Criminal Liability For Ai-Based Cybercrime: Comparative Analysis Of Common Law And Civil Law Approaches
DOI:
https://doi.org/10.38035/jlph.v6i2.2683Keywords:
AI; Comparative ; Criminal Liability; Cybercrime; Mens Rea.Abstract
This study analyzes the fundamental differences between common law and civil law systems in responding to criminal liability for artificial intelligence-based cybercrime. The background of the study covers the significant escalation of crimes utilizing AI, with 87% of global organizations experiencing AI-based attacks in 2024, AI-based fraud losses predicted to reach $40 billion by 2027, and a 223% increase in the trade of deepfake tools on dark web forums. The main problem identified by the research is a critical paradox: as AI technology becomes increasingly sophisticated in facilitating cybercrime, the gap between existing legal regulations and operational realities in the field widens, allowing criminals to exploit ambiguities in accountability to avoid responsibility. The research methodology uses a qualitative comparative legal analysis approach through analysis of primary legal documents from both systems, with case studies in four jurisdictions: the United States and the United Kingdom for common law, and Germany and France for civil law, as well as the supranational framework of the EU AI Act. The results show that the common law system has developed three models of liability—perpetration-via-another, natural-probable-consequence liability, and direct liability—but still faces fundamental difficulties in attributing mens rea to AI systems that lack moral consciousness. In contrast, civil law systems adopt a provider-deployer approach with the mechanisms of Organisationsverschulden in Germany and responsabilité pénale in France, which allow for liability based on organizational negligence, although they often lag behind in responding to technological developments. This study concludes that a hybrid approach is needed that combines the clarity of civil law codification with the adaptive flexibility of common law, as well as cross-jurisdictional harmonization to overcome the challenges of law enforcement in an increasingly autonomous AI era.
References
Abbott, R. (2020). The Reasonable Robot (1st ed.). Cambridge University Press. https://doi.org/10.1017/9781108631761
Abbott, R. B., & Sarch, A. F. (2019). Punishing Artificial Intelligence: Legal Fiction or Science Fiction. UC DAvies Law Review, 53(1). https://doi.org/10.2139/ssrn.3327485
Abdelaziz, D. K. A. (2025). Criminal liability for the misuse and crimes committed by AI: A comparative analysis of legislation and international conventions. Journal of Infrastructure, Policy and Development, 9(1). https://doi.org/10.24294/jipd10722
Affagard, P., & Carvès, M. (2024). Cybersecurity Laws and Regulations France 2025. In ICLG - Cybersecurity Laws and Regulation (1st ed.). ICLG. https://iclg.com/practice-areas/cybersecurity-laws-and-regulations/france
Allahverdiyev, S., & Othman, M. (2022). “Verbandssanktionengesetz” — Corporate Liability for Germany? German Law Journal, 23(4), 637–649. https://doi.org/10.1017/glj.2022.37
Arnal, J. (2025). AI at Risk in the EU: It’s Not Regulation, It’s Implementation. European Journal of Risk Regulation. https://doi.org/10.1017/err.2025.19
Baeyaert, J. (2025). Beyond Personhood. Technology and Regulation, 2025. https://doi.org/10.71265/ssvg8a97
Barkane, I. (2022). Questioning the EU proposal for an Artificial Intelligence Act: The need for prohibitions and a stricter approach to biometric surveillance1. Information Polity, 27(2). https://doi.org/10.3233/IP-211524
Basu, N., & Dave, R. (2025). Comparative Analysis of Laws in AI. Journal of Lifestyle and SDGs Review, 5(3). https://doi.org/10.47172/2965-730X.SDGsReview.v5.n03.pe05575
Bertolini, A. (2025). Artificial Intelligence and Civil Liability. In Think Tank European Parliament. European Parliament. https://www.europarl.europa.eu/thinktank/en/document/IUST_STU(2025)776426
