New liability rules for artificial intelligence in the European Union

2 November 2022 | Knowledge, News

There is a lot going on in the EU about Artificial Intelligence

Artificial Intelligence (AI) is at the heart of the EU’s strategy for creating a digital single market. In this context, a number of EU legal documents have been emerging for several years, such as the White Paper on Artificial Intelligence of February 2020 or the European Parliament’s resolutions on ethical framework, civil liability and intellectual property rights for AI of October 2020.

In April 2021, the European Commission presented a revolutionary proposal for a regulation on AI (Artificial Intelligence Act), laying the foundations for a legal framework for the use of AI within the European Union. Legislative work on the AI Act is already at an advanced stage and the document is expected to come into force at any moment.

AI system output and civil liability

For some time, the Union has also been working on the issue of regulating civil liability in the context of AI. A few years ago, the European Parliament drafted a proposal for a regulation on this issue, but the draft did not ‘take hold’.

Regulations apply directly in every Member State, in the exact same way, whereas civil liability regimes vary greatly from one EU country to another. The proposed wording of the regulation was unfortunately completely incompatible with several of these regimes (including Poland’s). A much better way for the EU to regulate the issue of liability is via a directive (which sets out certain standards and mechanisms, which must then be implemented by each Member State in a manner appropriate to its own law). This is precisely the mechanism that was resorted to this time.

On 28 September 2022, the European Commission adopted two proposals leading to the regulation of AI liability. One concerns the modernisation of existing rules on the strict liability of manufacturers for defective products, whereas the other proposes a new, separate directive on AI liability.

Artificial Intelligence Liability Directive

By its very title, the Artificial Intelligence Liability Directive (AILD) indicates that it concerns non-contractual liability.

In legal-speak, AILD primarily regulates tort liability or, to put it even more simply, liability for damage arising from random events or incidents between entities not bound by a contract. This is necessary in a situation where we are indeed surrounded by AI.

So what torts can AI commit against us? For example, an autonomously driven car hits a pedestrian in a zebra crossing. An AI-controlled drone destroys a parcel in transit by dropping it from too great a height. An AI system handling a company’s debt collection misidentifies a debtor and denies them access to services. An AI system for generating personalised medicines advises us to take a medicine that then causes harm. There may be many similar examples.  AILD regulates liability in precisely these types of situations.

However, the Directive does not regulate contractual liability. This means that, for example, if an organisation buys an AI system from an IT vendor and that system fails, then (as a general rule) such organisation has nothing to look for in the AILD and rather must seek redress via a well-written agreement, prepared by a lawyer who understands AI matters.

Presumption of causality at the core of AILD

Fundamental to the AILD is its Article 4, in accordance with which (subject, of course, to a number of specific prerequisites), if an injured person brings a compensation action to court for harm caused by AI, courts should presume the causal link between the fault of the defendant using AI and the AI system’s output or failure to produce an output which gave rise to damage. So, to make this simpler, it is the duty of the entity using AI to show that it should not be held liable for the harm caused by its AI, and not the other way around (because it is too challenging or too expensive for the injured person to do so).

AILD alleviates the burden of proof for victims

Courts hearing cases for compensation for damage caused by AI will be allowed to order the defendant to disclose relevant evidence even if the injured person (the claimant) did not request disclosure or was not aware of its existence at all.

AILD’s overarching goal is to make it as easy as possible for ‘ordinary people’ affected by malfunctioning AI used by businesses, including large corporations, to seek compensation. It is up to the beneficiaries of AI to show that it was not the errors in their solutions that caused the damage.

Remarkably, the AILD introduces regulations directly in reference to the AI Act and is based on the same grid of concepts. It differentiates liability issues according to the type of risk of system application that we are dealing with (high-risk vs. non-high-risk AI systems).

Thus, in relation to non-high-risk AI systems, the presumption of causality only applies if the court considers that it is excessively difficult for the claimant to prove a causal link. However, for high-risk AI systems five requirements are laid down and it is only where any one of them is not complied with that the presumption of causality may be deemed to have been met.

What next

The Commission’s proposals now need to be adopted by the European Parliament and the Council. The publication of the Commission’s draft legislation will open discussions at EU and national levels, which should lead to the best possible alignment of legislative solutions with ‘life’.

 

Any questions? Contact the authors

Piotr Kaniewski

Paulina Perkowska

 

Latest Knowledge

NIS2 and the National Cybersecurity System Act in transport: what you need to do before October 2026

The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.

Family foundations: the government has done the maths and presented the bill

Three years. That’s how long we’ve been waiting for what the Council of Ministers had seen in the data from the outset – and has now disclosed in its review of the Family Foundation Act. The document not only diagnoses the problems, but also previews substantial changes to rules that founders and their advisers treated as settled and stable. And therein lies a problem that goes far beyond tax matters. If the rules of the game are changed while the game is being played, there can be neither planning stability nor trust in the law. It is no coincidence that one of the greatest concerns among entrepreneurs considering setting up a foundation is not the level of taxation, but the stability of the legal framework – which today is once again being called into question.

What the new swiss franc act means for banks

We now have a new Act on Special Measures for the Adjudication of Cases Concerning Loan Agreements Denominated in or Indexed to the Swiss Franc. The provisions come into force 14 days after publication. So now is a good time to look at what lies ahead and what banks should be doing today.

New draft Pay Transparency Act – what has changed since December 2025?

A second version of the draft act on strengthening the application of the right to equal pay for equal work or work of equal value between men and women has now been published. It refines procedures and deadlines and introduces a new supervisory body. We have already discussed the changes affecting the recruitment stage and the three pillars of the forthcoming pay transparency framework, noting that Poland will miss the EU transposition deadline of 7 June 2026. Now, we take a closer look at the further changes, new developments and risks that have emerged in the latest, April version of the draft.

Payment Services Regulation (PSR) – between consumer protection and due diligence

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

“Withdraw from contract here” – what next for the new button in online shops, on trading platforms and in mobile apps?

From 19 June, national legislation was to require businesses in the European Union entering into distance contracts with consumers via an online interface to provide consumers with the option to withdraw from the contract via a dedicated function/button. However, due to Poland’s delay in transposing Directive 2023/2673, which requires the use of such a button, this obligation has been postponed in our country. We look at what remote contract withdrawal entails and which transactions the new feature will apply to.

Municipal master plans – new deadline, same old challenges

On 11 June 2026, the President signed into law a bill extending the deadline for municipalities to adopt their master plans (plany ogólne). The key deadline for adopting master plans was moved from 30 June to 31 August 2026. We examine the reasons behind this change and consider what the absence of a master plan might mean for potential investors and their future projects.