Civil Law And Artificial Intelligence Act Liability Framework In Europe .
Civil Law and Artificial Intelligence Act Liability Framework in Europe
1. Introduction
The European liability framework for artificial intelligence is not contained in one single civil-liability statute. Instead, AI-related civil liability in Europe is developing through a combination of:
EU Artificial Intelligence Act (AI Act) — Regulation (EU) 2024/1689
EU Product Liability Directive 2024/2853
GDPR and data-protection liability
National contract and tort/delict law
Consumer-protection law
Fundamental-rights law under the EU Charter and ECHR
Sector-specific rules, such as medical-device, employment, financial-services and transport regulation.
This distinction is extremely important: the AI Act primarily establishes regulatory obligations and compliance duties; it is not itself a comprehensive compensation code for every injury caused by AI. Civil compensation normally has to be founded on another legal basis, although an AI Act violation can become important evidence of unlawfulness, breach of duty, negligence or regulatory non-compliance.
The current consolidated AI Act has been amended in 2026, and its provisions apply in stages. The general application date is 2 August 2026, while some high-risk-system provisions have later application dates. (EUR-Lex)
2. Meaning of AI Act Liability Framework
The expression “AI Act liability framework” refers to the legal mechanisms used to determine:
who is responsible for an AI system;
whether the system complied with mandatory requirements;
whether a provider or deployer breached its obligations;
whether an AI system was defective;
whether an individual suffered legally compensable damage;
whether the AI system caused that damage;
whether the injured person can obtain compensation;
which party bears the evidential burden;
and whether contractual limitations can affect liability.
The central problem is that AI may involve numerous participants:
developer → provider → importer → distributor → deployer → professional user → data provider → infrastructure provider → affected person.
Consequently, identifying the legally responsible person can be more difficult than identifying the technical creator of an AI model.
3. AI Act and Civil Liability Must Be Distinguished
A major examination point is:
AI Act ≠ general civil-liability statute
The AI Act regulates the development, placing on the market, deployment and use of AI according to risk.
Civil liability asks a different question:
“Who must compensate the injured person?”
For example:
A hospital uses an AI diagnostic system. The AI makes an erroneous recommendation and a patient suffers injury.
There could be several independent legal questions:
Did the provider comply with the AI Act?
Was the hospital's deployment lawful?
Was the medical professional negligent?
Was the software defective?
Was personal data unlawfully processed?
Was there a contractual breach?
Was there a causal connection between the AI system and the injury?
Is compensation available under national tort law or the Product Liability Directive?
Thus, regulatory non-compliance and civil liability are related but not identical.
4. Main Sources of AI Civil Liability in Europe
A. Artificial Intelligence Act
The AI Act establishes a risk-based regulatory system.
Broad categories include:
prohibited AI practices;
high-risk AI systems;
transparency obligations;
obligations relating to general-purpose AI;
governance and monitoring;
human oversight;
accuracy and robustness;
cybersecurity;
record keeping;
post-market monitoring.
The Act therefore creates important standards against which conduct involving AI can be assessed. (EUR-Lex)
B. Product Liability Directive 2024/2853
This is particularly important for AI-related physical and economic harm.
The new Product Liability Directive expressly treats software and AI systems as products for product-liability purposes. It covers software whether supplied independently, through networks/cloud technology, or as software-as-a-service. (EUR-Lex)
The Directive applies to products placed on the market or put into service after 8 December 2026 following the 2026 corrigendum. (EUR-Lex)
This is a major development because traditional product liability was designed principally around physical products.
5. No-Fault Product Liability
Under the new EU product-liability framework, an injured person generally does not have to prove that the manufacturer was personally negligent.
The central elements are:
Defective product + damage + causal relationship
rather than:
Manufacturer's negligence + damage + causal relationship.
The new Directive specifically states that software, including AI systems, can constitute products for this purpose. (EUR-Lex)
Example
Suppose an autonomous medical AI system is defective because of an unsafe software design and causes physical injury.
