Abstract
The article argues that most first-generation AI liability issues can be resolved with conventional tort doctrine, or with only modest adjustment, because liability in negligence, products liability, and intentional torts is generally outcome-dependent rather than dependent on knowing an AI’s internal “state of mind” — so the AI “black-box” opacity problem is less of an obstacle than commentators assume. The more fundamental and previously overlooked challenge, the authors contend, is jurisprudential: whether the law should treat AI liability uniformly (as tort law has trended toward for most subjects) or diversely, varying the applicable liability regime — negligence, products liability, strict liability, or legislative solutions — depending on the type of AI and the setting in which it causes harm. The authors conclude that diversity, not one-size-fits-all uniformity, will often be the right approach, and that this choice interacts with the developing landscape of state and federal AI regulation and with the availability of liability and first-party insurance.
Introduction and Core Thesis
- The article addresses the role tort law can play in addressing harms caused by socially beneficial AI, departing from the view of “tort skeptics” who believe AI’s black-box nature makes conventional liability infeasible.
- Two questions frame the piece:
- Is AI’s opacity (“black-box” problem) really an insurmountable obstacle to tort liability?
- Should the law that governs AI liability be uniform (as most of tort law has evolved to be) or diverse (varying by AI type/setting), and can tort law actually implement diversity?
- Core claims:
- Many ostensible black-box obstacles can be handled because liability standards (reasonableness, design defect, intentional-tort scienter) turn on outcomes/conduct, not on knowing an AI’s internal decisionmaking “state of mind.”
- The more significant and overlooked challenge is the choice between uniform and diverse liability rules. The common law’s historical trajectory has been toward increasing uniformity (e.g., a single negligence standard for physical harm), but the authors argue the optimal approach to AI liability will be diverse — different applications/types of AI-related harm governed by different regimes (negligence, products liability, strict liability, legislation) depending on setting.
- This framework raises two subsidiary questions the article also addresses: (1) the interplay between diverse common-law liability and state/federal regulation of AI, and (2) how the availability and scope of insurance against AI liability should inform what liability is reasonable to impose.
- The article positions itself as offering an analytical framework and “proof of concept” — not a doctrinal blueprint for every possible AI tort case — to reassure courts and commentators that fashioning AI liability is generally feasible, given the wave of state-by-state common-law litigation expected over the next decade in the likely absence of comprehensive federal legislation.
- Analogy: the current moment for AI liability is compared to the aftermath of CERCLA (1980) — a long, piecemeal, jurisdiction-by-jurisdiction process of doctrinal development, here likely to occur mostly through common law given the lack of comprehensive AI legislation or preemption.
Part I: AI as a Subject of Liability
Defining AI and Its Operations
- No single definition of AI is necessary for the analysis; AI is understood broadly as software that uses machine learning to identify patterns in data and generate predictions, decisions, or content — in a sense “applied statistics,” though newer generative systems produce far more complex and flexible outputs.
- Three types of AI are distinguished for analytical purposes:
- Traditional/non-generative AI — earlier or rule-based systems and predictive models that classify or predict, reacting to specific commands.
- Generative AI — designed to produce novel content (text, images, code) rather than merely classify or predict (e.g., ChatGPT, Gemini); it does not itself take action, but the information it produces can be the basis for harmful action by others.
- Agentic AI — systems that not only produce outputs but pursue goals and take actions (e.g., invoking tools or other software), largely a matter of future development; will engage in something like “reasoning,” but developers/deployers will likely still be liable for its conduct.
- Prototypical examples of AI systems and the harm categories they may generate:
- Recommendation systems (Netflix, Amazon, Spotify, financial/tax advice) — emotional, privacy, and economic harm.
- Facial recognition — invasion of privacy from both accurate and inaccurate identification.
- Fraud detection — emotional, dignitary, privacy, and economic harm from wrongful investigations/accusations.
- Autonomous vehicles — physical injury, especially during the transitional period of mixed autonomous/conventional traffic.
- Medical AI — diagnostic/predictive tools and AI-enabled devices; misdiagnosis, or AI-based denial of health insurance claims that could violate fiduciary duties or amount to fraud.
