In this article
Responsibility exists because someone can pay. A fine, prison, a ruined reputation. A machine pays none of the three, so the chain of blame always hangs from a human. I used to think the problem was finding that human. Then I understood the problem is another. Sometimes there isn't one, and then responsibility doesn't transfer: it falls to the floor and stays there, under the citizen the harm happened to land on.
Why responsibility needs someone with something to lose
I started getting interested in this from the suspicion that the word "responsibility" gets used far too loosely whenever an AI is involved. Worth taking it apart.
Legal responsibility isn't a moral judgement. It's a mechanism of attribution that only works if there's a subject who can be harmed in a controlled way: stripped of money, freedom, prestige, licence. That's the lever. Without someone who perceives the loss and adjusts his conduct accordingly, the mechanism spins in a vacuum.
H.L.A. Hart took the machinery apart in Punishment and Responsibility (1968) and his analysis still serves. For someone to answer, four things are needed at once. That he had real alternatives, not a single exit disguised as a decision. That he could have foreseen what would happen, because charging someone with unforeseeable consequences empties the very idea of fault. That he be a subject capable of bearing the charge, a natural or legal person. And that the sanction bite: a fine only squeezes whoever has assets, prison whoever has freedom to lose, disgrace whoever has a position to defend.
Run an AI through the four filters. It doesn't choose in any sense that matters morally. It doesn't know the consequences, it calculates them. It isn't a person before a court. And there's no way to punish it: turn it off? fine the model? Classical responsibility simply has nowhere to grip in the technical system.
From which comes the question that runs through everything else. If the machine can't answer, someone in the human chain has to. The question isn't whether, but who.
The chain, and where it breaks
User, operator, manufacturer, state. That's the usual chain, and each link can carry a share of the blame. AI doesn't break it. It tangles it.
The user answers when he chose to use the system and chose how: negligent use, harm caused by an instrument he controlled. The operator answers when a third party deployed the system between manufacturer and end user and configured it badly, maintained it badly or set defective protocols. The manufacturer answers when the product is defective from the factory: in the United States the doctrine comes from the Restatement (Second) of Torts §402A (1965); in the European Union, from Directive 85/374/EEC, updated by Directive (EU) 2024/2853. And the state answers when it imposed the system by rule, or when the harm can no longer be charged to any of the prior private parties. In Spain that figure is the patrimonial liability of the administration, regulated in Law 40/2015.
So far, nothing new. The novelty is that AI strains each of those couplings until it deforms them.
The model's opacity makes it hard to point at the manufacturer: proving that a specific defect caused the specific harm, when not even the engineers themselves know why the system decided what it decided, is nearly impossible. The system's apparent autonomy makes it hard to point at the user: if the machine decided, what was he controlling? And the number of hands the product passes through between manufacturer and user dilutes the operator until nobody in particular is to blame for anything.
The chain is still there, formally intact. What fails is effective attribution, and that no longer gets fixed with the old doctrine. New doctrine has to be built, and it's being built at very different speeds depending on the country.
When the harm belongs to no one
The case that obsesses me is forced use. The administration obliges you to go through an AI, the AI fails, and then you ask who answers and discover the question has no comfortable answer.
It isn't a laboratory scenario. The medical appointment you can only book through an online system with automated triage. The tax return prepared by the official system's own assistant. The school assessment run through a ministry tool. The benefit application whose processing already comes assisted and which you can't opt out of. They all share the same architecture: the citizen must use the system, because the in-person counter either has disappeared or costs so much time and so many detours that in practice it doesn't exist.
Something fails. An unjust denial, a wrong calculation, a biased decision. And you try to walk the chain.
The user didn't choose to use the system, so his liability for negligent use is an argument that collapses on its own: there's no negligence in use when the use was imposed. The operator, usually the manufacturer under a public contract, followed the specifications the administration gave it, and its liability is bounded by the contract and by the technical diligence reasonably expected of it. The administration shelters behind the rule it itself issued: patrimonial liability requires proving an unlawful harm the citizen has no legal duty to bear, and it turns out the rule that imposed the system is precisely the one that articulates that duty. The circle closes on itself.
