Civil Law And Artificial Intelligence In Healthcare Liability In Europe .

Civil Law and Artificial Intelligence in Healthcare Liability in Europe

1. Introduction

Artificial Intelligence (“AI”) is increasingly used in European healthcare for:

diagnosis and early disease detection;

medical imaging;

radiology;

pathology;

clinical decision support;

robotic surgery;

patient monitoring;

drug and treatment recommendations;

hospital resource allocation;

remote diagnosis;

predictive analytics; and

personalised medicine.

AI can improve medical decision-making, but it also creates difficult civil-liability questions.

For example, an AI diagnostic system may fail to identify a tumour, incorrectly classify an X-ray, recommend an unsuitable treatment, or generate a false warning. The patient may then suffer injury.

The central legal question becomes:

Who is civilly liable when an AI-assisted healthcare decision causes injury—the doctor, hospital, AI provider, manufacturer, software developer, or several of them?

European law generally does not treat AI as an independent legal person. Liability therefore continues to be assigned to identifiable human or legal persons under medical-malpractice, product-liability, contract, tort/delict, consumer-protection and data-protection rules.

2. Meaning of AI Healthcare Liability

AI healthcare liability concerns civil responsibility arising from the design, supply, deployment or use of an AI system in healthcare.

Typical claims include:

A. Diagnostic error

AI fails to detect a disease.

B. False positive

AI identifies a disease that the patient does not have, resulting in unnecessary treatment.

C. Treatment error

AI recommends an inappropriate medication or treatment.

D. Surgical error

An AI-assisted robotic system performs an unsafe action.

E. Monitoring failure

An AI monitoring system fails to detect deterioration.

F. Software defect

A healthcare AI product contains a technical defect.

G. Data problem

Incorrect or incomplete training data causes an erroneous recommendation.

H. Bias or discrimination

The system performs less accurately for a particular patient population.

I. Lack of human supervision

A healthcare professional relies excessively on an AI recommendation.

3. Basic European Civil-Law Principle

A fundamental rule is:

AI does not normally replace the legal responsibility of healthcare professionals.

If a doctor uses an AI diagnostic tool, the doctor ordinarily remains responsible for exercising appropriate professional judgment.

For example:

AI says: “No tumour detected.”

Doctor: accepts the result without reviewing the patient's symptoms or imaging.

Patient: later develops serious cancer.

The legal issue may involve:

whether the AI system was defective;

whether the doctor should have independently assessed the result;

whether the hospital selected an appropriate AI system;

whether warnings were adequate;

whether the manufacturer supplied sufficient instructions;

whether the patient's injury was caused by the AI error.

4. European Liability Framework

AI healthcare liability can arise from several legal sources.

4.1 Medical malpractice

Traditional negligence/delict principles remain central.

The claimant generally has to establish:

Duty → Breach → Causation → Damage

4.2 Contractual liability

A patient may have a contractual relationship with:

a hospital;

physician;

private clinic;

healthcare provider.

Failure to provide professionally appropriate healthcare may therefore produce contractual liability depending on national law.

4.3 Product liability

Where an AI medical device is defective, product-liability law may apply.

The European product-liability framework has become particularly important because AI-enabled medical devices can constitute technologically complex products.

4.4 AI Act

The EU AI Act introduces specific obligations for high-risk AI systems.

Many AI systems used as medical devices or safety-related healthcare systems may fall within the high-risk AI framework.

Relevant concerns include:

risk management;

data governance;

technical documentation;

record keeping;

transparency;

human oversight;

accuracy;

robustness;

cybersecurity.

The AI Act does not simply replace ordinary civil liability.

Instead:

AI regulatory compliance and civil liability operate alongside one another.

5. Medical Device Regulation

AI healthcare systems may also fall within the EU Medical Devices Regulation (“MDR”).

The MDR is particularly important where AI software performs a medical purpose.

Questions include:

Was the software correctly classified?

Was conformity assessment performed?

Were clinical evaluations adequate?

Were post-market surveillance obligations satisfied?

Were risks appropriately identified?

Were users properly informed?

A regulatory violation may become important evidence in a later civil-liability case, although regulatory non-compliance and civil liability are not necessarily identical questions.

6. GDPR and AI Healthcare

Healthcare AI often processes extremely sensitive information.

Health information constitutes special-category personal data under GDPR.

AI systems may process:

medical history;

genetic information;

scans;

laboratory results;

biometric information;

treatment records.

