Abstract
AI-based entities are already causing damages and fatalities, and the scholarly and regulatory dispute over how to assign tort liability for them is creating harmful uncertainty. This Article advocates for a strict liability regime for current and future AI accidents by working through the available legal analogies for AI (products, animals, slaves, electronic persons, and industry-wide regimes like aviation and vaccination), arguing that the agency analogy is best-suited among them because every other analogy ultimately reduces to the same underlying agency structure. It concludes that applying the respondeat superior doctrine — making a human principal strictly liable for the acts of her AI agent — gives the AI industry the underlying liability regime it needs to keep evolving while still compensating victims.
Framing: Legal Analogies and the “AI Entity” Concept
- The Article uses “AI entities” (machines, robots, agents, algorithms) as a deliberately neutral umbrella term, since AI is not always embodied as a robot nor always a discrete algorithm.
- Its central move: AI entities should be understood as instruments created and designed for the mono-purpose of being used by humans for their own benefit. A suitable liability analogy must reflect that instrumental, non-autonomous role.
- Core claim: AI entities and their human principals share the same basic liability structure as human “judgment-proof agents” — in both cases, the agent will not (or cannot) be held liable for the harm it causes, and its principal must step in as the liable party while the agent effectively disappears from the liability picture.
- AI agents are inherently judgment-proof: they have no assets, no legal personality, and cannot bear sanctions, so recovery is only possible via their human principal.
- The principal is the entity best positioned to prevent damage, invest in an optimal level of activity, insure against risk, and take proactive precautions — the AI agent itself cannot do any of this, and the victim cannot protect herself against it either.
- The Article invokes Jack Balkin’s “Golem” example: the Rabbi is the principal behind the Golem (a judgment-proof agent), and is therefore liable for the Golem’s damages — illustrating the basic agency-liability intuition the Article extends to AI.
- Note on terminology: calling AI entities “agents” in this Article does not impute any human-like rights or obligations to them. On the contrary, it is used specifically to reject the idea that AI itself should ever be held liable — liability is always redirected to the human principal.
The Role and Limits of Legal Analogies in Law
- Legal analogical reasoning works by finding a unifying normative principle that justifies treating a new subject like a familiar one; “analogy without theory is blind” (Dworkin), but an inaccurate theory can be equally misleading.
- Choosing an analogy is inherently evaluative and normative, not a neutral exercise in spotting similarities — it reflects a policy choice about which principle should govern, and it will end up shaping the legal rules eventually adopted.
- The Article adopts Rawls’s “reflective equilibrium” as its method: reasoning back and forth between general principles/values and specific case outcomes, adjusting each in light of the other, until a stable, workable analogy is reached. An analogy is “tested up” against the values behind it and “tested down” against specific/hypothetical cases; if it survives, it is likely adequate.
- The case against legal analogies:
- Cardozo’s warning: “Metaphors in law are to be narrowly watched, for starting as devices to liberate thought, they end often by enslaving it.”
- Bentham condemned legal fictions/analogies as an institutional deception by which courts steal power from the legislature.
- Rebecca Crootof (writing on autonomous weapons) argues analogies can mislead by omitting features that don’t carry through, constrain imagination when facing genuinely new technology, and let courts fixate on a poor-fit analogy as technology matures — becoming result-driven (“drawing the target around the arrow after it hits the wall”).
- Early, simplistic analogies (e.g., for early radio/TV defamation or early airplane accidents) do not always favor the party they were meant to protect.
- The case for their inevitability: despite these risks, opponents of analogical reasoning have not offered a workable substitute, and disregarding analogies entirely would create an unhelpful gap between legal and non-legal understanding of new technology. Analogies remain a necessary tool en route to eventual legal standards, provided their limitations are taken seriously.
- The Article distinguishes the AI-liability context from autonomous weapons: ordinary commercial AI entities differ from weapons in scope, degree, and frequency of harm, so the appropriate analogy can (and should) differ too, and should adapt over time via the reflective-equilibrium process as AI’s features change.
- Electronic persons, children, and animals are flagged early as poor analogies because AI entities lack genuine independence — they can be controlled by users, manufacturers, or malicious hackers — which does not undermine the case for the agency analogy, since agency does not require full autonomy either.
AI as Property: Products, Animals, and Slaves
AI as Products
- The product-liability analogy treats AI entities as ordinary manufactured goods (in the Article’s phrase, “nothing more than toasters or fridges”), subject to the three classic product-defect categories: manufacturing defect, design defect, and failure-to-warn.
- Manufacturing defects are unlikely to explain most AI harm: today’s software is produced with low error rates, and most AI-caused damage occurs even when the AI performed exactly as coded and designed — it is not a deviation from the intended design.
