Civil Law And Artificial General Intelligence Civil Risk Assessment In Europe .
Civil Law and Artificial General Intelligence Civil Risk Assessment in Europe
1. Introduction
Artificial General Intelligence (AGI) civil risk assessment concerns the legal analysis of civil liability risks created when highly capable AI systems can perform a broad range of cognitive tasks, potentially across multiple sectors and with substantial autonomy.
As of 2026, European law does not yet contain a settled, AGI-specific civil-liability doctrine. Consequently, an AGI-related civil claim would generally have to be analysed through existing doctrines concerning:
defective products;
professional negligence;
contractual liability;
tort/delict;
causation;
vicarious or organisational responsibility;
privacy and data protection;
fundamental rights;
consumer protection;
product safety;
medical and professional liability.
The EU AI Act (Regulation (EU) 2024/1689) provides a major regulatory framework for AI, but it should not be confused with a comprehensive civil-liability code. The EU has also developed separate product-liability legislation relevant to software and AI.
2. What Is AGI?
There is no universally accepted legal definition of AGI.
In technological discussions, AGI generally refers to an AI system capable of performing a broad range of cognitive tasks rather than being restricted to one narrowly defined function.
Potential characteristics could include:
general reasoning;
learning across domains;
autonomous planning;
adaptation;
multimodal interaction;
tool use;
long-horizon decision-making;
generation of software;
interaction with physical systems.
For civil law, however, the label "AGI" is less important than the concrete risk-producing activity.
For example:
AGI makes an incorrect medical recommendation → patient suffers injury.
The legal questions become:
Who supplied the system? Who deployed it? Who relied upon it? Was it defective? Was there a duty to supervise it? Was the harm foreseeable?
3. Why AGI Creates Special Civil-Law Problems
Traditional civil liability normally assumes that a human or corporate actor can be connected to the harmful act.
AGI potentially complicates this chain:
Developer → Model → Autonomous system → Decision → Human/physical action → Harm
The system may:
generate unexpected outputs;
adapt after deployment;
interact with external tools;
make decisions not specifically programmed by a human;
operate across jurisdictions;
produce different outputs for similar inputs.
Therefore, conventional negligence analysis may face difficult questions concerning:
foreseeability;
control;
causation;
defect;
explainability;
allocation of responsibility.
4. European Legal Framework
Several legal instruments are particularly relevant.
A. EU AI Act
Regulation (EU) 2024/1689 establishes harmonised rules for artificial intelligence.
It uses a risk-based regulatory structure, including:
prohibited AI practices;
high-risk AI;
transparency obligations;
obligations concerning general-purpose AI;
governance and enforcement mechanisms.
It is primarily a regulatory instrument, rather than a comprehensive private damages regime.
5. General-Purpose AI
The AI Act contains specific provisions concerning general-purpose AI (GPAI).
This is particularly relevant to AGI-like systems because an advanced general-purpose model may be integrated into many downstream applications.
The legal chain may therefore involve:
GPAI provider → downstream AI provider → deployer → end user → injured person
Determining which participant is legally responsible becomes important.
6. Revised EU Product Liability Framework
The EU has adopted a new Product Liability Directive (EU) 2024/2853, replacing the earlier 1985 framework.
The modern framework expressly accommodates technological products, including software and AI-related products.
This is highly significant because an AI system can potentially produce civil liability as a defective product rather than merely through traditional negligence.
The central question becomes:
Was the AI-enabled product defective, and did that defect cause compensable damage?
7. Contractual Liability
If AGI is supplied through a contract, ordinary contractual principles may become central.
Examples:
AI enterprise service;
autonomous legal-research system;
AI medical system;
AI financial platform;
AI-controlled manufacturing system.
The contract may specify:
performance requirements;
accuracy standards;
safety obligations;
human oversight;
service availability;
limitations of liability;
audit requirements.
A failure to meet contractual obligations may constitute breach.
8. Tort/Delict Liability
Where there is no direct contractual relationship, the claimant may rely on tort/delict.
Potential examples:
autonomous vehicle injures pedestrian;
AI-controlled machine injures worker;
AI system causes property damage;
AI-generated misinformation causes economic harm;
AI decision unlawfully causes discrimination;
autonomous system improperly accesses or discloses personal information.
