Civil Law And Ai Credit Risk Assessment Error Claims In Europe .
Civil Law and AI Credit Risk Assessment Error Claims in Europe
1. Introduction
AI credit-risk assessment error claims arise when a bank, fintech, credit-information agency, or other lender uses an automated or AI-based system to assess a person's creditworthiness and the system produces an erroneous result.
Examples include:
an AI model wrongly classifying a consumer as high-risk;
incorrect credit-bureau information being fed into the model;
an algorithm using outdated debt information;
an automated system incorrectly predicting default;
a loan being rejected because of an inaccurate score;
an AI system approving credit despite an inadequate creditworthiness assessment;
discriminatory or proxy variables affecting the score;
a consumer being unable to discover why the AI produced the result;
a lender relying mechanically on a third-party score.
European law approaches these disputes through several overlapping areas:
GDPR and automated decision-making;
consumer-credit law;
civil/contractual liability;
data accuracy and correction rights;
unfair consumer terms;
financial-services regulation; and
increasingly, AI governance.
There is still relatively little reported European case law specifically concerning a modern generative-AI credit-risk model. However, the CJEU has already developed highly relevant jurisprudence on automated credit scoring and creditor creditworthiness assessments. The most important authority is SCHUFA (C-634/21). (Infocuria)
2. What Is an AI Credit-Risk Assessment?
An AI credit-risk system attempts to predict whether an individual or business will repay credit.
It may analyse:
income;
employment;
existing debts;
repayment history;
bank-account information;
credit-bureau data;
transaction behaviour;
financial ratios;
previous defaults;
public records;
sometimes alternative data.
A machine-learning system may then generate a score such as:
Credit-risk score: 82/100
The lender may use that score to determine:
whether to approve a loan;
the amount of credit;
interest rate;
repayment period;
collateral requirements;
credit limit;
whether an existing facility should be reduced.
The civil-law problem arises when the underlying assessment is wrong and causes legally recognisable harm.
3. Two Different Types of AI Credit Errors
A crucial distinction should be made.
A. Wrongful refusal of credit
Example:
AI incorrectly classifies a financially reliable consumer as a high-risk borrower.
Consequences may include:
loan refusal;
higher interest rate;
loss of business opportunity;
inability to purchase property;
reputational harm;
additional financing costs.
B. Wrongful approval of credit
Example:
AI incorrectly classifies an over-indebted consumer as creditworthy.
The consumer obtains a loan that he or she cannot realistically repay.
This creates a different legal problem because European consumer-credit law imposes obligations on creditors to assess creditworthiness.
Thus, AI errors can potentially harm both the applicant and the lender.
4. Main European Legal Framework
4.1 GDPR
The GDPR is central where AI uses personal data for credit scoring.
Particularly important are:
Article 5 — principles concerning personal-data processing;
Article 6 — lawful processing;
Article 15 — access rights;
Article 16 — rectification;
Article 17 — erasure in appropriate circumstances;
Article 21 — objection;
Article 22 — automated individual decision-making;
Article 82 — compensation.
Article 22 is especially important where an automated decision produces legal or similarly significant effects.
The CJEU has specifically considered automated credit scoring under Article 22 in SCHUFA.
5. Case Law 1 — SCHUFA Holding (Scoring)
OQ v Land Hessen / SCHUFA Holding AG
CJEU, Case C-634/21, ECLI:EU:C:2023:957
This is the leading European case for AI/automated credit scoring.
SCHUFA calculated a probability value concerning an individual's ability to meet future payment obligations. Banks and other businesses could use that score when deciding whether to enter into contracts.
The CJEU held that such scoring can constitute automated individual decision-making within Article 22 GDPR where the recipient of the score attributes a determining role to it in deciding whether to establish a contractual relationship. (Infocuria)
Importance
The case fundamentally changes how automated credit scoring should be understood.
The legal question is not simply:
“Did the bank make the final decision?”
Instead, the court can examine whether the automated score effectively determines the decision.
AI application
Suppose:
AI model → score = 35/100 → automatic loan rejection
Even if the bank technically clicks the final “reject” button, Article 22 may become relevant if the score effectively determines the outcome.
Civil-law significance
A claimant may potentially combine:
GDPR rights;
rectification;
access rights;
challenge to automated decision-making;
compensation under applicable law;
national civil remedies.
