Abstract
This RAND report describes the basic features of U.S. tort law and analyzes their significance for the liability of AI developers whose models inflict, or are used to inflict, large-scale harm. It concludes that AI developers face considerable liability exposure under existing tort law — particularly if their models are developed or released without rigorous safety procedures — even though no AI-specific liability legislation currently exists, and that this exposure can be mitigated (though not eliminated) through rigorous precautions. At the same time, tort law’s application to AI is unclear and uncertain in important respects, creating jurisdictional variation and litigation risk that policymakers might address through targeted legislation.
Scope and Purpose
- The report is meant to be useful to AI developers, policymakers, and other nonlegal audiences (as well as lawyers) who want to understand the liability exposure AI development may entail, how it might be mitigated, and how the liability regime might be improved by legislation to better incentivize responsible innovation.
- It focuses on large-scale harms to person and property, though most doctrines discussed apply to smaller-scale harms too. It does not address liability for reputational, emotional, or other non-physical injuries, or harms (such as to election security) the tort system does not redress.
- The authors focus specifically on developers that initially create or “train” advanced AI systems, rather than parties who later modify (e.g., fine-tune) or augment (e.g., via “scaffolding”) existing models, or other participants such as compute providers or chip manufacturers.
- The analysis draws on judicial decisions, jury instructions, leading treatises and academic articles, the Restatement (Second) of Torts, the Restatement (Third) of Torts: Liability for Physical and Emotional Harm, and the Restatement (Third) of Torts: Products Liability.
- The report explicitly does not aim to be comprehensive, resolve doctrinal uncertainty, or address the deeper normative question of what the scope of AI tort liability ought to be — it describes the law as it currently stands.
- Motivating context: developers, researchers, and governments (the report cites the U.S., UK, Australia, Canada, and many others) are increasingly concerned about advanced AI’s potential to facilitate biological/chemical weapons, enable powerful cyberattacks on critical infrastructure, or drive large-scale phishing and fraud — as well as the risk that AI simply malfunctions (e.g., deceiving users unprompted, or propagating uncontrollably like a computer worm).
- Key technical background the report relies on: the distinction between narrow AI and “foundation models” trained on broad datasets; “fine-tuning,” which can either install safeguards against dangerous behavior or (in the hands of a bad actor) strip them out; and the distinction between open-sourcing (publicly releasing model weights and architecture, which lets third parties freely modify and remove safeguards) and closed-sourcing (providing access only via a controlled interface such as an API, which preserves some developer control, albeit currently limited).
The Nature of Tort Law
- Tort law allows injured parties to sue those responsible for the injury to obtain compensatory damages (and, in some cases, punitive damages or injunctions). It applies by default to AI development — no statute is needed for tort liability to attach to activities that foreseeably risk harming person or property.
- Tort law is primarily common law, made incrementally by courts deciding individual cases rather than by legislatures. Judges sometimes expand, narrow, or overrule precedent to address novel circumstances (e.g., Judge Cardozo’s opinion in MacPherson v. Buick Motor Co.).
- Much of tort law consists of broad, open-textured standards (like “reasonable care”) applied by lay juries with considerable normative discretion, making outcomes highly contextual, fact-sensitive, and difficult to predict. This unpredictability is a major reason the vast majority of tort suits settle before or during trial.
- Tort law is jurisdictionally specific. Strictly speaking there is no single “U.S. tort law” — there is California tort law, New York tort law, and so on, alongside narrow enclaves of federal tort law (e.g., admiralty). Complex choice-of-law rules determine which state’s (or states’) law governs a dispute, and a single harmful action spanning multiple jurisdictions can escape liability in some states while incurring heavy liability in others.
- Example of jurisdictional divergence: New York makes it difficult for plaintiffs to recover against a manufacturer for harms from a substantially altered/misused product, while California and most other states allow recovery if the alteration and misuse were reasonably foreseeable.
