Civil Law And Ai Epistemic Harm Civil Liability Frameworks In Europe .
Civil Law and AI Epistemic Harm Civil Liability Frameworks in Europe
1. Introduction
AI epistemic harm refers to harm caused when an AI system produces, ranks, recommends, classifies, or communicates information in a way that causes a person to hold, rely upon, or act upon false, misleading, distorted, incomplete, or unjustifiably confident information.
Examples include:
an AI chatbot falsely accusing a person of criminal conduct;
an AI search engine generating a fabricated biography;
an automated credit system assigning an inaccurate risk score;
an AI medical system providing materially false information;
an algorithm systematically presenting unreliable information as authoritative;
an AI system making an unexplained factual classification that affects employment, insurance or credit;
an AI recommendation system amplifying demonstrably false information;
a generative-AI system inventing legal, financial or professional information on which a user reasonably relies.
European law does not presently recognise “epistemic harm” as one autonomous, harmonised civil-law cause of action. Instead, liability is constructed through several overlapping areas: product liability, contractual liability, national tort/delict law, GDPR, consumer law, platform regulation, professional liability and fundamental-rights jurisprudence.
This fragmentation is particularly important because the EU's new Product Liability Directive expressly treats software and AI systems as products, while at the same time excluding information itself from the definition of a product. It applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)
2. Meaning of AI Epistemic Harm
“Epistemic” concerns knowledge, belief, information and the ability to distinguish truth from falsehood.
Therefore, epistemic harm may arise where an AI system:
provides false information;
suppresses relevant information;
presents uncertain information as certain;
generates fabricated sources or authorities;
produces an inaccurate personal profile;
makes an erroneous automated classification;
causes a person to rely on false information;
damages reputation through false AI-generated statements;
interferes with a person's ability to make an informed decision;
creates economic or personal loss because the recipient relied upon inaccurate output.
Example
Suppose an AI credit system incorrectly calculates:
“This customer is highly likely to default.”
A bank relies on that assessment and refuses credit.
There may be several legally distinct harms:
informational harm — the underlying assessment is inaccurate;
autonomy harm — the individual cannot understand or challenge the decision;
economic harm — credit is refused;
reputational harm — the person is treated as financially unreliable;
data-protection harm — inaccurate personal data may have been processed;
civil liability — depending on the legal basis, compensation may become available.
3. Europe Has No Single “Epistemic Harm” Tort
A crucial point is that Europe is not one civil-law jurisdiction.
EU law creates common regulatory frameworks, but individual civil claims may arise under:
French responsabilité civile;
German Bürgerliches Gesetzbuch tort and contractual doctrines;
Italian responsabilità civile;
Spanish civil liability;
Dutch tort law;
national consumer law;
national defamation law;
national professional-negligence rules.
Consequently, an AI epistemic-harm claim normally requires identifying:
AI output → legally protected interest → wrongful/defective conduct → damage → causation → applicable remedy.
4. Main European Legal Framework
A. GDPR
The GDPR is particularly important where AI produces:
inaccurate personal profiles;
automated scores;
inferred characteristics;
discriminatory classifications;
automated decisions;
reputation-damaging personal information.
Article 5 requires personal data to be accurate, while Articles 15 and 22 are especially relevant to information about automated processing and automated decision-making.
Article 82 provides a compensation mechanism where unlawful processing causes material or non-material damage.
The CJEU has clarified that mere GDPR infringement is not automatically enough for compensation: infringement, damage and causal connection must be established. At the same time, EU law does not impose a minimum seriousness threshold for qualifying non-material damage. (Infocuria)
5. EU AI Act
The EU AI Act, Regulation (EU) 2024/1689, is important for epistemic-risk governance, transparency and prohibited/high-risk AI practices.
However, it should not be treated as a general AI civil-liability statute.
A claimant will often need to combine AI Act obligations with:
GDPR;
product liability;
contract;
tort/delict;
consumer protection;
professional negligence;
national defamation law.
Thus:
AI Act violation ≠ automatically a private damages claim.
The claimant must identify the applicable private-law cause of action and prove the required elements.
6. New EU Product Liability Framework
The Product Liability Directive (EU) 2024/2853 substantially changes the technological environment.
