Civil Law And Ai Financial Advisor Misconduct Claims In Europe .

Civil Law And AI Financial Advisor Misconduct Claims In Europe

1. Introduction

AI financial advisor misconduct concerns situations where an AI system, robo-adviser, automated portfolio manager, investment chatbot, algorithmic recommendation engine, or AI-assisted adviser provides financial advice or makes investment decisions in a manner that breaches applicable legal duties and causes loss to a client.

Typical disputes include:

unsuitable AI-generated investment recommendations;

incorrect or hallucinated financial information;

failure to assess the client's risk tolerance;

recommendations inconsistent with the client's ability to bear losses;

excessive trading caused by an AI system;

hidden conflicts of interest;

AI recommending proprietary products;

failure to disclose commissions or inducements;

inadequate warnings about investment risks;

discriminatory or biased recommendations;

algorithmic portfolio-management errors;

cybersecurity or data-processing failures;

failure to monitor or correct a malfunctioning AI system;

misleading statements about the capabilities of an AI financial adviser.

There is currently no substantial body of European case law dealing specifically with an autonomous generative-AI financial adviser. The strongest legal framework therefore comes from MiFID II and its delegated regulation, GDPR, the AI Act, consumer law and national civil/contract/tort law, while existing CJEU financial-services cases provide the principal analogies.

Importantly, ESMA has expressly stated that when investment firms use AI, MiFID II continues to apply, including suitability, organisational and best-interest obligations. ESMA specifically identifies algorithmic bias, data-quality problems, over-reliance on AI and inadequate controls as risks. (ESMA)

2. Meaning of an AI Financial Adviser

An AI financial adviser can operate at several levels.

Level 1 — Information

The AI merely provides general information:

“What is an ETF?”

This may not constitute regulated investment advice.

Level 2 — Personalised recommendation

The system analyses the client's circumstances and says:

“You should invest 30% of your portfolio in Fund X.”

This is much more likely to constitute investment advice if the applicable legal requirements are met.

Level 3 — Robo-advisory

The system:

collects client information → determines risk profile → selects investments → recommends portfolio → periodically rebalances.

Level 4 — Autonomous portfolio management

The AI itself decides:

buy → sell → rebalance → execute.

The greater the autonomy and financial consequence, the more important the firm's governance, monitoring and suitability obligations become.

3. Central European Legal Principle

The fundamental rule is:

A financial firm cannot normally avoid its regulatory responsibilities merely because the recommendation was generated by an algorithm.

MiFID II specifically requires investment firms providing advice or portfolio management to obtain information about:

the client's knowledge and experience;

financial situation;

ability to bear losses;

investment objectives;

risk tolerance.

The recommendation must then be suitable for that client. (EUR-Lex)

Even more directly, Article 54 of the MiFID II Delegated Regulation provides that where investment advice or portfolio management is provided wholly or partly through an automated or semi-automated system, responsibility for the suitability assessment remains with the investment firm. The use of an electronic system does not reduce that responsibility. (EUR-Lex)

This is one of the most important provisions for AI financial-adviser litigation.

4. Main Legal Framework

A. MiFID II

The Markets in Financial Instruments Directive II is the principal framework for regulated investment services.

Important obligations concern:

acting honestly, fairly and professionally;

acting in the client's best interests;

fair, clear and non-misleading information;

suitability;

appropriateness;

risk disclosure;

conflicts of interest;

costs and charges;

product governance;

record keeping;

organisational controls.

Article 25 is particularly important because suitability requires consideration of the client's financial circumstances, objectives, risk tolerance, knowledge and experience. (EUR-Lex)

5. Suitability Is the Core AI-Adviser Duty

Suppose an AI adviser recommends a highly volatile cryptocurrency-related financial product to a retiree who has:

low risk tolerance;

little investment experience;

limited ability to bear losses.

The question is not simply:

“Was the investment profitable?”

The legal question is:

Was the recommendation suitable for this particular client at the time it was made?

This distinction is crucial.

A profitable recommendation can still have been procedurally or legally defective.

Conversely, an investment that later loses money is not automatically evidence of misconduct.

