. Revised Product Liability and AI
The revised Product Liability Directive is particularly important because it expressly recognises software and AI systems as products.
It also recognises continuing control over software through:
updates;
upgrades;
machine-learning algorithms.
(EUR-Lex)
This is significant because traditional product liability was designed primarily around physical products.
Modern AI can instead be:
cloud-based + continuously updated + adaptive + interconnected.
The revised framework is designed to accommodate that technological reality.
27. Defect in an Algorithm
An algorithm might potentially be considered defective because of:
Design defect
The model was badly designed.
Training-data defect
The training data were inadequate or inappropriate.
Testing defect
The system was released without sufficient testing.
Updating defect
A later update introduced a harmful error.
Monitoring defect
The operator failed to detect an emerging problem.
Warning defect
Users were not properly warned about known limitations.
Thus:
DESIGN → DATA → TESTING → DEPLOYMENT → UPDATE → MONITORING
can become the civil-liability lifecycle.
28. Black-Box Problem
AI can make causation difficult because the claimant may not know:
Why did the algorithm produce this output?
The Commission's AI-liability proposal itself identified complexity, autonomy and opacity as factors that can make proving fault and causation difficult. (EUR-Lex)
Although that proposal was subsequently withdrawn, the problem it identified remains legally significant.
29. The Withdrawn AI Liability Directive
This requires special attention in a 2026 legal answer.
The European Commission proposed the AI Liability Directive in 2022 to address:
disclosure of evidence;
presumptions concerning causation;
AI-specific difficulties in proving fault;
national non-contractual liability.
The proposal recognised that AI opacity could make ordinary fault-based claims excessively difficult. (EUR-Lex)
However:
The proposal was withdrawn on 6 October 2025.
Therefore, it should be treated as legislative history, not as current binding European law. (EUR-Lex)
30. Why Withdrawal Matters
The practical consequence is that there is currently no standalone EU-wide AI tort regime based on that proposal.
Therefore the claimant may have to rely upon:
national tort/delict law;
contract;
GDPR;
Product Liability Directive;
financial regulation;
consumer law;
sector-specific rules;
collective-redress mechanisms.
This means that national civil law remains central.
31. Who Could Be Liable?
An algorithmic economic crisis can involve many potential actors.
1. AI developer
Possible issues:
defective design;
inadequate testing;
inadequate warnings;
known model weakness.
2. AI provider
Possible issues:
inadequate monitoring;
unsafe updates;
failure to correct known problems.
3. Operator
Possible issues:
negligent deployment;
excessive reliance on automation;
failure to supervise;
failure to deactivate the system.
4. Financial institution
Possible issues:
improper risk management;
failure to validate the model;
excessive automated dependence.
5. Data provider
Possible issues:
inaccurate or defective data.
6. Integrator
Possible issues:
defective integration of the AI into another system.
Therefore:
LIABILITY SHOULD FOLLOW THE ACTOR'S ROLE, CONTROL, DUTY AND CAUSAL CONTRIBUTION.
32. Contractual Liability
Contract may be especially important for business-to-business AI.
An AI provider may contractually promise:
accuracy;
uptime;
specified performance;
regulatory compliance;
security;
monitoring.
If the provider breaches those obligations, the customer may bring a contractual claim subject to:
contractual limitations;
exclusions;
indemnities;
force majeure;
causation;
applicable national law.
33. Tort/Delict Liability
A claimant without a direct contract may rely on national non-contractual liability.
The general structure is:
DUTY → BREACH/FAULT → DAMAGE → CAUSATION
The exact terminology differs across European legal systems.
For example, civil-law systems may use concepts such as:
fault;
unlawful act;
duty of care;
causation;
protected interest;
foreseeable damage.
34. Collective Economic Harm
A systemic algorithm may injure thousands of businesses.
For example:
Algorithmic supply-chain system incorrectly classifies thousands of suppliers as high risk.
Consequences:
contracts terminated;
credit withdrawn;
inventory cancelled;
employees dismissed;
businesses become insolvent.
The individual claims could be enormous in aggregate.
This creates questions concerning:
collective actions;
representative actions;
joinder;
aggregation;
insolvency proceedings;
contribution between defendants.
35. Contribution Between Multiple Defendants
Suppose:
Developer contributed 30%;
Bank contributed 40%;
Data provider contributed 20%;
Integrator contributed 10%.
The claimant may seek recovery according to applicable national law, followed by contribution or recourse between responsible parties.
There is no universal EU formula for dividing all AI-crisis damages among multiple tortfeasors.
36. Damage Calculation
Possible heads of loss include:
Direct loss
Actual financial loss.