It expressly recognises:
software;
AI systems;
software supplied through cloud technologies;
software-as-a-service models
within the concept of products for product-liability purposes. (EUR-Lex)
The Directive also recognises the evidentiary difficulties victims face with technologically complex products.
Importantly, however, it states that information itself is not a product. Consequently, a claimant cannot simply characterise every false AI statement as a defective product. The distinction between:
defective AI software
and
incorrect information produced by that software
may become crucial. (EUR-Lex)
The new Directive applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)
7. AI Liability Directive — Important Development
The proposed AI Liability Directive would have addressed certain non-contractual liability problems arising from AI systems, including evidentiary difficulties.
However, the legislative procedure for the proposed AI Liability Directive has been withdrawn. (EUR-Lex)
Therefore, it should not be presented as an enacted EU-wide civil-liability regime.
Its withdrawal increases the importance of existing mechanisms:
national tort law;
GDPR;
Product Liability Directive;
contractual liability;
consumer law;
sector-specific legislation.
8. At Least 6 Important Case Laws
Because reported European litigation specifically using the expression “AI epistemic harm” remains limited, the strongest authorities are principally analogical cases involving automated scoring, inaccurate information, data accuracy, product defects and proof of technologically complex causation.
Case 1 — SCHUFA Holding (Scoring)
OQ v Land Hessen / SCHUFA Holding, Case C-634/21, CJEU, 7 December 2023
ECLI:EU:C:2023:957
Facts
SCHUFA generated creditworthiness scores concerning individuals. Those scores were used in circumstances capable of significantly affecting access to economic opportunities.
Principle
The CJEU held that Article 22 GDPR can apply where an automated assessment effectively determines an important decision concerning an individual.
The case is particularly significant because the problem was not simply that data existed. It concerned the automated transformation of information into a consequential prediction.
The CJEU's judgment dealt specifically with automated scoring and the use of probability values concerning a person's ability to meet financial obligations. (Infocuria)
Relevance to epistemic harm
This is one of the closest European analogies to AI epistemic harm.
An AI system may transform uncertain statistical information into an apparently objective conclusion:
data → model → score → decision → harm.
The epistemic problem is that the model's prediction can acquire practical authority despite being probabilistic rather than factual.
Legal significance
It demonstrates that European law can regulate the consequences of machine-generated knowledge about an individual, particularly where that knowledge drives consequential decisions.
Classification: Directly relevant analogical authority.
Case 2 — Dun & Bradstreet Austria
CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria, Case C-203/22, CJEU, 27 February 2025
ECLI:EU:C:2025:117
Facts
An Austrian telecommunications customer was refused a contract following an automated assessment of her creditworthiness.
She sought information concerning the logic behind the automated assessment.
Decision
The CJEU addressed Article 15(1)(h) GDPR and the requirement to provide meaningful information about the logic involved in automated decision-making.
The explanation must enable the affected person to understand and challenge the automated decision. (Infocuria)
Epistemic importance
This case is extremely important for epistemic harm because a person may suffer harm not merely because an algorithm is wrong, but because:
the person cannot understand why the algorithm is wrong.
This creates an epistemic asymmetry:
AI provider possesses the model;
individual receives the outcome;
individual lacks access to the reasoning;
individual cannot effectively contest the result.
Legal significance
Transparency therefore becomes connected with substantive civil protection.
Classification: Strong analogical authority.
Case 3 — Österreichische Post
UI v Österreichische Post AG, Case C-300/21, CJEU, 4 May 2023
ECLI:EU:C:2023:370
Facts
Österreichische Post used an algorithm to analyse socio-demographic information and infer political affinities of individuals.
One individual was incorrectly associated with a political party.
He claimed distress, loss of confidence and a feeling of exposure resulting from the inference. (curia)
Principle
The CJEU held that:
GDPR infringement alone does not automatically establish a compensation claim;
actual material or non-material damage must be established;
there is nevertheless no requirement that non-material damage reach a particular minimum seriousness threshold. (Infocuria)
Epistemic significance
This is highly relevant because the alleged harm came from an algorithmically generated belief about the individual.
The system did not merely copy an existing fact.