The injured person may potentially pursue product liability without proving that an individual programmer personally acted negligently.
6. Types of AI Defects
An AI system may potentially be defective because of:
1. Design defect
The underlying architecture is unsafe.
2. Training-data defect
The training process produces systematically unsafe outputs.
3. Software defect
The program contains an error.
4. Cybersecurity defect
The system can be manipulated by foreseeable cyberattacks.
5. Update defect
An update introduces a harmful malfunction.
6. Instructions defect
Users are not adequately warned about foreseeable risks.
7. Monitoring defect
Known failures are not appropriately addressed after deployment.
The new Product Liability Directive expressly recognises the importance of software and AI-related defects. (EUR-Lex)
7. AI Act Compliance as Evidence in Civil Litigation
An important legal distinction is:
AI Act breach does not automatically equal damages.
Suppose a high-risk AI provider violates an AI Act requirement concerning:
risk management;
data governance;
logging;
human oversight;
accuracy;
cybersecurity;
post-market monitoring.
That regulatory breach may become significant evidence in subsequent civil litigation.
The court may then ask:
Was there a legal duty?
Was the duty breached?
Did the breach cause the claimant's loss?
Was the loss legally recoverable?
The precise consequences depend on applicable national civil law.
8. Liability of AI Providers
An AI provider may have responsibility concerning:
system design;
development;
training;
testing;
documentation;
conformity assessment;
monitoring;
corrective measures;
cybersecurity;
instructions for use.
For high-risk systems, the AI Act imposes substantial compliance requirements.
Civil-law significance
If an AI provider fails to comply with a mandatory safety requirement and that failure causes foreseeable injury, the claimant may attempt to use that violation in:
negligence;
statutory-duty claims;
product liability;
contractual liability;
consumer claims.
9. Liability of AI Deployers
The deployer is often the organization that actually uses the AI.
Examples:
hospital;
bank;
employer;
insurer;
government authority;
university;
retailer.
The deployer may be liable where the problem results from:
inappropriate deployment;
failure to supervise;
ignoring warnings;
use outside intended purposes;
inadequate human oversight;
inappropriate input data;
failure to investigate obviously abnormal outputs.
Therefore, an organization cannot necessarily escape liability merely by saying:
“The algorithm made the decision.”
AI does not automatically become a legal person or an independent bearer of civil responsibility.
10. Human Oversight
Human oversight is particularly important for high-risk AI.
The underlying principle is that humans must retain an appropriate ability to:
understand the system's limitations;
monitor its operation;
intervene;
override outputs;
interrupt operation where appropriate.
Civil-law significance
Failure to provide meaningful human oversight may become relevant when determining whether an organization:
breached its duty of care;
negligently relied upon an AI system;
failed to mitigate foreseeable harm.
11. AI and GDPR Liability
Many AI systems process personal data.
Therefore, an AI-related claim can simultaneously involve:
AI Act;
GDPR;
national civil law;
fundamental rights.
GDPR Article 82 provides an important compensation mechanism for unlawful processing of personal data.
The CJEU has repeatedly clarified the conditions for obtaining compensation.
12. Case Law
Case 1: SCHUFA Holding (Scoring)
C-634/21, CJEU, 7 December 2023
This is one of the most important European cases for algorithmic decision-making.
SCHUFA calculated credit scores using automated processing. The question concerned Article 22 GDPR and automated individual decision-making.
The CJEU held that scoring can constitute an automated individual decision where the recipient of the score attributes a determining role to it in making the decision. (Infocuria)
Importance for AI liability
The case establishes that an organization cannot necessarily characterize an algorithmic assessment as merely “preliminary” where it effectively determines the final decision.
Civil-law relevance
Suppose an AI credit system:
produces a score;
the bank automatically relies upon it;
the individual loses access to credit;
the algorithm contains unlawful processing or discriminatory characteristics.