- AI browser agents — agents that take over a user’s browser to complete tasks (e.g., purchases, emails); liability risk where guardrails/user-confirmation are absent or fail.
- Chatbots and “companion AI” — customer-service bots, virtual assistants (Siri, Alexa), and platforms like Character.AI that let users create and interact with customized chatbot personalities; risks include inaccurate information and, notably, wrongful-death litigation alleging chatbots encouraged self-harm/suicide in vulnerable (often young) users, and chatbots holding themselves out as licensed professionals (therapists, lawyers).
- Deepfakes — AI-generated fabricated text, images, voice, and video used to power financial fraud, romance scams, fake investment/charity solicitations, and impersonation of trusted individuals or institutions, causing financial and reputational harm plus broader erosion of public trust.
How Distinct Are AI’s Challenges for Tort Law?
- Opacity (“black-box” problem): the inability to peer inside certain AI operations to identify what and how the AI produced a given output.
- Opacity is not automatically an obstacle to liability. Example: it may be impossible to reconstruct why a self-driving car failed to stop, but this parallels ordinary tort disputes (e.g., the classic case Vaughan v. Menlove, where the reason for the defendant’s negligent conduct was unknowable, yet liability could still be found under the objective reasonableness standard because the law asks whether conduct was negligent, not what the defendant’s state of mind was).
- The authors’ throughline: many putative black-box obstacles can be handled by conventional doctrines that already turn on objective conduct/outcomes rather than a subjective “state of mind” — this applies to the objective negligence standard, the products-liability defective-design standard, and intentional torts such as invasion of privacy and defamation.
- AI will not be addressed by tort law alone — federal and state regulatory standards will develop alongside it (noting the Trump administration’s deregulatory federal stance as of the time of writing, alongside growing state-level piecemeal AI legislation).
- The truly novel and underappreciated challenge, per the authors, is the jurisprudential question of uniform versus diverse liability rules — discussed at length in Part III.
Part II: Low-Hanging Fruit — AI and Conventional Liability Issues
- Framing: any tort cause of action requires duty, breach, causation, and damages; the authors predict duty and breach will require the most elaboration for AI, with causation posing more limited practical difficulties and damages posing few problems of principle.
Duty
- Numerous AI-harm situations are amenable to conventional tort duties, automatically or with slight adjustment. Duty may run to the developer, seller, deployer, or user of AI depending on the causal mechanism and who is the relevant “human in the loop.”
- Conventional duty-related doctrines (vicarious liability, negligent enablement of third-party misconduct, affirmative duties, foreseeable misuse) can apply to AI cases without radical modification.
Breach
1. Negligence liability for physical injury
- The most frequently imposed tort cause of action can apply straightforwardly: negligence may lie in (1) the decision to use AI for a given purpose given the risks, (2) negligent creation techniques (inadequate testing, inadequate training, vulnerability to hacking), or (3) failure to comply with statutory/regulatory requirements (which could constitute negligence per se).
- Courts or juries could find that omitting a “human in the loop” as a check on AI missteps was itself negligent.
- Generative AI not treated as a product might still carry a negligence-based duty to warn of unavoidable risks (e.g., that “companion AI” guardrails against encouraging self-harm might not always work, as alleged regarding Character.AI).
- Subsidiary doctrines — vicarious liability, principal-agent liability, “enabling torts,” and affirmative duties to protect users from self-harm — will often apply straightforwardly, even where end users “misuse” the technology.
2. Products liability for harm caused by cyber-physical systems
- Self-driving cars and AI-enabled medical devices are clearly products, with the AI as a component part; manufacturers (and often component-part makers) are subject to liability for defective design and failure to warn.
- Some cases will be easy: a self-driving car that runs a red light, or a diagnostic device that misses a tumor a human physician using ordinary methods would catch, could be treated as defectively designed as a matter of law — the authors favor an “at least as good as a human” baseline standard for such cases.