Burri, T. (2022). The New Regulation of the European Union on Artificial Intelligence. In S. Voeneky, P. Kellmeyer, O. Mueller, & W. Burgard (Eds.), The Cambridge Handbook of Responsible Artificial Intelligence. Cambridge University Press. https://doi.org/10.1017/9781009207898.010
Cortez, E. K., & Maslej, N. (2023). Adjudication of Artificial Intelligence and Automated Decision-Making Cases in Europe and the USA. European Journal of Risk Regulation, 14(3), 457–475. https://doi.org/10.1017/err.2023.61
Crawford, G. E., Juhan, J.-L., Kempe-Müller, S., Maclean, F. M., Rubin, M. H., Saarinen, M., & Wybitul, T. (2025, January 31). Upcoming EU AI Act Obligations: Mandatory Training and Prohibited Practices. Latham & Watkins. https://www.lw.com/en/insights/upcoming-eu-ai-act-obligations-mandatory-training-and-prohibited-practices
Davey, O. M., & Sauerwein, L. (2023). Deepfake In Online Fraud Cases: The Haze Of Artificial Intelligence’s Accountability Based On The International Law. Sriwijaya Crimen and Legal Studies, 1(2). https://doi.org/10.28946/scls.v1i2.2654
de Lemos Campos, M. (2024). Comments on the Article Titled “The Regulation of AI Liability in Europe: A Critical Overview of Two Recent Directive Proposals – The (New) AILD and The (Revised) PLD” by Beatriz Garcia. E-Publica, 11(3). https://doi.org/10.47345/v11n3art3
Diamantis, M. E. (2020). The Extended Corporate Mind: When Corporations Use AI to Break the Law. North Carolina Law Review, 98(4). https://scholarship.law.unc.edu/nclr/vol98/iss4/6/
Duflot, A. (2024). Artificial Intelligence in the French Law of 2024. Legal Issues in the Digital Age, 5(1), 37–56. https://doi.org/10.17323/2713-2749.2024.1.37.56
Dyson, M. (2022). The Contribution of Complicity. The Journal of Criminal Law, 86(6). https://doi.org/10.1177/00220183221133439
Ellamey, Y., & Elwakad, A. (2023). The criminal responsibility of artificial intelligence systems: A prospective analytical study. Corporate Law and Governance Review, 5(1), 92–100. https://doi.org/10.22495/clgrv5i1p8
Garrett, B. L. (2025). Artificial Intelligence and Procedural Due Process. Penn Carey Law Journals, 27(5).
Ghigheci, C. (2019). Regulating negligence in French and Italian criminal law. Juridical Tribune, 9. https://www.tribunajuridica.eu/arhiva/An9vS/10.%20Cristinel%20Ghigheci.pdf
Giannini, A. (2023). Criminal behavior and accountability of artificial intelligence systems [Doctoral Thesis, Maastricht University]. https://doi.org/10.26481/dis.20231124ag
Gless, S., & Peralta, A. (2024). Discussion Paper on Criminal Liability Related to AI systems. https://rm.coe.int/cdpc-2024-09-ai-criminal-liability-discussion-paper-final-draft/1680b26f16
Hallevy, G. (2010). The Criminal Liability of Artificial Intelligence Entities - from Science Fiction to Legal Social Control. Akron Intellectual Property Journal, 4(2). https://ideaexchange.uakron.edu/akronintellectualproperty/vol4/iss2/1/
Hallevy, G. (2024). The Basic Models of Criminal Liability of AI Systems and Outer Circles. In D. M. Vicente, R. S. Pereira, & A. A. Leal (Eds.), Legal Aspects of Autonomous Systems (Vol. 4, pp. 69–82). CIDP. https://doi.org/10.1007/978-3-031-47946-5_5
Hargreaves, S. (2024). What has changed in the AI CSAM landscape? https://www.iwf.org.uk/media/drufozvi/iwf-ai-csam-report_update-public-jul24v12.pdf
Hashmi, M. A. I., Butt, M. F., Jawad, M., & Sultan, S. (2025). Criminal Liability in the Age of Autonomous Systems: Rethinking Mens Rea and Actus Reus. The Critical Review of Social Sciences Studies, 3(3). https://doi.org/10.59075/szbtkr93
Horder, J. (2022). Ashworth’s Principles of Criminal Law. Oxford University Press. https://doi.org/10.1093/he/9780192897381.001.0001
Hutapea, N. M. S., Sitepu, D. K. C., Damanik, J., & Sianipar, S. K. L. (2025). Artificial Intelligence and Criminal Liability: A Preliminary Study within the Indonesian Legal System. JIHK, 7(2). https://doi.org/10.46924/jihk.v7i2.330
