Ten years ago, I worked on liability for self-driving cars. The question AI raises today - who answers for a wrong, biased or unethical output? - has the same shape, and largely the same answer. In this article, I briefly map the autonomous-vehicle framework onto AI, across two axes that keep surfacing in many exComs: liability and reputation.


The news was shared at the beginning of the summer: a German court held Google directly liable for false statements generated by its "AI Overviews", considering it as Google's own content. The defence that "users can verify it themselves" did not hold.

In France, a Mistral representative said before the Assemblée that a model can produce a song "in the style of" J-J Goldman without ever using his lyrics - only what others wrote about his style. Different battlefield, but same question: who is liable for what the model produces?

Two questions still come up in our exComs: impact on 1/ liability and 2/ reputation of "wrong" - or worse, "biased / non-ethical" - recommendations from AI.

The experience of autonomous vehicles

On liability, I worked on this exact problem ten years ago... for autonomous vehicles. The answer came first through the UK: a "single-insurer model". The victim is compensated first by the front-facing party. That party then has recourse up the chain (e.g. the manufacturer or software provider).

The AI version is similar:

  • In B2B/C, the first "B" (the one putting the solution in your hands) answers to the customer.
  • In B2B2x, the middle B compensates first, then takes recourse against the upstream model provider - and, hopefully, insures against the serial risk.

The EU's revised Product Liability Directive now writes this down: software and AI are "products" under strict liability, and if you build on someone else's model, you are the "manufacturer" of the combined product.

Reputation, another well-known risk

The same applies on reputation. When a tribunal held Air Canada liable for its chatbot inventing a refund policy in 2024, the airline's defence "the chatbot is a separate entity" was dismissed. While the direct cost was limited to CAD 812, the brand damage was huge, with coverage from the BBC to the Washington Post.

A biased or off-tone recommendation isn't a new category of risk: it's the conduct and brand risk we already govern. The twist is scale: one flaw becomes systematic and instantly shareable. The controls are just as known (bias testing, human review, monitoring) and, for insurers, most of them already exist.

Implications for AI governance

So where does this land, concretely? 2 main axes:

  • Beyond the familiar questions of sovereignty and security, the liability scheme is what you actually negotiate into your contracts with AI providers. A French representative from a leading AI provider recently told me that most of their "sales" work is, in practice, contract drafting. The protection lives in the agreement - not in a disclaimer.
  • Ethics isn't a side topic for us: it's the core of what we do at AXA, as we shared again at Vivatech. "Augmenting" our agents and distribution networks is not a buzzword: it's a pragmatic, deliberate use of AI that keeps human judgment in the driver's seat — and, ultimately, serves our clients better.