Catena di anelli metallici con un anello centrale incrinato

Immagine creata con IAAI-generated image

Who answers when the system acts: attributability and liability in the AI value chain

Union law has always held firm on one point: the artificial intelligence system is an object, not a subject. Regulation (EU) 2024/1689 assigns it no duties and attributes to it no consequences, but constructs a list of operators, the provider, the product manufacturer, the deployer (as the Italian version of the Regulation calls the person who uses the system), the authorised representative, the importer and the distributor, and distributes obligations and responsibilities among them. The hypothesis of a status of electronic person, raised in Parliament almost ten years ago, does not appear to have been translated into any binding act of the Union.

The choice is correct, and we consider that it should not be abandoned. It remains to be verified, however, whether the way in which that responsibility is distributed withstands the test of systems that act, those which autonomously perform sequences of actions on the outside world.

Provider and deployer: two distinct figures

Article 3 of the Regulation defines the provider as a person who develops a system or has a system developed and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge, and the deployer as a person using a system under its authority, except where the system is used in the course of a personal non-professional activity (European Commission).

It is worth fixing at the outset a caveat which in practice is a source of errors: provider and deployer do not correspond to controller and processor. The two pairs belong to different regulations, respond to different criteria and may be distributed differently across the same organisation. An undertaking may be a deployer within the meaning of the AI Act and a controller within the meaning of Regulation (EU) 2016/679, or a deployer and a processor, and the qualification must be carried out twice.

The moment at which one becomes a provider: Article 25

This is, in our view, the most underestimated provision of the Regulation. Article 25 establishes that a distributor, importer, deployer or other third party shall be considered to be a provider of a high-risk system, and assumes all the obligations of a provider, in three cases: if it puts its name or trademark on a system already placed on the market; if it makes a substantial modification to a high-risk system already placed on the market in such a way that it remains high-risk; if it modifies the intended purpose of a system, including a general-purpose system, which has not been classified as high-risk, in such a way that it becomes high-risk (European Commission).

When this occurs, the initial provider ceases to be such for that specific system, while remaining bound to cooperate and to make available the information and the technical access reasonably necessary. Paragraph 4 adds that the provider and the third party supplying tools, services, components or processes integrated into the system must specify in writing the information and assistance necessary, with the exclusion of components made available to the public under a free and open-source licence.

It is the provision that shifts responsibility onto those who are often unaware of it. The organisation that integrates a general-purpose model into its own service, customises it and directs it to a purpose falling within Annex III is not using someone else’s product: it is placing on the market a high-risk system of its own, with everything that follows in terms of risk management, data governance, documentation, registration and conformity assessment.

The deployer and human oversight

Article 26 requires the deployer of a high-risk system to adopt appropriate technical and organisational measures to ensure use in accordance with the instructions and to assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. It is not an obligation of result as to the functioning of the system, which remains with the provider, but an obligation of organisation on the person who uses it.

Article 14(4)(b) completes the picture by requiring those exercising oversight to remain aware “of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system”, which the text calls “automation bias”. It should be recalled that the obligations of Chapter III, Sections 1 to 3, for the systems of Annex III will apply from 2 December 2027, by effect of the calendar redrawn by the Digital Omnibus, Regulation (EU) 2026/1744.

The gap left by the withdrawn directive

The foregoing concerns the public-law framework, which identifies the obligations of each operator. On the side of damage, by contrast, the European framework has shrunk. The proposal for a directive on non-contractual civil liability for artificial intelligence, presented in 2022, provided for an obligation to disclose evidence and a rebuttable presumption of causation in favour of the injured party. The Commission included it among the withdrawals in its work programme for 2025, and the withdrawal was formalised by notice C/2025/5423, published in the Official Journal of the European Union of 6 October 2025.

The result is that today there is no special regime of civil liability in Union law for damage caused by artificial intelligence systems. Those who bring a claim must proceed with the general instruments, and in Italy this means Article 2043 of the Civil Code, with the burden of proof on the injured party, Article 2050 on dangerous activities and Article 2051 on liability for things in one’s custody, whose applicability to a computer system is far from settled.

What the new Product Liability Directive covers, and what it does not

Part of the gap is filled by Directive (EU) 2024/2853 on liability for defective products, which the Member States must transpose by 9 December 2026 and which will apply to products placed on the market after that date (EUR-Lex). The innovation of interest here is the notion of product, which includes software and therefore artificial intelligence systems, irrespective of the channel of distribution, and which also covers modifications subsequent to placing on the market where they remain under the control of the manufacturer.

The Directive also introduces access to evidence and a system of presumptions designed to redress the information asymmetry: defectiveness is presumed, among other cases, where the defendant fails to comply with the disclosure order, and causation is presumed where the product is proven to be defective and the damage is consistent with that defect. There is then the presumption reserved for cases in which technical or scientific complexity makes it excessively difficult for the injured party to prove the defect or the causal link. All of them admit proof to the contrary.

