Updated as of 17 February 2026. As artificial intelligence (AI) systems become widespread in products and services, a central question arises: when the algorithm gets it wrong, who is liable for the harm? In Europe, the AI Act regulates placing AI on the market and its use, but creates no dedicated civil liability regime. In France, the answer therefore lies in traditional Civil Code regimes and rigorous contract design.
1) AI Act: a compliance framework, not a liability regime
The AI Act entered into force on 1 August 2024, with phased application until 2 August 2026. It classifies AI systems by risk level (unacceptable, high, limited, minimal) and imposes compliance obligations (data governance, human oversight, documentation, traceability, CE marking for high-risk systems), backed by administrative penalties reaching €35m or 7% of worldwide turnover for prohibited practices (EUR-Lex — AI Act; European Commission — AI regulatory framework).
Important: the AI Act establishes no specific civil liability. Following abandonment of the proposed European AI liability directive in 2025, compensation for harm falls under general national law (defective products, contractual/tort liability), overseen by civil and commercial courts (Justice.fr).
2) French regimes applicable when AI causes harm
2.1. Liability for defective products
The producer is liable for harm caused by a product's safety defect, whether hardware, embedded software or a digitised service integrated into a product. The victim must prove harm, defect and causation. Grounds for exemption exist (e.g. development risk, improper use). Deadlines and conditions are specified by the Civil Code (art. 1245 et seq.) (Legifrance).
2.2. Liability for things (custody of a thing)
Where AI is integrated into a “thing” (device, vehicle, sensor), its custodian may be liable under Article 1242, paragraph 1, unless an external cause applies. This regime is often used where the product or system falls outside the strict definition of a defective “product” but caused harm through abnormal operation (Legifrance).
2.3. Contractual and tort liability
Between businesses, contractual breach (non-conforming delivery, SLA breach, lack of agreed human oversight) gives rise to liability (art. 1231-1). Outside a contract, fault (negligent design, defective integration, missing critical updates) grounds tort liability (art. 1240) (Legifrance). Regulated professionals remain subject to a heightened duty of care: using AI does not remove the need to verify and document human decisions (Justice.fr).
3) The AI stakeholder chain: who may be liable?
- Provider: designs or develops AI. Exposed to defective-product liability and design/integration fault. Subject to AI Act obligations according to risk level (documentation, risk management, logs, CE marking for high risk) (EUR-Lex — AI Act).
- Integrator/Deployer: assembles AI into a solution or adapts it to a use case. May become an “apparent producer” or custodian of the thing; contractually responsible for integration choices, configuration and promised oversight.
- Importer/Distributor: conformity checks and information obligations. Their fault (failure to warn, late withdrawal) may give rise to liability.
- Professional user: must implement risk-appropriate human controls, train teams and respect individuals' rights (GDPR, transparency). Breach may give rise to contractual/tort liability (CNIL — Artificial intelligence).
4) Practical scenarios: how is liability allocated?
4.1. Recruitment AI (bias, discrimination)
Automated screening unlawfully rejects applicants. The provider may face a claim (design defect/biased training data). The employer using it remains responsible towards applicants (tool selection and oversight, compliance with employment and non-discrimination law). The CNIL outlines transparency and, where applicable, impact-assessment requirements (CNIL).
4.2. AI diagnostic support tool
If the algorithm directs care incorrectly, the manufacturer of the AI-equipped medical device may face proceedings (defective product). The practitioner remains bound by their duty of care and ultimate medical decision. Security and traceability obligations apply throughout the chain (logging, updates) (AI Act; Service Public Pro).
4.3. Customer chatbot providing misinformation
A bank deploys an AI assistant that provides incorrect information causing loss. The AI provider may be targeted (integration/failure). The bank is responsible towards the customer (inadequate information, duty to warn as applicable). The contract must include safeguards (human oversight, escalation thresholds) and proportionate liability limits (Legal commentary).
4.4. Vehicles with autonomous functions
For an accident linked to automated driving, liability may concern the manufacturer (defect), integrator or vehicle custodian depending on circumstances and activation status. The French framework has been adapted for introducing automated driving systems without removing application of the above civil regimes (Legifrance).
5) Evidence and causation: how to win (or avoid) litigation
- Logging and traceability: high-risk systems must retain logs. This is crucial to establish causation and demonstrate compliance (AI Act).
- Technical documentation: manuals, intended-use sheets, data sheets, test reports, risk assessments.
- Human oversight: evidence of prior and subsequent checks, human-review trigger thresholds, operator training (EU AI framework).
