{"id":8695,"date":"2023-09-30T04:37:01","date_gmt":"2023-09-30T02:37:01","guid":{"rendered":"https:\/\/eulawenforcement.com\/?p=8695"},"modified":"2023-09-30T04:37:03","modified_gmt":"2023-09-30T02:37:03","slug":"a-bi-partite-ai-liability-framework-compensatory-measures-to-enforce-compliance-with-preventive-measures","status":"publish","type":"post","link":"https:\/\/eulawenforcement.com\/?p=8695","title":{"rendered":"A \u201cbi-partite\u201d AI Liability framework: Compensatory measures to enforce compliance with preventive measures"},"content":{"rendered":"\n<p><strong>Redefining Liability<\/strong><\/p>\n<p><strong>&nbsp;<\/strong><\/p>\n<p>Current regimes and traditional notions of liability, in Europe and elsewhere, have been challenged by the emergence of Artificial Intelligence (AI) and its specific features. On one side, the combination of the features of openness, data-drivenness and vulnerability, enables the harm of further categories of protected interests \u2013 such as privacy, confidential information, cybersecurity, etc. \u2013 which in turn challenges the notion of <a href=\"https:\/\/cset.georgetown.edu\/publication\/hacking-ai\/\">damage<\/a>. On the other side, the characteristics of autonomy, unpredictability, opacity, and complexity, impact the notions&nbsp;of <a href=\"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/jetl-2022-0002\/html\">causation<\/a> and <a href=\"https:\/\/commission.europa.eu\/system\/files\/2020-02\/commission-white-paper-artificial-intelligence-feb2020_en.pdf\">duty of care<\/a>. All these features render liability assessments difficult, unless AI systems are adequately governed.<\/p>\n<p>&nbsp;<\/p>\n<p>So far, the EU\u2019s liability framework has only been partially harmonized. For instance, the current <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/PDF\/?uri=CELEX:31985L0374\">Product Liability Directive (Directive 85\/374\/EC, \u201cPLD\u201d)<\/a>, implemented into Member State law, dates back to 1984 and fails to encompass AI-related harm. Fragmentation in the EU\u2019s existing liability regime call for its revision, to catch up with the rapid changes brought by AI. This is what the proposed framework on AI liability, which can be defined as \u201cbi-partite\u201d, aims to achieve.<\/p>\n<p>&nbsp;<\/p>\n<p>The proposed <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=celex%3A52021PC0206\">AI Act<\/a>, part of the Commission\u2019s 2021 AI package \u2013 and coupled with the proposed <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A52021PC0202\">Machinery Regulation<\/a> \u2013 constitutes preventive, ex-ante measures adopting a risk-based approach to govern AI systems. Gaps in redress mechanisms under the AI Act, and doubts surrounding its surveillance authority system and AI auditing ecosystem, raise <a href=\"https:\/\/www.brookings.edu\/articles\/key-enforcement-issues-of-the-ai-act-should-lead-eu-trilogue-debate\/\">questions regarding the regulation\u2019s enforcement<\/a>. To face the scenario where a lack of compliance generates damages, the ex-ante legislation has been complemented by two proposals for compensatory, ex-post measures: the <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A52022PC0495\">revised Product Liability Directive<\/a> (\u201crevised PLD\u201d) and <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX%3A52022PC0496\">AI Liability Directive<\/a> (\u201cAILD\u201d). We look into how the revised PLD and the AILD contribute to the enforcement of the preventive measures, by pushing for compliance with the obligations they introduce.<\/p>\n<p>&nbsp;<\/p>\n\n\n\n<!--more-->\n\n\n\n<p><strong>Enforcement issues of AI Governance<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><u>The AI Act and Machinery Regulation<\/u> set out obligations allocated between different economic operators of certain AI systems. The AI Act proposes a <a href=\"https:\/\/www.cambridge.org\/core\/services\/aop-cambridge-core\/content\/view\/2E4D5707E65EFB3251A76E288BA74068\/S1867299X23000016a.pdf\/risk-management-in-the-artificial-intelligence-act.pdf\">risk-based approach to obligations<\/a>, differentiating between AI systems that create <a href=\"https:\/\/arxiv.org\/pdf\/2107.03721.pdf\">unacceptable risk<\/a> (i.e. prohibited), high risk (\u201cHRAIS\u201d), low risk or minimal risk. It imposes substantive and procedural <a href=\"https:\/\/www.adalovelaceinstitute.org\/resource\/eu-ai-act-explainer\/\">requirements for HRAIS<\/a> aimed at enhancing accountability, transparency, accuracy, fairness, safety, and robustness. As for machinery products integrating AI systems, they need to fulfil the essential requirements of both the AI Act and the <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_22_7741\">Machinery Regulation<\/a>.