Can an AI be responsible? The legal edifice has structural cracks

In this article

  1. The classic structure
  2. The AI doesn't fit
  3. The case of the compelled user
  4. The withdrawn proposal
  5. The strict-liability response of the maker
  6. The edifice with cracks
  7. The harm without redress
  8. The political asymmetry
  9. The discussion that doesn't arrive
  10. The new construction

Definitions · References · Going deeper · You may also like · Elsewhere

Classic legal responsibility, in both the continental and the common-law traditions, requires an intentional agent. The central categories —intent, fault, negligence, imputation, capacity for guilt— have been built over centuries on the assumption that the actor of the harm is a person with the capacity to will and to understand. AI is not. It's not a person, it's not intentional, it's not culpable in the legal sense. But the harms it produces are operationally real: contracts signed with invented clauses, mistaken medical diagnoses with clinical decisions taken, credit decisions that systematically discriminate, administrative scoring that denies benefits to those who should receive them. The most-used exit as of 2026 is to attribute responsibility to the human who used it —a legally operative and sometimes just solution, but one that caves in the moment the AI acts by delegation from the administration or the employer. The legal edifice has structural cracks. And it still hasn't moved.

The classic structure

Legal responsibility rests on three elements: an identifiable agent, attributable conduct, harm caused. When the three concur with a causal link, there's responsibility. The details vary between civil law and common law, between civil and criminal law, between objective and subjective regimes, but the general skeleton holds.

  • Agent: a natural or legal person with the capacity to act.
  • Conduct: a voluntary act or omission.
  • Subjective attribution: intent, fault, negligence. Requires intentionality or a lack of due care.
  • Harm: injury to an interest protected by law.
  • Causal nexus: a link between conduct and harm.

In civil law there are special regimes that partially dispense with some elements: strict liability (without fault, for created risk), vicarious liability (the employer answers for the subordinate), liability for a defective product. But even these regimes presuppose a human or legal agent at some point in the chain. No classic regime contemplates the non-human technical system as an agent.

The AI doesn't fit

What an AI system does —processing inputs, generating outputs, executing chained actions, interacting with external systems— is not conduct in the legal sense. There's no will. There's no intention. There's no capacity to will and to understand. Classic legal doctrine simply doesn't admit the AI system as a subject of imputation.

This meant, until recently, that liability for AI harms was redirected to the human or human entity behind the system:

  • The maker of the model, for a design defect.
  • The integrator, for improper use in its product.
  • The service provider, for configuration or deployment.
  • The end user, for improper or negligent use.

The chain works in clean cases. It fails when the chain becomes hard to trace or when none of the nodes has effective control over the system's concrete behavior at the moment of the harm.

The case of the compelled user

The case that breaks the most-used solution —offloading onto the user— is that of the compelled user. The doctor the hospital requires to use the biased system. The civil servant who applies algorithmic scoring whose internal challenge is penalized. The duty-roster legal-aid lawyer whose workload is only viable with an assistant. The teacher who grades with a system the school administration demands.

In these cases, transferring the responsibility to the individual user is legally operative but materially unjust. The user didn't really "choose"; he followed an instruction. The substantive responsibility lies with whoever imposed the use. But the classic legal regime has no adequate category for specifically imputing to whoever organized the system.

Administrative and labor law have partial tools —employer liability, administrative liability for the malfunction of a public service. But these tools were designed for cases where the operative agent was human. Their application to AI systems managed by an administration or a company works with friction.

The withdrawn proposal

The European Parliament Resolution of February 16, 2017 on civil-law rules on robotics (P8_TA(2017)0092) proposed exploring the creation of "electronic personhood" for autonomous systems: granting them limited legal capacity, with their own assets able to answer for harms. The proposal was intensely debated and, finally, withdrawn in later revisions. The reasons for the rejection:

  • Risk of shielding: if the AI is responsible, the maker and the integrator could hide behind it, escaping substantive liability.
  • Lack of conceptual foundation: classic legal personhood (for companies, foundations) is based on collective human interests behind the entity. AI has no identifiable collective human interests behind it.
  • Risk of diluting human rights: partially equating AI with a person conceptually endangers the category of person.
  • Operational unnecessity: AI harms can, in principle, be redirected to human responsible parties without needing to create a new legal category.