- Data protection: processing records, impact assessments (DPIAs) where necessary, compliant information and legal basis (CNIL).
6) Key contractual clauses for allocating AI risk
- Intended-use definition and user obligations (input data, oversight, updates).
- AI Act compliance warranty (if high risk: technical files, CE marking, logs, audit support) and proportionate audit rights.
- Liability limitations and caps suited to risk, targeted exclusions (consistent with applicable law, particularly consumer law).
- Contextualised quality/accuracy SLAs, with correction and withdrawal mechanisms.
- Security and updates (patch management, vulnerability disclosure).
- Intellectual property and data (licences, training-data provenance warranties, third-party claims) (INPI).
- End-user transparency (clear information, AI-use notices, consent where required) (Service Public Pro).
Need an AI contract package (terms of sale, DPA, DUA, compliance schedule, SLA)? Explore AI and law resources.
7) Practical AI Act and GDPR compliance: the 90-day plan
- Map your systems and classify by risk level (unacceptable/high/limited/minimal) (AI Act).
- Establish governance: AI compliance lead, risk-management policies, systems register.
- Document: technical file, logs, training data, performance assessment (robustness, accuracy).
- Implement human oversight: escalation procedures, confidence thresholds, retrospective review.
- Regulate data: legal basis, minimisation, DPIA if needed, individuals' rights (CNIL).
- Train teams (legal, data, product, business) and test under real conditions.
- Adapt contracts and insurance (professional indemnity, cyber, product).
- Prepare CE marking and registration (high risk), and interactions with competent authorities (EU — AI framework).
We use a tool-supported, iterative compliance approach. Discover the Initial journey.
For further operational detail, also see this industry guide: AI Act 2026: Compliance guide.
8) Authorities, inspections and penalties: what to expect
- Data protection: CNIL inspections and penalties for AI-project breaches (lawfulness, information, security) (CNIL).
- Commercial practices: oversight of fairness and consumer information (DGCCRF role). Useful references: Service Public Pro.
- Manipulated content: sector regulation (ARCOM), particularly transparency of synthetic content.
- AI Act penalties: significant administrative fines for non-compliance (prohibited practices, high-risk breaches) (AI Act).
9) Good practice to reduce exposure
- Systematically verify and document AI outputs for sensitive decisions.
- Implement technical safeguards (confidence thresholds, red teaming, kill switch).
- Track model versions, datasets and critical prompts.
- Clearly inform end users of AI use and limitations (Service Public Pro).
- Conduct regular audits and retain evidence (logs, reports); useful for both compliance and litigation defence (Justice.fr).
Our teams design and negotiate your risk-allocation clauses. Explore AI and law resources and read other AI and law analysis.
Further reading
Read our related guides: The legal limits of AI in business, European AI Act: complete guide and Contractual clause on AI use.
Quick FAQ
Does the AI Act mean automatic provider liability?
No. The AI Act is a compliance framework with administrative penalties. Civil liability remains governed by general law (France/EU) (AI Act).
Is harm caused by AI enough to make the producer liable?
A defect (failure to provide expected safety), harm and causation must be demonstrated. Technical evidence (logs, tests) is decisive (Legifrance).
Can I contractually limit my liability?
Yes, subject to mandatory rules and consumer law. Include suitable caps, intended use and mandatory oversight (Service Public Pro).
This content is informative and does not constitute legal advice. Contact a lawyer for a case-by-case analysis.
Further reading
Related resources
Frequently asked questions
FAQ
Does the AI Act create a specific civil liability regime for AI?
No. The AI Act regulates placing AI systems on the market and their use, and provides administrative penalties, but civil liability remains governed by general national law (defective products, contractual and tort liability).
Who is liable if a business chatbot provides incorrect information?
Depending on the case, the provider (design defect), integrator (misconfiguration) and business user (inadequate information, lack of oversight) may face claims. Allocation depends on contracts, technical evidence and causation.
How can an algorithm's role in harm be proved?
Through traceability (logs), technical documentation, test reports and analysis of the processing chain. For high-risk AI, the AI Act requires logging that facilitates investigation.
Can AI-related liability be contractually limited?
Yes, with suitable caps, targeted exclusions and user obligations (intended use, oversight). Beware of statutory B2C limits and mandatory obligations.
Which authorities may inspect my AI project in France?
Depending on the matter: CNIL (personal data), DGCCRF (fair consumer information), ARCOM (content). The AI Act also provides for market surveillance authorities in Member States.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.