Civil Law And Ai Diagnostic Tool Error Liability In Europe .
Civil Law and AI Diagnostic Tool Error Liability in Europe
1. Introduction
AI diagnostic tool error liability arises when an AI-enabled medical system incorrectly analyses symptoms, medical images, laboratory results, pathology slides, genetic information or other health data and the error causes harm.
Examples include:
an AI radiology system failing to detect a tumour;
an AI system incorrectly identifying a benign lesion as malignant;
an AI pathology tool producing a false-negative result;
an AI diagnostic system generating a false-positive result leading to unnecessary treatment;
an AI system using outdated clinical data;
an algorithm producing an incorrect risk score;
software malfunction after an update;
a healthcare professional relying excessively on an AI recommendation;
an AI diagnostic device being insufficiently tested or validated;
a medical AI system giving an incorrect result because of biased or incomplete training data.
European liability is not based on one single AI-liability rule. It involves a combination of medical-device regulation, product liability, professional negligence, contract law, data protection and, increasingly, AI-specific regulation.
The most important development is the new Product Liability Directive (EU) 2024/2853, which expressly treats software, including AI systems, as products for product-liability purposes. It applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)
2. Basic Liability Model
A diagnostic AI error can be analysed as:
AI diagnostic system
↓
Incorrect output
↓
Doctor/hospital/patient relies on output
↓
Incorrect diagnosis or delayed diagnosis
↓
Treatment delay / unnecessary treatment / physical injury
↓
Damage
↓
Causation
↓
Potential civil liability
The central legal question is:
Was the AI diagnostic system defective, was the healthcare professional negligent in relying on it, or did both factors contribute to the patient's injury?
3. What Is an AI Diagnostic Tool?
Under the EU Medical Devices Regulation, software can constitute a medical device where it is intended for medical purposes including diagnosis, prevention, monitoring, prediction, prognosis or treatment of disease. (EUR-Lex)
Therefore, an AI diagnostic program may fall within the medical-device regulatory framework where its intended purpose satisfies the relevant definition.
Examples:
Imaging AI
Analyses:
X-rays;
CT scans;
MRI images;
ultrasound;
mammograms.
Pathology AI
Analyses:
biopsy slides;
cancer cells;
tissue samples.
Clinical decision-support AI
Combines:
symptoms;
medical history;
laboratory results;
medications;
demographic information.
Predictive diagnostic AI
Predicts:
disease probability;
deterioration risk;
cardiovascular risk;
sepsis risk;
cancer probability.
4. Main European Legal Framework
A. Medical Devices Regulation — Regulation (EU) 2017/745
The MDR is fundamental for AI medical devices.
A medical device must satisfy relevant safety and performance requirements.
The general requirements include that devices achieve their intended performance and be designed and manufactured so that they are safe and effective and do not compromise the clinical condition or safety of patients, taking account of the generally acknowledged state of the art. (EUR-Lex)
For AI diagnostic tools, this raises questions concerning:
clinical validation;
accuracy;
reliability;
cybersecurity;
software updates;
data quality;
intended purpose;
human oversight;
post-market monitoring.
5. AI Act
The AI Act creates another regulatory layer.
AI systems that are safety components of products covered by specified EU harmonisation legislation, including medical devices and in-vitro diagnostic medical devices, can fall within the high-risk AI system framework where the Article 6 conditions are satisfied. (EUR-Lex)
This is particularly important because an AI diagnostic system may simultaneously be:
software + medical device + high-risk AI system
depending upon its precise regulatory classification.
The AI Act addresses issues such as:
risk management;
data governance;
technical documentation;
record keeping;
transparency;
human oversight;
accuracy;
robustness;
cybersecurity.
But an important distinction must be maintained:
Regulatory non-compliance does not automatically establish every element of a civil damages claim.
The claimant must still establish the appropriate liability basis, damage and causation.
6. New Product Liability Directive
Directive (EU) 2024/2853 is especially important for AI diagnostic litigation.
It expressly recognises that:
software, including AI systems, can constitute products.
The Directive states that software can be a standalone product or integrated into another product and can cause damage through its operation. It also expressly contemplates AI-system providers as manufacturers for product-liability purposes. (EUR-Lex)
The Directive applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)
Thus, there is an important date distinction:
| Situation | Principal framework |
|---|---|
| Older AI medical product | Existing national + EU product-liability framework |
| AI medical device before 8 Dec 2026 | MDR + existing national/product liability |
| Products covered by new Directive after 8 Dec 2026 | Directive 2024/2853 + national implementing law |
| AI medical device + high-risk AI | MDR + AI Act + applicable civil liability |
7. Case Law
The existing European case law predates modern generative AI, but several decisions provide highly relevant principles.
