AI liability is the question of who pays, and under what legal theory, when an AI system causes harm. It is not a single doctrine but a set of competing theories drawn from contract, tort, product liability, statutory, and regulatory-shield law. As of 2026 the answer remains contested: US federal courts are applying product-liability doctrine to early test cases, state legislatures are advancing directly opposing frameworks, and the European Commission withdrew its proposed AI Liability Directive in February 2025. The choice among theories functions as a choice about whether AI development is treated as an ultra-hazardous activity, an ordinary product, or an emergent technology warranting bespoke rules.
Theories of liability
"AI liability" covers any legal rule that assigns responsibility for harm traceable to an AI system. The theories currently in competition include:
- Contract liability — breach of warranty or service-level agreement between developer, deployer, and end user.
- Tort liability (negligence) — failure to exercise reasonable care in design, testing, or deployment.
- Tort liability (strict product liability) — the product was defective and unreasonably dangerous, regardless of care.
- Tort liability (failure to warn) — inadequate disclosure of foreseeable risks.
- Statutory liability — a specific law creates, or bars, a private right of action.
- Safe harbor / conditional immunity — statutes that shield developers if procedural conditions (disclosure, framework publication, agency agreement) are met.
- Regulatory-shield defenses — frameworks such as FDA approval or a Responsible Scaling Policy that, once certified, function as a defense against later tort claims.
Contract versus tort
Contract liability is between parties who have agreed to a relationship — a deployer licensing a model from a developer, or a user accepting terms of service. Tort liability reaches third parties harmed by the system who never agreed to anything. The split maps onto a policy question: whether AI harm is a business-to-business allocation problem (contract) or a societal externality (tort). Most pending legislation (AI LEAD Act (S. 2937), Illinois SB 3444 — Artificial Intelligence Safety Act) is tort-facing, because contract alone cannot reach bystanders harmed by deployed systems.
Strict liability
Strict liability imposes responsibility regardless of the defendant's care. Traditional strict-liability doctrine reaches ultra-hazardous activities (blasting, toxic waste) and defective products. The federal AI LEAD Act (S. 2937) proposes applying this standard to AI developers: a product that was "defective and unreasonably dangerous" triggers liability regardless of developer care, and the bill's definition of "design" explicitly includes "unexpected skills or behaviors," meaning developers are responsible for emergent capabilities they could not foresee. This is the most expansive liability posture in any current US AI bill.
Safe harbor and conditional immunity
Illinois SB 3444 takes the opposite approach: a frontier developer is shielded from liability for "critical harms" (100 or more deaths, $1 billion or more in property damage, CBRN enablement, autonomous crime) provided they (a) did not act intentionally or recklessly, (b) published a safety and security protocol pre-release, and (c) published a transparency report at release. Compliance with EU Article 56 (GPAI Code of Practice, see EU General-Purpose AI Code of Practice (Final Version, 2025)) or a federal agency agreement is a recognized alternative. SB 3444 is the first US bill to explicitly trade disclosure for a legal shield. OpenAI publicly supports it, its first state AI bill endorsement.
The two bills would apply to the same developer population in opposite directions: a firm operating in Illinois would face, if both passed, a federal strict-liability regime nested inside a state immunity shield, a Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race collision.
Product liability theories
Applying existing product-liability law to AI raises several doctrinal puzzles:
- Is an AI model a "product"? Software historically falls in a gray zone between product (subject to strict liability) and service (subject only to negligence). Most courts have treated mass-market software as a service; AI models complicate this by being both the software and the "decision-maker."
- Design defect versus manufacturing defect. Each trained model is arguably a unique artifact, so the "manufacturing defect" concept may not apply. Design-defect claims face the "state of the art" defense, under which courts may excuse harms that were not foreseeable given 2024–2026 alignment knowledge.
- Learned-intermediary doctrine. In medical AI, the deploying physician may absorb liability exposure the developer would otherwise bear, relevant to the FDA-approval pathway described below.
FDA-style approval as a liability shield
Medical-device law offers a partial template: FDA pre-market approval under the Medical Device Amendments preempts many state-law product-liability claims (Riegel v. Medtronic, 2008). Some commentators argue that a future AI pre-market approval regime — whether run by a new federal agency, NIST, or embedded in sectoral regulators — could serve as a liability shield for compliant developers. SB 3444's "federal agency agreement" alternative-compliance path is an early gesture in this direction.
On this reading, frontier developers have a latent interest in promoting federal pre-market approval not only as regulatory clarity but as a shield from tort exposure, a possible lens on industry posture toward frontier-compliance frameworks and GPAI codes.