Two situations remain excluded, and they are not marginal. The Directive covers damage caused by a defective product, not every damage arising from the use of the system, and it does not concern the liability of the person who uses the system. For the deployer, who is the figure closest to the event, Union law today offers no dedicated regime.

Italy: Decree 160/2026 and what is missing

Law No 132 of 23 September 2025 intervened on a procedural point, placing cases concerning the functioning of an artificial intelligence system among the matters within the exclusive competence of the tribunal under Article 9, second paragraph, of the Code of Civil Procedure (Official Gazette (Gazzetta Ufficiale)). The substantive rules were instead left to the delegation under Article 24, whose deadline expires on 10 October 2026.

Those rules have arrived with Legislative Decree No 160 of 9 September 2026, published on 15 September and in force from the 30th (Official Gazette (Gazzetta Ufficiale)), and are in substance the national recovery of some of the solutions contained in the withdrawn European directive.

Articles 16 to 20 build a procedural framework, not a new head of liability. Article 17 requires the court, on application by a party, to order the disclosure of evidence on the functioning of the system, and lists four kinds: the logs under Article 12 of the AI Act, the documentation on the risk management system under Article 9, the technical documentation under Article 11 and the information on the parameters and methods of human oversight under Article 14. The threshold for obtaining the order is lowered, since it suffices to plead “facts and elements capable of making the merits of the claim plausible”, and non-compliance has a precise consequence, since as regards the documentation listed the court “treats the facts pleaded by the applicant as admitted”. Article 18 establishes that, where the damage results from the breach of an obligation under the European Regulation, “the causal link between the breach and the damage is presumed, unless proven otherwise”. Article 19 specifies that conformity with the Regulation, even where certified, “does not in itself exclude the liability of the defendant”. Article 16 adds a concurrent forum in the place of residence or domicile of the injured party acting for purposes outside their professional activity, and Article 20 introduces a direct action against the insurance undertaking, with the compulsory joinder of the person liable.

Three clarifications are needed, because the summaries in circulation report these points inaccurately. First: there is only one presumption, that of causation, and it is rebuttable; no presumption of defectiveness of the system has been introduced. Second: Articles 2050 and 2051 of the Civil Code appear in the preamble of the decree but in no article, and Article 2043 is not even mentioned, so that the legislature has qualified the use of artificial intelligence systems neither as a dangerous activity nor as custody, and has left the question to the interpreter by constructing instruments neutral as to the head of liability: Article 16 refers the disclosure order to liability actions “whether contractual or non-contractual”. Third: the injured party’s forum is concurrent and not exclusive, because the provision says “shall also have jurisdiction”.

On the criminal side the decree introduces the new Article 437-bis of the Criminal Code, which punishes with imprisonment of one to five years the failure to adopt technical security measures or human oversight on high-risk systems, where this gives rise to a danger to life or physical safety, with more severe penalties if the danger concerns the security of the State. The fourth paragraph deserves particular attention: the offence extends to the professional user who intentionally omits human oversight. The new Article 25-vicies of Legislative Decree No 231 of 8 June 2001 finally brings this offence, together with Article 612-quater, among those grounding the liability of entities, with a financial penalty of six hundred to one thousand units and disqualification sanctions.

The second implementing decree, on the powers of the national authorities and on training, does not by contrast appear to have been published at the time of writing, a few weeks before the expiry of the delegation.

Critical aspects: agents and the attribution of autonomous actions

The framework described presupposes one thing: that between the conduct of an operator and the harmful event there runs a line that can be reconstructed. It is a presupposition that holds as long as the system is a tool and someone uses it to obtain a determined result. It holds far less when the system operates as an agent, when it receives a general objective, chooses the intermediate actions itself, invokes other services and produces effects on the outside world without any of those choices having been deliberated by a person.

In that scenario the categories continue to function formally and give way in substance. The provider can show that the system behaved according to its specifications; the deployer can show that it used the system in accordance with the instructions; the third party that supplied a component can show that its own component was compliant. Each answers for its own portion, and what remains uncovered is the chain, which is precisely what produced the damage. Liability does not lack persons to bear it: it lacks an object.

We consider that the distinction between attributability and responsibility helps to see the problem. Attributing an outcome to a subject is a formal operation, and the law performs it without difficulty. Making that subject effectively responsible requires that it was in a position to foresee and to avoid, and on this the current rules offer little, because they are built on the product and its defect and not on the conduct of the person who puts a system in a position to act. No artificial legal personality is needed to fill the gap, and indeed conferring one would displace the problem elsewhere without solving it: what is needed is a criterion of attribution that follows control and calls to account the person who defined the objective, the limits of action and the stopping points. It is, after all, the same question that arose with regard to artificial intelligence agents in the Meta case, and which the Italian law, built around the figure of the supporting tool, does not address.