No link holds the blame. It falls to the floor. And there it stays, while the citizen absorbs the harm with no redress.
There's a precedent worth keeping in mind so as not to believe this is wholly unprecedented: harm caused by mandatory public services—healthcare, education, defence. Mechanisms of state liability exist for those cases. They're slow, calibrated with extreme caution and very hard for a lone citizen to activate. Extending that regime to harm caused by a forced-use AI is doctrinal work still pending almost everywhere.
How the regulatory map looks in 2026
Here you have to tread carefully, because the dates matter and the press mixed them up.
The European Commission announced its intention to withdraw the proposed AI Liability Directive in its 2025 work programme, made public on 11 February 2025, citing "no foreseeable agreement" between the member states and the Parliament. The withdrawal was formally decided at the College of Commissioners meeting of 16 July 2025, and the corresponding notice was published in the Official Journal of the European Union on 6 October 2025. Euronews reported the confirmation in late July 2025; IAPP covered the October publication. I tell it with this much detail because the difference between "announcing," "deciding" and "publishing" isn't pedantry: it marks a process that ran most of a year.
What fell with that directive was no small thing. It would have set up a specific regime of liability for AI harm, with evidentiary presumptions in the claimant's favour and avenues to access the technical information manufacturers keep today. Without it, what's left is a mosaic.
Regulation (EU) 2024/1689, the AI Act, imposes obligations on providers and operators of high-risk systems and provides for administrative sanctions, but doesn't create a civil regime of liability for harm: it punishes non-compliance, it doesn't redress the harmed. Directive (EU) 2024/2853, on defective products, updates the 1985 one and at last includes software as a product, with strict liability for the manufacturer, but it still requires the claimant to prove the defect and the causal nexus. And underneath, the national civil-liability regimes applying classical doctrine case by case, with a diversity that turns the outcome into a lottery by jurisdiction.
The United States operates with no unified federal doctrine: court by court, state by state. Some have legislated on their own. Colorado passed its AI consumer-protection law (SB24-205) on 17 May 2024, though its entry into force has kept being delayed and rewritten. California regulates by sector. And Illinois has spent years applying its biometric-privacy law, BIPA, with already abundant case law.
The European citizen harmed by a forced-use AI moves, in 2026, through a grey zone: a fragmented regime, evidentiary presumptions that don't favour him, and a procedural burden few can afford to carry alone.
Four gaps, and the suspicion that some are convenient
That the subject to charge is missing isn't an accident of the current regime. It's a property of the situation. Filippo Santoni de Sio and Giulio Mecacci ordered it in Four Responsibility Gaps with Artificial Intelligence (Philosophy & Technology, 2021), and distinguishing the four gaps helps you not talk about one when you're suffering another.
There's the culpability gap: the system acted, but nobody specifically chose that action, so there's no one to attribute it to in the classical sense. There's the moral accountability gap: even if there were someone, technical opacity makes it impossible to reconstruct the process and require him to explain why it was decided this way. There's the public accountability gap: the provider hides behind trade secret and the administration behind technical complexity, and nobody has to answer to the public. And there's the active responsibility gap, the one that unsettles me most: nobody takes on the duty of preventing the harm before it happens, because preventive diligence is split among so many hands that it evaporates.
In real cases all four usually appear at once, overlapping.
And then there's Michael Da Silva, who in Responsibility Gaps (Philosophy Compass, 2024) turns the complaint around. The gap, he suggests, can also be a virtue, not just a defect. The absence of a clear culprit brakes the impulse to escalate control over human conduct and to over-criminalise. It's a minority position, and I bring it here precisely because it's uncomfortable: not every gap calls to be plugged in a hurry. Plugging it badly also does harm.