- Design defects require showing that a reasonable alternative design existed and its omission made the product unreasonably unsafe. This is extremely difficult to prove for AI given the “black-box” problem: because machine-learning systems teach themselves the “best” decision from data, neither users nor creators can fully reconstruct or explain the decision process, making it very hard to show an alternative design would have avoided the harm or would have been caught at the design stage.
- Failure to warn claims are easy to defeat cheaply — a company can attach a long list of generic instructions/warnings to an AI product, especially difficult when foreseeable risks are unknown at time of sale or the AI is an open product users can freely modify.
- Beyond the difficulty of proving any of the three defects, the Article argues AI entities differ from ordinary products in kind:
- Humans form emotional/social attachments to AI entities that they do not form with ordinary products (e.g., toasters), which bears on which analogy fits.
- The black-box problem and difficulty explaining why an alternative design would be safer distinguish AI from traditional, comparatively predictable hardware products (metal/plastic goods).
- AI entities are largely software-based and can behave erratically and unpredictably, unlike traditional hardware products valued for their predictability.
- Conclusion: the product analogy should give way to the agent analogy, though the two are not mutually exclusive — an injured party who can establish one of the three defects should still pursue that claim and may add an AI-as-agent claim alongside it.
AI as Animals — Domesticated and Wild
- Comparing AI to animals is intuitive: AI entities can be framed as domesticated pets (more predictable, evoking the human-animal companionship bond) or as wild animals (less predictable, more dangerous).
- At common law, owners of wild animals are strictly liable for harm caused by the animal’s “dangerous propensity characteristic of animals of that class,” regardless of experience with the particular animal — justified because the owner exposes others to abnormal risk.
- Owners of domesticated animals are strictly liable under the scienter action if they knew (or should have known) of the animal’s “vicious propensity” or an atypical dangerous trait, even absent negligence.
- Some AI entities are literally designed to look and behave like animals (Boston Dynamics’ “Spotmini” robot dog, Paro the therapeutic robot seal), reinforcing the analogy’s intuitive appeal.
- Both categories converge on the same practical result — a strict-liability regime falling on the owner/keeper/custodian — so the Article argues the domesticated/wild distinction adds no real analytical value.
- Two fundamental difficulties with the animal analogy:
- Classifying a given AI entity as “domesticated” or “wild” is not straightforward. Unlike animals, there is no process of domestication or birth-based obedience for AI — all AI entities are programmed and trained by humans to fulfil a task, meaning they are all “domesticated” in a loose technological sense, yet the black-box problem makes any wild/domesticated classification arbitrary. Autonomous weapons could just as easily be called “wild” as could an otherwise ordinary product turn dangerous.
- Unlike AI entities (created for a human-designated purpose), animals — domesticated or wild — were not created to serve a human purpose; their unpredictability stems from their own separate needs and desires as living beings, born rather than made. This disanalogy is not captured by the animal analogy and is better explained by agency.
- Conclusion: the animal analogy is appealing mainly because of the emotional bond people form with AI companions, but it overlooks real differences; the owner/keeper relationship it invokes reduces, again, to an agency triangle (owner–agent–victim) that the agency analogy explains more directly.
AI as Slaves
- Some scholars propose treating AI entities as their owners’ slaves — property that is more intelligent than a product and more human-like than an animal, yet still falls short of a free, autonomous human.
- Katz’s articulation: like a slave, an autonomous agent has no rights or duties of its own, can affect its master’s rights/liabilities through its decisions, facilitates commerce, and can do harm.
- Pagallo invokes the Roman-law concept of peculium — a mechanism letting a slave run a business (still legally the master’s property) — as a template for structuring AI-mediated commercial transactions, arguing it forestalls legislation that would place excessive burdens on robot “owners.” It functions as a limited-liability device for the owner and a business “warranty” for injured parties.
- The Article rejects this analogy:
- The peculium mechanism, while intriguing, adds nothing over ordinary legal agency (including corporate agency), since it too channels liability from the “slave”/agent to the principal — it does not improve on the agency framework, only recreates a piece of it via a more loaded metaphor.
- Joanna Bryson explicitly argues “robots should be slaves,” built and marketed as servants rather than companion peers, resting on four claims: (1) having servants is fine so long as no one is dehumanized; (2) a robot can be a servant without being a person; (3) it is natural for people to own robots; (4) it is wrong to let people think their robots are persons. The Article notes these claims actually support treating robots as servants/agents, not specifically as slaves — the analogy to a servant is not identical to that of a slave, and nothing in Bryson’s argument requires the slavery framing specifically.
- Robots can be understood as an extension of humans (their functionality is dictated and derived from human design), which does not require framing them as human property in the slavery sense — it just re-describes agency.