This is the most important case to cite for AI credit-scoring disputes in Europe. (curia)
6. Case Law 2 — SCHUFA II / Dun & Bradstreet
CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria GmbH
CJEU, Case C-203/22, ECLI:EU:C:2025:117
This is particularly important for the explainability of AI credit scoring.
The CJEU considered the right of a data subject to receive meaningful information about the logic involved in automated scoring under Article 15(1)(h) GDPR.
The Court addressed the relationship between:
automated scoring;
meaningful information;
accuracy of information;
trade secrets;
third-party personal data.
It held that the controller may not simply rely on a claim of trade secrecy to avoid judicial or supervisory scrutiny; the competent authority or court may have to balance the competing interests. (Curia)
Why this matters for AI
Suppose a consumer asks:
“Why did your AI give me a credit score of 410?”
The company cannot necessarily answer only:
“Our algorithm is confidential.”
The GDPR may require meaningful information about the logic involved, subject to the applicable limitations.
Civil claim
This becomes important when a claimant alleges:
“The AI made an error, but I cannot prove the error because the lender refuses to explain how the score was calculated.”
The 2025 SCHUFA/Dun & Bradstreet judgment provides important support for scrutinising that problem.
7. Case Law 3 — CA Consumer Finance
CA Consumer Finance SA v Bakkaus and Others
CJEU, Case C-449/13, ECLI:EU:C:2014:2464
This case concerned the creditor's obligation to assess a consumer's creditworthiness and the burden of proof concerning compliance with that obligation.
The CJEU examined the pre-contractual information and creditworthiness-assessment requirements under Directive 2008/48. (Infocuria)
Principle
A creditor cannot simply assert:
“We checked the borrower's creditworthiness.”
The legal framework can require evidence demonstrating that the relevant assessment actually occurred.
AI application
Suppose a lender says:
“Our AI automatically assessed your creditworthiness.”
The claimant can ask:
What information was used?
Was sufficient information obtained?
Was the data accurate?
Was the model operating correctly?
Was the assessment actually performed?
Was the result consistent with the consumer's financial circumstances?
Importance
This shifts the litigation from:
“The AI made a decision”
to:
“Can the lender demonstrate that the legally required creditworthiness assessment was properly performed?”
8. Case Law 4 — LCL Le Crédit Lyonnais
LCL Le Crédit Lyonnais SA v Kalhan
CJEU, Case C-565/12, ECLI:EU:C:2014:190
The CJEU considered the creditor's obligation to assess the consumer's creditworthiness before concluding the credit agreement and the consequences of failing to comply.
The case involved French legislation providing a sanction affecting the lender's entitlement to contractual interest where the required assessment was not properly performed. (Infocuria)
Principle
Creditworthiness assessment is a substantive legal obligation, not merely an optional banking procedure.
AI relevance
Imagine that:
the lender uses an AI scoring model;
the model receives incomplete income data;
the model incorrectly identifies a consumer as low-risk;
the lender approves a large loan.
The lender cannot necessarily say:
“Our algorithm gave a positive score, therefore our legal obligation was fulfilled.”
The question is whether the legally required creditworthiness assessment was actually performed.
Important distinction
AI prediction ≠ legal creditworthiness assessment.
An algorithmic probability score is a technological output. The legal obligation is determined by the applicable legislation.
9. Case Law 5 — OPR-Finance
OPR-Finance s.r.o. v GK
CJEU, Case C-679/18, ECLI:EU:C:2020:167
The case concerned Article 8 of Directive 2008/48 and the creditor's obligation to assess consumer creditworthiness.
The CJEU held that national rules must provide effective, proportionate and dissuasive consequences for failures to comply with the creditworthiness obligation. It also addressed the ability of national courts to examine compliance on their own initiative. (Infocuria)
AI application
Suppose an automated lender fails to properly evaluate a consumer.
The lender cannot necessarily escape the consequences merely because:
“The AI system was responsible for the calculation.”
The legal obligation remains attached to the relevant creditor.
Civil-law significance
This case is particularly useful for establishing the proposition that technological automation does not eliminate statutory creditor obligations.
10. Case Law 6 — Radlinger and Radlingerová
Radlinger and Radlingerová v FINWAY a.s.
CJEU, Case C-377/14, ECLI:EU:C:2016:283
The case concerned consumer credit and insolvency.
The CJEU emphasised effective judicial protection of consumer-credit rights and held that national courts must examine relevant consumer-protection issues in appropriate circumstances, including required information concerning the credit agreement. (Infocuria)
AI significance
This is important when an AI-generated credit decision eventually becomes the subject of litigation.
