Civil Law And Ai Epistemic Harm Civil Liability Frameworks In Europe .

Civil Law and AI Epistemic Harm Civil Liability Frameworks in Europe

1. Introduction

AI epistemic harm refers to harm caused when an AI system produces, ranks, recommends, classifies, or communicates information in a way that causes a person to hold, rely upon, or act upon false, misleading, distorted, incomplete, or unjustifiably confident information.

Examples include:

an AI chatbot falsely accusing a person of criminal conduct;

an AI search engine generating a fabricated biography;

an automated credit system assigning an inaccurate risk score;

an AI medical system providing materially false information;

an algorithm systematically presenting unreliable information as authoritative;

an AI system making an unexplained factual classification that affects employment, insurance or credit;

an AI recommendation system amplifying demonstrably false information;

a generative-AI system inventing legal, financial or professional information on which a user reasonably relies.

European law does not presently recognise “epistemic harm” as one autonomous, harmonised civil-law cause of action. Instead, liability is constructed through several overlapping areas: product liability, contractual liability, national tort/delict law, GDPR, consumer law, platform regulation, professional liability and fundamental-rights jurisprudence.

This fragmentation is particularly important because the EU's new Product Liability Directive expressly treats software and AI systems as products, while at the same time excluding information itself from the definition of a product. It applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)

2. Meaning of AI Epistemic Harm

“Epistemic” concerns knowledge, belief, information and the ability to distinguish truth from falsehood.

Therefore, epistemic harm may arise where an AI system:

provides false information;

suppresses relevant information;

presents uncertain information as certain;

generates fabricated sources or authorities;

produces an inaccurate personal profile;

makes an erroneous automated classification;

causes a person to rely on false information;

damages reputation through false AI-generated statements;

interferes with a person's ability to make an informed decision;

creates economic or personal loss because the recipient relied upon inaccurate output.

Example

Suppose an AI credit system incorrectly calculates:

“This customer is highly likely to default.”

A bank relies on that assessment and refuses credit.

There may be several legally distinct harms:

informational harm — the underlying assessment is inaccurate;

autonomy harm — the individual cannot understand or challenge the decision;

economic harm — credit is refused;

reputational harm — the person is treated as financially unreliable;

data-protection harm — inaccurate personal data may have been processed;

civil liability — depending on the legal basis, compensation may become available.

3. Europe Has No Single “Epistemic Harm” Tort

A crucial point is that Europe is not one civil-law jurisdiction.

EU law creates common regulatory frameworks, but individual civil claims may arise under:

French responsabilité civile;

German Bürgerliches Gesetzbuch tort and contractual doctrines;

Italian responsabilità civile;

Spanish civil liability;

Dutch tort law;

national consumer law;

national defamation law;

national professional-negligence rules.

Consequently, an AI epistemic-harm claim normally requires identifying:

AI output → legally protected interest → wrongful/defective conduct → damage → causation → applicable remedy.

4. Main European Legal Framework

A. GDPR

The GDPR is particularly important where AI produces:

inaccurate personal profiles;

automated scores;

inferred characteristics;

discriminatory classifications;

automated decisions;

reputation-damaging personal information.

Article 5 requires personal data to be accurate, while Articles 15 and 22 are especially relevant to information about automated processing and automated decision-making.

Article 82 provides a compensation mechanism where unlawful processing causes material or non-material damage.

The CJEU has clarified that mere GDPR infringement is not automatically enough for compensation: infringement, damage and causal connection must be established. At the same time, EU law does not impose a minimum seriousness threshold for qualifying non-material damage. (Infocuria)

5. EU AI Act

The EU AI Act, Regulation (EU) 2024/1689, is important for epistemic-risk governance, transparency and prohibited/high-risk AI practices.

However, it should not be treated as a general AI civil-liability statute.

A claimant will often need to combine AI Act obligations with:

GDPR;

product liability;

contract;

tort/delict;

consumer protection;

professional negligence;

national defamation law.

Thus:

AI Act violation ≠ automatically a private damages claim.

The claimant must identify the applicable private-law cause of action and prove the required elements.

