Civil Law And Ai-Powered Service Provider Liability In Europe .
Civil Law And AI-Powered Service Provider Liability In Europe
1. Introduction
AI-powered service provider liability concerns the civil responsibility of businesses that use, supply, operate, integrate, or maintain AI as part of a service where the AI causes or contributes to legally recognised harm.
Examples include:
AI medical-diagnostic services;
AI financial-advisory services;
automated insurance services;
AI recruitment platforms;
AI legal or professional services;
autonomous transport services;
AI customer-service systems;
AI cybersecurity services;
AI property-management systems;
AI-powered recommendation and decision services;
AI cloud/SaaS services.
The legal difficulty is that an AI service may involve software, data, human professionals, cloud infrastructure and a contractual service relationship simultaneously.
European law therefore does not create one universal tort called “AI service-provider liability.” Liability may instead arise from:
contract law;
national tort/delict law;
GDPR;
consumer law;
product liability;
AI Act compliance;
professional liability;
sector-specific legislation.
A major development is the new EU Product Liability Directive 2024/2853. It expressly treats software, including AI systems, as products, including software supplied through cloud technologies or SaaS. However, the Directive does not generally apply to services as such; it covers certain digital services that are integrated into or interconnected with a product and are within the manufacturer's control. (EUR-Lex)
2. Meaning of an AI-Powered Service Provider
An AI-powered service provider is an entity that uses or supplies AI in order to provide a service to another person or organisation.
Example
A financial company provides:
AI credit-assessment service → bank → consumer
The AI provider analyses:
income;
repayment history;
transactions;
employment information;
other personal data.
It generates a credit score.
The bank then refuses the customer's loan.
Possible legal questions include:
Was the AI assessment accurate?
Was personal data lawfully processed?
Was the automated decision legally permitted?
Was sufficient information provided?
Was there meaningful human review?
Did the service provider breach its contract?
Did the provider cause compensable damage?
3. Why AI Service Liability Is Different
Traditional services normally involve identifiable human decision-makers.
AI-powered services introduce:
A. Algorithmic autonomy
The system may make or recommend decisions without direct human intervention.
B. Black-box decision-making
The provider may not be able to give a simple explanation of every output.
C. Continuous modification
AI models can be updated or retrained after deployment.
D. Data dependency
The service may be defective because its training or input data are defective.
E. Multiple actors
The AI developer, cloud provider, service provider and customer may all participate.
F. Difficulty proving causation
It may be difficult to establish:
AI output → particular decision → specific damage.
4. European Legal Framework
A. Contractual Liability
Where a customer has contracted with an AI service provider, contractual liability is usually the first issue.
The contract may contain obligations concerning:
accuracy;
availability;
cybersecurity;
data protection;
service quality;
human supervision;
response times;
updates;
warranties;
professional standards.
For example:
AI accounting provider promises 99% accurate automated tax calculations.
If a defective AI output causes a customer's financial loss, the contractual terms and applicable national contract law may determine liability.
5. Tort/Delict Liability
National European civil-law systems generally maintain broader non-contractual liability.
The precise rules differ.
France
French civil liability may involve the general fault provisions of the Civil Code and, where relevant, special regimes such as defective-product liability.
Germany
German liability can arise particularly under § 823 BGB, subject to the requirements of the applicable cause of action.
Italy
Article 2043 of the Italian Civil Code provides the general framework for unlawful damage caused by another.
Spain
Spanish Civil Code provisions concerning extra-contractual liability may apply.
Therefore:
There is no single European AI tort law.
EU legislation increasingly harmonises particular areas, but national civil law remains important.
6. GDPR Liability
The GDPR becomes particularly important when an AI service provider processes personal data.
Relevant provisions include:
Article 5 — principles of processing;
Article 6 — lawful bases;
Articles 12–14 — transparency;
Article 15 — access;
Article 22 — automated individual decision-making;
Article 25 — data protection by design/default;
Article 32 — security;
Article 35 — impact assessment;
Article 82 — compensation.