A consumer may be disadvantaged by:
technical terminology;
opaque algorithms;
complex scoring;
incomplete explanations.
The court must nevertheless be able to apply the relevant consumer-protection rules effectively.
Practical lesson
An AI credit decision should not become legally unchallengeable merely because its reasoning is technically complex.
11. Case Law 7 — Home Credit Slovakia
Home Credit Slovakia a.s. v Bíróová
CJEU, Case C-42/15, ECLI:EU:C:2016:842
The CJEU considered mandatory information in consumer-credit agreements and the consequences of non-compliance with those requirements.
The case demonstrates the importance of transparent and legally sufficient credit documentation. (Infocuria)
AI relevance
An automated credit system may produce:
automated loan offers;
automated interest rates;
automated repayment schedules;
automated contractual documents.
The fact that those documents are generated automatically does not remove mandatory information requirements.
Principle
Automation does not replace statutory disclosure duties.
12. Case Law 8 — Dunai v ERSTE Bank Hungary
Dunai v ERSTE Bank Hungary Zrt
CJEU, Case C-118/17, ECLI:EU:C:2019:207
This case concerned foreign-currency lending and unfair contractual terms.
The CJEU addressed the consequences of unfair terms in consumer credit contracts and the protection that must be provided to consumers. (Infocuria)
AI relevance
AI-generated credit contracts may contain:
automated terms;
dynamic pricing;
automated fees;
default provisions;
algorithmically determined interest rates.
If the underlying terms are unfair, the fact that an algorithm generated or selected them does not prevent consumer-law scrutiny.
13. Case Law 9 — LCL and the Prevention of Over-Indebtedness
The LCL jurisprudence also has a broader social-protection significance.
The CJEU recognised that the creditworthiness assessment protects consumers against the risk of over-indebtedness. This principle is particularly relevant when AI systems make rapid, high-volume lending decisions. (Infocuria)
An AI lender can potentially approve thousands of loans in a short period.
If the model systematically underestimates risk, the resulting problem may become systemic rather than merely individual.
14. What Constitutes an AI Credit-Assessment Error?
Several categories should be distinguished.
14.1 Incorrect input data
Example:
The system records €60,000 annual income instead of €60,000 annual turnover.
The resulting credit score may be wrong.
14.2 Outdated information
Example:
A debt that has already been discharged continues to appear in the credit database.
The AI treats it as current.
14.3 Incorrect inference
The input data may be correct, but the algorithm makes a faulty inference.
Example:
Stable employment + recent account activity = high default probability.
The statistical model may simply be wrong for the particular person.
14.4 Algorithmic bias
The system may indirectly rely on variables correlated with:
geographical location;
socioeconomic background;
age;
disability;
ethnicity or other protected characteristics.
The precise legal analysis depends on the jurisdiction and applicable discrimination rules.
14.5 Model drift
A model trained on historical economic conditions may become inaccurate after:
recession;
inflation;
interest-rate changes;
labour-market disruption;
regulatory changes.
The model may remain operational while its predictive accuracy deteriorates.
15. Wrong Credit Score and Data Accuracy
A fundamental GDPR principle is that personal data must be accurate and, where necessary, kept up to date.
Suppose the credit database says:
“Outstanding default: €15,000.”
But the debt was actually paid five years ago.
An AI system uses that information to calculate a score.
The claimant can potentially have two connected problems:
Data problem
The underlying personal data is inaccurate.
AI problem
The incorrect data produces an incorrect automated assessment.
Thus:
incorrect data → incorrect model input → incorrect score → adverse decision → economic harm
16. Automated Decision vs Human Decision
This is one of the most important issues.
Suppose:
AI score = 20/100
and the bank employee automatically rejects the application.
The bank may argue:
“The decision was made by a human.”
But if the human merely accepts the AI result without meaningful independent assessment, the legal significance of Article 22 may become important.
This is precisely why SCHUFA is so important: the CJEU focused on whether the automated score has a determining role in the subsequent decision. (curia)
17. Meaningful Human Intervention
A meaningful human review should not necessarily mean:
“A human pressed the approval/rejection button.”
The more important question is whether the human decision-maker can:
understand the relevant circumstances;
question the algorithm;
depart from its recommendation;
correct erroneous information;
consider information omitted by the model.
A purely formal human review may provide little practical protection.