Jani, C. C., & Rathor, S. P. (2024). A Legal Framework for Determining The Criminal Liability And Punishment For Artificial Intelligence. Tuijin Jishu Journal of Propulsion Technology, 45(1). https://www.propulsiontechjournal.com/index.php/journal/article/view/4056
Janjeva, A. (2025, March 31). UK law enforcement inadequately equipped to tackle AI-enabled crime. The Alan Turing Institute. https://www.turing.ac.uk/news/uk-law-enforcement-inadequately-equipped-tackle-ai-enabled-crime
Jurgens, J., & Cin, P. D. (2025). Insight Report Global Cybersecurity Outlook 2025 . https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf
King, T. C., Aggarwal, N., Taddeo, M., & Floridi, L. (2020). Artificial Intelligence Crime: An Interdisciplinary Analysis of Foreseeable Threats and Solutions. Science and Engineering Ethics, 26(1), 89–120. https://doi.org/10.1007/s11948-018-00081-0
Lalchand, S., Srinivas, V., Maggiore, B., & Henderson, J. (2024, May 29). Generative AI is expected to magnify the risk of deepfakes and other fraud in banking. Deloitte. https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html
Lin, L. S. F. (2025). Organisational Challenges in US Law Enforcement’s Response to AI-Driven Cybercrime and Deepfake Fraud. Laws, 14(4). https://doi.org/10.3390/laws14040046
Ma, J. (2024, August 18). The number of Fortune 500 companies flagging AI risks has soared 473.5%. Fortune.Com. https://fortune.com/2024/08/18/ai-risks-fortune-500-companies-generative-artificial-intelligence-annual-reports/
Makam, G. (2023). Criminal Liability of Robots- A Critical Analysis of the Legal Framework in the US, UK, and Europe. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.4649764
Mantili, R., Putri, S. A., & Fakhriah, E. L. (2025). Compensation for Damages Caused by Artificial Intelligence under Indonesian Civil Law. Pena Justisia: Media Komunikasi Dan Kajian Hukum, 24(1). https://doi.org/10.31941/pj.v24i1.5164
Martin, K. (2025, May 27). AI Cyber Attack Statistics 2025. TechAdvisors. https://tech-adv.com/blog/ai-cyber-attack-statistics/
Maskur, M. A., Masyhar, A., Damayanti, R., Ramada, D. P., & Sanyal, S. (2025). Reimagining Criminal Liability in the Age of Artificial Intelligence: Toward a Comparative and Reform-Oriented Legal Framework. Journal of Law and Legal Reform, 6(4), 1805–1838. https://doi.org/10.15294/jllr.v6i4.35540
Mattia, C. (2024). Corporate Criminal Liability and Artificial Intelligence: Doctrinal Overview, Problems and Perspectives. Open Access Journal of Criminology Investigation & Justice, 2(1). https://doi.org/10.23880/oajcij-16000122
Maundrill, B. (2025, March 7). Majority of Orgs Hit by AI Cyber-Attacks as Detection Lags. Infosecurity Magazine.
Momsen, C. (2023). Implications and Limitations of the Use of AI in Criminal Justice in Germany. KriPoz, 1. https://kripoz.de/2023/01/19/implications-and-limitations-of-the-use-of-ai-in-criminal-justice-in-germany/
Nerantzi, E., & Sartor, G. (2024). ‘Hard AI Crime’: The Deterrence Turn. Oxford Journal of Legal Studies, 44(3). https://doi.org/10.1093/ojls/gqae018
Neuwirth, R. J. (2023). Prohibited artificial intelligence practices in the proposed EU artificial intelligence act (AIA). Computer Law & Security Review, 48. https://doi.org/10.1016/j.clsr.2023.105798
Osmani, N. (2020). The Complexity of Criminal Liability of AI Systems. Masaryk University Journal of Law and Technology, 14(1). https://doi.org/10.5817/MUJLT2020-1-3
Panattoni, B. (2025). Generative AI and Criminal Guilt. In Mimi Zou, C. Poncibò, M. Ebers, & R. Calo (Eds.), The Cambridge Handbook of Generative AI and the Law (1st ed., pp. 392–404). Cambridge University Press. https://doi.org/10.1017/9781009492553.027
Paunio, E. (2009). Beyond Predictability – Reflections on Legal Certainty and the Discourse Theory of Law in the EU Legal Order. German Law Journal, 10(11). https://doi.org/10.1017/S2071832200018332
Pehlivan, C. N. (2024). The EU Artificial Intelligence (AI) Act: An Introduction. Global Privacy Law Review, 5(Issue 1), 31–42. https://doi.org/10.54648/GPLR2024004
