Civil Law And Artificial General Intelligence Civil Risk Assessment In Europe .

Civil Law and Artificial General Intelligence Civil Risk Assessment in Europe

1. Introduction

Artificial General Intelligence (AGI) civil risk assessment concerns the legal analysis of civil liability risks created when highly capable AI systems can perform a broad range of cognitive tasks, potentially across multiple sectors and with substantial autonomy.

As of 2026, European law does not yet contain a settled, AGI-specific civil-liability doctrine. Consequently, an AGI-related civil claim would generally have to be analysed through existing doctrines concerning:

defective products;

professional negligence;

contractual liability;

tort/delict;

causation;

vicarious or organisational responsibility;

privacy and data protection;

fundamental rights;

consumer protection;

product safety;

medical and professional liability.

The EU AI Act (Regulation (EU) 2024/1689) provides a major regulatory framework for AI, but it should not be confused with a comprehensive civil-liability code. The EU has also developed separate product-liability legislation relevant to software and AI.

2. What Is AGI?

There is no universally accepted legal definition of AGI.

In technological discussions, AGI generally refers to an AI system capable of performing a broad range of cognitive tasks rather than being restricted to one narrowly defined function.

Potential characteristics could include:

general reasoning;

learning across domains;

autonomous planning;

adaptation;

multimodal interaction;

tool use;

long-horizon decision-making;

generation of software;

interaction with physical systems.

For civil law, however, the label "AGI" is less important than the concrete risk-producing activity.

For example:

AGI makes an incorrect medical recommendation → patient suffers injury.

The legal questions become:

Who supplied the system? Who deployed it? Who relied upon it? Was it defective? Was there a duty to supervise it? Was the harm foreseeable?

3. Why AGI Creates Special Civil-Law Problems

Traditional civil liability normally assumes that a human or corporate actor can be connected to the harmful act.

AGI potentially complicates this chain:

Developer → Model → Autonomous system → Decision → Human/physical action → Harm

The system may:

generate unexpected outputs;

adapt after deployment;

interact with external tools;

make decisions not specifically programmed by a human;

operate across jurisdictions;

produce different outputs for similar inputs.

Therefore, conventional negligence analysis may face difficult questions concerning:

foreseeability;

control;

causation;

defect;

explainability;

allocation of responsibility.

4. European Legal Framework

Several legal instruments are particularly relevant.

A. EU AI Act

Regulation (EU) 2024/1689 establishes harmonised rules for artificial intelligence.

It uses a risk-based regulatory structure, including:

prohibited AI practices;

high-risk AI;

transparency obligations;

obligations concerning general-purpose AI;

governance and enforcement mechanisms.

It is primarily a regulatory instrument, rather than a comprehensive private damages regime.

5. General-Purpose AI

The AI Act contains specific provisions concerning general-purpose AI (GPAI).

This is particularly relevant to AGI-like systems because an advanced general-purpose model may be integrated into many downstream applications.

The legal chain may therefore involve:

GPAI provider → downstream AI provider → deployer → end user → injured person

Determining which participant is legally responsible becomes important.

6. Revised EU Product Liability Framework

The EU has adopted a new Product Liability Directive (EU) 2024/2853, replacing the earlier 1985 framework.

The modern framework expressly accommodates technological products, including software and AI-related products.

This is highly significant because an AI system can potentially produce civil liability as a defective product rather than merely through traditional negligence.

The central question becomes:

Was the AI-enabled product defective, and did that defect cause compensable damage?

7. Contractual Liability

If AGI is supplied through a contract, ordinary contractual principles may become central.

Examples:

AI enterprise service;

autonomous legal-research system;

AI medical system;

AI financial platform;

AI-controlled manufacturing system.

The contract may specify:

performance requirements;

accuracy standards;

safety obligations;

human oversight;

service availability;

limitations of liability;

audit requirements.

A failure to meet contractual obligations may constitute breach.

8. Tort/Delict Liability

Where there is no direct contractual relationship, the claimant may rely on tort/delict.

Potential examples:

autonomous vehicle injures pedestrian;

AI-controlled machine injures worker;

AI system causes property damage;

AI-generated misinformation causes economic harm;

AI decision unlawfully causes discrimination;

autonomous system improperly accesses or discloses personal information.

