Who is liable when an AI system causes damage
There is no separate liability regime for AI. Damage is attributed under ordinary contract and tort law, with the duties of the AI Act working as protective statutes and the reformed product liability rules covering software expressly.
There is no dedicated liability regime for AI. Ordinary contract and tort law apply, supplemented by product liability. What is new is what sits alongside them. The duties of the AI Act work as protective statutes, and the reformed product liability rules cover software expressly.
Alongside that stands the regulatory side. Breaches of the AI Act carry fines of up to 35 million euros or seven per cent of worldwide annual turnover, whichever is higher, with the lower figure capping the amount for small and medium-sized enterprises. Fines and damages do not exclude one another, they run side by side.
Three risks specific to AI
- Autonomy riskThe system takes on a life of its own in a way neither provider nor deployer had foreseen.
- Interaction riskThe system does not act by human standards, it imitates them. Damage arises from the interplay with people.
- Chaining riskAgents reach into external services. A fault in one component propagates along the whole chain.
Three routes on which claims arise
Between businesses there is considerable room to shape liability. The centrepiece is a precise intended-purpose clause, because the division of provider and deployer duties under Art. 25 AI Act hangs on it. Alongside it belong liability caps, an indemnity for use outside the intended purpose, warranties on compliance with the AI Act, and provisions on monitoring, incident reporting and updates. Towards consumers the room is narrow, since exclusions for life, body and health and for gross negligence are ineffective under section 309 no. 7 BGB.
Sections 823 et seq. BGB run into structural limits with AI. Causation is hard to show, because a system decision cannot readily be traced, and autonomous behaviour fits poorly into attribution through agents or vicarious liability. Section 823(2) BGB takes the claimant further, because most provisions of the AI Act are protective statutes. Fault then only has to relate to the breach itself. Anyone running AI without internal controls also risks liability for breach of organisational duties.
The Product Liability Directive 2024 assigns software expressly to the notion of a product and treats providers of AI systems as manufacturers. The moment of placing on the market shifts to the loss of control over the product, which for continuously supplied systems only occurs on permanent discontinuation, and until then the manufacturer bears the development risk. Where the claimant shows a breach of the AI Act, defectiveness is presumed. Transposition is due by 9 December 2026.
What the logs are worth
Art. 12 AI Act requires the automatic recording of system activity, and Art. 26(5) AI Act obliges deployers to keep the logs for at least six months where they control them. In litigation those records are often the only evidence that still reconstructs what happened. Tamper-evident logging is therefore not a formality but the basis of your own defence.
Insurance, and where it stops
A residual risk remains even with careful governance, and insurance is the usual instrument for it. A product that covers AI risks as a whole does not yet exist. The risks spread across several lines that each capture only part of the picture, among them third-party claims, fines and damages for data protection breaches, security incidents, copyright infringement and discrimination.
There is also movement in the other direction. Since January 2026 several large insurers in the US market have introduced express exclusions for damage caused by AI-generated content, whether the system was developed in house or bought in. In Europe this is not yet standardised, but it can be expected when policy wordings are next revised. For deployers an imbalance results. Providers limit their liability by contract, insurers exclude, and the remainder stays with the deployer.
- Review existing policies for whether typical AI losses are covered
- Put the review into the renewal, where the wording is renegotiated anyway
- Look specifically for exclusions covering AI-generated content, they rarely carry that heading
- Name the gaps and discuss with the broker whether they can be closed
- Document intended purpose and oversight, because both feed into cover in a loss
Damage from an AI system, or a contract before signature?
We allocate the liability, review the clauses and tell you what your policy actually covers.
Get in touchFrequently asked questions
Is the provider liable, or are we as the deployer?
Both, in different places. The provider owes conformity assessment, technical documentation and post-market monitoring. The deployer owes use in line with the instructions and effective human oversight. Anyone using a system beyond its intended purpose or substantially modifying it takes on the provider duties under Art. 25(1)(c) AI Act.
Does a breach of the AI Act help the injured party?
In part. Most provisions of the AI Act are protective statutes within the meaning of section 823(2) BGB. Fault then only has to relate to the breach of that duty, not to the resulting damage. The causation problem remains, and the evidentiary relief planned in the AI Liability Directive will not arrive, because the procedure was discontinued.
What does the new Product Liability Directive change?
Software falls expressly within the notion of a product, and AI systems are understood as software. Providers under the AI Act count as manufacturers. The relevant moment shifts to the loss of control over the product, which for continuously supplied systems only occurs when supply is permanently discontinued. And defectiveness is presumed once a breach of the AI Act is shown. Member States have until 9 December 2026 to transpose the directive.
Can we limit liability by contract?
Between businesses to a considerable extent, provided intent and gross negligence stay outside the limitation. Towards consumers, exclusions for injury to life, body or health and for gross negligence are ineffective under section 309 no. 7 BGB. An indemnity given by a contracting partner also works only between the parties. Injured third parties can still turn to the provider.
Does our existing insurance cover AI damage?
That can only be answered against the individual policy. Typical AI losses often fit none of the existing lines, and in the US market several large insurers have introduced express exclusions for damage caused by AI-generated content since January 2026. A comparable development can be expected in Europe when policy wordings are next revised.