Rodrigues, R. (2020). Legal and human rights issues of AI: Gaps, challenges and vulnerabilities. Journal of Responsible Technology, 4. https://doi.org/10.1016/j.jrt.2020.100005
Rutecka, D. (2025, February 12). Liability for damages: the missing piece of the AI Act puzzle. Schoenherr. https://schoenherr.eu/content/liability-for-damages-the-missing-piece-of-the-ai-act-puzzle
Sachoulidou, A. (2024). AI Systems and Criminal Liability. Oslo Law Review, 11(1). https://doi.org/10.18261/olr.11.1.3
Sarch, A. (2024). Collective Knowledge and the Limits of the Expanded Identification Doctrine. Oxford Journal of Legal Studies, 44(4), 920–948. https://doi.org/10.1093/ojls/gqae025
Schuett, J. (2024). Risk Management in the Artificial Intelligence Act. European Journal of Risk Regulation, 15(2). https://doi.org/10.1017/err.2023.1
Selbst, A. D. (2020). Negligence and AI’s Human Users. Boston University Law Review, 100(4). https://www.bu.edu/bulawreview/files/2020/09/SELBST.pdf
Simmler, M. (2024). Ensuring Accountability for Robots and AI under Criminal Law. In W. Barfield, Y.-H. Weng, & U. Pagallo (Eds.), The Cambridge Handbook of the Law, Policy, and Regulation for Human–Robot Interaction (pp. 798–812). Cambridge University Press. https://doi.org/10.1017/9781009386708.050
Soyer, B., & Tettenborn, A. (2022). Artificial intelligence and civil liability—do we need a new regime? International Journal of Law and Information Technology, 30(4). https://doi.org/10.1093/ijlit/eaad001
Staszkiewicz, P., Horobiowski, J., Szelągowska, A., & Strzelecka, A. M. (2024). Artificial intelligence legal personality and accountability: auditors’ accounts of capabilities and challenges for instrument boundary. Meditari Accountancy Research, 32(7). https://doi.org/10.1108/MEDAR-10-2023-2204
Susila, M., & Salim, A. (2024). Cyber Espionage Policy and Regulation: A Comparative Analysis of Indonesia and Germany. PADJADJARAN Jurnal Ilmu Hukum (Journal of Law), 11(1), 122–144. https://doi.org/10.22304/pjih.v11n1.a6
TATARU, Ștefan R., & CREȚU, A.-C. (2024). Decoding The EU Artificial Intelligence Act: An Analysis Of Key Concepts And Provisions. Journal of Public Administration, Finance and Law, 31. https://doi.org/10.47743/jopafl-2024-31-33
Thaw, D. (2013). Criminalizing Hacking, not Dating: Reconstructing the CFAA Intent Requirement. Journal of Criminal Law and Criminology, 103(3). https://scholarship.law.pitt.edu/fac_articles/152/
Tual, M. (2025, July 24). Surge in AI-generated child sexual abuse images alarms advocacy groups and investigators. Lemonde. https://www.lemonde.fr/en/pixels/article/2025/07/24/surge-in-ai-generated-child-sexual-abuse-images-alarms-advocacy-groups-and-investigators_6743661_13.html
van Bekkum, M. (2025). Using sensitive data to de-bias AI systems: Article 10(5) of the EU AI act. Computer Law & Security Review, 56. https://doi.org/10.1016/j.clsr.2025.106115
Villasenor, J. (2021, June 7). Reining in overly broad interpretations of the Computer Fraud and Abuse Act. BVrookings. https://www.brookings.edu/articles/reining-in-overly-broad-interpretations-of-the-computer-fraud-and-abuse-act/
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Maslihati Nur Hidayati, Agus Surono, Ery Pamungkas

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish their manuscripts in this journal agree to the following conditions:
- The copyright on each article belongs to the author(s).
- The author acknowledges that the Journal of Law, Poliitic and Humanities (JLPH) has the right to be the first to publish with a Creative Commons Attribution 4.0 International license (Attribution 4.0 International (CC BY 4.0).
- Authors can submit articles separately, arrange for the non-exclusive distribution of manuscripts that have been published in this journal into other versions (e.g., sent to the author's institutional repository, publication into books, etc.), by acknowledging that the manuscript has been published for the first time in the Journal of Law, Poliitic and Humanities (JLPH).