It inferred something about the person.
That distinction is fundamental to AI epistemic harm.
AI systems routinely generate:
personality predictions;
risk scores;
political preferences;
health predictions;
behavioural classifications;
fraud probabilities.
Legal significance
It demonstrates that erroneous algorithmic inference can implicate both:
informational interests + non-material personal harm.
Classification: Strong analogical authority.
Case 4 — Google Spain
Google Spain SL and Google Inc. v AEPD and Mario Costeja González, Case C-131/12, CJEU, 13 May 2014
ECLI:EU:C:2014:317
Facts
An individual challenged the continued association of his name with information appearing in search results.
Principle
The CJEU recognised significant responsibilities for search-engine operators concerning the processing and presentation of personal information and developed the framework commonly associated with the right to delisting/de-referencing.
The case concerned the responsibility of search-engine operators for processing information contained on third-party websites. (Infocuria)
Epistemic-harm relevance
AI search and answer systems may similarly determine:
what information a person sees first and therefore what the person is likely to believe.
A traditional search engine ranks existing information.
A generative AI system may go further and synthesize an answer.
The epistemic risk therefore potentially becomes greater:
retrieval → ranking → synthesis → apparent factual assertion.
Legal significance
Google Spain supplies an important conceptual foundation for examining:
accuracy;
relevance;
persistence of information;
reputation;
informational autonomy.
Classification: Analogical authority.
Case 5 — W and Others v Sanofi Pasteur
W and Others v Sanofi Pasteur MSD SNC, Case C-621/15, CJEU, 21 June 2017
ECLI:EU:C:2017:484
Facts
The case involved an alleged defect in a hepatitis-B vaccine and the evidentiary difficulty of establishing causation where scientific knowledge was uncertain.
Principle
The CJEU examined whether national evidentiary rules could permit proof through sufficiently serious, specific and consistent evidence in circumstances where scientific consensus did not conclusively establish causation. (curia)
Relevance to AI epistemic harm
AI disputes may present exactly the same evidentiary problem:
How does a claimant prove that an opaque model caused the particular harm?
For example:
Was the AI model defective?
Was the training data defective?
Was the output caused by a model defect?
Was the user's interpretation responsible?
Did the AI output actually cause the financial loss?
Legal significance
The case provides an important analogy for causation under scientific and technical uncertainty.
Classification: Analogical product-liability authority.
Case 6 — Boston Scientific
Boston Scientific Medizintechnik GmbH v AOK Sachsen-Anhalt and Others, Joined Cases C-503/13 and C-504/13, CJEU, 5 March 2015
ECLI:EU:C:2015:148
Facts
The litigation concerned pacemakers and implantable cardioverter defibrillators which presented potential safety defects.
Principle
The CJEU held that where products in the same group or production series have a potential defect, an individual product may be regarded as defective without proving that the particular product examined contains that defect.
The Court also recognised consequential personal injury-related damage associated with replacement of defective devices. (Infocuria)
AI relevance
AI systems create a comparable problem.
Suppose a model version has a systematic:
hallucination problem;
bias;
data corruption;
unsafe reasoning mechanism;
cybersecurity vulnerability.
The claimant may face difficulty proving that the precise output resulted from a particular internal defect.
Boston Scientific provides an important conceptual analogy for dealing with systemic technological defects.
Legal significance
It may become particularly relevant to future litigation concerning defective AI software under the new Product Liability Directive.
Classification: Analogical authority.
Case 7 — Moteurs Leroy Somer
Moteurs Leroy Somer v Dalkia France and Ace Europe, Case C-285/08, CJEU, 4 June 2009
ECLI:EU:C:2009:351
This case concerned the scope of EU product liability and the distinction between damage falling within the harmonised product-liability regime and other forms of economic loss. (Infocuria)
Relevance
AI epistemic harm frequently involves pure economic loss:
incorrect investment information;
wrong credit classification;
erroneous business intelligence;
fabricated legal advice;
false commercial information.
Therefore, the classification of the alleged loss becomes critical.
A claimant must determine whether the loss is:
personal injury;
property damage;
legally protected non-material harm;
economic loss;
contractual loss;
damage caused by defective software.