The exact legal test differs among European jurisdictions.
9. Defective AI
An AI system may potentially be considered defective because of:
Design defect
The system was inadequately designed.
Manufacturing/deployment defect
The particular deployment differs from the safe design.
Information defect
Users were not adequately warned about foreseeable risks.
Cybersecurity defect
The system lacked reasonably expected security protections.
Updating defect
The provider failed to issue necessary updates.
Monitoring defect
The system was deployed without adequate safeguards.
10. Foreseeability
Foreseeability is particularly difficult with AGI.
Traditional question:
Could a reasonable professional have anticipated the harmful consequence?
For highly autonomous systems, courts may ask:
Was the risk known?
Was it technically foreseeable?
Were similar failures documented?
Did the provider conduct adequate testing?
Did the deployer ignore warnings?
Was the system placed in an environment outside its intended purpose?
The answer may depend heavily upon expert evidence.
11. Human Oversight
Human oversight can become an important factor.
Suppose:
An AGI system recommends an unsafe engineering design.
If a qualified engineer was required to review every output, the court may examine whether:
the engineer actually reviewed it;
review was meaningful;
the system was designed to permit effective review;
warnings were visible;
the engineer could reasonably identify the error.
Human oversight therefore does not automatically eliminate AI-related liability.
12. Causation
AGI disputes may involve several causal actors.
For example:
Developer error → AI output → company's deployment → employee reliance → injury
The court must determine which event legally caused the injury.
Possible causal questions include:
Would the harm have occurred without the AI?
Did the user independently make the harmful decision?
Did another system contribute?
Did the claimant misuse the system?
Was the AI output merely one factor among several?
13. Case Law
Because AGI-specific European case law remains limited, the most useful authorities are cases concerning AI decision-making, automated processing, digital systems, algorithmic responsibility, product liability and technological causation.
Case 1 — SCHUFA Holding AG — C-634/21
Court
Court of Justice of the European Union.
Issue
Automated credit scoring and Article 22 GDPR.
Principle
The CJEU examined circumstances in which an individual's credit score was generated through automated processing and used by third parties to make decisions affecting that individual.
The Court interpreted Article 22 GDPR as providing strong protection against certain decisions based solely on automated processing that produce legal or similarly significant effects.
Importance for AGI
The case demonstrates that highly automated decision systems are not legally neutral simply because a human organisation ultimately acts on the output.
It is relevant to future AGI systems performing:
credit assessment;
employment assessment;
insurance decisions;
access to services.
14. Case 2 — Dun & Bradstreet Austria — C-203/22
Issue
Automated decision-making and access to information concerning the logic involved.
Principle
The CJEU examined the relationship between automated decision-making and the individual's right to obtain meaningful information concerning the logic involved in automated processing.
The judgment is important for the transparency and explainability of algorithmic decision systems.
AGI relevance
Where an AGI system makes a consequential recommendation, litigation may involve questions such as:
What information was used?
What reasoning process was involved?
Can the system's output be reconstructed?
Was the decision explainable?
What records should have been preserved?
15. Case 3 — SCHUFA Holding AG — C-26/22 and C-64/22
Issue
Credit information, data processing and automated assessment.
Principle
The CJEU examined the legal significance of credit information systems and automated processing under the GDPR.
AGI relevance
AGI systems may combine enormous quantities of information to generate predictions about individuals.
This creates potential civil claims concerning:
inaccurate data;
unlawful processing;
discriminatory outcomes;
automated profiling;
consequential decisions.
The case demonstrates the importance of controlling the underlying data used by automated systems.
16. Case 4 — Google Spain v AEPD and Mario Costeja González
Case C-131/12
Issue
Search-engine processing of personal information.
Principle
The CJEU recognised important rights concerning the processing and presentation of personal information by search engines.
Importance for AGI
Although the case predates modern generative AI, it demonstrates a fundamental European principle:
Technological intermediaries can have legally significant responsibilities concerning information they process and present.
This becomes relevant when AGI systems:
retrieve personal information;
generate profiles;
reproduce personal data;
combine disparate data sources.
17. Case 5 — Wirtschaftsakademie Schleswig-Holstein — C-210/16
Issue
Responsibility for processing personal data through a digital platform.