- Independent of the legal-liability analysis, the slavery analogy carries serious personal, historical, and cultural baggage (especially in the American context) that makes it publicly unpalatable, and legal analogies must be intelligible and acceptable to the public, not just lawyers. A publicly rejected analogy is not optimal when the same regulatory goal (channeling liability to the principal) can be achieved through the far less controversial agency analogy.
- The property/slave framing is also too rigid to accommodate AI’s ability to evolve and improve over time, unlike the agency analogy.
AI as Electronic Persons
Quasi-Persons (the Child/Incompetent-Person Analogy)
- AI entities could be analogized to “quasi-persons” such as children, unborn fetuses, or severely brain-damaged/comatose individuals — beings with limited legal status and correspondingly limited responsibility for their own actions.
- The underlying rationale: if society diminishes a child’s responsibility because of limited self-control, and AI entities share that limited self-control, society might extend the same diminished-responsibility logic to AI.
- When a child causes independent harm, liability generally shifts to negligent-supervision claims against the child’s guardians, based on a duty to reasonably control the child or prevent foreseeable harm — again gated by a “propensity” requirement analogous to the animal scienter rule (parents are liable only if the child had a known propensity to cause that type of harm and the parents failed to act).
- The Article finds this analogy “fundamentally identical” in structure to the animal analogy, but adds a distinctly human element: unlike pets, children are expected to learn, grow, and eventually become fully capable adult members of society, and society sanctions their misbehavior pedagogically/rehabilitatively toward that end — a rationale that does not transfer to AI, which is not being reared toward eventual full independence in the same sense.
- The analogy also struggles to identify who the appropriate AI “parent/guardian” figure is — a question the Article argues is better and more precisely answered by identifying the agency principal.
- Like animals, children were never meant to fulfill fully mature human commands, even though both learn from mistakes via trial and error (reinforcement learning, in AI’s case) — the gaps in purpose and agenda are too large to fold into one category.
- Conclusion: the “AI child” is best understood as a judgment-proof agent of its custodian, making agency the better-equipped framework.
AI Personhood (“Electronic Persons”)
- The most liberal AI analogy grants AI entities full “electronic personhood” — legal personhood with rights and obligations, treating AI as equal to human adults (the “homunculus” idea: the AI is a separate legal being, responsible by itself for its own behavior and consequences).
- Potential incidents of such personhood include citizenship (Saudi Arabia’s 2017 grant of citizenship to the robot Sophia), tax obligations, First Amendment rights, intellectual property rights, and the capacity to give legal consent.
- The EU Parliament’s 2016/2017 report on Civil Law Rules on Robotics floated creating a specific legal status of “electronic persons” for the most sophisticated autonomous robots, including possible liability for damage they cause.
- This proposal triggered strong pushback: an open letter signed by over 150 experts in robotics, AI, law, medicine, and ethics warned the EU against granting robots rights, arguing the proposal was influenced more by science fiction than real-world experience.
- The Article notes, however, that the EU report does not actually favor personhood as a chosen solution — it only outlines possible future instruments, and importantly speaks only of AI obligations, not rights.
- The Article’s central objection: obligations and rights are difficult to separate cleanly. If an AI entity can be held liable for damage it causes, symmetry suggests a human should also be liable for harming the AI entity itself — a slippery slope where imposing obligations on AI risks inadvertently conferring rights society does not intend to grant.
- The EU Commission’s subsequent 2018 AI strategy did not repeat the electronic-personhood proposal, which the Article reads as reflecting the current technological gap between AI and human capacities rather than an outright, permanent rejection.
- Chopra and White argue the conditions for legal personality could, in principle, someday be met by AI, and that resistance is rooted in “human chauvinism” and misunderstanding of what a legal person is — but they concede this is a pragmatic, policy-driven question rather than a matter of present-day logical necessity, and that only a “high degree of autonomy” would justify it.
- Pagallo, reviewing Solum’s classic 1992 arguments against AI personhood (AI isn’t human; the “missing-something” argument; AI ought to remain property) and arguments for it (avoiding the ethical problem of robots-as-slaves; providing a more coherent legal picture), ultimately concludes independent AI personhood “will not be on the legal agenda” for the foreseeable future.
- Conclusion: treating today’s AI as full legal persons is premature and “grossly misguided” given AI’s continuing dependency on an owner, operator, designer, trainer, or programmer in its decision-making. This may change if AI’s capabilities someday equal human ones, but that future is not now.
AI as Agents — Agency Law and Corporations
- This is the analogy the Article advocates: AI entities as “servants” of their owners/operators/designers/trainers/programmers, monitored, guided, and directed by a human principal who controls the purposes the AI is meant to accomplish.
