Civil Law And Autonomous Factory Production Failure Claims In Europe
Civil Law and Autonomous Factory Production Failure Claims in Europe
1. Introduction
Autonomous factory production failure claims arise when an automated or AI-controlled manufacturing system independently performs production activities but a malfunction causes defective products, machinery damage, production stoppage, worker injury, environmental harm, or economic loss.
Examples include:
an AI-controlled robotic assembly line producing defective components;
autonomous machines incorrectly calibrating products;
an automated quality-control system failing to detect defective goods;
machine-learning software changing production parameters without direct human instruction;
interconnected robots causing a production-line collision;
an autonomous warehouse/production robot damaging equipment;
software or sensor failure causing an entire production batch to be defective;
an automated factory continuing production despite abnormal sensor readings.
There is no single European civil-law regime specifically called “autonomous factory production liability.” Instead, several legal regimes interact: product liability, national tort/delict law, contract law, machinery/product-safety rules, employer liability, and rules concerning software and connected systems.
The EU's revised Product Liability Directive is particularly important because EU institutions have expressly considered liability questions involving software, AI, interconnected products and autonomous systems. (IMIES)
A central principle is:
Autonomous operation does not make the machine a legal person.
The legal responsibility normally remains with identifiable human or corporate actors such as the manufacturer, software developer, factory operator, owner, integrator, maintenance provider or supplier.
2. Meaning of Autonomous Factory Production Failure
An autonomous factory may contain:
industrial robots;
AI production-management systems;
automated guided vehicles;
autonomous mobile robots;
predictive-maintenance systems;
machine-vision systems;
digital twins;
automated quality-control systems;
industrial IoT sensors;
cloud-based production software;
autonomous scheduling systems;
robotic packaging systems.
A production failure occurs when the system fails to perform the production process in the manner legally, contractually or technically required.
The failure can be:
A. Hardware failure
Example:
A robotic arm develops a defective braking mechanism and damages a production machine.
B. Software failure
The production-control software sends incorrect instructions to several machines.
C. Sensor failure
A temperature sensor reports 80°C when the actual temperature is 120°C, causing defective products.
D. AI decision failure
An AI system modifies production parameters based upon an incorrect prediction.
E. Integration failure
Individually safe machines become dangerous because their software interfaces are incompatible.
F. Cybersecurity failure
An external cyberattack changes machine instructions and causes production losses.
G. Human-supervision failure
The factory operator fails to respond to warnings generated by the autonomous system.
3. Main Legal Bases of Liability
Autonomous factory disputes can involve several overlapping forms of civil liability.
3.1 Product liability
The manufacturer may be liable where a defective machine, component or other product causes legally recoverable damage.
Under the EU product-liability framework, the injured claimant generally has to establish:
damage;
defect;
causal relationship between defect and damage.
The European Commission describes this as the basic structure of the EU product-liability system. (IMIES)
3.2 Contractual liability
Suppose a factory purchases an autonomous production line under a contract guaranteeing:
specified production capacity;
accuracy;
uptime;
safety;
maintenance;
software performance.
If the system repeatedly fails, the buyer may pursue contractual remedies such as:
damages;
repair;
replacement;
price reduction;
termination;
contractual penalties;
warranty claims.
The contractual claim may exist even where the strict product-liability regime does not cover the particular economic loss.
4. Pure Economic Loss
This is especially important for autonomous factories.
Suppose:
An autonomous production system stops for 72 hours but causes no personal injury and does not damage another person's property.
The factory may nevertheless suffer:
lost production;
lost profits;
contractual penalties;
customer claims;
wasted raw materials;
emergency repair costs.
Whether these losses are recoverable depends heavily upon the applicable national contract and tort law.
This is one reason why product liability and contractual liability must not be confused.
5. Defect in an Autonomous Production System
Traditional product liability asks whether the product provided the safety that persons were entitled to expect.
