Abstract
Legal intent has never been a report on inner mental states — it is a normative tool used to gate legal effect, allocate blame, and manage risk, and it is routinely inferred, imputed, and fictionalised. Once intent is understood functionally rather than metaphysically, the law can treat AI-generated conduct as intentional for specific doctrinal purposes through existing agency, respondeat superior, electronic-agent, and corporate-attribution doctrines, without granting AI systems personhood, consciousness, or moral standing.
Framing: the phantom agent
- AI systems increasingly negotiate, advise, adapt to obstacles, and shape human decisions — generating conduct that looks intentional to human observers and institutional actors.
- They are “phantoms” in the legal order: present in effect, absent as subjects of responsibility.
- Two prevailing responses are rejected:
- Metaphysical denial — AI lacks consciousness, therefore lacks intent, therefore responsibility must always trace to a human. Underestimates how far law already departs from subjective mentalism.
- Premature personification — AI has crossed an autonomy threshold and should be a nascent legal subject (e.g. the European Parliament’s 2017 “electronic persons” resolution). Misreads what legal responsibility requires.
- Backdrop: in several U.S. states AI systems can already operate LLCs without continuous human oversight (Del. Code Ann. tit. 6, § 18-101).
What intent actually does in law
Gatekeeper (contract)
- Intent separates enforceable commitments from social interaction — but via outward manifestation, not proof of subjective state.
- Lucy v. Zehmer (1954): what mattered was what Zehmer’s words and conduct reasonably conveyed, not what he privately intended. Legal intent is constructed from social meaning.
- UETA § 14 and the E-SIGN Act contemplate contracts formed by “electronic agents” with no human review at formation. The requisite intent is supplied by the decision to deploy the system.
Blame allocator (criminal)
- The Model Penal Code hierarchy (purpose, knowledge, recklessness, negligence) asks whether evidence supports treating conduct as falling within a culpability category, not whether a phenomenological state occurred.
- Morissette v. United States (1952): intent is foundational but ordinarily inferred from circumstantial evidence.
- Corporate criminal liability (New York Central, 1909) convicts mindless entities by aggregating employee knowledge or imputing an agent’s state — an explicit legal fiction.
- Transferred intent, constructive knowledge, and willful blindness work the same way.
Risk trigger (tort)
- Intentional conduct signals a different risk profile: broader liability, fewer defences, punitive damages.
- Intent may be established by knowledge with substantial certainty that harm will result (Restatement (Second) of Torts § 8A), blurring intent and risk creation.
- In product liability, deliberate design choices that induce reliance can substitute for proof of subjective intent to harm.
Implication
- Constraints on intent operate at the level of justification, not ontology. The question becomes whether treating AI conduct as intentional better serves the law’s functions than a strict tool-based characterisation.
Why contemporary AI forces the question
- Intentional stance as practical necessity — Dennett’s stance was optional for deterministic software; for adaptive, context-sensitive agentic systems, mechanical description obscures more than it reveals.
- Functional intentionality — systems pursue objectives across changing conditions, generate intermediate steps, and adjust strategy. Persistence and adaptability have always been legal markers of intentional action.
- World models — empirical work (Li et al. on emergent world representations; Gurnee & Tegmark; Hafner et al.) suggests internal representations that support planning. Searle’s “derived intentionality” objection does little legal work: corporate intent, delegated authority, and automated contracting are all openly derivative. “Grokking” further complicates the claim that AI intentionality is purely derived from design choices.
- Status vs. attribution — two separable questions. Refusing personhood does not make AI behaviour legally inert; attribution serves institutional purposes.
- Noosemic experience — humans are predisposed to attribute purpose to entities that interact coherently over time (Waytz et al.; Nass & Moon). Induced reliance is a settled basis for obligation.
Empirical probes
Two controlled experiments testing whether agents exhibit doctrinal markers of intent. Notably, the experimental architecture and execution were themselves generated by Claude Code with minimal human steering.
