Who pays when AI fails
Lesson 2 of 5 in Legal Intersections, Liability, and the Failure Files.
Regulatory penalties are only half the exposure map. The other half is liability — private parties suing for harm — and here the ground has been moving. Whoever advises on AI deployments needs the current lay of four regimes, because plaintiffs choose among them strategically.
Product liability, rebuilt for software. The EU’s revised Product Liability Directive (EU) 2024/2853 did quietly radical things: software — expressly including AI systems — is now a product; defectiveness accounts for a product’s ability to continue learning after deployment; manufacturers stay liable for defects arising from updates (or needed updates never supplied) within their control; and, crucially for AI, courts can order disclosure of technical evidence, with defectiveness or causation presumed where a defendant fails to disclose, or where proof is excessively difficult due to technical complexity — the black-box problem answered with a burden shift. Member-state transposition was due by December 2026.
The dog that did not bark. Alongside the PLD, the Commission had proposed a dedicated AI Liability Directive to ease fault-based claims. It was withdrawn in February 2025. The consequence: fault-based AI claims proceed under ordinary national negligence law, and the new PLD carries more of the load than originally designed — a genuine gap for harms the PLD does not cover well, like pure discrimination or reputational injury without material damage.
Negligence and its relatives. The workhorse theories: negligent deployment (you fielded a system a reasonable operator would have tested), negligent oversight (your rubber-stamp review), vicarious liability and agency (your AI or your vendor acted as your agent — the theory a US court allowed to proceed against Workday, treating the screening vendor as potentially an agent of the employer, in Mobley v. Workday). US doctrine still contests whether AI is a "product" for strict liability and how far Section 230 shields generated content — positions vary by circuit and are moving; date-stamp anything you write.
Contract and consumer protection. The most operationally instructive regime, because the cases are so clean — Air Canada’s chatbot, coming up in the failure files, is its flagship.
| Regime | Who sues | What must be proven | AI-specific features |
|---|---|---|---|
EU product liability (PLD 2024/2853) | Natural persons harmed by a defective product (death, injury, property, data destruction) | Defect, damage, causation — no fault required | Software and AI are products; liability follows post-sale updates and continued learning; disclosure orders plus presumptions of defect/causation where black-box complexity makes proof excessively hard |
Negligence (national tort law) | Anyone foreseeably harmed | Duty, breach of reasonable care, causation, damage | Your governance program is the evidence: testing records, monitoring, incident response define what "reasonable care" looked like — or prove you skipped it |
Contract / consumer protection | Counterparties and consumers | A representation or promise, reliance, loss | Companies are bound by what their AI tells customers (Moffatt v. Air Canada); disclaimers rarely defeat specific misstatements a reasonable consumer relied on |
Discrimination law | Applicants, employees, borrowers, tenants in protected classes | Disparate treatment or unjustified disparate impact — intent not required for the latter | Vendor tools do not launder liability (EEOC v. iTutorGroup settled exactly this in hiring); agency theory can reach the vendor too (Mobley) |
Public enforcement rounds out the picture — and its pattern matters more than any single action: regulators did not wait for AI-specific statutes. They stretched the tools they had.
EU AI Act penalties — the ceiling
Up to €35M or 7% of global annual turnover for prohibited practices; up to €15M or 3% for most other violations (including high-risk obligations); up to €7.5M or 1% for supplying misleading information to authorities. Whichever is higher — for large firms the percentage governs. The enforcement machinery (market surveillance authorities, the AI Office for GPAI) is covered in the enforcement module; what belongs here is the design signal: the ceiling exceeds the GDPR’s 4%, and it was set deliberately.
FTC — Rite Aid and the AI-claims sweeps
In December 2023 the FTC banned Rite Aid from using facial-recognition surveillance for five years: the pharmacy had deployed error-prone face matching that generated thousands of false shoplifter accusations, disproportionately in stores serving communities of color, with no accuracy testing and no meaningful redress channel. Legal basis: plain old unfairness under Section 5 of the FTC Act — no AI statute needed. The parallel "Operation AI Comply" sweeps hit companies for claims about AI (fake-review generators, "AI lawyer" overpromises): deception law reaches marketing departments faster than any AI act reaches models.
EEOC — iTutorGroup, the first AI hiring settlement
The EEOC’s first AI-discrimination settlement (2023, $365,000): iTutorGroup’s recruiting software automatically rejected female applicants aged 55+ and male applicants 60+. An applicant discovered it by resubmitting the identical résumé with a younger birth date — and getting an interview. The oldest discrimination statutes in the book, applied to software, with a detection method (matched-pair testing) any auditor could have run first.
State attorneys general and local laws
Texas’s AG reached a 2024 settlement with Pieces Technologies over accuracy claims for its clinical genAI summarization tool — healthcare AI marketing policed under state consumer-protection law — and later opened further health-AI inquiries. NYC’s Local Law 144 (bias audits for automated hiring tools) produced a quieter lesson: modest formal enforcement, but its public-audit requirement created a de facto disclosure regime whose real effect was vendors withdrawing tools they could not audit cleanly. Colorado’s AI Act, in force since June 2026, hands its AG an AI-specific duty-of-care regime for consequential decisions — the first of its kind actually operative.
The insurance market’s verdict
AI liability insurance now exists as a product category — underwriters price your governance program directly: inventory completeness, testing evidence, incident-response maturity, vendor-contract quality. When an underwriter charges less because you can produce the artifacts this domain taught you to build, the market has monetized the thesis of this entire curriculum.
Key terms: product liability, defectiveness, negligence, vicarious liability, disparate impact, unfairness
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.