The withdrawal of the proposal left the matter where it was: classic law applied with friction to new phenomena.

The strict-liability response of the maker

The most viable alternative, as of 2026, is strict liability of the maker or the integrator. Directive (EU) 2024/2853 on liability for defective products, in force since December 2024 and with transposition underway, goes in this direction. It explicitly includes software and AI. It provides presumptions of causality and a reversed burden of proof to ease things for the claimant.

The doctrine of strict liability has advantages:

  • It doesn't require proving intention or fault, only defect and harm.
  • It internalizes the cost of the harm in whoever has the capacity to design better.
  • It generates the right incentive: the maker invests in safety because it'll pay if it fails.
  • It's operative in complex systems where the chain of causality is hard to trace.

Its limits:

  • It doesn't resolve the compelled-user case: the maker answers, but whoever imposed the use (administration, employer) may not.
  • It doesn't resolve the case of systems with unforeseeable multiple uses: the maker built a general model; the concrete harm derives from a specific vertical use.
  • It doesn't resolve the case of the chain of integrators: maker A's base model is integrated into product B by maker B and used in flow C by organization C. Who is "the maker" responsible?
  • Its practical application requires significant evidentiary capacity, asymmetric between an individual claimant and a corporate defendant.

The 2024 Directive improves on the previous regime but leaves substantive cases without clear resolution.

The edifice with cracks

There are three structural cracks in the current legal edifice worth naming.

Crack 1: absence of an intermediate category. Current law offers two categories for agents: natural person or legal person. Both require a human substrate. There's no category for an autonomous technical system that acts in the world with consequences. The absence of an intermediate category forces the attribution onto humans whose connection with the concrete harm is remote.

Crack 2: insufficiency of the doctrine of delegation. When the administration or the employer delegates a function to an AI system, the classic legal doctrine of delegation —the principal answers for the agent— works with friction. The AI system isn't an agent in the legal sense; the principal answers, but the tools for pinning down exactly what it answers for and how aren't well honed.

Crack 3: technical opacity as an evidentiary obstacle. For liability to operate, the defect has to be proved. In opaque AI systems —black boxes, models with billions of parameters— proving the specific technical defect is operationally difficult. The 2024 Directive introduces presumptions to ease this, but the evidentiary asymmetry between claimant and defendant remains.

The three cracks reinforce one another. When they concur —the case of compelled use of an opaque system with a complex chain of integrators— liability operationally disappears.

The harm without redress

The material consequence is that many AI harms go without effective redress, not because the law explicitly allows it, but because the chain of imputation doesn't close within a timeframe and a cost reasonable for the claimant. Typical cases:

  • An unjustly denied credit decision: the affected party can appeal administratively with uneven success; he rarely obtains compensation proportional to the harm.
  • A wrong medical diagnosis with a material consequence: the medical-liability regime still applies; the AI component of the error is rarely addressed specifically.
  • An administrative sanction based on biased scoring: the challenge usually focuses on individual facts; the underlying system is rarely questioned.
  • Loss of a job opportunity through algorithmic filtering of applications: the evidentiary difficulty is sky-high; successful cases are few.

The harm exists; the redress doesn't arrive. The asymmetry between operational reality and legal response is structural and doesn't close with current regulation.

The political asymmetry

Why doesn't the response speed up? The reasons are the usual ones in regulatory innovation on AI:

  • Political asymmetry between actors. Makers and large integrators have significant political mobilization capacity. Harmed individuals don't.
  • Informational asymmetry. Technical complexity favors the actor with the resources to handle it, to the detriment of regulator and claimant.
  • Speed of change. The regulation designed today addresses the products of two years ago. By the time it's applied, the ecosystem has already mutated.
  • Jurisdictional heterogeneity. Each country has its own framework. Global actors operate in jurisdictional arbitrage; individuals can't.

This is personal opinion, but documentable: the combination produces an equilibrium where responsibility without intention is discussed academically with sophistication, debated politically with less intensity and applied in practice with modest results. The asymmetry favors whoever produces the systems and disfavors whoever receives the harms.

