Legal 13 min read

The AI Liability Directive: How Civil Liability Works Alongside the AI Act

The EU AI Act defines compliance obligations. The AI Liability Directive determines who pays when things go wrong. Together they create a comprehensive framework — but navigating both requires a new approach to legal risk.

By Dr. Henri Dubois · Published

Two Laws, One Framework

When most people discuss EU AI regulation, they focus on the AI Act — the compliance regulation that sets standards, requires documentation, and imposes fines. But the AI Act's sister legislation, the AI Liability Directive (AILD), addresses a different but equally important question: when an AI system causes harm, who pays and how do victims prove their case?

Understanding both laws — and how they interact — is essential for any organization operating AI systems in the EU market. The AI Act creates regulatory exposure. The AI Liability Directive creates civil litigation exposure. Together, they mean that non-compliant AI could result in regulatory fines and damages claims from injured parties simultaneously.

What Is the AI Liability Directive?

The AI Liability Directive is a separate EU legislative instrument, complementary to the AI Act. While the AI Act is a product safety regulation that applies before harm occurs, the AILD addresses after-the-fact liability — providing legal remedies for people who have been harmed by AI systems. The Directive was proposed in September 2022 and is expected to be adopted in 2026-2027.

The Core Innovation: Presumption of Causality

The fundamental challenge in AI-related litigation under existing law is proof of causation. AI decision-making processes are often opaque, the causal chain from AI output to harm may be indirect, and victims may have no access to technical documentation or model logs.

The AI Liability Directive addresses this by introducing a rebuttable presumption of causality. The presumption applies when three conditions are met:

  1. The defendant was non-compliant with an AI Act obligation relevant to the occurred harm
  2. It is reasonably likely that the non-compliance influenced the AI output that led to the harm
  3. The claimant demonstrates that the AI output caused the damage

This creates a powerful incentive for AI Act compliance. Non-compliance doesn't just create regulatory exposure — it makes civil litigation dramatically easier for claimants to win.

The Right to Access Evidence

The AILD also addresses the "black box" problem through a disclosure regime. Courts can order providers and deployers of high-risk AI systems to disclose relevant evidence — technical documentation, logs, data governance records — when a claimant makes a plausible case of harm.

Critically, if the defendant refuses to disclose ordered evidence, the court can presume that the evidence would have been unfavorable. For organizations that have built robust AI Act compliance documentation: this documentation is now also relevant litigation evidence.

Relationship to the Product Liability Directive

The AILD works alongside the EU's modernized Product Liability Directive (PLD), adopted November 2024, which explicitly extends product liability to AI systems and digital products.

Aspect AI Liability Directive Product Liability Directive (revised)
Fault requiredYes (fault-based)No (strict liability)
Damages coveredProperty, personal injury, and pure economic lossProperty and personal injury
Who is liableProvider or deployer (whoever was non-compliant)Manufacturer / economic operator
Limitation period3 years from knowledge of harm3 years / 10 years absolute

What Types of Harm Are Covered?

The AI Liability Directive covers physical harm (death, personal injury), property damage, significant psychological harm, and — notably — pure economic loss. This last category is particularly significant for AI in financial services (incorrect credit decisions), employment (wrongful AI-driven terminations), and professional services (AI-generated negligent advice).

Who Is Liable: Providers vs. Deployers

Liability attaches to whoever violated the applicable AI Act obligation that contributed to the harm. Providers are liable for design and development failures (insufficient risk management, inadequate training data, poor documentation), while deployers are liable for deployment failures (inadequate human oversight, incorrect use, failure to conduct a FRIA, failure to monitor the system).

Practical Steps for Legal and Compliance Teams

  1. Understand both frameworks: Build legal team expertise in both the AI Act's compliance requirements and the AILD's liability provisions
  2. Document everything: Comprehensive AI Act compliance documentation is both your regulatory defense and your litigation defense
  3. Review contracts: Provider-deployer contracts should address liability allocation for AILD claims, including indemnification provisions
  4. Insurance audit: Commission a specific review of AI-related coverage gaps across your insurance portfolio
  5. Incident response: Build AI incident response procedures that account for both Article 73 regulatory reporting and preservation of evidence for potential civil litigation
  6. Track legislative progress: The AILD is still in the legislative process — monitor developments and update your legal strategy as the final text emerges

Need legal advice on AI Act compliance and liability? Browse our directory of legal experts specializing in AI regulation and liability.