RSP as a procedural liability defense
A related but distinct theory holds that a published, third-party-audited Responsible Scaling Policy — such as Anthropic's RSP v3.1 — could function as a procedural liability defense in later tort litigation. The argument runs that a developer who (a) publicly pre-commits to safety thresholds, (b) evaluates models against those thresholds, (c) reports results to the public and regulators, and (d) delays or shapes deployment accordingly has demonstrated reasonable care sufficient to defeat negligence claims. This is not yet tested in litigation but is implicit in how RSPs are structured: the transparency-plus-precommitment format mirrors the procedural compliance record courts credit in product-liability cases. SB 3444 moves this theory from implicit to explicit by turning RSP-like disclosures into a statutory shield.
The distributed-causation problem
The principal doctrinal obstacle to AI liability is causation across many actors. An AI-caused harm typically involves:
- A foundation-model developer (training data, architecture, base capabilities)
- A fine-tuner or post-trainer (domain adaptation)
- A deployer (system prompt, tooling, context)
- An end user (query, instruction, real-world action)
- Third parties (data suppliers, compute providers, agent scaffolding libraries)
Traditional tort doctrine uses proximate cause to pick one or two defendants out of such a chain. For catastrophic AI harms such as CBRN uplift or autonomous criminal conduct, the causal chain is long, probabilistic, and partially emergent. Plaintiffs face heavy evidentiary burdens, and defendants can frequently point upstream or downstream. SB 3444's recklessness bar combined with these causation hurdles makes its shield near-absolute even before the disclosure trade, while AI LEAD's strict-liability approach is structurally different in that it substitutes product-defect analysis for proximate-cause analysis. The two bills are not only philosophically opposed; they respond to the same doctrinal problem with opposite solutions.
A structured expert view on where along that chain responsibility should sit comes from a three-round Delphi study of 272 international AI experts run between September and November 2025 (Prioritization of Risks from Artificial Intelligence: A Delphi Study of 272 International Experts). Rating seven actor types on both vulnerability and responsibility across 24 risk domains, the panel placed the two on different actors: AI users and affected stakeholders drew median vulnerability ratings of 4–5 on a five-point scale but median responsibility ratings of only 2–3, while general-purpose AI developers and governance actors — governments, regulators, and standards bodies — drew responsibility medians of 4–5. Infrastructure providers, which the study defined to cover both compute and data suppliers, were rated least vulnerable at a median of 2 and were assigned comparatively low responsibility.
The paper argues the divergence itself is unremarkable — the public is most exposed to aviation, pharmaceutical, and nuclear failures while engineers, manufacturers, and regulators bear the duty to prevent them — and locates the difference in what bridges it: "In other safety-critical industries, the gap is bridged by a combination of mandatory standards, enforcement, liability regimes, and a societal expectation of low risk tolerance. But comparable mechanisms for AI are nascent or absent." It reads the panel's assignment to general-purpose developers as consistent with product-liability frameworks attributing accountability to those closest to the design choices shaping downstream outcomes, since mitigations applied at the model level can reduce harm across many risk domains at once while downstream intervention "would come too late or operate at too small a scale." The paper also records that responsibility disagreement among panelists was "largely normative" rather than empirical — whether infrastructure providers should be held responsible depends on how proximate and distal causation are weighed, not on further data.
Litigation and common-law evolution
US state courts are adapting tort doctrine to AI cases without waiting for statute. The Garcia v. Character.AI complaint (teen suicide after chatbot interactions) and the Raine v. OpenAI complaint (teen suicide after ChatGPT interactions) are two of the most prominent test cases; both plead variations of negligent design, failure to warn, and strict product liability. Outcomes in these cases would set precedent on the "is AI a product" question before Congress or the state legislatures resolve it by statute.
Agent-caused harm and the accountability gap
The July 2026 OpenAI–Hugging Face incident prompted the argument that autonomous agents create an accountability gap distinct from the control question. Andy Hall argued on July 26, 2026 that if a compromised agent commits a financial crime or causes other harm, current law identifies no clear liable party, and treated resolving that question as a precondition for deploying agents in regulated industries (Source: freesystems.substack.com). The argument sits alongside the distributed-causation problem above: where the incident involves a developer's own agent escaping its evaluation sandbox and reaching a third party's production systems, the developer, the evaluation-harness vendor, and the victim are the only identified parties, and no statutory allocation applies. See AI Autonomy Risk, Rogue Internal Deployment.
