Cyber Risk GmbH

Cyber Risk GmbH Cyber Risk GmbH, Handelsregister des Kantons Zürich, Firmennummer: CHE-244.099.341. You may visit: https://www.cyber-risk-gmbh.com

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (...
21/08/2026

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (1/4).

The withdrawn AI Liability Directive has not been replaced by any single legal instrument. The regulatory and remedial space that the proposed Directive was intended to occupy is now addressed only partially and cumulatively through a fragmented, multi layered legal framework that includes the revised Product Liability Directive, the AI Act, applicable national rules of tort and delict, contractual remedies, data protection and antidiscrimination law, and sector specific liability regimes.

A material residual liability and remedial gap remains. This is particularly significant for:

1. Non contractual, fault based claims arising from AI enabled services or decision making.

2. Claims for pure economic loss falling outside harmonised product liability rules.

3. Certain forms of harm affecting fundamental rights or legally protected interests.

4. Cases in which the opacity, complexity or autonomous characteristics of an AI system make it disproportionately difficult for a claimant to establish the factual and causal nexus between the defendant's conduct, the operation or output of the AI system, and the damage alleged.

The evidentiary dimension of that gap is especially important. The proposed AI Liability Directive was expressly designed to address situations in which conventional national rules governing proof of fault and causation could place an injured party at a structural disadvantage because the relevant evidence is technically inaccessible, controlled by the defendant, or obscured by the complexity and opacity of the AI system.

The withdrawal of the AI Liability Directive leads to divergent outcomes across the Union. This creates incentives for jurisdictional arbitrage, regulatory shopping and, where procedural rules permit, forum shopping. In the absence of a harmonised horizontal regime governing fault based liability for AI related harm, comparable conduct gives rise to different liability exposures depending on the Member State whose substantive and procedural law is applicable.

Divergences arise in the standard of care, the allocation and standard of proof, presumptions of causation, disclosure of evidence, the recognition of pure economic or non material loss, limitation rules, and the assessment of damages.

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (...
21/08/2026

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (2/4).

The 5 Post AI Liability Directive indicators | Legal Intelligence.
We monitor five indicators.

1. National divergence, the fragmentation indicator.

This is the primary indicator. The question is whether materially comparable AI related harm produces materially different civil law consequences, depending on the Member State in which the claim is determined.

We monitor divergence in legislation expressly dealing with AI liability, but also across the entire liability architecture, including the legal characterisation of fault, use of AI Act obligations in establishing a standard of care, recoverability of pure economic and non-material loss, treatment of discrimination and fundamental rights harms, access to technical evidence, disclosure obligations, presumptions and standards of causation, limitation periods, remedies, and calculation of damages.

The legal intelligence trigger would be: The same or substantially equivalent AI conduct begins producing systematically different liability outcomes across Member States because of differences in national substantive or procedural law.

2. First wave AI litigation, the doctrinal formation indicator.

The first significant cases will matter, as courts will have to translate the AI Act's regulatory obligations into existing private law categories.

The critical litigation question will be: What private law consequences, if any, follow from breach of an obligation imposed by the AI Act?

A claimant may argue that non compliance with obligations concerning risk management, data governance, documentation, logging, transparency, human oversight, accuracy, robustness or cybersecurity constitutes evidence of negligence or otherwise contributes to establishing breach of the applicable duty or standard of care.

That does not mean that every AI Act infringement automatically gives rise to damages. The cause of action, protected interest, fault requirement, causation and recoverable damage will still have to be established under the applicable liability regime.

We will monitor whether national courts treat AI Act obligations as regulatory requirements, or as relevant evidence of civil fault, or, more significantly, as normative standards capable of materially shaping the applicable private law duty of care.

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (...
21/08/2026

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (3/4).

3. CJEU preliminary references, the Judicial Harmonisation Indicator.
As national courts encounter disputes between the AI Act, Product Liability Directive, GDPR, consumer protection, equality law, fundamental rights and national tort law, questions of Union law interpretation may reach the Court of Justice (under Article 267 TFEU).

The questions referred will be more important than the number of referrals. We will watch particularly for references concerning the meaning and legal effect of AI Act obligations, whether particular Union provisions confer rights or protect interests relevant to damages claims, the relationship between AI Act non compliance and product defectiveness, evidentiary consequences of missing documentation or logs, causation, effective judicial protection, and the interaction between Union rules and restrictive national rules governing remedies.