Liability can therefore arise from:

unlawful processing;

inadequate security;

improper automated decision-making;

failure to provide information;

inaccurate data;

unlawful secondary use of medical data.

7. Causation Is the Central Difficulty

AI healthcare cases often have a complicated causal chain:

AI error → Doctor's decision → Treatment → Patient injury

The defendant may argue:

“The AI did not directly cause the injury. The doctor made the decision.”

The patient may argue:

“The doctor relied on the AI because the system was marketed as reliable.”

The court may therefore need to determine:

Was the AI output erroneous?

Was the healthcare professional entitled to rely upon it?

Would a competent professional have detected the error?

Would the injury have occurred without the AI error?

Was the AI defect foreseeable?

Was there an adequate warning?

Did the hospital improperly configure the system?

8. Case Law

Direct European judicial decisions specifically imposing civil liability for modern generative AI or machine-learning medical systems remain limited. Therefore, established European medical-liability and medical-device cases provide important principles for analysing AI cases.

Case 1 — N.N. v Sweden, ECtHR

European human-rights jurisprudence has repeatedly recognised the importance of effective legal protection in cases involving serious medical harm.

Although the European Court of Human Rights does not operate as an ordinary medical-malpractice court, its Article 2 jurisprudence provides important principles concerning healthcare failures.

AI relevance

Where an AI system is used in critical healthcare, states may have positive obligations to maintain an effective regulatory and investigative framework.

The significance is therefore broader than ordinary negligence:

AI deployment in life-critical healthcare cannot exist outside a functioning system of professional and institutional accountability.

9. Case 2 — Glass v United Kingdom

Court: European Court of Human Rights
Case: Glass v United Kingdom
Judgment: 9 March 2004

The case concerned medical treatment administered to a severely disabled child despite objections from the child's mother.

The Court examined Article 8 of the European Convention on Human Rights and the requirement for respect for private and family life.

AI relevance

AI-assisted healthcare must not eliminate:

patient participation;

parental rights where legally applicable;

informed decision-making;

human medical responsibility.

If an AI system recommends a treatment, that recommendation does not itself eliminate the patient's legal rights.

Principle

Technological assistance in healthcare does not remove the legal importance of consent and respect for personal autonomy.

10. Case 3 — V.C. v Slovakia

Court: European Court of Human Rights
Judgment: 8 November 2011

The case concerned sterilisation without sufficiently informed consent.

The Court emphasised the importance of informed consent in medical treatment.

AI relevance

Suppose an AI system recommends an invasive procedure.

The doctor cannot simply tell the patient:

“The computer says this is necessary.”

The patient must still receive legally adequate information concerning:

the procedure;

risks;

alternatives;

consequences.

Principle

AI-supported medical decision-making does not replace informed consent.

11. Case 4 — Lambert and Others v France

Court: European Court of Human Rights
Grand Chamber: 5 June 2015

The case concerned withdrawal of life-sustaining medical treatment.

The Court examined the difficult relationship between:

patient autonomy;

medical judgment;

family interests;

end-of-life decision-making;

Article 2 of the Convention.

AI relevance

AI could increasingly assist doctors in predicting:

survival probabilities;

treatment effectiveness;

deterioration;

neurological recovery.

But such predictions cannot automatically determine a patient's legal treatment.

Principle

A predictive algorithm cannot by itself resolve fundamental medical and ethical questions concerning life-sustaining treatment.

12. Case 5 — Mortier v Belgium

Court: European Court of Human Rights
Judgment: 4 October 2022

The case concerned Belgian euthanasia law and procedural safeguards.

The Court examined the state's regulatory framework governing end-of-life decisions.

AI relevance

AI could potentially be used to assess:

suffering;

prognosis;

treatment alternatives;

medical conditions.

But highly consequential healthcare decisions require appropriate human and institutional safeguards.

Principle

Greater technological sophistication does not eliminate the need for procedural safeguards in life-and-death medical decisions.

13. Case 6 — Tysiąc v Poland

Court: European Court of Human Rights
Judgment: 20 March 2007

The case concerned access to lawful medical treatment and the absence of effective procedures for resolving medical disputes.

The Court emphasised the importance of effective procedural mechanisms where medical decisions significantly affect private life and bodily integrity.

AI relevance

If a hospital relies upon an AI system to make or influence a medical decision, the patient needs an effective mechanism to:

challenge the decision;

obtain human review;

access relevant medical information;

obtain an independent medical assessment.

