Artificial intelligence writes texts, screens job applications, generates predictions and supports people in making decisions. But the moment an AI system gets something wrong — and someone suffers real consequences as a result — a seemingly simple question arises:

Who is actually responsible?

Updated: August 30, 2026 · This article is intended for general information purposes only and does not constitute legal advice.

Artificial intelligence has long become more than a chat window where we type in a question and receive an answer a few seconds later. AI systems can screen job applications, categorize people and content, generate recommendations, manage workflows or form part of complex products. The EU AI Act therefore explicitly classifies certain applications as high-risk, including AI systems used for recruitment or selection, analyzing job applications or evaluating candidates. As long as everything works, this may sound like progress. Processes become faster. Large amounts of data can be processed. People receive support with tasks that would otherwise take considerable time. But imagine a different situation. A company receives 1,000 applications for a position. An AI system helps analyze them and produces a ranking. A highly qualified applicant ends up near the bottom and is therefore not invited to an interview. Later, it turns out that the system systematically disadvantaged certain characteristics.

And now what?
Was it the AI?
The company that developed the system?
The organization that used it?
The person who relied on the ranking?
Or perhaps several of them at the same time?
Welcome to one of the most important questions of our digital future:

Who is responsible when AI is involved in a decision?

WHAT IS HAPPENING?

We are no longer using AI simply to generate impressive images or write texts. Increasingly, we are deploying AI in situations where its outputs can have real consequences for people. The European AI Act recognizes this distinction. Its approach is not to treat every AI system in exactly the same way. Among other things, the intended purpose and the level of risk matter. The workplace is a particularly clear example. The AI Act lists certain systems used for recruitment, selection and personnel management among the potential high-risk use cases. This can include systems that filter applications or evaluate candidates. The reason is fairly easy to understand. A bad restaurant recommendation from a chatbot may be annoying. An incorrect AI-based assessment that contributes to someone not getting a job can potentially affect that person’s livelihood and future. The recitals of the AI Act address precisely this concern: AI systems used in employment can significantly affect career prospects and livelihoods and may, for example, perpetuate historical patterns of discrimination. And that changes the conversation.

We should no longer ask only:

  • What can AI do?

We also need to ask:

  • Who is allowed to use it for what — and who takes responsibility for the consequences?

WHY IS RESPONSIBILITY SO COMPLICATED WITH AI?

With a traditional tool, the roles may initially appear relatively straightforward.

Someone manufactures the tool.
Someone buys it.
Someone uses it.

Modern AI systems can involve a much longer chain of actors. One company might develop an AI model. Another integrates that model into software. A provider turns it into a finished product. An employer purchases the product. An HR department deploys it. An employee works with its outputs — and ultimately an applicant is affected by a decision.

So who is responsible?

The unsatisfying but important answer is:

  • It depends.

And this is exactly why talking about “the responsibility of AI” can be misleading.
An AI system is not a new colleague who can be called into the manager’s office after making a mistake.
Behind the system are people and organizations that develop it, provide it, configure it, deploy it and oversee it.
The AI Act therefore distinguishes between different roles and assigns different obligations to them. In the context of high-risk AI systems, for example, there are obligations for providers as well as for deployers — the organizations or individuals using a system under their authority.
Responsibility does not disappear because AI is involved.

It becomes distributed.

WHAT RESPONSIBILITY DOES THE PROVIDER HAVE?

For high-risk AI systems, the AI Act imposes a range of requirements on providers.
These include requirements relating to the system itself, quality management, documentation and record-keeping, as well as conformity assessment procedures before certain systems can be placed on the market or put into service. Under certain circumstances, providers also have corrective and information obligations.
This reflects an important principle.

A provider should not simply be able to say:

  • “We built the technology. What other people do with it is no longer our concern.”

But neither does it mean:

  • “The provider is responsible for absolutely everything that ever happens with the system.”

Because the organization actually deploying a high-risk AI system also has responsibilities.

WHAT ABOUT THE COMPANY USING THE AI?

Let’s return to our recruitment example.
The employer may not have developed the AI system at all. It may simply have purchased a ready-made solution.

Does that remove its responsibility?

  • No.

The AI Act establishes obligations for deployers of high-risk AI systems as well. Among other things, they are expected to use such systems in accordance with the instructions for use, take appropriate technical and organizational measures and monitor their operation. Human oversight must also be assigned to people who have the necessary competence, training and authority. That last point matters enormously.

A company cannot automatically hide behind the sentence:

  • “The software made the decision.”

When an organization uses AI in a sensitive context, how it uses that technology matters.

Who monitors the system?
Who understands its limitations?
What happens when something looks wrong?
Who has the authority to intervene?
And who ultimately makes the decision?

Technical capabilities and organizational responsibility belong together.

BUT THERE WAS A HUMAN INVOLVED…

This brings us to a problem that extends far beyond artificial intelligence.
Imagine a system evaluates 500 job applications and generates rankings.

Applicant A: 94 points.
Applicant B: 88 points.
Applicant C: 41 points.

A human sits in front of the screen.
Formally, that person makes the final decision.

But what happens in practice?
How likely is it that someone dealing with hundreds of AI-generated assessments will fundamentally question every single result?

This is where the concept of human oversight becomes particularly interesting.
Article 14 of the AI Act requires high-risk AI systems to be designed and developed in a way that allows them to be effectively overseen by natural persons. Those responsible for oversight should be able to understand relevant capabilities and limitations of the system, monitor its operation and, where appropriate, disregard, override or reverse its output. Interestingly, the legislation even addresses a psychological phenomenon:

Automation bias.