- The corporate-agency comparison is used to show that a valid, well-functioning agency relationship does not require the agent to be human:
- A corporation is a non-human legal entity that can sue, be sued, contract, and hold property; it acts through its board of directors (its agents), authorized by shareholders (its principals), and the corporation is liable when its agents cause harm.
- When the corporation is insolvent, sanctions fall on shareholders through the corporate veil, not on the (non-human) corporation itself or on its individual agents — closely paralleling how, since AI entities are perpetually “insolvent”/judgment-proof, liability must fall on the human principal(s) standing behind them.
- The Restatement (Third) of Agency’s own comments state that “a computer program is not capable of acting as a principal or an agent as defined by the common law” — at present, programs are mere instrumentalities, and their malfunction creates no different legal consequence than any other instrumentality malfunctioning.
- The Article engages with this directly: taken at face value, this comment would make the whole AI-agency discussion moot (AI would just be another product). But it argues the “at present” qualifier is doing real work — the comment reflects the state of software as understood in 2006, and AI’s subsequent advances (in autonomy, adaptiveness, and the ability to reach decisions differently than static software) may render that “at present” assumption obsolete. If the agency analogy is accepted, the Restatement’s language should be updated accordingly rather than treated as a permanent bar.
- Chopra and White, Calo, and others are cited as scholars already alluding to or supporting treating autonomous artificial agents functionally as agents/extensions of a person (the “long hand of the principal”), even though robots are not human and possess some degree of independent “will.”
- Ignacio Cofone’s competing framework is discussed and distinguished: Cofone proposes locating each AI accident on a spectrum from adult human, to child, to domesticated animal, to wild animal, to corporation/tool, based on the AI’s embodiment, emergence, and “social valence,” using “agency” to mean the AI’s own internal capacity to respond to legal incentives directly (a capacity Cofone says AI does not yet have). The Article’s own use of “agency” instead describes the external principal–agent relationship between the AI and its human controller, and argues that (a) assessing embodiment/emergence/social valence levels is itself unreliable, since different experts and disciplines would classify the same AI differently, and (b) analogizing AI to full adult humans or even children remains premature until AI genuinely develops the kind of internal agency Cofone describes.
- The AI-as-agent analogy is argued to be preferable because: it is more flexible and adaptable across contexts than fixed comparisons like pets or children; it accommodates AI’s context-specific, proactive, socially-interactive behavior along a spectrum of unpredictability (the more unpredictable, the more agent-like, without ever becoming fully human); and it draws on an existing, well-developed body of human-agent law (employees, drivers, delivery workers, trustees) that maps naturally onto AI performing tasks that formerly required human agents.
- Treating AI as agents explicitly rejects the “homunculus” idea (that there is a person “inside” the machine with its own intentions) — those who created, owned, or dispatched the AI entity are responsible for its behavior and damages; the AI itself is never liable.
The AI Industry-Wide Analogies: Aviation and Vaccination
- These two analogies operate at a different level — not comparing individual AI entities to individual objects/beings, but comparing the AI industry as a whole to other industries that received a no-liability or limited-liability regime by legislative intervention, precisely to spur innovation. The Article evaluates and ultimately rejects both as adequate models for AI.
The Aviation Industry
- Brouse v. United States (Ohio, 1949) held a pilot liable for a mid-air collision that occurred while the aircraft was on autopilot, reasoning that a person “in charge” of a robotically-controlled machine must keep a “proper and constant lookout.”
- The Article finds this precedent inadequate for the AI industry for three reasons:
- There is no guarantee a human driver/operator will even be present in future AI systems (e.g., fully autonomous vehicles) — pinning liability on an operator becomes meaningless once there is no operator role to speak of.
- The Brouse defendant was a military pilot flying a government-owned plane, which may have driven the liability finding via a “deep pockets” logic that does not carry over to commercial AI markets where government is rarely a manufacturing or marketing participant.
- Aviation is an exceptionally tightly regulated physical space built from inception around autopilot use, unlike the much more varied, less-regulated terrestrial/maritime environments where most AI operates.
- The General Aviation Revitalization Act of 1994 granted small-plane manufacturers an 18-year immunity from liability suits, justified by the aviation industry’s high perceived net social benefit; the Article is doubtful Congress would extend comparable industry-wide immunity to AI, since AI spans far more fields than aviation ever did, making a single sweeping immunity impractical (though a narrower carve-out for small AI companies, mirroring the small-plane exemption, is floated as a possible partial parallel).
- Time-limit and predictable-payout mechanisms borrowed from aviation regulation are argued to be poorly suited to ground-based AI (autonomous vehicles, vessels), given the far more diverse certification regimes and infrastructure needs on the ground versus in the air; a payout-based (strict liability with a damages cap) approach might be more transferable than the time-limit approach.
