When an AI system produces an output that costs someone money, the claim is made against a person, not a model. Liability is decided by the contract chain first and by the ordinary law of negligence and product liability after that. This is where responsibility actually sits, and what to negotiate before deployment.
When an AI system produces an output that costs somebody money, nobody sues the model. The claim is made against a person or a company: the business that deployed the system, the business that supplied it, or the business that built it. Which of those three answers, and for how much, is settled largely before the loss occurs, in documents signed at the point of procurement. The law of negligence and product liability then fills the gaps that the contracts left.
The contract chain decides most of it
The first question in any AI dispute is what the contracts say. There is usually a chain of them: the developer of the underlying model, an intermediate supplier or integrator, the business that deploys the system, and the customer or employee affected by the output.
Contracts for the supply of business AI systems, whether installed or provided as a service, largely follow the pattern of software and data licensing, and the same issues arise. The provisions that decide the outcome are the warranties given about performance and accuracy, the exclusions of liability and the caps on it, the indemnities for third party claims, the allocation of responsibility for the training data and for intellectual property in the output, and the change control provisions.
That last one is specific to this technology and is routinely overlooked. A model that is updated by the supplier without notice is a different system from the one that was tested and accepted. Where a business has assessed a deployment and documented it, silent updates make the assessment untrue. Require notice of material changes, and a right to test before they take effect.
At the consumer end, mass market AI services continue to be supplied on click-accept terms, which means that a business using a consumer product for business purposes has agreed to terms drafted for a different relationship and has almost certainly given away its position on confidentiality, liability and use of its inputs.
Negligence
Where there is no contract between the parties, the claim will be framed in negligence. The questions are the familiar ones: was a duty of care owed, what was the standard of care, was it breached, and did the breach cause the loss.
None of these questions becomes unanswerable because a machine was involved. The common law duty of care has always extended to activities that did not exist when the earlier cases were decided, and there is no reason it stops at software. The interesting question is the standard: where a system performs a task better than a competent human would, the standard expected of the person deploying it may rise, and where the system is known to be unreliable, deploying it without checking the output is itself the breach.
Causation is the harder problem in practice. AI systems are frequently opaque, and a claimant may be unable to explain how the output was reached. That evidential difficulty is the reason legislative reform in this area has focused on the burden of proof.
Product liability, and what became of the reform proposals
Two EU reform proposals were in play when this article was first written, and they ended differently.
The proposed AI Liability Directive, COM(2022) 496, which would have introduced a presumption of causality rebuttable by the defendant, was never adopted. The Commission withdrew it, and the withdrawal was published in the Official Journal on 6 October 2025. There is therefore no separate EU regime of non-contractual liability for AI, and claims of that kind fall back on national law.
Product liability was reformed. Directive (EU) 2024/2853 of 23 October 2024 on liability for defective products entered into force on 8 December 2024, repeals and replaces Directive 85/374/EEC, and carries a transposition deadline of 9 December 2026. It applies to products placed on the market from that date. Two points matter for anyone deploying an AI system. The first is that software is expressly a product for these purposes, including operating systems, applications and AI systems, whatever the mode of supply. The second is that the directive addresses the evidential problem directly, through provisions on disclosure of evidence and through presumptions of defectiveness and of the causal link in defined circumstances.
Cyprus has not transposed it yet. The tables of Cyprus primary legislation for 2025 and 2026 carry no law on liability for defective products, and the deadline is 9 December 2026. Until a transposing Law is published, a claim in Cyprus for damage caused by a defective product is still brought under the regime implementing the 1985 Directive, without the disclosure provisions and without the presumptions. That is a live gap rather than a settled position, and anyone modelling exposure on a deployment that will still be running in 2027 should assume the new regime and not the old one.
The planning assumption follows from that. A business deploying an AI system should proceed on the basis that it may have to explain, after the event, how the system reached a particular result, and that an inability to explain will not help it. That means keeping the version, the inputs, the output and the human decision that followed.
Liability is decided by the contract chain first and by the ordinary law of negligence and product liability after that.
Regulatory exposure sits alongside the civil claim
The Artificial Intelligence Act, Regulation (EU) 2024/1689, is in force and does not displace any of the above. It adds a separate layer of administrative fines, and those fines are owed to the state whether or not anyone has suffered a loss.