- The American Law Institute’s Restatements synthesize common threads across states and are treated as persuasive, but states are not bound by them and often adopt them selectively, so meaningful variation persists.
- Because large-scale AI harms may span many states, an AI developer whose model causes demonstrable large-scale harm will likely face some substantial tort liability in some jurisdiction, even if outcomes vary elsewhere.
- Liability insurance and settlement dynamics: sophisticated firms typically carry liability insurance, and insurers usually control the decision to litigate or settle. Legal “gray areas” create strong incentives to settle even plausible-but-uncertain claims, meaning developers may face real financial costs even where the law does not clearly render them liable. This dynamic breaks down in mass tort suits (many claims from the same harmful incident/activity), where defendants often lack risk-transfer insurance for such correlated losses (which may be uninsurable), retain control of their own defense, and can be forced into insolvency or bankruptcy — a real possibility for AI developers facing suits over a single large-scale harm event, compounded by significant reputational costs from public attention.
- Remedies:
- Compensatory damages restore the plaintiff to her pre-injury position, covering physical harm plus resulting economic and emotional harm (lost wages, loss of life’s pleasures, etc.).
- Punitive damages may be imposed on defendants who acted in an especially culpable or egregious manner, and can substantially exceed compensatory damages, though only about 5 percent of state tort cases result in a punitive award.
- Permanent (indefinite) injunctions can require a defendant to undertake or refrain from certain conduct before harm materializes, based on a balancing test weighing the magnitude/likelihood of harm against the cost of compliance. A plaintiff need not show harm is likely — a small probability of catastrophic harm may suffice. Courts could in principle enjoin further development or release of a highly capable AI system on grounds of catastrophic risk, though many courts would likely be reluctant absent concrete precedent of prior AI-caused harm.
Negligence
- Most tort cases sound in negligence, making it the most important doctrine for AI developers to understand. To prevail, a plaintiff must establish, by a preponderance of the evidence:
- Duty: the defendant owed the plaintiff a duty of care. This duty is broad by default — owed to essentially everyone whose person or property is foreseeably put at risk — with only “exceptional” carve-outs (e.g., no default duty against causing pure economic loss or standalone emotional harm). Whether a duty exists is decided by the judge, sometimes narrowed for public-policy reasons (e.g., concern about “enormous” liability, though this has not stopped enormous liability in other contexts like asbestos litigation).
- Breach: the defendant failed to exercise the care a “reasonably prudent person” would have used, sometimes assessed by weighing the social utility of the defendant’s conduct against the risk it created. Juries tend to weigh safety considerations more heavily than strict cost-benefit analysis would suggest.
- Factual causation: typically a “but-for” test — the injury would not have occurred absent the defendant’s tortious conduct.
- Proximate cause: liability is generally limited to foreseeable harms of the kind that made the conduct negligent in the first place; courts also use this doctrine to cut off liability for policy reasons.
- Industry custom and standards are central to the breach analysis. Compliance with widely accepted safety practices is strong (though not dispositive) evidence of non-negligence; failure to comply with them is strong evidence of negligence. Even where practices are not yet widespread enough to be “custom,” courts still consider other industry actors’ practices as evidence of what reasonable care requires.
- Practical upshot for developers: AI developers that forgo industry-leading safety practices — rigorous red-teaming/independent safety testing, fine-tuning to limit unsafe behavior, monitoring/moderating API-hosted models, strong information security for model weights, robust misuse safeguards, and cautious release practices that minimize the removal of installed safeguards — face substantially elevated liability risk, especially as such practices become more widespread and hence more clearly “customary.”
- Developers are advised not to eschew any safety practice with substantial currency in the industry unless they use a demonstrably comparable alternative.
- Safety-focused policymakers, developers, and advocacy/standard-setting bodies can strengthen industry-wide incentives by developing, publicizing, and formally promulgating new safety standards, which courts are likely to treat as evidence of the custom against which reasonableness is judged.
