Three European instruments look like they answer the question of who pays when a business AI agent causes damage. On inspection, the AI Act awards no compensation to anyone, the revised Product Liability Directive covers damage suffered by natural persons and excludes property used exclusively for professional purposes, and the AI Liability Directive that was drafted to cover the remainder was withdrawn in October 2025. For a business whose agent harms a client, that leaves national fault-based law and the contract. Knowing which of the three applies to your situation changes what you negotiate before you grant an agent authority.

The question "who is liable when AI makes a mistake" returns a large amount of published debate about whether a machine can hold legal responsibility. Almost none of it tells a European business what happens to them when the agent they deployed sends the wrong invoice, books the wrong slot, or tells a client something untrue.

This page answers the narrower and more useful version. Three European instruments govern the territory. Each one stops somewhere different, and the gaps between them are where a business actually sits.

This is not legal advice. Every claim below carries its article or recital number so you can check it against the source, and the sources are listed at the end. The position is moving, and where it is genuinely unsettled this page says so rather than resolving it for you.

Does the EU AI Act compensate anyone harmed by an AI agent?

No. The AI Act is a regulatory instrument. It sets obligations and it authorises penalties, and the penalties are paid to the state.

Article 85 gives "any natural or legal person" who suspects an infringement the right to complain to a market surveillance authority.[¹] That is a right to have the authority look. It is not a right to be paid. The article creates no entitlement to compensation, restitution, or damages.

This distinction gets lost constantly, and it matters commercially. If your agent breaches an AI Act obligation and a regulator fines you, that fine does not compensate the client who was harmed. Your client's claim against you is a separate matter, running on a separate track, under different law. You can face both at once.

A regulatory fine punishes you. It does not pay the person your agent harmed. Those are two different exposures, and settling one does not settle the other.

The EU AI Act deployer guide covers what the Act does require: which role you hold, which transparency duties attach, and what the intake looks like.

Does the Product Liability Directive cover AI systems?

Yes, and this is the genuine change. Directive (EU) 2024/2853 replaced the 1985 product liability regime and expanded the definition of a product. Article 4, point (1) expressly includes software, which brings AI systems inside a strict liability regime for the first time.[²]

Strict liability is a meaningful shift. An injured person does not have to prove anyone was careless. They prove three things: the product was defective, they suffered damage, and the defect caused it.

The Directive applies from 9 December 2026, to products placed on the market or put into service after that date.[²] Products already in service before then stay under the old regime.

Then come the limits, and for a business they are severe.

Can a company claim under the Product Liability Directive?

No. Article 5(1) is explicit. Member States must ensure that "any natural person who suffers damage caused by a defective product" is entitled to compensation.[²] The Directive calls that person the "injured person". Your company is a legal person. It cannot bring a claim under this Directive for its own losses. Your customer, as a natural person, can.

The heads of damage in Article 6(1) narrow it further:[²]

CoveredNot covered
Death and personal injury, including medically recognised psychological harmDamage to property used exclusively for professional purposes (Art. 6(1)(b)(iii))
Damage to property used for private or mixed purposesDestruction or corruption of data used for professional purposes
Destruction or corruption of data not used for professional purposesPure economic loss, privacy infringement, discrimination (Recital 24)

Read the middle row carefully, because the wording is more forgiving than the summaries suggest. Property used for mixed purposes is covered. Only property used exclusively for professional purposes falls outside. A laptop that runs the business and also the household is not automatically outside the Directive.

Recital 24 is the one that closes the door on most business claims. It excludes pure economic loss from the Directive's perimeter entirely, alongside privacy infringements and discrimination. Compensation for those under other regimes, notably the GDPR, remains available and unaffected.[²]

Pure economic loss is precisely what a misfiring business agent produces. A wrong invoice, a missed deadline, a booking that cost you a client. No injury, no damaged property, just money. The Directive does not reach it.

One asymmetry cuts the other way. Article 5 also says that liability under the Directive cannot be limited or excluded by contract, or by national law, as against the injured person.[²] So where the Directive applies, a supplier cannot contract its way out. That protection runs to the injured natural person. It does not run to your business.

The instrument that finally made software a product is written for the person your agent harms, not for the business that deployed it.
Two panels: a natural person who can claim under the Product Liability Directive for death, injury and private-use property, and a company that cannot claim for pure economic loss or professional-use property.
Article 5(1) entitles natural persons. Recital 24 excludes pure economic loss, which is what a business actually suffers.

