Civil Law And Ai Diagnostic Tool Error Liability In Europe .

Civil Law and AI Diagnostic Tool Error Liability in Europe

1. Introduction

AI diagnostic tool error liability arises when an AI-enabled medical system incorrectly analyses symptoms, medical images, laboratory results, pathology slides, genetic information or other health data and the error causes harm.

Examples include:

an AI radiology system failing to detect a tumour;

an AI system incorrectly identifying a benign lesion as malignant;

an AI pathology tool producing a false-negative result;

an AI diagnostic system generating a false-positive result leading to unnecessary treatment;

an AI system using outdated clinical data;

an algorithm producing an incorrect risk score;

software malfunction after an update;

a healthcare professional relying excessively on an AI recommendation;

an AI diagnostic device being insufficiently tested or validated;

a medical AI system giving an incorrect result because of biased or incomplete training data.

European liability is not based on one single AI-liability rule. It involves a combination of medical-device regulation, product liability, professional negligence, contract law, data protection and, increasingly, AI-specific regulation.

The most important development is the new Product Liability Directive (EU) 2024/2853, which expressly treats software, including AI systems, as products for product-liability purposes. It applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)

2. Basic Liability Model

A diagnostic AI error can be analysed as:

AI diagnostic system

↓

Incorrect output

↓

Doctor/hospital/patient relies on output

↓

Incorrect diagnosis or delayed diagnosis

↓

Treatment delay / unnecessary treatment / physical injury

↓

Damage

↓

Causation

↓

Potential civil liability

The central legal question is:

Was the AI diagnostic system defective, was the healthcare professional negligent in relying on it, or did both factors contribute to the patient's injury?

3. What Is an AI Diagnostic Tool?

Under the EU Medical Devices Regulation, software can constitute a medical device where it is intended for medical purposes including diagnosis, prevention, monitoring, prediction, prognosis or treatment of disease. (EUR-Lex)

Therefore, an AI diagnostic program may fall within the medical-device regulatory framework where its intended purpose satisfies the relevant definition.

Examples:

Imaging AI

Analyses:

X-rays;

CT scans;

MRI images;

ultrasound;

mammograms.

Pathology AI

Analyses:

biopsy slides;

cancer cells;

tissue samples.

Clinical decision-support AI

Combines:

symptoms;

medical history;

laboratory results;

medications;

demographic information.

Predictive diagnostic AI

Predicts:

disease probability;

deterioration risk;

cardiovascular risk;

sepsis risk;

cancer probability.

4. Main European Legal Framework

A. Medical Devices Regulation — Regulation (EU) 2017/745

The MDR is fundamental for AI medical devices.

A medical device must satisfy relevant safety and performance requirements.

The general requirements include that devices achieve their intended performance and be designed and manufactured so that they are safe and effective and do not compromise the clinical condition or safety of patients, taking account of the generally acknowledged state of the art. (EUR-Lex)

For AI diagnostic tools, this raises questions concerning:

clinical validation;

accuracy;

reliability;

cybersecurity;

software updates;

data quality;

intended purpose;

human oversight;

post-market monitoring.

5. AI Act

The AI Act creates another regulatory layer.

AI systems that are safety components of products covered by specified EU harmonisation legislation, including medical devices and in-vitro diagnostic medical devices, can fall within the high-risk AI system framework where the Article 6 conditions are satisfied. (EUR-Lex)

This is particularly important because an AI diagnostic system may simultaneously be:

software + medical device + high-risk AI system

depending upon its precise regulatory classification.

The AI Act addresses issues such as:

risk management;

data governance;

technical documentation;

record keeping;

transparency;

human oversight;

accuracy;

robustness;

cybersecurity.

But an important distinction must be maintained:

Regulatory non-compliance does not automatically establish every element of a civil damages claim.

The claimant must still establish the appropriate liability basis, damage and causation.

6. New Product Liability Directive

Directive (EU) 2024/2853 is especially important for AI diagnostic litigation.

It expressly recognises that:

software, including AI systems, can constitute products.

The Directive states that software can be a standalone product or integrated into another product and can cause damage through its operation. It also expressly contemplates AI-system providers as manufacturers for product-liability purposes. (EUR-Lex)

The Directive applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)

Thus, there is an important date distinction:

SituationPrincipal framework
Older AI medical productExisting national + EU product-liability framework
AI medical device before 8 Dec 2026MDR + existing national/product liability
Products covered by new Directive after 8 Dec 2026Directive 2024/2853 + national implementing law
AI medical device + high-risk AIMDR + AI Act + applicable civil liability

7. Case Law

The existing European case law predates modern generative AI, but several decisions provide highly relevant principles.