6. Automated Suitability Assessment

An AI adviser may use:

questionnaires;

transaction history;

income;

assets;

liabilities;

age;

investment objectives;

risk tolerance;

sustainability preferences;

knowledge and experience.

The system may then generate:

Risk Score = 82/100

and automatically recommend:

High-risk portfolio

The legal problem arises if:

the input data is inaccurate;

the model misinterprets the data;

the risk score is incorrectly calculated;

the algorithm ignores contradictory information;

the system recommends products inconsistent with the client profile.

The firm's legal responsibility does not disappear merely because the calculation was performed automatically. (EUR-Lex)

7. AI Hallucination and False Financial Information

Generative AI creates a new category of misconduct.

For example, an AI adviser could incorrectly state:

“This bond is guaranteed by the government.”

when it is not.

Or:

“Fund X has historically guaranteed a 12% annual return.”

when no such guarantee exists.

This may create claims involving:

misleading information;

breach of contract;

negligence;

breach of regulatory conduct duties;

consumer-protection law;

misrepresentation;

damages.

MiFID II requires information and communications directed to clients to be fair, clear and not misleading. (EUR-Lex)

8. AI Misconduct Through Data Errors

AI advice is only as reliable as the data used.

Suppose the system records:

Client risk tolerance = HIGH

when the actual answer was:

Client risk tolerance = LOW.

The AI may then recommend speculative investments.

Possible legal chain:

Incorrect data → incorrect AI profile → unsuitable recommendation → investment → loss

The firm could face difficulty arguing that the error was simply an independent “AI mistake” if it failed to maintain adequate controls.

ESMA specifically identifies data quality as an AI risk for investment firms. (ESMA)

9. AI Bias and Discriminatory Advice

AI may unintentionally recommend different financial products to different groups.

For example:

Client A and Client B have identical financial circumstances, but the AI produces materially different recommendations because of a proxy characteristic.

Potential issues include:

discrimination law;

GDPR;

AI governance;

consumer law;

equality legislation;

fiduciary/best-interest duties under applicable national law.

Bias may arise from:

historical training data;

socioeconomic proxies;

geographic variables;

language;

behavioural data;

inaccurate risk models.

ESMA has specifically identified algorithmic bias as a risk when AI is used in investment services. (ESMA)

10. AI and Conflicts of Interest

Imagine an AI system has access to:

5,000 investment products.

But its model systematically recommends products issued by the financial institution operating the AI.

The question becomes:

Was the recommendation genuinely in the client's best interest?

MiFID II requires disclosure concerning whether advice is independent and the breadth of products considered. Independent advice must assess a sufficiently diverse range of instruments and cannot be restricted in a manner that undermines independence. (EUR-Lex)

An AI model can therefore create a hidden algorithmic conflict of interest.

11. AI Optimised for Commission Revenue

A particularly serious scenario is:

AI objective = maximise platform revenue.

instead of:

AI objective = maximise suitability for client.

The system might recommend:

products with higher commissions;

more frequent trading;

proprietary funds;

complex derivatives;

products generating greater fees.

This can potentially conflict with the firm's regulatory duties.

The technical design of the model therefore becomes legally relevant.

12. Product Governance

AI advisers should not be viewed solely as client-level recommendation tools.

Investment firms also have product-governance obligations.

The system must not simply optimise:

“Which product produces the highest expected return?”

It must operate within the regulatory framework concerning:

target markets;

client characteristics;

product complexity;

risk;

costs;

distribution strategy.

ESMA's 2024 statement specifically says firms using AI should maintain controls ensuring that AI-supported investment services comply with MiFID II, including product governance and suitability. (ESMA)

13. AI and Sustainability Preferences

MiFID II suitability also incorporates relevant sustainability preferences.

An AI adviser may therefore be defective if a client states:

“I only want investments meeting specified sustainability preferences.”

but the algorithm recommends products inconsistent with those preferences.

This creates another possible chain:

incorrect client data → incorrect sustainability profile → unsuitable recommendation → loss/claim.

14. AI Portfolio Management

The risk becomes greater where AI does not merely recommend but manages the portfolio.

For example:

AI automatically sells €100,000 of securities during a temporary market movement.

