The shift from generative AI assistants to Agentic AI means that digital systems no longer just generate text or code, but actively make decisions and execute actions on behalf of an organization. But what if such an agent places a faulty order, executes an incorrect legal analysis, or disrupts a crucial operational process? Who is responsible?
There will be no separate EU regime for such damage. In its February 2025 work programme the European Commission announced the withdrawal of its proposal for an AI Liability Directive, and the withdrawal was published in the Official Journal on 6 October 2025 (C/2025/5423).
What does change: product liability for software
Where the AI Act sets rules before a system reaches the market, the revised Product Liability Directive (EU) 2024/2853 governs what happens when a product causes damage. Three points matter for organisations deploying AI:
- Software is a product. The directive names software explicitly (Art. 4). It applies to products placed on the market or put into service after 9 December 2026.
- The manufacturer is liable, and substantial modification can make you one. Liability rests first with the manufacturer (Art. 8). Anyone who substantially modifies a product outside the manufacturer's control and then puts it into service is treated as a manufacturer.
- Proof becomes easier for claimants. Courts can order disclosure of evidence (Art. 9) and, in certain cases, presume defectiveness or causation, for instance where technical complexity makes proof excessively difficult (Art. 10).
Mind the limits: the directive covers death and personal injury, damage to property and loss of data not used for professional purposes (Art. 6). Purely commercial losses from an agent's mistake fall outside it and remain a matter of national contract and tort law.
From Technology to Demonstrable Control
This legal reality forces organizations to look beyond just the intelligence or speed of an AI model. In 2026, it is above all about governance: how was the agent instructed? What guardrails have been built in? And where in the process is the human-in-the-loop?
In a modern, AI-enabled organization, humans and machines work closely together. It is crucial that every action of an autonomous agent is logged and explainable. This directly impacts the architecture of your IT landscape. The use of Private AI and sovereign solutions offers a massive strategic advantage here. Because the data never leaves your own tenant and logging is managed internally, you retain full control and always have a closed audit trail of your agents' decision trees.
Operational Action Items for Executives
Whether a case falls under product liability or ordinary liability law, the question is always whether you can show what the agent did and why. Organisations deploying AI agents should therefore take three practical steps:
- Build in auditability: Ensure that every agent decision is traceable to a specific prompt, business dataset, or policy rule. This is essential to prove that the agent operated within the given parameters.
- Dynamic risk assessment: Implement governance mechanisms that continuously monitor whether agent actions fall within predefined risk profiles.
- Clear escalation protocols: Determine exactly when an AI agent must stop acting and a human expert must intervene. This prevents an agent from getting stuck in a loop of erroneous decisions.
AI Liability is no longer a theoretical issue; it is an operational design principle for the entire organization. It forces us to build systems that are not just smarter, but above all safer and more transparent.
Want to know how to set up your AI agents to be compliant, responsible, and measurably successful according to the latest guidelines? Explore our AI Services or contact the experts at PrudAI.
Sources:
