EU AI Liability

The AI Liability Directive Proposal

The Proposal for a Directive on Adapting Non-Contractual Civil Liability Rules to Artificial Intelligence (the AI Liability Directive, COM(2022) 496 final), published by the European Commission on 28 September 2022, addresses one of the most pressing challenges in the regulation of emerging technologies: how to ensure effective legal redress for harm caused by AI systems. The proposal responds to the distinctive characteristics of AI — including opacity, autonomy, and complexity — that create particular difficulties for claimants seeking to establish liability under traditional tort law frameworks.

The Directive applies to claims for non-material harm caused by AI systems, complementing the revised Product Liability Directive. Its central innovation is a presumption of causality: where a claimant demonstrates that the defendant’s failure to comply with a relevant legal obligation (including obligations under the AI Act) contributed to the harm, and where it would be disproportionately difficult for the claimant to prove causation, the court shall presume a causal link between the non-compliance and the harm. The defendant may rebut this presumption by showing that alternative causes are more probable.

The Directive introduces a tailored disclosure of evidence mechanism, empowering courts to order the disclosure of relevant evidence concerning suspected AI systems where a claimant has presented plausible facts supporting a claim for damages. In determining proportionality, courts must balance the legitimate interests of all parties, including the protection of trade secrets and confidentiality. Where trade secrets are involved, courts must impose specific protective measures to ensure confidentiality while preserving access to essential evidence.

Product Liability Directive Revision

The Proposal for a Directive on Liability for Defective Products (COM(2022) 495 final) revises the existing Product Liability Directive (85/374/EEC) to address the challenges posed by AI, digital products, and the circular economy. The revised Directive expands the definition of product to include software, AI systems, and digital files, and clarifies that a product’s manufacturer remains liable where modifications occur through software updates or AI autonomous learning after the product has been placed on the market, provided the modification is within the manufacturer’s control.

The revised Directive updates the concept of defect to account for AI-specific characteristics. A product is defective where it does not provide the safety that a person is entitled to expect, taking into account: the presentation and instructions for use; the reasonably foreseeable use and misuse; the time when the product was placed on the market; product safety requirements, including cybersecurity updates; and the product’s ability to learn or acquire new features after being placed on the market. The requirement that safety expectations be assessed at the time of placing on the market is qualified for AI systems that continue to learn and evolve post-market.

The revision introduces a presumption of defectiveness where a claimant establishes that the product fails to meet safety requirements under EU law or relevant standards, and a presumption of causation where the product is of a type that typically causes the kind of damage suffered and the damage is consistent with the defect in question. Member States must ensure that national courts may order the disclosure of relevant evidence in the possession of the defendant.

Strict Liability for High-Risk AI

The AI liability framework establishes a layered approach to liability for AI systems, distinguishing between high-risk and non-high-risk applications. Under the revised Product Liability Directive, manufacturers of AI systems classified as high-risk under the AI Act are subject to strict liability for damage caused by defects in their products. The claimant need not prove fault or negligence; it suffices to show that the product was defective, that damage was suffered, and that a causal link exists between the defect and the damage.

The strict liability regime reflects the policy judgment that those who place high-risk AI systems on the market, deriving commercial benefit from their deployment, should bear the costs of harm that materialises from their operation. The manufacturer may raise the development risk defence, showing that the state of scientific and technical knowledge at the time the product was placed on the market was not such as to enable the discovery of the defect. However, this defence is limited in application to AI systems: where the defect arises from the autonomous behaviour of the AI system after being placed on the market, the manufacturer must demonstrate that it maintained adequate post-market monitoring and that the specific behaviour causing the harm was not reasonably foreseeable.

Defect Definition for AI Systems

The definition of defect in relation to AI systems raises distinctive legal questions. Traditional product liability law assesses defectiveness by reference to the reasonable safety expectations of the public at the time the product was placed on the market. For AI systems, this temporal reference point is complicated by the capacity of AI systems to change their behaviour through post-market learning. The revised Product Liability Directive addresses this by providing that a product may be considered defective where it fails to provide the safety that a person is entitled to have, even if the defect arises from the system’s autonomous behaviour after being placed on the market.

The Directive identifies three categories of defect relevant to AI systems: design defects, where the AI system’s architecture or training methodology produces systematically unsafe outcomes; information defects, where the manufacturer fails to provide adequate instructions, warnings, or transparency information; and post-market defects, where the manufacturer fails to implement necessary updates, cybersecurity measures, or corrective actions in response to emerging safety information. The manufacturer’s post-market monitoring obligations under the AI Act, including the obligation to report serious incidents, are relevant to determining whether the manufacturer has exercised appropriate care in addressing safety risks that become apparent after deployment.

Burden of Proof and Procedural Challenges

The AI Liability Directive addresses the fundamental asymmetry of information and expertise between claimants and defendants in AI-related litigation. Claimants face particular difficulty in establishing causation where AI systems are opaque, their decision-making processes are complex, and the relevant evidence is held exclusively by the defendant. The Directive’s rebuttable presumption of causation responds to this difficulty by shifting the evidential burden to the defendant once the claimant has established the defendant’s non-compliance with a relevant legal obligation.

Member States must ensure that their procedural rules enable courts to order the disclosure of evidence relating to specific AI systems that are suspected of having caused harm. The disclosure mechanism is limited to what is proportionate and necessary, and courts must impose protective measures for confidential information and trade secrets. The Directive does not harmonise national rules on standing, limitation periods, or the calculation of damages, leaving these matters to the procedural autonomy of Member States subject to the principles of equivalence and effectiveness.

Relationship with National Liability Regimes

The AI liability framework coexists with the national tort law regimes of Member States, which continue to govern areas not harmonised by EU legislation. The AI Liability Directive establishes minimum standards of protection, permitting Member States to maintain or introduce more favourable provisions for claimants. National liability regimes remain applicable to claims falling outside the scope of the Directive, including claims concerning pure economic loss not caused by death, personal injury, or damage to property, and claims based on fault-based liability for AI systems that are not classified as defective products.

The framework’s interaction with national strict liability regimes for inherently dangerous activities and with employer liability for AI systems used in the workplace will require detailed coordination. The Commission has indicated that the framework is intended as a first step, with further harmonisation possible in light of experience and technological development.

Conclusion

The EU’s AI liability framework represents a carefully calibrated response to the challenges that AI systems pose for traditional tort law. By combining targeted presumptions of causation, enhanced disclosure mechanisms, and an expanded concept of defect, the framework seeks to ensure that victims of AI-caused harm can obtain effective redress without imposing disproportionate burdens on AI developers and deployers. The framework’s interaction with national liability regimes and its adaptation to technological developments will be critical to its effectiveness in the years ahead.