6. New EU Product Liability Framework

The Product Liability Directive (EU) 2024/2853 substantially changes the technological environment.

It expressly recognises:

software;

AI systems;

software supplied through cloud technologies;

software-as-a-service models

within the concept of products for product-liability purposes. (EUR-Lex)

The Directive also recognises the evidentiary difficulties victims face with technologically complex products.

Importantly, however, it states that information itself is not a product. Consequently, a claimant cannot simply characterise every false AI statement as a defective product. The distinction between:

defective AI software

and

incorrect information produced by that software

may become crucial. (EUR-Lex)

The new Directive applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)

7. AI Liability Directive — Important Development

The proposed AI Liability Directive would have addressed certain non-contractual liability problems arising from AI systems, including evidentiary difficulties.

However, the legislative procedure for the proposed AI Liability Directive has been withdrawn. (EUR-Lex)

Therefore, it should not be presented as an enacted EU-wide civil-liability regime.

Its withdrawal increases the importance of existing mechanisms:

national tort law;

GDPR;

Product Liability Directive;

contractual liability;

consumer law;

sector-specific legislation.

8. At Least 6 Important Case Laws

Because reported European litigation specifically using the expression “AI epistemic harm” remains limited, the strongest authorities are principally analogical cases involving automated scoring, inaccurate information, data accuracy, product defects and proof of technologically complex causation.

Case 1 — SCHUFA Holding (Scoring)

OQ v Land Hessen / SCHUFA Holding, Case C-634/21, CJEU, 7 December 2023
ECLI:EU:C:2023:957

Facts

SCHUFA generated creditworthiness scores concerning individuals. Those scores were used in circumstances capable of significantly affecting access to economic opportunities.

Principle

The CJEU held that Article 22 GDPR can apply where an automated assessment effectively determines an important decision concerning an individual.

The case is particularly significant because the problem was not simply that data existed. It concerned the automated transformation of information into a consequential prediction.

The CJEU's judgment dealt specifically with automated scoring and the use of probability values concerning a person's ability to meet financial obligations. (Infocuria)

Relevance to epistemic harm

This is one of the closest European analogies to AI epistemic harm.

An AI system may transform uncertain statistical information into an apparently objective conclusion:

data → model → score → decision → harm.

The epistemic problem is that the model's prediction can acquire practical authority despite being probabilistic rather than factual.

Legal significance

It demonstrates that European law can regulate the consequences of machine-generated knowledge about an individual, particularly where that knowledge drives consequential decisions.

Classification: Directly relevant analogical authority.

Case 2 — Dun & Bradstreet Austria

CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria, Case C-203/22, CJEU, 27 February 2025
ECLI:EU:C:2025:117

Facts

An Austrian telecommunications customer was refused a contract following an automated assessment of her creditworthiness.

She sought information concerning the logic behind the automated assessment.

Decision

The CJEU addressed Article 15(1)(h) GDPR and the requirement to provide meaningful information about the logic involved in automated decision-making.

The explanation must enable the affected person to understand and challenge the automated decision. (Infocuria)

Epistemic importance

This case is extremely important for epistemic harm because a person may suffer harm not merely because an algorithm is wrong, but because:

the person cannot understand why the algorithm is wrong.

This creates an epistemic asymmetry:

AI provider possesses the model;

individual receives the outcome;

individual lacks access to the reasoning;

individual cannot effectively contest the result.

Legal significance

Transparency therefore becomes connected with substantive civil protection.

Classification: Strong analogical authority.

Case 3 — Österreichische Post

UI v Österreichische Post AG, Case C-300/21, CJEU, 4 May 2023
ECLI:EU:C:2023:370

Facts

Österreichische Post used an algorithm to analyse socio-demographic information and infer political affinities of individuals.

One individual was incorrectly associated with a political party.

He claimed distress, loss of confidence and a feeling of exposure resulting from the inference. (curia)

Principle

The CJEU held that:

GDPR infringement alone does not automatically establish a compensation claim;

actual material or non-material damage must be established;

there is nevertheless no requirement that non-material damage reach a particular minimum seriousness threshold. (Infocuria)

Epistemic significance

This is highly relevant because the alleged harm came from an algorithmically generated belief about the individual.