Case 1 — Boston Scientific Medizintechnik GmbH v AOK Sachsen-Anhalt and Others

Joined Cases C-503/13 and C-504/13

CJEU, 5 March 2015

This is probably the most important existing CJEU authority for an AI diagnostic-device liability analogy.

The case concerned pacemakers and implantable cardioverter defibrillators.

The Court held that where products belonging to the same group or production series have a potential defect, an individual product may be classified as defective even without proving that the specific individual device actually malfunctioned. (Infocuria)

The Court also held that necessary surgical replacement costs could constitute compensable personal-injury damage. (Infocuria)

Relevance to AI

Suppose an AI diagnostic product is discovered to have a systematic defect:

faulty training dataset;

recurring software bug;

systematic image-recognition error;

dangerous update;

flawed algorithmic threshold.

A claimant may argue that the defect concerns the system/product class, rather than requiring proof of every internal technical failure.

Principle

A systemic safety defect can be legally significant even where the precise technical malfunction in an individual case is difficult to isolate.

This is highly relevant to AI systems whose internal operations can be difficult for patients to reconstruct.

8. Case 2 — Veedfald

Case C-203/99

CJEU, 10 May 2001

Veedfald concerned a medical procedure involving a defective medical product.

The CJEU emphasised the requirement of effective compensation for persons injured by defective products.

The case is particularly important for understanding the broad protective objective of European product liability.

It is also cited in later product-liability decisions concerning compensation for harm caused by defective medical products.

AI relevance

An AI diagnostic tool can cause harm indirectly.

For example:

AI error → doctor receives incorrect result → incorrect treatment → physical injury.

The fact that the injury arises through a medical process does not necessarily eliminate product-liability considerations.

Principle

The product-liability regime is concerned with protection against damage caused by defective products, including in medical contexts.

9. Case 3 — González Sánchez v Medicina Asturiana

Case C-183/00

CJEU, 25 April 2002

This case concerned the EU Product Liability Directive and the relationship between the harmonised EU regime and national liability rules.

The CJEU emphasised the harmonising nature of the Directive and the framework governing producer liability for defective products. (curia)

AI relevance

An AI diagnostic claim may be brought under:

product liability;

contractual liability;

professional negligence;

national tort/delict law.

The claimant must determine which legal regime actually applies and whether EU harmonisation limits additional national rules.

Principle

The EU product-liability regime and national civil-liability rules must be carefully distinguished.

10. Case 4 — N.W. and Others v Sanofi Pasteur MSD

Case C-621/15

CJEU, 21 June 2017

This case concerned alleged harm caused by a vaccine.

The Court considered how defect and causation could be proved where scientific evidence does not provide a definitive consensus.

The Court accepted that, subject to national judicial assessment, serious, specific and consistent evidence could potentially establish defect and causation. Relevant circumstances could include temporal proximity and absence of relevant personal or family history. (curia)

AI relevance

AI diagnostic litigation can involve difficult scientific causation.

For example:

AI error → delayed diagnosis → disease progression.

The defendant may argue:

"The disease would have progressed anyway."

The claimant may therefore need medical and technical evidence connecting:

AI error → missed diagnosis → delay → worsened condition.

Principle

Causation in technically complex medical cases may require assessment of a combination of evidence rather than one isolated scientific fact.

This is an analogy, not an AI-specific ruling.

11. Case 5 — Elisabeth Schmitt v TÜV Rheinland

Case C-219/15

CJEU, 16 February 2017

This case concerned defective breast implants and the responsibilities of a notified body involved in conformity assessment.

The Court examined whether the notified body could have obligations under the Medical Devices Directive and how failure to perform those duties should be treated under national law. (Infocuria)

The case is important because it demonstrates that medical-device safety involves multiple actors:

manufacturer;

conformity-assessment body;

healthcare providers;

regulators.

AI relevance

An AI diagnostic tool may similarly involve:

AI developer → medical-device manufacturer → notified body → hospital → doctor → patient

A failure by one actor does not necessarily establish automatic liability of every other actor.

Principle

The legal responsibility of a conformity-assessment body must be distinguished from the manufacturer's product liability and assessed under the applicable legal framework.