<\/p>\n<p>\u00a0<\/p>\n<p>Both these regulations introduce penalties (respectively, administrative fines and criminal sanctions) for infringing the risk-management obligations \u2013 viewed as a way to hold parties responsible for their deployment of AI systems. Yet the question still arises as to who should compensate the AI-caused harm that materializes once the risk is not managed. The AI Act and the Machinery Regulation <a href=\"https:\/\/deliverypdf.ssrn.com\/delivery.php?ID=493006020002123031065018084102068122023021026063030057104022112027083010029093112081096098051127025111014064065102077010123124108084075058076084123117073089030004106052019066001114115029114119021113090097090104095097098064114122095081126105098119127103&amp;EXT=pdf&amp;INDEX=TRUE\">do not provide status recognition nor procedural rights<\/a>, and doubts surround the complaint mechanism introduced by the Council proposal of the AI Act. Therefore, holding economic operators liable for AI-generated harm implies a step further from the proposed rules on AI governance: this gap in private enforcement is somewhat filled by the proposed liability directives.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Compensatory measures to enforce compliance with preventive measures<\/strong><\/p>\n<p><u>\u00a0<\/u><\/p>\n<p><u>The <\/u><u>revised PLD and the new AILD<\/u> offer distinct yet overlapping means to push for transparency, burden of proof alleviation, and <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/ip_22_5807\">compensation of victims of AI-related damages<\/a> occurring despite the preventive measures.<\/p>\n<p>\u00a0<\/p>\n<p>The proposal for a revised PLD introduces <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/qanda_22_5791\">several changes relevant to AI<\/a>, related to the directive\u2019s subjective scope (including also any person that modifies a product \u2018already placed on the market or put into service\u2019, Article 7(4)) and objective scope. The notion of product refers to intangible items such as digital manufacturing files and software, and thus AI systems (Article 4(1)); damage encompasses \u201closs or corruption of data[\u2026]\u201d (Article 4(6)(c)); defect assessment considers \u201cthe effect on the product of any ability to continue to learn after deployment\u201d (Article 6(1)(c)). Software upgrades, updates, or lack thereof, can make a product defective even if it was not when put into circulation (Article 10(2)).<\/p>\n<p>The new AILD complements the revised PLD by creating a mechanism for national claims of <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/en\/QANDA_22_5793\">fault-based liability for AI-caused damage<\/a>, and introduces provisions linked to the AI Act\u2019s preventive measures.<\/p>\n<p>\u00a0<\/p>\n<p>The directives each propose <a href=\"https:\/\/www.lexology.com\/library\/detail.aspx?g=16dd7e96-ed0e-4d84-a6bf-364bcd4f144e\">two rebuttable legal presumptions and an evidence disclosure mechanism<\/a>, aimed at overcoming opacity.<\/p>\n<p>At (potential) claimants\u2019 request, national courts are empowered to order evidence disclosure from defendants \u2013 subject to safeguards and within the limits of what is \u201cnecessary and proportionate to support a claim\u201d (Revised PLD Article 8, AILD Article 3). Non-compliance with disclosure orders activates, under certain circumstances, rebuttable presumptions of defect (for the revised PLD, Article 9(2)) or of non-compliance with duty of care (for the AILD, Article 3(5)).