The assessment can involve:
product presentation;
reasonably foreseeable use;
time of placing into circulation;
design;
manufacturing;
warnings;
instructions;
software;
updates;
foreseeable interaction with other products.
The CJEU has explained the safety-based concept of defect in cases including Boston Scientific. (Infocuria)
For autonomous systems, the difficult question becomes:
Can autonomous behaviour itself constitute a defect?
The answer depends on whether the behaviour demonstrates that the system failed to provide the level of safety legally expected from the product.
6. Manufacturing Defect vs Design Defect
Manufacturing defect
The factory's autonomous machine is generally designed correctly, but one particular machine is incorrectly assembled or calibrated.
Example:
100 robotic arms are manufactured correctly, but one contains an improperly installed sensor.
Design defect
The entire system has an inherent design problem.
Example:
The AI production-control architecture does not contain adequate safeguards against simultaneous conflicting commands.
Software defect
The hardware is functioning correctly but its software produces unsafe instructions.
Warning/instruction defect
The manufacturer failed to adequately warn the operator about a foreseeable autonomous-system failure.
7. Important European Case Laws
Because there are relatively few reported European judgments dealing directly with autonomous factory AI systems, the following authorities are principally analogical product-liability authorities. They establish rules that can be applied to autonomous manufacturing failures.
Case 1 — Veedfald v Århus Amtskommune
CJEU, Case C-203/99, EU:C:2001:258, 10 May 2001
This is an important foundational EU product-liability decision.
The claimant's kidney transplant failed because a defective liquid used in preparing the kidney caused damage.
The defendant argued, among other things, that the relevant product had not been placed into circulation.
Principle
The CJEU interpreted the Product Liability Directive broadly concerning products used in providing services.
The case demonstrates that product liability can operate even where the defective product is incorporated into a wider service process. (Infocuria)
Application to autonomous factories
This is highly relevant where:
Machine + software + manufacturing process + service
operate as one technological production environment.
For example, a factory may argue that the autonomous production system is merely part of a service. Veedfald demonstrates why the legal analysis cannot automatically stop merely because the defective product operates within a broader service.
8. Case 2 — Moteurs Leroy Somer v Dalkia France
CJEU, Case C-285/08, EU:C:2009:351, 4 June 2009
This case involved an alternator manufactured by Moteurs Leroy Somer which overheated and caused damage to a hospital generator.
The dispute concerned damage to property used for professional purposes. (Eur-Lex)
Principle
The CJEU held that the Product Liability Directive did not prevent national law from allowing compensation for professional-use property where the claimant establishes:
damage;
defect;
causal connection.
(Eur-Lex)
Importance for autonomous factories
This is particularly useful for industrial machinery.
Imagine:
Autonomous motor → overheating → production generator damaged → factory shutdown.
The case demonstrates the importance of distinguishing:
product-liability minimum rules
from
broader national civil-law remedies.
9. Case 3 — O'Byrne v Sanofi Pasteur MSD
CJEU, Case C-127/04, EU:C:2006:93, 9 February 2006
The case concerned when a product is considered to have been put into circulation.
The CJEU held that a product is put into circulation when it leaves the producer's manufacturing process and enters the marketing process in the form in which it is offered for use or consumption. (Eur-Lex)
Application to autonomous factories
This becomes important when an autonomous machine:
receives software updates;
learns new operating parameters;
is modified after delivery;
is integrated with another production system.
A dispute may arise concerning which version of the system was actually placed into circulation.
For example:
Manufacturer → original robot → software update → autonomous modification → accident.
The legal question becomes whether the relevant defect existed when the product entered the relevant circulation process or resulted from later intervention.
10. Case 4 — Boston Scientific Medizintechnik v AOK Sachsen-Anhalt
CJEU, Joined Cases C-503/13 and C-504/13, EU:C:2015:148, 5 March 2015
This is one of the most important cases for autonomous-system failure analysis.
The dispute concerned pacemakers and implantable cardioverter defibrillators belonging to product groups in which a potential defect had been identified.