Classification: Analogical authority.
Case 8 — MediaMarktSaturn / GDPR Non-Material Damage
MediaMarktSaturn, Case C-687/21, CJEU, 25 January 2024
This jurisprudence reinforces the principle that GDPR compensation requires:
infringement;
actual damage;
causal connection.
At the same time, EU law does not impose a general minimum seriousness threshold for non-material damage. (Curia)
AI epistemic relevance
AI misinformation may produce:
anxiety;
loss of control;
reputational consequences;
humiliation;
fear;
loss of confidence.
But the claimant still needs to establish legally recognisable damage rather than relying solely on the existence of an AI-system error.
Classification: Analogical authority.
9. Core Types of AI Epistemic Harm
A. False factual statements
Example:
An AI chatbot states that an individual committed fraud when there is no such evidence.
Potential legal bases:
defamation;
personality rights;
privacy;
tort/delict;
consumer protection;
contractual liability.
B. False professional information
An AI system gives incorrect:
legal advice;
medical information;
tax information;
financial information.
The legal question becomes whether the provider owed a duty of care, whether reliance was foreseeable and whether the output caused compensable damage.
C. Algorithmic classification
Examples:
“high fraud risk”;
“unlikely to repay”;
“not suitable for employment”;
“high-risk patient”;
“likely extremist”;
“low-value customer.”
Here, epistemic harm overlaps strongly with GDPR and automated decision-making law.
10. Epistemic Harm Through AI Hallucination
AI hallucination presents a particularly difficult civil-liability question.
A hallucination may involve:
factually false output presented with apparent confidence.
The legal analysis should separate four questions.
Question 1 — Was the output false?
Evidence may include:
authoritative databases;
expert evidence;
original documents;
scientific literature;
metadata;
model logs.
Question 2 — Was the AI system defective or negligently operated?
Possible causes:
inadequate training;
defective retrieval;
faulty fine-tuning;
failure to implement safeguards;
inadequate testing;
outdated information;
failure to communicate uncertainty.
Question 3 — Did the claimant reasonably rely on the output?
Reliance may be more foreseeable where the AI system was marketed as:
professional;
expert;
accurate;
reliable;
suitable for decision-making.
Question 4 — Did reliance cause legally recognised damage?
The claimant may need to prove:
false output → reliance → action/inaction → damage.
11. Epistemic Harm and Causation
Causation is likely to become one of the hardest parts of AI litigation.
Consider:
AI gives incorrect investment advice → investor acts → investment falls.
The defendant may argue:
the claimant should have verified the information;
market conditions independently caused the loss;
the claimant made an independent decision;
the AI output was only one factor;
the user accepted a disclaimer.
The claimant may respond:
the system was designed for reliance;
the provider knew users relied upon it;
the output was presented as authoritative;
the error resulted from a defective system;
the provider failed to warn about uncertainty.
Thus courts may have to construct a counterfactual:
What would have happened if the AI system had supplied accurate information?
12. Evidence and Explainability
AI epistemic claims create unusual evidentiary problems.
A claimant may not know:
what training data were used;
which model version produced the answer;
which prompt was processed;
what retrieval documents were consulted;
why one answer was generated rather than another;
whether the provider subsequently modified the model;
whether the model had known failure rates.
The Dun & Bradstreet Austria judgment is particularly important because the CJEU emphasised meaningful information enabling an affected person to understand and challenge an automated decision. (Infocuria)
13. Epistemic Harm and Burden of Proof
Traditional civil liability generally requires proof of:
wrongful conduct/defect + damage + causation.
AI complicates all three.
Defendant possesses:
source code;
system logs;
model documentation;
training information;
safety evaluations;
incident reports.
Claimant possesses:
the harmful output;
resulting loss;
personal experience;
external evidence contradicting the output.
This information imbalance is one reason the new Product Liability Directive addresses evidence and technologically complex products.
14. Product Liability vs Information Liability
This distinction is fundamental.
Situation A — Defective AI software
Example:
A commercially supplied AI application systematically produces dangerous outputs because of a software defect.
Potential product-liability claim.
Situation B — Incorrect information alone
Example:
A user reads an incorrect AI-generated historical statement and suffers no legally recognised damage.