An AI service provider can potentially be:
controller;
joint controller;
processor;
depending on its actual role.
The contractual label alone does not necessarily determine the GDPR classification.
7. AI Act
The EU AI Act, Regulation (EU) 2024/1689, regulates providers and deployers of AI systems.
Its scope expressly includes:
providers placing AI systems on the EU market;
deployers established in the EU;
certain third-country providers where AI outputs are used in the EU;
importers;
distributors;
product manufacturers incorporating AI systems. (EUR-Lex)
The AI Act imposes different obligations depending upon the AI system's classification.
However:
AI Act compliance is not the same thing as civil-law immunity.
A provider can potentially comply with regulatory requirements and still face contractual, tortious, GDPR or product-liability claims if the relevant requirements of those regimes are satisfied.
8. Product Liability and AI Service Providers
This is one of the most important developments.
Directive 2024/2853 expressly states that software, including AI systems, is a product for the purposes of EU no-fault product liability, regardless of whether it is supplied through a device, communication network, cloud technology or SaaS model. It also states that AI-system providers can be treated as manufacturers. (EUR-Lex)
Thus:
AI software supplied as SaaS is no longer automatically outside the product-liability concept merely because it is delivered digitally.
However, an important distinction must be maintained:
AI software itself
Potentially a product under the new Directive.
A service as such
Not generally within the Directive's product-liability scope.
Related digital service integrated into/interconnected with a product
May be treated as a component where the statutory conditions are met.
The Directive specifically gives examples such as:
traffic-data services integrated into navigation systems;
health-monitoring services connected to physical products;
temperature-control services for smart appliances;
voice-assistant services controlling products. (EUR-Lex)
9. Effective Date of the New Product Liability Regime
The new Directive applies to products placed on the market or put into service after 9 December 2026 under the Directive's Article 2 framework. (EUR-Lex)
Therefore, in a current European litigation analysis, it is essential to distinguish:
old Product Liability Directive 85/374/EEC
from
new Product Liability Directive 2024/2853.
10. Case Law
Because AI-powered service-provider liability is still developing, there are relatively few reported judgments directly concerning an AI provider being sued for an AI-generated service failure.
The most useful authorities therefore combine:
direct AI/data-processing cases;
product-liability cases;
automated-decision cases;
digital-service cases.
Case 1 — SCHUFA Scoring
OQ v Land Hessen and SCHUFA Holding AG
Case C-634/21, CJEU, 7 December 2023, ECLI:EU:C:2023:957
Importance: Direct AI/automated-service analogy
SCHUFA is a private credit-information company providing creditworthiness information to customers such as banks.
It generated a probability score concerning an individual's ability to meet future payment obligations.
The bank used that score in making its credit decision.
The CJEU held that automated establishment of such a probability value can constitute an automated individual decision within Article 22 GDPR where the statutory conditions are satisfied and the score plays a determining role in the subsequent decision. (Infocuria)
Relevance to AI service providers
This is extremely important for:
AI service provider → automated assessment → customer decision → consumer harm
An AI provider cannot necessarily argue:
“We only generated the score; another company technically made the final decision.”
The actual role of the automated output matters.
Principle
An intermediate AI-generated score can have direct legal significance where another decision-maker relies upon it in a decisive way.
Case 2 — Dun & Bradstreet Austria
CK v Magistrat der Stadt Wien / Dun & Bradstreet Austria
Case C-203/22, CJEU, 27 February 2025, ECLI:EU:C:2025:117
Importance: AI transparency and explanation
Dun & Bradstreet provided automated credit assessments.
The CJEU considered Article 15(1)(h) GDPR and the right to receive meaningful information about the logic involved in automated decision-making.
The Court held that the information supplied must enable the data subject to understand and challenge the automated decision. (curia)
Where trade secrets or third-party data are involved, the information cannot simply be withheld automatically; the competent supervisory authority or court may need to balance the competing interests. (Curia)
Relevance
Suppose an AI service provider says:
“Our model rejected your application.”