Potential issues include:

incorrect market-data interpretation;

model malfunction;

excessive trading;

failure to follow investment mandate;

breach of risk limits;

inadequate human supervision;

failure to update the model;

cybersecurity interference.

The legal analysis depends on the contractual mandate and regulatory classification.

15. Human Oversight

Human supervision is important, but “human in the loop” is not automatically a complete defence.

Suppose:

AI produces 5,000 recommendations.

A human adviser approves all of them automatically without meaningful checking.

A court could need to examine whether the human intervention was genuinely substantive or merely formal.

ESMA has emphasised robust controls and quality-assurance processes for AI systems used by investment firms. (ESMA)

16. Case Law

Case 1 — Genil 48 SL and Comercial Hostelera de Grandes Vinos v Bankinter, C-604/11

CJEU, 30 May 2013

Facts

The dispute concerned interest-rate swaps and MiFID conduct-of-business requirements.

The CJEU examined:

investment advice;

suitability;

appropriateness;

investor protection;

consequences of non-compliance.

The case is one of the most important CJEU authorities for understanding the MiFID suitability framework. (Infocuria)

Principle

The applicable investor-protection requirements depend upon the nature of the investment service being provided.

AI relevance

An AI adviser must first be legally classified.

The provider cannot simply call its service:

“AI information”

if, in substance, it is providing a regulated personalised investment recommendation.

AI lesson:

Classification of the service comes before liability analysis.

17. Case 2 — Banif Plus Bank v Lantos, C-312/14

CJEU, 3 December 2015

Facts

The case concerned foreign-currency consumer loans and whether currency transactions associated with those loans constituted investment services under MiFID.

The CJEU concluded that the relevant foreign-exchange transactions forming part of those consumer loans did not constitute investment services for MiFID purposes. (EUR-Lex)

Importance

The case demonstrates that not every financial product or financial transaction automatically falls within MiFID.

AI relevance

Before bringing an AI-adviser claim under MiFID, the claimant must establish:

What exactly was the AI service?

An AI system giving general banking information may fall under a different framework from a regulated personalised investment adviser.

AI lesson:

Financial technology does not itself determine the legal classification.

18. Case 3 — Mastromartino v CONSOB, C-53/18

CJEU, 8 May 2019

Facts

The case concerned an Italian financial adviser authorised to provide offsite services.

The CJEU considered whether such an adviser constituted an investment firm or a tied agent under MiFID.

The Court concluded that a person acting under the full and unconditional responsibility of a single investment firm fell within the MiFID concept of tied agent, rather than investment firm.

AI relevance

AI systems can similarly operate inside an organisational structure.

The relevant question becomes:

Who is legally responsible for the AI's advice?

Possibilities may include:

investment firm;

robo-adviser provider;

tied agent;

outsourced AI vendor;

portfolio manager.

The provider cannot necessarily shift responsibility to the software developer merely because the developer supplied the model.

19. Case 4 — Genil 48 and Suitability/Appropriateness

The second major lesson from Genil 48 concerns the distinction between:

Suitability

For investment advice and portfolio management.

Appropriateness

For other investment services where the firm must assess the client's knowledge and experience.

MiFID II preserves this distinction in Article 25. (EUR-Lex)

AI relevance

An AI system must know which legal test applies.

A system cannot use one generic questionnaire for every type of financial service.

20. Case 5 — Banco Primus, C-421/14

CJEU, 26 January 2017

Area

Consumer credit and unfair contractual terms.

Principle

The CJEU examined the protection of consumers against unfair contractual terms and the role of national courts in ensuring effective consumer protection.

AI relevance

An AI financial-adviser contract may contain clauses such as:

“The AI provider accepts no responsibility for any investment loss.”

Such clauses do not automatically eliminate mandatory consumer or regulatory protections.

The court must examine the applicable consumer-law regime and the contractual circumstances.

This is an analogical authority, rather than an AI-investment-advice case.

21. Case 6 — Kásler v OTP Jelzálogbank, C-26/13

CJEU, 30 April 2014

Area

Consumer financial contracts and transparency.

Principle

The CJEU emphasised substantive transparency and the consumer's ability to understand the economic consequences of contractual terms.