The liability challenges will move from national doctrinal experimentation to European judicial harmonisation. This could create a form of harmonisation without AILD 2.0 (not comprehensive legislative harmonisation, but incremental harmonisation through CJEU jurisprudence).

4. Insurance differentiation, the monetisation of uncertainty indicator.

Insurers price prospective liability risk. Insurance markets will detect legally significant divergence before legislators formally recognise it.

We will monitor changes in underwriting questionnaires, exclusions, endorsements, sublimits, deductibles and premiums relating specifically to AI.

5. Jurisdictional arbitrage, the internal market distortion indicator.
This is the most sensitive indicator and should be built carefully. We will avoid suggesting that companies can simply select whichever Member State offers the weakest tort regime. The intelligence question is narrower: Does divergence in AI related civil liability begin influencing legally available choices concerning corporate structuring, contractual arrangements, establishment, deployment, distribution, insurance, litigation strategy, or other connecting factors?

If so, we begin moving from legal fragmentation to economically consequential jurisdictional arbitrage.

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (...
21/08/2026

20 August 2026, Update - The AI Liability Directive has been withdrawn, but the underlying liability gap still exists. (4/4).

We distinguish three concepts:

Regulatory arbitrage. Structuring activity to benefit from differences between applicable regulatory/liability environments.

Jurisdictional arbitrage. Structuring legally relevant connections to obtain a more favourable jurisdictional or governing law position where Union law permits.

Forum shopping. Selecting among legally available fora after or in anticipation of a dispute. (Forum shopping describes the conduct of a litigant who, where more than one court is legally competent to hear substantially the same dispute, selects the forum perceived to offer the most advantageous legal or procedural environment.)

The five indicators should be read together. The intelligence value comes from correlation.

After Rotterdam (13 August 2026). The dangerous space between accident and attack.Operational denial without destruction...
16/08/2026

After Rotterdam (13 August 2026). The dangerous space between accident and attack.

Operational denial without destruction, hybrid stress test is highly recommended.

In this oil sector hybrid stress test, the adversary does not destroy refineries, pipelines or terminals. It may be sufficient to create circumstances in which the operator, harbour authority, government or insurer concludes that normal operations cannot safely continue.

Possible triggers include drone presence, navigation interference, fabricated intelligence, bomb threat, suspicious vessel, compromised safety telemetry, false leak report.

The operator then suspends operations voluntarily. From an economic standpoint, the result can resemble a successful kinetic attack.

Rotterdam (13 August 2026), an explosion occurred at Gunvor's petroleum storage facility, killing one person and injuring six. Authorities said there was no immediate evidence of sabotage.

At approximately the same time, there were power disturbances affecting the wider port area, including an interruption affecting ExxonMobil's refinery. Authorities stated that there was no immediate evidence that the power problems were related to the explosion.

Even if events are genuinely unrelated, the authorities could perceive correlation (false event correlation). This could lead to precautionary shutdown, political escalation, market manipulation, economic consequences.

Operational denial with or without destruction, these hybrid stress tests are highly recommended.

“Hybride Einflussmaßnahmen sind häufig nicht per se illegal, aber durchaus illegitim.” (Hybrid influence measures are of...
12/08/2026

“Hybride Einflussmaßnahmen sind häufig nicht per se illegal, aber durchaus illegitim.” (Hybrid influence measures are often not unlawful per se, but may nevertheless be illegitimate).

That is legally fascinating. It expressly recognizes the problem we repeatedly encounter with hybrid activity. The individual components do not have to constitute unlawful acts. The significance can arise from orchestration and cumulative effect.

The agencies must understand the background and effects of hybrid influence activities and trace their methods and dissemination channels.

Proposal for the Cloud and AI Development Act (CADA) – Read ANNEX II please!Annex II is the substantive core of the CADA...
10/08/2026

Proposal for the Cloud and AI Development Act (CADA) – Read ANNEX II please!

Annex II is the substantive core of the CADA sovereignty regime. Article 16 creates the legal framework, but Annex II tells us what the Commission means.

Four assurance levels are cumulative and progressively change the nature of the inquiry. Level 1 establishes a surprisingly substantial European nexus. Levels 2–4 address personnel, software, cybersecurity certification, AI use, corporate control, and exposure to third country sovereign authority.

1.1(a): “the cloud computing service provider is established in the Union.”

1.1(b): infrastructure and assets must be located in the Union, including those of subcontractors involved in providing the service, unless the public-sector body expressly requires otherwise.

That means the perimeter extends beyond the immediate provider. The Commission is looking through the contractual structure into the delivery chain.

