Skip to content
AI Literacy
Lektion 7 von 170/17 abgeschlossen
Datenschutz, Haftung & Governance

Liability & Compliance

HaftungCompliance

🖱️ Interaktiv: Ziehen zum Drehen · Lektion 7

Learning objectives

After this lesson you will be able to:

  • Name the liability risks of using AI in business
  • Document proof of Art. 4 AI literacy
  • Report an AI incident correctly
  • Implement measures to minimize liability

Liability risks of AI use

Who is liable when an AI system causes damage? The answer is complex and depends on the context.

The liability cascade

  1. The employee is liable in cases of intent or gross negligence
  2. The company is liable for its employees (vicarious liability)
  3. Management is liable for organizational failures (missing policies)
  4. The AI provider is liable for product defects (EU AI Liability Directive)

Typical liability cases

ScenarioLiability
Employee enters trade secrets into ChatGPTCompany liable for missing training
AI recommends wrong treatment in healthcareProvider (product liability) + deployer (human oversight)
AI recruiting tool discriminates against applicantsCompany (missing bias test) + provider
Employee uses an unapproved AI toolCompany (missing shadow AI policy)

💡 Increased liability through AI

The EU AI Liability Directive tightens liability for AI damage: reversal of the burden of proof for high-risk AI. When an AI system causes damage, the victim doesn't have to prove the provider was negligent — the provider must prove they were not.

The Art. 4 evidence

Article 4 requires "sufficient AI literacy". How do you prove it?

What the supervisory authority wants to see:

  1. Training evidence per employee:

    • Who was trained?
    • When were they trained?
    • What content was covered?
    • Pass / fail
  2. Training plan:

    • Regular refreshers (recommended: annually)
    • Role-specific deep dives
    • Documentation of updates
  3. Organizational measures:

    • AI policy
    • Named responsible parties (AI officer)
    • Processes for monitoring AI literacy

Our AI literacy training

The training at ki-kompetenz-training.org meets these requirements:

  • Audit-ready certificate with date, content and pass status
  • Team dashboard for HR with an overview of training progress
  • Annual refreshers and updated content

📝 Schnellprüfung

What is the most important requirement for Art. 4 evidence?

Incident reporting

For AI incidents (AI causes damage, data breach via AI, discrimination by AI), structured incident reporting is required.

The reporting cascade

  1. Immediate action: stop the AI system, contain the damage
  2. Internal report: supervisor, data protection officer, AI officer
  3. Documentation: what happened? Which AI system? Which data?
  4. External report: to the supervisory authority if needed (data breach: within 72h)
  5. Inform those affected: in case of GDPR violation: inform the data subjects
  6. Prevention: measures to prevent similar incidents

🏢 Praxis-Szenario: AI incident in customer service

An AI chatbot in your company accidentally reveals one customer's login credentials to another customer. The incident is discovered during an internal review. How do you proceed?

Fines and sanctions

Possible penalties

ViolationMaximum fine
Prohibited AI practices (Art. 5)€35M or 7% of worldwide turnover
High-risk obligations€15M or 3% of worldwide turnover
AI literacy (Art. 4)Up to €15M or 3%
GDPR violation (AI-related)€20M or 4% of worldwide turnover

Aggravating factors

  • Intent vs. negligence
  • Severity of the violation
  • Size of the company
  • Cooperation with authorities
  • Previous violations

Minimizing liability — practical measures

  1. AI literacy training for all employees (Art. 4)
  2. AI policy created and communicated
  3. AI inventory maintained and regularly updated
  4. Human oversight for important AI decisions
  5. Incident response plan for AI incidents
  6. Insurance coverage reviewed (cyber insurance)
  7. Regular audits of AI systems

💡 The AI-compliant company: minimum requirements

  1. ✓ Art. 4 AI literacy training (documented) 2. ✓ AI policy (written, communicated) 3. ✓ AI inventory (all AI systems recorded) 4. ✓ Incident response plan (for AI incidents) 5. ✓ Named responsible parties (AI officer)

✅ Wichtige Erkenntnisse

Haken setzen, um deinen Lernfortschritt zu markieren:

→ Go deeper: AI governance in the enterprise — building an AI policy and governance structure · Data protection & GDPR — GDPR obligations for AI

Weiterführende Inhalte

Haftung & Bußgelder im Guide

Relevante Rechtsgrundlagen: Art. 5 · Art. 15 · Art. 16 · Art. 71

Im Modul "Datenschutz, Haftung & Governance" — weiter lernen