The CJEU held that products belonging to the same group or production series could be considered defective where that group presented a potential safety defect, even without proving that the particular individual product contained the defect. (Infocuria)
Principle
A claimant may not always need to demonstrate the precise physical defect in the individual product when the relevant production group presents a sufficiently serious safety risk.
Autonomous factory application
Suppose:
10,000 autonomous production robots receive the same defective software module.
One robot fails while the precise code-level defect cannot be physically located in that particular machine.
The Boston Scientific reasoning provides an important analogy:
Known systemic risk → individual product may be treated as defective under the applicable circumstances.
This is especially significant for:
common software versions;
common sensor models;
common AI models;
common firmware;
common production batches.
11. Case 5 — W and Others v Sanofi Pasteur MSD
CJEU, Case C-621/15, EU:C:2017:484, 21 June 2017
This case concerned proof of a product defect and causation where scientific evidence was uncertain.
The CJEU considered whether serious, specific and consistent evidence could establish defect and causation even in the absence of scientific consensus. (curia)
The judgment emphasised that the claimant bears the burden under Article 4, while national procedural law governs certain aspects of how proof is established. (Infocuria)
Application to autonomous factories
Autonomous systems create a similar evidentiary problem.
Suppose:
AI production software unexpectedly changes operating parameters.
The claimant may not possess the manufacturer's source code.
The evidence may instead consist of:
machine logs;
sensor readings;
production records;
error messages;
previous failures;
software-version records;
maintenance reports;
expert evidence.
The case therefore illustrates an important proposition:
Causation in technologically complex systems may have to be established through a body of consistent evidence rather than one simple physical observation.
12. Case 6 — Declan O'Byrne
CJEU, Case C-127/04, EU:C:2006:93
This case also provides an important principle concerning the producer and distribution chain.
The CJEU held that the relevant concept of circulation concerns the point at which the product leaves the producer's manufacturing process and enters the marketing process. It also examined circumstances involving a producer and wholly owned subsidiary. (Eur-Lex)
Autonomous-factory significance
Autonomous manufacturing frequently involves multiple corporate actors:
AI developer → robot manufacturer → system integrator → factory operator → maintenance provider.
The claimant therefore needs to determine:
who manufactured the relevant product;
who integrated the system;
who supplied the software;
who controlled the update;
who operated the machine;
who performed maintenance.
Corporate structure can become legally significant when identifying the proper defendant.
13. Case 7 — Commission v France / Commission v Greece / González Sánchez
Joined Cases C-52/00, C-154/00 and C-183/00, CJEU, 25 April 2002
These cases addressed the harmonised nature of the EU Product Liability Directive.
The CJEU emphasised that the Directive established a harmonised producer-liability framework and examined whether Member States could maintain additional rules inconsistent with that framework. (curia)
Importance
An autonomous factory operates across borders.
For example:
German manufacturer → French factory → Italian customer → Spanish component supplier.
The parties cannot simply assume that every national product-liability rule can be combined freely.
The applicable EU harmonisation rules and national law must be considered separately.
14. Case 8 — Boston Scientific and Production-Series Risk
The Boston Scientific decision deserves special emphasis because autonomous factories often produce thousands of identical or substantially identical products.
Its central proposition can be translated into manufacturing terminology:
A systemic defect can create liability concerns beyond a single physically identifiable malfunction.
This is particularly relevant to:
batch defects;
AI-model defects;
firmware defects;
defective sensor series;
defective robotic controllers;
common cybersecurity vulnerabilities.
15. Who Can Be Liable?
An autonomous factory failure may involve several possible defendants.
| Actor | Possible liability |
|---|---|
| Machine manufacturer | Hardware/design defect |
| Software developer | Software defect |
| AI developer | Defective autonomous decision system |
| System integrator | Integration/configuration failure |
| Factory operator | Negligent operation/supervision |
| Maintenance provider | Failure to maintain |
| Sensor manufacturer | Incorrect data |
| Cybersecurity provider | Security failure |
| Cloud provider | Relevant service failure, depending on contract |
| Component manufacturer | Defective component |
| Factory owner | Operational negligence |
| Employer | Workplace-related liability under applicable national law |
However, the existence of a possible defendant does not itself establish liability. The claimant still needs the legal basis, causation and recoverable damage.