Consequential loss
Loss caused as a consequence of the initial damage.
Lost profits
Expected profits that were lost.
Business interruption
Loss caused by system failure.
Market loss
Reduction in asset value.
Remediation costs
Costs of correcting the algorithmic failure.
Regulatory costs
Potentially recoverable only where recognised by applicable law.
Non-material damage
Potentially relevant under GDPR or other applicable regimes.
37. Österreichische Post and Causation
Österreichische Post is particularly useful because it confirms that compensation requires more than merely showing that a legal rule was violated.
The CJEU identifies the need for:
unlawful processing + damage + causal link.
For algorithmic economic-crisis litigation this means:
AI error alone is not enough.
The claimant must connect the error to legally recoverable damage.
38. W and Others and Scientific/Technical Evidence
Algorithmic causation may depend heavily upon experts.
For example:
“Would the crisis have happened if the algorithm had behaved correctly?”
That is essentially a counterfactual causation question.
The reasoning in W and Others is useful because the CJEU recognised that courts can assess complex causation using a body of serious, specific and consistent evidence, subject to the Product Liability Directive's burden-of-proof framework. (curia)
39. Boston Scientific and Systemic Defect
The importance of Boston Scientific goes beyond medical devices.
It demonstrates a broader product-liability idea:
Where a group of products shares a potential safety defect, liability may be considered at the level of the product group rather than requiring proof that every individual product has independently manifested the same defect.
For AI:
COMMON MODEL DEFECT → COMMON SYSTEMIC RISK
may become legally significant.
Again, this is an analogy—not a ruling on AI.
40. Economic Crisis and Foreseeability
Foreseeability becomes especially important.
Suppose a developer knows:
“If this algorithm incorrectly classifies liquidity risk, banks using it may simultaneously sell assets.”
The resulting systemic risk may be more foreseeable than if:
“An unforeseeable interaction between unrelated systems caused the crash.”
Therefore, courts may examine:
known risks;
warnings;
stress tests;
simulation results;
incident reports;
industry standards;
regulatory requirements.
41. Force Majeure and Autonomous Behaviour
A defendant might argue:
“The AI acted autonomously.”
Autonomy alone should not automatically eliminate responsibility.
The Commission's earlier AI-liability work specifically identified the difficulty created when operators argue that autonomous operation was outside their control. It also emphasised accountability for persons who create, maintain, control or interfere with AI systems. (EUR-Lex)
That material is policy/legislative history rather than binding case law, but it explains the legal reasoning behind modern AI-liability debates.
42. AI Autonomy Is Not a Separate Legal Person
An AI system generally does not become a civil-law defendant merely because it makes autonomous decisions.
The practical liability chain remains:
AI SYSTEM → HUMAN/LEGAL PERSON → LEGAL DUTY → LIABILITY
Potentially responsible entities are therefore normally:
company;
developer;
operator;
producer;
service provider;
financial institution.
43. Economic Crisis and Remoteness
A claimant may say:
Algorithm → bank failure → unemployment → house sale → personal bankruptcy.
A court may ask whether every downstream loss is sufficiently connected to the defendant's conduct.
The longer the causal chain becomes, the more difficult remoteness becomes.
Thus:
DIRECT LOSS is generally easier to analyse than REMOTE MACROECONOMIC LOSS.
44. Territorial and Cross-Border Issues
Algorithmic systems are often multinational.
Example:
Developer — France
Cloud provider — Ireland
Bank — Germany
Customer — Italy
Market — EU-wide
Questions include:
Which country's tort law applies?
Which court has jurisdiction?
Where did the damage occur?
Where did the harmful event occur?
Which contractual law governs?
Is the claim governed by EU harmonised law or national law?
For large-scale economic crises, private international law can therefore become almost as important as substantive liability.
