When software helps deny a loan, steers a vehicle into danger, misidentifies a suspect or guides a surgical workflow, the immediate question is technical: what went wrong? The legal question follows quickly behind: who pays? That issue has become sharper as artificial intelligence systems move from laboratories into hospitals, factories, courts, offices and consumer devices. Harm may be physical, financial or reputational; the chain of responsibility may run through model developers, data suppliers, integrators, deployers and users. The older law of negligence and defective products was not designed for systems whose behaviour may be adaptive, probabilistic and difficult even for their makers to explain.
The European Union has spent the past few years trying to solve that problem without building an entirely separate law of machine wrongdoing. Its emerging approach has two principal limbs. The first is the revised Product Liability Directive, adopted in 2024, which updates strict liability for defective products so that software, digital manufacturing files and some related digital services fall more squarely within the law. The second was the proposed AI Liability Directive, introduced in 2022, which sought to ease the burden on victims bringing fault-based claims by creating disclosure tools and rebuttable presumptions about causation. Together they signalled a distinctly European instinct: keep familiar legal concepts, but recalibrate them for opacity, complexity and evidential asymmetry.
The old categories under strain
Traditional private law distinguishes between two broad routes to compensation. In fault-based liability, a claimant generally must show that the defendant breached a duty of care and that the breach caused the harm. In strict product liability, by contrast, the focus is less on carelessness than on whether a product was defective and caused damage. Those categories worked reasonably well for mechanical goods and relatively simple software. They work less comfortably for AI.
The central difficulty is proof. A claimant may know that an automated system produced a harmful output, yet struggle to identify whether the problem lay in the training data, model design, testing, integration, post-market updates or human misuse. Access to evidence is often unequal. Technical documentation sits with manufacturers and deployers. The relevant causal chain may involve statistical inferences rather than deterministic steps. And because many AI systems are developed and deployed across borders, the legal chain may be as fragmented as the technical one.
The central legal problem is not whether AI can cause harm, but how a claimant proves that a particular system, actor or design choice caused it.
What Europe changed in product liability
The revised Product Liability Directive is the more concrete of Europe’s two liability reforms because it has become law. It replaces the 1985 directive that shaped EU product-liability rules for decades. The old regime was pioneering in its time, but it was written for an economy of tangible goods. The new text modernises the definition of a product to include software and digital manufacturing files, and it addresses the reality that a product’s safety may depend on updates, upgrades and connected digital services.
This matters because strict liability does not require the injured person to prove negligence. A claimant still has to show damage, defect and causation, but not fault. The producer is liable when a product does not provide the safety the public is entitled to expect, taking account of all circumstances. For AI-enabled goods and software, that enquiry now expressly reaches issues such as cybersecurity vulnerabilities, learning functions, and the effects of software updates or the failure to supply them. The directive also enlarges the circle of potentially responsible economic operators in some situations, including importers and fulfilment service providers, reflecting the complexity of modern distribution chains.
In practical terms, the revised directive is Europe’s acknowledgement that software can be defective in the legally meaningful sense, not merely buggy in the colloquial one. If an AI-enabled medical device, vehicle function or industrial system creates an unreasonable safety risk, the claimant need not first prove a careless act by a particular engineer. That lowers one barrier to recovery, especially where design and deployment are difficult to disentangle.
The central legal problem is not whether AI can cause harm, but how a claimant proves that a particular system, actor or design choice caused it.
Defect without negligence
Strict liability is often misunderstood as automatic liability. It is not. The claimant must still establish that the product was defective and that the defect caused compensable damage. Courts will remain central in deciding what counts as a defect in systems that are probabilistic by nature. An AI system need not be perfect to be safe, but nor can producers avoid liability by arguing that error is statistically inevitable in all complex models. Law does not ask whether a product is infallible; it asks whether the level and nature of risk are acceptable in light of legitimate safety expectations.
That inquiry becomes especially delicate when a system can change after it enters the market. Machine-learning models may be updated, fine-tuned or connected to new data sources. A product that was safe at launch may become hazardous after a patch, or remain hazardous because a patch was not provided. The revised directive therefore treats the product less as a static object than as a continuing bundle of code, functionality and support. For manufacturers, that means liability may attach not only to original design choices but to lifecycle governance.