AI relevance

The same concept is particularly important for AI financial services.

A consumer may technically receive thousands of lines of AI-generated information but still not understand:

why the product was recommended;

what risks exist;

what fees apply;

whether the adviser receives commissions;

why the algorithm selected one product rather than another.

Thus:

Information quantity ≠ meaningful transparency.

This is an analogical consumer-law authority.

22. Case 7 — Amazon EU, C-649/17

CJEU, 10 July 2019

Area

Online platforms and consumer information.

Relevance

The case concerned information obligations in an online environment.

Although not an investment-adviser case, it is useful for understanding how EU consumer law applies to digitally delivered services.

AI relevance

A financial service delivered through:

app + chatbot + automated recommendation

does not automatically escape consumer-information obligations.

The digital interface may therefore become part of the evidentiary record.

23. Case 8 — Meta Platforms, C-252/21

CJEU Grand Chamber, 4 July 2023

Area

Personal-data processing, profiling and competition.

The case concerned Meta's combination and use of personal data in the context of its social-network service.

The CJEU recognised that data-protection compliance can be relevant within competition-law analysis, subject to the institutional roles of the relevant authorities.

AI financial-adviser relevance

AI investment systems frequently process:

income information;

investment history;

financial objectives;

behavioural information;

transaction history.

Therefore:

AI advice + large-scale profiling + market power

can create overlapping GDPR and competition-law issues.

This is an analogical authority rather than an investment-advice case.

24. Case 9 — SCHUFA Holding, C-634/21

CJEU, 7 December 2023

Area

Automated scoring and GDPR.

The case concerned automated credit scoring and Article 22 GDPR.

AI relevance

Although credit scoring is not identical to investment advice, the underlying technological issue is closely related:

machine-generated score → consequential financial decision.

This case is therefore highly useful when analysing:

automated financial scoring;

AI risk classification;

algorithmic decisions;

meaningful human intervention.

The important distinction is that the precise application of Article 22 depends on the statutory conditions and facts.

25. Case 10 — Dun & Bradstreet Austria, C-203/22

CJEU, 27 February 2025

Area

Automated decision-making and explanation.

The CJEU considered the information that must be provided concerning automated decision-making so that an affected person can understand and challenge the decision.

AI financial-adviser relevance

This is particularly important where a financial AI says:

“Your portfolio should be high risk.”

The client may ask:

“Why?”

The relevant legal framework can require meaningful information concerning the logic involved, while also protecting matters such as trade secrets and third-party rights.

Principle

AI complexity is not itself a justification for complete opacity.

This is one of the strongest modern European authorities for AI-related financial decision-making.

26. Case-Law Summary Table

CaseLegal areaRelevance to AI financial adviser
Genil 48, C-604/11MiFID investment advice/suitabilityVery high
Banif Plus Bank, C-312/14Scope of MiFIDHigh
Mastromartino, C-53/18Financial advisers/tied agentsHigh
Banco Primus, C-421/14Consumer financial contractsAnalogical
Kásler, C-26/13Financial transparencyAnalogical
Amazon EU, C-649/17Digital consumer informationAnalogical
Meta Platforms, C-252/21Data/profiling/competitionAnalogical
SCHUFA, C-634/21Automated financial scoringVery high
Dun & Bradstreet Austria, C-203/22Automated decisions/explanationVery high

Thus there are more than six relevant authorities, while the cases most directly connected to AI-style financial decision-making are Genil 48, Mastromartino, SCHUFA and Dun & Bradstreet.

27. Liability of the AI Provider

There are potentially several actors.

A. Investment firm

Usually the central regulated entity.

B. AI developer

May have contractual/product liability exposure depending on the relationship and applicable law.

C. Cloud provider

Generally not automatically liable merely because its infrastructure hosted the system.

D. Data provider

Potential responsibility may arise where inaccurate or unlawfully supplied data contributes to the advice.

E. Human adviser

Potential responsibility may arise where the human adviser:

ignored obvious AI errors;

failed to supervise;

approved unsuitable recommendations;

entered incorrect client data.

The precise allocation depends on contract, regulatory status, national civil law and causation.