Case 1 — Boston Scientific Medizintechnik GmbH v AOK Sachsen-Anhalt and Others
Joined Cases C-503/13 and C-504/13
CJEU, 5 March 2015
This is probably the most important existing CJEU authority for an AI diagnostic-device liability analogy.
The case concerned pacemakers and implantable cardioverter defibrillators.
The Court held that where products belonging to the same group or production series have a potential defect, an individual product may be classified as defective even without proving that the specific individual device actually malfunctioned. (Infocuria)
The Court also held that necessary surgical replacement costs could constitute compensable personal-injury damage. (Infocuria)
Relevance to AI
Suppose an AI diagnostic product is discovered to have a systematic defect:
faulty training dataset;
recurring software bug;
systematic image-recognition error;
dangerous update;
flawed algorithmic threshold.
A claimant may argue that the defect concerns the system/product class, rather than requiring proof of every internal technical failure.
Principle
A systemic safety defect can be legally significant even where the precise technical malfunction in an individual case is difficult to isolate.
This is highly relevant to AI systems whose internal operations can be difficult for patients to reconstruct.
8. Case 2 — Veedfald
Case C-203/99
CJEU, 10 May 2001
Veedfald concerned a medical procedure involving a defective medical product.
The CJEU emphasised the requirement of effective compensation for persons injured by defective products.
The case is particularly important for understanding the broad protective objective of European product liability.
It is also cited in later product-liability decisions concerning compensation for harm caused by defective medical products.
AI relevance
An AI diagnostic tool can cause harm indirectly.
For example:
AI error → doctor receives incorrect result → incorrect treatment → physical injury.
The fact that the injury arises through a medical process does not necessarily eliminate product-liability considerations.
Principle
The product-liability regime is concerned with protection against damage caused by defective products, including in medical contexts.
9. Case 3 — González Sánchez v Medicina Asturiana
Case C-183/00
CJEU, 25 April 2002
This case concerned the EU Product Liability Directive and the relationship between the harmonised EU regime and national liability rules.
The CJEU emphasised the harmonising nature of the Directive and the framework governing producer liability for defective products. (curia)
AI relevance
An AI diagnostic claim may be brought under:
product liability;
contractual liability;
professional negligence;
national tort/delict law.
The claimant must determine which legal regime actually applies and whether EU harmonisation limits additional national rules.
Principle
The EU product-liability regime and national civil-liability rules must be carefully distinguished.
10. Case 4 — N.W. and Others v Sanofi Pasteur MSD
Case C-621/15
CJEU, 21 June 2017
This case concerned alleged harm caused by a vaccine.
The Court considered how defect and causation could be proved where scientific evidence does not provide a definitive consensus.
The Court accepted that, subject to national judicial assessment, serious, specific and consistent evidence could potentially establish defect and causation. Relevant circumstances could include temporal proximity and absence of relevant personal or family history. (curia)
AI relevance
AI diagnostic litigation can involve difficult scientific causation.
For example:
AI error → delayed diagnosis → disease progression.
The defendant may argue:
"The disease would have progressed anyway."
The claimant may therefore need medical and technical evidence connecting:
AI error → missed diagnosis → delay → worsened condition.
Principle
Causation in technically complex medical cases may require assessment of a combination of evidence rather than one isolated scientific fact.
This is an analogy, not an AI-specific ruling.
11. Case 5 — Elisabeth Schmitt v TÜV Rheinland
Case C-219/15
CJEU, 16 February 2017
This case concerned defective breast implants and the responsibilities of a notified body involved in conformity assessment.
The Court examined whether the notified body could have obligations under the Medical Devices Directive and how failure to perform those duties should be treated under national law. (Infocuria)
The case is important because it demonstrates that medical-device safety involves multiple actors:
manufacturer;
conformity-assessment body;
healthcare providers;
regulators.
AI relevance
An AI diagnostic tool may similarly involve:
AI developer → medical-device manufacturer → notified body → hospital → doctor → patient
A failure by one actor does not necessarily establish automatic liability of every other actor.
Principle
The legal responsibility of a conformity-assessment body must be distinguished from the manufacturer's product liability and assessed under the applicable legal framework.
