AI Liability: Who Is Responsible When Artificial Intelligence Causes Harm?
Quick Answer: Liability for AI-related harm depends on the facts, applicable jurisdiction, legal relationship between the parties and the type of harm involved. Potentially responsible parties can include AI developers, manufacturers, providers, deployers, operators, businesses using AI and other participants in the technology supply chain. Existing legal doctrines such as negligence, contract, consumer protection and product liability can apply, while newer legislation is increasingly addressing software and AI-specific risks.
An autonomous vehicle makes a dangerous decision.
A medical AI system produces an incorrect recommendation.
A recruitment algorithm systematically rejects qualified candidates.
A financial AI system incorrectly flags a customer as fraudulent.
A generative AI application produces false allegations about an individual.
A security system incorrectly identifies an innocent person as a threat.
Who is responsible?
The AI developer?
The company that purchased the system?
The employee who relied upon it?
The company that deployed it?
The manufacturer of the underlying hardware?
Or the AI provider?
Artificial intelligence creates a difficult liability problem because multiple actors can participate in the AI lifecycle.
An AI system may be:
- Designed by one company.
- Trained by another.
- Hosted by a third company.
- Integrated into a product by a fourth company.
- Configured by a customer.
- Used by an employee.
- Updated continuously after deployment.
When something goes wrong, determining responsibility can therefore be considerably more complicated than identifying a single manufacturer.
This article examines the emerging law of AI liability, including negligence, product liability, software defects, causation, provider responsibility, deployer responsibility and the changing European regulatory framework.
Legal disclaimer: This article provides general educational information and is not legal advice. Liability rules differ substantially between jurisdictions and depend on the facts of each case.
Key Takeaways
- There is no single universal rule assigning liability for every AI-related harm.
- Existing legal doctrines can apply to AI systems.
- Potential liability can arise through negligence, contract, consumer protection or product liability.
- Software can increasingly fall within product-liability regimes.
- The EU's new Product Liability Directive expressly includes software and AI systems within the definition of product.
- The EU Product Liability Directive applies to products placed on the market or put into service after 9 December 2026.
- Manufacturers can remain responsible for certain defects arising through software updates or continuous learning when the relevant software remains within their control.
- AI providers, manufacturers and deployers may have different legal responsibilities.
- Causation can be particularly difficult where AI systems are complex or continuously changing.
- Documentation and logging can become critical evidence in AI-liability disputes.
- Contractual allocation of risk can be important but cannot necessarily eliminate mandatory liability rules.
- Businesses should incorporate liability assessment into AI governance before deployment.
What Is AI Liability?
Quick Answer: AI liability refers to the legal responsibility of individuals or organisations for harm caused by an artificial-intelligence system or by the way an AI system is developed, supplied, deployed or used.
AI liability is not necessarily a separate legal category.
In many cases, existing legal doctrines can determine responsibility.
For example:
- A negligent developer may face negligence liability.
- A defective AI-enabled product may trigger product liability.
- A company may breach a contract involving an AI service.
- An AI deployment may violate consumer-protection requirements.
- An AI decision may create discrimination liability.
The applicable legal route depends on the circumstances.
Why Is AI Liability Difficult?
Quick Answer: AI liability is difficult because AI systems can involve multiple actors, complex technical processes, probabilistic outputs and continuously changing models.
Traditional products are often relatively predictable.
A manufacturer designs a product.
The product is manufactured.
The product is sold.
The consumer uses it.
If a defect causes harm, the liability analysis can focus on the product and its manufacturer.
AI can be different.
A model may change through:
- Updates.
- Retraining.
- New data.
- Fine-tuning.
- Continuous learning.
- Changes in deployment conditions.
The system may therefore behave differently after it has entered the market.
Who Can Be Liable for AI Harm?
Quick Answer: Depending on the legal framework and facts, potentially liable parties can include developers, manufacturers, providers, deployers, operators, distributors, importers and businesses using AI systems.
| Actor | Potential Responsibility |
|---|---|
| AI developer | Design and development defects |
| AI provider | System provision and contractual obligations |
| Manufacturer | Defective AI-enabled product |
| Deployer | Improper implementation or use |
| Operator | Operational failures |
| Distributor | Supply-chain responsibilities |
| Employer | Workplace AI decisions and deployment |
| Vendor | Contractual and service failures |
Not every actor will be liable in every case.
The purpose of identifying the actors is to determine where legal responsibility may potentially arise.
Can AI Itself Be Liable?