- The dual design-defect tests: the consumer-expectations test (does the product perform as safely as an ordinary consumer would expect?) and the risk-utility test (does the risk of the challenged design outweigh its utility, often requiring proof of a reasonable alternative design). Many states apply a hybrid of both.
- Consumer expectations may see a resurgence for AI given how tech companies market safety claims to users, and given intuitions people have about how humans (not just products) perform comparable tasks (e.g., driving).
- Where AI’s opacity prevents proof of a reasonable alternative design under the risk-utility test, that is a genuinely hard case (addressed further in Part III), but this does not undermine the application of products liability doctrine in the many cases that are not hard.
- Duty to warn: manufacturers/developers can reasonably be required to warn of foreseeable harms; the authors argue the traditional reluctance to impose liability for failure to warn of unforeseeable risks (developed to protect drug makers) should not carry over as strongly to AI, since AI developers are well-positioned “cheapest cost avoiders” for both foreseeable and increasingly-foreseeable harms as machine learning improves.
- Illustrative case: in Benavides v. Tesla a jury found Tesla liable for defective design and failure to warn regarding its Autopilot system, awarding $42.6 million in compensatory damages and $200 million in punitive damages (verdict later reduced on post-trial motions; Tesla has appealed).
- Waivers/disclaimers of liability for negligently-caused physical loss are governed by existing, if state-variable, doctrine; how far these transpose to AI remains to be worked out.
3. Liability for negligently inflicted emotional distress (NIED)
- Freestanding (non-physical-injury-parasitic) NIED liability is already sharply curtailed under existing tort law and courts have been reluctant to expand it, partly due to concerns about unlimited liability and feigned harms, and partly because of the lack of available insurance for “pure” emotional distress. The authors do not expect AI to pose unique pressure to expand this narrow category.
4. Liability for economic losses
- The “economic loss rule” (ELR) generally bars recovery in tort for purely economic losses, with several variants:
- The products liability ELR: no tort liability for a defective product’s purely economic losses to the buyer unless it causes damage to “other property.”
- The “contracting parties” ELR: no liability for economic losses from negligent contract performance between parties, subject to a significant carve-out for “professionals,” who remain liable in negligence (and contract) for purely economic loss.
- Hard AI-specific line-drawing example: if an AI legal-tool vendor (e.g., a hypothetical LexisNexis-type product) warrants no hallucinations, and a law firm’s malpractice results from relying on a hallucinating tool, is the vendor a “professional” subject to negligence liability, or protected by the ELR? This turns on whether courts characterize the AI vendor as a professional-service provider, based on the totality of the parties’ relationship, not on how the AI functions internally.
- Harder example: a chatbot (e.g., Character.AI) that holds itself out as a licensed professional (lawyer/therapist) and causes financial harm — raising the question whether an agency-type relationship can bind the company via its chatbot’s representations.
- Real litigation examples raised: a suit alleging ChatGPT acted as an unlicensed lawyer, and Nippon Life Insurance’s claims that ChatGPT caused legal fees by encouraging a user to file meritless filings and reopen a settled case, allegedly worsened by OpenAI’s own marketing of ChatGPT’s bar-exam-passing ability and belatedly added legal-advice disclaimer.
- The ELR’s application varies substantially by jurisdiction (whether it applies at all to non-product services, whether there is a professional-services exception, and who counts as a “professional”), and boilerplate contractual indemnification clauses will often override the nuances of state ELR law in practice.
- The “stranger” ELR: the majority rule bars recovery for economic losses arising from a defendant’s negligent injury to a third person’s person or property (no privity/relationship to plaintiff); a minority rule allows recovery for “particularly foreseeable” plaintiffs.
- The authors argue many AI-related economic-loss scenarios can bypass the AI black-box question entirely — e.g., a CrowdStrike-like faulty-code outage: the negligence inquiry (was the code faulty? was distributing it without testing negligent?) does not depend on AI-specific opacity, though the stranger-ELR analysis (majority vs. minority rule, “particularly foreseeable” plaintiffs) would not meaningfully change based on AI’s involvement either.
