Artificial Intelligence and Legal Liability in Aviation: Who Is Responsible When AI Fails?

Artificial intelligence is steadily entering safety-critical areas of aviation. AI-assisted systems may help pilots detect hazards, support air traffic controllers in managing traffic, improve predictive maintenance and optimise airline operations.
However, as AI is given greater decision-making authority, an important legal question emerges:

Who is responsible when an AI-supported decision contributes to an aviation accident?

The short answer is that the AI system itself would not normally be treated as the legally responsible party. Under the emerging European framework, responsibility remains connected to the people and organisations that design, manufacture, integrate, deploy, maintain and operate the system.
Depending on the cause of the failure, liability could involve an AI provider, aircraft or equipment manufacturer, system integrator, airline, air navigation service provider, maintenance organisation, pilot or air traffic controller. In a complex accident, responsibility may be shared between several of them.

Can Artificial Intelligence Be Legally Responsible?

Under current law, an AI system does not possess legal personality comparable to that of a person or company. It cannot independently hold an operating certificate, purchase liability insurance, comply with a court order or compensate accident victims from its own assets.
Therefore, a court would not ordinarily conclude that “the AI is liable” and end the investigation there.
Instead, investigators and courts would examine the system’s complete lifecycle:

AI developer → system provider → manufacturer or integrator → operator → human user → operational outcome

The central question would be where the safety and accountability chain failed. Was the algorithm defectively designed? Was its training or validation data unsuitable? Was the system integrated incorrectly? Did the operator fail to provide adequate training? Was a required software update omitted? Did a pilot or controller misunderstand an alert that should have been clear? These questions move legal analysis away from a single “human versus machine” distinction and towards distributed responsibility.

Recommended: Swiss Cheese Model – Aviation Safety

EASA’s Human-Centric Approach to Aviation AI

The European Union Aviation Safety Agency has consistently followed a human-centric approach to aviation AI. EASA’s Artificial Intelligence Concept Paper Issue 2 distinguishes between different levels of AI-based assistance. Level 1 applications enhance human capabilities, while Level 2 introduces “human–AI teaming,” in which an AI-based system may take decisions subject to human oversight.
EASA’s framework places particular importance on:

  • AI assurance
  • learning assurance
  • explainability
  • human factors
  • human–AI interaction
  • ethics-based assessment
  • operational oversight

In November 2025, EASA published NPA 2025-07 on AI trustworthiness. The proposal aims to establish detailed specifications, acceptable means of compliance and guidance material for the safe use of AI in aviation, in response to the EU AI Act. This does not mean that a human operator must permanently make every individual decision. It means that an accountable organisation must be able to demonstrate that the AI system was properly designed, assessed, integrated, monitored and controlled.

How the EU AI Act Affects Aviation

The EU Artificial Intelligence Act establishes a risk-based regulatory framework. Under Article 6, an AI system can be classified as high-risk when it is intended to serve as a safety component of a regulated product—or is itself such a product—and the relevant product is subject to the required conformity-assessment framework.
For high-risk systems, the Act establishes requirements concerning:

  • continuous risk management
  • data and data governance
  • technical documentation
  • automatic record-keeping
  • transparency and instructions for use
  • human oversight
  • accuracy, robustness and cybersecurity
  • quality-management and post-market monitoring

Article 14 requires high-risk AI systems to be designed so that they can be effectively overseen by appropriately authorised people. Depending on the system and its risks, the person responsible for oversight must be able to understand its limitations, identify anomalies, interpret its output and, where appropriate, disregard, override or interrupt the system.
These obligations are especially relevant in aviation. A nominal “human in the loop” provides little safety value if the pilot or controller cannot understand the AI’s limitations, does not have enough time to intervene or has been trained to trust its output almost automatically.
Importantly, the AI Act is primarily a regulatory and compliance framework. It does not, by itself, determine every civil claim or decide who must compensate every accident victim. Liability must also be considered under product-liability law, aviation law, contractual rules, national tort law and, where relevant, criminal law.

Software and AI as Products

The EU’s revised Product Liability Directive—Directive (EU) 2024/2853—expressly brings software within the product-liability framework. Its provisions are designed to cover AI systems as well as conventional software.
This is significant for aviation because a defective digital component can be as safety-critical as a defective physical component.
Potential defects may include:

  • unsafe system design
  • inadequate training or validation data
  • misleading instructions or warnings
  • insufficient cybersecurity
  • an unsafe software update
  • failure to supply a safety-related update
  • inadequate ability to explain or trace a safety-critical output

Depending on the circumstances, the producer of an AI system, a component manufacturer, an importer, an authorised representative or another relevant economic operator may fall within the liability chain.
The Directive also addresses situations involving several potentially responsible parties. Consequently, an accident involving both a defective AI component and an operator’s inadequate deployment procedures would not necessarily have to be attributed to only one organisation.
EU member states are required to transpose the Directive into national law by 9 December 2026, and its new rules apply to products placed on the market or put into service after that date. The precise outcome of an individual case will therefore still depend on the applicable national law, the relevant product and the date on which it entered the market.

Recommended: Exploring the Human–Computer Interaction Dimension of the Digital Divide in Air Traffic Management

Who Could Be Liable in an AI-Related Aviation Accident?

The likely responsibility depends on the failure mechanism.