Principle
The CJEU adopted a broad approach to joint responsibility for data processing activities.
The case involved Facebook fan pages and the role of the page administrator in relation to processing carried out through the platform.
AGI relevance
An AGI ecosystem may involve:
Model provider + application provider + deployer + user
Responsibility may therefore not necessarily rest exclusively with the company that created the underlying model.
18. Case 6 — Fashion ID — C-40/17
Issue
Joint responsibility for data processing.
Principle
The CJEU considered circumstances in which an entity embedding a Facebook "Like" plug-in could become a controller for certain stages of processing.
The case demonstrates that responsibility can attach to an actor that integrates technology into its own service, even when it did not create the underlying technology.
AGI relevance
This is potentially important for:
AI-integrated websites;
enterprise AI;
autonomous agents;
AI plugins;
third-party AI APIs.
19. Case 7 — Product Liability: Boston Scientific Medizintechnik
Joined Cases C-503/13 and C-504/13
Issue
Defective medical products.
Principle
The CJEU interpreted the EU Product Liability Directive and considered when a product may be regarded as defective where products belonging to the same series have an increased risk of failure.
AGI relevance
The reasoning is important for AI-enabled products because a claimant may argue that a particular system belongs to a product class presenting an unacceptable safety risk.
It illustrates the distinction between:
individual failure and systemic product risk.
20. Case 8 — N.W. and Others v Sanofi Pasteur MSD
Joined Cases C-621/15
Issue
Product liability and scientific uncertainty concerning causation.
Principle
The CJEU considered how national courts may evaluate evidence where scientific evidence does not establish causation with absolute certainty.
The case addressed the evidentiary role of serious, specific and consistent evidence.
AGI relevance
This is particularly significant for autonomous AI.
Suppose:
AI system → unexpected recommendation → injury.
A claimant may have difficulty proving exactly how the system produced the harmful output.
The Sanofi jurisprudence illustrates the broader importance of evidentiary rules where direct scientific proof of causation is difficult.
21. Case 9 — Google LLC v CNIL — C-507/17
Issue
Territorial scope of obligations relating to search engines and personal data.
Principle
The CJEU examined the geographical scope of the right to delist from search results.
AGI relevance
AGI systems operate internationally.
A model may be:
developed in one country;
hosted in another;
trained using multinational data;
deployed throughout Europe;
causing harm in another jurisdiction.
Therefore, questions of territorial scope and applicable law become highly important.
22. Case 10 — SCHUFA and Algorithmic Credit Assessment
The SCHUFA line of jurisprudence is particularly relevant to AGI because it demonstrates a broader European concern:
automated systems can generate legally consequential outputs even where the final formal decision is taken by a human.
For civil-risk analysis, this creates several possible liability theories:
unlawful automated decision-making;
defective data;
inadequate transparency;
negligent deployment;
contractual breach;
discrimination;
privacy violations.
23. AGI Risk Categories
Civil-law risk can be divided into several categories.
1. Physical injury
AGI controls:
vehicles;
robots;
industrial machinery;
medical equipment.
2. Property damage
AGI incorrectly controls:
buildings;
factories;
energy systems;
infrastructure.
3. Economic loss
AGI produces:
incorrect financial decisions;
defective business advice;
erroneous forecasts;
failed transactions.
4. Privacy damage
AGI:
processes personal information;
creates profiles;
reveals confidential information.
5. Reputational harm
AGI generates false statements about individuals or businesses.
6. Intellectual-property loss
AGI improperly reproduces or transforms protected material.
7. Discrimination
Automated systems produce unequal treatment.
24. AGI and Professional Liability
An AGI system used by a professional creates a dual-liability problem.
Example:
Law firm → AGI legal research → incorrect legal advice → client financial loss
Potential defendants include:
AI provider;
law firm;
individual professional;
software integrator.
The court must determine:
Who owed the relevant professional duty?
The mere fact that an AI system generated the error does not necessarily answer that question.
25. AGI in Medicine
Medical applications present particularly significant civil-risk issues.
Possible scenarios:
incorrect diagnosis;
incorrect treatment recommendation;
medication error;
failure to identify symptoms;
inappropriate triage;
autonomous clinical decision.
Potential liability could involve:
AI developer + hospital + doctor + medical-device manufacturer
The applicable law may include:
medical negligence;
product liability;
professional liability;
informed-consent rules;
data protection.