Article 99 sets the ceilings. Infringement of the prohibited practices in Article 5 attracts up to EUR 35 000 000 or, if the offender is an undertaking, up to 7 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher. Non-compliance with the operator obligations listed in Article 99(4) attracts up to EUR 15 000 000 or 3 per cent, whichever is higher. Supplying incorrect, incomplete or misleading information to a notified body or a national competent authority attracts up to EUR 7 500 000 or 1 per cent, whichever is higher. Lower ceilings apply to small and medium enterprises and start-ups. A liability cap negotiated with a supplier does not touch any of this.
If you are at this point
The time to allocate this liability is in the contract, before deployment. Tell us about the draft or write to office@kleanthousplatis.com.
Data protection
Where personal data goes into or comes out of a system, the General Data Protection Regulation, Regulation (EU) 2016/679, applies, and it applies to organisations outside the EU that have an establishment within it.
Four questions come up on almost every instruction. Whether the AI supplier is acting as a processor on the deployer's instructions or as a controller in its own right, which is a question of who decides the purposes and means and not of what the contract calls them. Whether data said to be anonymised really is, given what can be inferred from a model's output. Whether there is a lawful basis for the data used to develop or fine-tune the system, which is the live issue where material has been scraped from the web. And whether the deployment involves profiling or automated decision-making producing legal or similarly significant effects, which carries its own restrictions and its own transparency duties.
Resolve the controller and processor question in writing before the contract is signed. It determines who is answerable to the individual, who must respond to access requests, and who bears the cost of a breach.
Smart contracts
Automated, self-executing contracts raise the same threshold questions as any other agreement: capacity, intention to create legal relations, offer, acceptance and certainty of terms. The prevailing view is that established contract principles apply and that such agreements are enforceable where those elements are present.
The practical difficulties lie elsewhere: identifying the parties, dealing with a contract that has executed itself on a state of affairs that turns out to be wrong, and proving the terms and their integrity to a court. Those are addressed in Smart Contracts and Cyprus Property Transactions.
What to send us
The supplier contract and the terms of service, the description of what the system does and what it decides, any assessment or documentation the supplier has provided, and the records held about the output complained of. Where a claim has been intimated, send the correspondence before responding to it.
Technology contracting and data work sits within our corporate and commercial practice, and claims within our litigation and arbitration practice. For the regulatory analysis of the same systems, see The EU Artificial Intelligence Act.
Discuss your own situation with us
Questions we are asked
Who is liable when an AI system produces a costly output?
A person or a company, never the model: the business that deployed the system, the business that supplied it, or the business that built it. Which of the three, and for how much, is settled largely before the loss occurs, in the documents signed at procurement, and the law of negligence and product liability then fills the gaps the contracts left.
Which contract provisions actually decide the outcome?
The warranties given about performance and accuracy, the exclusions of liability and the caps on it, the indemnities for third party claims, the allocation of responsibility for the training data and for intellectual property in the output, and the change control provisions.
Why does change control matter so much here?
Because it is specific to this technology and routinely overlooked. A model updated by the supplier without notice is a different system from the one that was tested and accepted, and where a business has assessed a deployment and documented it, silent updates make the assessment untrue. Require notice of material changes and a right to test before they take effect.
We use a consumer AI product for business work. Does that matter?
It does. Mass market AI services continue to be supplied on click-accept terms, so a business using a consumer product for business purposes has agreed to terms it did not negotiate, in a context where the exposure is the business's own.
Related Reading
This article is for general information only and does not constitute legal advice. Laws and their application can change, and individual circumstances differ. For advice on your own matter, contact Klitos Platis at klitos@kleanthousplatis.com or telephone +357 22 680 330.

Klitos Platis
Advocate, Partner
Kleanthous & Platis LLC, Nicosia · Revised 4 August 2026
Need advice on your own matter?
Briefly describe your situation, the people involved and any deadline.
We reply within one business day. We will ask for documents once we confirm we can act.
Receive legal updates by email
When Cyprus law changes, hear it from us
One short email when something changes that matters: new legislation, a decision worth knowing, a deadline. Written by the partners, no marketing, unsubscribe with one click.
You are on the list. The next update on Cyprus law will reach your inbox.
That did not go through. Please write to office@kleanthousplatis.com and we will add you.
Your address is used for these updates and nothing else. Privacy notice.