What is the Artificial Intelligence Liability Directive?
On 28 September 2022, the European Commission released the proposal for an Artificial Intelligence Liability Directive ("AI Liability Directive"), that deals with claims for harm caused by AI systems, or the use of AI, adapting non-contractual civil liability rules to artificial intelligence.
The AI Liability Directive complements the Artificial Intelligence Act by introducing a new liability regime that ensures legal certainty, enhances consumer trust in AI, and assists consumers’ liability claims for damage caused by AI-enabled products and services.
It applies to AI systems that are available on the EU market, or operating within the EU market.
Before the directive, national liability rules, in particular based on fault, were not suited to handling liability claims for damage caused by AI-enabled products and services. Under such rules, victims need to prove a wrongful action or omission by a person who caused the damage. The specific characteristics of AI, including complexity, autonomy and opacity, make it difficult or prohibitively expensive for victims to identify the liable person and prove the requirements for a successful liability claim.
In particular, when claiming compensation, victims could incur very high up-front costs and face significantly longer legal proceedings, compared to cases not involving AI. Victims could therefore be deterred from claiming compensation altogether.
If a victim brings a claim, national courts, faced with the specific characteristics of AI, may adapt the way in which they apply existing rules on an ad hoc basis to come to a just result for the victim.
This caused legal uncertainty. Businesses would have difficulties to predict how the liability rules would be applied, and thus to assess and insure their liability exposure. It would particularly affect businesses trading across borders, and small and medium-sized enterprises (SMEs), which cannot rely on in-house legal expertise or capital reserves.
Several Member States were considering, or even concretely planning, legislative action on civil liability for AI. If the EU did not act, Member States would adapt their national liability rules to the challenges of AI. This would result in further fragmentation and increased costs for businesses active throughout the EU.
20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists.
The withdrawn AI Liability Directive has not been replaced by any single, functionally equivalent legal instrument. The regulatory and remedial space that the proposed Directive was intended to occupy is now addressed only partially and cumulatively through a fragmented, multi layered legal framework that includes the revised Product Liability Directive, the AI Act, applicable national rules of tort and delict, contractual remedies, data protection and antidiscrimination law, and sector specific liability regimes.
In particular, the revised Product Liability Directive establishes a liability regime for defective products, expressly covering software and AI systems, and introduces mechanisms for access to evidence and presumptions of defectiveness and causation. Its material scope, however, remains tied to product defect and specified categories of compensable damage.
A material residual liability and remedial gap remains. This is particularly significant for:
1. Non contractual, fault based claims arising from AI enabled services or decision making.
2. Claims for pure economic loss falling outside harmonised product liability rules.
3. Certain forms of harm affecting fundamental rights or legally protected interests.
4. Cases in which the opacity, complexity or autonomous characteristics of an AI system make it disproportionately difficult for a claimant to establish the factual and causal nexus between the defendant's conduct, the operation or output of the AI system, and the damage alleged.
The evidentiary dimension of that gap is especially important. The proposed AI Liability Directive was expressly designed to address situations in which conventional national rules governing proof of fault and causation could place an injured party at a structural disadvantage because the relevant evidence is technically inaccessible, controlled by the defendant, or obscured by the complexity and opacity of the AI system.
The withdrawal of the AI Liability Directive did not solve the underlying legal problem. It removed the proposed horizontal Union law mechanism for addressing it. The resulting framework is characterised by partial functional substitution. Where the revised Product Liability Directive, the AI Act or another harmonised Union regime does not provide an applicable cause of action or remedial mechanism, questions of fault, causation, recoverable damage, access to evidence and compensation continue to depend on the private law and procedural rules of the individual Member States.
This leads to divergent outcomes across the Union. This creates incentives for jurisdictional arbitrage, regulatory shopping and, where procedural rules permit, forum shopping. In the absence of a harmonised horizontal regime governing fault based liability for AI related harm, comparable conduct gives rise to different liability exposures depending on the Member State whose substantive and procedural law is applicable. Divergences arise in the standard of care, the allocation and standard of proof, presumptions of causation, disclosure of evidence, the recognition of pure economic or non material loss, limitation rules, and the assessment of damages.
Recital 6 of the proposed AI Liability Directive:

20 August 2026, Update - The 5 Post AI Liability Directive indicators | Legal Intelligence
The legal question: Are there observable legal developments that recreate and expand the fragmentation, evidentiary difficulties, and internal market distortions that the AI Liability Directive was originally intended to prevent?
We monitor five indicators.