28. Product Liability and AI

A separate issue is whether an AI financial-advisory system can be treated as a defective product under applicable European product-liability rules.

Possible defects include:

defective software;

incorrect model;

cybersecurity vulnerability;

inadequate instructions;

unsafe AI functionality.

However, financial loss caused by bad investment advice is not automatically identical to physical injury or property damage, so the precise product-liability route must be analysed carefully.

Contract and professional-liability rules may be more directly relevant in many cases.

29. Causation

Investment litigation has a major causation problem.

Suppose:

AI recommends Stock X → investor buys → Stock X falls 40%.

The loss does not automatically prove misconduct.

The claimant may need to establish:

AI breach → decision to invest → transaction → loss

and address alternative causes.

For example:

general market collapse;

investor's own subsequent decisions;

independent market information;

failure to follow warnings;

extraordinary events.

30. “Loss of Chance” Issues

Investment losses may involve arguments about:

“What would the investor have done if proper advice had been provided?”

For example:

AI recommends Product A.

Had correct advice been provided:

investor would have selected Product B.

The claimant may need to establish the counterfactual investment and resulting difference.

This makes expert evidence extremely important.

31. Evidence in AI Financial-Adviser Litigation

Important evidence can include:

Client records

risk questionnaire;

financial information;

investment objectives;

sustainability preferences.

AI records

prompts;

model outputs;

recommendation logs;

model versions;

decision records;

system alerts.

Technical evidence

training data;

validation tests;

model documentation;

error rates;

audit reports.

Financial evidence

transaction records;

account statements;

commissions;

fees;

portfolio performance.

Governance evidence

internal AI policies;

human-review procedures;

risk assessments;

compliance reports.

32. Model-Version Problem

AI systems can change over time.

For example:

Model V1 → recommendation made
Model V2 → recommendation investigated
Model V3 → current system.

The claimant may therefore ask:

Which model actually generated the disputed advice?

A failure to maintain adequate records can make litigation substantially more complicated.

MiFID II's organisational and reporting requirements make record keeping particularly significant.

33. AI Hallucination Defence

A provider might argue:

“The AI generated the statement unexpectedly.”

That is not necessarily a complete defence.

The more important questions are:

Was the AI appropriately tested?

Were safeguards implemented?

Was human monitoring required?

Were users warned about limitations?

Was the AI used for a regulated service?

Did the provider know about recurring errors?

Was the system reasonably suitable for the intended use?

ESMA has specifically highlighted the need for quality assurance and controls around AI systems used in investment services. (ESMA)

34. Public AI Chatbots vs Regulated Robo-Advisers

This distinction is extremely important.

Public AI chatbot

Example:

User asks a general-purpose AI: “Which stocks should I buy?”

The chatbot may not itself be a regulated investment firm.

ESMA warned in 2025 that publicly available AI tools can produce inaccurate or misleading investment information and may not be subject to obligations to act in the investor's best interest. (ESMA)

Regulated AI financial adviser

A licensed investment firm deliberately deploys an AI system to provide personalised investment advice.

Here:

MiFID II responsibilities remain with the investment firm.

This distinction can fundamentally change the legal analysis.

35. Contractual Liability

An AI advisory agreement may contain:

scope of service;

investment mandate;

risk profile;

fees;

limitations;

disclaimers;

termination;

data processing;

dispute resolution.

A claimant may allege:

The AI advice failed to conform to the contractual advisory mandate.

The court may then examine:

contractual terms;

mandatory regulatory obligations;

professional standards;

actual AI behaviour;

causation;

damages.

Mandatory regulatory duties cannot necessarily be neutralised by a broad disclaimer.

36. Consumer Protection

Where the client is a consumer, additional rules may apply.

Potentially problematic statements include:

“Our AI always selects the optimal investment.”

“AI guarantees superior returns.”

“Zero-risk AI investing.”

Such statements could create issues concerning:

misleading commercial practices;

unfair terms;

transparency;

consumer information.

The precise consequences depend upon the applicable national implementation and facts.

37. Remedies

Potential remedies include:

1. Compensation

For legally recoverable financial or non-material damage.

2. Rescission or other contractual relief

Depending on national contract law.