5. “Intentional” torts
- These torts (scienter requirements vary) can often be handled by conventional doctrine because liability turns on outcome, not process — including malicious prosecution and interference with prospective economic advantage.
- Where AI is deployed as part of a business’s communications, the deploying entity has a “standing intention” to make the communications the AI produces in pursuit of business purposes, satisfying most intentional-tort scienter requirements; where AI “goes rogue” despite guardrails, courts may (by modest doctrinal adjustment, analogous to battery’s “intent to contact” doctrine) still hold the AI’s user/deployer to have intended the results the AI produces.
- Invasion of privacy (public disclosure of private facts): little/no complication from opacity — no scienter requirement typically applies beyond intent to make the (non-accidental) disclosure; courts could place the onus on AI developers/trainers to prevent unauthorized disclosure of highly offensive, non-newsworthy private information.
- Disclosure of confidential information (financial, genetic, etc., not necessarily “highly offensive”): could be strict liability without any need to examine AI’s internal processes — the only question is whether the disclosed data fits the actionable category.
- Fraud or negligent misrepresentation: fraud requires a false statement made knowingly or recklessly; where a human deploys AI to generate content communicated to third parties, the human’s state of mind toward that decision can satisfy scienter. Thorny issues arise around corporate vicarious fraud liability (was an “agent” — human or AI — acting with the requisite knowledge?) and securities-fraud contexts (must corporate officers verify AI-generated data feeding public disclosures?); some relaxation of strict scienter requirements may be warranted so AI cannot become a liability shield. Negligent misrepresentation may also apply based on the negligence of a human in the loop, even with agentic AI deployed — illustrated by Moffat v. Air Canada, where a Canadian small-claims tribunal held Air Canada liable for its chatbot’s negligent misrepresentation of a bereavement-fare policy, treating the chatbot as akin to any other website/app feature rather than as an autonomous agent whose internal workings mattered.
- Defamation and other torts (false imprisonment, etc.): where scienter (actual malice or negligence) is required, courts can look to the human/entity’s care in verifying AI-generated information, without needing to know why the AI generated inaccurate content. Deepfakes could be actionable in defamation (where reputational harm results) or false light (where the harm is more dignitary/non-reputational); a possible complementary doctrine is a common-law duty of take-down-upon-notice.
6. Hallucinations
- AI “hallucinations” (false information generated by the system) cut across the above categories and are not automatically tortious — whether they are turns on the same doctrines already discussed (e.g., whether the hallucination reflects a design defect, a failure to warn, or negligent failure to detect hallucinations, given available detection tools). Failure to use available hallucination-detection tools could itself be evidence of negligence or negligence per se.
Summary of Part II’s breach analysis: many bases for AI tort liability do not require peering into AI’s opaque internal operations because products liability focuses on the product’s performance (not the conduct of individual actors), and negligence/intentional torts focus on how human actors used the AI — a familiar inquiry regardless of the underlying technology.
Causation
1. Cause-in-fact
- Standard but-for causation rules generally apply; proof (often via expert testimony) that negligent training/design caused a harm may be complicated by opacity, but tort law has long dealt with analogous evidentiary difficulties in non-AI cases (e.g., whether a driver going over the speed limit could have stopped in time regardless; whether a fall would have happened even on lit stairs) via conventional standards of inference, sometimes with statistical/probabilistic proof techniques already used in tort law.
- Speculative future possibility: “explainable AI” techniques, or AI itself simulating counterfactual “rewinds” of an incident absent the alleged negligence/defect, could eventually help resolve cause-in-fact questions, including via statistical proof from multiple stochastic re-runs.
- One genuine AI-specific difference: because AI is a nascent technology, the state of causal knowledge linking AI conduct to harm types is still developing — analogous to the early, pre-epidemiological-evidence era for toxic tort litigation over drugs and chemicals. This is one reason to favor development of minimal regulatory standards for AI (as with FDA/EPA regulation of drugs and chemicals) rather than relying on tort liability alone to generate causal knowledge over time.