Product liability is much less straightforward because the new Directive expressly distinguishes software from information itself. (EUR-Lex)
Situation C — Incorrect information causes physical injury
Example:
An AI medical product produces an erroneous diagnosis that causes physical injury.
Product liability becomes substantially more significant.
Situation D — Incorrect information causes economic loss
The claimant may instead need:
contract;
professional negligence;
tort/delict;
consumer law;
GDPR;
sector-specific legislation.
15. Contractual Liability
Where a user has a contract with an AI provider, liability may arise from:
failure to provide contracted functionality;
inaccurate outputs;
failure to comply with service specifications;
breach of express warranties;
inadequate safety measures;
breach of confidentiality;
failure to maintain agreed accuracy standards.
A major issue will be contractual allocation of AI risk through:
disclaimers;
liability caps;
exclusions;
acceptable-use terms;
verification requirements.
Consumer contracts remain subject to mandatory consumer-protection rules.
16. Tort/Delict Liability
National civil-law systems may provide liability where an AI operator:
acts negligently;
violates a protected legal interest;
creates an unreasonable risk;
fails to implement appropriate safeguards;
negligently disseminates false information.
The precise test varies among European jurisdictions.
Therefore, an AI epistemic-harm claim must be analysed under the applicable national law, not merely EU AI legislation.
17. Reputation and Personality Rights
AI-generated false statements may affect:
honour;
reputation;
dignity;
privacy;
professional standing;
commercial reputation.
This is particularly important where AI-generated content is publicly searchable.
The Google Spain jurisprudence demonstrates the importance European law attaches to the relationship between online information, personal identity and informational control. (Infocuria)
18. Consumer Protection
A consumer may argue that an AI provider:
represented its system as accurate;
concealed material limitations;
failed to disclose hallucination risks;
used misleading claims such as “expert-level” reliability;
failed to provide adequate warnings.
The legal question becomes whether the provider's marketing and contractual representations created a reasonable expectation of reliability.
19. AI Epistemic Discrimination
Epistemic harm may also become discriminatory.
Example:
An AI recruitment system incorrectly associates certain groups with:
low competence;
high attrition;
fraud risk;
poor performance.
The problem is not merely that the information is wrong.
The model may create a systematic hierarchy of credibility or opportunity.
Potential legal regimes include:
GDPR;
equality/non-discrimination law;
employment law;
AI Act;
national tort law;
contractual liability.
20. AI Epistemic Harm and Human Autonomy
A particularly important civil-law concept is autonomy.
AI can influence decisions by controlling:
what information a person receives;
what information is prioritised;
what alternatives are displayed;
what risks are emphasised;
what predictions are presented;
how confidently conclusions are expressed.
Therefore:
epistemic harm → impaired information → impaired decision → consequential harm.
This may be more legally significant where the AI system is used in:
healthcare;
employment;
credit;
insurance;
education;
public services;
legal services.
21. Defences Available to AI Providers
A provider may argue:
1. No legal duty
The defendant may argue that it owed no relevant duty concerning the particular use.
2. No defect
The AI system may have operated according to its documented specifications.
3. User misuse
The user may have employed the system for an unintended purpose.
4. Lack of reasonable reliance
The provider may argue that users were clearly warned that outputs could be inaccurate.
5. Intervening cause
Another person's conduct may have caused the loss.
6. Lack of causation
The claimant may not establish that the AI output actually caused the damage.
7. Contractual limitations
Subject to mandatory law, contractual limitations may restrict recovery.
8. Contributory fault
The claimant's failure to verify information may reduce damages under applicable national law.
22. Remedies
Depending on the cause of action and jurisdiction, remedies may include:
monetary damages;
compensation for material loss;
compensation for non-material harm;
correction of inaccurate data;
deletion;
de-referencing;
injunction;
cessation of unlawful processing;
correction or withdrawal of misleading information;
contractual remedies;
replacement or repair of defective software/product.