3. Restitution

Where legally available.

4. Injunction

Stopping unlawful AI-advisory practices.

5. Corrective recommendation

Reassessing the client's portfolio.

6. Data correction

Correcting inaccurate client information.

7. Human review

Reviewing an AI-generated recommendation.

8. Regulatory sanctions

Separate from the client's private civil claim.

38. Defences

An investment firm might argue:

No regulated advice

The system only provided general information.

No breach

The recommendation complied with the client's risk profile.

Market loss rather than misconduct

The investment was suitable but subsequently lost value.

Client supplied incorrect information

The suitability assessment depended on inaccurate client data.

Causation not established

The claimant would have invested anyway.

Contributory fault

The client ignored warnings or independently changed the investment strategy.

Extraordinary market event

The loss resulted from an unforeseeable market event rather than the advisory error.

Each defence must be evaluated under the relevant national law and regulatory framework.

39. European AI Financial-Adviser Liability Model

A useful legal model is:

INPUT

↓

Client information

↓

AI PROCESSING

Risk model + investment model + product database

↓

RECOMMENDATION

Buy / sell / hold / portfolio allocation

↓

EXECUTION

Transaction

↓

LOSS

↓

LEGAL ANALYSIS

Duty + AI Error + Unsuitable Advice + Causation + Damage

40. Six Core Questions for a Court

A court dealing with an AI financial-adviser dispute could essentially ask:

Question 1

Was the service actually investment advice or portfolio management?

Question 2

Was the firm subject to MiFID II or another regulatory regime?

Question 3

Did the firm obtain adequate information about the client?

Question 4

Was the AI-generated recommendation suitable?

Question 5

Did the provider have adequate controls and supervision?

Question 6

Did the alleged breach cause legally recoverable damage?

41. Special Importance of Article 54

For examination purposes, MiFID II Delegated Regulation Article 54 deserves special attention.

Its central idea is:

Automated system ≠ transfer of responsibility.

Where investment advice or portfolio management is automated or semi-automated, the investment firm remains responsible for the suitability assessment. (EUR-Lex)

This directly answers one of the central legal questions:

“Can a bank escape liability because its AI made the recommendation?”

The use of automation does not by itself remove the investment firm's suitability responsibility.

42. Difference Between Bad Advice and Bad Investment

This distinction is essential.

Bad investment

Suitable investment + unforeseen market loss.

Not necessarily misconduct.

Bad advice

Unsuitable investment + inadequate assessment + regulatory/contractual breach.

Potential liability.

Therefore:

Investment loss ≠ automatic adviser liability.

The claimant must connect the loss to a legally actionable failure.

43. Exam-Oriented Conclusion

AI financial-adviser misconduct in Europe is governed by a multi-layered legal framework rather than a single AI-liability statute.

The most important layer is MiFID II, particularly its suitability, best-interest, disclosure, conflicts and organisational requirements. Article 54 of the MiFID II Delegated Regulation is particularly significant because it expressly preserves the investment firm's responsibility when advice or portfolio management is provided through an automated or semi-automated system. (EUR-Lex)

The CJEU's Genil 48 case provides an important foundation for understanding suitability and appropriateness obligations; Mastromartino helps determine responsibility within the financial-adviser structure; SCHUFA provides important guidance on automated financial scoring; and Dun & Bradstreet Austria strengthens the importance of meaningful information concerning automated decision-making. (Infocuria)

ESMA's current guidance reinforces the practical position: financial firms using AI must continue complying with MiFID II and should address bias, data quality, over-reliance, privacy, security, suitability and quality assurance. (ESMA)

Ultra-basic revision formula

AI FINANCIAL ADVISER LIABILITY = DUTY + CLIENT DATA + SUITABILITY + AI OUTPUT + SUPERVISION + CAUSATION + LOSS + REMEDY

One-line exam answer

AI financial-adviser misconduct in Europe arises where an automated or semi-automated investment service breaches applicable suitability, best-interest, disclosure, organisational, data-protection or contractual duties and that breach causes legally recoverable harm; automation itself does not transfer the investment firm's regulatory responsibility to the AI system.

LEAVE A COMMENT