- Intervening agency and third-party misuse: A defendant’s action can be negligent if it foreseeably enables a third party’s improper conduct, but courts have sometimes held that an intervening wrongdoer “breaks the chain” of causation (an early cigar-into-an-oil-spill case established that whether the intervening act was foreseeable governs this outcome). Modern courts generally reject a blanket rule that criminal or malicious intervening acts always cut off liability; instead, liability usually turns on foreseeability and whether the defendant had a duty to guard against the third party’s conduct.
- Given publicly prominent warnings from developers, researchers, and governments about AI misuse risk (e.g., for cyberattacks or bioweapons), it will often be difficult for a defendant to argue such misuse was unforeseeable — and the fact that most leading developers install misuse safeguards cuts both ways, supporting both the claim that misuse is foreseeable and the claim that developers are obligated to guard against it.
- Where the intervening actor is innocent or merely negligent (e.g., a user instructs a model to pursue an innocuous goal and the model malfunctions into theft), intervening-agency doctrines offer little protection to the developer, even under defendant-friendly formulations.
- Analogy to other dangerous instrumentalities is mixed: New York shields product manufacturers from liability for harm following substantial alteration by a third party, while California and most other states allow liability if the alteration/misuse was reasonably foreseeable. Some courts have similarly shielded gun manufacturers from liability for third-party criminal misuse (on foreseeability or public-policy grounds), though Congress ultimately preempted most such suits by federal statute, and some state legislatures (e.g., California) have since clarified that manufacturers can be sued for negligent practices enabling misuse.
- The report argues AI developers should not assume courts will extend gun-industry-style protection to them: AI developers plausibly can take effective misuse precautions (unlike gun manufacturers, per some courts’ reasoning), several courts have allowed similar cases past summary judgment before Congress intervened by statute, the gun industry’s insulation was partly driven by its heavy regulation (AI development is largely unregulated), and California-style legislative clarifications point the other way.
- Judges may be more reluctant to impose liability where a wrongdoer used a model merely to obtain advice or information it then used to commit a wrong (raising First Amendment concerns, discussed below) than where the AI system directly causes the harm or acts as the tool of the wrongdoing (e.g., a model that itself constructs and deploys a cyberweapon).
- The report recommends that any legislative clarification of third-party-misuse liability proceed cautiously, since existing flexible standards, while murky, may better accommodate situations that are hard to analyze in advance than rigid statutory rules would.
- Causation issues: plaintiffs must show both that the AI system caused their injury (which may be hard if the malicious actor concealed which AI was used) and that the developer’s negligent conduct (e.g., failure to install adequate safeguards) — as opposed to non-negligent features — caused it. Courts, however, generally permit fairly liberal causal inferences by juries rather than demanding rigorous counterfactual proof, and legislatures could further relax causation-proof requirements for AI cases as they have in other contexts (e.g., toxic tort cases).
- Jury dynamics and settlement: because different juries may reach very different verdicts on similar facts, and because negligence is judged in hindsight (making it easy for a sympathetic, injured plaintiff to persuade a jury that a catastrophic risk should not have been taken), even developers whose conduct was arguably reasonable ex ante may face costly settlement pressure after harm occurs.
- Conclusion: negligence is a significant source of liability risk, with substantial uncertainty about issues like third-party-misuse liability, but developers can meaningfully reduce their exposure by adopting industry-leading safety practices and standards.
Products Liability
- Products liability is a specialized body of doctrine applicable to items legally classified as “products” (as opposed to services, which remain subject to ordinary negligence). It encompasses three types of claims: manufacturing defect (set aside in the report as unlikely to apply to AI), design defect, and failure to warn.
- Are AI systems “products”? This threshold question is unclear and unsettled, and may be answered differently across states. Most judicial decisions on point (concerning software generally) have said software is not a “product.” Most scholarly commentators, however, argue it should be treated as one, particularly software integrated into a physical product (e.g., an autonomous vehicle). Even where a court holds AI is not a “product,” it may still look to products liability doctrine as instructive in shaping the parallel negligence analysis.