18. Right to Explanation
A claimant may want to know:
“Why was I rejected?”
Possible explanations include:
low credit score;
excessive debt;
insufficient income;
repayment history;
high debt-to-income ratio.
But modern AI models may involve hundreds of variables.
The C-203/22 judgment is therefore particularly important because it addresses meaningful information concerning the logic involved in automated scoring. (Curia)
19. Trade Secrets and AI Algorithms
Financial institutions may argue:
“The model is a trade secret.”
That may be relevant, but it does not necessarily eliminate GDPR rights.
The 2025 CJEU judgment in C-203/22 demonstrates that trade-secret interests and data-subject rights must be balanced rather than simply assuming that one automatically defeats the other. (Curia)
Therefore:
algorithmic secrecy ≠ automatic immunity from explanation or judicial scrutiny.
20. Civil Liability for Wrongful Credit Refusal
Suppose:
AI incorrectly classifies A as high-risk;
bank rejects A's mortgage;
A subsequently loses a property purchase;
A claims damages.
Potential issues include:
Duty
Did the bank or credit-information provider owe a legal duty?
Breach
Was the information or assessment defective?
Causation
Did the AI error actually cause the financial loss?
Foreseeability
Was the loss a foreseeable consequence?
Damage
What measurable loss occurred?
21. Possible Damages
Depending on applicable national law, possible claims may involve:
1. Financial loss
For example:
additional borrowing costs;
increased interest;
transaction expenses.
2. Lost opportunity
For example:
loss of a property purchase.
This is often difficult to prove because courts may require sufficiently certain evidence.
3. Reputational damage
An inaccurate credit record may affect the individual's financial reputation.
4. Non-material damage
GDPR Article 82 can potentially become relevant where the requirements for compensation are satisfied.
22. Wrongful Credit Approval
The opposite problem is equally important.
Suppose an AI system approves a €50,000 consumer loan even though the borrower is clearly unable to repay it.
The lender may face arguments that:
the creditworthiness assessment was inadequate;
insufficient information was used;
the algorithm was improperly configured;
the lender failed to verify the result.
The consumer may also have arguments concerning the consequences of non-compliance.
The CJEU's cases concerning LCL, CA Consumer Finance, and OPR-Finance provide the principal European framework. (Infocuria)
23. AI Developer vs Bank vs Credit Bureau
A typical AI credit system may look like:
Credit bureau → AI vendor → bank → consumer
Each participant may have a different legal role.
Credit bureau
Potential issue:
Was inaccurate personal information supplied?
AI provider
Potential issue:
Was the model technically defective or inadequately configured?
Bank
Potential issue:
Did the bank comply with its own legal creditworthiness obligations?
Consumer
Potential issue:
Did the consumer provide accurate information?
The court therefore needs to identify which failure caused the harm.
24. Contractual Liability
Where a contractual relationship exists, a claimant may allege:
breach of credit agreement;
breach of advisory/financial-service agreement;
failure to perform agreed assessment;
breach of information duties;
improper automated processing.
Contractual liability is governed largely by national civil law.
Therefore, a European cross-border dispute may require determining:
governing law;
jurisdiction;
applicable EU regulation;
contractual terms;
mandatory consumer protections.
25. Tort/Delict Liability
A claimant may alternatively rely on non-contractual liability.
Potential allegations include:
negligent processing of personal data
or
negligent provision of inaccurate credit information.
The exact elements differ between European civil-law systems.
Typically relevant questions include:
unlawful conduct;
fault or negligence;
protected interest;
causation;
damage.
26. Data-Protection Compensation
GDPR Article 82 is potentially important where unlawful processing causes material or non-material damage.
An AI credit dispute could involve:
unlawful/inaccurate processing → incorrect credit profile → adverse decision → damage
However, not every incorrect AI output automatically creates a compensable GDPR claim.
The claimant generally still needs to establish the requirements for liability and damage under the GDPR and applicable case law.
27. AI Act
The EU AI Act adds another layer to the analysis.
Creditworthiness assessment is particularly sensitive because AI systems used for evaluating the creditworthiness of natural persons can fall within the EU AI Act's high-risk AI framework, subject to the precise statutory scope and exceptions.
This can bring requirements concerning:
risk management;
data governance;
technical documentation;
record keeping;
transparency;
human oversight;
accuracy;
robustness;
cybersecurity.
However, an important distinction must be maintained:
Regulatory non-compliance and private damages liability are not automatically identical.