1. National divergence, the fragmentation indicator.
This is the primary indicator. The question is whether materially comparable AI related harm produces materially different civil law consequences, depending on the Member State in which the claim is determined.
We monitor divergence in legislation expressly dealing with AI liability, but also across the entire liability architecture, including the legal characterisation of fault, use of AI Act obligations in establishing a standard of care, recoverability of pure economic and non-material loss, treatment of discrimination and fundamental rights harms, access to technical evidence, disclosure obligations, presumptions and standards of causation, limitation periods, remedies, and calculation of damages.
The legal intelligence trigger would be: The same or substantially equivalent AI conduct begins producing systematically different liability outcomes across Member States because of differences in national substantive or procedural law.
2. First wave AI litigation, the doctrinal formation indicator.
The first significant cases will matter, as courts will have to translate the AI Act's regulatory obligations into existing private law categories.
The critical litigation question will be: What private law consequences, if any, follow from breach of an obligation imposed by the AI Act?
A claimant may argue that non compliance with obligations concerning risk management, data governance, documentation, logging, transparency, human oversight, accuracy, robustness or cybersecurity constitutes evidence of negligence or otherwise contributes to establishing breach of the applicable duty or standard of care.
That does not mean that every AI Act infringement automatically gives rise to damages. The cause of action, protected interest, fault requirement, causation and recoverable damage will still have to be established under the applicable liability regime.
We will monitor whether national courts treat AI Act obligations as regulatory requirements, or as relevant evidence of civil fault, or, more significantly, as normative standards capable of materially shaping the applicable private law duty of care.
3. CJEU preliminary references, the Judicial Harmonisation Indicator.
As national courts encounter disputes between the AI Act, Product Liability Directive, GDPR, consumer protection, equality law, fundamental rights and national tort law, questions of Union law interpretation may reach the Court of Justice (under Article 267 TFEU).
The questions referred will be more important than the number of referrals. We will watch particularly for references concerning the meaning and legal effect of AI Act obligations, whether particular Union provisions confer rights or protect interests relevant to damages claims, the relationship between AI Act non compliance and product defectiveness, evidentiary consequences of missing documentation or logs, causation, effective judicial protection, and the interaction between Union rules and restrictive national rules governing remedies.
The intelligence threshold: National courts begin asking Luxembourg to determine what the AI Act requires, and what legal consequences must follow when those requirements are infringed.
The liability challenges will move from national doctrinal experimentation to European judicial harmonisation. This could create a form of harmonisation without AILD 2.0 (not comprehensive legislative harmonisation, but incremental harmonisation through CJEU jurisprudence).
4. Insurance differentiation, the monetisation of uncertainty indicator.
Insurers price prospective liability risk. Insurance markets will detect legally significant divergence before legislators formally recognise it.
We will monitor changes in underwriting questionnaires, exclusions, endorsements, sublimits, deductibles and premiums relating specifically to AI.
Particularly significant are insurer demands concerning AI Act classification, technical documentation, logging, human oversight, model governance, third party foundation models, training data, post market monitoring, incident management, and contractual allocation of AI liability.
The strongest signal would be jurisdiction sensitive pricing. If substantially similar AI deployment attracts materially different premiums, exclusions or coverage conditions depending on the Member State, applicable law, or anticipated litigation, the legal fragmentation has acquired an economic price.
5. Jurisdictional arbitrage, the internal market distortion indicator.
This is the most sensitive indicator and should be built carefully.
We will avoid suggesting that companies can simply select whichever Member State offers the weakest tort regime. The intelligence question is narrower: Does divergence in AI related civil liability begin influencing legally available choices concerning corporate structuring, contractual arrangements, establishment, deployment, distribution, insurance, litigation strategy, or other connecting factors?
If so, we begin moving from legal fragmentation to economically consequential jurisdictional arbitrage.
We distinguish three concepts:
Regulatory arbitrage. Structuring activity to benefit from differences between applicable regulatory/liability environments.
Jurisdictional arbitrage. Structuring legally relevant connections to obtain a more favourable jurisdictional or governing law position where Union law permits.
Forum shopping. Selecting among legally available fora after or in anticipation of a dispute. (Forum shopping describes the conduct of a litigant who, where more than one court is legally competent to hear substantially the same dispute, selects the forum perceived to offer the most advantageous legal or procedural environment.)
The five indicators should be read together. The intelligence value comes from correlation.
11 February 2025 - The European Commission Withdraws the Artificial Intelligence Liability Directive.
On February 11, 2025, the European Commission disclosed in the "2025 Work Programme" that it will withdraw the proposal for a new Artificial Intelligence Liability Directive.