The system did not merely copy an existing fact.

It inferred something about the person.

That distinction is fundamental to AI epistemic harm.

AI systems routinely generate:

personality predictions;

risk scores;

political preferences;

health predictions;

behavioural classifications;

fraud probabilities.

Legal significance

It demonstrates that erroneous algorithmic inference can implicate both:

informational interests + non-material personal harm.

Classification: Strong analogical authority.

Case 4 — Google Spain

Google Spain SL and Google Inc. v AEPD and Mario Costeja González, Case C-131/12, CJEU, 13 May 2014
ECLI:EU:C:2014:317

Facts

An individual challenged the continued association of his name with information appearing in search results.

Principle

The CJEU recognised significant responsibilities for search-engine operators concerning the processing and presentation of personal information and developed the framework commonly associated with the right to delisting/de-referencing.

The case concerned the responsibility of search-engine operators for processing information contained on third-party websites. (Infocuria)

Epistemic-harm relevance

AI search and answer systems may similarly determine:

what information a person sees first and therefore what the person is likely to believe.

A traditional search engine ranks existing information.

A generative AI system may go further and synthesize an answer.

The epistemic risk therefore potentially becomes greater:

retrieval → ranking → synthesis → apparent factual assertion.

Legal significance

Google Spain supplies an important conceptual foundation for examining:

accuracy;

relevance;

persistence of information;

reputation;

informational autonomy.

Classification: Analogical authority.

Case 5 — W and Others v Sanofi Pasteur

W and Others v Sanofi Pasteur MSD SNC, Case C-621/15, CJEU, 21 June 2017
ECLI:EU:C:2017:484

Facts

The case involved an alleged defect in a hepatitis-B vaccine and the evidentiary difficulty of establishing causation where scientific knowledge was uncertain.

Principle

The CJEU examined whether national evidentiary rules could permit proof through sufficiently serious, specific and consistent evidence in circumstances where scientific consensus did not conclusively establish causation. (curia)

Relevance to AI epistemic harm

AI disputes may present exactly the same evidentiary problem:

How does a claimant prove that an opaque model caused the particular harm?

For example:

Was the AI model defective?

Was the training data defective?

Was the output caused by a model defect?

Was the user's interpretation responsible?

Did the AI output actually cause the financial loss?

Legal significance

The case provides an important analogy for causation under scientific and technical uncertainty.

Classification: Analogical product-liability authority.

Case 6 — Boston Scientific

Boston Scientific Medizintechnik GmbH v AOK Sachsen-Anhalt and Others, Joined Cases C-503/13 and C-504/13, CJEU, 5 March 2015
ECLI:EU:C:2015:148

Facts

The litigation concerned pacemakers and implantable cardioverter defibrillators which presented potential safety defects.

Principle

The CJEU held that where products in the same group or production series have a potential defect, an individual product may be regarded as defective without proving that the particular product examined contains that defect.

The Court also recognised consequential personal injury-related damage associated with replacement of defective devices. (Infocuria)

AI relevance

AI systems create a comparable problem.

Suppose a model version has a systematic:

hallucination problem;

bias;

data corruption;

unsafe reasoning mechanism;

cybersecurity vulnerability.

The claimant may face difficulty proving that the precise output resulted from a particular internal defect.

Boston Scientific provides an important conceptual analogy for dealing with systemic technological defects.

Legal significance

It may become particularly relevant to future litigation concerning defective AI software under the new Product Liability Directive.

Classification: Analogical authority.

Case 7 — Moteurs Leroy Somer

Moteurs Leroy Somer v Dalkia France and Ace Europe, Case C-285/08, CJEU, 4 June 2009
ECLI:EU:C:2009:351

This case concerned the scope of EU product liability and the distinction between damage falling within the harmonised product-liability regime and other forms of economic loss. (Infocuria)

Relevance

AI epistemic harm frequently involves pure economic loss:

incorrect investment information;

wrong credit classification;

erroneous business intelligence;

fabricated legal advice;

false commercial information.

Therefore, the classification of the alleged loss becomes critical.

