Home Reviews About
Twenty of Time

the EU AI Liability Directive reshapes surveillance tech accountability

The European Union has spent the last few years building what may become the most consequential regulatory scaffolding for artificial intelligence anywhere in the world. After the AI Act entered into force in 2024, Brussels turned its attention to a quieter but equally important piece of the puzzle: who pays when AI causes harm. The proposed AI Liability Directive would shift the cost of damage from injured people to the companies that design, deploy, or profit from intelligent systems. For surveillance technology, this is not a minor adjustment but a structural change that could finally give victims of algorithmic overreach a realistic path to compensation.

Australia sits on the other side of the world from Brussels, yet ripples from EU regulation tend to wash up on local shores with surprising speed. Compliance officers in Sydney and Melbourne routinely track EU policy as a bellwether, and consumers already feel the indirect effects of the General Data Protection Regulation whenever they use European services. The question of who is responsible when surveillance cameras and biometric scanners misfire in Westfield centres, train stations, and regional councils is no longer academic.

The stakes are concrete. If a face recognition system misidentifies a passerby and that person is wrongly detained, or if a predictive algorithm flags an innocent family for welfare fraud checks, the harm is real and lasting. The Directive tries to balance innovation with protection for ordinary people. Understanding how it works, and where it falls short, matters for anyone living under the gaze of these systems.

Origins and purpose of the directive

Brussels first floated harmonised AI liability rules in 2022, alongside the broader AI package. Existing product liability frameworks were designed for tangible goods, not adaptive software. When an AI-driven surveillance camera wrongly matches someone to a suspect database, the chain of responsibility runs through datasets, model training, vendor contracts, and oversight.

The Directive introduces two key mechanisms. The first is a presumption of causation, meaning that if a claimant can show that an AI system likely caused the harm and that the defendant failed to comply with relevant obligations, the court can infer a causal link. The second is a disclosure right, allowing victims to demand access to technical information about how a system was built and operated. Together, these tools attempt to level a playing field where individuals rarely have the technical resources to dissect proprietary algorithms.

Critics argue the proposal is too cautious and leaves too much room for defendants to claim trade secret protection. Supporters counter that it is a pragmatic first step, calibrated to survive lobbying from Europe's powerful tech sector. Either way, the Directive sends a signal that the era of "move fast and break things" carries a price tag, and that price is no longer borne only by users.

Surveillance tech in the regulatory crosshairs

Surveillance technology occupies an uncomfortable position in the AI landscape. Unlike chatbots or recommendation engines, surveillance tools are explicitly designed to watch, classify, and act upon people. Biometric identification, emotion recognition, behaviour prediction, and real-time tracking all involve sensitive inferences about individuals who often have no idea they are being analysed. The harms from these systems include wrongful arrests, exclusion from services, and chilling effects on lawful assembly.

Under the proposed Directive, vendors of biometric surveillance systems would face a higher duty of care than developers of less intrusive AI. A company selling a face recognition camera to a shopping centre in Parramatta or a stadium in Brisbane would need to demonstrate that its product was reasonably safe and properly documented. If the system disproportionately misidentifies women, people with darker skin, or those with disabilities, the vendor could be held liable even if the customer used the product exactly as advertised.

This shifts a longstanding industry pattern. Until now, surveillance providers have often shielded themselves behind end-user agreements and disclaimers. The Directive would pierce that veil, forcing companies to invest in rigorous testing, documentation, and post-deployment monitoring. For an industry accustomed to light-touch oversight, that is a significant cultural shock. The same logic extends to consumer devices, where smart speakers quietly listen for wake words; Australians can learn to remove hidden microphones from smart speakers as a first step.

How the burden of proof actually changes

Proving that an AI caused harm is daunting in most legal systems. The AI Liability Directive attacks this asymmetry by reversing the presumption of causation in certain cases. If a claimant can show that the harm is consistent with a known failure mode of the AI and that the defendant had access to relevant technical information, the burden shifts.

This is more than a procedural tweak. It transforms litigation from an evidence-gathering marathon into something closer to a contested debate. For a small business owner in Adelaide whose premises are swept by a privately owned facial recognition network, this could mean the difference between a viable complaint and a quiet surrender. The Directive does not eliminate the technical challenges, but it removes some of the most punishing obstacles that currently keep ordinary people out of court.