2. Proximate cause
- Proximate cause in AI litigation manifests in two familiar ways: (1) foreseeability of the plaintiff, the extent of harm, or the type of harm — a fact-sensitive inquiry that, once some harm from unreasonably risky AI conduct is established, is no more difficult than in conventional cases; and (2) a more normative/policy-driven inquiry (akin to duty) about whether liability should extend to certain foreseeable harms, arising in the context of sequential causes, “enabling torts,” and responsibility for the conduct of others (e.g., allocating liability between an AI developer and an AI user). These are treated as normative policy questions, not questions of empirical fact, and are not viewed as distinctively troubling for AI.
Damages
- Most AI damages issues pose no special problems of principle; recoverable damages depend on the cause of action and applicable duty/no-duty rules, and losses (bodily injury, property damage, emotional loss, economic loss, reputational harm) are provable through the same methods used in conventional tort cases.
Part III: The More Difficult Challenges — Diversity and Opacity
A. Uniform or Diverse AI Rules?
1. The choice of liability rules and constitutive categories
- Tort law has moved historically toward comparatively uniform liability rules (e.g., a single negligence standard for physical harm from ordinary conduct), but even within products liability there are multiple distinct bases (manufacturing defect, design defect, failure to warn) and separate treatment of unavoidably unsafe products (e.g., drugs).
- Treating all AI as a single, unitary “thing” subject to one liability template (all AI as a product; all AI as a service subject to negligence; blanket Section 230-style immunity by analogy to the Communications Decency Act) will usually not be sensible, because not all AI is a product and not all AI is a service — though the authors think the products liability template will often (not always) be superior.
- Analogy to electricity: tort law does not treat “electricity” as a single constitutive category — strict products liability applies to harm from electricity that has passed through a meter at abnormal voltage (Ransome v. Wisconsin Electric Power Co.), while negligence governs harm from contact with transmission lines before the meter. AI, similarly, need not be a single constitutive/normative category — tort law can apply different existing frameworks (more like products liability, more like electricity’s mixed treatment) to different AI operations, without needing to declare AI to be one “thing.” The authors align with computer scientists who view AI as fundamentally “normal technology,” while focusing specifically on how tort liability should respond.
- It seems likely that AI developers should be liable on a different basis than deployers and mere users, and that further distinctions within those categories may also be warranted.
2. AI as a product, service, or hypothetical “person”
- This characterization question matters because different standards of care and different regulatory authority may attach depending on whether AI is classified as a product or a service. Some commentators have proposed instead analyzing AI liability as though AI itself were a person/agent.
- a. Advantages of the “product” characterization: courts that classify AI (or a particular AI system) as a product can use the existing products liability doctrinal toolkit (defect analysis, component-part manufacturer liability, duty to warn) rather than inventing new common law from scratch; products liability doctrine and safety regulation have historically had a synergistic relationship, with tort litigation acting as an information-forcing catalyst for regulatory response — a role the products liability model is well-suited to continue playing for AI.
- b. The analogy versus first-principles approaches to whether a non-obviously-tangible AI system counts as a “product”:
- The analogy (defect-specific) approach asks whether the particular functionality alleged to have caused harm is sufficiently analogous to an equivalent function in a conventional tangible product (e.g., is a chatbot’s parental-lock feature analogous to a parental control on a search engine or a vehicle?).
- The first-principles (whole-system) approach, which the authors find more appealing when properly applied, asks whether the policy rationales underlying strict products liability — chiefly, allocating liability to the party best positioned to control the risk (the “cheapest cost avoider”), mass marketing, and entry into the stream of commerce — apply to the AI system, rather than whether the system is tangible.
- Illustrative cases applying a first-principles “product” characterization based on control and mass distribution rather than tangibility: Brookes v. Lyft (Lyft held liable on cheapest-cost-avoider grounds because it controlled the risk posed by its distracting app, rejecting the argument that it was “just” a service); T.V. v. Grindr (Grindr’s app treated as a product because Grindr controlled the risk and mass-marketed the app); Garcia v. Character Technologies (a wrongful-death suit alleging a chatbot encouraged a 14-year-old’s suicide survived dismissal on a products liability theory against both Character.AI and Google as an alleged component-part manufacturer, given Google’s alleged “considerable level of involvement” in developing the underlying model).
