Who Is Liable When AI Causes Harm?

An AI system rejects someone’s loan application. Another system recommends a medical treatment that turns out to be dangerous. An autonomous vehicle makes the wrong decision and causes a crash.

In each situation, there is an obvious question:

Who is liable when AI causes harm?

The tempting answer is to blame the AI.

But legally, that usually isn’t how responsibility works.

An AI system is not normally treated as a person that can simply be sued, fined or ordered to pay compensation. The harder question is which human or organization behind the system should bear responsibility: the developer, manufacturer, deployer, operator, seller, or potentially several parties at once.

And this is where AI becomes different from many traditional products.

When a system is complex, autonomous or difficult to explain, finding the person responsible can become much harder.

Who Is Liable When AI Causes Harm?

The answer depends on what caused the harm, who controlled the relevant part of the system, what legal rules apply, and what can actually be proved.

That means there is no universal rule saying that the developer is always responsible or that the company using the AI is always responsible.

Consider a simple example.

A company purchases an AI system to screen job applications. The system repeatedly produces discriminatory results.

Was the problem caused by the underlying model?

Was it caused by the company’s data?

Did the employer configure the system incorrectly?

Did the company use the system for a purpose it was not designed for?

Or did nobody adequately monitor it after deployment?

Each possibility can point toward a different legal analysis.

That is the central challenge of AI legal liability.

1. The AI Usually Isn’t the Legal Defendant

When people ask, can an AI system be held legally liable, they are often imagining a future in which an AI itself becomes the responsible party.

Current liability systems generally work differently.

They assign legal responsibility to people and organizations.

For example, if a software system causes damage because it was defective, the relevant question may be whether the manufacturer or another economic operator can be held responsible under applicable product-liability rules.

The European Union’s revised Product Liability Directive is particularly important here because it explicitly treats software, including AI systems, as products for the purposes of its no-fault product-liability regime.

So the more useful question is not simply who is liable when AI causes harm.

It is:

Which person or organization had the legal responsibility to prevent this particular harm?

That distinction becomes increasingly important as AI systems move from simple tools toward autonomous systems.

2. Developer vs Deployer Liability: Who Was in Control?

Imagine a hospital purchases an AI system designed to help doctors identify abnormalities in medical scans.

The developer created the model.

The hospital selected the system, integrated it into its workflow and decided how much doctors should rely on its recommendations.

Then the system makes a dangerous error.

This creates the AI developer vs deployer liability problem.

The developer might potentially face responsibility if the system itself was defective, poorly designed or failed to meet applicable legal requirements.

The deployer could potentially face responsibility if it used the system improperly, ignored warnings, failed to supervise it or introduced it into a situation for which it was not appropriate.

The exact answer depends on the jurisdiction and facts.

Under the EU AI Act, for example, providers and deployers have different obligations, reflecting the fact that responsibility can exist at different stages of an AI system’s lifecycle.

That does not mean the AI Act itself automatically decides who must compensate a victim.

It is primarily a regulatory framework governing how certain AI systems are developed and used.

3. The Black Box Liability Problem

Now imagine something more complicated.

An AI system produces a harmful result, but even the people operating it cannot easily explain exactly why that particular output occurred.

This is the black box liability problem.

Traditional negligence cases often depend on evidence.

Who made the decision?

What did they know?

What should they reasonably have done differently?

Was there a failure to take reasonable care?

With complex AI, tracing the chain from input to output can be difficult.

The European Commission has previously identified opacity, complexity, autonomy and difficulties proving causation as important challenges for AI liability.

This matters because proving that an AI system caused harm is not necessarily enough.

A victim may also need to establish the legal basis for holding a particular party responsible.

And the evidence needed to do that may be held by the developer or operator.

4. What If an Autonomous Car Crashes?

Consider the question people often ask:

Who is at fault if an autonomous car crashes?

The answer cannot simply be “the car.”

Suppose an autonomous vehicle suddenly fails to recognize an obstacle.

Several questions immediately appear:

  • Was the vehicle’s software defective?
  • Was a sensor malfunctioning?
  • Was the system improperly maintained?
  • Was the vehicle operating within its intended conditions?
  • Did the manufacturer know about a software problem?
  • Did an update create the defect?
  • Did the human driver fail to follow required instructions?
  • Did another road user contribute to the accident?

The legal analysis therefore depends on the chain of events.

The EU’s revised Product Liability Directive specifically recognizes that software and AI can be products and also addresses defects that emerge through software updates or machine-learning algorithms that remain under a manufacturer’s control.

This illustrates why autonomous systems negligence cannot be reduced to one simple rule.

The more autonomous the technology becomes, the more important it becomes to identify where human decisions, design choices and operational controls existed around it.

5. Liability Can Travel Through the AI Supply Chain

Modern AI rarely comes from one company.

A single application may involve:

Model developer → software provider → system integrator → business deployer → end user

Now imagine that something goes wrong.

The developer might have supplied a general-purpose model.

Another company might have built the application around it.

A third company might have integrated that application into a product.

A fourth organization might use the product in its workplace.

So how to assign liability in AI supply chains becomes a much harder question than simply asking who built the model.

Different legal rules can apply to different participants.