The customer asks:
“Why?”
The provider cannot necessarily satisfy the transparency requirement merely by saying:
“The neural network generated that result.”
Principle
AI complexity does not automatically eliminate the legal requirement for meaningful explanation.
Case 3 — Österreichische Post
UI v Österreichische Post AG
Case C-300/21, CJEU, 4 May 2023, ECLI:EU:C:2023:370
Importance: AI profiling and compensation
Österreichische Post processed information in order to predict individuals' political affinities.
The CJEU considered Article 82 GDPR and clarified that three elements are required for compensation:
GDPR-infringing processing;
damage;
causal link between the unlawful processing and damage.
The mere fact of a GDPR infringement does not automatically create a compensation claim, but EU law does not require non-material damage to exceed a particular seriousness threshold imposed by national law. (Infocuria)
AI-service relevance
Suppose an AI service provider:
collects personal data → creates an inferred profile → supplies the profile to a customer → consumer suffers damage.
The provider's AI-generated inference may therefore create GDPR liability if the applicable requirements are satisfied.
Principle
Unlawful AI data processing and compensable damage are related but distinct legal questions.
Case 4 — Boston Scientific
Boston Scientific Medizintechnik GmbH v AOK Sachsen-Anhalt and Betriebskrankenkasse RWE
Joined Cases C-503/13 and C-504/13, CJEU, 5 March 2015
Importance: Product defect and systemic risk
The cases concerned pacemakers and implantable cardioverter-defibrillators.
The CJEU held that products belonging to a group or production series presenting a significantly increased risk of failure could be regarded as defective without proving that every individual product had already manifested the defect.
AI service relevance
Consider an AI software service used by:
50,000 hospitals.
A particular model version is discovered to have a systematic diagnostic defect.
The problem may exist across a class of systems even where every individual customer has not yet suffered measurable harm.
This is important for:
recalls;
model replacement;
safety updates;
risk management.
Principle
A systemic defect affecting a product group can have legal significance even before every individual unit produces actual damage.
This principle becomes increasingly important under the new EU Product Liability Directive, which expressly includes software and AI systems within the product concept. (EUR-Lex)
Case 5 — Veedfald
Henning Veedfald v Århus Amtskommune
Case C-203/99, CJEU, 10 May 2001
Importance: Product liability and services
The case concerned a defective product used in connection with medical treatment.
The CJEU addressed the application of the EU defective-product regime where a product is supplied or used in the context of a broader service.
AI relevance
This is useful for distinguishing:
AI software/product
from
AI-enabled professional service.
For example:
AI diagnostic software → hospital → patient
The hospital may provide the medical service, while the AI developer provides software.
Different liability regimes can potentially apply to each participant.
Principle
A product can remain legally relevant even when it operates within a broader professional service.
Case 6 — Moteurs Leroy Somer
Moteurs Leroy Somer v Dalkia France
Case C-285/08, CJEU, 4 June 2009
Importance: Defective industrial product
The case involved a defective alternator that overheated and caused a fire in an industrial setting.
The CJEU considered the scope of the EU defective-product regime, particularly damage to property used for professional purposes.
AI-service relevance
Imagine:
AI industrial-management service → incorrect instruction → machine overheats → factory fire.
The case demonstrates why courts must distinguish between:
damage caused by the defective product;
damage to the defective product itself;
damage to other property;
economic losses.
Principle
Different categories of damage may fall under different legal regimes.
This is especially important for AI-powered industrial and professional services.
Case 7 — Sanofi Pasteur
W and Others v Sanofi Pasteur MSD
Case C-621/15, CJEU, 21 June 2017
Importance: Causation under technical uncertainty
The case concerned alleged harm from a vaccine and the evidentiary problem of establishing defect and causation where scientific knowledge was uncertain.
The CJEU recognised the importance of serious, specific and consistent evidence in circumstances where direct scientific proof may be difficult, subject to national evidentiary rules.
AI-service relevance
AI systems present similar evidentiary problems.