Which is the reason?
"No foreseeable agreement - the Commission will assess whether another proposal should be tabled or another type of approach should be chosen."
26 July 2024, Update
Contrary to circulating rumors, the assertion that the AI Liability Directive would be abandoned is unfounded. The European Commission has unequivocally reaffirmed its commitment to advancing the Directive, as evidenced by the recent dissemination of the amended proposal to EU governments and lawmakers for further examination. This underscores the Commission's dedication to establishing a robust legal framework for AI liability, reinforcing the alignment with the new AI Act - Regulation (EU) 2024/1689, and expanding the scope of liability for high-risk AI applications.
Understanding the AI Liability Directive.
AI can harm interests and rights that are protected by EU or national law. For instance, the use of AI can adversely affect a number of fundamental rights, including life, physical integrity, non-discrimination, and equal treatment.
The AI Act introduces requirements intended to reduce risks to safety and fundamental rights. Other EU law instruments regulate general and sectoral rules applicable also to AI-enabled products. While such requirements intended to reduce risks to safety and fundamental rights, and prevent, monitor and address societal concerns, they do not provide individual relief to those that have suffered damage caused by AI.
Existing requirements provide in particular for authorisations, checks, monitoring and administrative sanctions in relation to AI systems in order to prevent damage. They do not provide for compensation of the injured person for damage caused by an output or the failure to produce an output by an AI system.
To reap the economic and societal benefits of AI and promote the transition to the digital economy, it is necessary to adapt in a targeted manner certain national civil liability rules to those specific characteristics of certain AI systems. Such adaptations should contribute to societal and consumer trust and thereby promote the roll-out of AI. Such adaptations should also maintain trust in the judicial system, by ensuring that victims of damage caused with the involvement of AI have the same effective compensation as victims of damage caused by other technologies.
This Directive follows a minimum harmonisation approach. Such an approach allows claimants in cases of damage caused by AI systems to invoke more favourable rules of national law. Thus, national laws could, for example, maintain reversals of the burden of proof under national fault-based regimes, or national no-fault liability (referred to as ‘strict liability’) regimes of which there are already a large variety in national laws, possibly applying to damage caused by AI systems.
Access to information about specific high-risk AI systems that are suspected of having caused damage is an important factor to ascertain whether to claim compensation and to substantiate claims for compensation. Moreover, for high risk AI systems, the AI Act provides for specific documentation, information and logging requirements, but does not provide a right to the injured person to access that information.
It is therefore appropriate to lay down rules on the disclosure of relevant evidence by those that have it at their disposal, for the purposes of establishing liability. This should also provide an additional incentive to comply with the relevant requirements laid down in the AI Act to document or record the relevant information.
The large number of people usually involved in the design, development, deployment and operation of high-risk AI systems, makes it difficult for injured persons to identify the person potentially liable for damage caused and to prove the conditions for a claim for damages.
To allow injured persons to ascertain whether a claim for damages is well-founded, it is appropriate to grant potential claimants a right to request a court to order the disclosure of relevant evidence before submitting a claim for damages.
Such disclosure should only be ordered where the potential claimant presents facts and information sufficient to support the plausibility of a claim for damages and it has made a prior request to the provider, the person subject to the obligations of a provider or the user to disclose such evidence at their disposal about specific high-risk AI systems that are suspected of having caused damage which has been refused.
Ordering disclosure should lead to a reduction of unnecessary litigation and avoid costs for the possible litigants caused by claims which are unjustified or likely to be unsuccessful.
National courts will be able, in the course of civil proceedings, to order the disclosure or preservation of relevant evidence related to the damage caused by high-risk AI systems from persons who are already under an obligation to document or record information pursuant to the AI Act.
There could be situations where the evidence relevant for the case is held by entities that would not be parties to the claim for damages but which are under an obligation to document or record such evidence pursuant to the AI Act. It is thus necessary to provide for the conditions under which such third parties to the claim can be ordered to disclose the relevant evidence.

This website is developed and maintained by Cyber Risk GmbH as part of its professional activities in the fields of risk management and regulatory compliance.
Cyber Risk GmbH specializes in supporting organizations in understanding, navigating, and implementing complex European, U.S., and international risk related regulatory frameworks.
Content is produced and maintained under the professional responsibility of George Lekatis, General Manager of Cyber Risk GmbH, a well known expert in risk management and compliance. He also serves as General Manager of Compliance LLC, a company incorporated in Wilmington, NC, with offices in Washington, DC, providing risk and compliance training in 58 countries.