Quick Answer: Under current mainstream legal frameworks, AI systems are not generally treated as independent legal persons capable of bearing liability in the same manner as human beings or corporations.
An AI system does not normally have:
- Independent legal personality.
- Its own assets.
- Independent contractual capacity.
- Human legal responsibility.
Therefore, legal systems generally allocate responsibility to human or corporate actors associated with the system.
What Is AI Developer Liability?
Quick Answer: AI developers may face liability where their development, design, testing or implementation falls below applicable legal standards and causes legally recognised harm.
Potential issues can include:
- Defective design.
- Inadequate testing.
- Failure to address known risks.
- Inadequate security.
- Insufficient warnings.
- Misleading representations.
Whether these issues create legal liability depends on the applicable law and evidence.
What Is AI Provider Liability?
Quick Answer: AI providers can face contractual, regulatory or tort-related consequences depending on their role and the circumstances of the harm.
A provider may supply:
- A general-purpose AI model.
- An AI API.
- An AI-powered software application.
- An AI-enabled service.
- An AI component integrated into another product.
The legal responsibilities can differ substantially between these scenarios.
What Is AI Deployer Liability?
Quick Answer: A deployer can potentially be responsible where an AI system is improperly configured, implemented or used.
For example, a business may purchase a generally reliable AI recruitment system but configure it in a way that produces discriminatory outcomes.
The resulting liability analysis may therefore concern not only the developer but also the organisation that deployed the system.
What Is AI Operator Liability?
Quick Answer: An operator may face responsibility where an AI system is used improperly, maintained inadequately or operated contrary to established safeguards.
This is particularly important where humans are expected to supervise AI systems.
If an employee ignores an obvious warning and blindly follows an AI recommendation, the legal analysis may differ from a case in which the AI system failed despite proper human supervision.
AI Liability and Negligence
Quick Answer: Negligence can potentially apply when a person or organisation owes a duty of care, breaches that duty and causes legally recognised harm.
A simplified negligence framework involves:
- Duty.
- Breach.
- Causation.
- Damage.
AI can complicate each stage.
What level of care should a reasonable AI developer exercise?
How much testing is sufficient?
What warnings should be provided?
When should a system be withdrawn?
These questions will often depend on the technology and use case.
What Is AI Product Liability?
Quick Answer: AI product liability concerns responsibility for harm caused by defective products incorporating or consisting of AI or software.
This area is undergoing major legal development.
The EU's Directive (EU) 2024/2853 expressly modernises product-liability rules for new technologies and includes software and AI systems within the definition of product. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
Does the EU Product Liability Directive Cover AI?
Quick Answer: Yes. The new EU Product Liability Directive expressly includes software, including AI systems, within the definition of product.
The Directive explains that software can be supplied as a standalone product, integrated into another product or accessed through cloud and software-as-a-service arrangements. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024L2853&utm_source=chatgpt.com))
This is a major development because traditional product-liability frameworks were primarily designed around physical products.
When Does the New EU Product Liability Directive Apply?
Quick Answer: Directive (EU) 2024/2853 applies to products placed on the market or put into service after 9 December 2026. Member States must transpose the Directive by that date. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
This timing is particularly important for businesses operating in the European market.
Companies developing or deploying AI-enabled products should prepare for the new framework rather than waiting until the implementation deadline.
What Is a Defective AI Product?
Quick Answer: A product can potentially be defective where it does not provide the safety that a person is entitled to expect, taking into account relevant circumstances under the applicable legal framework.
For AI-enabled products, defects can potentially arise from:
- Design.
- Manufacturing.
- Software.
- Updates.
- Security vulnerabilities.
- Instructions.
- Warnings.
- Continuous learning.
Can Software Be a Defective Product?
Quick Answer: Under the new EU Product Liability Directive, software is expressly included within the concept of product.
The Directive states that software includes operating systems, firmware, computer programmes, applications and AI systems. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024L2853&utm_source=chatgpt.com))
This creates an important connection between software development and product-liability law.
What About AI Software Updates?
Quick Answer: Under the new EU framework, manufacturers can remain responsible for defects arising from software updates or upgrades within their control.
The Directive recognises that digital products can remain under manufacturer control after their initial placement on the market. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
This is particularly important for AI because models and software frequently change after deployment.
What About Continuous-Learning AI?
Quick Answer: The EU Product Liability Directive specifically recognises continuous learning as a circumstance that can affect product defectiveness when the AI system remains under the manufacturer's control.
The Directive provides that where a substantial modification occurs through a software update, upgrade or continuous learning of an AI system, the substantially modified product can be considered newly placed on the market or put into service when the modification occurs. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
This is highly significant for adaptive AI systems.