A claimant must determine whether the loss is:

personal injury;

property damage;

legally protected non-material harm;

economic loss;

contractual loss;

damage caused by defective software.

Classification: Analogical authority.

Case 8 — MediaMarktSaturn / GDPR Non-Material Damage

MediaMarktSaturn, Case C-687/21, CJEU, 25 January 2024

This jurisprudence reinforces the principle that GDPR compensation requires:

infringement;

actual damage;

causal connection.

At the same time, EU law does not impose a general minimum seriousness threshold for non-material damage. (Curia)

AI epistemic relevance

AI misinformation may produce:

anxiety;

loss of control;

reputational consequences;

humiliation;

fear;

loss of confidence.

But the claimant still needs to establish legally recognisable damage rather than relying solely on the existence of an AI-system error.

Classification: Analogical authority.

9. Core Types of AI Epistemic Harm

A. False factual statements

Example:

An AI chatbot states that an individual committed fraud when there is no such evidence.

Potential legal bases:

defamation;

personality rights;

privacy;

tort/delict;

consumer protection;

contractual liability.

B. False professional information

An AI system gives incorrect:

legal advice;

medical information;

tax information;

financial information.

The legal question becomes whether the provider owed a duty of care, whether reliance was foreseeable and whether the output caused compensable damage.

C. Algorithmic classification

Examples:

“high fraud risk”;

“unlikely to repay”;

“not suitable for employment”;

“high-risk patient”;

“likely extremist”;

“low-value customer.”

Here, epistemic harm overlaps strongly with GDPR and automated decision-making law.

10. Epistemic Harm Through AI Hallucination

AI hallucination presents a particularly difficult civil-liability question.

A hallucination may involve:

factually false output presented with apparent confidence.

The legal analysis should separate four questions.

Question 1 — Was the output false?

Evidence may include:

authoritative databases;

expert evidence;

original documents;

scientific literature;

metadata;

model logs.

Question 2 — Was the AI system defective or negligently operated?

Possible causes:

inadequate training;

defective retrieval;

faulty fine-tuning;

failure to implement safeguards;

inadequate testing;

outdated information;

failure to communicate uncertainty.

Question 3 — Did the claimant reasonably rely on the output?

Reliance may be more foreseeable where the AI system was marketed as:

professional;

expert;

accurate;

reliable;

suitable for decision-making.

Question 4 — Did reliance cause legally recognised damage?

The claimant may need to prove:

false output → reliance → action/inaction → damage.

11. Epistemic Harm and Causation

Causation is likely to become one of the hardest parts of AI litigation.

Consider:

AI gives incorrect investment advice → investor acts → investment falls.

The defendant may argue:

the claimant should have verified the information;

market conditions independently caused the loss;

the claimant made an independent decision;

the AI output was only one factor;

the user accepted a disclaimer.

The claimant may respond:

the system was designed for reliance;

the provider knew users relied upon it;

the output was presented as authoritative;

the error resulted from a defective system;

the provider failed to warn about uncertainty.

Thus courts may have to construct a counterfactual:

What would have happened if the AI system had supplied accurate information?

12. Evidence and Explainability

AI epistemic claims create unusual evidentiary problems.

A claimant may not know:

what training data were used;

which model version produced the answer;

which prompt was processed;

what retrieval documents were consulted;

why one answer was generated rather than another;

whether the provider subsequently modified the model;

whether the model had known failure rates.

The Dun & Bradstreet Austria judgment is particularly important because the CJEU emphasised meaningful information enabling an affected person to understand and challenge an automated decision. (Infocuria)

13. Epistemic Harm and Burden of Proof

Traditional civil liability generally requires proof of:

wrongful conduct/defect + damage + causation.

AI complicates all three.

Defendant possesses:

source code;

system logs;

model documentation;

training information;

safety evaluations;

incident reports.

Claimant possesses:

the harmful output;

resulting loss;

personal experience;

external evidence contradicting the output.

This information imbalance is one reason the new Product Liability Directive addresses evidence and technologically complex products.

14. Product Liability vs Information Liability

This distinction is fundamental.

Situation A — Defective AI software

Example:

A commercially supplied AI application systematically produces dangerous outputs because of a software defect.

