Criminal responsibility for ‘hard AI crime’: drawing bright lines in the aftermath of the EU AI Act
Author(s)
Romanò, Leonardo
Date Issued
June 5, 2025
Type
Doctoral Thesis
Abstract
The rapid proliferation of autonomous AI systems across high-stakes domains — healthcare, financial markets, transportation, and beyond — is generating a category of harm that existing criminal law frameworks are structurally ill-equipped to address. This dissertation examines what it terms “hard AI crime”: harmful outcomes caused by AI systems operating through emergent, self-learned behaviours that were neither explicitly intended nor reasonably foreseeable by the humans involved in their design, development, or deployment. Unlike cases in which AI is merely a tool of human wrongdoing, hard AI crime arises precisely where autonomous machine behaviour displaces meaningful human control and foreseeability, triggering a “criminal responsibility trilemma”: AI systems cannot be punished in any meaningful legal sense; harmful outcomes cannot reliably be traced back to culpable human actors; yet society cannot tolerate impunity when criminally significant harms occur.
Building on the EU AI Act (Regulation 2024/1689) as its conceptual foundation, the study critically analyses the capacity of traditional criminal law categories — actus reus, mens rea, causation, foreseeability — to govern AI-caused harm, and finds them systematically deficient in the face of AI's defining characteristics: opacity, unpredictability, and substantive operational autonomy. The dissertation advances the doctrine of permissible risk (erlaubtes Risiko) as the central organising principle for drawing the boundary between justified responsibility gaps, which reflect socially acceptable technological risk-taking, and unjustified ones, which reflect negligent or reckless conduct deserving criminal sanction.
The analysis proceeds in four main stages. First, it addresses the criminal liability of AI providers, arguing that the AI Act's ex ante and ex post obligations offer a viable foundation for defining standards of due care, and proposing a scenario-based risk assessment model that moves beyond the Act's static categorical classifications toward a more contextually sensitive liability framework. Second, it turns to AI deployers, examining how the AI Act's human oversight requirement translates — or fails to translate — into actionable criminal responsibility across three paradigmatic human-machine interaction models: human-in-the-loop (illustrated through AI-assisted clinical decision-making), human-on-the-loop (autonomous vehicles), and human-outside-the-loop (SAE Level 4 automation). Third, adopting a de jure condendo perspective, it evaluates the case for anticipatory criminal intervention through new endangerment offences targeting the negligent release of insufficiently safeguarded AI systems, as well as the prospects for corporate criminal liability grounded in organisational fault. Fourth, it argues in favour of harmonised criminal liability rules at EU level, given the inherently cross-border nature of AI development and deployment and the significant knowledge asymmetries among Member States.
Throughout, the study maintains a methodologically conservative stance: it rejects proposals for direct criminal liability of AI systems as conceptually incoherent and normatively undesirable, affirming instead the principle nulla poena sine culpa as a non-negotiable constraint. The dissertation draws on comparative analysis across Italian, French, German, and UK law, as well as a broad international criminal law literature, to ground its theoretical proposals in concrete legal contexts.
The study concludes that the central task for criminal law in the age of AI is not the elimination of all responsibility gaps — an impossible demand given AI’s inherent unpredictability — but the principled definition of their acceptable limits. Achieving this requires both doctrinal refinement of existing negligence standards and targeted legislative innovation, ideally coordinated at the European level, so that the law can function as a genuine last resort: one that neither stifles socially beneficial innovation nor tolerates negligent impunity.
Additional information
Dottorato di ricerca in Diritto dei mercati europei e globali. Crisi, diritti, regolazione
Tesi di dottorato. 37. ciclo
Tesi di dottorato. 37. ciclo
File(s)![Thumbnail Image]()
Name
lromano_tesid.pdf
Size
2.63 MB
Format
Adobe PDF
Checksum (MD5)
d15516dc28acbf3508f9197bbbf46115