Who Is Liable Under the EU Product Liability Directive?
Quick Answer: The Directive identifies economic operators including manufacturers, manufacturers of defective components and, in certain circumstances, importers, authorised representatives and fulfilment service providers.
The Directive provides that manufacturers can be liable for defective products and defective components, while additional economic operators can be liable where the manufacturer is established outside the EU. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/2024-11-18/eng?utm_source=chatgpt.com))
Does AI Product Liability Require Proof of Negligence?
Quick Answer: The EU Product Liability Directive is based on no-fault liability for defective products, meaning the claimant does not have to prove manufacturer fault in the same way required by a negligence claim.
The European Union describes the system as allowing compensation claims based on proof of defect and causal connection without requiring proof that the manufacturer was at fault. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/en/LSU/?uri=CELEX%3A32024L2853&utm_source=chatgpt.com))
This is distinct from negligence-based liability.
What Is Causation in AI Liability?
Quick Answer: Causation connects the AI-related conduct or defect to the harm suffered by the claimant.
Causation can become particularly difficult when:
- Multiple systems contribute to the outcome.
- Humans modify AI outputs.
- AI models change over time.
- Third-party software is integrated.
- Large datasets influence the outcome.
Consider an AI medical system.
The model produces a recommendation.
A doctor reviews it.
The doctor accepts it.
The patient suffers harm.
Was the harm caused by:
- The AI model?
- The training data?
- The software developer?
- The hospital?
- The doctor?
- The deployment process?
These questions demonstrate why causation can become one of the central issues in AI-liability litigation.
Why Is Evidence Important in AI Liability?
Quick Answer: Evidence can be particularly important because AI systems may be technically complex and claimants may have limited access to information about how a system operated.
Important evidence can include:
- Model documentation.
- Training information.
- System logs.
- Version history.
- Model updates.
- Testing results.
- Risk assessments.
- Human interventions.
- Warnings.
- Incident reports.
Without adequate records, reconstructing an AI incident can be extremely difficult.
AI Liability and the Black Box Problem
Quick Answer: The “black box” problem refers to situations where the internal reasoning or operation of an AI system is difficult to understand or explain.
This can create difficulties for liability analysis.
If an AI system produces a harmful outcome but the parties cannot determine why, proving defect, negligence or causation may become more difficult.
This is why documentation and explainability can have legal importance beyond transparency alone.
Can AI Companies Be Liable for Hallucinations?
Quick Answer: AI-generated false information can create potential legal exposure depending on the context, representations made by the provider and the nature of the harm.
Potential areas include:
- Defamation.
- Consumer protection.
- Negligence.
- Contract.
- Professional liability.
A hallucinated answer in a casual conversation is not necessarily equivalent to a false statement used in a regulated professional service.
The context matters.
AI Liability for Medical Systems
Quick Answer: Medical AI can create particularly serious liability questions because incorrect outputs can potentially cause physical injury or other significant harm.
Governance should address:
- Clinical validation.
- Accuracy.
- Human oversight.
- Warnings.
- Updates.
- Patient safety.
- Record keeping.
AI should not be treated as a substitute for professional legal or clinical accountability merely because the technology produces a recommendation.
AI Liability in Employment
Quick Answer: Employers using AI for recruitment, promotion, performance evaluation or termination can face legal risks where automated systems produce discriminatory or otherwise unlawful outcomes.
Potential issues include:
- Discrimination.
- Privacy.
- Automated decision-making.
- Failure to supervise.
- Inadequate validation.
This connects AI liability with the employment-law issues discussed in Article #52.
AI Liability and Consumer Protection
Quick Answer: Consumer-protection laws can apply where businesses make misleading claims about AI systems or cause consumer harm through AI-enabled products or services.
Businesses should therefore ensure that statements about AI are accurate.
For example, claims that an AI system is:
- “100% accurate”.
- “Bias-free”.
- “Fully autonomous”.
- “Completely safe”.
can create legal risk if the claims cannot be substantiated.
In June 2026, the U.S. Federal Trade Commission proposed a policy statement concerning the application of its prohibition on deceptive acts or practices to companies marketing AI systems, illustrating the continuing consumer-protection dimension of AI governance. ([ftc.gov](https://www.ftc.gov/policy/public-comments/policy-statement-concerning-suppression-accuracy-artificial-intelligence-systems?utm_source=chatgpt.com))
AI Liability and Contract Law
Quick Answer: Contracts can allocate responsibilities between AI providers and customers, but contractual terms operate alongside mandatory statutory and tort rules.