- Design defect — risk-utility test: A substantial minority of states apply this test exclusively (following the Restatement (Third)); most states apply it alongside or blended with the consumer-expectations test. It closely resembles ordinary negligence — so close some regard it as negligence under a different name — asking whether the manufacturer failed to incorporate feasible, cost-justified safety features (e.g., misuse safeguards) to prevent foreseeable harm.
- Courts are generally reluctant to declare an entire category of product defective (e.g., ruling all frontier models unsafe), even if that category’s risks arguably outweigh its benefits — courts more often ask whether a particular product’s specific design choice (e.g., inadequate safeguards) was defective relative to a feasible alternative.
- This creates an interesting wrinkle for open-source models: a developer might argue an open-sourced model (whose safeguards are easily strippable by any technically modest actor) is a fundamentally different product category from a closed-source, API-accessed model — potentially escaping design-defect liability for choosing to open-source, even where safeguards were foreseeably easy to remove. If a court instead treats open- and closed-source release as two instances of a single product category, no such shield would exist. The report notes this line-drawing is unsettled and could go either way.
- Design defect — consumer expectations test and the malfunction doctrine: A smaller number of states rely exclusively on this genuinely strict-liability test, which asks whether the product’s design was more dangerous than an ordinary consumer would expect (paradigmatically: a malfunctioning product, e.g., steering that swerves a car off the road unprompted).
- This test could fit some catastrophic AI harms well — e.g., a model that escapes user control and self-replicates/propagates online, damaging digital infrastructure, could plausibly be characterized as “malfunctioning” in a way ordinary consumers would not expect.
- It may provide less help where a model’s dangerous propensity is or becomes an obvious, widely known feature (courts have held the test loses force where dangers are already commonly understood), or where the developer has provided a clear warning of the risk (some courts hold this forecloses “frustrated expectations”).
- The Restatement (Third)‘s §3 provides an alternative path to recovery via circumstantial evidence of defect — a plaintiff who cannot directly prove the risk-utility balance failed can still recover if the harm is of a kind that “ordinarily occurs as a result of product defect” and was not solely caused by something else. Various states have adopted this provision, and it might apply where an AI system behaves in a manifestly unintended and undesirable way (though defendants could argue an unprecedented event doesn’t provide the needed circumstantial evidence, since it isn’t yet known to “ordinarily” indicate defect).
- Liability for defective warnings: A product is defective for inadequate instructions/warnings if reasonable warnings could have reduced foreseeable harm and their omission rendered the product unreasonably unsafe. This doctrine may apply to AI even if courts decline to treat AI systems as “products,” since it can inform the ordinary negligence standard for warnings.
- Example: an open-source developer that fails to warn that fine-tuning may inadvertently strip built-in safeguards (enabling manipulation or deception) could be liable for resulting harm — though developers might counter that such a warning would itself be dangerous, by tipping off bad actors to fine-tune out safeguards deliberately.
- Warning-defect claims carry a notable strategic advantage for plaintiffs: recovery does not require proof that a proper warning would have changed anyone’s behavior (i.e., that the user would have heeded it) — only that the failure to warn caused the harm to occur while unwarned.
- Conclusion: which products-liability doctrines apply, and whether AI counts as a “product” at all, remains highly uncertain and will vary by state. Under the risk-utility test, results will largely track ordinary negligence outcomes; under the consumer expectations test, plaintiffs face a substantially easier path to recovery since they need not prove any specific design or development fault.
Strict Liability for Abnormally Dangerous Activities
- Beyond negligence and products liability, tort law imposes strict liability (liability without fault) on parties who engage in abnormally dangerous or “ultrahazardous” activities (e.g., using certain explosives, keeping dangerous wild animals) — liability attaches even if all due care was exercised, on top of any separate negligence liability.
- Courts weigh several factors in classifying an activity as abnormally dangerous: the level and magnitude of risk posed, the inability to eliminate that risk through reasonable care, how common the activity is, and its social value.