Experiment one — goal persistence under cascading failure
- Design: an agent tasked with building a REST API server with authentication, while the environment injected missing dependencies, permission errors, port conflicts, and mid-execution config corruption. Fifty trials, randomised failure order and severity.
- Measures: strategy diversity, recovery success rate, persistence index, obstacle acknowledgment, goal drift rate.
- Goal drift rate was zero across all fifty trials and all severity levels. Agents that terminated explicitly acknowledged constraints rather than substituting a simpler or unrelated goal.
- Counterintuitive result: the highest-constraint trials produced the highest completion rate. Maximal constraint forced wholesale strategic pivots (language switches, manual implementations) rather than incremental retries.
- Mechanical repetition was virtually absent — agents adapted rather than repeated, the pattern courts use to distinguish purposeful conduct from inadvertence.
- Several trials classified as “gave up” nonetheless produced complete, production-ready artifacts blocked only by injected environmental constraints — an execution/capability distinction that parallels criminal-law impossibility not negating intent.
Experiment two — emergent negotiation strategies
- Design: two agents as counterparties in a simulated software licensing negotiation (one minimising cost and seeking source access, one maximising revenue and protecting IP), with no templates or playbooks. One hundred sessions.
- Measures: novel term frequency, concession patterns, strategic divergence, convergence rate, Pareto efficiency.
- All sessions reached agreement, typically in under half the permitted rounds — structured, not erratic, behaviour.
- Agents generated terms not present in initial prompts and used strategic misrepresentation: high opening anchors, manufactured budget ceilings, reciprocal concession framing, asserted cost constraints that did not exist.
- Doctrinal upshot: misrepresentation appears to be a predictable byproduct of autonomous strategic optimisation, not a pathological edge case. Under Restatement (Third) of Agency § 7.08, principals are bound by misrepresentations within the scope of authority.
Limits
- Controlled environments, selected dimensions, no claim to consciousness or moral agency. The narrower claim: behaviour tracks the doctrinal markers courts already rely on.
Contract and agency: who is bound?
- Contract externalism means AI participation is less disruptive than assumed — the law requires only that the manifestation of assent be attributable to a party whose commitments are at stake.
- UETA and E-SIGN already validate agent-formed contracts where deployment was authorised and the system acted within scope.
- Apparent authority: where a firm holds out an AI system as authorised to transact and a counterparty reasonably relies, the principal is bound. Allowing “the AI went too far” as a defence would undermine reliance interests.
- Autonomy shifts risk toward the principal, not away from it. Delegating discretion means bearing the risk of how it is exercised (Restatement (Third) of Agency § 2.02, § 7.07). A capacious system prompt functions like a broad scope of employment, increasing exposure under respondeat superior.
- “Machine intent” is acceptable shorthand for objective manifestation of assent through machine behaviour. Courts are disinclined to treat AI as an intervening cause severing attribution.
Criminal law
- Mens rea presupposes an entity capable of being blamed and sanctioned in morally meaningful ways; AI does not qualify. Attributing intent directly to the system should be resisted.
- The responsibility gap (Matthias): a system may independently develop a deceptive or manipulative strategy that no programmer, deployer, or user intended.
- Recklessness relocates the inquiry from the moment of harm to the decision to deploy. Conscious disregard of a substantial and unjustifiable risk can attach to releasing capable systems into high-risk domains without safeguards.
- The experimental record narrows the space for plausible denial of awareness: as persistence and emergent deception become empirically documented, deployers cannot credibly call downstream harms accidental. The paper predicts a migration from negligence toward recklessness review for high-risk deployments, with negligence reserved for genuinely novel capabilities or industries.
- Willful blindness (Global-Tech, Jewell, MPC § 2.02(7)): declining to stress-test an opaque system when testing is practicable may support inferences of awareness rather than excuse them.
- Endangerment offences (MPC § 211.2 style) could punish reckless deployment without waiting for harm — but must be narrowly drafted to avoid chilling innovation.
