Liability & Compliance
🖱️ Interaktiv: Ziehen zum Drehen · Lektion 7
Learning objectives
After this lesson you will be able to:
- Name the liability risks of using AI in business
- Document proof of Art. 4 AI literacy
- Report an AI incident correctly
- Implement measures to minimize liability
Liability risks of AI use
Who is liable when an AI system causes damage? The answer is complex and depends on the context.
The liability cascade
- The employee is liable in cases of intent or gross negligence
- The company is liable for its employees (vicarious liability)
- Management is liable for organizational failures (missing policies)
- The AI provider is liable for product defects (EU AI Liability Directive)
Typical liability cases
| Scenario | Liability |
|---|---|
| Employee enters trade secrets into ChatGPT | Company liable for missing training |
| AI recommends wrong treatment in healthcare | Provider (product liability) + deployer (human oversight) |
| AI recruiting tool discriminates against applicants | Company (missing bias test) + provider |
| Employee uses an unapproved AI tool | Company (missing shadow AI policy) |
💡 Increased liability through AI
The EU AI Liability Directive tightens liability for AI damage: reversal of the burden of proof for high-risk AI. When an AI system causes damage, the victim doesn't have to prove the provider was negligent — the provider must prove they were not.
The Art. 4 evidence
Article 4 requires "sufficient AI literacy". How do you prove it?
What the supervisory authority wants to see:
-
Training evidence per employee:
- Who was trained?
- When were they trained?
- What content was covered?
- Pass / fail
-
Training plan:
- Regular refreshers (recommended: annually)
- Role-specific deep dives
- Documentation of updates
-
Organizational measures:
- AI policy
- Named responsible parties (AI officer)
- Processes for monitoring AI literacy
Our AI literacy training
The training at ki-kompetenz-training.org meets these requirements:
- Audit-ready certificate with date, content and pass status
- Team dashboard for HR with an overview of training progress
- Annual refreshers and updated content
📝 Schnellprüfung
What is the most important requirement for Art. 4 evidence?
Incident reporting
For AI incidents (AI causes damage, data breach via AI, discrimination by AI), structured incident reporting is required.
The reporting cascade
- Immediate action: stop the AI system, contain the damage
- Internal report: supervisor, data protection officer, AI officer
- Documentation: what happened? Which AI system? Which data?
- External report: to the supervisory authority if needed (data breach: within 72h)
- Inform those affected: in case of GDPR violation: inform the data subjects
- Prevention: measures to prevent similar incidents
🏢 Praxis-Szenario: AI incident in customer service
An AI chatbot in your company accidentally reveals one customer's login credentials to another customer. The incident is discovered during an internal review. How do you proceed?
Fines and sanctions
Possible penalties
| Violation | Maximum fine |
|---|---|
| Prohibited AI practices (Art. 5) | €35M or 7% of worldwide turnover |
| High-risk obligations | €15M or 3% of worldwide turnover |
| AI literacy (Art. 4) | Up to €15M or 3% |
| GDPR violation (AI-related) | €20M or 4% of worldwide turnover |
Aggravating factors
- Intent vs. negligence
- Severity of the violation
- Size of the company
- Cooperation with authorities
- Previous violations
Minimizing liability — practical measures
- AI literacy training for all employees (Art. 4)
- AI policy created and communicated
- AI inventory maintained and regularly updated
- Human oversight for important AI decisions
- Incident response plan for AI incidents
- Insurance coverage reviewed (cyber insurance)
- Regular audits of AI systems
💡 The AI-compliant company: minimum requirements
- ✓ Art. 4 AI literacy training (documented) 2. ✓ AI policy (written, communicated) 3. ✓ AI inventory (all AI systems recorded) 4. ✓ Incident response plan (for AI incidents) 5. ✓ Named responsible parties (AI officer)
✅ Wichtige Erkenntnisse
Haken setzen, um deinen Lernfortschritt zu markieren:
→ Go deeper: AI governance in the enterprise — building an AI policy and governance structure · Data protection & GDPR — GDPR obligations for AI
Weiterführende Inhalte
Relevante Rechtsgrundlagen: Art. 5 · Art. 15 · Art. 16 · Art. 71