- Mass production/mass marketing to a uniform, unmodified userbase (as with “off-the-shelf” software like Grindr and Character.AI) supports treating such AI as a product, echoing earlier cases about whether navigational charts should be considered products.
- A contrasting decision (the “Social Media Cases” MDL) found that consumer expectations and risk-utility approaches don’t fit AI systems that evolve interactively and differ from user to user, and thus applied negligence (treating the platform as a service) rather than products liability.
- c. No-duty limitations on products liability: even where AI is treated as a product, no-duty rules (analogous to the products liability economic loss rule, or limits on liability for pure emotional distress) can cabin the scope of liability, rather than avoiding the issue by simply reclassifying the AI as a service to invoke a negligence test. Most significantly, First Amendment and common-law limitations on liability for inaccurate information (e.g., liability for negligent navigational charts, but no general liability for an inaccurate recipe or an inaccurate image of a non-poisonous mushroom) could be imported as no-duty limitations within products liability, where an AI system is treated as a product.
3. The choice between common law and regulatory rules
- Given the volume of pending and expected litigation, courts will have “no choice” but to make new common law case-by-case, in no particular sequence and with no guaranteed consistency across jurisdictions — a slow, potentially decades-long process toward doctrinal coherence, echoing the CERCLA insurance-coverage litigation experience.
- Comprehensive superseding federal legislation is deemed unlikely and infeasible in current political conditions, and even undesirable if hastily drafted, given the authors’ own conclusion that uniform rules are often not optimal for AI.
- The more plausible middle path is administrative regulation operating in parallel with tort liability (on the model of product-safety regulation coexisting with products liability), where tort litigation helps surface AI risks that then inform regulatory standard-setting, and courts subsequently address the interaction between new regulatory standards and tort liability (including preemption questions).
B. Opacity
- Opacity is often treated by commentators as the central, near-intractable obstacle to AI liability, on the theory that if you cannot explain how an AI produced an output, you cannot assess the reasonableness of its “conduct” under negligence or products-liability standards. Part II showed many liability bases avoid this problem entirely (e.g., analyzing a cyber-physical product’s design defect without probing the embedded AI’s internals).
- But opacity genuinely can impede claims requiring proof of an unsafe/defective AI configuration and that the configuration caused the harm — particularly the risk-utility design-defect test and certain negligent-AI-design claims. The authors offer three possible approaches/workarounds, without claiming a full general solution.
1. “System-wide performance metrics” (and critique of the Geistfeld proposal)
- Professor Mark Geistfeld (Chief Reporter of the ALI’s Civil Liability for AI project) has proposed a negligence-based “system-wide performance metrics” standard: once pre-market testing/refinement brings a “narrow,” domain-specific AI system (e.g., autonomous vehicles, medical diagnosis) to the point where it causes less than fifty percent of the harm a comparable non-AI system/human would cause, there should be no liability, because the design is then not negligent.
- The authors reject this as a liability shield (though they find it potentially useful as a “sword” — i.e., a violation of the metric could support a finding of liability), for several reasons:
- It is overprotective as a matter of principle and policy: tort law has always applied a “one-way safety ratchet” — a new, safer technology is not thereby immunized from liability for failing to be reasonably safe on its own terms. Just as MRI machines aren’t excused from liability merely for being twice as safe as X-rays, or acetaminophen for being twice as safe as aspirin, an AI system twice as safe as a human should not be excused from liability for harms attributable to its own residual unreasonable design.
- It is impractical: it would require detailed comparative accident-rate statistics for equivalent human performance under closely matched “driving conditions” (or equivalent) that simply do not exist in any comparably precise form, making it unworkable for a jury applying the standard in an actual case.
- It runs counter to how tort law has always handled new, safer technology — that a new technology reduced net risk relative to what preceded it has never itself meant that the technology was reasonably safe or free of design defect.