The discussion that doesn't arrive

The fundamental options the legal debate could seriously raise:

1. Recognize a new legal category for autonomous systems, with limited rights and obligations, against the risk of shielding the maker. 2. Reinforce the strict liability of the integrator with stronger presumptions and a significant reversed burden of proof. 3. Establish joint and several liability of the whole chain (maker, integrator, operator, user) with an internal apportionment regime among them but a single external liability. 4. Create public or private compensation funds for cases where the chain of responsibility doesn't close, financed by a contribution from the AI industry. 5. Establish mandatory auditing of critical systems with a regime comparable to financial auditing, to ease proof in case of harm.

The five options are discussed in academic publications and in regulatory proposals. Their effective implementation in national regimes is modest. The political discussion, in most jurisdictions, is still in an exploratory phase.

The new construction

The current legal edifice was built during the nineteenth century and consolidated in the twentieth to respond to harms produced by identifiable human agents. Applying it to AI systems without reconstruction means forcing categories that don't fit. The choice is between forcing the existing categories —with growing cracks— or building new ones —with significant political and conceptual cost.

The two options have supporters. Those who prefer to force the existing ones argue continuity, stability and lower costs. Those who prefer to build new ones argue that without an adequate framework, reality will end up overflowing the law in a less orderly way. Both arguments have merit; the balance will depend on how the magnitude of unredressed harm evolves over the coming years.

Definitions

  • Imputation: the legal attribution of a conduct or a result to an agent, a condition for responsibility.
  • Intent / fault: two forms of subjective attribution in law. The first implies intention to cause harm; the second, a lack of due care.
  • Strict liability: a regime in which the agent answers for the harm without needing to prove intent or fault. Applied in defective-product law and in some other areas.
  • Vicarious liability: a regime in which the principal answers for the conduct of his subordinate. Applied in labor and administrative law.
  • Electronic personhood: a withdrawn proposal of the European Parliament (2017) to grant limited legal capacity to autonomous systems.
  • Reversed burden of proof: a procedural technique that shifts to the defendant the obligation to prove the nonexistence of the defect, instead of requiring the claimant to prove its existence.
  • EU AI Act: Regulation (EU) 2024/1689. The European regulatory framework for AI based on risk levels.
  • Product Liability Directive 2024/2853: the updated European directive that includes software and AI in the concept of a defective product.

References

  • European Parliament. Resolution of February 16, 2017 on civil-law rules on robotics, P8_TA(2017)0092. Provisions on electronic personhood withdrawn in later revisions.
  • Directive (EU) 2024/2853 on liability for defective products.
  • Regulation (EU) 2024/1689 (EU AI Act).
  • Pasquale, F. New Laws of Robotics: Defending Human Expertise in the Age of AI. Belknap Press, 2020.
  • Crootof, R. "A Meaningful Floor for Meaningful Human Control." Temple International & Comparative Law Journal 30, 2016.
  • Selbst, A. D. "Negligence and AI's Human Users." Boston University Law Review 100, 2020.
  • Kaminski, M. E. "Regulating the Risks of AI." Boston University Law Review 103, 2023.
  • Hartzog, W. Privacy's Blueprint. Harvard University Press, 2018.

Going deeper

  • Frank Pasquale & Glyn Cashwell. "Four Futures of Legal Automation." UCLA Law Review Discourse 63, 2015. A framework distinguishing four possible scenarios for legal automation with different implications for liability; useful for anticipating regulatory trajectories.
  • Madeleine Clare Elish. "Moral Crumple Zones: Cautionary Tales in Human-Robot Interaction." Engaging Science, Technology, and Society 5, 2019. A concept on how in socio-technical systems the human functions as a moral crumple zone; applicable directly to imputation onto the compelled user.
  • Mireille Hildebrandt. Smart Technologies and the End(s) of Law. Edward Elgar, 2015. A philosophical-legal analysis of how smart technologies reorganize the assumptions of modern law; needed to understand the underlying question beyond the regulatory patches.

You may also like

Elsewhere

Comments0

No comments yet.

Leave a comment