Potential product-liability claim.

Situation B — Incorrect information alone

Example:

A user reads an incorrect AI-generated historical statement and suffers no legally recognised damage.

Product liability is much less straightforward because the new Directive expressly distinguishes software from information itself. (EUR-Lex)

Situation C — Incorrect information causes physical injury

Example:

An AI medical product produces an erroneous diagnosis that causes physical injury.

Product liability becomes substantially more significant.

Situation D — Incorrect information causes economic loss

The claimant may instead need:

contract;

professional negligence;

tort/delict;

consumer law;

GDPR;

sector-specific legislation.

15. Contractual Liability

Where a user has a contract with an AI provider, liability may arise from:

failure to provide contracted functionality;

inaccurate outputs;

failure to comply with service specifications;

breach of express warranties;

inadequate safety measures;

breach of confidentiality;

failure to maintain agreed accuracy standards.

A major issue will be contractual allocation of AI risk through:

disclaimers;

liability caps;

exclusions;

acceptable-use terms;

verification requirements.

Consumer contracts remain subject to mandatory consumer-protection rules.

16. Tort/Delict Liability

National civil-law systems may provide liability where an AI operator:

acts negligently;

violates a protected legal interest;

creates an unreasonable risk;

fails to implement appropriate safeguards;

negligently disseminates false information.

The precise test varies among European jurisdictions.

Therefore, an AI epistemic-harm claim must be analysed under the applicable national law, not merely EU AI legislation.

17. Reputation and Personality Rights

AI-generated false statements may affect:

honour;

reputation;

dignity;

privacy;

professional standing;

commercial reputation.

This is particularly important where AI-generated content is publicly searchable.

The Google Spain jurisprudence demonstrates the importance European law attaches to the relationship between online information, personal identity and informational control. (Infocuria)

18. Consumer Protection

A consumer may argue that an AI provider:

represented its system as accurate;

concealed material limitations;

failed to disclose hallucination risks;

used misleading claims such as “expert-level” reliability;

failed to provide adequate warnings.

The legal question becomes whether the provider's marketing and contractual representations created a reasonable expectation of reliability.

19. AI Epistemic Discrimination

Epistemic harm may also become discriminatory.

Example:

An AI recruitment system incorrectly associates certain groups with:

low competence;

high attrition;

fraud risk;

poor performance.

The problem is not merely that the information is wrong.

The model may create a systematic hierarchy of credibility or opportunity.

Potential legal regimes include:

GDPR;

equality/non-discrimination law;

employment law;

AI Act;

national tort law;

contractual liability.

20. AI Epistemic Harm and Human Autonomy

A particularly important civil-law concept is autonomy.

AI can influence decisions by controlling:

what information a person receives;

what information is prioritised;

what alternatives are displayed;

what risks are emphasised;

what predictions are presented;

how confidently conclusions are expressed.

Therefore:

epistemic harm → impaired information → impaired decision → consequential harm.

This may be more legally significant where the AI system is used in:

healthcare;

employment;

credit;

insurance;

education;

public services;

legal services.

21. Defences Available to AI Providers

A provider may argue:

1. No legal duty

The defendant may argue that it owed no relevant duty concerning the particular use.

2. No defect

The AI system may have operated according to its documented specifications.

3. User misuse

The user may have employed the system for an unintended purpose.

4. Lack of reasonable reliance

The provider may argue that users were clearly warned that outputs could be inaccurate.

5. Intervening cause

Another person's conduct may have caused the loss.

6. Lack of causation

The claimant may not establish that the AI output actually caused the damage.

7. Contractual limitations

Subject to mandatory law, contractual limitations may restrict recovery.

8. Contributory fault

The claimant's failure to verify information may reduce damages under applicable national law.

22. Remedies

Depending on the cause of action and jurisdiction, remedies may include:

monetary damages;

compensation for material loss;

compensation for non-material harm;

correction of inaccurate data;

deletion;

de-referencing;

injunction;

cessation of unlawful processing;

correction or withdrawal of misleading information;

contractual remedies;

replacement or repair of defective software/product.

