0
KI-gesteuerter Roboterarm berührt menschlichen Finger in einem modernen Büro.
KI-Wissen

Welche Haftungsrisiken entstehen ohne KI-Compliance-Beauftragten?

Without a defined AI Compliance Officer, companies bear the full liability risk for violations of the EU AI Act and related legal standards. Fines under Article 90 of the AI Regulation can amount to up to 7 percent of global annual revenue. On top of that come civil law damage claims, employment law risks, and reputational damage that are nearly impossible to control without a clear accountability structure. This article answers the most important questions about liability scenarios, responsibilities, and practical solutions.

What specific liability scenarios does the EU AI Act create?

The EU AI Act creates concrete liability scenarios for companies that use AI systems without meeting the legal requirements. Particularly critical are violations in the area of high-risk AI systems, missing transparency obligations, and the breach of reporting duties to authorities. Companies are liable both to supervisory authorities and to injured third parties.

The specific liability scenarios can be divided into three categories:

  • Fines from supervisory authorities: Article 90 of the AI Regulation provides for fines of up to 7 percent of global annual revenue for serious violations. For a mid-sized company with 50 million euros in revenue, that means a potential fine of up to 3.5 million euros.
  • Tortious liability under § 823 BGB: Anyone who negligently injures the legal interests of third parties through the use of an AI system is liable for damages. The decisive factor is whether a breach of duty has occurred — for example, because employees were not trained in the use of the system in accordance with Article 4 of the AI Regulation.
  • Contractual liability: If an AI system fails to fulfil contractually guaranteed performance promises, damages for breach of duty under §§ 280 ff. BGB may follow. Marketing statements can also become part of the contract and generate liability risks.

Additional risks arise from the Act Against Unfair Competition. Competitors or associations can issue cease-and-desist letters, apply for injunctions, or file damages claims in the event of violations. In cases of intentional serious violations, criminal consequences under §§ 16 to 20 UWG are also possible, including fines or imprisonment of up to five years.

Who bears liability when no AI compliance responsibility has been defined?

When no AI compliance responsibility has been defined, liability rests in principle with the company as the operator of the AI system, as well as with the individuals who made or supervised the decision to deploy it. A diffuse accountability structure does not protect against legal consequences — it merely complicates internal attribution.

From a legal perspective, the operator of a high-risk AI system is liable under the AI Regulation for compliance with a wide range of obligations, including the implementation of human oversight mechanisms, the retention of log files, and the reporting of serious incidents. If there is no designated person to coordinate these obligations, structural gaps arise that directly lead to liability in the event of damage.

Particularly relevant is product liability: manufacturers of AI solutions must take all necessary precautions within the bounds of what is technically feasible to prevent harm to third parties. Types of defects such as design defects, instruction defects, or organisational defects each give rise to independent liability risks. Anyone who fails to define clear internal responsibility for monitoring these requirements risks being unable to defend against organisational defects in the event of a claim.

Employment law also plays a role: if AI systems make discriminatory decisions, employers are liable under the General Equal Treatment Act, regardless of whether the decision was made by an AI system. Without a responsible function to identify and address such risks, the company remains fully exposed.

What tasks does an AI Compliance Officer take on to minimise risk?

An AI Compliance Officer takes on the systematic monitoring of all legal requirements for AI use within the company and ensures that violations are identified before they become liability cases. The role encompasses technical, legal, and organisational dimensions.

Legal monitoring and documentation

The AI Compliance Officer ensures that all relevant legal standards are adhered to. These include the requirements of the EU AI Act, the GDPR, copyright law, employment law, and information security law. They coordinate data protection impact assessments for high-risk AI systems, monitor retention obligations for automated logs, and ensure that reporting duties to authorities are met on time. Structured documentation is not only a legal obligation but also a central instrument of liability defence.

Training and internal communication

Article 4 of the AI Regulation obliges operators to train their employees in the use of AI systems. An AI Compliance Officer bears responsibility for ensuring that these training obligations are fulfilled, and acts as an internal multiplier for legal requirements. They communicate compliance requirements clearly throughout the organisation, identify training needs, and coordinate appropriate measures. Without this function, the failure to carry out a mandatory employee training alone can give rise to tortious liability.

From what company size is an AI Compliance Officer necessary?

The AI Regulation does not prescribe an explicit minimum size for appointing an AI Compliance Officer. The necessity arises instead from the actual use of AI within the company — in particular, whether high-risk AI systems are being operated, or whether AI systems are being used in sensitive areas such as personnel decisions, credit lending, or medical applications.

In practice, the necessity can be assessed using the following criteria:

  • Type of AI systems in use: Anyone operating high-risk AI systems has extensive obligations under the AI Regulation that are barely fulfillable without dedicated accountability.
  • Number of AI applications: Beyond a certain breadth of AI use within the company, the complexity of compliance requirements grows exponentially.
  • Regulatory environment: Companies in regulated industries such as healthcare, financial services, or critical infrastructure are affected earlier and more severely.
  • Liability exposure: The higher the revenue, the greater the absolute fine risk for violations of Article 90 of the AI Regulation.

Even smaller companies that want to build AI governance in line with ISO 42001 benefit from a clearly defined accountability. The function does not necessarily have to be a full-time position. In smaller organisations, it can be anchored as a partial responsibility within an existing role — for example in data protection or IT security — as long as the accountability is clearly documented.

How can AI compliance be implemented without internal resources?

AI compliance can also be implemented without dedicated internal resources by selectively upskilling existing employees, clearly distributing responsibilities, and making use of external training offerings. The key lies not in creating a new full-time position, but in systematising accountability and building legal knowledge within the organisation.

The following approaches have proven effective in practice:

  1. Upskill existing specialists: Employees from the areas of data protection, law, IT security, or project management can take on the fundamentals of AI compliance through targeted further training. The decisive factor is that they know the core legal standards and can act as internal multipliers.
  2. Distribute tasks in a structured way: Not all compliance tasks need to rest with one person. Reporting duties, training coordination, documentation, and risk assessment can be distributed across multiple roles, as long as overall responsibility is clearly assigned.
  3. Rely on recognised frameworks: Standards such as ISO 42001 provide a structured framework for building an AI management system. They help to systematically capture compliance requirements and make them actionable internally.

It is important that the chosen solution is documented and verifiable. In the event of a claim, it is not sufficient to handle compliance measures informally. Authorities and courts expect a structured, evidenced engagement with the legal requirements. Anyone who deploys AI training for employees at an early stage not only reduces liability risk but also builds the internal knowledge base necessary for a sustainable compliance culture.

How mITSM supports you in building AI compliance

We at mITSM offer specialised training and further education that prepares professionals and managers specifically for the requirements of the EU AI Act and related legal standards. Our trainers are certified experts who know AI compliance not only from theory but from practical work in companies.

Our offering in the area of AI compliance includes:

  • Training on the legal foundations of AI use, from the EU AI Regulation to data protection law and liability law
  • Further education as AI Compliance Officer with personal certifications through ICO-Cert as a recognised certification partner for AI topics
  • Training on ISO 42001, the international standard for AI management systems
  • Courses as in-person training, online live training, or in-house training at your location

Companies that want to build their AI governance in a structured way and specifically reduce liability risks will find the right further training format with us. Find out now about our training offering in the area of AI compliance and take the first step towards legally secure AI use in your company.

Dieser Inhalt wurde mithilfe von KI erstellt und kann Fehler enthalten.

+49 89 - 44 44 31 88 0 Chat starten
4.9
Basierend auf 126 Rezensionen