2. When negligence or defect may “speak for itself”
- A more limited but doctrinally cleaner opacity workaround: apply res ipsa loquitur (in negligence) and its analogous provision in strict products liability (Restatement (Third) of Torts: Products Liability § 3, “circumstantial evidence supporting inference of product defect”) to infer negligence or defect from the sufficiently frequent or severe occurrence of AI-associated harm, even without direct proof of a specific defect or negligent act.
- Such an inference would place the onus on AI defendants to explain what occurred, thereby creating an incentive for developers to invest in explainability techniques to rebut the inference.
- A related, distinct doctrine: where a defendant’s own negligence (e.g., failure to include a reasonably available explainability feature) creates the evidentiary gap in the plaintiff’s case, the burden of proof on that evidentiary issue can shift to the defendant, since the defendant is responsible for the difficulty of proof.
3. Strict liability
- Because opacity does not trouble strict liability the way it troubles negligence and design-defect analysis (which require proof of unreasonable risk/inadequate alternative design), strict liability is a candidate workaround, in two forms:
- a. “General” strict liability for all losses arising out of specified AI systems: liability for essentially all harm “arising out of” a given AI system, analogous to workers’ compensation or auto no-fault. The authors argue this is almost always undesirable and infeasible as a general matter — it would not serve deterrence or rights-based justifications for strict liability where harm is otherwise avoidable only by users taking more care (the ladder-manufacturer example: strict liability on ladder makers for all ladder-related harm would simply shift costs from careless users to manufacturers without improving safety, unless tied to actual defects). It also sidesteps hard causal-boundary (“what-is-a-cause-of-what”) questions about what conduct or activity harm should be attributed to, and could impose disproportionate costs on smaller AI enterprises/startups (including insurance costs), discouraging valuable market entry. However, exceptions may be appropriate: (1) domains (e.g., fully autonomous vehicles, certain medical AI) where AI so substantially reduces the frequency of physical injury that it becomes economically feasible and arguably desirable to impose strict liability for the smaller residual set of AI-caused losses, since negligence litigation would not be “worth the candle” for the few remaining cases; and (2) “low-hanging fruit” categories from Part II (e.g., facial recognition errors, public disclosure of private facts, some forms of defamation) where opacity is present but general strict liability (or the narrower DCE approach below) could still work.
- b. The Designated Compensable Event (DCE) approach: rather than general strict liability, target strict liability at specific, identified categories of losses (“designated compensable events”) that occur with enough combined frequency and severity (echoing the “P” in the Learned Hand B/PL formula, or the “risk” component of risk-utility) to justify treating them as a cost of doing business the AI developer/deployer should internalize, without needing case-by-case proof of negligence or defect — analogous to existing narrow compensation-fund models like the National Childhood Vaccine Injury Act and state birth-related neurological injury funds. The authors are uncertain how broadly feasible this approach will prove for AI (most AI harms may have causal connections too attenuated or uncertain for it), but think it may suit a few AI systems particularly well. A duty-to-warn alternative (rather than a duty to compensate) is also possible for such designated events, though the authors are skeptical that meaningful, non-vague AI warnings will be broadly practicable.
4. Assessment
- Even after applying all of the above tools, opacity poses challenges tort law cannot, at present, completely surmount: the ideal that liability regimes optimally provide remedies for wrongdoing, optimally compensate, and optimally deter will not be fully realized for AI, at least for a considerable period.
- Until the opacity problem is solved or circumvented at a general level, there will likely be more than the ideal number of false negatives (Type II errors — real wrongs that escape liability because they cannot be proven), and possibly false positives (Type I errors — liability imposed where it is not truly optimal), under negligence, strict products liability, general strict liability, and DCE-style targeted strict liability alike, in varying proportions that cannot currently be known with precision. Reducing false negatives will require tolerating some false positives — a tradeoff tort law has faced before and will have to accept again for AI.
Part IV: Insurance
A. Liability Insurance
- The availability of liability insurance has historically been a necessary (if not sufficient) condition for the expansion of tort liability, and the authors argue insurance considerations properly inform, without dictating, decisions about the appropriate scope of AI liability.
