SecurityTechInsider AI security & governance
EN/ NL
Governance

Who is liable for an AI error? How the law divides responsibility in 2026

A German ruling holds Google liable for incorrect AI output. What does that mean for professionals, providers and insurers, and what should you record now?

6 September 2026 4 min
Illustration for this article: Who is liable for an AI error? How the law divides responsibility in 2026. Optical fibre ends clustered together, each carrying a pinpoint of light in near darkness.
Professionals must now document which AI system was used, what checking occurred, and on what basis decisions were made. Image: SecurityTechInsider — original editorial illustration

You must be able to demonstrate per workflow which AI system was used, what checking occurred, and on what basis any decision rested. This is now a distributed duty of care: the provider, the professional and the insurer each carry obligations to show what they did.

The prompt is an analysis of 6 September 2026 of liability for AI errors under German and European law, which argues that responsibility for AI mistakes is divided across provider, professional user and insurer, with each required to demonstrate their risk management. The trigger is a ruling by the Landgericht München I on 28 May 2026 holding Google directly liable for incorrect statements in its AI Overviews, on the grounds that Google produces the content, not merely passes it on. In our assessment, this shifts liability from a hypothetical question to a practical compliance obligation: professionals in high-trust domains must now be able to show that AI output was checked and substantiated before use, and insurers are increasingly excluding generative-AI-related damage unless risk management is demonstrable.

What changed in the legal framework?

The German ruling treats AI systems as producers of content, not neutral conduits. Because Google builds, controls and offers the system, statements formulated by the AI are attributed to Google itself rather than to underlying sources. This removes the classic platform defence that a company merely passes on information created elsewhere.

This sits within a broader European shift. The revised Product Liability Directive (Directive (EU) 2024/2853) explicitly treats software and AI systems as products and must be transposed into national law by 9 December 2026. The EU AI Act imposes risk-based compliance obligations. Together, these tighten the evidence framework: providers must increasingly demonstrate that their systems met safety and documentation requirements, while injured parties can in certain cases rely on eased burden of proof.

Where does ultimate responsibility lie?

In high-trust domains, ultimate responsibility does not shift to the system. Healthcare offers a reference point: AI may support decision-making but may not replace it, and the care provider remains ultimately responsible for the quality of care under existing duty-of-care obligations. A professional who adopts an AI-generated report without checking it bears the same liability as though they had made the error themselves.

This pattern extends beyond healthcare. In legal, financial and supervisory practice, existing professional obligations remain fully in force once AI enters the chain. You must be using AI responsibly and must be able to show that an AI suggestion has been checked and substantiated. Anyone who adopts AI output without a checking moment bears the risk themselves.

What are the failure modes and risk categories?

  • Provider liability — the system builder is now liable for incorrect output it produces, not merely for passing on information from other sources.
  • Professional negligence — a staff member who adopts AI output without verification can be held liable as though they had made the error themselves.
  • Coverage gaps in insurance — general liability policies increasingly exclude generative-AI-related damage through new ISO clauses, leaving professionals uninsured for certain harms.
  • Verification failure — output that is not checked or substantiated before use creates liability for the professional who deployed it.
  • Documentation failure — inability to reconstruct who did what, with what care, and on what basis a decision was made.

What must you be able to demonstrate?

  1. Identify the AI system per workflow — document which model or tool was used for each decision or output, and the lawful basis for any data it processed.
  2. Record the checking step — show what verification, correction or disagreement occurred before the output was adopted or acted upon.
  3. Document the decision basis — establish what information, sources or reasoning supported the final decision and who made it.
  4. Maintain an audit trail — keep records that allow you to reconstruct per incident who did what and with what care.
  5. Verify coverage — confirm that your liability insurance does not exclude the specific AI-related damage you are now exposed to, and identify any gaps.

What is the insurance picture?

A coverage gap is emerging. General liability insurance has, since 1 January 2026, increasingly excluded generative-AI-related damage through new ISO clauses. At the same time, specialised AI liability insurers are entering the market and tying coverage to demonstrable risk management.

If AI damage falls under such an exclusion, your existing policy may not cover it, or may cover it only partially. In our assessment, demonstrable risk management—through verifiable and loggable AI workflows—will become an increasingly important underwriting factor. Insurers are moving from asking who is at fault to asking what evidence exists that risk was managed.

Tooling can make verification steps, corrections and sources visible so that you can check them per workflow. This helps make evidence and accountability visible and makes the available checking demonstrable. But tooling does not guarantee that output is correct and does not remove the risk of hallucination. The core professional judgement—whether to trust the output and act on it—always remains with you.

Sources: This article draws on reporting and guidance from DLA Piper – Innovation Law Insights, Chambers Practice Guides, Japan Ministry of Economy, Trade and Industry (METI), Sovib and Zylos.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.