16. Autonomous AI and Causation
Causation can become the hardest issue.
Consider:
Defective sensor → wrong data → AI decision → robot movement → defective product → customer loss.
There may be five potential causal stages.
The court may need to determine:
Was the sensor defective?
Did it actually produce incorrect data?
Did the AI system rely upon that data?
Did the AI decision cause the production error?
Did the production error cause legally recoverable damage?
This creates a multi-layer causation chain.
17. Human Intervention and Autonomous Decision-Making
The existence of autonomy does not automatically eliminate operator responsibility.
For example:
Scenario A
The manufacturer designs a dangerous autonomous system.
Potential issue:
design/manufacturing/software liability.
Scenario B
The system correctly detects danger but the operator ignores repeated warnings.
Potential issue:
operator negligence.
Scenario C
The operator disables safety controls.
Potential issue:
misuse or intervening conduct.
Scenario D
A software update unexpectedly changes the machine's behaviour.
Potential issue:
software/update responsibility.
Thus, courts should distinguish:
Autonomous decision-making from autonomous legal responsibility.
18. Evidence in Autonomous Factory Claims
Evidence is particularly important because the system may make decisions without leaving conventional documentary evidence.
Important evidence includes:
Technical evidence
machine logs;
sensor logs;
PLC records;
AI model versions;
firmware versions;
software updates;
system architecture;
digital-twin records.
Operational evidence
maintenance records;
inspection reports;
operator instructions;
safety warnings;
production records;
calibration records.
Causation evidence
timestamps;
error codes;
sensor outputs;
machine-learning decisions;
production-batch records;
photographs;
expert reports.
Cyber evidence
access logs;
intrusion records;
authentication records;
network traffic;
cybersecurity alerts.
19. Black-Box Problem
AI systems can create a major evidentiary problem.
Suppose an AI production system changes the speed of a robotic arm.
The factory knows:
What happened
but cannot explain:
Why the AI made that decision.
This creates questions concerning:
explainability;
access to technical information;
expert evidence;
burden of proof;
confidentiality;
trade secrets;
preservation of digital evidence.
The EU's assessment of product-liability law has specifically identified difficulties involving software, AI, connected products and autonomous robots. (Eur-Lex)
20. Damage Categories
An autonomous factory failure can produce several types of damage.
A. Personal injury
Example:
A robotic arm injures a worker.
B. Property damage
Example:
The robot damages another machine.
C. Product damage
Example:
A defective production system damages raw materials.
D. Finished-product losses
Example:
The autonomous system produces 50,000 defective components.
E. Production interruption
The factory stops operating for several days.
F. Contractual losses
The factory fails to deliver goods to customers.
G. Recall expenses
Defective products already distributed must be recalled.
H. Business interruption
The factory loses revenue during the shutdown.
Whether each category is recoverable depends on the particular legal basis and applicable national law.
21. Product Liability vs Contract Liability
This distinction is essential.
| Issue | Product liability | Contract |
|---|---|---|
| Basis | Defective product | Breach of agreement |
| Typical claimant | Injured person/customer | Contracting party |
| Fault normally required? | Generally no under strict regime | Depends on applicable law/contract |
| Defect required? | Yes | Not necessarily |
| Pure economic loss | Restricted under product-liability framework | Often central |
| Production downtime | Depends on applicable regime | Frequently addressed contractually |
| Warranty | Not necessarily | Frequently relevant |
| Liability limits | Statutory + national rules | Contractual/statutory |
Therefore:
A factory's inability to recover under product liability does not necessarily mean that it has no civil claim.
A contractual claim may remain available.
