AI and Legal Liability: What the Law Can Do, and Where It Still Falls Short
- Stéphane Guy

- 5 hours ago
- 10 min read
A self-driving car brakes for no reason on the highway. A hiring algorithm systematically screens out women. An AI-assisted diagnosis sends a patient toward the wrong treatment. In every one of these cases, one question lands with startling clarity: who's responsible?
The short answer: not the AI. It has no legal personhood, it can't be sued, and it can't be convicted. It's a tool, sophisticated and often opaque, but a tool nonetheless. That leaves the question of who, in the human chain that designed, deployed, or operated it, actually bears the loss. And that's where things get genuinely complicated.
European and national law is shifting fast on this front. The AI Act, in force since August 2024, imposes a new layer of obligations. But a directive specifically designed to govern AI civil liability was abandoned by the European Commission in February 2025. The gap persists, and in the meantime, AI systems keep making decisions that touch real lives.

In Short
An AI is not a legal person: it cannot be held liable. When harm occurs, courts turn to its developers, deployers, or users instead.
U.S. and EU frameworks lean on general tort principles. In France, primarily Civil Code Articles 1240 and 1242, written for conventional harm and poorly suited to the opacity of AI systems.
The EU AI Act (2024) sorts AI by risk level and imposes obligations on providers and deployers, backed by fines of up to €35 million or 7% of global annual turnover.
The EU's dedicated AI Liability Directive was shelved in February 2025 and formally withdrawn later that year, leaving a regulatory vacuum that individual member states must now fill on their own.
The core obstacle remains the "black box" problem: proving an AI system caused a specific harm is technically and legally difficult, especially when the system keeps learning and evolving after deployment.
A Machine That Decides, But Answers to No One
Let's start with the problem in its simplest form. Under tort law, establishing liability requires three things: a fault, a harm, and a causal link between them. In French law, that triptych sits in Civil Code Article 1240, which states that any human act causing harm to another obliges the person at fault to make repair.*
An AI doesn't fit this framework. It has no intent, no will, and none of the legal personhood that humans, and, under certain conditions, companies or associations, possess.
That might sound obvious. But it's less obvious once you consider how many everyday decisions AI systems now make with little real human oversight: résumé screening, credit scoring, symptom triage, content moderation... In every one of these, when something goes wrong, the question of who answers for it stays wide open.
The Human Chain Behind Every Algorithm
If the AI itself answers to no one, the humans who designed it, brought it to market, and used it can. But identifying them, and each one's share of the harm, is its own challenge.
In the value chain of an AI system, three roles typically emerge:
The developer (or provider) designs the model, choosing training data, technical architecture, and optimization targets. If bias is baked in at this stage, liability can trace back to this point in the chain.
The deployer is the company or institution that integrates the system into a real product or service: a hospital running diagnostic software, a recruiter automating résumé screening, an insurer automating claims decisions... Deployers carry a duty of vigilance over what the AI actually produces.
The end user, finally, is whoever operates the tool day to day: a lawyer who publishes an AI-drafted legal brief without review, a doctor who signs off on an algorithmic diagnosis without double-checking... They remain accountable for their own oversight.
Picture a law firm using AI to draft contracts. If a configuration error produces unenforceable clauses and a client suffers a loss, the firm's own duty of diligence, not the AI's design, is what a court will scrutinize. The human operator is usually first in line precisely because they retain effective control of the tool.