The proposed AI Liability Directive
The proposed AI Liability Directive addressed a different problem. Where strict product liability is unavailable or incomplete, victims often rely on national fault-based claims: negligence, breach of duty, or similar doctrines. The Commission argued that AI can make these claims exceptionally difficult because evidence of fault and causation is often inaccessible to the claimant. Its answer was not to harmonise all tort law, but to insert two targeted tools into national systems.
First, courts would be able to order disclosure of relevant evidence about high-risk AI systems from providers or certain users, subject to safeguards for trade secrets and confidentiality. Second, where a claimant proved a relevant fault and showed that fault was reasonably likely to have influenced the AI output, courts could presume a causal link between fault and output, unless the defendant rebutted the presumption. This was intended to reduce the near-impossible burden of reconstructing the internal operation of complex systems from the outside.
The measure was narrower than some early political rhetoric suggested. It did not create strict liability for AI. It did not make an AI system itself a legal person. And it was designed to work alongside, not replace, ordinary national tort law and the broader regulatory architecture of the AI Act. Yet it touched the most contentious issue in civil litigation: who bears the burden of uncertainty when the facts are hard to uncover?
Burden of proof as the real battleground
In litigation, substantive rights matter less than they appear if a claimant cannot obtain the evidence needed to prove them. That is why the burden of proof sits at the centre of AI liability debates. European policymakers recognised that sophisticated systems create information asymmetries that ordinary consumers, workers and even business users may struggle to overcome. A presumption of causation, even a rebuttable one, can change settlement incentives and insurance pricing long before a court reaches final judgment.
At the same time, defendants and some member states worried that loosening evidential standards too far could encourage speculative claims and chill development. They also pointed out that causation in AI cases may be multicausal: bad data, poor governance, inadequate oversight and user misuse may all play a role. Presumptions can help courts manage that complexity, but they can also blur distinctions among actors whose degree of control differs sharply.
Europe’s reforms do not create a grand new regime of robot responsibility; they modify old doctrines of defect and fault for an age of opacity.
Europe’s reforms do not create a grand new regime of robot responsibility; they modify old doctrines of defect and fault for an age of opacity.
How the AI Act fits in
The AI Act is not, strictly speaking, a compensation law. It is a public-law instrument built around risk management, conformity assessments, documentation duties and oversight obligations. Yet it will influence private litigation. Compliance failures under the AI Act may furnish evidence of fault; documentation generated for regulatory purposes may become crucial in disclosure battles; and the Act’s classification of high-risk systems provides a legal vocabulary for arguing what precautions were reasonably required.
This interaction is one reason the proposed AI Liability Directive focused on high-risk systems in parts of its disclosure regime. Europe’s broader strategy is cumulative. Ex ante regulation is meant to reduce the likelihood of harm. Product liability provides compensation when defective products still cause damage. Fault-based claims fill gaps where conduct, rather than product defect alone, is central. The result is not a single code of AI accidents, but a layered structure in which regulatory non-compliance may reverberate into civil liability.
Insurance: pricing uncertainty rather than eliminating it
Whenever liability rules change, insurers become the quiet interpreters of the new settlement. The question is not only whether courts will compensate victims, but how risks will be pooled, excluded and priced. EIOPA and the OECD have both noted that AI complicates underwriting and claims handling in at least two ways. First, AI creates new liability exposures for firms that develop or deploy systems. Second, insurers themselves increasingly use AI, generating their own governance and accountability questions.
From an insurance perspective, the hardest cases are those with uncertain frequency, uncertain causation and potentially correlated losses. If many organisations rely on similar models, training pipelines or software components, a single flaw may affect many insureds at once. That looks less like a random accident and more like systemic risk. Traditional liability insurance is better suited to dispersed mishaps than common-cause failures.
The likely consequence is differentiation. Some risks will remain insurable through familiar professional indemnity, product liability and cyber policies, albeit with tighter wording around software updates, autonomous functions and data governance. Other risks may attract exclusions, sub-limits or higher premiums until claims data mature. In Europe, clearer legal definitions of product defect may help insurers model exposure, but easier proof for claimants in fault-based suits would push in the opposite direction by increasing uncertainty over litigation outcomes.