For example:
AI diagnostic service → incorrect prediction → medical treatment → injury.
The claimant may not be able to inspect the complete model or reproduce its exact output.
The dispute may therefore concern:
system logs;
training data;
model validation;
known error rates;
alternative explanations;
expert evidence.
Principle
Technical complexity does not eliminate the need for proof of defect and causation, but European product-liability law recognises evidentiary difficulties in technically complex cases.
Case 8 — Google Spain
Google Spain SL and Google Inc. v AEPD and Mario Costeja González
Case C-131/12, CJEU, 13 May 2014
Importance: Responsibility for algorithmic processing
Google's search engine automatically processed information originating from third-party websites.
The CJEU recognised that the search-engine operator was itself processing personal data and could have obligations under EU data-protection law.
Relevance to AI services
This is useful for a general principle:
An AI service provider cannot necessarily escape responsibility merely because its system automatically processes information supplied by third parties.
The same problem can arise where an AI provider receives:
third-party databases;
public information;
customer-provided information;
external APIs.
Principle
Automated aggregation or processing of information can itself constitute legally relevant processing.
Case 9 — Amazon EU
Bundesverband der Verbraucherzentralen und Verbraucherverbände v Amazon EU Sàrl
Case C-649/17, CJEU, 10 July 2019
Importance: Digital service-provider obligations
The case concerned communication methods available to consumers dealing with an online trader.
The CJEU held that the trader did not necessarily have to provide a telephone number in every circumstance but had to provide an effective means of communication allowing consumers to contact it rapidly and efficiently.
AI-service relevance
An AI-powered service should not create a situation where:
AI makes decision → consumer disputes decision → no meaningful human/contact mechanism exists.
The digital nature of the service does not eliminate applicable consumer communication obligations.
Principle
Digital automation does not remove the provider's underlying consumer-law responsibilities.
9. Liability of Different AI Actors
A. AI Developer
Potential liability for:
defective software;
inadequate testing;
defective model;
unsafe architecture;
inadequate warnings;
defective updates.
Under the new Product Liability Directive, an AI-system developer/provider may fall within the manufacturer concept where the AI system is a product. (EUR-Lex)
B. AI Service Provider
The service provider may be responsible where it:
selects the model;
configures it;
controls inputs;
makes decisions through it;
provides the service to customers;
fails to monitor known risks.
C. Deployer
The deployer may be responsible where it:
uses the system improperly;
ignores instructions;
supplies defective data;
fails to supervise;
uses the system outside its intended purpose.
D. Integrator
An integrator combines:
AI + existing software + physical equipment + databases.
Incorrect integration may create a separate liability issue.
E. Cloud Provider
A cloud infrastructure provider will not automatically become liable merely because the AI system operates on its servers.
Liability depends on:
contractual role;
control;
defect;
causation;
applicable statutory regime.
10. AI Service Provider vs AI Product Manufacturer
This distinction is essential.
Situation 1
Company sells an AI-powered medical device.
Product liability is highly relevant.
Situation 2
Company supplies standalone AI software through SaaS.
The new Product Liability Directive expressly treats software, including AI systems supplied through SaaS, as a product. (EUR-Lex)
Situation 3
Company provides an ordinary professional service using AI internally.
Example:
Law firm uses AI to help prepare a legal document.
The client may primarily have a professional/contractual liability claim against the law firm, depending on national law and the engagement terms.
The AI developer is not automatically the client's contractual service provider.
Situation 4
AI service controls a physical product.
Example:
Autonomous vehicle navigation service.
A related digital service integrated into or interconnected with a product may fall within the new product-liability framework when the statutory conditions concerning the manufacturer's control are met. (EUR-Lex)
11. The Control Test
An important question is:
Who controlled the relevant AI component when the defect existed?
The new Product Liability Directive recognises continuing manufacturer control over software and related services in specified circumstances.
It specifically addresses defects arising after placing on the market through:
software updates;
upgrades;
machine-learning algorithms.