- Two categories of AI liability insurance are distinguished:
- 1. “Silent” AI insurance: coverage under existing, unmodified insurance products (Commercial General Liability, Cyber, Tech Errors & Omissions/Malpractice, Employment Practices, Media Liability) that already cover the underlying type of harm (bodily injury, property damage, defamation, invasion of privacy, data/network losses, negligent provision of technical/health-care services, employment discrimination) and do not currently exclude AI-related causation. As claims experience accumulates, insurers are likely to begin adding AI-specific exclusions (a few already have), which — as happened historically with cyber insurance — will likely spur growing demand for and development of affirmative AI coverage.
- 2. Affirmative AI liability insurance: still nascent, “niche,” and publicly described only in rudimentary fashion (some covering breach of performance guarantees, general liabilities, data poisoning, or IP liability), but the authors predict a growth trajectory similar to cyber insurance, which grew from about $2 billion (2018) to roughly $16.6 billion (2024) in the U.S. alone. Advantages: the institution of insurance is already in place (unlike, e.g., a wholly new regulatory agency that must be built from scratch), and insurance underwriting carries some (imperfect) safety-promoting effects. Potential headwinds: competitive premium pressure may deter some insurers from entering; insurers’ difficulty assessing the safety of different AI systems (a form of insurer-side opacity) may hinder underwriting and loss-prevention guidance; and adverse selection (riskier prospective insureds disproportionately seeking coverage) and moral hazard (insured parties potentially taking less care) may be harder for insurers to counteract in AI than in other insurance lines, at least initially. The authors’ considered conclusion, notwithstanding these obstacles, is that affirmative AI liability insurance will develop and follow closely behind the development of AI liability itself.
B. First-Party Insurance
- First-party insurance (of victims — health, property, business-interruption insurance) as distinct from liability insurance (of injurers) is also relevant, because its availability sometimes serves as an argument against imposing tort liability on injurers (illustrated by the “stranger” economic loss rule, where victims’ access to contingent business interruption insurance is sometimes cited as part of the rationale for barring recovery from a negligent stranger tortfeasor).
- In the AI context, both “silent” (existing property/cyber/business-interruption policies covering some AI-related losses) and new “affirmative” first-party AI insurance products are developing, though only in minimal amounts and types so far.
- The authors are skeptical that courts should let the availability of first-party insurance drive AI liability rules, drawing an analogy to bodily-injury/property-damage tort law generally: even though most victims are covered by health/homeowners insurance, tort liability has not been curtailed on that basis, because subrogation preserves both expeditious victim compensation (through their own first-party insurer) and the deterrent effect of tort liability (since the first-party insurer can then pursue the tortfeasor). The authors expect a similar arrangement — first-party AI insurance and AI tort liability developing on parallel, mutually reinforcing tracks — to be the sensible path forward.
Conclusion
- The article’s core insight is that understanding what is, and is not, currently feasible for tort law to address regarding AI-related harm — including the choice between diverse and uniform liability approaches — is a prerequisite to overcoming the challenges AI poses for tort law.
- Two overriding theoretical principles: (1) a backward-looking principle, that while there are real limits on what tort law can do in the face of AI opacity, these are limits on the particular manner in which tort law can handle AI-caused harm, not insuperable obstacles to handling AI liability at all; and (2) a forward-looking principle, calling for a new jurisprudential approach in which tort law embraces diverse liability regimes — rather than the one-size-fits-all uniformity historically applied within most tort categories — to address what looks, at a high level of generality, like a single subject matter but in practice calls for different treatment depending on the AI operation involved.
- A key component of the called-for diversity is room for administrative regulation to operate in parallel with common-law tort liability, with tort litigation helping to surface emerging AI risks that in turn inform regulatory standard-setting, and courts then addressing how new regulatory standards interact with tort liability.
- The practical upshot: courts and commentators can be reassured that efforts to fashion AI liability — taking into account the availability and scope of insurance as a necessary ingredient in determining what liability is sensible to impose — will generally be a workable and fruitful undertaking, notwithstanding AI’s opacity and the diversity of forms AI liability may need to take.