The exact legal test differs among European jurisdictions.

9. Defective AI

An AI system may potentially be considered defective because of:

Design defect

The system was inadequately designed.

Manufacturing/deployment defect

The particular deployment differs from the safe design.

Information defect

Users were not adequately warned about foreseeable risks.

Cybersecurity defect

The system lacked reasonably expected security protections.

Updating defect

The provider failed to issue necessary updates.

Monitoring defect

The system was deployed without adequate safeguards.

10. Foreseeability

Foreseeability is particularly difficult with AGI.

Traditional question:

Could a reasonable professional have anticipated the harmful consequence?

For highly autonomous systems, courts may ask:

Was the risk known?

Was it technically foreseeable?

Were similar failures documented?

Did the provider conduct adequate testing?

Did the deployer ignore warnings?

Was the system placed in an environment outside its intended purpose?

The answer may depend heavily upon expert evidence.

11. Human Oversight

Human oversight can become an important factor.

Suppose:

An AGI system recommends an unsafe engineering design.

If a qualified engineer was required to review every output, the court may examine whether:

the engineer actually reviewed it;

review was meaningful;

the system was designed to permit effective review;

warnings were visible;

the engineer could reasonably identify the error.

Human oversight therefore does not automatically eliminate AI-related liability.

12. Causation

AGI disputes may involve several causal actors.

For example:

Developer error → AI output → company's deployment → employee reliance → injury

The court must determine which event legally caused the injury.

Possible causal questions include:

Would the harm have occurred without the AI?

Did the user independently make the harmful decision?

Did another system contribute?

Did the claimant misuse the system?

Was the AI output merely one factor among several?

13. Case Law

Because AGI-specific European case law remains limited, the most useful authorities are cases concerning AI decision-making, automated processing, digital systems, algorithmic responsibility, product liability and technological causation.

Case 1 — SCHUFA Holding AG — C-634/21

Court

Court of Justice of the European Union.

Issue

Automated credit scoring and Article 22 GDPR.

Principle

The CJEU examined circumstances in which an individual's credit score was generated through automated processing and used by third parties to make decisions affecting that individual.

The Court interpreted Article 22 GDPR as providing strong protection against certain decisions based solely on automated processing that produce legal or similarly significant effects.

Importance for AGI

The case demonstrates that highly automated decision systems are not legally neutral simply because a human organisation ultimately acts on the output.

It is relevant to future AGI systems performing:

credit assessment;

employment assessment;

insurance decisions;

access to services.

14. Case 2 — Dun & Bradstreet Austria — C-203/22

Issue

Automated decision-making and access to information concerning the logic involved.

Principle

The CJEU examined the relationship between automated decision-making and the individual's right to obtain meaningful information concerning the logic involved in automated processing.

The judgment is important for the transparency and explainability of algorithmic decision systems.

AGI relevance

Where an AGI system makes a consequential recommendation, litigation may involve questions such as:

What information was used?

What reasoning process was involved?

Can the system's output be reconstructed?

Was the decision explainable?

What records should have been preserved?

15. Case 3 — SCHUFA Holding AG — C-26/22 and C-64/22

Issue

Credit information, data processing and automated assessment.

Principle

The CJEU examined the legal significance of credit information systems and automated processing under the GDPR.

AGI relevance

AGI systems may combine enormous quantities of information to generate predictions about individuals.

This creates potential civil claims concerning:

inaccurate data;

unlawful processing;

discriminatory outcomes;

automated profiling;

consequential decisions.

The case demonstrates the importance of controlling the underlying data used by automated systems.

16. Case 4 — Google Spain v AEPD and Mario Costeja González

Case C-131/12

Issue

Search-engine processing of personal information.

Principle

The CJEU recognised important rights concerning the processing and presentation of personal information by search engines.

Importance for AGI

Although the case predates modern generative AI, it demonstrates a fundamental European principle:

Technological intermediaries can have legally significant responsibilities concerning information they process and present.

This becomes relevant when AGI systems:

retrieve personal information;

generate profiles;

reproduce personal data;

combine disparate data sources.

17. Case 5 — Wirtschaftsakademie Schleswig-Holstein — C-210/16

Issue

Responsibility for processing personal data through a digital platform.