- It is plausible, though controversial, that developing and releasing the most powerful frontier models (or certain high-risk narrow AI, such as biological design tools) poses risks of a different kind and magnitude than ordinary commercial or scientific activity, and that such development is not yet in sufficiently “common usage” to escape this classification (since it currently occurs within a very small number of labs) — though this argument may weaken as such development becomes more widespread.
- Several factors counsel caution before predicting courts will apply this doctrine to AI developers, however:
- Courts have historically been very hesitant to expand the list of abnormally dangerous activities, even for activities arguably just as dangerous as those already covered.
- Courts have rarely subjected sellers or distributors of a dangerous instrumentality (as opposed to its owner or possessor) to this form of strict liability — meaning a developer that open-sources or transfers a copy of a model to a purchaser would likely not be covered by analogous precedent, though a developer that instead retains custody and control (e.g., API-only access) might be more exposed. This would create an odd asymmetry incentivizing the riskier release method (open-sourcing), which might lead courts to decline to apply the doctrine to any form of release.
- Courts weigh an activity’s net social value against its dangers, and the substantial societal value plausibly created by advanced AI development may lead courts to hesitate before deeming it abnormally dangerous, notwithstanding its risks.
- The report concludes there is little precedent for imposing this strict liability on the seller/distributor of a dangerous product post-distribution, but no bright-line rule precludes it either — and courts may be more willing to find strict liability where a powerful model has escaped the developer’s possession/control (analogous to an escaped wild animal) or has caused sufficiently widespread, catastrophic harm, which could shift the balance toward finding the activity abnormally dangerous after the fact.
Public Nuisance
- Public nuisance — “an unreasonable interference with a right common to the general public” — originated in medieval England to protect public roads and waterways but has been used in recent decades by state attorneys general and plaintiffs’ attorneys against manufacturers/distributors of tobacco, opioids, guns, lead paint, subprime loans, greenhouse gases, and water pollutants.
- If an AI model causes harm to many members of the public, public nuisance claims could be brought alongside negligence claims, offering plaintiffs several advantages:
- Although most defendants in prominent nuisance cases have arguably behaved negligently (or worse), public nuisance is in theory a form of strict liability — the defendant need not be shown to be at fault, relieving plaintiffs of the burden of proving duty, breach, and that the negligent aspect of the conduct caused the injury.
- Public nuisance suits can be brought by state officials on behalf of the public, in addition to private parties claiming “special injuries” — and state officials often have greater legal resources than individual litigants, potentially securing larger verdicts or settlements.
- Plaintiffs have sometimes been able to recover for pure economic loss (financial loss unconnected to bodily injury or property damage) via public nuisance, which is generally unavailable in ordinary negligence — meaning a developer found liable in public nuisance could face substantially larger financial exposure than one liable only in negligence.
- Public nuisance claims against dangerous-product manufacturers/distributors have received markedly uneven treatment in the courts — some rejected, others allowed to trial and resulting in large settlements or verdicts (e.g., opioid litigation) — making this another significant source of legal uncertainty for developers whose models cause widespread harm.
The First Amendment and Section 230
- These constitutional/statutory provisions can significantly constrain common-law tort liability, though their application to AI is largely untested and the report characterizes its treatment of both as preliminary.
- First Amendment considerations:
- Courts are typically resistant to imposing liability for the mere provision of ideas or information, even when it results in serious harm (e.g., the Ninth Circuit barred strict-liability claims against publishers of a book, The Encyclopedia of Mushrooms, whose inaccurate content led to food poisoning, holding publishers had no duty to verify accuracy of what they publish).
- Whether similar reasoning shields AI developers from liability for injuriously inaccurate model outputs may turn on whether developers are treated as “publishers” or another kind of protected speaker, and on whether AI development is characterized as an expressive activity or a nonexpressive one with informational by-products.
