What happens when AI gets it wrong?
As long as everything works well, the use of AI is almost imperceptible. It helps us automate, make decisions, and streamline processes. After a while, using it feels completely natural in every field. These systems are trusted more and more, and with that trust they are given ever greater decision-making power. That is precisely why the question matters: what happens when, one day, it doesn't work well?
Because of the name "artificial intelligence," many people imagine some kind of independent intelligence, but that is far from the case. AI solutions do not operate on their own: a human prepares them for every task, they learn from the data fed into them, and they follow predefined patterns. Yet while a human error is easier to trace, with AI it is much harder to pinpoint where responsibility lies. When a colleague makes a mistake, it is usually clear who made the decision and on what basis, and it is also clear how it can be corrected. But when an AI system offers a recommendation and someone makes a decision in response to it, it becomes difficult afterwards to say who actually decided. This is the so-called responsibility gap: there is a consequence, but no clearly responsible party.
In such cases, many companies argue that "the AI only helped," but regulatory logic does not work that way. The AI Act was created precisely so that, in situations like these, we can see the boundaries and the framework clearly. And here, according to one of its core principles, what matters is not whether the system makes the final decision, but whether it materially influences it. If it scores, ranks, pre-screens, or recommends, then it already affects the outcome even if, on paper, a human makes the decision. It is important to clarify, however, that the AI Act primarily governs who has which obligations around the system; the question of actual liability for damages is left largely to national law and to product-liability rules.
This is where the question of who takes the blame gets more interesting.
The AI Act names who bears which responsibility, because the regulation separates out the different actors. There is the one who develops the system and places it on the market under their own name; we call this party the provider. There is the one who uses the finished system day to day in their own processes; this is the deployer. Between the two there are differences in responsibility, which the regulation defines precisely.
Beyond having to ensure that the system works properly, the provider must be able to prove that they have tested it, documented it, and thought through the possible scenarios. The deployer's responsibility begins at the point of use: how they apply the system, whether they provide human oversight, whether they follow the instructions for use, and whether they inform those affected.
The provider and the deployer are the two main actors, but the chain is longer and a little more complex than that. It may also include a distributor, who passes on the finished system without altering it. Their responsibility is more limited, but not zero: they too must make sure the product's documentation is in order. And if the system happens to come from outside the Union, another actor steps in — the importer — who must verify that the manufacturer has carried out its conformity obligations before the product reaches the market. The regulation, then, does not look for a single responsible party; it follows the system's journey from development all the way to actual use, and assigns an actor to every stage.
The responsibility gap that at first seemed impossible to resolve is, in fact, only apparent: when a problem arises, when something goes wrong, responsibility does not disappear behind the machine; it is distributed among the actors. The developer — the provider — is liable if the system did not work as promised, or if its documentation was incomplete. The deployer is liable if they failed to provide genuine human oversight, or if they used the system other than as intended. The "blame" does not vanish; it is shared, yes, but it always has an owner.
Some companies present artificial intelligence as a mere supporting tool. Under the AI Act, however, this only holds up if the system does not rank, score, pre-screen, or influence the outcome. Human oversight must not be a formality: the regulation expects there to be someone who can genuinely override the system and stop it when necessary.
On the other side, there is the person whom all of this affects. The AI Act did not think only of companies; it also grants rights to the person standing at the end of the decision. If someone is subject to an adverse decision, they can request a review and an explanation of the basis on which it was made. And if that is not enough, they can also lodge a complaint with the supervisory authority.
AI systems become truly trustworthy precisely because, when they get it wrong, there is someone to turn to. The machine does not take the blame; behind it there is always someone who decided to develop it, to use it, or to rely on it. Perhaps that is exactly the point: the AI Act does not promise that systems will never fail; it promises that responsibility will not disappear behind the machine.
Try the AI Act risk classifier
Find out in 5 minutes which risk category your AI system falls into — free, 100% private, with a detailed PDF result.