GDPR compensation is specifically compensatory rather than punitive; the claimant must establish the legally relevant damage and causal connection. (Curia)
23. Relationship Between AI Act, GDPR and Civil Liability
| Legal instrument | Main function | Epistemic-harm relevance |
|---|---|---|
| AI Act | AI governance and safety | Transparency, risk management, prohibited/high-risk practices |
| GDPR | Personal-data protection | Accuracy, profiling, automated decisions, compensation |
| Product Liability Directive 2024/2853 | No-fault product liability | Defective software/AI causing legally recognised damage |
| Consumer law | Protects consumers | Misleading claims and unfair practices |
| Contract law | Enforces contractual obligations | Accuracy/service promises and warranties |
| National tort/delict law | Civil responsibility | Negligence, wrongful information, protected interests |
| Defamation/personality law | Protects reputation/personality | False AI-generated statements |
| Fundamental-rights law | Protects dignity/privacy/expression | Interpretation of national rules |
24. Important Case-Law Revision Table
| Case | Court | Principle | Epistemic-harm relevance |
|---|---|---|---|
| SCHUFA, C-634/21 | CJEU | Automated scoring and Article 22 GDPR | Algorithmic classification |
| Dun & Bradstreet, C-203/22 | CJEU | Meaningful explanation of automated decisions | Explainability and contestability |
| Österreichische Post, C-300/21 | CJEU | Non-material damage under GDPR | Harm from algorithmic inference |
| Google Spain, C-131/12 | CJEU | Search-engine responsibility and personal information | Online informational identity |
| W and Others, C-621/15 | CJEU | Proof and causation under technological uncertainty | AI causation/evidence |
| Boston Scientific, C-503/13 & C-504/13 | CJEU | Systemic/product-group defect | Defective AI/software systems |
| Moteurs Leroy Somer, C-285/08 | CJEU | Product-liability damage boundaries | Economic loss classification |
| MediaMarktSaturn, C-687/21 | CJEU | Actual damage and causation required under GDPR | AI-related non-material harm |
25. Key Legal Principles
Principle 1
AI epistemic harm is not currently a standalone harmonised European tort.
Principle 2
A false AI output does not automatically create civil liability.
Principle 3
The claimant normally needs to establish a legally protected interest and compensable damage.
Principle 4
Causation is central.
False information alone may be insufficient unless it produces legally recognised damage.
Principle 5
GDPR is particularly important where AI creates or processes personal profiles.
Principle 6
Automated decision-making creates a special transparency and contestability problem.
Principle 7
Dun & Bradstreet Austria strengthens the importance of meaningful explanations for automated decisions. (Infocuria)
Principle 8
Österreichische Post demonstrates that algorithmic inference can produce legally relevant non-material harm, but actual damage and causation remain necessary. (Infocuria)
Principle 9
The new Product Liability Directive treats AI/software as products, but distinguishes software from information itself. (EUR-Lex)
Principle 10
The new Product Liability Directive applies to products placed on the market or put into service after 8 December 2026. (EUR-Lex)
Principle 11
The proposed EU AI Liability Directive should not be treated as current law because the legislative procedure has been withdrawn. (EUR-Lex)
Principle 12
Future European litigation is likely to focus heavily on evidence, model transparency, causation, reasonable reliance and allocation of responsibility between AI provider, deployer and user.
26. Conclusion
AI epistemic harm represents a developing category of civil-law problems in Europe in which the central injury is initially harm to knowledge, information, belief, reputation or decision-making, followed in many cases by economic, personal or non-material damage.
The existing European framework is therefore layered rather than unified. GDPR is particularly important for inaccurate personal data, profiling and automated decisions; national civil law remains important for negligence, reputation, contract and economic loss; consumer law addresses misleading representations; and the new Product Liability Directive significantly expands product liability into software and AI.
The most important judicial foundations are SCHUFA, Dun & Bradstreet Austria, Österreichische Post, Google Spain, W and Others, and Boston Scientific. They do not collectively establish a standalone “AI epistemic tort”; rather, they provide principles that can be applied when AI-generated or AI-inferred information produces legally recognisable harm.
Ultra-short exam formula
AI epistemic harm = False/distorted/opaque AI information + legally protected interest + damage + causation + applicable civil-liability regime.
Main legal routes:
GDPR + AI Act + Product Liability + Contract + Tort/Delict + Consumer Law + Reputation/Personality Rights.

comments