Principle

AI-assisted healthcare requires meaningful avenues for human challenge and review.

14. Case 7 — Pretty v United Kingdom

Court: European Court of Human Rights
Judgment: 29 April 2002

The case involved end-of-life autonomy and Article 8.

The Court recognised the importance of personal autonomy while considering the limits imposed by the Convention.

AI relevance

Healthcare AI raises similar autonomy issues.

A patient should not automatically become subject to an AI recommendation simply because the technology has a statistical advantage.

Principle

Personal autonomy remains legally relevant even when medical decisions are increasingly supported by predictive technology.

15. Case 8 — Lambert and Others v France as a Model for AI Evidence

The Lambert litigation is particularly useful for understanding the evidentiary problem.

Medical decision-making may depend upon:

expert evidence;

medical records;

clinical assessments;

prognosis;

competing professional opinions.

AI will introduce an additional evidential layer.

For example:

Doctor's opinion + AI prediction + patient records + expert evidence

A court may need to decide how much evidential weight to give the AI output.

The existence of an algorithmic prediction does not automatically determine causation.

16. AI and the Standard of Medical Care

The traditional standard asks whether the healthcare professional acted with the level of care expected from a reasonably competent professional.

AI creates a new question:

What should a reasonably competent doctor do when an AI system gives a recommendation that conflicts with the doctor's clinical judgment?

Three situations can arise.

Situation A — Doctor follows AI

AI recommends treatment X.

Doctor follows it.

Treatment causes injury.

The doctor may need to explain why reliance was professionally reasonable.

Situation B — Doctor ignores AI

AI warns of a dangerous condition.

Doctor ignores the warning.

Patient suffers harm.

The doctor may face questions concerning why the warning was disregarded.

Situation C — AI itself was defective

Doctor follows accepted clinical procedures, but the AI system contains a hidden defect.

The manufacturer or healthcare institution may potentially bear responsibility.

17. Manufacturer Liability

AI healthcare manufacturers may be exposed to liability where:

the algorithm is defective;

the software is incorrectly designed;

training data are inadequate;

cybersecurity vulnerabilities cause malfunction;

warnings are inadequate;

the product is not sufficiently tested;

software updates introduce dangerous defects.

A medical AI system may therefore create a multi-party liability structure.

Possible defendants

Manufacturer + AI developer + hospital + doctor + software integrator

The exact allocation depends on national law and the facts.

18. Hospital Liability

Hospitals may have responsibilities concerning:

selecting AI systems;

testing;

staff training;

supervision;

cybersecurity;

software updates;

maintenance;

monitoring accuracy;

ensuring human oversight.

For example, a hospital that purchases an AI diagnostic system and gives doctors no training may face a different liability analysis from a hospital that implements a comprehensive validation and monitoring programme.

19. Doctor's Liability

A doctor cannot generally defend every error by saying:

“The AI told me to do it.”

Professional responsibility may require:

independent clinical judgment;

consideration of patient-specific factors;

recognition of obvious AI errors;

appropriate documentation;

escalation where the AI result conflicts with clinical evidence.

However, the doctor's liability should not automatically be presumed merely because AI produced an incorrect result.

The court must examine the reasonable professional standard at the relevant time.

20. AI Bias in Healthcare

AI systems may produce different error rates among patient populations.

For example, an AI trained predominantly on one population may perform poorly on another.

This can produce:

misdiagnosis;

delayed diagnosis;

inappropriate treatment;

unequal access;

discriminatory outcomes.

Civil claims could potentially involve:

negligence;

discrimination;

product liability;

data protection;

breach of contractual duties;

institutional liability.

21. The Black-Box Problem

Some AI models are difficult to explain.

A patient may ask:

“Why did the AI say I did not have cancer?”

The hospital might respond:

“The model does not provide an explanation.”

This creates a major litigation problem.

The patient may need to establish:

what the AI was designed to do;

what information it received;

what output it produced;

how the output influenced the doctor;

whether the system complied with regulatory requirements.

Therefore:

AI opacity can become an evidentiary issue as well as a regulatory issue.

22. Human Oversight

Human oversight is one of the most important principles in AI healthcare.

A robust model is:

AI recommendation → Human medical assessment → Patient communication → Clinical decision

rather than:

AI recommendation → Automatic treatment

Human oversight should be meaningful rather than purely formal.