The SCHUFA principles can become relevant to establishing unlawful automated decision-making.
13. Case 2: Österreichische Post — Non-Material Damage
C-300/21, CJEU, 4 May 2023
Österreichische Post used an algorithm to analyse demographic information and predict political affinities.
The claimant alleged distress and loss of confidence arising from the unlawful processing.
The CJEU held that mere infringement of the GDPR does not itself automatically create a compensation claim, but compensation for non-material damage does not require the damage to reach a particular seriousness threshold. (curia)
AI significance
This is important where AI produces:
profiling;
inferred characteristics;
behavioural predictions;
personality classifications;
political-affinity predictions.
Principle
The claimant still needs:
GDPR infringement + actual damage + causal connection.
14. Case 3: Natsionalna agentsia za prihodite
C-340/21, CJEU, 14 December 2023
The Bulgarian National Revenue Agency suffered a major cyberattack involving personal information.
The case concerned:
security of processing;
controller responsibility;
technical and organizational measures;
liability;
non-material damage;
fear of possible misuse.
The CJEU examined whether a controller could escape liability merely because a third party unlawfully accessed the information. (Infocuria)
AI significance
AI systems increasingly depend upon enormous databases and cloud infrastructure.
A cybersecurity failure involving an AI database can therefore generate:
GDPR liability;
contractual claims;
tort claims;
regulatory penalties;
potentially product-liability questions.
The case demonstrates that organizations must consider cybersecurity as part of legal responsibility.
15. Case 4: Österreichische Post — Right of Access
C-154/21, CJEU, 12 January 2023
The claimant sought information about recipients to whom his personal data had been disclosed.
The CJEU held that where personal data have been or will be disclosed, the controller generally must provide information identifying the actual recipients where they can be identified, rather than merely providing categories of recipients. (Infocuria)
AI significance
This becomes particularly relevant to complex AI ecosystems involving:
AI developers;
cloud providers;
data brokers;
model providers;
analytics companies;
downstream users.
It reinforces the importance of knowing who receives or processes the data used by AI systems.
16. Case 5: Boston Scientific Medizintechnik
Joined Cases C-503/13 and C-504/13, CJEU, 5 March 2015
Although the case concerned medical devices rather than AI, it is highly relevant to modern AI product liability.
The CJEU held that where products belonging to the same group or production series present a potential defect, an individual product may be treated as defective even without proving that the particular item had already malfunctioned. (Infocuria)
AI analogy
Consider an AI-controlled medical device where a software architecture is discovered to create a serious safety risk.
The case demonstrates an important product-liability concept:
Safety expectations can concern systemic risks, not merely a proven malfunction in the individual product.
This is particularly significant for AI systems whose risks may emerge across a model or software version.
17. Case 6: Glukhin v Russia
ECtHR, Application No. 11519/20, 4 July 2023
This case concerned the use of facial-recognition technology to identify a person following a solo protest.
The European Court of Human Rights found a violation of Article 8 concerning private life. The Court's materials identify the technology as highly intrusive facial-recognition processing. (ECHR-KS)
AI significance
The case demonstrates that AI liability cannot be understood purely through economic loss.
AI can affect:
privacy;
personal autonomy;
freedom of expression;
dignity;
personal data.
Therefore, AI-related civil claims may intersect with fundamental-rights protections.
18. Case 7: Gemeinde Ummendorf
C-456/22, CJEU
The case concerned unlawful publication of personal information and compensation under GDPR Article 82.
The CJEU emphasized the distinction between:
mere GDPR infringement; and
actual non-material damage.
The jurisprudence confirms that compensation requires the relevant elements of liability, including damage and causation, rather than automatically following from every regulatory infringement. (Curia)
AI relevance
This is useful where an AI system unlawfully exposes or processes personal data but the claimant must still establish compensable harm.