- The 2018 Uber autonomous-vehicle fatality in Tempe, Arizona (killing pedestrian Elena Herzberg) is used to show how operator liability breaks down in practice: the human “safety driver,” Rafaela Vasquez, could not reasonably be expected to react in time despite sitting in the driver’s seat — analogous to security guards who must snap into split-second action after long stretches of monotony — suggesting liability is more sensibly directed at the AI’s designer/manufacturer than at a nominal human operator whose real role is passive observation, not active control.
The Vaccination Industry
- Vaccines are argued by some to offer a template because, like AI, they provide undisputed net social value while nonetheless causing occasional harm.
- Before federal preemption, vaccine manufacturers faced significant liability exposure (e.g., an $8.5 million verdict for a polio infection contracted from an oral polio vaccine), prompting Congress to pass the National Childhood Vaccine Injury Act of 1986, which limited vaccine-supplier liability and created a compensation fund financed independently of ordinary tort suits.
- The Article’s critique: legislative immunity of this kind “diminishes, if not eliminates,” manufacturers’ incentive to make marginal safety improvements. Marchant and Lindor argue this tradeoff is nonetheless worthwhile for autonomous vehicles specifically, because even an imperfect AV will likely be safer than the average human driver, so accepting near-term harm to accelerate adoption is a net positive; to them, a no-liability regime strikes the right balance of incentives.
- The Article pushes back: there is no principled reason an individual victim should personally subsidize the industry’s advancement by absorbing uncompensated damage, and a no-liability regime may itself dampen the (more valuable) incremental improvement of an already-existing technology, as opposed to the initial invention of something new.
- Bruesewitz v. Wyeth (2011) is discussed: the majority (Scalia) held the Vaccine Injury Act preempts design-defect claims against vaccine manufacturers; Justice Sotomayor’s dissent warned this creates “a regulatory vacuum in which no one ensures that vaccine manufacturers adequately take account of scientific and technological advancements” — a warning the Article treats as directly applicable to any comparable no-liability shield for AI.
- A no-liability regime removes any internalization of costs and, with it, any real incentive to improve; conditioning immunity on mandated improvements is floated but dismissed as economically impractical, since without accountability there remains no genuine driver to improve.
- A compensation fund (as with vaccines) can achieve some measure of corrective justice/fairness for victims, but does not achieve the efficient risk-allocation or deterrence goals that a properly calibrated liability regime would.
- Bottom line: because the government has made a policy decision that vaccines’ universal social benefit justifies detaching liability from the manufacturer (a decision this Article does not dispute on its own terms), and because aviation’s earlier grace period is judged to have already run its course given how much more mature aviation technology is today than in 1994, neither analogy justifies extending a comparable no-liability regime to the still-maturing, more heterogeneous AI industry. If a grace period is warranted anywhere in AI, at most it might be a narrow one for small AI companies (echoing the small-aircraft carve-out), and even that should be addressed through antitrust-style tools rather than by withholding tort remedies from injured victims.
Final Note: Is AI Something Old or New?
- The Article closes Part III by rejecting two extremes: (1) that AI requires an entirely new legal category/doctrine built from scratch (too slow, and unnecessary given AI’s continuities with existing legal categories), and (2) that AI damages are simply identical to any other accident (car accidents, workplace accidents, discriminatory-employer cases) requiring no analogy or special framing at all — a claim it says is defensible as a matter of clean liability outcomes (holding “the person behind AI” liable), but analogies remain useful tools even where a direct rule might reach a similar conclusion, because they translate an unfamiliar phenomenon into commonly understood legal language for judges, officials, and laypeople who need not be technical experts to reason about it.
- Judges are not required to be domain experts, but they need shared conceptual tools to analyze new phenomena — legal analogies supply exactly this kind of common language and toolset for courts, legislatures, and regulators.
- Of the analogies surveyed, only agency achieves a coherent, adjustable equilibrium between the general principles at stake and how specific AI-harm cases actually play out — every other candidate analogy (products, animals, slaves, electronic persons) reduces, on close inspection, to the same underlying three-party agency structure (agent, principal, victim).
Treating AI Entities as Agents-Servants
- Part IV develops the agency analogy in detail. The Article concedes the analogy is imperfect at a deep conceptual level — AI entities are not “real” servants and were never created to be — but argues its true value lies not in deep resemblance but in its legal function: direct applicability of strict liability for the harmful acts of a servant under a principal’s control and care.