A claimant still needs an appropriate private-law or data-protection basis for compensation.
28. Burden of Proof
AI litigation creates an important evidentiary problem.
The consumer may know only:
“My loan was rejected.”
The bank may possess:
model outputs;
risk scores;
training information;
data inputs;
internal decision rules;
logs;
human-review records.
The CA Consumer Finance case is particularly useful because it addresses the evidentiary burden concerning compliance with creditworthiness obligations. (Infocuria)
Modern AI litigation may therefore involve substantial disclosure and evidentiary questions.
29. Algorithmic Transparency
A claimant may seek information about:
input variables;
data sources;
scoring factors;
model version;
decision thresholds;
error rates;
human intervention;
reasons for rejection.
But transparency does not necessarily mean disclosure of the entire source code.
The CJEU's 2025 C-203/22 judgment is important because it demonstrates that the legal concept is meaningful information about the logic, rather than an automatic right to receive every element of the proprietary algorithm. (Curia)
30. Discrimination and Proxy Variables
AI credit models may create indirect discrimination.
Example:
The model does not explicitly use a protected characteristic but uses:
postcode
The postcode may strongly correlate with socioeconomic or other protected characteristics.
The legal analysis would require determining:
whether discrimination occurred;
whether the characteristic is protected;
whether the effect is direct or indirect;
whether a justification exists;
which EU/national discrimination rules apply.
The fact that:
“The algorithm selected the variable”
does not automatically resolve the legal issue.
31. AI Hallucination in Credit Assessment
Generative AI introduces another risk.
A chatbot might invent:
employment history;
debt information;
repayment history;
financial statements;
regulatory information.
For example:
“The applicant has two previous defaults.”
If that statement is fabricated and becomes part of a credit decision, the consequences can be serious.
This is distinct from ordinary predictive error.
Predictive error
The model correctly receives the data but predicts wrongly.
Hallucination/data fabrication
The system generates information that was never true or never existed.
The second situation can create particularly strong data-accuracy and governance concerns.
32. Human Error Plus AI Error
AI disputes will often involve a combination.
Example:
consumer submits €4,000 monthly income;
employee enters €400;
AI processes €400;
system rejects loan;
bank says “AI made the decision.”
The AI may actually have processed the wrong human-entered data.
Therefore courts should distinguish:
AI error
from
human data-entry error
from
bad underlying database
from
bad model design
from
improper human reliance on the model.
33. Causation Problems
Causation may become difficult.
Suppose the AI wrongly rejects a mortgage.
The consumer claims:
“I lost €100,000 because of the AI.”
The court may ask:
Would the bank otherwise have approved the mortgage?
Would the consumer have completed the purchase?
Would another bank have provided financing?
Did the property transaction actually fail because of the AI decision?
Was the claimed loss foreseeable?
Did the consumer mitigate the loss?
Therefore:
AI error ≠ automatic entitlement to the entire claimed financial loss.
34. Case-Law Synthesis
The major authorities can be organised into four groups.
Group 1 — Automated scoring
SCHUFA, C-634/21
→ Automated credit scoring can fall within Article 22 GDPR when it has a determining role. (Infocuria)
Group 2 — Explainability
C-203/22
→ Meaningful information concerning automated scoring and judicial/supervisory balancing of data rights, trade secrets and related interests. (Curia)
Group 3 — Creditworthiness obligation
CA Consumer Finance, C-449/13
LCL, C-565/12
OPR-Finance, C-679/18
→ Creditors have legally significant obligations concerning assessment of consumer creditworthiness, with effective consequences for non-compliance. (Infocuria)
Group 4 — Effective consumer protection
Radlinger, C-377/14
Home Credit Slovakia, C-42/15
Dunai, C-118/17
→ Consumer-credit obligations must be capable of effective judicial enforcement and mandatory information requirements remain important. (Infocuria)
35. Comparative Case-Law Table
| Case | Court | Main legal principle | AI credit-risk relevance |
|---|---|---|---|
| SCHUFA, C-634/21 | CJEU | Automated scoring can constitute automated individual decision-making | Central authority for AI credit scoring |
| C-203/22, Dun & Bradstreet | CJEU | Meaningful information concerning automated scoring | Explainability and algorithmic transparency |
| CA Consumer Finance, C-449/13 | CJEU | Creditworthiness assessment and burden of proof | Lender must be able to demonstrate compliance |
| LCL Le Crédit Lyonnais, C-565/12 | CJEU | Pre-contractual creditworthiness obligation and effective sanctions | AI cannot replace the legal assessment |
| OPR-Finance, C-679/18 | CJEU | Effective, proportionate and dissuasive consequences for failure to assess creditworthiness | Automated lending remains subject to creditor duties |
| Radlinger, C-377/14 | CJEU | Effective judicial consumer protection | AI credit decisions must remain legally challengeable |
| Home Credit Slovakia, C-42/15 | CJEU | Mandatory credit-contract information | Automated credit documentation remains subject to law |
| Dunai, C-118/17 | CJEU | Consumer protection against unfair credit terms | AI-generated contractual terms remain reviewable |
36. Practical Example
Assume a European fintech uses an AI model to approve personal loans.