12. Case 6 — O'Byrne v Sanofi Pasteur MSD
Case C-127/04
CJEU, 9 February 2006
This case concerned the concept of putting a product into circulation under the Product Liability Directive.
The Court examined circumstances in which a product supplied within a corporate group could be regarded as having been put into circulation.
AI relevance
AI medical systems may have complicated supply structures:
AI developer → software distributor → medical-device manufacturer → hospital → cloud provider.
Determining who legally placed the product on the market may therefore become important.
Principle
Identifying the legally responsible producer/supplier is essential in product-liability litigation.
This becomes especially important for AI systems supplied through cloud or software-as-a-service models.
13. Case 7 — Commission v United Kingdom
Case C-300/95
CJEU, 29 May 1997
This case concerned the so-called development-risk defence under the Product Liability Directive.
The case is relevant to the question of whether the state of scientific and technical knowledge made it possible to discover a defect.
AI relevance
AI technology develops continuously.
A manufacturer might argue:
"The diagnostic error could not have been discovered using the scientific and technical knowledge available at the relevant time."
The claimant may respond with evidence showing:
known validation problems;
known dataset limitations;
known performance disparities;
previous complaints;
known software errors;
inadequate testing.
The new Product Liability Directive continues to recognise a state-of-scientific-and-technical-knowledge defence, subject to its conditions. (EUR-Lex)
14. Case 8 — Boston Scientific: Broader Importance
The Boston Scientific decision deserves additional attention because the Court recognised that the safety level a patient is entitled to expect is central to determining defectiveness.
For AI diagnostic systems, expected safety may involve:
diagnostic accuracy;
reliability;
predictable operation;
adequate warnings;
cybersecurity;
software updates;
appropriate intended-use limitations.
The new Product Liability Directive expressly recognises that machine learning and AI can create technical and causal complexity. It allows national courts to consider excessive difficulties faced by claimants in proving defectiveness or causation. (EUR-Lex)
That is particularly significant for AI litigation.
15. What Constitutes an AI Diagnostic Defect?
A diagnostic AI system may potentially be defective where it fails to provide the level of safety persons are entitled to expect.
Potential defects include:
A. Design defect
The algorithm is inherently unsuitable for its intended purpose.
Example:
The model systematically misses early-stage tumours.
B. Manufacturing/software defect
A coding or deployment error causes incorrect outputs.
C. Training-data defect
The training dataset is materially inadequate for the intended patient population.
D. Validation defect
The manufacturer releases the system without sufficient clinical validation.
E. Warning defect
The manufacturer fails to warn doctors that the system:
performs poorly on certain populations;
should not be used for particular diseases;
requires human verification.
F. Update defect
An update reduces diagnostic reliability.
G. Cybersecurity defect
A vulnerability allows manipulation of diagnostic outputs.
The new Product Liability Directive expressly recognises liability for certain defects arising from software updates, upgrades and machine-learning algorithms remaining within the manufacturer's control. (EUR-Lex)
16. Incorrect Result vs Defective Product
An important distinction is:
Wrong diagnosis ≠ automatically defective AI product.
Suppose AI says:
"No tumour detected."
The patient later develops cancer.
There are several possibilities:
Scenario A
The AI system correctly operated according to its intended performance.
The error may not automatically establish product defect.
Scenario B
The AI had a known systematic detection problem.
This strengthens a defect argument.
Scenario C
The doctor ignored the system's warning or instructions.
Professional negligence may become relevant.
Scenario D
The AI should never have been used for that clinical purpose.
This may support a product/regulatory argument.
Scenario E
The AI manufacturer failed to provide a critical warning.
A warning/information defect may arise.
17. Doctor's Liability
AI does not automatically replace professional responsibility.
Suppose a physician receives:
"Low probability of cancer — 2%."
The physician accepts the result without considering:
symptoms;
patient history;
clinical examination;
contradictory laboratory findings.
If the patient is harmed, the doctor may face a professional negligence claim under national law.
The legal question may become:
Was it reasonable for the physician to rely on the AI result in the circumstances?
18. Shared Responsibility
AI diagnostic cases may involve several defendants.
| Actor | Possible liability |
|---|---|
| AI developer | Software/product defect |
| Medical-device manufacturer | Product and regulatory liability |
| Hospital | Contractual/institutional liability |
| Doctor | Professional negligence |
| Distributor | Product-liability responsibility where applicable |
| Cloud provider | Contract/service liability depending on role |
| Notified body | Specific regulatory/conformity obligations |
| Data provider | Possible contractual/data-related liability |
The claimant must establish the appropriate legal basis against each defendant.