Put simply, this describes our tendency to place too much trust in automated results.

The machine calculated it.
The algorithm probably knows what it’s doing.

And that can become dangerous.
Simply putting a human in front of a screen does not automatically create meaningful human control.

Human oversight is more than human presence.

SO WHAT DOES “HUMAN OVERSIGHT” ACTUALLY MEAN?

At its core, it means that the human being should not become a decorative final link in an otherwise automated decision-making chain.
Someone overseeing a high-risk AI system should be able to understand its relevant capabilities and limitations. They need to be able to recognize when something may be wrong, interpret outputs appropriately and — where necessary — decide not to use an output or to stop the system.

For that, people need two things:

  • Competence and genuine authority.

If an employee recognizes that an AI system is producing nonsense but has no organizational authority to deviate from its output, even the best concept of “human oversight” becomes meaningless. This is also one reason why AI literacy goes far beyond knowing how to write a good prompt.

AI literacy also means:

  • Knowing when not to trust the machine.

WHO IS LIABLE WHEN SOMETHING ACTUALLY GOES WRONG?

Here we need to separate two concepts that are often mixed together in public debate:

  • Regulatory responsibility and civil liability.

The AI Act establishes requirements and obligations for certain actors and AI systems.

But that does not automatically create one simple universal rule saying:

  • “Whenever AI causes damage, X always pays.”

Whether a particular person or organization is legally liable for a specific loss can depend on the circumstances and on other applicable legal rules. That distinction matters because “responsibility” in everyday language is much broader than “liability” in the legal sense.

A company may carry organizational responsibility.
A provider may have regulatory obligations.
A human being may make a decision.
And determining who is legally liable for a particular harm is a separate question requiring its own assessment.
This is why we should be careful with overly simple headlines about AI.

“Who is liable for AI?” does not have a universal one-sentence answer.

WHAT HAPPENS WHEN AI IS USED IN MEDICINE?

The issue becomes even clearer when we change the context. Instead of recruitment, imagine a medical product in which an AI system analyzes data and supports a medical assessment.

Here too, the category is not simply “medical AI = high-risk.”

Under the AI Act, AI used in regulated products may qualify as high-risk depending, among other things, on whether the system itself is a product — or a safety component of a product — covered by certain EU product legislation and whether a third-party conformity assessment is required.

But the fundamental question remains:

  • What happens when the AI makes a mistake?

Should a doctor ignore every recommendation simply because it came from a machine?
Of course not.
Should the doctor accept every recommendation simply because an advanced system calculated it?
Also no.
One of the biggest challenges of the coming years lies somewhere between these two extremes.
We want to benefit from AI without simply outsourcing human responsibility to software.

WHICH PERSPECTIVES ARE THERE?

This is where the debate becomes particularly interesting.
One perspective says:

We need clear rules.

The more AI enters sensitive areas of people’s lives, the more important transparency, oversight and clearly assigned responsibilities become.
That concern is understandable.
Nobody wants to be rejected by a faulty system only to hear:

  • Sorry. That’s just what the algorithm does.

Another perspective argues:

  • Too many — or unclear — obligations can make innovation more difficult.

If companies face complex regulatory requirements whenever they develop or deploy new AI applications, costs can increase and development may slow down. Smaller companies in particular may feel these burdens more strongly than large corporations with dedicated legal and compliance departments.

And then there is a third perspective:

Perhaps the decisive issue is not simply the number of rules.
Perhaps what matters most is whether we organize responsibility effectively in practice.
Neither a complete absence of regulation nor a hundred-page compliance document automatically guarantees good decisions.
Ultimately, people need to understand what a system can do, where its limitations lie and when human intervention is necessary.

WHAT DOES THIS MEAN FOR US?

We will probably have to get used to AI becoming part of more and more decisions without necessarily making those decisions entirely on its own.
And that is precisely why language matters.

  • “The AI decided.”

It sounds convenient.
Perhaps too convenient.
Because that sentence can hide all the human decisions that happened before the AI ever produced an output.
Someone decided to use an AI system.
Someone decided which system to use.
Someone determined what data would be fed into it.
Someone designed the processes around it.
Someone determines how much weight its output receives.
And someone decides whether — and when — a human being is allowed to intervene.

So perhaps the more interesting question is not:

  • Can AI take responsibility?

But rather:

  • How do we make sure that people and organizations do not lose their responsibility simply because an algorithm suddenly stands between them and a decision?

AI IS NOT THE END OF RESPONSIBILITY

Artificial intelligence will become more capable.
It will take on more tasks, and we will probably encounter decisions where it becomes increasingly difficult to determine exactly how much of the outcome came from a human, the data, the model or the organization surrounding it. That is precisely why we need more than better AI. We need people who understand the systems they work with. Organizations willing to take responsibility for how those systems are used. Providers that take their obligations seriously. Rules that provide protection where risks are particularly high. And a society willing to discuss these questions without treating every new technology as either our salvation or our downfall.

Because in the end, perhaps this is the defining question of our AI future:

  • Not whether machines will eventually be able to take responsibility — but whether we are willing to take responsibility for the machines we develop and use.

This article is intended for general information and educational purposes only. It does not constitute legal advice. The applicable legal provisions and the circumstances of each individual case remain decisive.

Leave A Comment

Are you human? Please solve:Captcha