<\/p>\n<p>The revised PLD and AILD both introduce rebuttable presumptions of causality, respectively between the product\u2019s defectiveness and the damage (Revised PLD, Article 9(3)) and between the defendant\u2019s fault and the AI system\u2019s produced output (or failure to do so) giving rise to the damage (AILD, Article 4). The AILD\u2019s presumption only applies if the requirement of fault (e.g. non-compliance with AI Act obligations) is established. To further incentivize disclosure, the AILD provides that the defendant may rebut the causality presumption by demonstrating (although difficult) that \u201csufficient evidence and expertise is reasonably accessible for the claimant to prove the causal link\u201d \u2013 namely through the AI Act obligations of transparency, documentation, logging and recording.<\/p>\n<p>\u00a0<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>Remaining gaps in enforcement and harmonization<\/strong><\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p>The rules on AI governance and on AI liability constitute \u201ctwo sides of the same coin\u201d, creating an AI liability framework in the EU. The proposals for the AILD and the revised PLD reinforce the importance of compliance with the ex-ante obligations, particularly concerning HRAIS, and provide tools for consumers to be compensated if compliance is not enough to prevent harm. By doing so, the compensatory measures aim to fill the enforcement gaps of the preventive measures.<\/p>\n<p>\u00a0<\/p>\n<p>Yet criticism still arises regarding the enforcement of the much-needed AI liability framework, firstly due to uncertainty on the coordination between the various provisions. This encompasses the potential overlap between the AILD and the PLD (which is addressed for the current version only but not the revised one), <a href=\"https:\/\/deliverypdf.ssrn.com\/delivery.php?ID=627112031031098002071103093118005126017039000080068005126026108090070068081065079105028099044055108047124127090003009025005072027083008052040019107023008078066012102067081035117114088028066022088018126006127071008101065117099106117096089113115124102106&amp;EXT=pdf&amp;INDEX=TRUE\">the delimitation of the two directives\u2019 respective scopes<\/a> (regarding <a href=\"https:\/\/towardsdatascience.com\/no-artificial-intelligence-doesnt-exist-yet-3318d83fdfe8\">complex algorithms that do not fall under the strict definition of AI<\/a>), and <a href=\"https:\/\/deliverypdf.ssrn.com\/delivery.php?ID=544017099074089112028123101028064011027055029016031058025074020064121024095092111074110122119106047059058114067125114126093027102009075041077098102023124110076030006031016046086004124121007123114112124103029099108098015116125068093007096108006101092105&amp;EXT=pdf&amp;INDEX=TRUE\">the legal uncertainty arising from the choice of directives as legal instruments<\/a> (which also calls for greater understanding of AI functioning by authorities and courts enforcing the legislation).<\/p>\n<p>\u00a0<\/p>\n<p>The approach adopted by the framework is also criticized. First, <a href=\"https:\/\/deliverypdf.ssrn.com\/delivery.php?ID=054105104066066029102065092086117099056021035048087017065112119113127017090115089103124041097041114016032001100123028027071004118018046086035019105114065001121090073036050073100123009112122094078116074112102001074124121082028102125013064011120097114085&amp;EXT=pdf&amp;INDEX=TRUE\">applying the AI Act\u2019s risk-based approach to the AI Liability Directive<\/a> (and to its core principles like disclosure of evidence and part of the burden of proof alleviation) runs the risk of under-inclusiveness of individually pronounced risks. Second, <a href=\"https:\/\/watermark.silverchair.com\/eaac013.pdf?token=AQECAHi208BE49Ooan9kkhW_Ercy7Dm3ZL_9Cf3qfKAc485ysgAAA1EwggNNBgkqhkiG9w0BBwagggM-MIIDOgIBADCCAzMGCSqGSIb3DQEHATAeBglghkgBZQMEAS4wEQQMZK14AaIxQo-KdKnlAgEQgIIDBCJkXu1F0ki_Xf5vdtQyrlERKXQgmuL-CtscWMaTsh46OopvEt6nGmxsQkDQLZAVUcOG1FKJw551Ft2XIQptMWtausXjLoaE7FvZvnRAYIVsmADisbQwI8sfzITGVy8TU32IXIcsUEV63qM11F-GxHhxO0eCDtSVoRVDaloX0wUsPm1kF_0oVmYjZSEYB6LnBVro7kimEIRMwqVrL7CqW3XxQ5twKJLUDLXPbvqkM-grvtp_t8WRzJyswxHBAvLDGtZ06hWRYd-lb1am1GTvl2psNmshdwuMiNfeHp7T9HauBXiPYOaXniG9zS-PUlvsvqn75sejJmeKIPXwsDsteZrb4gEuMmeIplwH_wa7K3hoeeT1Q2GUwzE27QPL_UL-4dy04nanqFu6mHep5D_ZwKAqY2pDpPRJNzv7e_TrWXGnxPfCQdqV3JG1GTlVrYTYVXKSRNpewRgJ7ACTbaAYysGQKdvAvEwY5spCX2Rc2J14HAezaPZ39z4UiyHrONTNgFmgTSQvyFbbjsCrRJ4JkVcTjDvOCCB9yrY5_e_2jC4TJ3v_9Yw2P_pSlkUid40izqduJG7IuafNSEKg1NaaOGumGoOojqbIyhgvgWi-dcdI4x0mUJMPinZZNYtRQxZz07UIWmVp4eNnbUhCdqbEX2rDWs78RQtdhgpTcA1aMa2zpah15SX-W96ZYPOHCkheOrNUqn38y5IZQuDaxShmztLs94VbT7wzkwR7ncOvCYu6_p12Na9dI3B3XOQRPtO2rpv6wIfPloIZ1alhCu4cHK4NTgFZbGadd5MQXeooo6dPPHgjDNto3VBVaObrSoYXpfMBXRBZe4apokA9TT__Gc9iduY6ylGUayOipnODYDu6S9CttVdeA0d_cysLnE38PmPJ3SG1kBSLzpZKeFEb7uiDtTXLQfZwsvGUtALbU_q2nf9xX2cX_SVdFBiyxcxs08Kyn0k9_QgAd5el8pbNPWewqYuoZed1AgYnFic4AhbyvBb5yaBIOarnxTBFHChdA9mlwsA\">applying