AI contracts should address:
- Performance standards.
- Service levels.
- Accuracy representations.
- Indemnities.
- Liability caps.
- Security.
- Data protection.
- Intellectual property.
- Incident notification.
- Model changes.
Businesses should not assume that a liability clause automatically eliminates all possible legal exposure.
Can Companies Exclude AI Liability?
Quick Answer: Contractual exclusions can sometimes allocate commercial risk, but their enforceability depends on applicable law and the type of liability involved.
Some legal regimes impose mandatory liability rules.
For example, the EU Product Liability Directive requires Member States to ensure that liability under the Directive cannot be contractually excluded or limited against an injured person. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
Businesses therefore need jurisdiction-specific contractual advice.
AI Liability and Insurance
Quick Answer: Businesses deploying AI should consider whether their existing insurance arrangements adequately address AI-related risks.
Potential insurance categories can include:
- Professional liability.
- Cyber insurance.
- Product liability.
- Technology errors and omissions.
- Directors and officers insurance.
The appropriate coverage depends on the business and AI use case.
AI Liability Risk Matrix
| AI Use Case | Potential Harm | Primary Liability Concern |
|---|---|---|
| Autonomous vehicle | Personal injury | Product liability / negligence |
| Medical AI | Patient harm | Product / professional liability |
| Recruitment AI | Discrimination | Employment liability |
| Financial AI | Economic loss | Negligence / consumer protection |
| Generative AI | False information | Defamation / consumer / tort issues |
| Cybersecurity AI | Security failure | Contract / negligence / regulatory liability |
How Can Businesses Reduce AI Liability Risk?
Quick Answer: Businesses can reduce AI liability risk through appropriate governance, testing, documentation, human oversight, contractual controls and continuous monitoring.
- Maintain an AI inventory.
- Classify AI systems according to risk.
- Conduct legal review.
- Test systems before deployment.
- Document model performance.
- Establish human oversight.
- Monitor AI outputs.
- Maintain system logs.
- Review vendor contracts.
- Establish incident procedures.
- Maintain appropriate insurance.
- Review systems after updates.
- Retire systems that create unacceptable risks.
AI Liability Incident Response
Quick Answer: Organisations should have a documented procedure for responding when an AI system causes or may have caused harm.
A practical response process can include:
- Stop or restrict the affected system.
- Preserve evidence.
- Identify the affected individuals.
- Determine what happened.
- Identify the AI model and version.
- Review logs.
- Assess legal obligations.
- Notify relevant parties where required.
- Remediate the system.
- Document lessons learned.
What Should an AI Liability Audit Examine?
Quick Answer: An AI liability audit should assess whether the organisation has identified foreseeable risks and established appropriate controls.
- AI inventory.
- Risk classification.
- System documentation.
- Testing.
- Human oversight.
- Vendor contracts.
- Insurance.
- Incident records.
- Model updates.
- Security controls.
- Customer disclosures.
- Regulatory compliance.
AI Liability and the EU AI Act
Quick Answer: The EU AI Act establishes obligations concerning AI systems, but AI liability is not contained in one single provision of the Act. Liability can intersect with product-liability, consumer-protection, data-protection, employment and national civil-liability rules.
The EU's broader legislative approach therefore requires businesses to consider AI compliance and liability together.
The new Product Liability Directive is particularly significant because it expressly incorporates software and AI systems into the product-liability framework. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
Is There a Separate EU AI Liability Directive?
Quick Answer: The European Commission previously proposed an AI Liability Directive aimed at adapting non-contractual civil-liability rules to AI-related harm, but businesses should distinguish that proposal from the enacted EU Product Liability Directive.
The proposed AI Liability Directive sought to address evidence and causation difficulties associated with AI systems. ([eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/PIN/?uri=CELEX:52022PC0496&utm_source=chatgpt.com))
The legal position should therefore not be described as though the proposal itself were already an enacted standalone AI civil-liability regime.
Why Does AI Governance Matter for Liability?
Quick Answer: Strong AI governance can create evidence that an organisation identified and managed foreseeable risks.
Governance records can include:
- Risk assessments.
- Approval records.
- Testing reports.
- Vendor due diligence.
- Monitoring records.
- Incident reports.
- Human-review procedures.
These records can become important when an organisation must demonstrate how it managed an AI system.
Frequently Asked Questions
What is AI liability?
AI liability refers to legal responsibility for harm caused by an AI system or by the development, supply, deployment or use of an AI system.