It also addresses cybersecurity vulnerabilities and inadequate security updates in certain circumstances. (EUR-Lex)
This represents an important departure from a purely traditional physical-product model.
12. AI Updates and Continuous Liability
Traditional products generally leave the manufacturer's control after sale.
AI products can behave differently.
Example:
January: AI service is safe.
March: Provider deploys model update.
April: Updated model generates dangerous output.
May: Customer suffers damage.
The legal question becomes:
Is the provider responsible for the post-deployment change?
The new Product Liability Directive expressly contemplates defects arising after placing the product on the market where software, related services or machine-learning algorithms remain within the manufacturer's control. (EUR-Lex)
13. Cybersecurity Liability
AI services can fail because of cyberattacks.
Example:
Hacker manipulates AI model → AI gives incorrect command → customer suffers loss.
Possible issues include:
inadequate security;
failure to patch;
foreseeable cyber risks;
third-party intervention;
causation;
contractual cybersecurity obligations.
The new Product Liability Directive specifically recognises that cybersecurity vulnerabilities and failure to provide necessary security updates can affect product safety and liability. (EUR-Lex)
14. AI Hallucination and Service Liability
Generative AI creates another problem.
Example:
AI legal service generates a fictitious legal authority.
The customer relies on it and loses a legal claim.
Potential defendants could include:
AI developer;
AI service provider;
professional firm deploying the AI;
human professional who failed to verify the output.
But liability is not automatic.
The claimant would need to establish the relevant legal elements, which may include:
duty/contractual obligation;
breach or defect;
causation;
legally recognised damage.
15. AI Medical-Service Liability
Consider:
AI diagnostic service says “no cancer” → doctor relies on output → delayed treatment → injury.
Potential liability may involve:
AI provider
Defective model or inadequate warnings.
Hospital
Failure of clinical supervision.
Doctor
Professional negligence under applicable national law.
Software manufacturer
Product liability where applicable.
Data provider
Potentially defective clinical data.
Thus:
AI does not replace the ordinary professional-liability framework.
It adds another technological layer to it.
16. AI Financial-Service Liability
Example:
AI investment service recommends a high-risk investment.
Customer loses €100,000.
Questions include:
Was the service contractually obligated to provide suitable advice?
Was the AI properly trained?
Were warnings given?
Was the consumer properly informed?
Was the provider subject to financial-sector regulation?
Was the AI output automatically generated?
Did the customer receive human review?
GDPR may also apply if personal profiling was involved.
17. AI Employment-Service Liability
Example:
AI recruitment service incorrectly classifies an applicant as unsuitable.
Potential legal issues:
GDPR;
anti-discrimination law;
AI Act;
employment law;
contract;
tort/delict.
SCHUFA is particularly useful by analogy because the CJEU recognised that an automated score can have legal significance where it plays a determining role in a subsequent decision. (Infocuria)
18. Transparency as a Liability Issue
AI service providers should be able to address:
what the system does;
what data it uses;
relevant limitations;
degree of automation;
human oversight;
significant risks;
circumstances in which the system should not be relied upon.
The Dun & Bradstreet judgment is especially significant because meaningful information about automated logic must be sufficient to enable understanding and challenge of the decision in the circumstances covered by the GDPR. (curia)
19. Human Oversight
One of the most important principles is:
Human involvement does not automatically eliminate AI-service-provider liability.
There is a difference between:
Genuine human review
A qualified human examines the AI output and independently decides.
and
Rubber-stamp review
A human merely clicks:
“Approve AI recommendation.”
The second situation can raise much stronger questions about whether the human intervention was genuinely meaningful.
The SCHUFA decision demonstrates why courts may examine the actual influence of automated output rather than merely the formal existence of another decision-maker. (curia)
20. Causation
Causation is likely to be one of the most difficult aspects of AI-service litigation.
Suppose:
AI gives wrong advice
↓
human professional receives advice
↓
professional makes decision
↓
customer suffers loss
Who caused the damage?