Who is liable under the Directive, and is it the business running the agent?

The Directive points liability at a cascade of economic operators.[³][⁴] The list runs: manufacturers of a finished product or component. Anyone who substantially modifies a product after it goes on the market. Importers and authorised representatives, where the manufacturer sits outside the EU. Fulfilment service providers. And in defined circumstances, distributors and online platforms.

A business that buys an agent product and configures it for its own workflow is not named in that cascade. The role the Directive contemplates for you is closer to the injured party than the liable one.

One caveat worth taking seriously: the cascade includes those who substantially modify a product. Where heavy customisation shades into substantial modification is not settled, and it is exactly the sort of question that gets decided case by case once claims start arriving. Treat "we only configured it" as a position that may need defending rather than a certainty.

What happened to the AI Liability Directive?

The AI Liability Directive was withdrawn. This is the part most summaries omit, and it is the reason the picture has a hole in it.

The European Commission proposed the AI Liability Directive on 28 September 2022, specifically to address fault-based claims involving AI, including the evidential difficulty of proving how an opaque system caused harm. The European Parliament's Legislative Train now records its status as Withdrawn.[⁵] The Commission listed it in its 2025 work programme. The formal withdrawal appeared in the Official Journal as C/2025/5423 on 6 October 2025.

The Commission reserved the right to assess whether to table another proposal or take a different approach. Nothing has replaced it.

The consequence is direct. The instrument designed to help a claimant prove fault in an AI case, and to ease the evidential burden that makes those cases hard to run, does not exist. Claims fall back on national law that was not written with autonomous systems in mind.

Is the Product Liability Directive actually in force across Europe yet?

Mostly not, and this is a live problem rather than a technicality.

A member state progress report dated 24 June 2026 found that Hungary had fully transposed the Directive, with legislation adopted on 16 December 2025. Germany published a draft bill in September 2025 and revised it in December 2025, aiming for a close one-to-one transposition. The Netherlands published a draft implementation bill in April 2025 and retained the development risk defence. Ireland was still drafting as of May 2026 while stating an intent to meet the deadline.[⁶]

Thirteen member states had made no significant progress: Belgium, Bulgaria, Cyprus, Estonia, France, Greece, Latvia, Lithuania, Luxembourg, Malta, Poland, Slovenia and Spain. The deadline was six months out. The report's authors thought several would miss it.[⁶]

Two things follow. First, the answer to "what does the law say" currently depends on which country you are in, and in most of them the answer is still the old regime. Second, divergences are already appearing in the drafts, particularly on the development risk defence and on burden-of-proof standards. A single European answer is not going to exist even after transposition.

Bar chart of EU member state transposition status as at 24 June 2026: one state fully transposed, three drafting, thirteen with no significant progress.
One member state had fully transposed the Directive by June 2026. Thirteen had made no significant progress.

So what actually governs when your agent harms a client?

Put the three together. The AI Act does not compensate. The Product Liability Directive is built for natural persons and excludes pure economic loss. The directive written to cover the remainder was withdrawn.

What is left is national fault-based liability and the contract you signed. That conclusion is an inference from where the instruments stop rather than a quoted rule, and it is worth stating as such. No European instrument says "and the rest is contract." The rest is contract because nothing else reaches it.

Three horizontal bars of decreasing reach representing the AI Act, the revised Product Liability Directive and the withdrawn AI Liability Directive, each stopping short of the right edge, above a full-width orange-outlined bar representing national fault-based law and contract.
Each European instrument stops somewhere different. National law and the contract are what runs the whole width.

That is not a bad outcome for a business that reads its contracts. It is a very bad one for a business that has not.

Practically, three documents decide your exposure long before any court does:

  1. Your provider's terms. Look for the liability cap, what it is a multiple of, and what it excludes. Most AI provider terms cap liability at fees paid over some recent window, which for a small deployment is close to nothing. Check whether indemnities cover third-party claims from your clients.
  2. Your own client contracts. If your agent touches client work, your liability to that client is governed by what you agreed with them, not by what your provider agreed with you. A gap between the two is a gap you fund.
  3. Your insurance. Will a professional indemnity policy respond to damage caused by an agent your firm deployed? Put that to your broker in writing, before you need the answer. Policies written before agents were common may not address them either way. An ambiguous policy gets discovered at the worst possible moment.

None of these three is a legal question in the first instance. They are documents you already hold, and reading them is free.

Which controls actually reduce the exposure?