22. Defences
Potential defences include:
1. No defect
The manufacturer argues that the system was safe when supplied.
2. Misuse
The factory operated the machine outside reasonably foreseeable conditions.
3. Unauthorized modification
The factory modified the software or hardware.
4. Poor maintenance
The failure resulted from inadequate maintenance.
5. Intervening cause
A third party caused the accident.
6. Cyberattack
An external attack altered the system.
7. Scientific and technical knowledge
Depending on the applicable regime and date, the producer may invoke relevant statutory defences concerning discoverability of the defect.
8. Component defence
A component manufacturer may argue that the defect arose from the design of the finished product rather than the component itself.
The available defences depend on the particular EU and national legal regime.
23. New EU Product Liability Framework
The EU has updated its product-liability framework to address modern technologies.
The European Commission explains that the new Product Liability Directive entered into force on 8 December 2024 and is intended to adapt liability rules to technologies including software and AI. (IMIES)
This is highly relevant to autonomous factories because modern production systems increasingly combine:
hardware + software + AI + sensors + connectivity + cloud services.
The older model of:
manufacturer → physical product → consumer
is therefore increasingly replaced by:
manufacturer → component → software → AI → sensor → network → autonomous machine → production process.
24. Interconnected Product Liability
Autonomous factories rarely use isolated machines.
A typical system may look like:
Sensor → PLC → AI controller → robotic arm → conveyor → quality-control camera → cloud platform
A failure in one component can therefore produce a failure in another.
The EU's evaluation of the Product Liability Directive specifically examined interconnected products, IoT systems and autonomous systems and the problem of allocating responsibility among multiple participants. (Eur-Lex)
This creates what may be called:
Distributed technological causation
No single component necessarily causes the entire accident by itself.
25. Manufacturer vs Factory Operator
A court may ask:
Manufacturer responsibility
Was the machine defective?
Was the software defective?
Was the design unsafe?
Were adequate warnings supplied?
Was the system reasonably safe?
Operator responsibility
Was the machine properly installed?
Was it maintained?
Were warnings ignored?
Were safety mechanisms disabled?
Was unauthorized software installed?
Was the machine used outside its intended purpose?
Integrator responsibility
Were different machines correctly connected?
Were interfaces properly configured?
Was the AI system correctly trained?
Was the safety architecture correctly implemented?
26. Practical Legal Test
For an autonomous factory production failure, the court can conceptually proceed through the following questions:
Step 1 — Identify the system
What autonomous machine or AI system failed?
Step 2 — Identify the damage
Was there:
personal injury?
property damage?
product damage?
economic loss?
production interruption?
Step 3 — Identify the defect
Was the failure caused by:
design;
manufacturing;
software;
AI;
sensor;
cybersecurity;
maintenance?
Step 4 — Identify responsible actors
Who:
manufactured;
programmed;
integrated;
installed;
maintained;
operated the system?
Step 5 — Establish causation
Did the system failure actually cause the claimed damage?
Step 6 — Identify the legal regime
Consider:
EU product liability;
national tort/delict;
contract;
machinery/product-safety law;
employment/workplace liability;
consumer law where relevant.
Step 7 — Examine defences
Was there:
misuse?
unauthorized modification?
poor maintenance?
third-party intervention?
cyberattack?
Step 8 — Determine damages
Which losses are legally recoverable?
Step 9 — Examine limitation
Are there statutory or contractual limits?
Step 10 — Examine insurance
Which party's insurance potentially responds?
27. Special Problem: Autonomous Learning
Traditional machinery normally behaves according to predetermined programming.
AI-enabled machinery may:
receive data;
identify patterns;
change parameters;
produce new outputs;
adapt its behaviour.
This creates a legal question:
Can a system's behaviour become defective even though the original programming was technically correct?
The answer requires examination of the system's expected behaviour, foreseeable use, safety architecture, updates, training data, monitoring and applicable liability rules.
Autonomous learning therefore makes the distinction between:
design defect
and
emergent system behaviour
particularly important.