Principle

The CJEU adopted a broad approach to joint responsibility for data processing activities.

The case involved Facebook fan pages and the role of the page administrator in relation to processing carried out through the platform.

AGI relevance

An AGI ecosystem may involve:

Model provider + application provider + deployer + user

Responsibility may therefore not necessarily rest exclusively with the company that created the underlying model.

18. Case 6 — Fashion ID — C-40/17

Issue

Joint responsibility for data processing.

Principle

The CJEU considered circumstances in which an entity embedding a Facebook "Like" plug-in could become a controller for certain stages of processing.

The case demonstrates that responsibility can attach to an actor that integrates technology into its own service, even when it did not create the underlying technology.

AGI relevance

This is potentially important for:

AI-integrated websites;

enterprise AI;

autonomous agents;

AI plugins;

third-party AI APIs.

19. Case 7 — Product Liability: Boston Scientific Medizintechnik

Joined Cases C-503/13 and C-504/13

Issue

Defective medical products.

Principle

The CJEU interpreted the EU Product Liability Directive and considered when a product may be regarded as defective where products belonging to the same series have an increased risk of failure.

AGI relevance

The reasoning is important for AI-enabled products because a claimant may argue that a particular system belongs to a product class presenting an unacceptable safety risk.

It illustrates the distinction between:

individual failure and systemic product risk.

20. Case 8 — N.W. and Others v Sanofi Pasteur MSD

Joined Cases C-621/15

Issue

Product liability and scientific uncertainty concerning causation.

Principle

The CJEU considered how national courts may evaluate evidence where scientific evidence does not establish causation with absolute certainty.

The case addressed the evidentiary role of serious, specific and consistent evidence.

AGI relevance

This is particularly significant for autonomous AI.

Suppose:

AI system → unexpected recommendation → injury.

A claimant may have difficulty proving exactly how the system produced the harmful output.

The Sanofi jurisprudence illustrates the broader importance of evidentiary rules where direct scientific proof of causation is difficult.

21. Case 9 — Google LLC v CNIL — C-507/17

Issue

Territorial scope of obligations relating to search engines and personal data.

Principle

The CJEU examined the geographical scope of the right to delist from search results.

AGI relevance

AGI systems operate internationally.

A model may be:

developed in one country;

hosted in another;

trained using multinational data;

deployed throughout Europe;

causing harm in another jurisdiction.

Therefore, questions of territorial scope and applicable law become highly important.

22. Case 10 — SCHUFA and Algorithmic Credit Assessment

The SCHUFA line of jurisprudence is particularly relevant to AGI because it demonstrates a broader European concern:

automated systems can generate legally consequential outputs even where the final formal decision is taken by a human.

For civil-risk analysis, this creates several possible liability theories:

unlawful automated decision-making;

defective data;

inadequate transparency;

negligent deployment;

contractual breach;

discrimination;

privacy violations.

23. AGI Risk Categories

Civil-law risk can be divided into several categories.

1. Physical injury

AGI controls:

vehicles;

robots;

industrial machinery;

medical equipment.

2. Property damage

AGI incorrectly controls:

buildings;

factories;

energy systems;

infrastructure.

3. Economic loss

AGI produces:

incorrect financial decisions;

defective business advice;

erroneous forecasts;

failed transactions.

4. Privacy damage

AGI:

processes personal information;

creates profiles;

reveals confidential information.

5. Reputational harm

AGI generates false statements about individuals or businesses.

6. Intellectual-property loss

AGI improperly reproduces or transforms protected material.

7. Discrimination

Automated systems produce unequal treatment.

24. AGI and Professional Liability

An AGI system used by a professional creates a dual-liability problem.

Example:

Law firm → AGI legal research → incorrect legal advice → client financial loss

Potential defendants include:

AI provider;

law firm;

individual professional;

software integrator.

The court must determine:

Who owed the relevant professional duty?

The mere fact that an AI system generated the error does not necessarily answer that question.

25. AGI in Medicine

Medical applications present particularly significant civil-risk issues.

Possible scenarios:

incorrect diagnosis;

incorrect treatment recommendation;

medication error;

failure to identify symptoms;

inappropriate triage;

autonomous clinical decision.