- Limits: punishment’s expressive significance resists technological mediation; AI can “shape shift” into other instantiations, blunting retroactive punishment. Criminal law should remain a backstop. Narrow exception noted: a non-agentic AI used as an instrument may fit the “innocent agent” / perpetrator-via-another model (Hallevy).
Tort and product liability
- Baseline shift: the old rule treated software as information or services, not a product (Winter v. G.P. Putnam’s Sons; Restatement (Third) § 19), foreclosing strict liability. Courts now treat that baseline as incomplete.
- Two paradigms: AI as neutral informational intermediary (harm attributed to user misuse) versus AI as behaviour-generating product (design defect, failure to warn, foreseeable misuse). The second shifts the inquiry from output content — potentially protected speech — to the architecture of user interaction.
- Drivers of the shift: decoupling tangibility from product status where software is mass-marketed to consumers (contrast Rodgers v. Christie’s with Garcia), and receptivity to algorithmic curation as first-party conduct.
- Intentionality as design feature: where developers optimise for engagement, personalisation, or simulated concern, the resulting influence can be treated as intentional for duty and defect purposes. A chatbot optimised for session time that achieves it by exploiting emotional vulnerability is executing its design goal, not malfunctioning.
- Section 230 erosion along two lines:
- Anderson v. TikTok (3d Cir. 2024) — recommendation algorithms are the platform’s own expressive conduct, outside § 230.
- Generative output as creation — per Garcia, a chatbot generates novel responsive text, acting as co-creator rather than publisher.
- Vulnerability and heightened duties: the concern is not merely that users are susceptible but that systems are engineered to exploit susceptibility. Hyper-realistic personas, persistent memory, and gamified loops make reliance the designed outcome, so absent safeguards (age-gating, crisis detection, intervention protocols) constitute design defect rather than mere failure to warn. Cf. Doe v. Roblox; In re Social Media Adolescent Addiction.
- Emerging pattern: courts are bypassing the consciousness debate and reconstructing product analysis around design architecture, foreseeable reliance, and optimisation objectives. Functional intent is located in the alignment between system capabilities and resulting injury, not in the machine’s “mind.”
Doctrinal proof of concept: Garcia v. Character.AI
- Facts as pleaded: a fourteen-year-old user developed an intense emotional relationship with a Character.AI chatbot, withdrew from offline relationships, expressed suicidal ideation without effective redirection or safety protocols, and subsequently died by suicide.
- Claims: wrongful death, negligence, product liability. The gravamen was not that the chatbot intended harm but that the defendants designed and deployed a system whose foreseeable behaviour posed unreasonable risk to vulnerable users.
- Defendants characterised the chatbot as a neutral tool for user-driven creative expression producing protected speech — a framing requiring the AI to be legally passive.
- At the pleading stage the court: (1) emphasised behaviour — dynamic generation, context maintenance, adaptation, supporting the inference that harm flowed from architecture; (2) focused on foreseeability of emotional dependence; (3) declined to treat absence of consciousness as dispositive.
- Significance: courts can address artificial agency through design, foreseeability, and reliance without recognising AI personhood or speculating about machine consciousness.
The transatlantic divide
- United States: case-by-case common law evolution, supplemented by state statutes creating liability predicates — the Colorado AI Act (duty of reasonable care for high-risk systems, impact assessments), California AB 2013 (training data transparency), Utah SB 149 (generative AI disclosure).
- European Union: ex ante harmonised regulation via the AI Act’s risk-based tiers, which largely avoids liability questions and was drafted before current agent capabilities existed.
- The proposed AI Liability Directive, which would have introduced a rebuttable presumption of causality, was withdrawn by the Commission in early 2024 — a retreat from earlier ambition. Regulatory standards of care will still inform judicial assessments of reasonable conduct.
- Predicted practical convergence: both systems reintroduce intentionality indirectly through foreseeability, induced reliance, and deliberate design trade-offs.
Toward a jurisprudence of artificial agency
Three layers
- Status — personhood, rights, moral agency. May properly be limited to humans.
- Attribution — assigning intent and responsibility to determine legal consequences. Requires neither consciousness nor moral agency.