26. AGI and Autonomous Vehicles
Consider:
AGI-controlled vehicle incorrectly identifies a pedestrian and causes injury.
Potential legal questions:
Was the software defective?
Was the vehicle defective?
Was the deployment unsafe?
Was the owner negligent?
Was the manufacturer responsible?
Did the pedestrian's conduct contribute?
Was the system updated?
Were warnings ignored?
The new EU product-liability framework is particularly relevant to such technology-driven products.
27. AGI and Contractual Liability
Contracts should increasingly address:
permitted uses;
prohibited uses;
human supervision;
accuracy expectations;
cybersecurity;
model updates;
logging;
incident reporting;
liability allocation;
indemnification;
audit rights.
A poorly drafted AI contract can create uncertainty over whether an output constitutes:
a service failure;
a product defect;
professional negligence;
user misuse.
28. Defective Software and Updates
One important modern issue is post-sale software updating.
Suppose:
AI system is safe at deployment → model update changes behaviour → harmful output occurs.
The civil-law questions include:
Who supplied the update?
Was updating contractually required?
Was the update reasonably foreseeable?
Did the provider know of the risk?
Did the deployer fail to install a necessary update?
Modern European product-liability law increasingly recognises that software and continuing digital functionality can be relevant to product safety.
29. Cybersecurity Risk
AGI may be compromised through:
prompt injection;
malicious tool calls;
model manipulation;
data poisoning;
unauthorized access;
compromised APIs.
If the system subsequently causes physical or economic damage, liability may depend upon whether reasonable cybersecurity precautions were implemented.
30. Autonomous Agents
An AGI system functioning as an autonomous agent presents additional risk.
For example:
AI agent receives a general instruction → independently contracts with suppliers → transfers funds → causes financial loss.
The civil-law questions include:
Did the agent have authority?
Was the transaction authorised?
Who is the principal?
Is the AI merely a tool?
Was the third party entitled to rely on the agent's actions?
Traditional agency and contract principles may need to be adapted to these circumstances.
31. Evidence and Explainability
AGI litigation may require preservation of:
prompts;
system instructions;
model version;
logs;
tool calls;
retrieved information;
output;
human approvals;
safety filters;
model updates.
Without such evidence, proving causation may become difficult.
Therefore, auditability becomes a major component of civil-risk management.
32. Standard of Care
The standard of care may evolve with technology.
A court could consider:
industry practice;
known AI risks;
technical standards;
regulatory guidance;
available testing methods;
professional guidelines;
incident history.
However, courts would still need to apply the applicable national legal standard rather than automatically treating every unexpected AI output as negligence.
33. Human-in-the-Loop Defence
A defendant may argue:
"The AI only provided a recommendation; a human made the final decision."
This may be relevant but is not automatically decisive.
The court could examine whether the human:
had adequate expertise;
had sufficient time;
received warnings;
could understand the recommendation;
genuinely reviewed it;
was trained to challenge the AI.
A nominal human approval process may not necessarily eliminate liability.
34. AI Provider vs Deployer
A useful allocation model is:
Developer
Responsible potentially for:
fundamental design;
model defects;
training problems;
safety architecture.
Provider
Responsible potentially for:
deployment;
documentation;
updates;
cybersecurity;
warnings.
Deployer
Responsible potentially for:
inappropriate use;
inadequate supervision;
ignoring warnings;
using the system outside its intended purpose.
User
May be responsible where:
misuse;
deliberate circumvention;
unauthorized use;
failure to follow instructions
causes the harm.
35. Causation Model
AGI civil liability can be analysed using:
System defect
↓
AI behaviour
↓
Human/automated action
↓
Harm
↓
Economic/physical/legal loss
↓
Causal attribution
↓
Liability
The court must avoid treating the AI system as an independent legal person merely because it acted autonomously.
36. Can AGI Be Personally Liable?
Under current European civil law, an AI system does not generally possess the legal personality of a natural person or corporation simply because it is autonomous.
Therefore, liability normally has to be allocated to relevant human or legal persons, such as:
developer;
provider;
manufacturer;
deployer;
owner;
employer;
professional user.
The legal issue is consequently allocation of responsibility, rather than treating the AI itself as a conventional civil defendant.