Potential liability could involve:

AI developer + hospital + doctor + medical-device manufacturer

The applicable law may include:

medical negligence;

product liability;

professional liability;

informed-consent rules;

data protection.

26. AGI and Autonomous Vehicles

Consider:

AGI-controlled vehicle incorrectly identifies a pedestrian and causes injury.

Potential legal questions:

Was the software defective?

Was the vehicle defective?

Was the deployment unsafe?

Was the owner negligent?

Was the manufacturer responsible?

Did the pedestrian's conduct contribute?

Was the system updated?

Were warnings ignored?

The new EU product-liability framework is particularly relevant to such technology-driven products.

27. AGI and Contractual Liability

Contracts should increasingly address:

permitted uses;

prohibited uses;

human supervision;

accuracy expectations;

cybersecurity;

model updates;

logging;

incident reporting;

liability allocation;

indemnification;

audit rights.

A poorly drafted AI contract can create uncertainty over whether an output constitutes:

a service failure;

a product defect;

professional negligence;

user misuse.

28. Defective Software and Updates

One important modern issue is post-sale software updating.

Suppose:

AI system is safe at deployment → model update changes behaviour → harmful output occurs.

The civil-law questions include:

Who supplied the update?

Was updating contractually required?

Was the update reasonably foreseeable?

Did the provider know of the risk?

Did the deployer fail to install a necessary update?

Modern European product-liability law increasingly recognises that software and continuing digital functionality can be relevant to product safety.

29. Cybersecurity Risk

AGI may be compromised through:

prompt injection;

malicious tool calls;

model manipulation;

data poisoning;

unauthorized access;

compromised APIs.

If the system subsequently causes physical or economic damage, liability may depend upon whether reasonable cybersecurity precautions were implemented.

30. Autonomous Agents

An AGI system functioning as an autonomous agent presents additional risk.

For example:

AI agent receives a general instruction → independently contracts with suppliers → transfers funds → causes financial loss.

The civil-law questions include:

Did the agent have authority?

Was the transaction authorised?

Who is the principal?

Is the AI merely a tool?

Was the third party entitled to rely on the agent's actions?

Traditional agency and contract principles may need to be adapted to these circumstances.

31. Evidence and Explainability

AGI litigation may require preservation of:

prompts;

system instructions;

model version;

logs;

tool calls;

retrieved information;

output;

human approvals;

safety filters;

model updates.

Without such evidence, proving causation may become difficult.

Therefore, auditability becomes a major component of civil-risk management.

32. Standard of Care

The standard of care may evolve with technology.

A court could consider:

industry practice;

known AI risks;

technical standards;

regulatory guidance;

available testing methods;

professional guidelines;

incident history.

However, courts would still need to apply the applicable national legal standard rather than automatically treating every unexpected AI output as negligence.

33. Human-in-the-Loop Defence

A defendant may argue:

"The AI only provided a recommendation; a human made the final decision."

This may be relevant but is not automatically decisive.

The court could examine whether the human:

had adequate expertise;

had sufficient time;

received warnings;

could understand the recommendation;

genuinely reviewed it;

was trained to challenge the AI.

A nominal human approval process may not necessarily eliminate liability.

34. AI Provider vs Deployer

A useful allocation model is:

Developer

Responsible potentially for:

fundamental design;

model defects;

training problems;

safety architecture.

Provider

Responsible potentially for:

deployment;

documentation;

updates;

cybersecurity;

warnings.

Deployer

Responsible potentially for:

inappropriate use;

inadequate supervision;

ignoring warnings;

using the system outside its intended purpose.

User

May be responsible where:

misuse;

deliberate circumvention;

unauthorized use;

failure to follow instructions

causes the harm.

35. Causation Model

AGI civil liability can be analysed using:

System defect

↓

AI behaviour

↓

Human/automated action

↓

Harm

↓

Economic/physical/legal loss

↓

Causal attribution

↓

Liability

The court must avoid treating the AI system as an independent legal person merely because it acted autonomously.

36. Can AGI Be Personally Liable?

Under current European civil law, an AI system does not generally possess the legal personality of a natural person or corporation simply because it is autonomous.

Therefore, liability normally has to be allocated to relevant human or legal persons, such as:

developer;

provider;

manufacturer;

deployer;

owner;

employer;

professional user.