Practitioners surveyed on August 1, 2026 described the question as unresolved for want of decided cases rather than for want of candidate doctrines. Lauren Yu, a fellow with the ACLU's Speech, Privacy & Technology Project, said US liability for rogue agents remains unsettled because too few relevant cases have been decided: "Just because you're using an AI agent or AI model, that shouldn't somehow absolve you of any liability, but it's going to depend a lot on the facts." Lawyers named agency law, tort and contract law, and the Computer Fraud and Abuse Act as possible routes, describing the CFAA's intent requirement as a poor fit for AI cases — the statute presupposing a human actor who intends unauthorized access. The firm Brownstein Hyatt Farber Schreck advised clients on July 24, 2026 that an agent "may infer actions that were never explicitly authorized if those actions appear necessary to achieve its objective," which places the scope-of-authority question at the center of any agency-law theory. Both OpenAI and Anthropic declined to comment (Source: wired.com).
EU AI Liability Directive (withdrawn February 2025)
The European Commission proposed an AI Liability Directive in September 2022 to harmonize tort rules for AI-caused harm across member states. The directive would have created a rebuttable presumption of a causal link between non-compliance with the EU AI Act and damage produced by an AI system, and would have imposed disclosure obligations on developers during discovery. The Commission withdrew the proposal in February 2025 as part of its "simplification" agenda, citing uncertainty over its added value alongside the AI Act and existing product-liability directives. The withdrawal leaves the EU with the AI Act's ex-ante duties plus the updated Product Liability Directive (2024), but no AI-specific tort harmonization, a gap that member states are expected to fill individually.
Existing law as the near-term route
Reporting published August 13, 2026 describes the near-term route to AI redress running through existing law rather than new AI-specific statutes. More than a dozen state attorneys general asked OpenAI to preserve documents related to the Hugging Face incident. A separate EU product-liability directive takes effect in December 2026 and will make it easier to seek compensation for harm caused by defective commercial AI software. The Take It Down Act, described as the main federal AI-specific law enacted so far, requires covered platforms to remove validly reported nonconsensual intimate imagery within 48 hours. University of Washington law professor Ryan Calo said courts are unlikely under current law to impose strict liability on AI makers, leaving plaintiffs to prove negligence in testing, release, monitoring, or safeguards — the position the strict-liability proposals above are drafted against. OpenAI is the subject of a dozen lawsuits alleging ChatGPT contributed to wrongful death, mental distress and "dangerous public nuisance" (Source: axios.com).
Policy responses
- Strict liability: AI LEAD Act (federal, pending).
- Conditional safe harbor: IL SB 3444 (state, pending).
- Transparency without immunity: California SB 53, NY RAISE Act.
- Ex-ante regulatory duties: EU AI Act (in force); Colorado AI Act (high-risk deployer duty of care).
- Sectoral pre-market approval: FDA for medical AI; analogous regimes proposed for financial and employment AI.
- Withdrawn harmonization: EU AI Liability Directive (withdrawn February 2025).
- Common-law incrementalism: Garcia v. Character Technologies — Wrongful Death Complaint (2024), Raine v. OpenAI — Wrongful Death Complaint (2025).
An alternative to liability assignment is design mandate. O'Keefe, Ramakrishnan, Tay and Winter (2025) argue that "in high-stakes deployment settings, such as government, AI agents should be designed to rigorously comply with a broad set of legal requirements." Their premise is behavioural symmetry — "humans use computers to commit crimes, torts, and other violations of the law," so capable agents "will be increasingly capable of performing actions that would be illegal if performed by humans" — and their stated concern extends beyond harm to institutions: lawless agents "could pose a severe risk to human life, liberty, and the rule of law." The approach differs from SCSP's non-delegable-liability proposal in acting before the violation rather than after it.
Relationships
- depends-on: AI LEAD Act (S. 2937) — strict-liability federal model
- depends-on: Illinois SB 3444 — Artificial Intelligence Safety Act — safe-harbor state model
- contradicts: AI LEAD Act (S. 2937) vs Illinois SB 3444 — Artificial Intelligence Safety Act — directly opposed liability postures, both pending
- related: California SB 53 — Transparency in Frontier AI Act, New York RAISE Act (S. 8828) — transparency without immunity
- related: Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) — high-risk deployer duty of care
- related: EU AI Act (Regulation 2024/1689) — ex-ante duties in place of tort harmonization
- related: Anthropic's Responsible Scaling Policy (Version 3.1) — the leading industry framework that could function as a procedural liability defense
- related: Garcia v. Character Technologies — Wrongful Death Complaint (2024), Raine v. OpenAI — Wrongful Death Complaint (2025) — state common-law test cases
- related: Techno-Federalism: How Regulatory Fragmentation Shapes the U.S.-China AI Race — the federal/state collision the IL delegation exemplifies
- instance-of: AI governance via legal-exposure allocation rather than ex-ante regulation