45. Civil Liability Matrix
| Problem | Potential legal route |
|---|---|
| Defective AI software | Product Liability Directive |
| Negligent AI deployment | National tort/delict |
| Contractual AI failure | Contract law |
| Personal-data violation | GDPR |
| Automated credit decision | GDPR Article 22 |
| Defective financial algorithm | Financial/sectoral regulation + civil law |
| Discriminatory algorithm | Equality law + GDPR + national law |
| Unsafe AI product | Product liability |
| Incorrect AI update | Product liability / contract / tort |
| Systemic market harm | Financial regulation + national civil law |
| Multiple victims | Collective/representative procedures |
46. Eight Cases — Revision Table
| Case | Court | Main principle | Relevance |
|---|---|---|---|
| SCHUFA, C-634/21 | CJEU | Automated scoring can trigger Article 22 GDPR | Direct |
| Dun & Bradstreet, C-203/22 | CJEU | Meaningful explanation of automated credit assessment | Direct |
| Österreichische Post, C-300/21 | CJEU | Damage + infringement + causation required for GDPR compensation | Direct |
| Google Spain, C-131/12 | CJEU | Responsibility of data-processing operators | Analogical |
| Boston Scientific, C-503/13 & C-504/13 | CJEU | Systemic product-defect risk | Analogical |
| W and Others, C-621/15 | CJEU | Complex proof of defect and causation | Analogical |
| O'Byrne, C-127/04 | CJEU | Producer/putting-into-circulation principles | Analogical |
| Agentsia po vpisvaniyata, C-200/23 | CJEU | GDPR compensation framework and causation | Supporting |
The first three are the strongest algorithmic/data authorities; the product-liability cases are useful because the revised Product Liability Directive now expressly covers software and AI. (Infocuria)
47. Important Legal Distinction
Do not write:
“The AI Act creates automatic liability whenever AI causes an economic crisis.”
That would be inaccurate.
A better statement is:
The AI Act establishes preventive obligations whose violation may be relevant to other liability regimes, while the revised Product Liability Directive provides a no-fault route for defective products including software and AI systems, and national civil law remains important for other forms of economic loss.
The Commission's own AI-liability analysis distinguishes the preventive AI framework from compensation mechanisms. (European Commission)
48. Present European Position in 2026
The current picture can be simplified as:
Before deployment
AI Act → risk prevention and compliance
If software/product is defective
Product Liability Directive → potentially no-fault compensation
If personal data are unlawfully processed
GDPR → rights and compensation
If negligence/breach of duty occurs
National tort/delict law → fault-based liability
If contract is breached
National contract law → contractual remedies
If financial markets are affected
Financial regulation + national civil liability
If millions are affected
Collective/representative mechanisms + ordinary liability principles
49. Special Problem: “Economic Crisis” Is Not Itself a Cause of Action
An economic crisis is a consequence, not necessarily an independent civil wrong.
For example:
“The algorithm caused an economic crisis”
does not itself establish liability.
The claimant needs to identify:
WHAT WAS WRONG?
defective design?
negligence?
unlawful data processing?
contractual breach?
regulatory violation?
market manipulation?
Then:
WHO DID IT?
Then:
WHAT DAMAGE OCCURRED?
Then:
DID THAT CONDUCT CAUSE THE DAMAGE?
50. Exam Formula
Remember:
ALGORITHM → DUTY → BREACH/DEFECT → CAUSATION → ECONOMIC DAMAGE → RESPONSIBLE ACTOR → REMEDY
For systemic crises:
COMMON ALGORITHM → COMMON ERROR → CORRELATED DECISIONS → CASCADING EFFECT → MARKET DAMAGE → CAUSATION → MULTIPLE LIABILITY
For AI-specific analysis:
AI ACT → PRODUCT LIABILITY → GDPR → CONTRACT → TORT → FINANCIAL LAW → CIVIL REMEDY
51. Conclusion
Algorithmic economic-crisis liability in Europe is an emerging and fragmented area of civil law. There is currently no single EU rule under which the creator of an algorithm automatically becomes liable for every macroeconomic consequence of that algorithm.
The strongest direct authorities are SCHUFA (C-634/21) and Dun & Bradstreet (C-203/22), which demonstrate the legal importance of automated scoring, significant automated decisions and meaningful explanations. (Infocuria)
Österreichische Post (C-300/21) supplies the important compensation principle that unlawful data processing must be connected to actual legally relevant damage through causation. (Infocuria)
For defective AI, the revised Product Liability Directive 2024/2853 is especially significant because it expressly brings software and AI systems within the concept of products for no-fault liability. (EUR-Lex)
At the same time, the proposed AI Liability Directive should not be treated as current law: the Commission withdrew it on 6 October 2025. (EUR-Lex)
Therefore, the best overall civil-law framework is:
AI SYSTEM → REGULATORY DUTY/PRODUCT DUTY → DEFECT OR FAULT → CAUSATION → ECONOMIC LOSS → RESPONSIBLE ACTOR → COMPENSATION
Ultra-basic keywords
Algorithmic Crisis – Systemic Risk – AI Act – AI Liability – Product Liability – Software as Product – Defect – Fault – Black Box – Causation – Pure Economic Loss – Market Loss – Financial Regulation – GDPR – Automated Decision – SCHUFA – Dun & Bradstreet – Österreichische Post – Boston Scientific – W and Others – O'Byrne – Collective Harm – Compensation.

comments