The legal position is largely outside your control. What the agent is permitted to do is entirely inside it, and that is the part that determines how large a claim can get.

An agent that drafts and waits for approval cannot send the wrong thing to a client. An agent that can read but not write cannot delete a record. An agent scoped to one mailbox cannot reach the finance system. These are configuration decisions made before go-live, and they set the ceiling on what any single failure can cost.

Three specifics do most of the work:

  • Approval gates on outbound and irreversible actions. Enforced in the system rather than requested in a prompt. What approval workflows do in an AI agent system covers the mechanism.
  • Scoped access. The agent reaches the accounts and records the workflow needs and nothing else. What an AI agent can access covers how permissions are actually set.
  • An audit log. When something goes wrong, you need to show what the agent did, when, and on whose authority. That is the difference between a contained incident and an unprovable mess.

For the data protection side of the same question, which runs on GDPR rather than liability law, GDPR for AI agents covers controller and processor roles. For what to do in the hours after a failure, what to do when your AI agent makes a mistake covers containment and recovery.

What this page cannot tell you

This page cannot tell you whether you are liable in a specific situation. That depends on your jurisdiction, your contracts, the facts of what happened, and in most of Europe on transposition legislation that is not final. Ask a qualified lawyer in your own country.

It also cannot predict the position in two years. The Commission may table a successor to the withdrawn directive. Member states are still transposing, and diverging as they do. Every claim on this page carries a retrieval date for that reason.

What it can tell you is where to look, which questions to put to your provider and your insurer, and that the instrument most people assume protects them is written for someone else.

Frequently asked questions

Does the EU AI Act make my business pay compensation if my AI agent harms a customer?

No. The AI Act is regulatory. Article 85 lets any person complain to a market surveillance authority about an infringement, and authorities can impose penalties, but those penalties are paid to the state rather than to the person harmed. A customer seeking compensation from you would bring a separate claim under national contract or fault-based liability law. Both can happen at the same time over the same incident.

Can my company sue an AI vendor under the EU Product Liability Directive?

Not for your own business losses. Directive (EU) 2024/2853 covers damage suffered by natural persons under Article 1(1), and Recital 24 excludes pure economic loss from its scope entirely. A company cannot use it to recover money lost because a defective AI system caused a business failure. Claims for that fall under contract or national fault-based liability instead.

When does the new EU Product Liability Directive apply to AI systems?

From 9 December 2026, for products placed on the market or put into service after that date. As of a member state progress report dated 24 June 2026, only Hungary had fully transposed it, and thirteen member states had made no significant progress. The regime that applies to you therefore depends on your country's transposition status as well as on the date.

Is a business liable for what its AI agent does, or is the software vendor?

The Product Liability Directive points at manufacturers, importers, authorised representatives and distributors, not at businesses that deploy a system for their own use. That does not make a deploying business safe. Its liability to its own clients runs under contract and national fault-based law, which the Directive does not displace. A business that substantially modifies a product may also enter the Directive's liability cascade.

Notes

  1. European Parliament, Article 85 of the AI Act: Right to lodge a complaint with a market surveillance authority, accessed September 3, 2026. Used for the wording of Article 85 and the absence of a compensation entitlement.
  2. Directive (EU) 2024/2853 on liability for defective products, article and recital references, accessed September 3, 2026. Used for Article 1(1) natural persons, Article 4 point (1) software as product, Article 6(1) heads of damage, Recital 24 exclusions, and the 9 December 2026 application date.
  3. Gibson Dunn, EU Product Liability Directive: Responding to Software, AI and Complex Supply Chains, accessed September 3, 2026. Used for the liable economic operators and the professional property exclusion.
  4. Cleary Gottlieb, The New EU Product Liability Reform: Addressing the Digital Age, accessed September 3, 2026. Used for the Article 8 cascade of liable operators and the application date.
  5. European Parliament Legislative Train Schedule, AI liability directive, accessed September 3, 2026. Used for the proposal date of 28 September 2022, the withdrawn status, and Official Journal reference C/2025/5423 of 6 October 2025.
  6. Faegre Drinker, Transposing the EU's New Product Liability Directive: A Member State Progress Report, dated June 24, 2026, accessed September 3, 2026. Used for the transposition status of Hungary, Germany, the Netherlands and Ireland, and the thirteen member states with no significant progress.
  7. A&L Goodbody, EU revised Product Liability Directive: What you need to know, accessed September 3, 2026. Used for the wording of the professional property and professional data exclusions.