28. Special Problem: Software Updates
Suppose:
Day 1: Factory receives safe machine.
Day 100: Manufacturer releases update.
Day 110: Autonomous machine starts producing defective goods.
The dispute may involve:
whether the update created the defect;
whether installation was mandatory;
who installed it;
whether the update was tested;
whether the factory modified the system;
whether the original contract covered updates;
whether the updated system remained the same legally relevant product.
The O'Byrne circulation principles become relevant by analogy when identifying the legal significance of the point at which a product enters circulation. (Eur-Lex)
29. Special Problem: Mass Production
Autonomous factories are particularly vulnerable to multiplication of damage.
A traditional machine might produce one defective item.
An autonomous factory can produce:
1 defective product → 10 → 1,000 → 100,000.
Therefore, one software defect can create thousands of defective products before discovery.
This makes the Boston Scientific production-series reasoning especially significant. (Infocuria)
30. Key Case-Law Principles — Revision Table
| Case | Principle | Autonomous-factory relevance |
|---|---|---|
| Veedfald, C-203/99 | Product liability can apply to products used within a wider service process | Machine + software + manufacturing service |
| Moteurs Leroy Somer, C-285/08 | National law may provide compensation concerning professional-use property | Damage to industrial equipment |
| O'Byrne, C-127/04 | Meaning of putting a product into circulation | Software/product version disputes |
| Boston Scientific, C-503/13 & C-504/13 | Potential systemic defect can affect products in same group/series | Common AI/software/firmware defect |
| W v Sanofi Pasteur, C-621/15 | Defect and causation can be established through appropriate evidence even amid scientific uncertainty | AI causation and evidentiary complexity |
| Commission v France / Commission v Greece / González Sánchez, C-52/00 etc. | EU product-liability harmonisation limits incompatible national variations | Cross-border autonomous manufacturing |
31. Core Legal Formula
A useful examination formula is:
Autonomous Factory Liability =
System Failure + Defect/Breach + Causation + Responsible Actor + Legally Recognised Damage + Applicable Liability Regime
For a product-liability claim:
Defective Product → Damage → Causal Link → Producer Liability → Available Defence → Compensation
For a contractual claim:
Contract → Performance Obligation → Failure/Breach → Causation → Recoverable Loss → Contractual Remedy
32. Important Legal Distinction
An autonomous factory does not create an automatic rule that:
“The AI made the decision, therefore the AI is liable.”
Instead, the legal analysis normally asks:
Who created the risk?
Who controlled the system?
Who supplied the defective component?
Who programmed it?
Who integrated it?
Who maintained it?
Who ignored the warning?
Who suffered the legally recoverable damage?
That allocation is the heart of autonomous-factory civil liability.
33. Conclusion
Autonomous factory production failure claims in Europe are governed by an interaction of EU product-liability principles, national civil/tort law, contract law, machinery and safety rules, and rules applicable to software and interconnected systems.
The most important problems are:
identifying the legally relevant product;
distinguishing hardware, software and AI defects;
identifying the responsible actor;
proving causation in a technologically complex system;
determining whether production-series risks affect multiple machines;
allocating responsibility between manufacturer, software developer, integrator and operator;
distinguishing property damage from pure economic loss;
determining the effect of software updates and autonomous learning;
preserving machine and AI evidence;
calculating recoverable production and business losses.
The key principle can therefore be stated as:
Autonomous factory failure does not create a liability vacuum. Autonomy changes the factual and evidentiary questions, but civil liability remains attached to legally identifiable manufacturers, suppliers, integrators, operators and other responsible actors under the applicable EU and national rules.
Exam one-line answer:
“In European civil law, autonomous factory production failures are principally analysed through product defect, contractual breach, causation, attribution and recoverable damage, with Veedfald, Moteurs Leroy Somer, O'Byrne, Boston Scientific and W v Sanofi Pasteur providing important analogical principles for technologically complex liability.”

comments