- A servant is legally a sub-category of agent, distinguished by acting under closer control and supervision than agents with greater independent discretion — a fit the Article argues suits AI particularly well, since AI entities are given tasks but not genuine discretion to depart from their assigned purpose.
- Policy rationale: AI users/operators should sometimes be held to more than mere passive property-ownership standards, because they hold real ability and responsibility to prevent harm beyond what a simple product owner has; a strict liability regime tied to respondeat superior creates the right incentive structure for this.
The Meaning and Purpose of the Term “Agent”
- The Restatement (Third) of Agency defines agency as “the fiduciary relationship that arises when one person (a ‘principal’) manifests assent to another person (an ‘agent’) that the agent shall act on the principal’s behalf and subject to the principal’s control, and the agent manifests assent or otherwise consents so to act.” Black’s Law Dictionary offers a similar formal definition.
- The Article notes that “agent” is used loosely and inconsistently across contexts — e.g., “chemical agents” (active harmful substances) versus “agents” in the sentient, purposive sense — and that scholars advocating other analogies (or no analogy at all) nonetheless casually use the phrase “AI agents,” revealing an underlying conceptual gap or inconsistency in how the term is actually deployed.
- The Article’s own usage is precise and legal: “agent” describes AI entities in a relationship with human principals, deliberately using the neutral term “entities” elsewhere to avoid anthropomorphizing. It cautions that even where “agency” is used correctly in its legal sense, the same narrow rules will not necessarily apply uniformly across every type of AI agent — context still matters.
Who is the Principal?
Two possible approaches to identifying the principal:
- Mission-based approach (illustrated via Israeli agency law, the Shlichut Law): the agency relationship covers every act reasonably necessary to properly execute the specific mission given to the agent, including urgent/unforeseen acts reasonably required to safeguard the principal’s interests — even beyond the agent’s formal authorization. Liability for harm during the mission attaches to whoever sent the agent on that mission.
- Relationship-based approach (the American Restatement (Third) of Agency model): takes a broader view of the overall relationship between agent and principal — focused on the principal’s general ability to control and guide the agent — rather than on one discrete mission.
- The Article argues the second (relationship-based) approach fits AI better, because an AI entity is not typically dispatched on one bounded mission but exists in a continuous state of “being an agent” for its principal’s benefit, much like a servant. This approach also better locates the party with the greatest practical and economic capacity (“pressure point”) to train, equip, insure, or sanction the AI — administrative efficiency favors it, since the number of plausible principal-candidates is naturally limited (unlike open-ended negligence litigation).
- A structural disanalogy with human agents: human servants have both an “agent share” (tasks assigned by the principal) and an “autonomous share” (an independent life outside the agency relationship) — AI entities have no autonomous share at all; they exist in a constant, unbroken agency state from activation to deactivation, with no separate life outside their assigned function.
Creation and Termination of an AI Agency
- Agency is ordinarily created by contract (express or implied, with no formal writing required) or as a matter of law implied from the circumstances; there is no rigid formal requirement, which supports finding an agency relationship with AI even without any explicit “consent” step by the AI itself (already a somewhat awkward fit given AI cannot truly consent).
- Because the AI’s entire purpose is to function as an agent, its agency effectively begins at its creation/activation and functions continuously — unlike a human servant who takes on discrete agency tasks against a backdrop of an otherwise independent life.
- Termination: an AI agency can only end if the principal chooses to end it (even an AI’s own “choice,” if it had one, would only be a choice it was already programmed to make). Termination takes the form of the AI being decommissioned or reassigned to a different principal (by choice or the death/insolvency of the former principal) — but this only ends that specific agency relationship, not the AI’s underlying, continuing status as an agent generally.
- Several termination modes available to human agents do not translate to AI: an AI cannot itself elect to end the relationship, and it has no fixed “term” or discrete “task” whose completion would naturally end the agency, since its purpose is unbounded by time or specific task.
- Termination “by operation of law” (death, incapacity, or insolvency of principal or agent) can occur for an AI’s principal, but this merely changes who the relevant principal is, rather than terminating the AI’s status as an agent as such.
- This reinforces the case for the relationship-based (rather than mission-based) approach to identifying the principal, since the mono-purpose, uninterrupted nature of AI agency does not map onto the mission-by-mission structure of the alternative approach.
Fiduciary Duties
- Fiduciary duties normally serve to prevent, control, and minimize conflicts of interest between agent and principal — arising when an agent’s interest diverges from the principal’s and the agent acts to serve herself rather than the principal.
- The Article argues this conflict-of-interest rationale largely does not apply to AI: AI agents have no personal interests distinct from the tasks assigned to them under their mono-purpose design. The risk with AI is not divided loyalty but rather “excessive loyalty” — an AI single-mindedly pursuing its assigned objective to an extreme or bizarre degree, potentially causing harm in the process (also relevant to why intentional-tort doctrine, built around an agent’s personal motives, does not map cleanly onto AI, since an AI’s actions always serve its principal’s agenda rather than any interest of its own).
