Back to blog
AI Capability

Who is liable when AI makes a mistake?

Every director asks this question and almost no supplier answers it. The short version: liability does not disappear because a machine was involved. It lands on a person, and you get to influence which one.

Radical AI Team8 September 20265 min read
A statue of justice holding scales. Liability for an AI error does not sit with the AI.

This is the question that comes up in every boardroom conversation about AI, usually about forty minutes in, and it is the question suppliers are most practised at not answering. The evasion is always some version of "the model provides a recommendation, the final decision remains with the user." That sentence is doing an enormous amount of work, and it is worth unpacking what it actually means for you.

The AI is not a party to anything

Start with the thing that clears up half the confusion. An AI system has no legal personality. It cannot be sued, cannot hold obligations, and cannot be at fault in any legal sense. When a model produces a wrong output that causes damage, the liability question is not "was the AI wrong" but "which human or company failed in a duty they had."

That reframing matters because it tells you where to look. There are only three candidates, and they are the same three every time.

An empty courtroom. The question is not whether someone is liable, but which of three parties.An empty courtroom. The question is not whether someone is liable, but which of three parties.

The three candidates

You, as the deploying organisation. This is the default and by far the most common answer. If your company used a tool to make or support a decision affecting a customer, employee or third party, your company is answerable for that decision. Under normal Dutch civil liability, the fact that you delegated the work to software changes nothing about your duty of care. You are in the same position as if you had delegated it to an inexperienced junior: still your responsibility, still your problem.

Your supplier. The company that sold you the tool may be liable, but usually only for what they actually promised. This is where most businesses discover, at the worst moment, that the contract they signed disclaims almost everything. The supplier warrants that the software functions, not that its outputs are correct, and there is a large difference between those two.

The model provider. The organisation behind the underlying general-purpose model has obligations under the AI Act, but they run to documentation, transparency and, above a compute threshold, systemic risk testing. Those obligations are largely owed to regulators and downstream integrators, not to you as an end user with a damaged customer. Practically speaking, a small business is not going to recover damages from a foundation model provider.

So in the overwhelming majority of real cases, the answer to "who is liable" is: you are.

The three candidates side by side

PartyWhen they are on the hookWhat they typically oweRealistic for an SME to pursue
You, the deploying companyAlmost always, for any decision affecting a customer, employee or third partyFull duty of care, unchanged by having delegated the work to softwareNot applicable, you are the one being pursued
Your supplierOnly for what the contract actually warrantsUsually that the software functions, rarely that its outputs are correctSometimes, and entirely dependent on the contract you signed
The model providerObligations under the AI Act toward regulators and downstream integratorsDocumentation, transparency, systemic-risk testing above a compute thresholdEffectively no, not a practical route to recovering damages

Read that table top to bottom and the pattern is hard to miss: liability concentrates on the party with the least ability to disclaim it, which is you. That is not a flaw in the system; it follows from the fact that you are the one who chose to use the tool on a real customer.

Why the AI Act does not answer this question

A common misreading is that the AI Act settles liability. It does not. The AI Act is a product-safety and market-conformity regulation: it says what a system must do before it may be placed on the market or put into use, who must document what, and what the fines are for non-compliance. Those fines are owed to a regulator. They are not compensation to a damaged party.

Civil liability, the question of who pays your customer when something goes wrong, still runs through ordinary national law. The AI Act changes the picture indirectly, and in a way worth understanding: if you were required to keep documentation, ensure human oversight, or run a conformity assessment and you did not, that failure is evidence of not meeting a standard of care. Non-compliance does not create liability by itself, but it makes defending yourself considerably harder.

Two people talking. A named person who can explain the decision is the practical answer.Two people talking. A named person who can explain the decision is the practical answer.

The practical answer: a person who can explain the decision

Here is the part that actually protects you, and it is organisational rather than legal.

For any AI-supported decision that affects someone, there should be a named person who can explain why that decision was made. Not "the system flagged it," but the reasoning, the inputs, and why the human agreed. That is what human on the loop means in practice: not a person who theoretically could intervene, but one who actually reviewed and can account for the outcome.

This is the difference between two very different conversations. In the first, a customer complains and you explain that a person considered the case, saw the system's recommendation, and decided as follows for these reasons. In the second, you explain that the system decided and nobody looked. The first is a defensible position and often a resolvable complaint. The second is neither, regardless of how good the model was.

Four things to settle before you need them

One: read the liability clause before signing, not after an incident. Specifically look for what the supplier warrants about outputs, as opposed to uptime. If they warrant nothing about correctness, that is normal, and it means the risk sits with you. Price that in.

Two: write down which decisions may never be fully automated. Rejecting a job applicant, refusing a claim, changing a customer's terms. Put it in your AI-beleid so it does not depend on someone's judgment on a busy afternoon.

Three: keep a record of the human review. Not a heavy audit system. A note of who checked what and when. If it never becomes relevant, you lost a few seconds per decision. If it becomes relevant once, it is the difference between the two conversations above.

Four: check your insurance. Professional liability policies vary widely in how they treat damage arising from automated decision support, and the time to find out is not while making a claim.

About this page

This is a description of how liability is structured, not legal advice for a specific case. The AI Act references concern its nature as a product-safety regulation with administrative fines rather than a civil liability regime; the point that non-compliance functions as evidence rather than as automatic liability is the accurate framing and is deliberately stated that way. For anything concrete, involve your own lawyer. Written by Radical's own team; no client data was used.

Frequently asked questions

No. An AI system has no legal personality, so it cannot hold obligations or be at fault. Liability always lands on a person or a company.

Sources

  1. EU AI Act, Article 99 (penalties)artificialintelligenceact.eu
  2. EU AI Act, Article 14 (human oversight)artificialintelligenceact.eu
  3. Human on the loop (Radical definitiepagina)radicalai.nl
Looking for AI talent?

Tell us what you need.

We respond within 24 hours, from a real human.

Get in touch

Related reads

Pallets stacked outside and going nowhere. AI projects rarely fail loudly, they simply stop moving.
AI Capability

Why AI projects run aground in mid-sized companies

They do not crash. They go quiet. Five places an AI project runs aground in a mid-sized company, and why more technology fixes none of them.

4 August 20269 min read
A team around one laptop. The gap between mid-sized and large companies is twenty-one percentage points.
AI Capability

Five signals that your AI ambition is stalling on your organisation

Cost is named by 3 per cent as the reason for not using AI. Lack of experience inside the company by 11 per cent. Here is what that looks like on your own floor.

10 August 20269 min read
A calculator on a desk. The real cost is not on the invoice.
AI Capability

What AI really costs, and the budget nobody plans for

A licence of six hundred euro a month against twenty-eight thousand in staff hours. The ratio nobody puts in a business case, and how to budget it yourself.

12 August 20268 min read