GDPR compensation is specifically compensatory rather than punitive; the claimant must establish the legally relevant damage and causal connection. (Curia)

23. Relationship Between AI Act, GDPR and Civil Liability

Legal instrumentMain functionEpistemic-harm relevance
AI ActAI governance and safetyTransparency, risk management, prohibited/high-risk practices
GDPRPersonal-data protectionAccuracy, profiling, automated decisions, compensation
Product Liability Directive 2024/2853No-fault product liabilityDefective software/AI causing legally recognised damage
Consumer lawProtects consumersMisleading claims and unfair practices
Contract lawEnforces contractual obligationsAccuracy/service promises and warranties
National tort/delict lawCivil responsibilityNegligence, wrongful information, protected interests
Defamation/personality lawProtects reputation/personalityFalse AI-generated statements
Fundamental-rights lawProtects dignity/privacy/expressionInterpretation of national rules

24. Important Case-Law Revision Table

CaseCourtPrincipleEpistemic-harm relevance
SCHUFA, C-634/21CJEUAutomated scoring and Article 22 GDPRAlgorithmic classification
Dun & Bradstreet, C-203/22CJEUMeaningful explanation of automated decisionsExplainability and contestability
Österreichische Post, C-300/21CJEUNon-material damage under GDPRHarm from algorithmic inference
Google Spain, C-131/12CJEUSearch-engine responsibility and personal informationOnline informational identity
W and Others, C-621/15CJEUProof and causation under technological uncertaintyAI causation/evidence
Boston Scientific, C-503/13 & C-504/13CJEUSystemic/product-group defectDefective AI/software systems
Moteurs Leroy Somer, C-285/08CJEUProduct-liability damage boundariesEconomic loss classification
MediaMarktSaturn, C-687/21CJEUActual damage and causation required under GDPRAI-related non-material harm

25. Key Legal Principles

Principle 1

AI epistemic harm is not currently a standalone harmonised European tort.

Principle 2

A false AI output does not automatically create civil liability.

Principle 3

The claimant normally needs to establish a legally protected interest and compensable damage.

Principle 4

Causation is central.

False information alone may be insufficient unless it produces legally recognised damage.

Principle 5

GDPR is particularly important where AI creates or processes personal profiles.

Principle 6

Automated decision-making creates a special transparency and contestability problem.

Principle 7

Dun & Bradstreet Austria strengthens the importance of meaningful explanations for automated decisions. (Infocuria)

Principle 8

Österreichische Post demonstrates that algorithmic inference can produce legally relevant non-material harm, but actual damage and causation remain necessary. (Infocuria)

Principle 9

The new Product Liability Directive treats AI/software as products, but distinguishes software from information itself. (EUR-Lex)

Principle 10

The new Product Liability Directive applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)

Principle 11

The proposed EU AI Liability Directive should not be treated as current law because the legislative procedure has been withdrawn. (EUR-Lex)

Principle 12

Future European litigation is likely to focus heavily on evidence, model transparency, causation, reasonable reliance and allocation of responsibility between AI provider, deployer and user.

26. Conclusion

AI epistemic harm represents a developing category of civil-law problems in Europe in which the central injury is initially harm to knowledge, information, belief, reputation or decision-making, followed in many cases by economic, personal or non-material damage.

The existing European framework is therefore layered rather than unified. GDPR is particularly important for inaccurate personal data, profiling and automated decisions; national civil law remains important for negligence, reputation, contract and economic loss; consumer law addresses misleading representations; and the new Product Liability Directive significantly expands product liability into software and AI.

The most important judicial foundations are SCHUFA, Dun & Bradstreet Austria, Österreichische Post, Google Spain, W and Others, and Boston Scientific. They do not collectively establish a standalone “AI epistemic tort”; rather, they provide principles that can be applied when AI-generated or AI-inferred information produces legally recognisable harm.

Ultra-short exam formula

AI epistemic harm = False/distorted/opaque AI information + legally protected interest + damage + causation + applicable civil-liability regime.

Main legal routes:
GDPR + AI Act + Product Liability + Contract + Tort/Delict + Consumer Law + Reputation/Personality Rights.

LEAVE A COMMENT