Disclosure rights matter just as much. Claimants can request information about training data, model architecture, and deployment logs. Trade secrets are protected, but only to a degree. Courts can order disclosure when necessary to adjudicate a claim, and confidentiality rings can shield sensitive material from public view. The practical effect is that surveillance vendors will need to keep far better records than they do today, which makes failure analysis and accountability far more feasible.

Real-world stakes for Australians

Australian deployments of surveillance technology are no longer confined to government agencies. Private landlords use licence plate readers in apartment car parks. Retail chains track shoppers through their stores using AI-driven video analytics. Most of these use cases operate with very little external scrutiny.

When these systems fail, the consequences can be deeply personal. A wrong facial match can lead to police attention, damaged reputation, and lost employment. Behavioural analysis tools can flag innocent people based on posture or fidgeting. Cases involving AirTag stalking legislation gaps show how quickly small tracking devices become tools of harassment, and how poorly equipped current laws are to respond.

The AI Liability Directive would not directly apply to Australian vendors or users, but its influence will be felt. Global companies tend to design products to the highest standard they operate under, and the EU market is simply too large to ignore. A product too risky for Europe will be harder to insure, harder to defend in court, and harder to sell to risk-averse enterprise buyers.

Comparing EU and Australian approaches

Australia does not yet have a comprehensive AI law. The government released a voluntary AI Ethics Framework and has signalled that binding regulation is coming, but the timeline remains vague. The Office of the Australian Information Commissioner handles privacy complaints under the Privacy Act, and the eSafety Commissioner deals with online harms, but neither has the reach or technical mandate to oversee algorithmic decision-making in the way the EU's AI Office does.

This regulatory gap is not necessarily a disaster. It gives Australian regulators the chance to learn from Europe's mistakes and avoid duplicating them. But it also leaves consumers exposed. A worker in a Melbourne warehouse monitored by an AI-driven productivity system has limited recourse if the algorithm penalises them unfairly. A renter in Perth whose building uses facial recognition cannot easily find out where their biometric data is stored or how long it is kept.

The AI Liability Directive is not a perfect model for Australia to copy. Its disclosure rules are complex, and its reliance on presumptions may not translate cleanly to common law traditions. It counters the "innovate now, regulate later" mindset in Canberra. A clear liability regime, even a modest one, would give Australian courts tools they currently lack.

The hidden risks of opaque algorithms

Opacity is the surveillance industry's most prized asset. Vendors argue that their algorithms are proprietary and that revealing how they work would undermine competitive advantage. Sometimes this is genuine; sometimes it is a convenient way to avoid accountability. The AI Liability Directive acknowledges this tension by allowing disclosure only when necessary to resolve a claim, and by protecting trade secrets through confidentiality orders.

Even so, opacity is a feature, not a bug, in many surveillance products. A face recognition system that can be easily audited is a system that can be more easily circumvented by those who wish to evade detection. Vendors push back against transparency requirements, arguing that public scrutiny aids criminals. This argument has some merit, but it is often deployed selectively. The same companies that resist external audits happily sell to private investigators, debt collectors, and stalkers.

For consumers, the practical lesson is that opacity cuts both ways. A system that cannot be examined cannot be trusted, but a system that is fully open can be gamed. The Directive attempts to find a middle ground, and whether it succeeds will depend on how courts interpret the disclosure rules. Australians who care about this issue should watch the early cases and consider how similar principles might be applied locally.

What businesses and individuals can do

For businesses operating in or selling to the EU, the message is clear: start treating AI documentation as a compliance essential, not a nice-to-have. That means keeping detailed logs of training data, model versions, deployment configurations, and known limitations. It means conducting regular bias audits. For Australian exporters, these practices are increasingly table stakes.

For individuals, the Directive offers hope but no immediate remedy. Australians cannot file claims under EU law unless they are directly affected by a company's EU operations. The more practical path is to push for stronger domestic rules that give regulators like the OAIC real teeth over algorithmic systems, and to back legislative efforts mandating transparency for biometric surveillance in public and private spaces.

Practical steps matter as well. Reviewing the SIM swapping protection guide helps you understand where your digital identity is most exposed. These small actions buy time while the legal scaffolding catches up.

The EU's AI Liability Directive is not a finished product. It will be tested in court for years. The era of unaccountable surveillance is drawing to a close in jurisdictions willing to follow Europe's lead, and Australians have a direct stake in where that trajectory ends. The right to be free from arbitrary surveillance is one of those quiet protections that only matters once it is gone.