Who is responsible when AI causes harm?
Responsibility depends on the facts and applicable law. Potentially responsible parties can include developers, providers, manufacturers, deployers, operators and businesses using AI.
Can AI itself be sued?
AI systems are not generally treated as independent legal persons capable of bearing liability like corporations or human beings.
Can AI developers be liable?
Potentially. Liability can arise where applicable legal requirements concerning design, development, testing, warnings, security or other responsibilities are breached and harm results.
Can companies be liable for AI decisions?
Yes. Businesses can potentially face liability for the way they deploy, configure, supervise or rely on AI systems, depending on the applicable law.
Is AI software covered by product liability?
In the EU, the new Product Liability Directive expressly includes software, including AI systems, within the definition of product.
When does the new EU Product Liability Directive apply?
The Directive applies to products placed on the market or put into service after 9 December 2026, with Member States required to transpose it by that date.
Does AI product liability require proof of negligence?
The EU Product Liability Directive establishes a no-fault liability framework for defective products. Claimants must establish the relevant defect, damage and causal connection rather than proving manufacturer negligence in the traditional sense.
Can continuously learning AI create liability?
Yes. The EU Product Liability Directive specifically addresses substantial modifications arising from software updates, upgrades and continuous learning where the AI system remains within the manufacturer's control.
What is AI negligence?
AI negligence refers to potential liability arising where a person or organisation fails to meet an applicable duty of care in developing, deploying, supervising or operating an AI system and that failure causes legally recognised harm.
Can AI hallucinations create legal liability?
Potentially. The legal consequences depend on the context, the nature of the statement, representations made about the AI system and the harm caused.
Can businesses be liable for AI discrimination?
Yes. Organisations deploying AI in employment, housing, credit, insurance or other regulated contexts may face liability where AI systems produce unlawful discriminatory outcomes.
Can AI providers limit their liability through contracts?
Contracts can allocate certain commercial risks, but mandatory statutory liability rules may restrict contractual exclusions or limitations.
Why is causation difficult in AI cases?
AI systems can involve multiple actors, complex models, changing data, software updates and human intervention, making it difficult to determine precisely how a particular harmful outcome occurred.
What evidence matters in AI liability cases?
Important evidence can include model versions, system logs, training documentation, testing records, risk assessments, human interventions, warnings and incident reports.
Should businesses insure against AI liability?
Businesses should assess whether their existing insurance policies adequately address the risks associated with their AI activities and whether additional technology, cyber, professional or product-liability coverage is appropriate.
Conclusion
Artificial intelligence does not eliminate legal responsibility.
It changes the circumstances in which responsibility must be determined.
An AI system may produce an unexpected result, but the legal system still has to ask:
Who created it?
Who supplied it?
Who deployed it?
Who controlled it?
Who failed to identify the risk?
And what caused the harm?
There is no universal answer.
Different legal doctrines can apply depending on the circumstances.
Negligence may be relevant where a party failed to exercise reasonable care.
Contract law may govern relationships between AI providers and customers.
Consumer-protection law may apply where AI systems are marketed through misleading claims.
Employment law can become relevant when AI makes or influences workplace decisions.
Privacy law can apply where AI processes personal information.
Product liability can become relevant where defective AI or software causes legally recognised damage.
The European Union's new Product Liability Directive represents an especially important development.
It expressly includes software, including AI systems, within the definition of product and recognises that software updates, upgrades and continuous learning can affect product defectiveness where the relevant system remains within the manufacturer's control. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
The Directive will apply to products placed on the market or put into service after 9 December 2026. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/dir/2024/2853/oj?utm_source=chatgpt.com))
For businesses, the practical lesson is clear.
AI liability should not be considered only after something goes wrong.
It should be addressed before deployment.
Organisations should know what AI systems they use, who controls them, what risks they create, how they were tested and what happens when they fail.
They should also maintain sufficient documentation to reconstruct significant AI decisions and incidents.
As AI becomes embedded into software, vehicles, medical devices, financial systems and consumer products, the distinction between “software risk” and “product risk” will become increasingly difficult to maintain.
The central principle of AI liability is therefore not that machines become legally responsible. It is that organisations must increasingly account for the human and corporate decisions surrounding the machines they build, supply and use.
Legal Disclaimer
This article is provided for general educational and informational purposes only. It is not legal, regulatory, product-liability, insurance or technology advice and does not create an attorney-client relationship. AI liability rules differ between jurisdictions and are developing rapidly. Businesses should obtain jurisdiction-specific advice before relying on any particular liability framework.