37. Damages
Potential compensation may include:
Physical injury
medical expenses;
rehabilitation;
loss of earnings;
disability-related losses.
Property damage
repair;
replacement;
diminution in value.
Economic loss
lost profits;
transaction losses;
additional costs.
Data-related harm
Depending on applicable law:
material damage;
non-material damage.
38. Risk-Assessment Framework
For an AGI deployment, civil-law risk assessment should consider:
| Risk | Question |
|---|---|
| Design | Was the system appropriately designed? |
| Data | Were training/input data lawful and reliable? |
| Testing | Was the system adequately tested? |
| Deployment | Was it used for an appropriate purpose? |
| Oversight | Was meaningful human supervision provided? |
| Transparency | Were relevant warnings supplied? |
| Security | Was cybersecurity adequate? |
| Updating | Were necessary updates implemented? |
| Causation | Can the harmful output be connected to the loss? |
| Documentation | Are logs and records preserved? |
| Contract | Are liability responsibilities clearly allocated? |
| Insurance | Is the relevant risk insured? |
39. Key Case-Law Principles
| Case | Main relevance to AGI civil-risk assessment |
|---|---|
| C-634/21, SCHUFA | Automated decision-making and significant effects |
| C-203/22, Dun & Bradstreet Austria | Transparency surrounding automated decision logic |
| C-26/22 & C-64/22, SCHUFA | Automated processing and credit information |
| C-131/12, Google Spain | Responsibility of digital information intermediaries |
| C-210/16, Wirtschaftsakademie | Shared responsibility in digital processing |
| C-40/17, Fashion ID | Responsibility of technology integrators |
| C-503/13 & C-504/13, Boston Scientific | Defect and systemic product risk |
| C-621/15, Sanofi Pasteur | Causation and evidentiary difficulties |
| C-507/17, Google v CNIL | Territorial scope of digital obligations |
40. Major Civil-Law Issues for Future AGI Litigation
The most important future questions are likely to include:
1. Autonomous conduct
How should responsibility be allocated when the harmful action was not specifically programmed?
2. Emergent behaviour
Who bears responsibility for behaviour that was difficult to predict before deployment?
3. Model updates
Can a later modification create a new product defect?
4. Multi-provider ecosystems
How should liability be divided between foundation-model developers and downstream deployers?
5. Evidence
Who must preserve model logs and internal reasoning records?
6. Causation
How can a claimant prove that an opaque model caused the harm?
7. Economic loss
Should pure economic losses caused by incorrect autonomous decisions be recoverable?
8. Insurance
How should extremely large and uncertain AI risks be insured?
9. Cross-border claims
Which country's law applies when development, deployment and injury occur in different states?
10. Contractual allocation
To what extent can sophisticated commercial parties contractually allocate AGI risks?
41. Conclusion
European civil law currently approaches AGI civil risk through existing legal concepts rather than through a single AGI-specific liability doctrine.
The most important legal pathways are:
Contract → Tort/Delict → Product Liability → Professional Liability → Data Protection → Consumer Protection → Construction/Medical/Automotive Liability, depending on the application.
The emerging case law does not establish that an autonomous AI system itself becomes a civilly liable legal person. Instead, cases such as SCHUFA, Dun & Bradstreet Austria, Google Spain, Wirtschaftsakademie and Fashion ID demonstrate how European courts are already addressing responsibility, transparency and accountability in increasingly automated technological environments.
For physical-product risks, Boston Scientific and Sanofi Pasteur are particularly useful analogies because they demonstrate how European product-liability law approaches defect, systemic risk, scientific uncertainty and causation.
The central civil-law framework can therefore be summarised as:
AGI capability → foreseeable risk → duty of care → system design/deployment → human oversight → harmful output → causation → legally recognised damage → allocation of liability.
Exam-ready keywords
AGI — artificial general intelligence — civil liability — contractual liability — tort/delict — product liability — AI Act — GPAI — Product Liability Directive — automated decision-making — Article 22 GDPR — explainability — human oversight — defect — foreseeability — causation — autonomous systems — AI agents — cybersecurity — model updates — professional negligence — economic loss — physical harm — evidence — audit logs — developer liability — deployer liability — joint responsibility — damages.

comments