A consumer has:
€4,000 monthly income;
no outstanding defaults;
€20,000 savings;
stable employment.
The AI incorrectly obtains a third-party database entry showing:
“€35,000 unpaid debt.”
The AI assigns:
Risk score: 94/100
The loan is automatically rejected.
The consumer discovers the mistake six months later.
Possible legal issues
1. Data accuracy
Was the underlying debt information inaccurate?
2. Rectification
Can the consumer require correction?
3. Automated decision
Did the score determine the rejection?
4. Explanation
Can the consumer obtain meaningful information about the score?
5. Negligence
Did the bank or credit-information provider fail to maintain accurate data?
6. Causation
Did the rejection cause an identifiable financial loss?
7. Compensation
Is material or non-material damage legally established?
8. AI governance
Were appropriate controls in place to detect the erroneous database entry?
37. Another Example — Wrongful Loan Approval
A lender's AI system evaluates a consumer.
The consumer has:
substantial existing debts;
unstable income;
several recent missed payments.
The AI nevertheless approves a €30,000 loan.
The consumer later becomes insolvent.
Potential questions include:
Did the lender conduct a legally adequate creditworthiness assessment?
Did it use sufficient information?
Did the AI ignore relevant data?
Was the model improperly calibrated?
Did the lender blindly rely on the score?
What consequences does national law attach to the failure?
The LCL, CA Consumer Finance, and OPR-Finance authorities become particularly relevant. (Infocuria)
38. Key Legal Principles
AI credit scoring is not legally neutral simply because it is automated.
SCHUFA is the leading CJEU authority on automated credit scoring.
A credit score may amount to automated individual decision-making when it plays a determining role. (curia)
Incorrect underlying personal data can undermine the entire AI assessment.
Creditors have substantive duties to assess consumer creditworthiness.
AI does not replace the lender's legal responsibility.
A lender cannot necessarily defend an inadequate assessment merely by saying that its AI produced the result.
Consumers may have rights to meaningful information about automated scoring.
Trade-secret arguments do not automatically eliminate scrutiny of automated decision-making.
Human intervention must be meaningful where the law requires it.
A formal human click does not necessarily transform an automated decision into a genuinely human decision.
AI developers, credit bureaus and lenders may have different legal responsibilities.
Contractual, tort/delict and GDPR claims may potentially overlap.
Causation and proof of damage remain essential.
Regulatory infringement does not automatically equal civil damages; the applicable private-law requirements must still be satisfied.
39. Conclusion
AI credit-risk assessment error claims in Europe represent the convergence of civil law, consumer-credit law, data protection and AI regulation. The traditional legal duty of a lender to assess creditworthiness does not disappear merely because the assessment is performed by machine learning.
The most important European authority is SCHUFA (C-634/21), where the CJEU held that automated credit scoring can fall within Article 22 GDPR when the score has a determining role in a subsequent credit decision. (Infocuria) The later C-203/22 judgment strengthens the importance of meaningful information concerning the logic involved in automated scoring. (Curia)
The consumer-credit cases—CA Consumer Finance, LCL Le Crédit Lyonnais and OPR-Finance—establish the complementary principle that creditors have legally enforceable obligations to assess consumer creditworthiness and that effective consequences must exist for failure to comply. (Infocuria)
Accordingly, the central civil-law formula is:
Incorrect data or defective AI model → erroneous credit assessment → legally significant adverse decision → breach of applicable duty → causation → provable damage = potential civil/data-protection liability, subject to the applicable European and national law.
Ultra-short exam revision
AI Credit Error = Data Accuracy + Automated Decision + Creditworthiness Duty + Explainability + Human Oversight + Causation + Damage + Remedy.

comments