Possible answers may depend upon:
whether the AI output was defective;
whether the human should have detected the error;
whether the service provider gave adequate warnings;
whether the customer's conduct contributed;
whether another independent event caused the loss.
The Sanofi Pasteur line of reasoning is relevant because complex technical causation cannot simply be assumed from temporal sequence.
21. Evidence
AI litigation requires specialised evidence.
Important material can include:
Model information
model version;
architecture;
training methodology;
validation;
testing.
Input data
customer data;
third-party data;
sensor data;
external databases.
Output
exact AI response;
probability score;
recommendation;
classification.
Operational evidence
logs;
timestamps;
human interventions;
model updates.
Contractual evidence
terms of service;
warranties;
disclaimers;
service-level agreements.
22. Black-Box Evidence
The provider may argue:
“We cannot explain the precise output because the model is complex.”
That argument does not necessarily end the inquiry.
The CJEU's Dun & Bradstreet decision demonstrates that, where GDPR automated-decision rights apply, the individual can be entitled to meaningful information about the logic involved. (curia)
Courts may also need to balance:
transparency;
privacy;
third-party data;
trade secrets;
intellectual property.
23. Contractual Disclaimers
AI providers may attempt to include terms such as:
“AI output is provided for informational purposes only.”
Such clauses can be relevant but do not necessarily eliminate all liability.
Their effectiveness depends upon:
applicable national contract law;
consumer status;
mandatory statutory rights;
unfair-terms rules;
the precise wording;
the provider's actual conduct.
A provider cannot necessarily contract out of mandatory statutory liability simply by calling its AI output “informational.”
24. Professional Services
The distinction is especially important when AI is used by professionals.
Lawyer uses AI
The client generally has a professional relationship with the lawyer, not necessarily with the AI developer.
Doctor uses AI
The patient normally has a medical relationship with the doctor/hospital.
Accountant uses AI
The client normally contracts with the accounting firm.
Therefore:
AI deployment does not automatically transfer professional responsibility from the professional to the AI developer.
The professional may still have a duty to verify AI-generated work.
25. Consumer AI Services
Consumer-facing AI services raise additional issues.
Examples:
AI travel-planning service;
AI financial service;
AI shopping assistant;
AI health application;
AI educational service.
Consumer law can address:
unfair contract terms;
misleading statements;
transparency;
pricing;
withdrawal rights where applicable;
digital-content/service obligations;
compensation.
26. Joint Liability
A single accident may involve:
AI developer + service provider + deployer + professional + hardware manufacturer.
The new Product Liability Directive expressly contemplates situations where more than one party is liable for the same damage and provides for joint and several liability in specified defective-component situations. (EUR-Lex)
National tort and contract law may also provide mechanisms for contribution or allocation between responsible parties.
27. Defences
Potential defences include:
1. No defect
The AI system was not defective.
2. No breach
The service provider complied with its contractual and legal obligations.
3. No causation
The AI output did not cause the damage.
4. Human intervention
An independent human decision caused the loss.
5. Unforeseeable misuse
The system was used outside reasonably foreseeable conditions.
6. Third-party interference
A third party manipulated the system.
7. State of scientific and technical knowledge
The applicable product-liability regime may permit this defence under specified conditions.
8. Customer's own conduct
The customer's conduct contributed to the damage.
28. Damages
Depending upon the applicable legal regime, compensation may concern:
Personal injury
medical expenses;
rehabilitation;
loss of earnings;
disability;
pain and suffering where recognised.
Property damage
physical property;
equipment;
data-related consequences where legally compensable.
Economic loss
lost profits;
business interruption;
additional costs.