12. Case 6 — O'Byrne v Sanofi Pasteur MSD

Case C-127/04

CJEU, 9 February 2006

This case concerned the concept of putting a product into circulation under the Product Liability Directive.

The Court examined circumstances in which a product supplied within a corporate group could be regarded as having been put into circulation.

AI relevance

AI medical systems may have complicated supply structures:

AI developer → software distributor → medical-device manufacturer → hospital → cloud provider.

Determining who legally placed the product on the market may therefore become important.

Principle

Identifying the legally responsible producer/supplier is essential in product-liability litigation.

This becomes especially important for AI systems supplied through cloud or software-as-a-service models.

13. Case 7 — Commission v United Kingdom

Case C-300/95

CJEU, 29 May 1997

This case concerned the so-called development-risk defence under the Product Liability Directive.

The case is relevant to the question of whether the state of scientific and technical knowledge made it possible to discover a defect.

AI relevance

AI technology develops continuously.

A manufacturer might argue:

"The diagnostic error could not have been discovered using the scientific and technical knowledge available at the relevant time."

The claimant may respond with evidence showing:

known validation problems;

known dataset limitations;

known performance disparities;

previous complaints;

known software errors;

inadequate testing.

The new Product Liability Directive continues to recognise a state-of-scientific-and-technical-knowledge defence, subject to its conditions. (EUR-Lex)

14. Case 8 — Boston Scientific: Broader Importance

The Boston Scientific decision deserves additional attention because the Court recognised that the safety level a patient is entitled to expect is central to determining defectiveness.

For AI diagnostic systems, expected safety may involve:

diagnostic accuracy;

reliability;

predictable operation;

adequate warnings;

cybersecurity;

software updates;

appropriate intended-use limitations.

The new Product Liability Directive expressly recognises that machine learning and AI can create technical and causal complexity. It allows national courts to consider excessive difficulties faced by claimants in proving defectiveness or causation. (EUR-Lex)

That is particularly significant for AI litigation.

15. What Constitutes an AI Diagnostic Defect?

A diagnostic AI system may potentially be defective where it fails to provide the level of safety persons are entitled to expect.

Potential defects include:

A. Design defect

The algorithm is inherently unsuitable for its intended purpose.

Example:

The model systematically misses early-stage tumours.

B. Manufacturing/software defect

A coding or deployment error causes incorrect outputs.

C. Training-data defect

The training dataset is materially inadequate for the intended patient population.

D. Validation defect

The manufacturer releases the system without sufficient clinical validation.

E. Warning defect

The manufacturer fails to warn doctors that the system:

performs poorly on certain populations;

should not be used for particular diseases;

requires human verification.

F. Update defect

An update reduces diagnostic reliability.

G. Cybersecurity defect

A vulnerability allows manipulation of diagnostic outputs.

The new Product Liability Directive expressly recognises liability for certain defects arising from software updates, upgrades and machine-learning algorithms remaining within the manufacturer's control. (EUR-Lex)

16. Incorrect Result vs Defective Product

An important distinction is:

Wrong diagnosis ≠ automatically defective AI product.

Suppose AI says:

"No tumour detected."

The patient later develops cancer.

There are several possibilities:

Scenario A

The AI system correctly operated according to its intended performance.

The error may not automatically establish product defect.

Scenario B

The AI had a known systematic detection problem.

This strengthens a defect argument.

Scenario C

The doctor ignored the system's warning or instructions.

Professional negligence may become relevant.

Scenario D

The AI should never have been used for that clinical purpose.

This may support a product/regulatory argument.

Scenario E

The AI manufacturer failed to provide a critical warning.

A warning/information defect may arise.

17. Doctor's Liability

AI does not automatically replace professional responsibility.

Suppose a physician receives:

"Low probability of cancer — 2%."

The physician accepts the result without considering:

symptoms;

patient history;

clinical examination;

contradictory laboratory findings.

If the patient is harmed, the doctor may face a professional negligence claim under national law.

The legal question may become:

Was it reasonable for the physician to rely on the AI result in the circumstances?

18. Shared Responsibility

AI diagnostic cases may involve several defendants.

ActorPossible liability
AI developerSoftware/product defect
Medical-device manufacturerProduct and regulatory liability
HospitalContractual/institutional liability
DoctorProfessional negligence
DistributorProduct-liability responsibility where applicable
Cloud providerContract/service liability depending on role
Notified bodySpecific regulatory/conformity obligations
Data providerPossible contractual/data-related liability

The claimant must establish the appropriate legal basis against each defendant.