There is, finally, an immediate practical consequence of which many undertakings are unaware. Whoever integrates a general-purpose model into its own service, modifies its purpose and directs it to a use under Annex III becomes a provider within the meaning of Article 25, and from that moment answers as such. It is not a contractual matter: paragraph 1, point (a), preserves different contractual allocations only for the case of putting one’s trademark on the system, not for substantial modification nor for the change of purpose.

Conclusions

European law holds firm to the choice not to confer legal personality on systems and to distribute obligations among human operators, and on that plane Article 25 is more incisive than its position suggests. On the plane of damage, by contrast, the withdrawal of the directive on liability for artificial intelligence has left a gap that the new Product Liability Directive covers only in part, because it looks to the product and not to the person who uses it. In Italy that gap has been filled by procedural means by Legislative Decree 160/2026, which facilitates access to evidence and presumes causation without, however, choosing a head of liability, and by criminal means with an offence that reaches the person who uses the system as well. For those assessing a project today, the questions to be asked before any other are three: whether the intended use makes them a provider within the meaning of Article 25; who, within their organisation, will have the authority and the competence to stop the system; and whether that person is placed in a position to exercise oversight in practice, because from September intentionally omitting it is no longer merely a breach of an obligation.

Author: Valentina Grazia Sapuppo


AI AnthropoCosmic In evidenzaAI AnthropoCosmicUn progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo, che mette al centro la dignità della persona nella progettazione dei sistemi. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicAn international project for an AI at the service of humanity, the environment and the cosmos, placing human dignity at the centre of system design. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article
Intervista Radio Radio IntervistaLegge e colossi del digitaleIl patteggiamento di Meta sui minori non è una condanna. Stati Uniti ed Europa seguono strade opposte, e sugli agenti di IA resta aperta la domanda su chi risponde.Un Giorno Speciale su Radio Radio, con Alessio De Paolis · audio dal minuto 2:26:00Ascolta l’intervistaGuarda il videoLeggi l’articolo
Digital Omnibus ContributoIl Digital Omnibus cambia l’AI ActNuove scadenze per i sistemi ad alto rischio e un chiarimento sull’obbligo di AI literacy: più tempo per adeguarsi, nessuno sconto sulla preparazione di persone e processi.Articolo scritto per il blog di SkillaLeggi su Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo tra i relatori del festival dedicato a protezione dei dati, archivi digitali e regole del futuro. Interviene sul tema «Le regole dell’IA: nuove leggi o principi del diritto?».Venerdì 6 novembre 2026, ore 16:30, Ex Convitto Palmieri, LecceL’interventoLa scheda relatriceIl festival
AI AnthropoCosmic 2026Moderatrice e relatriceAI AnthropoCosmic 2026Valentina Grazia Sapuppo nel progetto dell’Università Pontificia Salesiana su Persona, Ambiente e Cosmo: moderazione della sessione mattutina del Convegno finale e intervento negli AI Laboratori del Domani su commercio elettronico e IA.14 novembre 2026, online · 28 novembre 2026, Università Pontificia Salesiana, RomaIl convegnoL’incontroIl contributoLa relatriceIl progetto
Interview Radio Radio InterviewLaw and the digital giantsThe Meta settlement on minors is not a conviction. The United States and Europe take opposite paths, and on AI agents the question of who answers remains open.Un Giorno Speciale on Radio Radio, with Alessio De Paolis · audio from 2:26:00 · in ItalianListen to the interviewWatch the videoRead the article
Digital Omnibus ContributionThe Digital Omnibus reshapes the AI ActNew deadlines for high-risk systems and a clarification on the AI literacy duty: more time to comply, no discount on preparing people and processes.Article written for the Skilla blog, in ItalianRead on Skilla
Digeat Festival 2026 SpeakerDigeat Festival 2026Valentina Grazia Sapuppo among the speakers of the festival on data protection, digital archives and the rules of the future. She takes part in the panel «The rules of AI: new laws or principles of law?».Friday 6 November 2026, 16:30, Ex Convitto Palmieri, LecceThe panelSpeaker profileThe festival
AI AnthropoCosmic 2026Moderator and speakerAI AnthropoCosmic 2026Valentina Grazia Sapuppo in the project of the Università Pontificia Salesiana on Person, Environment and Cosmos: moderator of the morning session of the closing conference and speaker at the AI Laboratori del Domani on e-commerce and AI.14 November 2026, online · 28 November 2026, Università Pontificia Salesiana, Rome · sessions held in ItalianThe conferenceThe sessionThe contributionSpeakerThe project