What Civil Law Says, and Where It Falls Short for AI
In most common-law and civil-law jurisdictions, courts reach for general tort principles when AI causes harm. In France specifically, two provisions do most of the work.
Article 1240 sets out fault-based liability: the victim must prove a fault occurred, that it caused a specific harm, and that a link exists between the two. In an AI context, that's often an uphill climb. AI systems are complex because of the large volumes of data involved, their dependence on algorithms, and the opacity of the decision-making process, all of which make it difficult to predict how an AI-assisted product will behave or to pinpoint the possible causes of harm.
Article 1242 opens an alternative path, liability for things under one's care. A person can be held liable for harm caused by an object in their custody, without the victim needing to prove fault at all.*
That principle could extend to AI systems. In practice, if an AI-powered robot injures someone in a public space, whoever holds custody of that robot can be held liable, no fault required on the victim's part. This regime is more protective for victims.
But it raises a question legal scholars are actively debating: who is the "custodian" of an AI system once it updates itself, evolves autonomously, and produces decisions no one can fully predict anymore? The AI Act doesn't answer that question. Victims can still pursue a system's designer or user depending on the circumstances, but pinning down the custodian in a concrete case remains genuinely open.
The AI Act: Rules for Risk, Not Rules for Victims
Regulation (EU) 2024/1689 aims to encourage the development and uptake of safe and trustworthy AI systems across the EU single market, in both the private and public sectors, while protecting citizens' health, safety, and fundamental rights. It is the world's first comprehensive legal framework for AI.
Its organizing principle is risk classification. The regulation sets out risk-based rules covering the placing on the market, putting into service, and use of certain AI systems, sorting them into four tiers: unacceptable risk (banned outright), high risk, limited risk (transparency obligations), and minimal risk. High-risk systems, in healthcare, judicial processes, employment, and critical infrastructure, face strict documentation, traceability, and impact-assessment requirements. The maximum penalty for non-compliance with the rules on prohibited AI uses is the higher of a €35 million fine or 7% of worldwide annual turnover.*
But the AI Act is a compliance and prevention text, not a compensation mechanism. It tells companies how to build and deploy responsibly. It doesn't say who pays the victim when something goes wrong. That's precisely the gap a dedicated directive was supposed to close, and didn't.
The Abandoned Directive: A Retreat That Worries Legal Experts
This was 2025's legal plot twist. The European Commission does not plan to renew debate on draft legislation for handling harms caused by AI, citing a lack of agreement as the technology industry pushed for simpler regulation. The decision was noted in the Commission's 2025 work program, adopted February 11 and presented to the European Parliament on February 12. The formal withdrawal was confirmed later that year: the European Commission formally withdrew its proposals for an AI Liability Directive and a Standard Essential Patents regulation, despite resistance from some lawmakers and member states.*
This wasn't a minor procedural footnote. The proposed directive would have eased the burden of proof for victims by allowing a rebuttable presumption of causality and permitting national courts to order disclosure of evidence. Those tools no longer exist at EU level.
What remains is the revised Product Liability Directive (EU) 2024/2853, adopted in October 2024, which modernizes a 40-year-old framework. It confirms strict liability for manufacturers and explicitly extends the definition of "product" to cover software, digital manufacturing files, and, by extension, AI systems. Software is now treated as a product for no-fault liability purposes regardless of how it's supplied, on-device, cloud, or SaaS.*
However, while the directive excludes purely autonomous services from its scope, it does cover connected services essential to a product's operation. It retains a "development-risk" defense for manufacturers, but that defense is now tightly bound: it cannot be invoked if a defect stems from an AI system's continuous learning or from a software update the manufacturer controlled. The goal is to keep companies accountable even as their systems keep evolving after launch.