19. Causation

Causation is usually one of the hardest issues.

Consider:

AI fails to detect cancer

↓

Doctor does not order further testing

↓

Six-month delay

↓

Cancer progresses

↓

More invasive treatment

↓

Physical and financial damage

The claimant may need to prove:

the AI was defective or the use of AI was negligent;

the doctor relied on the AI output;

correct diagnosis would probably have occurred earlier;

earlier diagnosis would have changed treatment/outcome;

the delay caused legally recognised damage.

20. The "Black Box" Problem

AI diagnostic systems may be difficult for patients to understand.

A patient may know:

"The AI said the scan was normal."

But may not know:

which features were analysed;

which training data were used;

confidence level;

model version;

whether the image was outside the training distribution;

whether the system detected uncertainty;

whether a human reviewer overrode the result.

This creates an important evidence asymmetry.

The new Product Liability Directive expressly recognises the difficulty of proving causation where the claimant may be required to explain the inner workings of an AI system. (EUR-Lex)

21. Disclosure and Technical Evidence

Important evidence may include:

AI records

input data;

model output;

confidence scores;

model version;

timestamps;

audit logs.

Clinical records

doctor's notes;

diagnostic reports;

treatment records;

imaging records;

laboratory results.

Manufacturer documents

validation studies;

clinical evaluation;

risk assessment;

post-market surveillance;

complaints;

incident reports;

software updates.

Technical evidence

training-data documentation;

performance testing;

false-negative rate;

false-positive rate;

subgroup performance.

22. Bias and Population-Specific Errors

AI diagnostic errors can be particularly serious where a model performs differently across populations.

For example:

Model trained mainly on one demographic group → lower accuracy for another group → missed diagnosis.

Potentially relevant factors include:

sex;

age;

skin characteristics;

ethnicity;

geographic population;

disease prevalence;

hospital environment.

However, poor performance alone does not automatically establish civil liability. The claimant must connect the technical problem to the relevant legal duty, defect or negligence and damage.

23. Product Liability vs Medical Negligence

This distinction is essential.

Product-liability claim

Focus:

Was the AI product defective?

Possible defendant:

manufacturer/provider.

Medical-negligence claim

Focus:

Did the healthcare professional breach the applicable professional standard?

Possible defendant:

doctor/hospital.

Contractual claim

Focus:

Was the healthcare service performed according to the applicable contractual obligations?

Data-protection claim

Focus:

Was personal health data processed unlawfully?

One factual event can potentially generate more than one legal claim.

24. New Directive and AI-Specific Evidence

The new Product Liability Directive is particularly important for future diagnostic-AI cases because it recognises:

software as a product;

AI systems as products;

machine-learning complexity;

complex causal relationships;

updates and upgrades;

cybersecurity vulnerabilities;

cloud/software delivery;

AI-system providers as manufacturers.

It also provides mechanisms concerning disclosure and evidentiary difficulties in technically complex cases. (EUR-Lex)

This is a major change from the older Product Liability Directive, which was drafted before modern AI systems became widespread.

25. AI Act Does Not Replace Civil Liability

The AI Act primarily establishes regulatory obligations.

For example:

AI system fails regulatory requirements.

That fact can be highly relevant evidence.

But the claimant must still establish the civil-law requirements applicable to the particular claim.

Therefore:

AI Act breach

does not automatically equal

automatic compensation.

The same applies to the MDR.

26. Possible Remedies

Depending on the applicable national law and liability regime, remedies may include:

Compensation for physical injury

additional treatment;

rehabilitation;

disability;

loss of earnings;

future medical expenses.

Non-material damage

Depending upon national law:

pain and suffering;

loss of enjoyment of life;

psychological consequences.

Economic damage

medical expenses;

care expenses;

lost income;

additional treatment costs.

Product-related remedies

replacement;

corrective action;

recall-related costs where legally recoverable.

Injunctive/regulatory remedies

Depending on the procedural framework:

cessation of unlawful conduct;

corrective measures;

withdrawal of unsafe products.

27. Defences

AI developers and medical institutions may argue:

1. No defect

The system performed according to its intended purpose.

2. Misuse

The hospital or physician used the system outside its intended purpose.

3. Human error

The AI generated an appropriate warning but the physician ignored it.

4. Causation failure

The patient's outcome would have occurred regardless.

5. State of scientific knowledge

The alleged defect could not reasonably have been identified using the relevant scientific and technical knowledge.

