AI Policy Wiki
Dashboard

Standards as Litigation Evidence

medium confidence · updated 2026-06-06

The trend in which courts use voluntary AI standards (NIST AI RMF, ISO/IEC 42001) to define the standard of care in negligence and strict-liability cases against AI developers and deployers — regardless of whether any statute formally mandates the standard. Compliance becomes evidence of good faith; non-adoption becomes evidence of negligence.

Standards as litigation evidence refers to the pattern in which courts use voluntary AI standards to define the legal standard of care, even absent any statute that formally mandates compliance. Under this pattern, compliance with a recognized standard becomes evidence of good faith, while non-adoption becomes evidence of negligence. The pattern was identified and named by Andrew Clearwater in Standards Are the New Legislation (Clearwater, March 2026) (March 2026).

Mechanism

Product-liability law has long treated industry standards as setting the bar for what counts as negligent. A jury asks whether the defendant exercised the standard of care that a reasonable industry participant would have exercised; where a recognized industry standard exists, that standard becomes evidence of what reasonable care looked like.

Applied to AI, compliance with the NIST AI RMF serves as presumptive evidence of good faith in negligence and strict-liability suits, while non-adoption serves as presumptive evidence of failure to exercise reasonable care. The Future of Privacy Forum has documented courts already invoking NIST in AI-related cases without statutory direction.

Clearwater's account holds that a court can treat NIST compliance as defining reasonable conduct without a state legislature first passing a bill that references NIST, so that standards acquire force through judicial reasoning rather than statute. On this view the operative compliance question shifts from whether regulators require a standard to whether a court would use it as evidence against a defendant, an outcome Clearwater describes as increasingly likely in 2026 for both the NIST AI RMF and ISO/IEC 42001.

Implications for governance programs

Clearwater draws several prescriptions from the pattern. He argues that standards should not be treated as optional, contending that an explanation such as "we hadn't gotten to that yet" will not hold up in litigation or regulatory scrutiny. He recommends building for interoperability from the outset, designing unified governance programs that map controls across NIST, ISO, and applicable jurisdictions rather than running siloed compliance tracks. He also emphasizes documentation: in litigation where standards compliance can serve as an affirmative defense, he argues that the ability to show systematic governance processes that predate an inquiry is dispositive, and that binders assembled after an inquiry do not satisfy this.

Relation to the three-lane framework

The pattern operates independently of the three-lane standards-based governance framework. Courts can use standards as evidence whether the relevant state has adopted an incentive-lane safe harbor (Texas TRAIGA), a mandate (Illinois SB 3312, Washington HB 2157), or only a disclosure regime (California SB 53). The litigation effect persists across all three lanes.

Cybersecurity precedent

The pattern has a precedent in cybersecurity. The NIST Cybersecurity Framework followed a comparable trajectory: voluntary at issuance, then cited by state laws and federal procurement, then invoked by courts as standard-of-care, and in effect mandatory for any business seeking liability protection. The bipartisan support that built around NIST cybersecurity is now mirrored in support for NIST AI standards.

Relationships