After the AI Liability Directive: Civil Liability for Healthcare AI and the Limits of EU Risk Regulation
Omar Tujjar, Gabriele Ientile, Francesca ToppettiAbstract
Following the withdrawal of the proposed AI Liability Directive in 2025, claims concerning harm caused by healthcare AI continue to be addressed through product liability, national medical liability and sectoral regulation. This article analyses that architecture through three deployment archetypes, a CE-marked radiology triage tool, a machine-learning deterioration score and an ambient clinical scribe, across Ireland, Italy and Germany. It argues that five recurrent gaps persist notwithstanding the revised Product Liability Directive and the AI Act: evidence asymmetry, documentation integrity, multi-actor control, warning and reliance, and causation under uncertainty. The revised Product Liability Directive improves software coverage and producer-side proof tools, while the AI Act, together with the Medical Devices Regulation where applicable, strengthens the evidential environment through logging, documentation, oversight and post-market duties. Yet those gains are uneven in time and scope and do not eliminate the claimant-facing difficulty created by vendor-held artefacts, distributed control and negligence-side causal proof. The most immediate improvements therefore lie in upstream governance: procurement clauses on artefact retention and exportability, express contractual control-point allocation, and deployment-stage assessment of whether system design is genuinely consistent with the human verification expected of clinical users.