19. Case 8: Google Spain
Google Spain SL and Google Inc. v AEPD and Mario Costeja González
C-131/12, CJEU, 13 May 2014
The CJEU recognised important rights concerning the removal of certain search-engine results involving personal information.
Although this case predates modern generative AI, its principles are highly relevant to:
AI search engines;
retrieval-augmented systems;
AI profiling;
personal-data indexing;
automated dissemination of information.
The case demonstrates that technological intermediaries can have legal responsibilities concerning personal information rather than being treated as completely neutral technical instruments.
20. Contractual AI Liability
AI-related disputes can also arise through ordinary contract law.
Examples include:
AI developer → customer
The AI fails to perform according to contractual specifications.
Cloud provider → AI company
The infrastructure becomes unavailable.
AI company → business customer
The system produces materially inaccurate results.
AI vendor → hospital
The system fails to satisfy agreed safety or performance specifications.
Potential claims include:
breach of contract;
warranty;
indemnification;
service-level agreement violations;
limitation-of-liability disputes;
misrepresentation;
termination;
damages.
Therefore, the AI Act does not eliminate ordinary contract law.
21. Tort / Delict Liability
National European tort systems may impose liability where AI-related conduct causes:
bodily injury;
property damage;
privacy harm;
reputational harm;
economic loss;
discrimination;
infringement of personality rights.
The applicable test differs among Member States.
Typical questions are:
Was there a legally recognized duty?
Was the defendant's conduct unlawful?
Was there fault, where required?
Was the harm foreseeable?
Did the AI system cause the damage?
Was the claimant's loss legally recoverable?
22. Causation Is One of the Most Difficult AI Issues
AI systems frequently involve multiple causal stages.
For example:
training data → model → recommendation → human decision → harm
The claimant must potentially establish where the legally relevant failure occurred.
Example
An AI medical system recommends against surgery.
The doctor accepts the recommendation.
The patient suffers injury.
Possible defendants could include:
AI developer;
hospital;
doctor;
software integrator.
But the claimant must still establish the relevant causal connection.
23. The “Black Box” Problem
A major civil-law problem is:
How can a claimant prove negligence or defect when the AI system is technically difficult to understand?
Traditional litigation assumes that evidence can reveal:
what happened;
why it happened;
who controlled the process.
AI can complicate all three.
This creates potential asymmetry:
Claimant
May have only the harmful output.
Provider
May possess:
training information;
logs;
testing records;
model documentation;
technical specifications;
incident reports.
The AI Act's documentation, logging and monitoring requirements can therefore have indirect importance in litigation.
24. Evidence and Disclosure
AI disputes may require evidence concerning:
training data;
model versions;
prompts;
system logs;
output histories;
human interventions;
safety testing;
risk assessments;
technical documentation;
cybersecurity records;
update history.
The newer European product-liability framework is designed to address some evidential difficulties associated with complex digital products.
This is important because modern AI liability is often as much an evidence problem as a substantive-law problem.
25. AI Discrimination Liability
AI systems may produce discriminatory results in:
recruitment;
lending;
insurance;
housing;
education;
public services.
Potential legal sources include:
AI Act;
GDPR;
EU equality directives;
national anti-discrimination law;
employment law;
tort law;
fundamental-rights law.
Example
An AI recruitment tool systematically downgrades applicants belonging to a protected category.
Potential claims could concern:
discriminatory outcome;
unlawful processing;
inadequate testing;
lack of human oversight;
defective system;
employer liability.
26. AI Employment Liability
Suppose an employer uses AI to determine:
recruitment;
promotion;
dismissal;
salary;
employee performance;
workplace monitoring.
A claimant could potentially rely on several legal frameworks simultaneously.
Possible legal questions
Was the AI system high-risk?
Was human oversight adequate?
Was personal data processed lawfully?
Was the result discriminatory?
Was the employee given appropriate information?
Did the employer breach employment duties?