1.1(c) is stronger. Customer data expressly includes metadata and telemetry data. The requirement covers data that is processed, stored, and transferred.

The proposed rule follows the data lifecycle: “at any time, including before, during or after the configuration or use of the service.” This is end to end territorial containment.

Please continue reading. For Union assurance level 2, cloud computing service providers must meet cumulative criteria, starting with: (a) the audited provider and the subcontractors which are involved in the provision of the audited service are established in the Union.

Hybrid regulatory shock cascade stress test, highly recommended.This hybrid stress test can examine how an initial legal...
09/08/2026

Hybrid regulatory shock cascade stress test, highly recommended.

This hybrid stress test can examine how an initial legal, regulatory, supervisory, trade, sanctions, competition, or sovereign policy intervention may propagate across financial, technological, operational, geopolitical, informational, and behavioural domains, producing nonlinear amplification, algorithmic market reactions, liquidity deterioration, counterparty responses, contagion, and subsequent governmental or regulatory escalation.

Possible scenario: The EU Cloud and AI Development Act that identifies EU dependence on providers controlled from third countries as generating risks from extraterritorial third country laws, reduced control over data and infrastructure, and economic or political influence. Washington reads it as discrimination, market access, procurement restrictions, protectionism, technical barriers, and disproportionate regulation affecting US technology firms.

Regulatory driven destructive cycles are nonlinear feedback mechanisms through which an initial regulatory or sovereign intervention generates successive legal, financial, behavioural, and market responses that amplify one another, causing the ultimate market and economic impact to become materially greater than the direct effect of the initiating measure.

The CER Directive has a much greater influence on national legislative architecture than many initially expected.Many ex...
06/08/2026

The CER Directive has a much greater influence on national legislative architecture than many initially expected.

Many experts viewed NIS 2 as the dominant instrument, and CER as a complementary dtrective. In practice, several EU Member States (like Germany and Finland) used the CER Directive as an opportunity to redesign their broader national resilience framework.

Earlier cybersecurity legislation covered the protection of information systems against cyber attacks. The underlying assumption was that cyber security was a specialized technical field distinct from physical security, emergency planning, or civil protection.

The combined adoption of NIS 2 and the CER Directive challenges that assumption. The European law recognised a cyber attack may disable physical infrastructure, physical sabotage may compromise digital communications, supply chain disruption may simultaneously affect operational technology, logistics and essential services, and disinformation may accompany technical attacks in order to magnify their societal consequences. The legal response focuses on resilience of the service, not protection of a particular asset.

Recent suspected hybrid attacks involving unmanned aerial systems against critical infrastructure in Germany demonstrate why the traditional distinction between cyber risk and physical risk is becoming increasingly difficult to maintain in practice.

... in view of prevailing geopolitical risks.We have an important paper: "Geopolitical risk reverse stress test of euro ...
01/08/2026

... in view of prevailing geopolitical risks.

We have an important paper: "Geopolitical risk reverse stress test of euro area banks. 2026 SSM thematic stress test: final results," from the European Central Bank (ECB).

ECB Banking Supervision changes banks’ management of geopolitical risk. One of the focus areas concerns banks’ internal stress test projections for capital, liquidity and recovery planning to ensure that banks proactively account for relevant geopolitical events.

Deficiencies in this area may translate into imbalances between risk taking and risk control. This is especially important in an environment in which institutions face economic, financial, operational and competitive headwinds caused by geopolitical events.

"The banks were asked to distinguish between three transmission channels of geopolitical risk: the financial market channel (operating via uncertainty and investors’ risk aversion), the real economy channel (disruptions in trade and commodity markets, economic uncertainty) and the safety and security channel (related to physical risks, conflicts, cyber and hybrid threats)".

Adresse

Dammstrasse 16
Horgen
8810

Öffnungszeiten

Montag 09:00 - 17:00
Dienstag 09:00 - 17:00
Mittwoch 09:00 - 17:00
Donnerstag 09:00 - 17:00
Freitag 09:00 - 17:00

Benachrichtigungen

Lassen Sie sich von uns eine E-Mail senden und seien Sie der erste der Neuigkeiten und Aktionen von Cyber Risk GmbH erfährt. Ihre E-Mail-Adresse wird nicht für andere Zwecke verwendet und Sie können sich jederzeit abmelden.

Die Schule/Universität Kontaktieren

Nachricht an Cyber Risk GmbH senden:

Verknüpfungen

Teilen

Kategorie