The EU’s Product Liability Directive addresses multiple economic operators and provides rules for situations in which more than one operator may be liable for the same damage.

That is significant because responsibility does not always have to stop at one company.

6. What Happened to the EU AI Liability Directive?

This is where an important update is necessary.

The European Commission proposed an AI Liability Directive in 2022. Its purpose was to address certain difficulties victims could face when trying to prove non-contractual civil liability involving AI.

However, the proposal was officially withdrawn on 6 October 2025. It is therefore incorrect to describe it today as an active EU liability law.

So if you have searched for eu ai liability directive explained, remember the date matters.

The proposal is useful for understanding the legal debate, but it is not currently an operative EU directive creating a single new AI-specific civil-liability regime.

The EU instead has several pieces of legislation that address different parts of the problem.

The AI Act regulates certain AI systems through risk-based requirements, while the revised Product Liability Directive modernizes product-liability rules and expressly includes software and AI systems.

7. The New EU Product Liability Rules Matter

The revised Product Liability Directive, Directive (EU) 2024/2853, is particularly relevant to AI.

It expands the concept of a product to cover software, including AI systems, and maintains a no-fault product-liability framework where a claimant must establish the relevant defect and causal connection to the damage.

Member States must transpose the directive by 9 December 2026. The directive applies to products placed on the market or put into service after 8 December 2026, following a 2026 corrigendum.

That timing is important because AI liability rules are still developing.

For businesses operating in Europe, the question is therefore not only whether an AI system works technically.

It is also whether the organization understands the legal responsibilities surrounding its design, updates, integration and use.

A Simple Way to Think About AI Liability

When an AI system causes harm, ask five questions:

1. What exactly caused the harm?
Was it the model, software, hardware, data, human decision or combination of factors?

2. Who created the relevant component?
Identify the developer, manufacturer or supplier.

3. Who controlled the system when the harm occurred?
The deployer may have changed how the system operated.

4. Was there a failure of reasonable care or a defective product?
This depends heavily on the applicable law.

5. What evidence connects the system to the damage?
Logs, documentation, testing records, instructions, updates and other technical evidence can become critical.

This framework helps explain why who is liable when AI causes harm cannot be answered simply by naming the company that built the AI.

The Bigger Problem Is Not Just the AI

The hardest part of AI liability may not be deciding whether artificial intelligence can make mistakes.

Everyone already knows it can.

The harder problem is deciding where responsibility sits when many people and companies contribute to a system and the final decision emerges from a process that is difficult to understand.

That is why the debate around AI liability is ultimately a debate about human accountability.

AI can make a recommendation.

It can generate an output.

It can control part of a machine.

But behind those systems are still people who design them, sell them, integrate them, deploy them, supervise them and decide where they should be used.

For more on how The Practical World approaches complex technology and law topics, see our editorial standards and fact-checking approach.

The Bottom Line

So, who is liable when AI causes harm?

There is no single answer.

Depending on the circumstances and jurisdiction, responsibility may potentially involve a developer, manufacturer, deployer, operator, seller or several parties.

The key is to follow the chain from design to deployment to harm.

And as AI becomes more autonomous, the most important legal question may become less about whether the machine made the decision and more about who was responsible for putting that machine in a position to make it.

That is the real challenge of AI legal liability.

Frequently Asked Questions

Who is responsible when artificial intelligence makes a mistake?

Usually, the AI itself is not treated as a legal person responsible for compensation. Responsibility may instead fall on a developer, manufacturer, deployer, operator or another party depending on the applicable law and circumstances.

Can an AI system be held legally liable?

Generally, current liability systems assign responsibility to people and organizations rather than treating AI systems themselves as independent legal defendants. The specific rules depend on the jurisdiction and type of harm.

Who is at fault if an autonomous car crashes?

There is no universal answer. Investigators may need to examine the vehicle’s software, sensors, maintenance, manufacturer instructions, updates, human supervision and the actions of other parties involved in the crash.

What is the black box liability problem?

It refers to the difficulty of establishing why a complex AI system produced a particular result and how that result connects to a person’s harm. This can make proving causation and responsibility more difficult.

Does the EU have an AI Liability Directive?

The European Commission’s proposed AI Liability Directive was withdrawn on 6 October 2025. It should therefore not be described as an active EU directive today. The EU’s revised Product Liability Directive and AI Act are relevant parts of the current legal framework.

Who is responsible in an AI supply chain?

Potential responsibility can involve multiple participants, including model developers, software providers, manufacturers, integrators and deployers. The answer depends on the specific legal claim, the role each party played and the evidence connecting that role to the harm.

Does the EU AI Act decide who pays compensation?

The AI Act establishes regulatory obligations for AI providers and deployers, but it is not itself a comprehensive civil-liability regime determining compensation for every instance of AI-related harm. Civil liability is addressed through other applicable laws and legal frameworks.

Is AI liability the same in every country?

No. Liability rules differ across jurisdictions. Product liability, negligence, contract law, consumer protection and sector-specific rules can all affect how an AI-related claim is handled.

Trending

Discover more from THE PRACTICAL WORLD

Subscribe now to keep reading and get access to the full archive.

Continue reading