AI Liability and Governance: Navigating the Global Legal Minefield

- The EU AI Act establishes a risk-based framework with extraterritorial reach, impacting any company operating in the European market.
- Traditional liability models based on human error are failing, shifting focus toward product defect and algorithmic accountability.
- US experimental 'sandboxes', such as Utah's AI prescription pilot, are testing the limits of autonomous professional licensure.
- The role of the Chief Legal Officer (CLO) is evolving from a legal guardian to an architect of enterprise AI governance.
The rapid integration of artificial intelligence into critical business infrastructure has outpaced the legal frameworks designed to govern it. For decades, civil and criminal liability rested on a fundamental premise: the existence of human error. However, as autonomous systems begin to prescribe medication, manage critical infrastructure, and filter job applicants, the legal world is facing a conceptual revolution. The central question is no longer just about what the technology can do, but who pays when the algorithm fails.
The EU AI Act and the Risk-Based Paradigm
The European Union has taken the first comprehensive step toward solving this puzzle with the AI Act (Regulation EU 2024/1689), which entered into force in August 2024. Rather than applying a blanket set of rules, the EU has adopted a risk-based classification system that determines the level of regulatory scrutiny a system must undergo. At the top of the pyramid are 'unacceptable risk' systems, such as social scoring, which are banned outright. Below these are 'high-risk' systems—those used in healthcare, education, justice, and critical infrastructure management.
For entrepreneurs and tech providers, the high-risk category is where the most significant burdens lie. These systems must adhere to strict technical conformity, ensure traceability, and maintain human oversight. A practical example is AI-driven recruitment software; if classified as high-risk, it must meet non-discrimination standards and provide verifiable technical documentation. Crucially, the EU AI Act possesses extraterritorial reach, meaning it applies to any entity offering or using AI systems within the EU market, regardless of where the company is headquartered.
The Collapse of Traditional Liability Models
The shift toward autonomy creates a vacuum in traditional tort law. Historically, liability was built around fault, causal links, and the predictability of damage. When an AI system makes an independent decision that leads to harm, the chain of causality becomes blurred. The legal debate now centers on whether the responsibility lies with the software developer, the entity that trained the model, the owner of the system, or the end-user.
Current frameworks in both Europe and the US often fall back on product liability—treating AI as a defective product. However, the 'black box' nature of deep learning makes it difficult to prove a specific defect in the traditional sense. This has led to a push for new interpretations of civil liability. In Italy, for instance, legal experts are analyzing how the civil liability framework must evolve to distribute the social costs of innovation without stifling the technology itself.
Autonomous AI in Action: The Utah Experiment
While Europe focuses on regulation, parts of the United States are experimenting with 'regulatory sandboxes' to test the limits of autonomy. A landmark case is the AI Prescription Renewal Pilot in Utah, launched in January 2026. Under the Utah Artificial Intelligence Policy Act, a company called Doctronic has been permitted to use an AI system to autonomously prescribe medication renewals for 191 chronic conditions, including diabetes and depression, without a physician in the loop.
This pilot represents a significant departure from clinical decision support, moving directly into autonomous action. However, the experiment has hit immediate friction. The Utah Medical Licensing Board has demanded the suspension of pilot activities, raising critical questions about licensure and the corporate practice of medicine. The dispute highlights a primary tension in the US market: the desire for rapid innovation via state-level sandboxes versus the rigid requirements of professional licensing and federal law. This case serves as a bellwether for how autonomous AI will be integrated into highly regulated professions globally.
Redefining the Chief Legal Officer
As the legal landscape shifts, the internal structure of the corporation must follow. The role of the Chief Legal Officer (CLO) is undergoing a fundamental transformation. No longer just the guardian of established precedents, the modern CLO is becoming the architect of enterprise AI governance. This involves moving beyond a 'yes or no' approach to innovation and instead designing the operational frameworks that allow for algorithmic accountability.
The CLO now faces a series of unsettled questions that impact the bottom line:
- Who owns the intellectual property of AI-generated content?
- How is liability assigned when an automated system makes a consequential business decision?
- How can the company maintain trust while deploying AI-enabled pricing or fraud detection?
The Gap Between Regulation and Execution
Despite the introduction of the AI Act and various state-level initiatives, a significant gap remains between the existence of rules and their practical execution. Many organizations have identified their new legal needs but lack the framework to implement them. The complexity is compounded by the velocity of AI development; by the time a regulation is debated and passed, the technology has often evolved into a new form.
The evolution of AI is putting the law at a crossroads. The normative architecture of civil and criminal liability is based on the premise that error is human. But if the error is that of a machine, how do we distribute the blame?
This tension is evident in the struggle to define the 'human in the loop' requirement. While the EU mandates human supervision for high-risk AI, the practical application of this—whether it means a human signing off on every decision or merely having the ability to override the system—remains a point of contention and a potential source of future litigation.
Global Implications for International Enterprises
For businesses operating across the USA, UK, and global markets, the current environment is one of fragmented compliance. Companies cannot rely on a single legal strategy. In the US, the approach remains largely decentralized, with states like Utah creating experimental zones, while federal oversight focuses on specific sectors via agencies like the FDA. The UK continues to pursue a more flexible, pro-innovation stance, though it remains mindful of international alignment.
However, the EU AI Act acts as a global gravity well. Because of its extraterritorial application, any US or UK firm selling AI services into the European market must comply with its risk classifications and transparency obligations. Failure to do so could result in massive fines and market exclusion. For the international entrepreneur, the strategy must be twofold: adopt the highest common denominator of safety and transparency (often the EU standard) to ensure global market access, while leveraging local sandboxes in the US to push the boundaries of autonomous functionality. The transition from 'clinical decision support' to 'autonomous action' is the next great legal frontier, and the winners will be those who integrate AI governance into their core corporate DNA rather than treating it as a compliance checkbox.
FAQ
Does the EU AI Act apply to companies based in the USA or UK?
Yes, it applies to any provider or user of an AI system that is placed on the market or put into service within the European Union, regardless of where the company is located.
What is a regulatory sandbox in the context of AI?
It is a controlled environment, such as the one created by Utah's Artificial Intelligence Policy Act, where companies can test innovative AI products in the real world for a limited time with temporary relief from certain state rules.
Who is typically held liable for AI-generated damages under current laws?
Most current frameworks rely on product liability, meaning the manufacturer or developer is held responsible if the AI is found to have a defect. However, this is evolving toward more complex models involving the user and the trainer of the AI.
What are 'high-risk' AI systems according to the EU?
These are systems used in critical areas such as healthcare, education, justice, and the management of critical infrastructure, which are subject to strict obligations regarding transparency, data quality, and human oversight.
Sources: Giuridicamente, Narrativadiritto, Studiolegalegolini ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email