19. Causation
Causation is usually one of the hardest issues.
Consider:
AI fails to detect cancer
↓
Doctor does not order further testing
↓
Six-month delay
↓
Cancer progresses
↓
More invasive treatment
↓
Physical and financial damage
The claimant may need to prove:
the AI was defective or the use of AI was negligent;
the doctor relied on the AI output;
correct diagnosis would probably have occurred earlier;
earlier diagnosis would have changed treatment/outcome;
the delay caused legally recognised damage.
20. The "Black Box" Problem
AI diagnostic systems may be difficult for patients to understand.
A patient may know:
"The AI said the scan was normal."
But may not know:
which features were analysed;
which training data were used;
confidence level;
model version;
whether the image was outside the training distribution;
whether the system detected uncertainty;
whether a human reviewer overrode the result.
This creates an important evidence asymmetry.
The new Product Liability Directive expressly recognises the difficulty of proving causation where the claimant may be required to explain the inner workings of an AI system. (EUR-Lex)
21. Disclosure and Technical Evidence
Important evidence may include:
AI records
input data;
model output;
confidence scores;
model version;
timestamps;
audit logs.
Clinical records
doctor's notes;
diagnostic reports;
treatment records;
imaging records;
laboratory results.
Manufacturer documents
validation studies;
clinical evaluation;
risk assessment;
post-market surveillance;
complaints;
incident reports;
software updates.
Technical evidence
training-data documentation;
performance testing;
false-negative rate;
false-positive rate;
subgroup performance.
22. Bias and Population-Specific Errors
AI diagnostic errors can be particularly serious where a model performs differently across populations.
For example:
Model trained mainly on one demographic group → lower accuracy for another group → missed diagnosis.
Potentially relevant factors include:
sex;
age;
skin characteristics;
ethnicity;
geographic population;
disease prevalence;
hospital environment.
However, poor performance alone does not automatically establish civil liability. The claimant must connect the technical problem to the relevant legal duty, defect or negligence and damage.
23. Product Liability vs Medical Negligence
This distinction is essential.
Product-liability claim
Focus:
Was the AI product defective?
Possible defendant:
manufacturer/provider.
Medical-negligence claim
Focus:
Did the healthcare professional breach the applicable professional standard?
Possible defendant:
doctor/hospital.
Contractual claim
Focus:
Was the healthcare service performed according to the applicable contractual obligations?
Data-protection claim
Focus:
Was personal health data processed unlawfully?
One factual event can potentially generate more than one legal claim.
24. New Directive and AI-Specific Evidence
The new Product Liability Directive is particularly important for future diagnostic-AI cases because it recognises:
software as a product;
AI systems as products;
machine-learning complexity;
complex causal relationships;
updates and upgrades;
cybersecurity vulnerabilities;
cloud/software delivery;
AI-system providers as manufacturers.
It also provides mechanisms concerning disclosure and evidentiary difficulties in technically complex cases. (EUR-Lex)
This is a major change from the older Product Liability Directive, which was drafted before modern AI systems became widespread.
25. AI Act Does Not Replace Civil Liability
The AI Act primarily establishes regulatory obligations.
For example:
AI system fails regulatory requirements.
That fact can be highly relevant evidence.
But the claimant must still establish the civil-law requirements applicable to the particular claim.
Therefore:
AI Act breach
does not automatically equal
automatic compensation.
The same applies to the MDR.
26. Possible Remedies
Depending on the applicable national law and liability regime, remedies may include:
Compensation for physical injury
additional treatment;
rehabilitation;
disability;
loss of earnings;
future medical expenses.
Non-material damage
Depending upon national law:
pain and suffering;
loss of enjoyment of life;
psychological consequences.
Economic damage
medical expenses;
care expenses;
lost income;
additional treatment costs.
Product-related remedies
replacement;
corrective action;
recall-related costs where legally recoverable.
Injunctive/regulatory remedies
Depending on the procedural framework:
cessation of unlawful conduct;
corrective measures;
withdrawal of unsafe products.
27. Defences
AI developers and medical institutions may argue:
1. No defect
The system performed according to its intended purpose.
2. Misuse
The hospital or physician used the system outside its intended purpose.
3. Human error
The AI generated an appropriate warning but the physician ignored it.
4. Causation failure
The patient's outcome would have occurred regardless.
5. State of scientific knowledge
The alleged defect could not reasonably have been identified using the relevant scientific and technical knowledge.