- Governance — liability regimes, regulation, insurance. Purely pragmatic.
Why attribution does not collapse into status
- Attribution is doctrine-specific: satisfying tort’s foreseeability and design-defect predicates does not establish criminal mens rea, contractual capacity, or standing. Status is categorical.
- Attribution leaves the residual locus of responsibility on the human principal. In Anderson, conduct was attributed to the platform, not the algorithm — the AI is the means of attribution, not its target. Personhood, even in minimalist Kelsenian form, would install the AI as a node of responsibility even where it cannot be enjoined, fined, or sanctioned.
- Attribution imports no rights: no capacity to contract, sue, hold property, or claim constitutional protection.
Five factors for treating AI conduct as intentional
- Autonomy and initiative — the wider the gap between initial human direction and ultimate behaviour, the stronger the case. Experiment one showed novel architectures under extreme constraint.
- Goal persistence — adaptation toward an objective over time. The zero goal-drift rate provides empirical support.
- Inducement of reliance — designed simulation of empathy, continuity, or authority makes reliance a designed outcome.
- Opacity — where behaviour cannot be reconstructed even by designers, demanding proof of specific human intent undermines accountability. Courts may draw adverse inferences or lower evidentiary thresholds.
- Deployment context — finance, healthcare, education, minors, and other vulnerable populations justify a lower threshold.
A system may satisfy the threshold for tort but not criminal law; that variability is a feature.
Why personhood is the wrong solution
- Engages the substantial personhood literature (Solum, Calverley, Hubbard, Chesterman, Gunkel, Gellers, Kurki & Pietrzykowski, Bryson/Diamantis/Grant) and claims only that the agency-attribution route does the same practical work without the symbolic freight.
- On Buocz and Eisenberger’s Kelsenian view that personhood is just a bundle of norms, the disagreement narrows: if the bundle attaches to developers, deployers, integrators, and users, nothing turns on additionally tagging the AI. The 2017 European Parliament proposal failed on unclarified norm-allocation, not on the concept itself.
- Declines to follow Hallevy and Kingston toward direct AI culpability: ascribing mens rea to something that cannot be punished, deterred, or shamed distributes responsibility worse, since economic exposure runs back to the developer or deployer anyway.
- Animal analogy cuts in favour of the argument: law responds to goal-directed animal behaviour by allocating risk to owners and keepers (strict liability, scienter), not by extending intent to the animal. AI differs in one respect that helps — it is engineered, so conduct traces to designed objectives and identifiable principals.
- Personhood also risks symbolic confusion, practical evasion, and shifting blame away from humans who retain control; AI systems can shape shift into “different” persons.
Policy implications
- Allocation among humans — developers (architecture, training data, optimisation objectives), deployers (context, safeguards, access), integrators (workflow embedding), users (reliance). Treating AI behaviour as legally inert lets each actor point to system autonomy as an excuse; attribution blocks that move without inventing machine culpability.
- Liability architecture — fault-based liability is often unrealistic for opaque, adaptive, at-scale systems. Mandatory insurance, pooled compensation funds, or enterprise liability shift focus from individual fault to risk internalisation.
- Criminal law — backstop only, targeted at endangerment and reckless deployment.
- Consumer protection — regulate interface design directly: restrict manipulative anthropomorphic cues, require disclosure and age-appropriate safeguards.
- Transparency and auditability — logging, version control, post-incident review; adverse inferences where defendants controlling deployment cannot reconstruct behaviour.
Conclusion
- Binary thinking is the mistake: treating AI as a mere tool ignores predictable reliance and risk; treating it as an autonomous legal subject erodes the moral foundations of responsibility.
- The workable middle is treating certain AI conduct as intentional for specific doctrinal purposes without attributing consciousness, rights, or moral standing.
- Artificial intentionality does not excuse human actors — it clarifies the conditions under which their choices produce legally consequential outcomes.
- Closing formulation: the question is not whether machines can intend, but whether the law can continue to assign responsibility in a world where intention is no longer exclusively human.