Did the AI system contain a defect?
The employer cannot necessarily transfer all responsibility to the software supplier.
27. AI Medical Liability
Healthcare is one of the most important areas.
An AI system could be used for:
diagnosis;
imaging;
triage;
surgery;
drug recommendations;
patient monitoring.
Potential liability can be divided among:
| Actor | Possible responsibility |
|---|---|
| AI developer | Software/design defect |
| Manufacturer | Product liability |
| Hospital | Deployment/supervision |
| Doctor | Professional negligence |
| Data provider | Data-related breach |
| Integrator | Integration failure |
| Cloud provider | Infrastructure failure |
The Boston Scientific case is particularly useful by analogy because it illustrates how product safety expectations operate where technological defects create serious health risks. (Infocuria)
28. AI Consumer Liability
Consumers may encounter AI through:
chatbots;
smart appliances;
autonomous vehicles;
recommendation systems;
financial applications;
health applications.
Consumer claims may involve:
defective product;
misleading information;
contractual non-performance;
unfair commercial practices;
privacy violations;
personal injury.
The new Product Liability Directive explicitly brings software and AI systems within the concept of products, making this area considerably more important from December 2026 onward. (EUR-Lex)
29. Generative AI Liability
Generative AI creates special problems.
Possible harms include:
Hallucinated information
False information causes financial or reputational harm.
Defamation
AI generates a false allegation about an identifiable person.
Copyright-related harm
AI generates material allegedly infringing protected rights.
Privacy harm
The system exposes personal information.
Professional reliance
A lawyer, doctor or financial professional relies upon incorrect AI output.
Product defect
A generative AI product has an unsafe design or failure.
The applicable liability regime depends heavily on the precise harm.
30. General-Purpose AI
The AI Act contains specific rules for general-purpose AI models.
These rules are important because a foundation model may be incorporated into numerous downstream products.
This creates a complex responsibility chain:
Model provider → downstream provider → deployer → end user → injured person
Civil litigation may therefore require courts to determine which actor's conduct actually caused the harm.
31. AI Act and Product Liability Work Together
A useful way to understand the relationship is:
AI Act
“Was the AI system lawfully developed and deployed?”
Product Liability Directive
“Was the AI product defective and did that defect cause compensable damage?”
GDPR
“Was personal data lawfully processed?”
Tort law
“Did the defendant unlawfully or negligently cause harm?”
Contract law
“Did the party perform its contractual obligations?”
Fundamental-rights law
“Did AI use unlawfully interfere with protected rights?”
These regimes can operate simultaneously.
32. Can an AI Act Violation Automatically Create Compensation?
Generally, no automatic compensation rule should be assumed merely because an AI Act requirement was violated.
A claimant normally needs an applicable civil-liability route.
For example:
AI Act breach → evidence of unlawful conduct/breach of duty → damage → causation → applicable civil remedy.
This is different from saying:
AI Act breach → automatic damages.
The CJEU's GDPR compensation jurisprudence reinforces the importance of separating regulatory infringement from proof of compensable damage. (curia)
33. Regulatory Fines and Civil Damages Are Different
Another important distinction:
Regulatory enforcement
Authorities may impose administrative consequences for violations.
Civil compensation
An injured person seeks compensation for legally recognized damage.
A company could potentially face:
regulatory enforcement;
civil damages;
contractual claims;
product liability;
data-protection compensation
arising from the same underlying AI incident.
These remedies serve different legal purposes.
34. Limitation-of-Liability Clauses
AI contracts frequently contain clauses such as:
liability caps;
exclusion of consequential losses;
disclaimers;
indemnity provisions;
service limitations.
Their enforceability depends on applicable law.
Particularly important are:
consumer contracts;
personal injury;
mandatory product liability;
GDPR rights;
statutory protections.
A contractual clause cannot simply be assumed to eliminate mandatory statutory liability.