6. Third-party intervention
Another party altered or misused the system.
7. Insufficient evidence
The claimant cannot demonstrate the alleged technical defect.
The strength of these defences depends heavily on the facts and applicable national law.
28. AI Diagnostic Error — Hypothetical Example
Suppose a hospital uses an AI radiology system.
The system analyses a patient's CT scan and reports:
"No evidence of malignancy."
Six months later, the patient is diagnosed with advanced cancer.
An effective legal analysis would ask:
Step 1 — Was the AI a medical device?
If yes, MDR requirements become relevant.
Step 2 — Was it high-risk AI?
Determine its classification under the AI Act.
Step 3 — Was the system defective?
Examine:
algorithm;
training data;
validation;
software version;
known failure rates.
Step 4 — Did the doctor rely on it?
Examine clinical records.
Step 5 — Was the reliance reasonable?
Apply the relevant national professional standard.
Step 6 — Did earlier diagnosis probably change the outcome?
Medical expert evidence.
Step 7 — What damage occurred?
Medical, economic and non-material damage.
Step 8 — Which defendant is responsible?
Potentially:
AI manufacturer;
medical-device manufacturer;
hospital;
physician.
29. Six Most Important Cases for Revision
| Case | Citation | Key rule | AI diagnostic relevance |
|---|---|---|---|
| Boston Scientific | C-503/13 & C-504/13 | Potential defect in medical-device series can establish defectiveness | Very high |
| Veedfald | C-203/99 | Broad protection/compensation in defective medical-product cases | High |
| González Sánchez | C-183/00 | Harmonised product-liability framework | High |
| Sanofi Pasteur | C-621/15 | Evidence and causation in scientifically complex medical claims | Very high |
| Schmitt v TÜV Rheinland | C-219/15 | Medical-device conformity-assessment responsibilities | High |
| O'Byrne v Sanofi Pasteur | C-127/04 | Putting product into circulation / producer responsibility | High |
| Commission v UK | C-300/95 | Development-risk defence | High |
30. Key Legal Formula
For an AI diagnostic product-liability claim:
AI Medical Device + Defect + Failure of Expected Safety + Personal Injury/Damage + Causation + Responsible Economic Operator = Potential Product-Liability Claim
For professional negligence:
AI Error + Unreasonable Professional Reliance + Breach of Professional Standard + Causation + Patient Damage = Potential Medical-Negligence Claim
For a combined claim:
AI Defect + Clinical Reliance + Professional Error + Causal Medical Harm = Potential Multiple-Defendant Liability
31. Important Distinction for 2026
Because the current date is 28 September 2026, the timing of the new Product Liability Directive matters.
Directive (EU) 2024/2853 states that it applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)
Therefore, a 2026 AI diagnostic case cannot simply be analysed as though the new Directive were already applicable to every existing product.
For earlier products, the analysis may instead depend on:
the former Product Liability Directive 85/374/EEC;
MDR;
AI Act;
national tort/delict law;
national medical-negligence law;
contract law;
applicable procedural/evidentiary rules.
32. Conclusion
AI diagnostic tool error liability in Europe is a multi-layered civil-law problem.
The central issues are:
Was the AI system a regulated medical device?
Was it defective?
Did it perform below the safety level reasonably expected?
Was there inadequate validation or warning?
Did the doctor reasonably rely on it?
Did the AI error cause the medical harm?
Which actor legally controlled the defective system?
Can the claimant obtain sufficient technical evidence?
Which product-liability regime applies according to the date of market placement?
Do national medical-negligence and civil-law rules create additional liability?
The most important authorities are Boston Scientific (C-503/13 and C-504/13), Veedfald (C-203/99), González Sánchez (C-183/00), Sanofi Pasteur (C-621/15), Schmitt (C-219/15), O'Byrne (C-127/04), and Commission v United Kingdom (C-300/95).
The future significance of Directive (EU) 2024/2853 is particularly strong: it expressly brings software and AI systems within the concept of products and recognises the special evidentiary and causal difficulties associated with AI and machine learning. (EUR-Lex)
Exam/Revision Keywords
AI medical device — diagnostic error — false negative — false positive — medical negligence — product defect — defective software — MDR — AI Act — Product Liability Directive — medical-device safety — clinical validation — training data — algorithmic bias — human oversight — causation — black-box problem — technical evidence — notified body — manufacturer — hospital liability — doctor liability — software update — cybersecurity defect — development-risk defence — personal injury — compensation — evidentiary difficulty — machine learning liability.

comments