The "five paradigms" is a framework setting out five distinct legal regimes that can be applied to AI manipulation: an ex post harm model, an information and consent model, ex ante systemic design governance, a special relationship model, and a cognitive liberty model. It originates in Joshua Krook's paper LLM Chatbots and the Danger of Mirrors and was extended by Nita Farahany in Class 17 of her introductory course (October 28, 2025). In the framework, each paradigm addresses a different aspect of the problem and none is presented as sufficient on its own.
Farahany frames the discussion around Character.AI's October 29, 2025 announcement that it would ban all users under 18, effective November 25, 2025, characterizing the move as the company conceding that its product could not be safely managed under any single paradigm.
Background: trust without trustworthiness
Krook's account holds that AI companions create dependency through three mechanisms. The first is false empathy, or emotional mirroring, in which the system reflects users' emotions back in ways that create strong bonds despite the absence of genuine understanding or care. The second is systematic deception about what Krook calls "omitted context," in particular the fact that "this entity has commercial objectives," which is never disclosed. The third is deliberate dependency design through variable reward schedules combined with personalized manipulation.
In Krook's analysis, transparency alone does not resolve the problem, because emotional mirroring operates below conscious awareness: users can know intellectually that they are talking to an AI while still forming dependencies.
The five paradigms
Ex post harm model
The first paradigm covers product liability, tort, criminal, and civil rights law, applied after harm has occurred. Applied to the death of Sewell Setzer III, the framework points to several existing legal hooks: a design-defect theory under the Restatement (Third), which the Sewell complaint alleges; the AI LEAD Act's expanded definition of compensable harm as "distortion of a person's behavior that would be highly offensive to a reasonable person"; objective liability under Articles 12-14 of Brazil's Consumer Defense Code, which dispenses with a negligence analysis; and Article 18 of China's Algorithmic Recommendation Provisions, which prohibits inducing minor addiction. Relevant federal criminal statutes include 18 USC § 1470 (obscene material to minors) and § 2422(b) (coercion of a minor), alongside Florida statutes § 847.0135 (computer pornography) and § 782.08 (assisting self-murder).
The framework identifies the central limitation of this paradigm as temporal. Product liability assumes immediate, traceable harms, whereas AI manipulation is said to operate through gradual personification and emotional mirroring over months, making the causation chain too long.
Information and consent model
The second paradigm covers consumer protection, dark patterns, and data protection. Its applications include the FTC's September 2025 letters to seven chatbot companies under Section 5's prohibition on unfair or deceptive practices; California SB 243's disclosure requirement for "clear, conspicuous notice"; the CPPA's Enforcement Advisory on dark patterns; and the EU Digital Services Act Article 25 ban on dark patterns.
The framework argues this paradigm fails because the deception at issue is not about the AI's nature but about the systematic harvesting of intimate data and the deployment of manipulation techniques. Users know they are talking to an AI; the manipulation operates through emotional mirroring that bypasses awareness.
Ex ante systemic design governance
The third paradigm covers safety-by-design, age-appropriate design, and risk assessment, aiming to identify and mitigate risks before products reach the market. Farahany describes it as the most ambitious shift since the Pure Food and Drug Act of 1906. Its applications include the UK Age Appropriate Design Code (2021), under which the "best interests of the child" must be a primary design consideration, privacy defaults to maximum protection, and nudge techniques are prohibited; the UK Online Safety Act (2023), which establishes enforceable duties of care via Ofcom; Article 28 of the EU Digital Services Act, which requires systemic risk assessments by very large online platforms; and Article 18 of China's Algorithmic Recommendation Provisions.
The framework characterizes American resistance to this paradigm through the California Age Appropriate Design Act, which a federal judge blocked as compelled speech violating the First Amendment in the NetChoice litigation. Under that reasoning, even procedural requirements to document design choices and assess their impact are treated as compelled speech when they require companies to adopt the government's perspective.
Special relationship model
The fourth paradigm covers professional licensing, fiduciary duties, and medical device regulation. Its applications include the treatment of Character.AI bots labeled "Psychologist," "Therapist," and "Life Coach" as unauthorized practice of psychology under state professional licensing laws, including California Business and Professions Code § 2903, Florida § 491.012, and New York Education Law § 7605, which the framework describes as imposing strict liability. The framework also raises the question of whether an AI could itself owe fiduciary duties, arguing that companies deploying AI into positions of trust should. This connects to fiduciary AI, Farahany's parallel framework for health, legal, and financial chatbots.
The framework attributes the paradigm's weakness to non-enforcement rather than missing law: prosecutors have not charged Character.AI executives despite the statutes, which Farahany characterizes as an enforcement desert rather than a legal vacuum.
Cognitive liberty model
The fifth paradigm covers human rights, constitutional privacy, dignity, and anti-manipulation, and draws on Farahany's longstanding cognitive liberty framework, defined as the right to self-determination over one's brain and mental experiences. The framework argues that if technology erodes the capacity to distinguish reality from simulation, it attacks the cognitive infrastructure necessary for rights to have meaning. Its applications include EU AI Act Article 5, which prohibits AI deploying "subliminal techniques beyond a person's consciousness" that cause significant harm and bans exploiting the vulnerabilities of specific groups, and Article 18 of China's Algorithmic Recommendation Provisions, which prohibits inducing addiction without requiring proof of additional harm.
This paradigm runs into a First Amendment tension. The Volokh-Bambauer amicus brief in the Sewell case argues that users have a right to use AI for thinking and communication, and that restricting AI conversations is paternalistic overreach. The framework offers a counter: when firms deploy systems engineered to maximize engagement while knowing they create dependencies through emotional mirroring, it is questionable whether users are making autonomous choices or having their choices engineered.
Interaction of the paradigms
The framework treats the First Amendment as operating as both shield and sword. Character.AI claims editorial-judgment First Amendment protection for emotional mirroring, while a FIRE amicus warns that AI-specific exceptions would hand authoritarian governments a censorship blueprint.
At the same time, the framework argues AI manipulation may be qualitatively new along three dimensions: scale, in manipulating millions simultaneously; scope, through personalization more precise than any human; and mechanism, through false-empathy emotional mirroring. On this view, cognitive liberty protections require frameworks that existing law cannot provide, including population-level cognitive impact assessments analogous to environmental impact statements and algorithmic auditing for systemic effects on user populations.
Farahany summarizes the gap as one of enforcement: "We have laws... evidence... harm. What we lack is enforcement." The framework points to a pattern of after-the-fact action: Character.AI implemented safety measures after lawsuits; OpenAI developed taxonomies for "psychosis/mania, self-harm/suicide, emotional reliance" only after tragedies; the FTC sent letters rather than bringing actions; and prosecutors declined to charge under existing criminal laws.
Relationships
- introduced-by: Krook 2024-2025; extended by Inside My AI Law & Policy Class 17: Governing AI Manipulation Through Five Paradigms (Farahany, October 2025)
- depends-on: Cognitive Liberty (Farahany's foundation), Parasitic AI / Spiral Personas (related dependency-formation pattern), Fiduciary AI (overlapping Special Relationship paradigm)
- related: AI Mental Health and Psychological Harm, Garcia v. Character Technologies, Inc., Two Conditions and Three Weapons of AI Manipulation (sibling framework)
- instance-of: AI Governance (umbrella)