The political part, which is mine
What follows is opinion, though the legal theory of responsibility sustains it with fair coherence. AI is opening attribution gaps because of how it's built, not because anyone is evil. And an attribution gap is, first of all, an opportunity for abuse: where nobody answers, someone does as he pleases. Closing those gaps demands new legal design. Good intentions fill nothing.
I'll point to three directions, without claiming they're the solution, just to leave the debate somewhere concrete.
A regime of its own for forced use, where the state's patrimonial liability operates with presumptions in the citizen's favour when it's the administration imposing the machine; that's legislative work not yet done. A reversal of the burden of proof when the system is so opaque the harmed party can prove nothing, shifting that burden toward whoever does have access to the technical innards, something Directive (EU) 2024/2853 already sketches for defective products. And joint-and-several liability of the whole chain, redressing the citizen immediately and leaving the internal apportionment of blame for later, among the actors: theoretically inefficient, practically the only thing that arrives on time.
In the meantime, what's verifiable is this. The Commission withdrew the AI Liability Directive in 2025, and the European regime was left split among an AI Act that sanctions but doesn't redress, a products directive that redresses but demands the weak prove the impossible, and twenty-seven national laws each applying its own criterion. The gaps Santoni de Sio and Mecacci described in 2021 haven't closed; they distribute the harm downward, onto citizens, and leave prevention in the hands of a collective or regulatory action that always lags behind deployment. The doctrine will come, probably by accumulation of rulings over the next decade. The interval until then is the problem. During that interval, in a proportion of cases that isn't small, the blame will keep falling to the floor, and underneath there will keep being someone.
Definitions
Responsibility gap: rupture in the classical chain of attribution when an AI intervenes, such that the harm can't be charged to any human or legal subject in the usual way. Santoni de Sio and Mecacci (2021) break it down into four: culpability, moral accountability, public accountability and active responsibility.
Forced use: situation in which the citizen must use an AI system because the alternative doesn't exist or carries a prohibitive cost, usually because an administration imposes it by rule.
Patrimonial liability of the administration: legal figure obliging the state to redress harm caused by the normal or abnormal functioning of public services. In Spain it's regulated by Law 40/2015. It's slow and applied with conservative criteria.
AI Liability Directive (AILD): European legislative proposal, put forward in 2022, to create a specific regime of civil liability for AI harm. The European Commission announced its withdrawal in February 2025 and formalised it that same year.
References
Hart, H. L. A. — Punishment and Responsibility (Oxford University Press, 1968). Source of the analysis of the four elements of legal responsibility.
Santoni de Sio, F. & Mecacci, G. — Four Responsibility Gaps with Artificial Intelligence: Why they Matter and How to Address them. Philosophy & Technology, 34(4), 2021, pp. 1057-1084. DOI 10.1007/s13347-021-00450-x. Taxonomy of the four responsibility gaps.
Da Silva, M. — Responsibility Gaps. Philosophy Compass, 2024. DOI 10.1111/phc3.70002. View according to which the gap can be a virtue as well as a defect.
European Commission — Withdrawal of the proposed AI Liability Directive: announced in the 2025 work programme (11 February 2025), decided at the College of Commissioners meeting of 16 July 2025 and published in the Official Journal of the European Union on 6 October 2025. Coverage in Euronews (31 July 2025) and IAPP.
Regulation (EU) 2024/1689 — Artificial Intelligence Regulation (AI Act). Obligations and administrative sanctions for high-risk systems.
Directive (EU) 2024/2853 — Liability for damage caused by defective products. Updates Directive 85/374/EEC and includes software as a product.
Colorado SB24-205 — Consumer Protections for Artificial Intelligence Act. Signed on 17 May 2024; entry into force successively delayed and reformed.
To go deeper
Honoré, T. — Responsibility and Fault (Hart Publishing, 1999).
Pasquale, F. — The Black Box Society (Harvard University Press, 2015), on algorithmic opacity.
Floridi, L. — The Ethics of Information (Oxford University Press, 2013).

Comments0
No comments yet.
Leave a comment