Source of failurePossible responsibility
Defective AI architecture or unsafe algorithmic designAI provider, developer or manufacturer
Unsuitable training, validation or testing dataAI provider or system developer
Incorrect system integrationAircraft manufacturer, avionics supplier, integrator, airline or ANSP
Inadequate operational proceduresAirline, ANSP or other operator
Insufficient user trainingAirline, ANSP or approved training organisation
Failure to install or provide a safety updateManufacturer, provider, maintenance organisation or operator
Misleading interface or incomprehensible alertDesigner, manufacturer, integrator and possibly operator
Unreasonable rejection or misuse of a clear warningPilot, controller or operator, depending on the facts
Cybersecurity weaknessProvider, manufacturer, integrator or operator
Combination of technical and organisational failuresShared or multiple-party liability

This table describes possible responsibility, not an automatic legal result. The governing jurisdiction, contracts, certification basis, operational rules and available evidence would all matter.

An Air Traffic Control Example

Consider an AI-based conflict-resolution tool used by an air navigation service provider.

The system recommends:
“Turn Aircraft A left heading 270 and descend to FL100.”
The controller accepts the recommendation. A loss of separation follows.

It would be misleading to conclude automatically that the controller is responsible simply because the controller transmitted the clearance. Investigators would need to examine several factors:

  1. Was the AI system approved for that operational function?
  2. Did the system receive accurate surveillance and flight-plan data?
  3. Was the recommendation affected by a software or integration defect?
  4. Were its limitations clearly presented?
  5. Did the controller have enough information and time to evaluate the recommendation?
  6. Had the ANSP provided adequate training and procedures?
  7. Did the interface encourage automation bias?
  8. Did the controller act reasonably under the circumstances?

If the recommendation appeared credible, came from an officially deployed safety tool and could not reasonably be evaluated within the available time, placing the entire burden on the controller would ignore the organisational and technical causes of the occurrence. Conversely, if the controller disregarded an obvious conflict or used the system outside its approved purpose, individual conduct could remain relevant.

Pilots and Air Traffic Controllers Will Not Automatically Carry All Liability

AI does not eliminate professional responsibility. Pilots and air traffic controllers must still comply with applicable procedures, exercise professional judgement and respond appropriately to available information. However, human oversight must be meaningful.
An organisation cannot reasonably deploy an opaque, highly automated system and then assume that the final human operator carries all responsibility merely because an override button exists. Effective oversight requires sufficient authority, competence, system knowledge, situational awareness and time to intervene.
This issue is closely connected to automation bias and the “out-of-the-loop” problem. As automation becomes more reliable and more authoritative, human operators may become less able to identify the rare occasions on which it is wrong.
That makes interface design, workload, training and explainability part of the legal accountability discussion—not merely technical or human-factors considerations.

What About Airlines and Passenger Compensation?

Liability towards passengers must be distinguished from responsibility for creating the underlying AI defect.
In international carriage, passenger claims may fall within the established airline-liability framework of the Montreal Convention and the national rules implementing it. An airline may therefore face obligations towards passengers even when the technical origin of an accident lies in software supplied by another company.
The airline or its insurer may subsequently seek recovery from a manufacturer, supplier or other responsible party. In practice, the party compensating a passenger and the party ultimately responsible for the defect may not be the same.

Civil, Regulatory and Criminal Responsibility Are Different

An AI-related event could produce several parallel legal processes:

  • Safety investigation: establishes causes and makes safety recommendations rather than assigning civil or criminal blame.
  • Regulatory enforcement: examines compliance with aviation, certification and AI requirements.
  • Civil litigation: determines compensation for death, injury or property damage.
  • Product-liability proceedings: examine whether the AI-enabled product was defective.
  • Contractual claims: allocate losses between manufacturers, providers, integrators and operators.
  • Criminal proceedings: may arise under national law where conduct reaches the required level of negligence, recklessness or intent.

These processes apply different legal tests. A safety investigation’s finding of a contributing factor does not automatically determine civil or criminal liability.

European occurrence-reporting law also seeks to protect safety reporting through just-culture principles while preserving the possibility of action in cases involving serious misconduct. This distinction will remain important when professionals report errors involving AI systems.

Does Legal Liability Make Fully Autonomous Aviation Impossible?

Not necessarily.

The lack of legal personality for AI creates an accountability challenge, but it is not an absolute legal barrier to autonomous aviation. Law can allocate responsibility to the organisations that place an autonomous system into service, exercise control over it, benefit from its operation or are best positioned to manage its risks.
A future autonomous aircraft or AI-operated ATM function could therefore exist without making the AI itself a legal person. The operator, manufacturer, system provider or another designated entity could be required to carry responsibility and insurance.

The more difficult question is whether regulators can be satisfied that such a system:

  • achieves an acceptable level of safety
  • behaves safely outside its training distribution
  • remains secure against cyber threats
  • produces adequate evidence for certification
  • can be monitored throughout its operational life
  • has a safe response to unexpected conditions
  • provides sufficient records for accident investigation
  • operates within a clear liability and insurance framework

For this reason, the foreseeable path is more likely to progress from human control to human–AI teaming and then towards supervision of increasingly autonomous systems, rather than moving directly to aviation without operational human involvement.

The Future: From Human Error to Lifecycle Accountability

In conventional aviation investigations, attention often focuses on the last person who took an operational action. AI makes that approach increasingly inadequate.

A safety-critical AI output may be shaped by decisions made months or years earlier: selection of training data, safety requirements, interface design, system integration, software updates and organisational procedures.

The central legal question will therefore evolve from:

Who made the final mistake?

to:

Where did the AI safety-assurance and accountability chain fail?

The answer may involve developers, manufacturers, airlines, ANSPs, maintenance organisations and operational personnel at the same time. Artificial intelligence will not become legally responsible simply because it becomes operationally powerful. The organisations behind it will need to demonstrate who controls the system, who monitors it, who can intervene and who bears the consequences when it fails.

That accountability framework may prove just as important as the technology itself in determining how far aviation autonomy can safely advance.

References

This article provides a general analysis of developing aviation and AI regulation. It does not constitute legal advice for any particular accident, jurisdiction or organisation.

Scroll to Top