- Tort recovery is likely to be substantially easier to obtain where an AI system directly causes harm or acts as a tool wielded by a bad actor (e.g., a model that itself constructs and deploys a cyberweapon) than where it merely provides dangerous information that a human then acts on (e.g., instructing a bioterrorist on weapon construction).
- The First Amendment status of software code generally remains unsettled — lower courts have found some protection, but the Supreme Court has not ruled directly, and the degree of protection is unclear. The report argues model weights may be even less analogous to protected expression than ordinary code: weights are derived through a largely inscrutable, trial-and-error training process and may not embody the developers’ own conscious design choices or communicative intent, suggesting a plausible (if contestable) argument that weights merit little or no First Amendment protection.
- Section 230 of the Communications Decency Act of 1996, which shields providers of “interactive computer services” from being treated as the publisher/speaker of information provided by another party, has been a major shield for social media platforms hosting user content. Courts have not yet decided whether it covers a firm that provides API access to an AI model that itself generates outputs resembling human-created content (rather than merely hosting content created by a distinct third party).
- Some commentators (and an offhand remark by Justice Gorsuch during oral argument) suggest Section 230 likely will not protect AI developers, since the AI model itself — rather than a separate “information content provider” — is generating the content; other commentators reach more mixed or favorable conclusions.
- Section 230 is unlikely to protect a developer that transfers a model to another party who then hosts it, since this likely would not qualify as providing an “interactive computer service.”
- The report’s tentative conclusion: while unsettled, early indicators suggest Section 230 will not prevent developers from being held liable for AI-generated harms.
- The report cautions that an expansive judicial application of either doctrine to AI could significantly curtail the availability of tort claims for AI-caused damage, so courts, scholars, and policymakers will need to carefully work out the proper scope of each in this new context.
Conclusion and Policy Implications
- Highly capable AI systems are a growing presence in consumer products, industrial and military enterprise, and critical infrastructure, and are likely to become a growing presence in tort litigation as their autonomous behavior and misuse potential increase.
- Key takeaways the authors highlight for lawyers, judges, researchers, developers, and policymakers:
- Tort law applies to AI developers by default, since it applies to any activity that poses foreseeable risks of physical injury or property damage — no AI-specific statute or regulation is needed to trigger this exposure.
- AI developers whose models cause injury or damage face significant liability exposure under existing law, potentially under negligence, products liability, and public-nuisance doctrine simultaneously.
- Developers that fail to adopt industry-leading safety practices are especially likely to be found negligent, since negligence law gives substantial evidentiary weight to industry custom and practice.
- Tort law thereby already gives developers meaningful incentives to take care in developing and releasing advanced AI systems, reducing both the risk of causing harm and the risk of liability if harm occurs.
- At the same time, significant interpretive uncertainty remains — especially regarding liability for third-party misuse of AI models, and regarding how the First Amendment and Section 230 will bound or shape common-law tort liability. These uncertainties are, in the authors’ view, ripe for further research and analysis.
- Policy options for legislators: policymakers could pass statutes to clarify or modify the common law of tort liability as applied to AI development — for example, by clarifying or altering developers’ duties of care, clarifying the evidentiary significance of industry best practices, modifying causation-proof standards, or clarifying the conditions under which developers are liable for third-party modification or misuse of their models. Such interventions could reduce uncertainty for developers and the public and provide clearer guidance on how large-scale AI harms should be treated.
- A caution about legislating too aggressively: the authors argue legislators should be mindful of the common law’s distinctive value — it imperfectly embeds a large body of accumulated legal learning and societal experience about governing safety risks, and its generality (rather than detailed statutory specificity) may make it more flexible and responsive to fast-changing technology and a rapidly evolving understanding of AI safety risks than more rigid statutory rules. In some areas of unsettled doctrine (e.g., third-party-misuse liability), the very unsettledness of the common law may reflect the genuine difficulty of formulating adequate general principles for a novel problem, counseling deliberate, well-informed legislative engagement rather than hasty codification.