a horizontal approach to AI liability<\/a> (with a \u00ab\u00a0one-size-fits-all solution\u00a0\u00bb for various sectors) does not consider the intrinsic differences between distinct AI applications and the issues they raise. Third, <a href=\"https:\/\/europeanlawblog.eu\/2022\/11\/07\/the-proposed-eu-ai-liability-rules-ease-or-burden\/\">the approach to alleviating the claimants\u2019 burden of proof<\/a> is deemed not effective enough, as claimants still have to prove numerous elements for the directives\u2019 presumptions and disclosure mechanism to apply.<\/p>\n<p>\u00a0<\/p>\n<p>The coordination issues and general criticism reverberate on the effectiveness and enforcement of the proposed AI liability European framework. <a href=\"https:\/\/www.brookings.edu\/articles\/key-enforcement-issues-of-the-ai-act-should-lead-eu-trilogue-debate\/\">The redress mechanisms\u2019 effect remains uncertain<\/a>, and individual redress might need to be complemented by other means to ensure enforcement. Although obligations and rights related to explanation and overcoming opacity have been introduced, difficulties persist in understanding whether one was harmed because of an AI system. Consumers would still find difficulties in proving fault when it comes to complex systems, <a href=\"https:\/\/www.euractiv.com\/section\/digital\/podcast\/the-new-liability-rules-for-ai\/\">with the PLD\u2019s no-fault mechanism applying only to material harm<\/a>. Effective facilitation of redress mechanisms might <a href=\"https:\/\/www.europarl.europa.eu\/thinktank\/en\/document\/EPRS_BRI(2023)739342\">require the framework to address victims\u2019 need for specific resources<\/a> \u2013 both technical and financial \u2013 in order to support their claims \u2013 and the availability of legal assistance for AI liability cases. Additionally, <a href=\"https:\/\/www.debevoisedatablog.com\/2022\/10\/24\/eu-ai-liability-directive\/\">organizations investing in AI should start taking steps towards compliance<\/a> with the new liability framework despite the lack of legal certainty. The overall harmonization of the AI Liability framework, seemingly limited, will need to be evaluated in light of the national implementation of the directives vis-a\u0300-vis the direct application of the ex-ante provisions.<\/p>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>Redefining Liability &nbsp; Current regimes and traditional notions of liability, in Europe and elsewhere, have been challenged by the emergence of Artificial Intelligence (AI) and its specific features. On one side, the combination of the features of openness, data-drivenness and vulnerability, enables the harm of further categories of protected interests \u2013 such as privacy, confidential &hellip; <a href=\"https:\/\/eulawenforcement.com\/?p=8695\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;A \u201cbi-partite\u201d AI Liability framework: Compensatory measures to enforce compliance with preventive measures&#8221;<\/span><\/a><!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":254,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-8695","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts\/8695","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/users\/254"}],"replies":[{"embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8695"}],"version-history":[{"count":2,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts\/8695\/revisions"}],"predecessor-version":[{"id":8698,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=\/wp\/v2\/posts\/8695\/revisions\/8698"}],"wp:attachment":[{"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8695"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8695"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eulawenforcement.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}