GDPR-related damage
Where Article 82 applies, compensation requires infringement, damage and causal connection. Österreichische Post is the central authority. (Infocuria)
29. Important Distinction: Product Liability vs Service Liability
| Situation | Main legal issue |
|---|---|
| Defective AI software | Product liability |
| AI software supplied through SaaS | New PLD may apply |
| AI service integrated with a physical product | Related-service/component rules |
| Professional uses AI | Professional/contractual liability |
| AI processes personal data | GDPR |
| Automated significant decision | GDPR Article 22 |
| Consumer-facing AI | Consumer law |
| AI causes physical injury | Tort/product liability |
| AI causes financial loss | Contract/tort/sectoral rules |
| AI provider breaches regulatory duties | AI Act/sectoral regulation |
30. Eight Important Cases — Quick Revision
| Case | Main principle | AI-service relevance |
|---|---|---|
| SCHUFA, C-634/21 (2023) | Automated scoring can constitute automated decision-making | Very high |
| Dun & Bradstreet, C-203/22 (2025) | Meaningful explanation of automated logic | Very high |
| Österreichische Post, C-300/21 (2023) | GDPR damage and causation | Very high |
| Google Spain, C-131/12 (2014) | Algorithmic processing creates legal responsibility | High |
| Boston Scientific, C-503/13 & C-504/13 (2015) | Systemic product defect | High |
| Veedfald, C-203/99 (2001) | Product liability in service context | High |
| Moteurs Leroy Somer, C-285/08 (2009) | Industrial product damage | High |
| Sanofi Pasteur, C-621/15 (2017) | Technical causation/evidence | High |
| Amazon EU, C-649/17 (2019) | Digital consumer-service obligations | Medium–high |
31. Key Legal Principles
Principle 1
AI service providers are not automatically liable for every incorrect AI output.
Principle 2
Liability normally requires an applicable legal basis and the relevant elements such as breach/defect, causation and damage.
Principle 3
The new Product Liability Directive expressly treats AI systems and software as products.
Principle 4
The new Directive nevertheless distinguishes products from services as such. Related digital services integrated into/interconnected with products can receive special treatment. (EUR-Lex)
Principle 5
SaaS delivery does not by itself prevent software from being treated as a product under the new regime. (EUR-Lex)
Principle 6
AI providers processing personal data can face GDPR obligations independently of product liability.
Principle 7
Automated scoring can have legal significance even if another organisation formally makes the final decision — SCHUFA. (curia)
Principle 8
Meaningful explanation can be required for automated decisions covered by the GDPR — Dun & Bradstreet. (curia)
Principle 9
A GDPR infringement alone does not automatically establish compensable damage — Österreichische Post. (Infocuria)
Principle 10
AI does not eliminate professional responsibility where a human professional deploys the technology.
32. Simple Liability Formula
For examination purposes:
AI-powered service + applicable legal duty/product defect + breach/defect + causation + legally recognised damage = potential liability.
For GDPR:
Unlawful AI data processing + damage + causal link = potential Article 82 compensation claim. (Curia)
For automated decision-making:
Personal data + automated decision/profiling + legally significant effect + Article 22 conditions = potential GDPR challenge.
For product liability:
Defective AI/software product + damage + causal connection = potential no-fault product liability, subject to the applicable temporal and statutory conditions.
33. Conclusion
AI-powered service provider liability in Europe is a multi-layered civil-law problem rather than a single AI-liability doctrine.
The most significant recent development is the EU Product Liability Directive 2024/2853, which modernises product liability for the digital economy and expressly treats software and AI systems as products, including software delivered through cloud and SaaS models. At the same time, services as such remain outside the Directive except for specified integrated or interconnected digital services. (EUR-Lex)
The GDPR provides a separate and extremely important liability framework. SCHUFA establishes the importance of automated scoring; Dun & Bradstreet strengthens the right to meaningful information about automated logic; and Österreichische Post establishes the need for infringement, damage and causation for Article 82 compensation. (Infocuria)
The central legal question in future litigation will often be:
Was the harm caused by the AI itself, by the way the service provider deployed it, by defective data, by human reliance, by a physical product, or by a combination of these factors?
Accordingly, the strongest European liability analysis is usually:
AI system → service relationship → applicable legal regime → provider's role/control → defect or breach → causation → damage → allocation of liability.

comments