A doctor who is technically permitted to override an AI recommendation but is practically unable to understand or challenge it may raise difficult questions concerning whether the human oversight was genuine.

23. AI and Informed Consent

Traditional informed consent requires adequate information.

AI-assisted treatment creates additional questions:

Was the patient told that AI was used?

Was the AI's role significant?

Was the patient informed about limitations?

Could the patient request human review?

Was an alternative assessment available?

Not every minor use of AI necessarily requires a separate disclosure under every legal system.

But where AI materially influences a significant medical decision, transparency becomes much more important.

24. AI and Medical Records

AI systems can create extensive digital records:

prompts;

model outputs;

recommendations;

confidence scores;

timestamps;

alerts;

overrides;

system updates.

These records may become important evidence in litigation.

A hospital should therefore be able to demonstrate:

What did the AI say, when did it say it, what data did it receive, and what did the doctor do with the output?

25. Causation Model

A useful litigation model is:

AI defect

↓

AI output

↓

Healthcare professional's reliance

↓

Medical intervention

↓

Patient injury

↓

Damage

The claimant must connect the stages sufficiently under the applicable national law.

26. Multiple-Cause Problems

Suppose:

AI failed to identify cancer;

doctor also failed to examine symptoms;

patient delayed returning to hospital;

disease was already advanced.

Who caused the injury?

European civil-law systems may use different approaches to:

concurrent causation;

contributory negligence;

loss of chance;

evidentiary presumptions;

apportionment.

Therefore, AI cases will frequently require detailed medical expert evidence.

27. Loss of Chance

AI healthcare disputes may be particularly suited to loss-of-chance reasoning in jurisdictions that recognise it.

Example:

AI fails to detect cancer.

If detected six months earlier, treatment would have had a substantially higher probability of success.

The patient may argue that the AI error deprived them of a chance of successful treatment.

The precise availability of such a claim varies between European legal systems.

28. Product Liability and Software

AI healthcare systems challenge traditional concepts of a “product.”

Modern systems may contain:

physical medical devices;

cloud software;

machine-learning models;

continuously updated algorithms;

third-party datasets;

remote software updates.

A defect can therefore emerge after deployment.

The legal analysis must consider:

product status;

defect;

injury;

causation;

applicable statutory regime;

software updates;

foreseeable use.

29. AI Act and Civil Liability

The EU AI Act is primarily a regulatory instrument, but its requirements may become important evidence in civil litigation.

For example, failure to maintain:

appropriate risk management;

data governance;

technical documentation;

logging;

human oversight;

accuracy;

robustness;

could potentially be relevant when determining whether reasonable precautions were taken.

But:

Violation of the AI Act should not automatically be treated as identical to civil liability.

The claimant must still satisfy the relevant requirements of the applicable civil-liability regime.

30. Evidence and Burden of Proof

AI healthcare litigation can produce an information imbalance.

The hospital or manufacturer may possess:

model architecture;

training documentation;

logs;

validation reports;

error rates;

incident reports;

update records.

The patient may possess only:

medical records;

treatment results;

injury evidence.

European legislation is increasingly moving toward stronger documentation and transparency obligations, which can become important in resolving this information asymmetry.

31. Defences

Potential defendants may argue:

1. No defect

The AI performed within its validated parameters.

2. No negligence

The doctor acted according to accepted professional practice.

3. No causation

The injury would have occurred regardless.

4. Patient's own conduct

The patient failed to follow medical instructions.

5. Intervening cause

Another medical event caused the injury.

6. Reasonable reliance

The AI system was appropriately validated and the professional had reasonable grounds to rely on it.

7. State-of-the-art defence

The relevant legal regime may provide a defence where a defect could not reasonably have been discovered at the relevant time.

The availability and scope of these defences depend upon the applicable national and EU law.

32. Remedies

Potential civil remedies include:

compensation for bodily injury;

medical expenses;

rehabilitation costs;

lost income;

pain and suffering where recognised;

future care costs;

damages for loss of opportunity/chance where recognised;

restitution;

declaratory relief;

injunctions;

correction of inaccurate medical information.

Data-protection claims may additionally produce remedies under GDPR.

33. Important Distinction: AI Error vs Medical Negligence

An AI system can be wrong without the doctor necessarily being negligent.

Likewise:

A doctor can be negligent even when the AI system itself worked correctly.