- Practical limitation of using “who is owed fiduciary duties” as a tool to identify the principal: since AI has no natural inclination toward loyalty except as explicitly programmed, pointing to a specific human as the beneficiary of “loyalty” may just reflect whoever programmed that loyalty in, rather than genuinely indicating the appropriate principal — making this an imperfect (though not fatal) tool for identifying the principal.
- The absence of a reliable fiduciary-duty relationship in the AI context reveals a genuine gap between human agency and AI agency, but the Article argues this does not undermine the analogy overall — it simply underscores that the strict liability regime behind the analogy matters more than the analogy’s perfect conceptual fit.
The Problem with Identifying the Principal
- This is presented as the reflective equilibrium’s genuinely difficult but productive problem (as opposed to the animal analogy’s genuinely disqualifying problem).
- An ex-ante, one-size-fits-all rule fixing the principal’s identity in advance is rejected: although administratively cheaper, it cannot accommodate the widely varying degrees of control and involvement different candidate-principals (owner, operator, designer, trainer, programmer, user) have across different circumstances, and would short-circuit the ongoing back-and-forth reasoning process the Article relies on throughout.
- Instead, the principal should be identified case-by-case, based on the degree of involvement, supervision, monitoring, and ability to direct the AI’s actions in light of the specific harm — a fact-sensitive inquiry rather than a fixed rule.
- At earlier stages of an AI entity’s life/use, the designer, programmer, trainer, or manufacturer is more likely to be the appropriate principal; as usage becomes more pervasive and the operator/owner’s own control and monitoring role grows, the operator/owner becomes more likely to be named principal.
- Respondeat superior does not require the principal to be personally at fault — only that the agent acted within the scope of authority the principal gave it — so fault-based objections to naming a particular principal are not decisive.
- Hacking scenario: if a third-party hacker seizes control of an AI and causes harm, the hacker is technically the ad-hoc “principal” for that harm, but is often difficult to locate or prosecute. Because the operator/owner typically has low ability to prevent hacking, the Article suggests the designer, programmer, or manufacturer — who has more control over the AI’s security architecture — is the more appropriate liable party in this scenario, though this discussion is offered only as an illustrative anecdote of the complexity involved, not an exhaustive treatment.
Multiple Principals
- Recognizes that more than one person/entity may simultaneously be in co-control of an AI agent’s activities — “multiple” or “joint” principals.
- Multiple-principal doctrine already exists across several agency-law systems: the Restatement (Second) of Agency (§ 41) and Restatement (Third) of Agency (§ 3.16) both allow two or more persons to jointly appoint an agent; Israeli agency law presumes an agent given authorization by several principals acts on behalf of all of them jointly; and civil-law systems (Louisiana Civil Code art. 3015; French Civil Code) handle multiple principals through joint-and-several liability.
- The Article adopts joint-and-several liability as its own preferred solution: where more than one entity among the candidate principals (owner, operator, designer, trainer, programmer) can properly be identified as exercising relevant control, all such principals should be held jointly and severally liable for the resulting damage.
- Illustrative examples:
- Mall security robot: a robot patrolling a mall runs over an infant. If the mall itself is both owner and operator and chose the robot’s patrol route, the mall is the most likely principal given its monitoring/supervisory ability — but if the designer/programmer already knew of a malfunction and failed to update the software, liability may be shared between the mall and the designer/programmer, since each controls a different failure point.
- Discriminatory hiring algorithm: a tech company implements a hiring algorithm that discriminates by selecting only a specific population segment. If the company chose the metrics and decided to implement the algorithm’s discriminatory recommendations, the company alone is the principal, even if it could not have predicted the discriminatory outcome. But if the metrics/scoring system were built in by an outside designer/programmer and simply adopted wholesale by the company, responsibility may be shared between the company and the algorithm’s creators.
- These examples are explicitly flagged as simplified illustrations of the reasoning process, not fully worked-out doctrinal conclusions — different underlying assumptions would change the specific liability outcome, though not the overall multi-principal framework.
The Respondeat Superior Doctrine
- Having established that AI entities form agency relationships with their human controllers, the Article turns to respondeat superior (“let the master answer”) — vicarious liability — as the doctrine that operationalizes strict liability within that agency framework.
- Rationale for the doctrine generally: when a principal entrusts a subordinate with inherently risk-bearing activities, fairness requires the principal/superior to bear responsibility for harm caused by the subordinate in the course of those duties, because the principal is in the best position to bear the loss or insure against it (the best “pressure point”), and because the doctrine incentivizes more careful selection, training, and monitoring of agents, and protects tort victims from being left uncompensated by an insolvent/judgment-proof agent.
