Skip to content

Who Is Liable When a High-Risk AI System Causes Harm: the Current EU Answer

11 min read · updated August 11, 2026

The EU has spent years building the most detailed AI rulebook in the world. If a high-risk AI system injures you tomorrow, almost none of it helps you get paid. The argument here is that the compensation question is answered by three older instruments and one abandoned proposal, and that the answer has a hole in the middle of it.

The AI Act gives a claimant nothing

Regulation (EU) 2024/1689 creates obligations and it creates penalties. It does not create a right to compensation. There is no provision entitling a person harmed by a non-compliant high-risk system to damages, no private right of action, and no statutory cause of action of any kind. What Article 85 gives an affected person is the right to lodge a complaint with a market surveillance authority — the Act is on EUR-Lex at ELI reg/2024/1689. A complaint may produce enforcement. It does not produce a payment.

This is deliberate. The AI Act is product-safety-shaped legislation, and product safety law has always been about keeping unsafe things off the market rather than about compensating the people the unsafe things reached. The compensation half was supposed to be the AI Liability Directive, which the Commission listed for withdrawal on 11 February 2025 — the withdrawal and its stated reason. With that gone, the Act’s contribution to a damages claim is indirect: it generates documentation, logs and conformity records a claimant may be able to obtain, and non-compliance with it is evidence of fault or of defectiveness under other regimes.

This page argues a position about instruments in force as at August 2026. It is not legal advice, and liability is decided under the national law of a member state on the facts of a case — take advice there.

Route one: product liability

The strongest route, where it fits, is Directive (EU) 2024/2853. It is strict liability, software is expressly a product, and Articles 9 and 10 give a claimant disclosure and a set of presumptions including relief where technical complexity makes proof excessively difficult. For a person physically injured by a defective AI-enabled device placed on the market after the transposition deadline of 9 December 2026, this is the claim.

Its limits are structural rather than accidental. It compensates death and personal injury, damage to privately used property, and destruction or corruption of privately used data. It does not compensate pure economic loss. It does not compensate a business at all. And it requires a defect — a failure to provide the safety the public is entitled to expect — which is a coherent question about a braking system and a much harder one about a model that produced a plausible, wrong answer within its documented accuracy range. A system performing as designed and as documented is not obviously defective, however badly the outcome went for one person. That question is unresolved and it is the one that will decide how much of this regime bites on AI at all.

Route two: GDPR Article 82

Article 82 of Regulation (EU) 2016/679 is the most underused route in this area. Any person who has suffered material or non-material damage as a result of an infringement of the GDPR has the right to compensation from the controller or processor, and the controller is liable unless it proves it is not in any way responsible for the event giving rise to the damage. That reversed burden is stronger than anything the AI Liability Directive proposed.

The Court of Justice has drawn its edges. In Case C-300/21, decided 4 May 2023, it held that an infringement alone does not establish a right to compensation — damage must be shown, though no threshold of seriousness applies. In Case C-340/21, decided 14 December 2023, it accepted that a well-founded fear of misuse of one’s own data can itself be non-material damage. Awards in national courts have generally been modest, and that is the practical objection to this route rather than a doctrinal one.

What makes it fit AI harms well is that so many of them are processing harms. A wrong automated decision, a profiling inference, an output that states a falsehood about an identifiable person, training on data that had no lawful basis: each is a GDPR infringement before it is anything else, and Article 22 supplies an additional hook where the decision is solely automated. Whether it is solely automated is where these cases are won or lost — see what counts as meaningful human involvement.

Route three: national fault-based law

Everything the first two routes do not cover falls to member state tort law: section 823 BGB in Germany, article 6:162 BW in the Netherlands, the general delictual provisions in France, negligence in Ireland. These are capable regimes and they are not AI-illiterate. They are, however, fault-based, which means the claimant proves a breach of a duty of care and proves that the breach caused the loss.

That is the asymmetry the AI Liability Directive existed to fix, and now nothing fixes it. A claimant does not have the training data, the evaluation results, the system logs, the model version that served their request or the prompt. The defendant has all of it. National disclosure rules vary enormously — a claimant in Ireland is in a very different position from one in Germany — and that variation is now the single largest determinant of whether an AI claim is viable in the EU, which is precisely the fragmentation the harmonising proposal was meant to prevent.

There is one lever. Non-compliance with a statutory duty is, in most of these systems, evidence of fault or a breach of a protective norm. The AI Act’s Article 12 logging duty, its Article 11 technical documentation and its Article 26 deployer obligations therefore feed a national negligence claim even though the Act creates no claim itself. The claimant’s difficulty is getting at those records, and how those logs function as evidence is where the fight will happen.

Where the gap actually falls

Put the three routes together and the shape of the hole is clear. Physical injury from a device is covered. Data-protection harm is covered, thinly. Everything else — a business damaged by a defective AI service, a candidate excluded by a screening model, a person denied credit, an organisation whose operations failed on an incorrect output — is pure economic loss or discriminatory treatment, and lands on unmodified national law with no disclosure right and no causal presumption.

Those are not exotic edge cases. They are the harms AI systems most commonly cause. Discrimination claims have their own directives and their own shifted burden of proof, which is a genuine partial answer for the hiring and credit cases; commercial loss has contract, which is an answer only if you negotiated one, and AI contract clauses is where that gets decided rather than in any statute.

The honest conclusion is that the current EU answer to “who is liable” is: it depends which member state you are in, and for most AI harms you will find out in a national court applying general tort law without ever seeing the system. That is an unsatisfying answer and it is the true one, and it stays true until either the Commission returns with a liability instrument or a member state legislates its own presumptions first.