35. Insurance
AI companies increasingly need to consider:
professional indemnity insurance;
cyber insurance;
product liability insurance;
errors and omissions insurance;
directors' and officers' insurance;
technology liability insurance.
Insurance disputes may themselves involve:
disclosure;
causation;
policy exclusions;
cyber exclusions;
contractual warranties;
regulatory breaches.
36. Defences to AI Liability
Depending upon the applicable regime, defendants may argue:
1. No defect
The system performed according to its specifications.
2. No causation
The injury resulted from another cause.
3. User misuse
The system was used contrary to instructions.
4. Human intervention
The final decision was independently made by a human.
5. State-of-the-art defence
The alleged defect could not reasonably have been discovered under the applicable legal test.
6. No compensable damage
The claimant suffered no legally recognized loss.
7. Third-party interference
A cyberattack or unauthorized modification caused the incident.
However, the availability of each defence depends upon the specific legal regime and applicable national law.
37. Special Problem: Autonomous AI
Traditional civil liability assumes:
human or corporate actor → decision → consequence.
Autonomous AI may look like:
human actor → system → autonomous processing → output → human response → consequence.
The law therefore needs to identify the legally relevant human or corporate responsibility at the points of:
design;
deployment;
supervision;
maintenance;
updating;
use.
The AI itself generally does not become a separate civil defendant merely because it generated the harmful output.
38. Territorial and Cross-Border Liability
AI systems frequently operate across borders.
For example:
German company develops model;
Irish subsidiary provides service;
French hospital deploys it;
Spanish consumer suffers harm;
cloud infrastructure is outside the EU.
Potential issues include:
jurisdiction;
applicable law;
Brussels Ia;
Rome I;
Rome II;
GDPR territorial scope;
AI Act territorial scope;
recognition and enforcement.
Thus, European AI liability is also an important private international law issue.
39. Important Distinction: Provider vs Deployer
This distinction should always be examined.
Provider
Usually responsible for putting the AI system into the market or service and satisfying applicable provider obligations.
Deployer
Uses the AI system in a real-world environment.
Example
A company purchases recruitment AI.
The developer may be responsible for defective system design.
The employer may be responsible for:
inappropriate use;
discriminatory deployment;
inadequate human review;
unlawful employee-data processing.
Both may potentially face legal consequences, but on different legal bases.
40. Practical Liability Matrix
| AI problem | Potential legal basis |
|---|---|
| Physical injury from AI product | Product liability / tort |
| Privacy violation | GDPR |
| Automated discriminatory decision | Equality law / GDPR / AI Act |
| Defective AI software | Product Liability Directive |
| Contractual AI failure | Contract law |
| Wrong medical AI output | Medical/product/tort law |
| Facial recognition misuse | GDPR / fundamental rights |
| Cyberattack through AI vulnerability | Cybersecurity / GDPR / tort |
| AI-generated defamatory content | National civil/tort law |
| Employment AI discrimination | Employment/equality law |
| Financial AI loss | Contract/tort/financial regulation |
| Unsafe autonomous system | Product liability/tort |
| Failure to supervise AI | Tort/contract/regulatory law |
41. Key Principles Emerging from European Case Law
The cases collectively support several important principles.
Principle 1 — Algorithmic decisions can have legal consequences
SCHUFA demonstrates that an apparently intermediate algorithmic score can constitute automated decision-making where it effectively determines the final decision. (curia)
Principle 2 — Regulatory infringement and damages are different
Österreichische Post shows that infringement does not automatically equal compensation; legally relevant damage and causation remain important. (curia)
Principle 3 — Cybersecurity failures can produce liability
Natsionalna agentsia za prihodite illustrates the importance of technical and organizational security measures and controller responsibility. (Infocuria)
Principle 4 — Transparency matters
Österreichische Post, C-154/21 strengthens the data subject's ability to identify recipients of personal information. (Curia)
Principle 5 — Technological products can be defective because of systemic safety risks
Boston Scientific is important for understanding defectiveness in technologically complex products. (Infocuria)
Principle 6 — AI can interfere with fundamental rights
Glukhin demonstrates the importance of privacy and fundamental rights where facial-recognition technology is used. (ECHR-KS)
42. Major Challenges in AI Civil Liability
1. Causation
Determining whether AI actually caused the harm.
