AI and Legal Liability: Who Is Responsible When an AI Causes Harm?
When an autonomous vehicle injures a pedestrian, an AI diagnostic system misdiagnoses a patient, or a legal chatbot gives wrong advice — who bears responsibility? These questions have moved from theoretical to practical, and the law is still catching up.
1. Existing Liability Frameworks: Tort Ordinance and AI
Israel has no dedicated AI liability legislation yet. Current frameworks rely on the Torts Ordinance (New Version) 1968. The negligence tort requires duty of care, breach, damage, and causation. AI developers may be liable for inadequate testing and safety measures.
2. The Liability Chain: Developer, Deployer, User
AI liability is distributed across the supply chain. Developers may be liable for defective models. Deployers may be liable for inappropriate use cases or inadequate disclosure. Users may bear responsibility for over-reliance on AI in high-stakes decisions.
3. International Regulation: EU AI Act and What Will Come to Israel
The EU AI Act (2024), with full effect from 2026, classifies AI systems by risk level and imposes mandatory obligations. Israeli companies serving the European market must comply. Israel is developing its own national AI policy.
4. Defective Products: Can AI Be a Defective Product?
The Defective Products Liability Act 1980 may apply to AI products. Proving a defect in a probabilistic AI model is complex — what constitutes a defect when the model is inherently probabilistic?
5. Proactive Risk Management for AI Companies
Documentation of development processes, clear disclosure of limitations, contractual liability limitations, professional liability insurance, and regular safety testing are all essential risk management tools.
Checklist
- Document the model development process, assumptions, and known limitations
- Add clear disclosure of system limitations to terms of service
- Conduct a risk assessment before deploying AI in high-risk domains
- Review compliance with EU AI Act requirements if operating in the European market
- Include specific AI liability limitation clauses in contracts
- Maintain professional liability insurance covering AI-related damage
Common Pitfalls
- Assuming AI liability always falls on the final developer alone
- Failing to disclose model limitations to users — creates negligence exposure
- Using AI in high-risk domains (medicine, law) without human oversight
- Not documenting testing and safety processes — makes defense against claims difficult
- Ignoring EU AI Act requirements for companies with European customers
שאלות ותשובות
Who is liable when an AI system makes a harmful error?
Liability depends on the specific circumstances and the nature of the error. The developer may be liable if the model was defectively designed or tested. The deployer may be liable if the system was used for inappropriate purposes without adequate safeguards. The user may bear responsibility for over-reliance on AI output in situations requiring human professional judgment.
Is there a specific Israeli law on AI liability?
Not yet. Israel does not have dedicated AI liability legislation as of 2026. Cases are analyzed under existing legal frameworks: the Torts Ordinance for negligence, the Defective Products Liability Act for product liability, and contract law for commercial relationships. Dedicated regulation is under development.
Does the EU AI Act apply to Israeli companies?
Directly, only to companies in the EU. However, any Israeli company that offers AI products or services to EU customers, processes EU personal data, or deploys AI systems affecting EU residents is likely subject to EU AI Act requirements. Israeli companies active in Europe need to review compliance obligations carefully.
How can an AI company limit its liability exposure?
Key risk management steps include: documenting development and testing processes thoroughly, including clear AI disclosure and limitation statements in terms of service and contracts, conducting risk assessments before high-stakes deployments, implementing human oversight for high-risk use cases, and maintaining appropriate professional liability insurance.
What is a high-risk AI system under the EU AI Act?
The EU AI Act categorizes AI systems in sectors like healthcare, education, employment, essential services, law enforcement, and critical infrastructure as high-risk. These systems face mandatory conformity assessments, technical documentation requirements, human oversight provisions, and registration obligations before deployment.