Blog

Who is liable for an AI error? How the law divides responsibility in 2026

A German ruling holds Google liable for incorrect AI output. What does that mean for professionals, providers and insurers, and what should you record now?

· By

A printed report with a marked passage and a pen lies on a desk beside an open case folder in daylight.
The professional remains ultimately responsible and must be able to show that AI output was checked before a decision rests on it.Image: IamVera.ai — original editorial illustration

Liability for AI errors is divided in 2026 across three links: the provider, the professional using the system and the insurer. A German ruling holds Google directly liable, but the professional remains ultimately responsible; therefore record per workflow who checked and on what a decision rested.

The trigger is concrete. According to an analysis by law firm DLA Piper in its Innovation Law Insights of 2 July 2026, the Landgericht München I ruled on 28 May 2026 (case number 26 O 869/26) that Google is directly liable for incorrect statements in its AI Overviews. The court did not regard Google as a neutral conduit, but as the producer of its own content: the system generated claims that were not present in the linked sources. For professionals who work with AI, this means that the question "who is liable when an AI makes a mistake?" is no longer hypothetical.

Why does the Munich court hold Google itself liable for AI output?

According to DLA Piper's analysis, the ruling turned on how the output was classified. Because Google builds and offers the system and controls the algorithms, the statements formulated by the AI were attributed to Google itself, not to the underlying sources. This removes the classic defence that a platform merely passes on information.

This fits into a broader European framework. The Chambers Practice Guide Artificial Intelligence 2026 describes how the revised Product Liability Directive (Directive (EU) 2024/2853) explicitly treats software and AI systems as products and must be transposed into national law by 9 December 2026 at the latest. In addition, the EU AI Act imposes a risk-based compliance obligation. In our assessment, this tightens the evidence framework: providers will increasingly have to be able to demonstrate that their system met safety and documentation requirements, while injured parties can in certain cases rely on eased burden of proof under the new directive.

It is not an exclusively European phenomenon. Japan's Ministry of Economy, Trade and Industry (METI) published on 9 April 2026 a guidance on civil liability in AI use, in which it emphasises that existing fault-based liability and duties of care are in many cases already sufficient, provided it is carefully explained how causation and duty of care should be assessed in the context of AI.

Do I remain liable as a professional if an AI is part of my workflow?

Yes. In high-trust domains, ultimate responsibility does not shift to the system. The sector publication by Sovib on AI in healthcare states that AI may support decision-making but may not take it over, and that under the Dutch Medical Treatment Contracts Act (WGBO) the care provider remains ultimately responsible for the quality of care. A staff member who blindly adopts an AI-generated report without checking it can, according to Sovib, be liable as though they had made the error themselves.

In our assessment, this pattern in healthcare offers a reference point for other high-trust domains, although the precise application will differ per sector and jurisdiction. In legal, financial and supervisory practices too, existing professional and duty-of-care obligations remain fully in force once AI enters the chain. This means that as a professional you must be using AI responsibly in professional practice and must be able to show that an AI suggestion has been checked and substantiated. Anyone who adopts AI output without a checking moment bears the risk themselves.

Why are insurers increasingly excluding generative AI damage?

A coverage gap is emerging. According to an analysis by Zylos.ai on liability insurance around AI agents, general liability insurance (CGL) has, since 1 January 2026, increasingly excluded generative-AI-related damage through new ISO clauses (CG 40 47, CG 40 48 and CG 35 08). At the same time, Zylos.ai describes an emerging niche of specialised AI liability insurers that tie coverage to demonstrable risk management.

The practical consequence: if AI damage falls under such an exclusion, a coverage gap can arise and you run the risk that your existing policy does not cover the damage, or covers it only partially. Sovib also points out that liability coverage via general liability insurance (AVB) can indeed absorb part of the risks, but that gaps exist for cyber-related damage. In our assessment, for many insurers demonstrable risk management, for example through verifiable and loggable AI workflows, will become an increasingly important underwriting factor, alongside the legal questions around liability.

What should I record per AI workflow to be able to bear liability?

The common thread through ruling, directive and insurance trend is that each link must be able to demonstrate what measures it took. We see this as a distributed duty of care: it is less about who is formally at fault, and more about whether everyone can show what happened. As an editorial checklist, based on the cited sources:

  • Make human checking visible. Record who assessed an AI suggestion and with what outcome, so that you can demonstrate the output was not blindly adopted.
  • Trace the origin of claims. Retain which sources an AI answer rested on; the German ruling turned precisely on claims that were not present in the sources.
  • Delineate roles and decision rights. Make clear which decision lies with the human and where AI merely supports.
  • Secure supplier obligations contractually. Arrange that the provider can demonstrate its documentation and safety duties under the new product liability; consider setting out audit rights and evidence obligations in AI contracts.
  • Test insurance coverage. Check whether your policy excludes generative AI damage and what risk management an insurer expects.

A verification layer can help here. Vera is not a chatbot and not its own language model, but it can make verification steps, corrections, disagreements and sources visible so that a professional can check them. This makes it clearer per workflow which AI system was used, what checking there was and on what a decision rested, which helps in making evidence and accountability visible per workflow. That does not guarantee that output is correct and does not remove the risk of hallucinations, but it does make the available checking demonstrable. To recognise unreliable output, you can additionally look into practical tips on recognising and checking misleading AI citations, as we discuss in a separate blog.

The core point for the reader: make sure you can reconstruct per incident who did what, and with what care. The professional final judgement always remains with you.

Sources and references

  1. Google AI Overviews liability: Munich court holds Google directly liable for what its AI inventsDLA Piper – Innovation Law Insights · 2026-07-02
  2. Artificial Intelligence 2026 – EU chapter (Product Liability Directive and AI)Chambers Practice Guides · 2026-05-21
  3. Guidance on the Interpretation and Application of Civil Liability in the Utilization and Application of AIJapan Ministry of Economy, Trade and Industry (METI) · 2026-04-09
  4. Als AI een fout maakt, wie is dan aansprakelijk?Sovib · 2026-02-17
  5. Who Pays When an Agent Gets It Wrong: The 2026 AI Agent Liability Insurance Underwriting LandscapeZylos.ai · 2026-07-10

Sources: The article relies on the ruling of the Landgericht München I as analysed by DLA Piper, the Chambers Practice Guide on the EU Product Liability Directive, the METI guidance from Japan, the sector analysis by Sovib and the research by Zylos.ai.

← All articles in this topic ← All articles