Real Cases, Real Precedent
Legal theory is now meeting courtroom reality, cautiously, but unmistakably.
First, Italy. In a ground-breaking ruling handed down on December 31, 2020, the employment section of a tribunal in Bologna found that an algorithm used by food-delivery platform Deliveroo was discriminatory. The algorithm, called "Frank," discriminated against couriers because it failed to distinguish between legally protected reasons for not working, illness, or exercising a protected right to strike, and more trivial reasons for underperforming. The court ordered Deliveroo to pay €50,000 to the applicants, plus their legal costs, and to publish the ruling on its own website.*
More recently, in the United States: a Florida jury found Tesla liable to pay $243 million to the victims of a 2019 fatal crash involving an Autopilot-equipped Model S. Driver George McGee had run stop signs and driven well over the speed limit while distracted, his own negligence was never in dispute. But jurors awarded the estate of Naibel Benavides Leon and her boyfriend Dillon Angulo $129 million in compensatory damages plus $200 million in punitive damages, holding Tesla liable for roughly a third of the compensatory total. The case turned on whether Tesla oversold Autopilot's capabilities and encouraged drivers to disengage from monitoring the road, the system didn't stop McGee from behaving recklessly, and it didn't stop the car from entering a road it was never designed for. A federal judge upheld the verdict in February 2026, rejecting Tesla's bid to have it overturned.*
Together, these rulings sketch out a doctrine that's starting to stabilize: liability follows supervision. Whoever delegated a decision to AI without checking its outputs, or brought a system to market without testing it adequately, is the one who answers for it. It's not a coherent regime yet, but it's the beginning of real case law.
The Black Box: The True Obstacle in Court
The problem every legal expert raises is proof. For a victim to be compensated, they must show that the AI system actually caused their harm, not a concurrent human error, not simple bad luck.
Modern AI systems, like deep neural networks, large language models, reinforcement-learning algorithms… run on architectures whose decision-making processes are notoriously hard to trace, even for their own developers. This is the "black box" problem, and it's a genuine obstacle in court.
The EU's revised Product Liability Directive offers partial tools here. It introduces presumptions of defectiveness, shifting the burden onto manufacturers once harm clearly resulted from a product. It also mandates disclosure of technical evidence, useful in complex cases like medical AI. A claimant who presents a plausible case can ask a court to order disclosure of relevant technical evidence, and if the company refuses, the court presumes the product was defective.
That's real progress. But it's still incomplete.
AI systems that evolve through updates or autonomous learning present unique challenges. The directive extends manufacturer liability to defects caused by faulty updates or unforeseen changes in an AI's learning process, but in practice, proving that a specific update caused a specific harm remains extraordinarily difficult.
What This Actually Changes for AI and the Law
The invisible dangers of generative AI aren't limited to misinformation or manipulation, they extend into a legal gray zone where victims struggle to secure compensation. And beyond compensation itself, recognition matters: it's what opens the door to legal precedent and builds broader awareness of a pattern likely to multiply as AI embeds itself deeper into sensitive, high-stakes decisions.
For companies, the lesson is straightforward: folding AI into a hiring, credit, diagnostic, or contracting decision doesn't remove liability. It relocates it, it doesn't erase it. Evidentiary hurdles multiply because of the number of actors involved and the often-opaque nature of systems trained on millions of data points. The same dynamic runs through the real risks of AI and automation for society more broadly: automation doesn't remove human accountability, it just makes it harder to locate.
For individuals harmed by an algorithmic decision, remedies exist, but the path is still uneven. General tort law applies. Specific remedies are starting to emerge through the AI Act. And case law, still fragile but genuinely forming, is taking shape in courts across the U.S. and Europe.
The real open question, one the law hasn't resolved yet, concerns autonomous AI agents: systems capable of chaining decisions together, signing contracts, and acting on financial markets. When an entity like that causes harm, who answers? The debate over legal personhood for AI is no longer just philosophical. It's becoming urgent.

FAQ
Can an AI be held legally liable?
No. Under both French and EU law, an AI has no legal personhood. It can't be prosecuted or convicted. When harm occurs, liability is sought from the humans or companies that designed, deployed, or used it.
Who's responsible if AI makes a bad call inside my company?
Generally, it's the deployer, the company that integrated the AI system into its decision-making process, that bears liability toward third parties. Courts have consistently held that delegating a decision to an algorithm doesn't remove the duty of oversight.
What does the AI Act actually change about liability?
It imposes transparency, traceability, and risk-assessment obligations on providers and deployers, backed by significant fines. But it doesn't create a direct right to compensation for victims, that's its biggest blind spot.
Why was the EU's AI liability directive abandoned?
The European Commission pulled it from its work program in February 2025, citing a lack of political agreement, and formally withdrew it later that year. The move reflects a broader push to lighten AI regulation in the name of innovation, but it leaves a real legal gap for victims.
What can you do if you're harmed by a faulty algorithmic decision?
You can pursue a claim under general tort law (fault-based or strict liability, depending on jurisdiction). For high-risk systems covered by the AI Act, you can also request access to the system's technical documentation. Consulting a lawyer who specializes in technology law is strongly advisable.
Is a doctor liable if a medical AI gets it wrong?
Potentially, yes. The physician remains responsible for the final clinical decision, even when it's AI-assisted, human validation of a diagnosis or treatment remains a professional obligation. At the same time, the software's manufacturer can also be held liable if the system itself was defective.




Comments