Therefore:

ScenarioPotential liability
AI defective + doctor reasonably relies on itManufacturer/hospital potentially liable
AI correct + doctor ignores it without justificationDoctor potentially liable
AI defective + doctor should have detected errorShared liability possible
AI correct but patient suffers unavoidable complicationNo liability merely because AI was involved
Hospital improperly deploys AIInstitutional liability possible
AI unlawfully processes medical dataGDPR liability may arise
AI recommendation causes discriminatory treatmentMultiple legal regimes may apply

34. Six+ Cases — Quick Revision Table

CaseCourtKey principleAI healthcare relevance
Glass v UKECtHRMedical autonomy and Article 8AI cannot eliminate consent
V.C. v SlovakiaECtHRInformed medical consentAI-assisted treatment requires meaningful consent
Lambert v FranceECtHRMedical decision-making and safeguardsAI cannot independently decide end-of-life issues
Mortier v BelgiumECtHRProcedural safeguards in end-of-life medicineHuman oversight of AI in critical decisions
Tysiąc v PolandECtHREffective procedures for medical disputesPatients need mechanisms to challenge AI-assisted decisions
Pretty v UKECtHRPersonal autonomy under Article 8AI must not replace patient autonomy
Lambert v FranceECtHRBalancing medical evidence and rightsAI evidence must be assessed within broader clinical evidence

Note: These cases are primarily medical-autonomy, procedural and human-rights authorities, rather than cases imposing direct civil damages for AI. Direct reported European civil cases specifically involving machine-learning medical malpractice remain comparatively scarce. Consequently, future AI healthcare cases will likely adapt established medical-liability, product-liability and data-protection doctrines.

35. Practical European AI Healthcare Liability Framework

A court examining an AI healthcare injury can use the following sequence:

Step 1 — Identify the AI

What exactly did the system do?

Step 2 — Identify the legal relationship

Was the dispute between:

patient and doctor;

patient and hospital;

patient and manufacturer;

hospital and AI provider?

Step 3 — Identify the applicable law

Consider:

national civil law;

medical-malpractice law;

product-liability law;

MDR;

AI Act;

GDPR;

consumer law.

Step 4 — Determine the standard of care

What would a reasonably competent healthcare professional have done?

Step 5 — Examine AI reliability

Was the system:

validated?

properly configured?

updated?

appropriate for the patient population?

Step 6 — Examine human oversight

Did a competent professional review the AI output?

Step 7 — Establish causation

Did the AI-related error materially contribute to the injury?

Step 8 — Examine contributory factors

Were there:

patient factors;

other doctors;

hospital failures;

manufacturer defects?

Step 9 — Allocate responsibility

Responsibility may potentially be divided among several actors.

Step 10 — Calculate damages

Assess the patient's actual legally compensable loss.

36. Future European Litigation Issues

The most important emerging disputes are likely to concern:

AI cancer-detection errors;

AI radiology errors;

robotic surgery;

AI medication recommendations;

AI emergency-room triage;

AI intensive-care monitoring;

AI prediction of patient deterioration;

AI-generated treatment plans;

algorithmic discrimination;

defective medical datasets;

AI hallucinations in clinical decision support;

autonomous medical devices;

software updates creating new defects;

cybersecurity attacks against medical AI;

liability for cloud-based medical AI;

informed consent concerning AI use;

disclosure of algorithmic evidence;

doctor reliance on AI;

manufacturer versus hospital liability;

loss-of-chance claims.

37. Conclusion

European civil law is moving toward a multi-layered liability model for AI in healthcare.

The basic structure is:

AI system

↓

Manufacturer / developer

↓

Hospital / healthcare institution

↓

Doctor / healthcare professional

↓

Patient

Liability depends on the specific failure.

The most important principles are:

AI has no automatic independent legal personality.

Doctors generally retain professional responsibilities.

Hospitals have duties concerning safe deployment and supervision.

Manufacturers may face product-related liability for defective systems.

Patients retain rights to informed consent and medical autonomy.

AI decisions must be capable of meaningful human oversight where required.

GDPR applies to personal and health data processed by AI.

The AI Act and Medical Devices Regulation add important compliance requirements.

AI output does not automatically establish causation.

The claimant must connect the AI-related failure to the actual medical injury.

Exam Formula

AI Healthcare Liability =

AI Defect/Failure + Medical Duty + Human Oversight + Informed Consent + Product Liability + GDPR + AI Act/MDR + Causation + Damage + Allocation of Responsibility.

LEAVE A COMMENT