- These underlying rationales are argued to apply with particular force to AI: AI agents are inherently and permanently insolvent/judgment-proof, so ensuring victims are not left without a remedy is especially pressing; and strict liability (rather than negligence) is the right regime because it lets the principal expand and calibrate her actual control over her AI agent’s level and scope of activity, better internalizing the true costs of that activity — something a negligence regime’s narrower “duty of care” inquiry cannot achieve as effectively.
- To establish respondeat superior, courts typically require (1) an appropriate agency relationship between principal/superior and agent/subordinate, and (2) that the harmful conduct occurred “within the scope of employment” — a line meant to separate acts for which the principal will and will not answer.
- The Article argues this scope-of-employment distinction essentially collapses in the AI context: because AI agents are mono-purpose and exhibit “excessive loyalty” rather than independent motive, there is no realistic scenario in which an AI entity acts in “an independent course of conduct not intended to further any purpose of” its principal — everything the AI does is, definitionally, in service of the task its principal assigned it. This makes the scope-of-employment gatekeeping function, which does real work in human-agency cases, largely inapplicable (or at least far less limiting) for AI agents.
- The Article engages critically with Yavar Bathaee’s related proposal to apply respondeat superior to autonomous AI given the black-box problem, but only in “mission-critical” settings or ones with a high possibility of externalizing failure risk onto others (treating it as less appropriate in “less dangerous” settings). The Article rejects this proposed limitation for two reasons: (1) the line between “mission-critical” and “less dangerous” AI is not clear, and the risk of externalizing failure onto third parties is high in both categories given the pervasiveness of the black-box problem; (2) the risk of chilling desirable AI innovation is not meaningfully greater in one category than the other, so it does not justify differential treatment. At the same time, the Article acknowledges the innovation-chilling concern is real and significant, but argues that retreating to no-liability or negligence-based supervision standards would prevent the AI industry from properly internalizing and improving on the damage it causes — the opposite of the desired incentive effect.
- Terminology clarification offered at the close of this section: because an AI agent can never itself be “found liable” in the first place, the human principal is not, strictly speaking, vicariously liable (liable in place of a liable agent) but rather primarily liable (there being no other party who was ever capable of bearing liability). This distinction does not matter to the injured third party, who is compensated either way, but it matters to the principal herself — for example, for purposes of what insurance coverage is available (insurance for vicarious liability is more readily available than for primary liability). Given that AI cannot bear responsibility for its own acts, the human principal(s) will always be primarily liable for their AI agents’ conduct, not merely vicariously so.
Conclusion
- AI entities are already an essential and rapidly growing part of society, already causing real damage, and their integration into daily life and industry will only increase. Using legal analogies to reason toward an appropriate liability regime is a standard method for handling new technologies and phenomena generally, but the choice of analogy is not free-standing — it is shaped by, and in turn shapes, the underlying regulatory purposes the analyst is pursuing.
- The Article concludes that treating AI entities as AI agents under the control and guidance of human principals is the most accurate available analogy, because of AI’s mono-purpose character, its purely instrumental value in accomplishing tasks assigned by humans, and the fact that every other non-agency analogy considered (products, animals, slaves, electronic persons) can, on inspection, be reduced to the same three-way agency structure (principal, agent, victim) with AI entities functioning, in essence, as judgment-proof agents. Even readers who reject the agency analogy itself should, the Article argues, still accept the strict liability regime (via respondeat superior) that stands behind it as the most fitting liability approach for AI.
- Quoting Rawls, the Article frames its own contribution as achieving reflective equilibrium: bringing clarity and reducing disagreement in an otherwise “cloudy and unpredictable” field. It acknowledges the theory is not fully problem-free — identifying the correct principal or principals in a given case remains a real and recurring difficulty — but characterizes this as a manageable, productive problem to be worked out within the judiciary, insurance markets, and administrative systems over time, rather than a flaw that defeats the analogy.
- The Article closes by noting the agency analogy is itself provisional and could someday become “localized” or outgrown: if AI entities eventually develop a genuine intelligence level entitling them to new rights and obligations, the mono-purpose, judgment-proof premise underlying the agency analogy would be undermined, and society would need to revisit older or newer analogies (including personhood) through the same back-and-forth reflective equilibrium process. But until that day, AI entities remain judgment-proof agents capable of causing serious harm without their victims being able to protect themselves, and holding their human principals strictly liable for that harm — via respondeat superior — is presented as the incentive structure best suited to producing a safer environment in today’s “algorithmic society.”