6. Third-party intervention

Another party altered or misused the system.

7. Insufficient evidence

The claimant cannot demonstrate the alleged technical defect.

The strength of these defences depends heavily on the facts and applicable national law.

28. AI Diagnostic Error — Hypothetical Example

Suppose a hospital uses an AI radiology system.

The system analyses a patient's CT scan and reports:

"No evidence of malignancy."

Six months later, the patient is diagnosed with advanced cancer.

An effective legal analysis would ask:

Step 1 — Was the AI a medical device?

If yes, MDR requirements become relevant.

Step 2 — Was it high-risk AI?

Determine its classification under the AI Act.

Step 3 — Was the system defective?

Examine:

algorithm;

training data;

validation;

software version;

known failure rates.

Step 4 — Did the doctor rely on it?

Examine clinical records.

Step 5 — Was the reliance reasonable?

Apply the relevant national professional standard.

Step 6 — Did earlier diagnosis probably change the outcome?

Medical expert evidence.

Step 7 — What damage occurred?

Medical, economic and non-material damage.

Step 8 — Which defendant is responsible?

Potentially:

AI manufacturer;

medical-device manufacturer;

hospital;

physician.

29. Six Most Important Cases for Revision

CaseCitationKey ruleAI diagnostic relevance
Boston ScientificC-503/13 & C-504/13Potential defect in medical-device series can establish defectivenessVery high
VeedfaldC-203/99Broad protection/compensation in defective medical-product casesHigh
González SánchezC-183/00Harmonised product-liability frameworkHigh
Sanofi PasteurC-621/15Evidence and causation in scientifically complex medical claimsVery high
Schmitt v TÜV RheinlandC-219/15Medical-device conformity-assessment responsibilitiesHigh
O'Byrne v Sanofi PasteurC-127/04Putting product into circulation / producer responsibilityHigh
Commission v UKC-300/95Development-risk defenceHigh

30. Key Legal Formula

For an AI diagnostic product-liability claim:

AI Medical Device + Defect + Failure of Expected Safety + Personal Injury/Damage + Causation + Responsible Economic Operator = Potential Product-Liability Claim

For professional negligence:

AI Error + Unreasonable Professional Reliance + Breach of Professional Standard + Causation + Patient Damage = Potential Medical-Negligence Claim

For a combined claim:

AI Defect + Clinical Reliance + Professional Error + Causal Medical Harm = Potential Multiple-Defendant Liability

31. Important Distinction for 2026

Because the current date is 28 September 2026, the timing of the new Product Liability Directive matters.

Directive (EU) 2024/2853 states that it applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)

Therefore, a 2026 AI diagnostic case cannot simply be analysed as though the new Directive were already applicable to every existing product.

For earlier products, the analysis may instead depend on:

the former Product Liability Directive 85/374/EEC;

MDR;

AI Act;

national tort/delict law;

national medical-negligence law;

contract law;

applicable procedural/evidentiary rules.

32. Conclusion

AI diagnostic tool error liability in Europe is a multi-layered civil-law problem.

The central issues are:

Was the AI system a regulated medical device?

Was it defective?

Did it perform below the safety level reasonably expected?

Was there inadequate validation or warning?

Did the doctor reasonably rely on it?

Did the AI error cause the medical harm?

Which actor legally controlled the defective system?

Can the claimant obtain sufficient technical evidence?

Which product-liability regime applies according to the date of market placement?

Do national medical-negligence and civil-law rules create additional liability?

The most important authorities are Boston Scientific (C-503/13 and C-504/13), Veedfald (C-203/99), González Sánchez (C-183/00), Sanofi Pasteur (C-621/15), Schmitt (C-219/15), O'Byrne (C-127/04), and Commission v United Kingdom (C-300/95).

The future significance of Directive (EU) 2024/2853 is particularly strong: it expressly brings software and AI systems within the concept of products and recognises the special evidentiary and causal difficulties associated with AI and machine learning. (EUR-Lex)

Exam/Revision Keywords

AI medical device — diagnostic error — false negative — false positive — medical negligence — product defect — defective software — MDR — AI Act — Product Liability Directive — medical-device safety — clinical validation — training data — algorithmic bias — human oversight — causation — black-box problem — technical evidence — notified body — manufacturer — hospital liability — doctor liability — software update — cybersecurity defect — development-risk defence — personal injury — compensation — evidentiary difficulty — machine learning liability.

LEAVE A COMMENT