Fault, strictness and the politics of fairness
There is an old moral intuition behind fault-based liability: one should pay for harm one carelessly causes. Strict product liability rests on a different intuition: those who place products on the market should bear the costs of defects, because they control design and can spread losses through pricing and insurance. AI blurs the appeal of both ideas. Some harms arise from negligent deployment or inadequate human oversight, which sounds in fault. Others stem from latent defects in software or integration, which sound in product liability. Many cases involve both.
European reformers have resisted the temptation to declare one principle supreme. Instead they have redistributed risk across doctrines. Where a software-enabled product is defective, strict liability should do more work than before. Where the claimant must still sue in fault, evidential barriers should be lower than in conventional disputes. This is less philosophically tidy than a wholly new AI-liability code, but more realistic. The machine may err, yet the legal system still asks human questions about control, foreseeability, safety expectations and proof.
In the United States, the argument still runs largely through existing tort categories, with courts moving case by case rather than through a single federal statute.
The American contrast
The United States is approaching the problem more incrementally. There is no federal equivalent to the EU’s package of AI-specific civil-liability reforms. Instead, disputes tend to be filtered through existing state tort law, product-liability doctrines, sector-specific regulation and enforcement actions. The Restatement (Third) of Torts remains influential in organising product-liability analysis around manufacturing defects, design defects and failure to warn. Courts are accustomed to dealing with software-related harms, but AI adds fresh complications around autonomy, update cycles and explainability.
American claimants often face formidable causation hurdles, especially in cases involving algorithmic discrimination, automated decision-making or advanced driver-assistance systems. Plaintiffs may rely on negligence, strict products liability, breach of warranty, consumer-protection statutes or, in some domains, civil-rights law. But without a harmonised federal rule on disclosure or presumptions tailored to AI, outcomes are likely to remain highly fact-specific and jurisdiction-dependent.
That does not mean the American system is inert. It means development is judicial and piecemeal rather than legislative and systemic. High-profile litigation over automated driving and algorithmic harms can still shape incentives, particularly when combined with regulator investigations and media scrutiny. Yet the overall pattern is one of adaptation through existing categories, not the deliberate recalibration of burdens that Europe has attempted.
In the United States, the argument still runs largely through existing tort categories, with courts moving case by case rather than through a single federal statute.
What claimants, defendants and courts will actually argue about
In coming years, AI-liability disputes are likely to turn on a handful of recurring questions. Was the system itself defective, or merely misused? Was the harm caused by the model, the surrounding human workflow, or the absence of adequate monitoring? Were updates and warnings sufficient? Did the deployer rely unreasonably on automation? Did regulatory non-compliance make the harm more foreseeable? And, crucially, what evidence may the claimant obtain to answer any of these questions?
Courts will also have to confront the distinction between error and unlawfulness. An AI system can make mistakes without being legally defective if the residual risk falls within acceptable bounds and warnings or safeguards are adequate. Conversely, a system that performs well on average may still be defective if it predictably fails in safety-critical edge cases. The legal analysis is therefore neither a referendum on innovation nor a simple comparison of human and machine error rates. It is a context-specific inquiry into risk allocation.
An unsettled settlement
The politics of AI liability remain fluid. The revised Product Liability Directive gives Europe a firmer legal basis for claims involving software and connected products. The proposed AI Liability Directive, however, has faced a more uncertain legislative path amid wider disputes over the Union’s digital agenda and the practical overlap with the AI Act. Even so, the direction of travel is clear. Policymakers have accepted that opacity and complexity are not mere technical inconveniences; they are obstacles to justice that law may need to address directly.
The deeper question is whether liability law can keep compensation, deterrence and innovation in balance when systems are built by many actors and behave in probabilistic ways. No legal regime can make causation simple where technology makes it diffuse. But rules on defect, disclosure and presumptions can decide who bears the cost of that complexity. In the end, the machine does not pay when it errs. Designers, deployers, distributors, insurers and sometimes users do. The struggle now is over which of them should carry how much of the burden, and how easily an injured person can make that burden stick.