The legal issue is consequently allocation of responsibility, rather than treating the AI itself as a conventional civil defendant.

37. Damages

Potential compensation may include:

Physical injury

medical expenses;

rehabilitation;

loss of earnings;

disability-related losses.

Property damage

repair;

replacement;

diminution in value.

Economic loss

lost profits;

transaction losses;

additional costs.

Data-related harm

Depending on applicable law:

material damage;

non-material damage.

38. Risk-Assessment Framework

For an AGI deployment, civil-law risk assessment should consider:

RiskQuestion
DesignWas the system appropriately designed?
DataWere training/input data lawful and reliable?
TestingWas the system adequately tested?
DeploymentWas it used for an appropriate purpose?
OversightWas meaningful human supervision provided?
TransparencyWere relevant warnings supplied?
SecurityWas cybersecurity adequate?
UpdatingWere necessary updates implemented?
CausationCan the harmful output be connected to the loss?
DocumentationAre logs and records preserved?
ContractAre liability responsibilities clearly allocated?
InsuranceIs the relevant risk insured?

39. Key Case-Law Principles

CaseMain relevance to AGI civil-risk assessment
C-634/21, SCHUFAAutomated decision-making and significant effects
C-203/22, Dun & Bradstreet AustriaTransparency surrounding automated decision logic
C-26/22 & C-64/22, SCHUFAAutomated processing and credit information
C-131/12, Google SpainResponsibility of digital information intermediaries
C-210/16, WirtschaftsakademieShared responsibility in digital processing
C-40/17, Fashion IDResponsibility of technology integrators
C-503/13 & C-504/13, Boston ScientificDefect and systemic product risk
C-621/15, Sanofi PasteurCausation and evidentiary difficulties
C-507/17, Google v CNILTerritorial scope of digital obligations

40. Major Civil-Law Issues for Future AGI Litigation

The most important future questions are likely to include:

1. Autonomous conduct

How should responsibility be allocated when the harmful action was not specifically programmed?

2. Emergent behaviour

Who bears responsibility for behaviour that was difficult to predict before deployment?

3. Model updates

Can a later modification create a new product defect?

4. Multi-provider ecosystems

How should liability be divided between foundation-model developers and downstream deployers?

5. Evidence

Who must preserve model logs and internal reasoning records?

6. Causation

How can a claimant prove that an opaque model caused the harm?

7. Economic loss

Should pure economic losses caused by incorrect autonomous decisions be recoverable?

8. Insurance

How should extremely large and uncertain AI risks be insured?

9. Cross-border claims

Which country's law applies when development, deployment and injury occur in different states?

10. Contractual allocation

To what extent can sophisticated commercial parties contractually allocate AGI risks?

41. Conclusion

European civil law currently approaches AGI civil risk through existing legal concepts rather than through a single AGI-specific liability doctrine.

The most important legal pathways are:

Contract → Tort/Delict → Product Liability → Professional Liability → Data Protection → Consumer Protection → Construction/Medical/Automotive Liability, depending on the application.

The emerging case law does not establish that an autonomous AI system itself becomes a civilly liable legal person. Instead, cases such as SCHUFA, Dun & Bradstreet Austria, Google Spain, Wirtschaftsakademie and Fashion ID demonstrate how European courts are already addressing responsibility, transparency and accountability in increasingly automated technological environments.

For physical-product risks, Boston Scientific and Sanofi Pasteur are particularly useful analogies because they demonstrate how European product-liability law approaches defect, systemic risk, scientific uncertainty and causation.

The central civil-law framework can therefore be summarised as:

AGI capability → foreseeable risk → duty of care → system design/deployment → human oversight → harmful output → causation → legally recognised damage → allocation of liability.

Exam-ready keywords

AGI — artificial general intelligence — civil liability — contractual liability — tort/delict — product liability — AI Act — GPAI — Product Liability Directive — automated decision-making — Article 22 GDPR — explainability — human oversight — defect — foreseeability — causation — autonomous systems — AI agents — cybersecurity — model updates — professional negligence — economic loss — physical harm — evidence — audit logs — developer liability — deployer liability — joint responsibility — damages.

LEAVE A COMMENT