2. Explainability
Understanding why the system produced a particular result.
3. Evidence asymmetry
The provider may possess most of the technical evidence.
4. Multiple actors
Several companies may participate in one AI ecosystem.
5. Continuous updates
AI systems can change after deployment.
6. Emergent behaviour
Unexpected outputs may not have been specifically programmed.
7. Cross-border operation
Development, deployment and damage can occur in different jurisdictions.
8. Allocation of responsibility
Courts must distinguish provider, deployer, manufacturer, integrator and user responsibility.
43. Future Direction of European AI Liability
The major structural development is the convergence of:
AI Act + Product Liability Directive + GDPR + national tort law + contract law + fundamental rights.
The new Product Liability Directive is especially significant because it expressly brings software and AI systems into the product-liability framework. (EUR-Lex)
The result is increasingly a layered liability system rather than a single AI-liability statute.
44. Exam-Oriented Legal Test
For an AI civil-liability problem, use this sequence:
Step 1
Identify the AI system.
Step 2
Identify the actors:
provider;
manufacturer;
deployer;
importer;
distributor;
professional user.
Step 3
Determine whether the AI Act applies.
Step 4
Determine whether the system is prohibited, high-risk, general-purpose or otherwise regulated.
Step 5
Check GDPR implications.
Step 6
Check the Product Liability Directive.
Step 7
Apply contract or tort/delict law.
Step 8
Identify the damage.
Step 9
Establish causation.
Step 10
Examine evidence and disclosure.
Step 11
Consider defences.
Step 12
Determine the appropriate remedy.
45. Short Revision Table of Cases
| Case | Principle | AI relevance |
|---|---|---|
| SCHUFA, C-634/21 | Automated scoring can constitute automated decision-making | AI credit/recruitment decisions |
| Österreichische Post, C-300/21 | GDPR infringement alone does not automatically produce compensation | AI profiling/privacy damages |
| Natsionalna agentsia za prihodite, C-340/21 | Security, controller responsibility and GDPR compensation | AI cybersecurity |
| Österreichische Post, C-154/21 | Right to information about actual data recipients | AI data ecosystem transparency |
| Boston Scientific, C-503/13 & C-504/13 | Systemic product risk can establish defectiveness | Defective AI/software products |
| Glukhin v Russia | Facial recognition can seriously interfere with privacy rights | Biometric AI |
| Gemeinde Ummendorf, C-456/22 | Actual compensable damage must be distinguished from mere infringement | AI data exposure |
| Google Spain, C-131/12 | Search-engine processing can create legal responsibility | AI search and information systems |
46. Conclusion
The European AI liability framework is best understood as a multi-layered civil-law system.
The AI Act establishes standards for safe, transparent and accountable AI. The Product Liability Directive 2024/2853 significantly expands no-fault product liability into the digital environment by expressly covering software and AI systems. GDPR provides an additional compensation route for unlawful personal-data processing, while national contract and tort law continues to govern many AI-related injuries. (EUR-Lex)
The most important legal point is:
An AI Act violation does not automatically mean that damages are payable.
A claimant generally still needs an applicable civil-liability basis, legally recognized damage and a sufficient causal connection. Conversely, an AI system can potentially create civil liability even where the claim is not framed directly as an “AI Act” claim.
Thus, European AI liability is moving from the old model of “human error versus machine” toward a more complex model of shared responsibility across developers, providers, deployers, manufacturers and users, supported by regulatory compliance, product liability, data protection, contract, tort and fundamental-rights law.

comments